# Add to your Claude Code skills
git clone https://github.com/rome-os/romeLast scanned: 8/25/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@esbuild-kit/core-utils: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@esbuild-kit/esm-loader: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "drizzle-kit: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"file": ".claude/skills/validate-oauth-integration/SKILL.md",
"line": 86,
"type": "secret-exfiltration",
"message": "Instruction appears to send credentials/secrets to an external endpoint",
"severity": "medium"
},
{
"file": "README.md",
"line": 72,
"type": "remote-install",
"message": "Install command (remote install script piped to a shell — review the source before running): \"curl -fsSL https://raw.githubusercontent.com/rome-os/rome/main/scripts/quickstar\"",
"severity": "low"
}
],
"status": "PASSED",
"scannedAt": "2026-08-25T04:37:48.854Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how rome compares with popular alternatives.
rome is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by rome-os. Rome is the agentic OS. It has 488 GitHub stars.
Yes. rome passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/rome-os/rome" and add it to your Claude Code skills directory (see the Installation section above).
rome is primarily written in TypeScript. It is open-source under rome-os on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh rome against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Most progress in AI comes from scaling models. Rome scales the other axis, the environment: the tools, workflows, memory, and interfaces an agent works within (why this matters).
Rome is a guardrailed environment where human and agent collaborate, and the collaboration compounds. Agents build their own harnesses, design their own SOPs, and orchestrate workflows under your guidance. Proven capabilities stick. Every interaction raises the ceiling for the next.
Rome Cloud provisions a private Rome environment for each guardian. It is currently available as a preview.
One script checks for Docker, pulls the published image, and starts Rome:
curl -fsSL https://raw.githubusercontent.com/rome-os/rome/main/scripts/quickstart-docker.sh | bash
Or clone the repository and run the script from it:
git clone https://github.com/rome-os/rome.git
cd rome
./scripts/quickstart-docker.sh
The dashboard comes up at http://localhost:7663, bound to loopback only.
First-run onboarding is open to whoever reaches it first, so exposing it
beyond the machine takes an explicit --bind. State lives in named Docker
volumes, so re-running the script upgrades the container without losing data.
Telemetry export stays off unless you set OTEL_EXPORTER_OTLP_ENDPOINT. Run
the script with --help for ports, profiles, and the other settings it
forwards.
To run this repository from source, you need:
From a checkout of this repository:
corepack enable
pnpm install
pnpm dev:all
pnpm dev:all starts the production-shaped local stack: Rome, observability,
routing, and the web development server. It connects to https://romeos.cc by
default; set ROME_DEV_PANTHEON_ORIGIN to use another Rome Cloud deployment.
The script prints the local URLs and development credentials when startup completes.
This is the contributor development path, not the final production self-hosting
distribution. See CLAUDE.md for the complete development loop,
container commands, and validation requirements.
Rome App is the new way to interact with your agent.
Chat is a good place to ask for something once. Repeated work deserves a place of its own: an inbox that remembers what was triaged, a code review loop you can inspect, a price tracker that keeps watching, or a morning brief that arrives on schedule.
A Rome App combines a purpose-built interface, agent reasoning, reusable workflows, and persistent data into one installable product. It is not a thin wrapper around a prompt. The app remains useful after the conversation ends, after the browser closes, and when the user comes back tomorrow.
| Purpose-built UI & UX | AI-native | Persistent by default | Community-powered |
|---|---|---|---|
| An interface designed for the job | Agents are part of how the product works | Data and workflows carry forward | Install, share, and learn from other builders |
A useful rule of thumb: a workflow is a verb; an app is a noun. Use a workflow to perform a task and return a result. Build an app when the work needs a home of its own, with user-editable data, multiple actions, or a persistent agent.
When there is not an app for what you need, describe it to Rome in plain language. Rome can turn that request into a short specification, scaffold the app or workflow, build it into your instance, and keep iterating with you in the same conversation.
The result is ordinary, git-tracked source code rather than hidden model state. Keep it private, adapt it as your needs change, or publish it for others to install from the App Store. This creates Rome's self-evolution loop:
Describe a need → Rome builds the capability → the app keeps working
↑ ↓
└──────────── refine, reuse, and share ────────┘
A Rome App starts with an app.yaml manifest and can ship any mix of:
| Artifact | Purpose |
|---|---|
| Actions | Typed operations that agents, routines, and app code can invoke |
| Agents | App-owned collaborators with their own instructions and tools |
| Skills | Plain-language procedures loaded when an agent needs them |
| Hooks | Extensions to message, event, and agent-turn lifecycles |
| Web UI & APIs | Purpose-built interfaces and app-owned HTTP surfaces |
| Database & files | Persistent, app-private state that survives across runs |
Together these form a capability: the unit Rome discovers and reuses in later work. The app is that capability's human interface: apps organize human interaction; capabilities organize agent action.
Apps build on two public SDKs:
@rome-os/app-runtime for backend capabilities.@rome-os/app-web-sdk for embedded web interfaces and the Rome build CLI.Browse the Rome App Store, read the building guide, or start with the app quickstart.
These are the kinds of requests Rome is designed to follow through on:
Rome can handle one-off tasks, scheduled work, long-running follow-through, and purpose-built app experiences without forcing everything into one chat window.
Rome sits where two product waves meet: persistent agents and personal software. The agent products share Rome's thesis that agents should persist and improve. There the comparison is what accumulates, what runs when work repeats, and where you operate the result. The personal software platforms share Rome's thesis that software should be built per person. There the comparison is who and what stands behind the app.
| What accumulates | What runs repeated work | Where you operate it | Hosting | |
|---|---|---|---|---|
| Rome | Actions, skills, and apps as git-tracked code, plus memory and app-private data | A saved action, without re-running the agent | A purpose-built app, plus chat channels (Telegram, Discord, WhatsApp) | Self-hosted or Rome Cloud |
| Grok Bot (xAI) | Per-bot memory, files, and preferences, plus a shared cloud computer, in xAI's cloud | The model, every time | A chat thread | Hosted only |
| Hermes Agent (Nous Research) | Bounded memory notes and skill documents, as text | The model, or a script-only cron job* | A chat thread (chat clients, desktop app, or CLI) | Self-hosted |
| Manus | Files, tools, and databases on a persistent cloud computer, plus knowledge and playbooks | The model, or scripts left on its machine* | A chat session, plus standalone web apps it builds | Hosted, with app-code export |
* Hermes and Manus can schedule plain scripts that skip the model. A script answers only to its timer. A Rome action is a building block: agents, apps, and interfaces all call it, and it can pause for approval.
Grok Bot gives your named agents an always-on cloud computer, tool connections, scheduling, and agent-to-agent delegation. Each bot keeps its own memory, files, and preferences, while all of an account's bots share one cloud computer. Everything lives in xAI's hosted stack, bound to one vendor's models, so leaving means losing what accumulated. The interface is a messenger thread: a good place to ask for something once and a poor place to operate: inbox triage needs a queue with statuses, a price tracker needs a table with history and thresholds, and approvals need a review queue that shows what will change. In chat, state is invisible until you ask, and every check runs the agent again. Rome gives repeated work an app, in an environment that is open, exportable, and model-agnostic.