by saltmd
The open-source workspace for people and AI agents. Docs, databases and realtime collaboration with an MCP server in the same binary, so agents work in the same workspace on the same permissions. One Go binary, one SQLite file, self-hosted.
# Add to your Claude Code skills
git clone https://github.com/saltmd/salt.mdLast scanned: 10/9/2026
{
"issues": [
{
"file": "README.md",
"line": 27,
"type": "remote-install",
"message": "Install command (remote install script piped to a shell — review the source before running): \"curl -fsSL https://raw.githubusercontent.com/saltmd/salt.md/main/install.sh | sh\"",
"severity": "low"
}
],
"status": "PASSED",
"scannedAt": "2026-10-09T11:09:50.514Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how salt.md compares with popular alternatives.
salt.md is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by saltmd. The open-source workspace for people and AI agents. Docs, databases and realtime collaboration with an MCP server in the same binary, so agents work in the same workspace on the same permissions. One Go binary, one SQLite file, self-hosted. It has 128 GitHub stars.
Yes. salt.md passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/saltmd/salt.md" and add it to your Claude Code skills directory (see the Installation section above).
salt.md is primarily written in TypeScript. It is open-source under saltmd on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh salt.md against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
curl -fsSL https://raw.githubusercontent.com/saltmd/salt.md/main/install.sh | sh
One command downloads the binary for your platform, installs it, starts it and
prints the address to open. On a Linux server it sets itself up as a systemd
service, and running it again upgrades it. No curl on the machine?
wget -qO- … | sh does the same.
Or with Docker:
docker run -d -p 8420:8420 -v salt-data:/data ghcr.io/saltmd/salt.md:latest
There is nothing else to install: no database server, no cache, no object store. Reverse proxies, TLS and backups are in the self-hosting guide.
An agent is asked to organise the launch notes. A page appears, a database is created, the rows fill in. A person opens the same board a second later and carries on. Same pages, same permissions, same history.
Connect Claude, ChatGPT, Codex, Cursor, Gemini CLI or any other MCP client to
/mcp and it works on the workspace you use:
And a list it cannot touch. No agent can create or delete accounts, issue tokens, take or restore a backup, change instance settings or decide who is in a workspace, and the server tells every agent that connects. A credential carries its person's access and never more, every workspace decides what agents may do there, and the activity log keeps their changes apart from yours.
MCP tools · Agent access · Permissions
Moving in? Markdown files, CSVs and a Notion export import from the same menu.
flowchart LR
people(["People<br>browser · desktop · phone"]) --> salt
agents(["Agents<br>Claude · ChatGPT · Cursor"]) -- MCP --> salt
tools(["Your tools"]) -- "REST · webhooks · iCal" --> salt
salt["salt.md<br>one Go binary"] --> data[("SQLite file<br>+ uploads")]
One Go process, built with CGO_ENABLED=0: a static binary with a pure-Go
SQLite driver and the frontend embedded. No PostgreSQL, no Redis, no object
store, no separate collaboration server.
install.sh, or the Docker imageThe desktop app for macOS and Linux is a window onto a server you run, not a second copy of the product.
salt.md/wiki covers every screen, every property type,
every tool an agent can call and every setting on the server. It is written next
to this code and checked against it on every build: a tool name that no longer
exists, an API path that is not a route or a screenshot whose screen has changed
fails the build. Every page is also plain Markdown at the same address with
.md on the end, indexed for agents at
/wiki/llms.txt.
Issues and pull requests are welcome. Pull requests need a signed CLA; CONTRIBUTING.md says what that means and why it exists. Security reports go to dev@salt.md, not to a public issue: see SECURITY.md.
AGPL-3.0. Use it, run it at work, change it. If you offer it to others over a network, publish your changes.
The components salt.md is built on, with their licences in full, are in
THIRD-PARTY-NOTICES.md. A running instance serves the
same list at /licenses.