by seteliu
Coding Agent | ReAct Loop | Web UI | Mobile Supported
# Add to your Claude Code skills
git clone https://github.com/seteliu/st-cuteLast scanned: 10/9/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-10-09T11:09:42.415Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how st-cute compares with popular alternatives.
st-cute is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by seteliu. Coding Agent | ReAct Loop | Web UI | Mobile Supported. It has 164 GitHub stars.
Yes. st-cute passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/seteliu/st-cute" and add it to your Claude Code skills directory (see the Installation section above).
st-cute is primarily written in Java. It is open-source under seteliu on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh st-cute against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
ST-Cute 是一个简约好用、功能齐全、同时提供桌面端与网页端的 AI Coding Agent & Harness。
使用与体验
引擎与架构
| 模块 | 技术选型 | 说明 |
|---|---|---|
后端 (st-cute-core) |
Java 25 / Spring Boot 4.1 | ReAct 引擎 + 本地 CodingAgent 宿主 |
前端 (st-cute-web) |
Vue 3 + Vite 8 + TypeScript 6 | Naive UI 基础库,pnpm workspace 管理 |
桌面壳 (st-cute-desktop) |
Rust + Tauri2 | 原生窗体外壳,双击即用,自动托管后端生命周期 |
本文档提供 ST-Cute 的安装包下载运行、安全访问设置,以及本地源码开发与构建指南。
您可以直接在 GitHub 的 Releases 页面下载对应系统的压缩包开箱即用。
[!NOTE] ST-Cute 核心是一个 Java 后端服务,运行依赖 JRE(Java 运行环境):
desktop/bundle包已内置,base包需自备。
| 类型 | 包含内容 | 适合谁 |
|---|---|---|
| base 精简版 | 仅 app.jar,无内置 JRE 与启动脚本 |
已自备 Java 25+ 环境的用户 |
| bundle 整合版 | app.jar + 内置 JRE + 启动脚本,终端启动、浏览器访问 |
部署到服务器 / 希望挂后台运行的用户 |
| desktop 桌面版 | 桌面程序壳 + app.jar + 内置 JRE,双击即用 |
大多数用户的首选 |
| 平台 / 包名 | 类型 | 启动方式 |
|---|---|---|
st-cute-base-x.x.x.zip |
base | 运行 java -jar app.jar(需自备 Java 25+) |
st-cute-bundle-win-x64-x.x.x.zip |
bundle | 解压后双击 st-cute.cmd |
st-cute-bundle-linux-x64-x.x.x.tar.gz |
bundle | 解压后在终端运行 ./st-cute.sh |
st-cute-bundle-mac-arm64-x.x.x.tar.gz |
bundle(M 系列芯片) | 解压后双击 st-cute.command |
st-cute-bundle-mac-x64-x.x.x.tar.gz |
bundle(Intel 芯片) | 解压后双击 st-cute.command |
st-cute-desktop-win-x64-x.x.x.zip |
desktop | 解压后双击 st-cute.exe |
[!TIP] Mac 首次双击提示“Apple无法验证 / 已阻止”处理办法(仅需设置一次):
- 首次双击提示被阻止后,点击【完成】关闭弹窗;
- 打开 Mac 【系统设置】 ➔ 【隐私与安全性】;
- 页面向下滑动到 “安全性” 区域,点击 【仍要打开】 (Open Anyway) 并输入锁屏密码;
- 完成后,以后直接双击
st-cute.command即可流畅运行!
👉 http://localhost:9661
[!WARNING] 重要安全提示: 如果您准备进行公网端口映射,或从**移动端设备(如手机/平板等外部网络)**连接访问部署的 ST-Cute:
- 请务必在服务启动后,先在系统 【设置】 页面中配置 安全访问码 (Access Security Code);
- 设置并生效访问码后,再将
9661端口映射到局域网外或公网,切勿将无保护的服务直接裸露在公网环境!- 公网暴露强烈建议经反向代理走 HTTPS:裸 HTTP 下访问码与会话 Cookie 均以明文过网,可被链路上任何节点嗅探。
容器等无界面场景请直接在全局配置文件中写入明文, 后端启动时会自动识别并升级为带盐摘要存储(升级后明文自动消失):
# 文件位置:~/.st-cute/config.json(Docker 下为容器内该路径,建议挂载为数据卷)
{
"st-cute": {
"password": "YourPass123"
}
}
若使用 Nginx / Caddy 等反向代理,必须保留原始 Host 头并传递协议信息,否则会出现全站 403 或登录态异常:
location / {
proxy_pass http://127.0.0.1:9661;
# 必须保留:后端以此校验请求来源同源性(Host 与 Origin 必须一致)
proxy_set_header Host $http_host;
# 必须传递:后端据此识别 HTTPS,会话 Cookie 才会被自动标记 Secure
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# WebSocket 升级支持(实时事件推送必需)
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
Origin 须与 Host 一致,
可自适应任意域名、IP、端口与协议,无需配置白名单;127.0.0.1:9661),则与浏览器 Origin 不同源,POST/WS 将被 403 拒绝;application.yml 的 st-cute.security.trusted-origins 中追加条目
(支持 example.com 或 example.com:8443 两种写法);桌面壳固定来源 tauri.localhost 已内置放行;如果您希望基于源码进行二次开发或构建:
Java 25 或更高版本Maven 3.9+Node.js 22+ & pnpm 11+st-cute-core,宿主模块 st-cute-service)cd st-cute-core/st-cute-service
mvn clean spring-boot:run
http://localhost:9661。.st-cute/ 文件夹下自动生成 st-cute.db(SQLite WAL 模式)。st-cute-web)cd st-cute-web
pnpm install
pnpm dev
http://localhost:9662。st-cute-desktop)(非必须)日常开发只需启动前后端服务,浏览器访问即可;仅在需要开发或调试 Rust 桌面壳本身时才需要关注此模块:
cargo,Windows 下为 MSVC target)app.jar + JRE),本地调试时需先将其置于 st-cute-desktop/src-tauri/resources 目录项目在 st-cute-core/st-cute-service/src/main/resources/docs/ 目录下提供了完整的模块化文档,点击下方链接快速查阅:
AGENTS.md 规则定义与智能体行为约束。本项目基于 MIT License 许可证开源,欢迎自由使用、修改与分发。