by shibit-net
"AI 桌面管家 · 多 Agent 协作编排 · 一句话调动团队完成复杂任务
# Add to your Claude Code skills
git clone https://github.com/shibit-net/xuanjiLast scanned: 7/23/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@anthropic-ai/claude-code: @anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@babel/core: @babel/core: Arbitrary File Read via sourceMappingURL Comment",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@larksuiteoapi/node-sdk: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@vitest/coverage-v8: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "@vitest/ui: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "@xenova/transformers: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: Uncontrolled recursion in XML serialization leads to DoS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "axios: Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF",
"severity": "high"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Large numeric range defeats documented `max` DoS protection",
"severity": "high"
},
{
"type": "npm-audit",
"message": "concurrently: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "form-data: form-data: CRLF injection in form-data via unescaped multipart field names and filenames",
"severity": "high"
},
{
"type": "npm-audit",
"message": "glob: glob CLI: Command injection via -c/--cmd executes matches with shell:true",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "joi: joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnx-proto: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnxruntime-web: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "protobufjs: Arbitrary code execution in protobufjs",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "sharp: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591",
"severity": "high"
},
{
"type": "npm-audit",
"message": "shell-quote: shell-quote quote() does not escape newlines in object .op values",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "tar: node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "tmp: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite-node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "xlsx: Prototype Pollution in sheetJS",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-07-23T06:30:16.524Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}xuanji is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by shibit-net. "AI 桌面管家 · 多 Agent 协作编排 · 一句话调动团队完成复杂任务. It has 103 GitHub stars.
xuanji failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/shibit-net/xuanji" and add it to your Claude Code skills directory (see the Installation section above).
xuanji is primarily written in TypeScript. It is open-source under shibit-net on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh xuanji against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
中文版本 | English Version
璇玑是一个桌面端 AI 管家。你跟它对话,它自动调度多个 AI Agent 分工协作,交付成品。
和聊天机器人不同:
| 聊天 AI | 璇玑 |
|---|---|
| 你说一句,它回一句 | 你说一句,它调动一个团队 |
| 每次对话都是新对话 | 记住你的偏好、关系、历史决策 |
| 你需要手动串联多个工具 | 它自动编排工具链,端到端交付 |
| 做错了你再说一遍 | 纠正一次,永久修正 |
核心能力:多 Agent 协作编排 · 知识图谱记忆 · 分层 Prompt 引擎 · MCP/Skills 按需加载 · 桌面端原生体验
看过《钢铁侠》就知道贾维斯。Tony 说「帮我把 Mark 42 的推进系统优化一下」——贾维斯调取历史数据、对比合金方案、跑模拟、出报告。中间不需要 Tony 当搬运工,方案被否决后永远不会再提。璇玑想成为这样的 AI 管家。
现在的 AI 助手还差三步:
① 记不住关系。 别人存的是文档,能搜到你写过的句子。璇玑建的是图谱——知道「Morgan 是 Tony 的女儿」「Morgan 不喜欢吃辣」,信息之间有连线。
② 不会团队协作。 别人一个人干活,或者几个人各自干活。璇玑是一支有分工、有配合、可以当场扩编的团队——5 种协作策略,串行/并行/层级/辩论/流水线。
③ 不会学。 别人猜你可能要什么(可能猜错),或者这次改了下次又犯。璇玑被你纠正一次,知识图谱永久更新,下次自动修正。
璇玑内置 7 个 Agent + 5 种协作策略。没有合适的预置 Agent?当场创建一个。
| 策略 | 做什么 | 适用场景 |
|---|---|---|
| 串行 | 一个接一个,前人的输出是后人的输入 | 有依赖关系的多步骤任务 |
| 并行 | 几个人同时分析不同维度 | 代码审查、多角度分析 |
| 层级 | Leader 分配任务,汇总结果 | 复杂项目分解 |
| 辩论 | 各抒己见,争论达成共识 | 方案难分高下时 |
| 流水线 | 数据像工厂流水线逐步处理 | 数据处理、内容生产 |
你说:"帮我做一条璇玑的宣传视频"
→ product-manager: 分析目标用户,输出需求文档
→ ui-designer: 设计视觉风格和分镜脚本
→ software-engineer: 生成视频分镜代码
→ 璇玑主Agent: 汇总交付完整方案
| 特性 | 璇玑 | OpenClaw | Hermes |
|---|---|---|---|
| 多 Agent 协作 | ✅ 5 种策略 | ⚠️ 单模式子Agent | ⚠️ 并行+看板 |
| 知识图谱记忆 | ✅ 实体-关系-事件 | ⚠️ 向量搜索 | ✅ 三层记忆 |
| 记忆可视化 | ✅ Cytoscape 拓扑图 | ❌ | ❌ |
| 记忆反馈修正 | ✅ 纠正即永久生效 | ⚠️ 自动推断 | ❌ |
| 分层 Prompt | ✅ L0-L2 按场景加载 | ⚠️ 文件拼接 | ⚠️ 组件拼接 |
| 桌面应用 | ✅ Electron + React Flow | ✅ Web UI | ⚠️ 终端 TUI |
| 当场建 Agent | ✅ | ❌ | ❌ |
| MCP + Skills | ✅ 天工坊市场 | ✅ ClawHub | ✅ agentskills.io |
| 知识图谱 | 多 Agent 辩论 |
|---|---|
![]() |
![]() |
| Agent 库 | 视频生成 |
|---|---|
![]() |
![]() |
┌─────────────────────────────────────────────────┐
│ 🖥️ Electron 桌面应用 │
│ 对话界面 · React Flow 流程图 · 知识图谱 │
├─────────────────────────────────────────────────┤
│ 🤖 多 Agent 协作引擎 │
│ 主Agent · 场景分类器 · 工程师 · PM · 设计师 │
│ 记忆管理 · 上下文压缩 │
│ 5 种协作策略 · 当场创建 Agent │
├─────────────────────────────────────────────────┤
│ 📚 L0-L2 动态 Prompt 引擎 │
│ L0 基础层(始终) · L1 场景层(1-3个) · L2 协调层 │
├────────────────────┬────────────────────────────┤
│ 🔌 MCP + Skills │ 💾 本地存储 │
│ 按需加载·天工坊 │ SQLite 图谱 · 加密存储 │
└────────────────────┴────────────────────────────┘
git clone https://github.com/shibit-net/xuanji.git
cd xuanji
npm install
export ANTHROPIC_API_KEY="sk-ant-..."
export OPENAI_API_KEY="sk-..."
# 或自定义端点
export XUANJI_BASE_URL="https://your-api-endpoint.com"
export XUANJI_MODEL="claude-sonnet-4-6"
npm run dev:gui # 桌面应用(推荐)
npm run build:gui:mac # 构建 macOS
npm run build:gui:win # 构建 Windows
npm run dev # 命令行开发模式
环境要求:Node.js >= 20、npm >= 9
| 场景 | 具体能力 |
|---|---|
| 知识分析与决策 | 读长篇文档、对比技术方案、出分析报告 |
| 跨会话记忆管家 | 记住偏好、关系、重要日期 |
| 自动化工作流 | 一句话需求 → 多 Agent 流水线 → 交付 |
| 多媒体创作 | 剧本 → 定妆照 → 短剧视频,同一条对话全流程 |
| 社交媒体运营 | 浏览器自动登录、撰写内容、配图发布 |
| 群聊协作 | 飞书 Bot 加入群聊,理解上下文、指代消解 |
| 桌面自动化 | computer-use MCP 操控桌面软件 |
| 层级 | 技术 |
|---|---|
| 语言 | TypeScript 5.7+ (ESM, ES2022) |
| 运行时 | Node.js 20+ |
| LLM SDK | @anthropic-ai/sdk, openai, node-llama-cpp |
| 数据库 | better-sqlite3 |
| 桌面 | Electron 40+, React 18, TailwindCSS, shadcn/ui |
| 可视化 | React Flow, Cytoscape |
| 代码分析 | tree-sitter (TS/Python/Java) |
| Agent | 角色 |
|---|---|
| xuanji | 主 Agent,唯一面向用户,40+ 工具 |
| scene-classifier | 意图分析,分类场景+复杂度 |
| memory-manager | 提取并维护长期记忆 |
| context-compressor | 长对话压缩为结构化摘要 |
| software-engineer | 代码编写与调试 |
| product-manager | 需求分析与产品规划 |
| ui-designer | UI/UX 设计 |
贾维斯是电影里的终极形态。璇玑才刚刚起步。
模型推理有天花板,复杂任务偶尔走偏。多 Agent 协作在极端场景还不够稳定。记忆图谱准确度随数据量衰减。桌面客户端体验也还在打磨。
但我们在持续迭代,每周都有新版本。欢迎来提 issue、参与讨论。
GNU Affero General Public License v3.0 with Commons Clause — 详见 LICENSE