跳到主要内容
Supermarket
返回能力市场
Claude Skill
programming
MIT

invisible_dots

Open-source, self-hosted alternative to OpenAI Dots, Meta Muse, Grok Bot, Manus Cue and Claude Cowork. AI agents, each with a virtual machine on your PC with a desktop, a shell, files, memory and skills that stay, invisible to anti-bots. Any model on OpenRouter.

feder-crfeder-cr
89/ 100

公开评测 · 综合采用结论

证据充分,整体质量与安全表现优秀

查看评测依据 评测我的项目基于公开项目证据,非安全认证或安装推荐
31.8kstars
4.7kforks
最近更新 2小时前
评测生成时间(北京时间)
本报告引擎
v3.16.0
当前引擎
v3.16.0

规则版本一致,但报告只反映生成时的证据,不代表项目代码和安全状态始终不变。

重新评测此项目

进入后确认来源与额度,提交才会创建任务。

Evaluation report

综合采用结论

89
A
满分 100
值得推荐低风险
决策摘要

证据充分,整体质量与安全表现优秀

90%
高置信度
91
文档
100
安全
83
质量
100
活跃
65
采用
  • 基础评测完成+25/25确定性评分与静态安全扫描已完成
  • README 有效证据+15/256,103 个去重后的有效字符
  • 独立证据来源+20/205 类非重复证据,重复文件不叠加
  • 仓库元数据+10/10已取得仓库状态与采用数据
  • 活跃记录+5/5已取得最近提交时间
  • AI 复核+15/15已完成结构化 AI 证据复核
How it works · 架构图

invisible_dots 组件与权限关系

README以组件与依赖关系描述系统(VM、浏览器、权限、通道),无明确时间顺序,故用架构图

AI 提取 · 证据约束

左右滑动查看完整图示

invisible_dots 组件与权限关系README以组件与依赖关系描述系统(VM、浏览器、权限、通道),无明确时间顺序,故用架构图消息/任务工具调用审批在VM内执行驱动浏览器调用模型Web UI/CLI/API入口Dot 引擎代理核心权限与Inbox审批QEMU 虚拟机隔离环境反检测Firefox浏览器身份OpenRouter 模型推理
图示依据
  • • What a Dot has:A computer of its own 为硬件加速VM,A browser that is not blocked 为C++补丁Firefox
  • • Permissions you set:每个工具属allow/ask/deny,ask在Inbox等待并只执行一次
  • • Many ways to reach it:Web UI、命令行、HTTP API、Telegram、WhatsApp
五维表现
自托管持久化AI代理,每代理独立QEMU虚拟机与反检测Firefox,权限分级与任务队列明确,价值可验证;最大缺口是README未给出输出/结果示例与API细节,且SKILL.md格式校验未通过。
质量证据
  • 未通过: Agent Skills 格式校验 0/1 个通过
  • Quickstart:需Node 24+、Go 1.25+、Git与硬件虚拟化,执行 setup --all 安装QEMU并启用加速器
  • What a Dot has 表格:权限为allow/ask/deny,ask在Inbox等待且重启后仍有效并只执行一次
  • Which one fits 对比表:工作运行在自有PC的VM,浏览器为C++补丁Firefox,每身份独立profile
  • SKILL.md(format_valid=false):browser_identity_create/launch/close、browser_snapshot、browser_click_at 等工具与操作顺序
  • License 章节:MIT,第三方组件见 THIRD_PARTY_NOTICES.md;Disclaimer 声明按现状提供
采用建议
优势
  • 问题与用途描述
  • 有效 README
  • 安装或接入步骤
  • 可执行示例
  • 未发现已知高风险模式
关注点
  • invisible_engine_dots/skills/invisible-playwright/SKILL.md:YAML frontmatter 无法安全、唯一地解析
  • 缺少输出或结果说明
  • README缺少输出或结果说明,仅有hero.gif描述,无文本化结果示例
  • SKILL.md格式校验未通过(0/1),其正文不能作为可复用性证据
  • 浏览器反检测依赖C++补丁的Firefox,首次启动新身份可能耗时数分钟
适合

需要在本地PC运行持久化浏览器代理的个人或小团队、需要按身份隔离cookie/登录并设置工具级权限的用户、需要定时任务与多通道(Web UI/CLI/HTTP API/Telegram)接入的场景

不建议直接用于

无硬件虚拟化或非x86-64环境的用户、需要稳定生产级SLA而非alpha状态软件的场景、不愿在本地运行QEMU虚拟机与自备OpenRouter密钥的用户

也有自己的公开项目?先看完证据,再用当前规则生成独立报告。

评测我的项目 →
文档证据
91/100
问题与用途描述10 分
有效 README12 分
安装或接入步骤14 分
可执行示例16 分
输入、参数或工具说明11 分
输出或结果说明9 分
限制、权限或边界12 分
错误处理或排障8 分
许可证信息5 分
结构化章节3 分
安全证据
低风险
未发现已知高风险模式

静态扫描不是安全保证,生产接入前仍应人工复核权限和数据边界。

优先改进清单
  1. 01修复 invisible_engine_dots/skills/invisible-playwright/SKILL.md:YAML frontmatter 无法安全、唯一地解析
  2. 02补充输出或结果说明
方法、证据与局限展开
数据来源

GitHub Repository API

扫描范围

19 个文件 · 26,341 字符

评测引擎

v3.16.0 · AI 复核已启用(deepseek-flash)

局限
  • 静态评测不会安装或执行项目代码
  • 安全扫描基于高信号文件与已知模式,不能替代人工审计
  • 流行度只反映采用程度,不代表安全或工程质量

30 天热度趋势

README

invisible_dots

Open-source, self-hosted alternative to OpenAI Dots, Meta Muse, Grok Bot, Manus Cue and Claude Cowork.

A virtual machine on your PC with a desktop, a shell, files, memory and skills that stay,
invisible to anti-bots. Any model on OpenRouter. You decide what each one may do.

tests license: MIT status: alpha hosts: Linux and Windows

Quickstart · Guide · Architecture · Security · Privacy

A real Dot at work: asked in its chat to open github.com/trending and the day's top repository, it opens Firefox on its own computer, which the Computer tab shows live, reads the trending list and the repository's page, and answers in the chat with what the repository does and its stars.

A Dot is a persistent AI agent with a QEMU virtual machine of its own, on your own PC. Its disk, files, memory, skills and browser logins outlast every task. You talk to it from a web UI, the command line, an HTTP API or Telegram, and it runs on any model on OpenRouter, with your key.

Quickstart

You need Node 24+, Go 1.25+, Git and hardware virtualization (x86-64), plus an OpenRouter key.

Windows (PowerShell):

winget install -e --id OpenJS.NodeJS.LTS; winget install -e --id GoLang.Go; winget install -e --id Git.Git
git clone https://github.com/feder-cr/invisible_dots; cd invisible_dots
npm ci; npm run build --workspace @invisible-dots/cli
node apps/cli/dist/invisible-dots.mjs setup --all
node apps/cli/dist/invisible-dots.mjs server

Linux (Ubuntu 24.04):

curl -fsSL https://deb.nodesource.com/setup_24.x | sudo -E bash - && sudo apt-get install -y nodejs git && sudo snap install go --classic
git clone https://github.com/feder-cr/invisible_dots && cd invisible_dots
npm ci && npm run build --workspace @invisible-dots/cli
node apps/cli/dist/invisible-dots.mjs setup --all
node apps/cli/dist/invisible-dots.mjs server

setup --all installs QEMU and turns on the accelerator (KVM, or the Windows Hypervisor Platform), then builds or downloads the Dot's images; run it again after a restart and it carries on. Then open http://127.0.0.2:3000, paste your OpenRouter key and create your first Dot. Every step and its failure modes: the guide's quickstart.

What to ask a Dot

Anything that needs a computer and a person's judgement, for as long as it takes:

Open a browser identity called research, go to https://example.com and tell me the page's title and its first sentence. Leave the browser open.

Every morning, check one-way fares from Milan to Lisbon for the next two weeks, write them to ~/workspace/fares.csv and tell me the cheapest day.

Log in to the shop with the shopping identity, download this month's invoices to ~/documents, and remember where the invoices page is for next time.

What a Dot has

A computer of its ownA hardware-accelerated VM with a Linux desktop and a persistent disk. It sleeps when idle and wakes for the next message, task or automation.
A browser that is not blockedinvisible_playwright_mcp: Firefox patched in C++, the fingerprint set inside the engine. Each identity keeps its own cookies and logins.
Memory and skillsIt writes its own notes and how-tos in its home folder, as Claude Code does, and reads them on the next task.
Permissions you setEvery tool belongs to a permission: allow, ask or deny. An ask waits in your Inbox, survives a restart and runs the call once.
Tasks and automationsA queue with priorities and start times, and its own recurring jobs, for which its computer is started on time.
Many ways to reach itWeb UI, command line, HTTP API with live events, Telegram, and WhatsApp as an opt-in.
Nothing lost on a crashA restart or a kill -9 keeps every message and task you saw accepted, and a tool call cut short is never run twice.

Which one fits

A browser API or libraryA cloud sandbox for agentsinvisible_dots
Where the agent's work runsYour code drives a browserA machine in someone's cloudA VM on your own PC, one per agent
What stays between tasksWhat your code savesWhat the sandbox keeps, for its lifetimeIts disk, files, memory, skills and browser logins
The browserChromium, often over CDPWhatever the sandbox shipsFirefox patched in C++, one identity per profile
Risky actionsYour code decidesYour code decidesAllow, ask or deny per permission, answered from the Inbox or a chat
What you writeCodeCodeA message or a task

Documentation

Related projects

The pieces of this one. A Dot's browser is invisible_playwright_mcp, on invisible_playwright and invisible_core; the engine is a fork of nanobot.

Neighbours. cua gives agents computers through its own SDK and sandboxes; E2B runs agents' code in cloud sandboxes; OpenHands is a platform for software-development agents; browser-use lets an LLM drive a Chromium browser from Python; Open Interpreter runs the code a model writes on your own machine. invisible_dots puts the agent, its computer and its browser on your PC, one VM per agent, behind permissions you set.

License

MIT, see LICENSE. Third-party components and their licenses: THIRD_PARTY_NOTICES.md.

Disclaimer

This project is provided as-is, with no warranties. Use it at your own risk and in compliance with the laws of your jurisdiction. A Dot acts with your accounts and from your connection: respect the terms of the sites it visits and their robots.txt.


Built by Federico Elia