invisible_dots
Open-source, self-hosted alternative to OpenAI Dots, Meta Muse, Grok Bot, Manus Cue and Claude Cowork. AI agents, each with a virtual machine on your PC with a desktop, a shell, files, memory and skills that stay, invisible to anti-bots. Any model on OpenRouter.
- 评测生成时间(北京时间)
- 本报告引擎
- v3.16.0
- 当前引擎
- v3.16.0
规则版本一致,但报告只反映生成时的证据,不代表项目代码和安全状态始终不变。
进入后确认来源与额度,提交才会创建任务。
综合采用结论
证据充分,整体质量与安全表现优秀
- 基础评测完成+25/25确定性评分与静态安全扫描已完成
- README 有效证据+15/256,103 个去重后的有效字符
- 独立证据来源+20/205 类非重复证据,重复文件不叠加
- 仓库元数据+10/10已取得仓库状态与采用数据
- 活跃记录+5/5已取得最近提交时间
- AI 复核+15/15已完成结构化 AI 证据复核
invisible_dots 组件与权限关系
README以组件与依赖关系描述系统(VM、浏览器、权限、通道),无明确时间顺序,故用架构图
左右滑动查看完整图示
- • What a Dot has:A computer of its own 为硬件加速VM,A browser that is not blocked 为C++补丁Firefox
- • Permissions you set:每个工具属allow/ask/deny,ask在Inbox等待并只执行一次
- • Many ways to reach it:Web UI、命令行、HTTP API、Telegram、WhatsApp
- 未通过: Agent Skills 格式校验 0/1 个通过
- Quickstart:需Node 24+、Go 1.25+、Git与硬件虚拟化,执行 setup --all 安装QEMU并启用加速器
- What a Dot has 表格:权限为allow/ask/deny,ask在Inbox等待且重启后仍有效并只执行一次
- Which one fits 对比表:工作运行在自有PC的VM,浏览器为C++补丁Firefox,每身份独立profile
- SKILL.md(format_valid=false):browser_identity_create/launch/close、browser_snapshot、browser_click_at 等工具与操作顺序
- License 章节:MIT,第三方组件见 THIRD_PARTY_NOTICES.md;Disclaimer 声明按现状提供
- 问题与用途描述
- 有效 README
- 安装或接入步骤
- 可执行示例
- 未发现已知高风险模式
- invisible_engine_dots/skills/invisible-playwright/SKILL.md:YAML frontmatter 无法安全、唯一地解析
- 缺少输出或结果说明
- README缺少输出或结果说明,仅有hero.gif描述,无文本化结果示例
- SKILL.md格式校验未通过(0/1),其正文不能作为可复用性证据
- 浏览器反检测依赖C++补丁的Firefox,首次启动新身份可能耗时数分钟
需要在本地PC运行持久化浏览器代理的个人或小团队、需要按身份隔离cookie/登录并设置工具级权限的用户、需要定时任务与多通道(Web UI/CLI/HTTP API/Telegram)接入的场景
无硬件虚拟化或非x86-64环境的用户、需要稳定生产级SLA而非alpha状态软件的场景、不愿在本地运行QEMU虚拟机与自备OpenRouter密钥的用户
也有自己的公开项目?先看完证据,再用当前规则生成独立报告。
评测我的项目 →静态扫描不是安全保证,生产接入前仍应人工复核权限和数据边界。
- 01修复 invisible_engine_dots/skills/invisible-playwright/SKILL.md:YAML frontmatter 无法安全、唯一地解析
- 02补充输出或结果说明
方法、证据与局限展开收起
GitHub Repository API
19 个文件 · 26,341 字符
v3.16.0 · AI 复核已启用(deepseek-flash)
- 静态评测不会安装或执行项目代码
- 安全扫描基于高信号文件与已知模式,不能替代人工审计
- 流行度只反映采用程度,不代表安全或工程质量
30 天热度趋势
README
invisible_dots
Open-source, self-hosted alternative to OpenAI Dots, Meta Muse, Grok Bot, Manus Cue and Claude Cowork.
A virtual machine on your PC with a desktop, a shell, files, memory and skills that stay,
invisible to anti-bots. Any model on OpenRouter. You decide what each one may do.
Quickstart · Guide · Architecture · Security · Privacy
A Dot is a persistent AI agent with a QEMU virtual machine of its own, on your own PC. Its disk, files, memory, skills and browser logins outlast every task. You talk to it from a web UI, the command line, an HTTP API or Telegram, and it runs on any model on OpenRouter, with your key.
Quickstart
You need Node 24+, Go 1.25+, Git and hardware virtualization (x86-64), plus an OpenRouter key.
Windows (PowerShell):
winget install -e --id OpenJS.NodeJS.LTS; winget install -e --id GoLang.Go; winget install -e --id Git.Git
git clone https://github.com/feder-cr/invisible_dots; cd invisible_dots
npm ci; npm run build --workspace @invisible-dots/cli
node apps/cli/dist/invisible-dots.mjs setup --all
node apps/cli/dist/invisible-dots.mjs server
Linux (Ubuntu 24.04):
curl -fsSL https://deb.nodesource.com/setup_24.x | sudo -E bash - && sudo apt-get install -y nodejs git && sudo snap install go --classic
git clone https://github.com/feder-cr/invisible_dots && cd invisible_dots
npm ci && npm run build --workspace @invisible-dots/cli
node apps/cli/dist/invisible-dots.mjs setup --all
node apps/cli/dist/invisible-dots.mjs server
setup --all installs QEMU and turns on the accelerator (KVM, or the Windows Hypervisor Platform), then builds or
downloads the Dot's images; run it again after a restart and it carries on. Then open http://127.0.0.2:3000,
paste your OpenRouter key and create your first Dot. Every step and its failure modes:
the guide's quickstart.
What to ask a Dot
Anything that needs a computer and a person's judgement, for as long as it takes:
Open a browser identity called research, go to https://example.com and tell me the page's title and its first sentence. Leave the browser open.
Every morning, check one-way fares from Milan to Lisbon for the next two weeks, write them to ~/workspace/fares.csv and tell me the cheapest day.
Log in to the shop with the shopping identity, download this month's invoices to ~/documents, and remember where the invoices page is for next time.
What a Dot has
| A computer of its own | A hardware-accelerated VM with a Linux desktop and a persistent disk. It sleeps when idle and wakes for the next message, task or automation. |
| A browser that is not blocked | invisible_playwright_mcp: Firefox patched in C++, the fingerprint set inside the engine. Each identity keeps its own cookies and logins. |
| Memory and skills | It writes its own notes and how-tos in its home folder, as Claude Code does, and reads them on the next task. |
| Permissions you set | Every tool belongs to a permission: allow, ask or deny. An ask waits in your Inbox, survives a restart and runs the call once. |
| Tasks and automations | A queue with priorities and start times, and its own recurring jobs, for which its computer is started on time. |
| Many ways to reach it | Web UI, command line, HTTP API with live events, Telegram, and WhatsApp as an opt-in. |
| Nothing lost on a crash | A restart or a kill -9 keeps every message and task you saw accepted, and a tool call cut short is never run twice. |
Which one fits
| A browser API or library | A cloud sandbox for agents | invisible_dots | |
|---|---|---|---|
| Where the agent's work runs | Your code drives a browser | A machine in someone's cloud | A VM on your own PC, one per agent |
| What stays between tasks | What your code saves | What the sandbox keeps, for its lifetime | Its disk, files, memory, skills and browser logins |
| The browser | Chromium, often over CDP | Whatever the sandbox ships | Firefox patched in C++, one identity per profile |
| Risky actions | Your code decides | Your code decides | Allow, ask or deny per permission, answered from the Inbox or a chat |
| What you write | Code | Code | A message or a task |
Documentation
- Guide: install, the web UI, the command line, the browser, channels, configuration, updating
- Architecture: every component and why it is there
- Troubleshooting and development and tests
Related projects
The pieces of this one. A Dot's browser is invisible_playwright_mcp, on invisible_playwright and invisible_core; the engine is a fork of nanobot.
Neighbours. cua gives agents computers through its own SDK and sandboxes; E2B runs agents' code in cloud sandboxes; OpenHands is a platform for software-development agents; browser-use lets an LLM drive a Chromium browser from Python; Open Interpreter runs the code a model writes on your own machine. invisible_dots puts the agent, its computer and its browser on your PC, one VM per agent, behind permissions you set.
License
MIT, see LICENSE. Third-party components and their licenses: THIRD_PARTY_NOTICES.md.
Disclaimer
This project is provided as-is, with no warranties. Use it at your own risk and in compliance with the laws of your jurisdiction. A Dot acts with your accounts and from your connection: respect the terms of the sites it visits and their robots.txt.
Built by Federico Elia