Your AI chat gets a computer.

Add Husk to Claude Code, Codex or Cursor and your AI gets a machine of its own: a terminal, files and a browser. It can run the code it writes, check the pages it talks about, and keep what it finds in a workspace you can reopen tomorrow.

Workspaces are in the 0.2.0 public preview, which isn’t code-signed yet. The guide walks you through setup and a first task.

No Husk account, and no extra API key for workspace tasks. Open source under Apache-2.0. Your AI app’s own usage limits still apply.

An AI chat panel with a short exchange in it, wired by a cable to a small computer below, whose port is lit.

Keep scrolling
windows laptop · no docker daemon · no api key
$ husk up demo --provider local
✓ demo is up
  provider   local  (WSL2 (Ubuntu))
  isolation  guardrails only — not a sandbox
  workdir    /work

$ husk exec demo -- 'uname -sr; echo hello > /work/note.txt; cat /work/note.txt'
Linux 6.18.33.2-microsoft-standard-WSL2
hello

$ husk exec demo -- 'sudo rm -rf /'
error refused: privilege escalation
hint:  add a pattern to guardrails.allowCommands in husk.yaml if this is intentional

This ran on a Windows laptop with no Docker and no API key. Husk found WSL2 and used it as the computer. At the end it refused a command that couldn’t be undone, and said what to change if you meant it.

before and after one line

youclaude mcp add husk -- npx -y @husk-ai/mcp

the conversation now has

  • shellrun a command and get back what it printed
  • read_fileread a file in the workspace
  • write_filewrite a file in the workspace
  • expose_portopen up a server your AI started, so you can visit it
$ husk exec demo -- 'uname -sr; echo hello > /work/note.txt; cat /work/note.txt'Linux 6.18.33.2-microsoft-standard-WSL2hello

a computer, for the rest of the conversation

claude mcp add husk -- npx -y @husk-ai/mcp

what it does

Husk does two things.

It gives your AI somewhere to do the work, and it can turn a conversation you’ve already had into a bot that keeps running.

It gives your AI a computer.

The computer is a throwaway Linux machine with a shell, files and open ports. Husk doesn’t start it until your AI actually needs it, and the whole conversation uses the same one, so a file made in one step is still there in the next.

husk doctor · first run
$ npx -y @husk-ai/cli

husk 0.1.0 · first run · ~/.husk created

computer providers
  docker      unavailable   the daemon is not reachable
  podman      not found
  local       ready         guarded working directory
                          ~/.husk/workspaces -- guardrails, not a sandbox

model providers
  ollama      ready         gemma3, qwen2.5-coder
  anthropic   no key        set ANTHROPIC_API_KEY

selected      local + ollama/gemma3       free, on this machine, no account

no telemetry. nothing left this machine.
chat → husk.yaml → service
$ husk import                            # find your transcripts
$ husk distill tr_01hxyz --out triage.yaml   # chat -> agent spec
$ husk run triage.yaml "check the build"
$ husk serve                             # http, discord, cron, cli

It turns a chat you already had into a bot.

Point Husk at a Claude Code, ChatGPT or Cursor conversation. It follows the thread the way it actually went, skipping the branches you backed out of, and writes it down as a short husk.yaml file you can read and edit.

This works without an API key. Husk picks out the instructions you kept repeating, the answers you left alone and the tools you actually used. Anything it can’t work out, it tells you instead of guessing.

setup

One line gives your AI a computer.

claude mcp add husk -- npx -y @husk-ai/mcp

One command. Nothing else to edit.

In Claude Code and Codex, that’s the whole setup. Cursor, Zed and Antigravity don’t have an add command, so for those you paste a short block into a settings file. The tabs above show what to paste and where. Either way, your AI gets a shell, files, ports and a browser, and its files stay put for the rest of the conversation.

The first thing Husk tells your AI is how well its machine is walled off from yours. An AI that wrongly thinks it’s walled off will take risks it otherwise wouldn’t.

  • shellrun a command and get back what it printed
  • read_fileread a file in the workspace
  • write_filewrite a file in the workspace
  • edit_filechange one exact piece of text, and stop if it isn’t there or appears twice
  • list_dirlist a directory
  • expose_portopen up a server your AI started, so you can visit it
  • computer_infowhat the machine has: CPU, memory, disk and network, so your AI doesn’t have to poke around
  • browser_gotoopen a page and get back its text
  • browser_snapshotlist what on the page can be read or clicked
  • browser_clickclick something from that list
  • browser_typetype into a field
  • browser_screenshottake a screenshot, to check a layout or show you

13 in all. It’s a full Chromium browser running inside the computer. Your AI reads each page as text rather than a screenshot, so it doesn’t need to see it.

after setup

Three things to ask it first.

Setup is one line, and then nothing tells you what changed. Ask these three, in this order. They show you quickly that there’s a real machine on the other end.

  1. “What kernel are you on?”

    It runs a command on the machine and reads the answer back. You get Linux, on a computer that didn’t exist a second ago, and not an answer your AI could have made up.

  2. “Write a note to /work/note.txt, then read it back next turn.”

    The file is still there next turn, and for the rest of the conversation. You don’t have to keep track of anything.

  3. “Start a web server and give me the URL.”

    It starts the server and hands you a link you can open in your own browser. That’s usually when it sinks in that there’s a real computer there.

isolation

Run husk doctor to see which one you have.

Husk can run your AI’s computer five ways, and two of them don’t really keep it apart from your own machine. Husk always says which kind you’re on, so you never have to guess.

How each option keeps the computer apart from your machine, what it costs, and when to use it.
providerisolationhowcostbest for
dockerisolatedits own container with no admin rights, read-only system files and a short list of allowed system callsfree, localthe default when Docker is running
podmanisolatedthe same as Docker, without needing admin rights to runfree, localLinux machines without Docker
localguardrails onlya folder it can’t leave, API keys hidden from it, a short list of blocked commands, and a time limitfree, localwhen nothing else is available
sshdepends on the machinewhatever machine you point it at; Husk can’t see how that one is set up, so it doesn’t guessfree if you own the boxa free Oracle Cloud server, a Raspberry Pi, a VPS
flyisolated (VM)a small virtual machine on Fly.io, not a container on your own computermeteredlots of work at once, without using your own machine

Husk never quietly swaps in a weaker option. If you ask for Docker and Docker isn’t running, you get an error, not a downgrade.

provider
docker
isolation
isolated
cost
free, local
when it wins
the default when Docker is running

its own container with no admin rights, read-only system files and a short list of allowed system calls. Drawn without WebGL — the shape carries the same reading.

guardrails, not a sandboxOn the local option, your AI is kept inside one folder. It can’t follow a path out of it, API keys are stripped from its environment, its output is capped, and anything it starts is stopped when time runs out. That stops accidents. It won’t stop someone trying to break out, and an AI tricked by something it read is closer to that than to an accident.

the output

What comes out is a file you can read.

It’s laid out for a person to read, with a note at the top saying which conversation it came from. That matters, because the first thing you’ll want to do is disagree with a line and change it.

Make one, edit it, then run it from the terminal or as a bot on Discord, Slack, a web endpoint or a schedule. Switching it from Claude Opus to a free model on your own machine means changing one word.

triage.yaml
# Distilled from a Claude Code session where I kept asking the same
# questions about red builds. Most of the persona is text I had already
# typed into the chat four separate times.
apiVersion: husk/v1
name: ci-triage
model: sonnet
# Falls through to a local model rather than failing when the key is
# rate limited.
fallbackModels: [flash, gemma]

persona: |
  You triage CI failures for a TypeScript monorepo.

  Always read the failing job's log before forming an opinion. Quote the
  first line that actually failed -- not the last line, which is usually
  the runner giving up.

  Never rerun a job more than once. If it fails twice the same way, it is
  not a flake.

tools: [computer, files]

computer:
  flavor: node
  network:
    mode: egress
    allow: ['*.github.com']
  idleTimeoutSec: 600

limits: { maxSteps: 24, maxCostUsd: 0.25 }

triggers:
  - { type: http }
  - { type: cron, schedule: '*/15 * * * *', prompt: 'any red builds?' }

cost

The free version is the full version.

Husk was built to run on your own machine first. Docker, Podman, SSH and Fly plug into that same base, so nothing in Husk needs an account, a card or an internet connection. Nothing is locked, nothing expires, and there’s no paid version with more in it.

Husk doesn’t collect usage data or crash reports. It only talks to the websites, AI providers and services your tasks actually use. Anything you share with your AI app is covered by that app’s own policy. This website and the docs do use Vercel Web Analytics.

What a paid, hosted version would need to offer before we charged for it.

  • no accountnothing to sign up for, nothing to log in to
  • no API keyrun a free model like Gemma or Llama on your own machine with Ollama
  • no DockerHusk works without it, and tells you what you’re missing
  • no usage trackingin Husk itself; this website uses basic analytics
  • Apache-2.0fork it, ship it, run it inside your company