Your AI chat gets a computer.
Add Husk to Claude Code, Codex or Cursor and your AI gets a machine of its own: a terminal, files and a browser. It can run the code it writes, check the pages it talks about, and keep what it finds in a workspace you can reopen tomorrow.
Workspaces are in the 0.2.0 public preview, which isn’t code-signed yet. The guide walks you through setup and a first task.
An AI chat panel with a short exchange in it, wired by a cable to a small computer below, whose port is lit.
$ husk up demo --provider local ✓ demo is up provider local (WSL2 (Ubuntu)) isolation guardrails only — not a sandbox workdir /work $ husk exec demo -- 'uname -sr; echo hello > /work/note.txt; cat /work/note.txt' Linux 6.18.33.2-microsoft-standard-WSL2 hello $ husk exec demo -- 'sudo rm -rf /' error refused: privilege escalation hint: add a pattern to guardrails.allowCommands in husk.yaml if this is intentional
This ran on a Windows laptop with no Docker and no API key. Husk found WSL2 and used it as the computer. At the end it refused a command that couldn’t be undone, and said what to change if you meant it.
youclaude mcp add husk -- npx -y @husk-ai/mcp
the conversation now has
- shellrun a command and get back what it printed
- read_fileread a file in the workspace
- write_filewrite a file in the workspace
- expose_portopen up a server your AI started, so you can visit it
$ husk exec demo -- 'uname -sr; echo hello > /work/note.txt; cat /work/note.txt'Linux 6.18.33.2-microsoft-standard-WSL2hello
a computer, for the rest of the conversation
what it does
Husk does two things.
It gives your AI somewhere to do the work, and it can turn a conversation you’ve already had into a bot that keeps running.
It gives your AI a computer.
The computer is a throwaway Linux machine with a shell, files and open ports. Husk doesn’t start it until your AI actually needs it, and the whole conversation uses the same one, so a file made in one step is still there in the next.
$ npx -y @husk-ai/cli husk 0.1.0 · first run · ~/.husk created computer providers docker unavailable the daemon is not reachable podman not found local ready guarded working directory ~/.husk/workspaces -- guardrails, not a sandbox model providers ollama ready gemma3, qwen2.5-coder anthropic no key set ANTHROPIC_API_KEY selected local + ollama/gemma3 free, on this machine, no account no telemetry. nothing left this machine.
$ husk import # find your transcripts $ husk distill tr_01hxyz --out triage.yaml # chat -> agent spec $ husk run triage.yaml "check the build" $ husk serve # http, discord, cron, cli
It turns a chat you already had into a bot.
Point Husk at a Claude Code, ChatGPT or Cursor conversation. It follows the thread the way it actually went, skipping the branches you backed out of, and writes it down as a short husk.yaml file you can read and edit.
This works without an API key. Husk picks out the instructions you kept repeating, the answers you left alone and the tools you actually used. Anything it can’t work out, it tells you instead of guessing.
setup
One line gives your AI a computer.
claude mcp add husk -- npx -y @husk-ai/mcpOne command. Nothing else to edit.
In Claude Code and Codex, that’s the whole setup. Cursor, Zed and Antigravity don’t have an add command, so for those you paste a short block into a settings file. The tabs above show what to paste and where. Either way, your AI gets a shell, files, ports and a browser, and its files stay put for the rest of the conversation.
The first thing Husk tells your AI is how well its machine is walled off from yours. An AI that wrongly thinks it’s walled off will take risks it otherwise wouldn’t.
the computer
- shellrun a command and get back what it printed
- read_fileread a file in the workspace
- write_filewrite a file in the workspace
- edit_filechange one exact piece of text, and stop if it isn’t there or appears twice
- list_dirlist a directory
- expose_portopen up a server your AI started, so you can visit it
- computer_infowhat the machine has: CPU, memory, disk and network, so your AI doesn’t have to poke around
the browser
- browser_gotoopen a page and get back its text
- browser_snapshotlist what on the page can be read or clicked
- browser_clickclick something from that list
- browser_typetype into a field
- browser_screenshottake a screenshot, to check a layout or show you
13 in all. It’s a full Chromium browser running inside the computer. Your AI reads each page as text rather than a screenshot, so it doesn’t need to see it.
after setup
Three things to ask it first.
Setup is one line, and then nothing tells you what changed. Ask these three, in this order. They show you quickly that there’s a real machine on the other end.
“What kernel are you on?”
It runs a command on the machine and reads the answer back. You get Linux, on a computer that didn’t exist a second ago, and not an answer your AI could have made up.
“Write a note to /work/note.txt, then read it back next turn.”
The file is still there next turn, and for the rest of the conversation. You don’t have to keep track of anything.
“Start a web server and give me the URL.”
It starts the server and hands you a link you can open in your own browser. That’s usually when it sinks in that there’s a real computer there.
isolation
Run husk doctor to see which one you have.
Husk can run your AI’s computer five ways, and two of them don’t really keep it apart from your own machine. Husk always says which kind you’re on, so you never have to guess.
| provider | isolation | how | cost | best for |
|---|---|---|---|---|
| docker | isolated | its own container with no admin rights, read-only system files and a short list of allowed system calls | free, local | the default when Docker is running |
| podman | isolated | the same as Docker, without needing admin rights to run | free, local | Linux machines without Docker |
| local | guardrails only | a folder it can’t leave, API keys hidden from it, a short list of blocked commands, and a time limit | free, local | when nothing else is available |
| ssh | depends on the machine | whatever machine you point it at; Husk can’t see how that one is set up, so it doesn’t guess | free if you own the box | a free Oracle Cloud server, a Raspberry Pi, a VPS |
| fly | isolated (VM) | a small virtual machine on Fly.io, not a container on your own computer | metered | lots of work at once, without using your own machine |
Husk never quietly swaps in a weaker option. If you ask for Docker and Docker isn’t running, you get an error, not a downgrade.
- provider
- docker
- isolation
- isolated
- cost
- free, local
- when it wins
- the default when Docker is running
its own container with no admin rights, read-only system files and a short list of allowed system calls. Drawn without WebGL — the shape carries the same reading.
guardrails, not a sandboxOn the local option, your AI is kept inside one folder. It can’t follow a path out of it, API keys are stripped from its environment, its output is capped, and anything it starts is stopped when time runs out. That stops accidents. It won’t stop someone trying to break out, and an AI tricked by something it read is closer to that than to an accident.
the output
What comes out is a file you can read.
It’s laid out for a person to read, with a note at the top saying which conversation it came from. That matters, because the first thing you’ll want to do is disagree with a line and change it.
Make one, edit it, then run it from the terminal or as a bot on Discord, Slack, a web endpoint or a schedule. Switching it from Claude Opus to a free model on your own machine means changing one word.
# Distilled from a Claude Code session where I kept asking the same
# questions about red builds. Most of the persona is text I had already
# typed into the chat four separate times.
apiVersion: husk/v1
name: ci-triage
model: sonnet
# Falls through to a local model rather than failing when the key is
# rate limited.
fallbackModels: [flash, gemma]
persona: |
You triage CI failures for a TypeScript monorepo.
Always read the failing job's log before forming an opinion. Quote the
first line that actually failed -- not the last line, which is usually
the runner giving up.
Never rerun a job more than once. If it fails twice the same way, it is
not a flake.
tools: [computer, files]
computer:
flavor: node
network:
mode: egress
allow: ['*.github.com']
idleTimeoutSec: 600
limits: { maxSteps: 24, maxCostUsd: 0.25 }
triggers:
- { type: http }
- { type: cron, schedule: '*/15 * * * *', prompt: 'any red builds?' }
cost
The free version is the full version.
Husk was built to run on your own machine first. Docker, Podman, SSH and Fly plug into that same base, so nothing in Husk needs an account, a card or an internet connection. Nothing is locked, nothing expires, and there’s no paid version with more in it.
Husk doesn’t collect usage data or crash reports. It only talks to the websites, AI providers and services your tasks actually use. Anything you share with your AI app is covered by that app’s own policy. This website and the docs do use Vercel Web Analytics.
What a paid, hosted version would need to offer before we charged for it.
what free means here
- no accountnothing to sign up for, nothing to log in to
- no API keyrun a free model like Gemma or Llama on your own machine with Ollama
- no DockerHusk works without it, and tells you what you’re missing
- no usage trackingin Husk itself; this website uses basic analytics
- Apache-2.0fork it, ship it, run it inside your company