惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
MyScale Blog
MyScale Blog
量子位
WordPress大学
WordPress大学
F
Full Disclosure
V
V2EX
美团技术团队
I
InfoQ
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Security Archives - TechRepublic
Security Archives - TechRepublic
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
W
WeLiveSecurity
Google DeepMind News
Google DeepMind News
TaoSecurity Blog
TaoSecurity Blog
大猫的无限游戏
大猫的无限游戏
Project Zero
Project Zero
Spread Privacy
Spread Privacy
P
Palo Alto Networks Blog
Know Your Adversary
Know Your Adversary
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Application and Cybersecurity Blog
Application and Cybersecurity Blog
阮一峰的网络日志
阮一峰的网络日志
The Register - Security
The Register - Security
罗磊的独立博客
博客园 - 叶小钗
H
Hacker News: Front Page
N
News | PayPal Newsroom
宝玉的分享
宝玉的分享
腾讯CDC
The Cloudflare Blog
T
Threat Research - Cisco Blogs
Latest news
Latest news
博客园 - 司徒正美
T
Tailwind CSS Blog
H
Help Net Security
IT之家
IT之家
C
CXSECURITY Database RSS Feed - CXSecurity.com
NISL@THU
NISL@THU
O
OpenAI News
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Privacy International News Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
S
Security @ Cisco Blogs
AWS News Blog
AWS News Blog
T
Tor Project blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
T
Threatpost

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店 GitHub - EdoardoBambini/Agent-Armor-Iaga: AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens. HN Vibes — Week 15, Apr 7–13 2026 GitHub - chojs23/ec: Easy terminal-native 3-way git mergetool vim-like workflow GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - JakOb-dotcom/cloud-sandbox-security-analysis: Technical analysis and Proof of Concept (PoC) regarding environment variable exfiltration in containerized cloud sandboxes via side-channel data leaks. Springboards - Flint Alpha Show HN: A simpler coding agent harness GitHub - audiodude/sudomake-friends GitHub - 256thFission/mini-mythos: OSS clone of Anthropic’s Mythos harness to locate C/C++ memory vulnerabilities Show HN: OpenParallax: OS-level privilege separation for AI agent execution Hacker News Sorted - Chrome 应用商店 Show HN: How to Install Docker on Ubuntu 24.04 LTS: Complete 2026 Guide GitHub - himanshudongre/smriti GitHub - sverrirsig/claude-control: macOS desktop dashboard for monitoring and managing multiple Claude Code sessions GitHub - ory/dockertest: Write better integration tests! Dockertest helps you boot up ephermal docker images for your Go tests with minimal work. Chiral - Chrome 应用商店 Show HN: Two Claudes collaborating through shared memory on a $100 mini-PC GitHub - pmichaillat/latex-cv: Minimalist LaTeX template for academic CVs GitHub - oguzbilgic/posse: A web UI for Anthropic Managed Agents. GitHub - sshiraz/depsly: Dependency risk analysis tool for npm packages ABI Add safari/agent-harness — Safari browser automation via safari-mcp by achiya-automation · Pull Request #212 · HKUDS/CLI-Anything GitHub - Halfblood-Prince/trustcheck: Verify PyPI package attestations and improve Python supply-chain security GitHub - oguzbilgic/kern-ai: Agents that do the work and show it. GitHub - bruits/satteri: High-performance Markdown and MDX processing for the JavaScript ecosystem GitHub - tylergibbs1/feedstock: High-performance web crawler and scraper for TypeScript, powered by Bun and Playwright GitHub - Grimm67123/grimmbot: The self-improving sandboxed and open-source AI agent. With persistent memory and scheduling. GitHub - whitevanillaskies/whitebloom: Local whiteboard that blooms. GitHub - hwdsl2/docker-whisper: Docker image for a self-hosted Whisper speech-to-text server with speaker diarization and OpenAI-compatible transcription and translation APIs. Powered by faster-whisper. Supports all Whisper models, NVIDIA GPU (CUDA) acceleration, JSON/SRT/VTT output, SSE streaming, offline mode, and multi-arch (amd64, arm64). GitHub - yisding/reviewwiggum GitHub - MarwanAlsoltany/serrors: Structured errors for Go: sentinel hierarchies, typed data, custom formatting, and slog integration. GitHub - soatok/age-php GitHub - Luthiraa/markitme GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits GitHub - tombedor/excalicharts GitHub - wh1le/excalidraw-edit: Open and edit .excalidraw files from the terminal. Offline, auto-saves to disk. MalExt Sentry - Malicious Extension Scanner - Chrome 应用商店 GitHub - syi0808/asciianimesvg: Generate animated ASCII art SVGs from text. CLI, Rust library, WASM, and web editor. GitHub - zaina-ml/ml_forge: A visual-based graph node editor for training computer vision models. GitHub - anakin87/llm-rl-environments-lil-course: 🌱 A little course on Reinforcement Learning Environments for evaluating and training Language Models GitHub - takaakit/superpowers-uml: Superpowers-UML modifies Superpowers to ensure a software development workflow in which AI agents design through UML modeling. AdriByte Studio - Sviluppo Web e Soluzioni Digitali GitHub - chouligi/angel-copilot: Your personalized Angel Investment Advisor Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 GitHub - agenteractai/lodmem: Level Of Detail Context Management for Agents GitHub - ostefani/subnetlens: A fast, concurrent network scanner with a TUI and plain-text CLI, built in Go. It discovers live hosts on your network, scans their open ports, resolves hostnames, and fingerprints operating systems—delivered. Cyber Pulse: Agentic Intel - Apps on Google Play Whisper API: Self-Hostable Speech to Text Transcription The Agent-Web Protocol Stack: A Research Thesis GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Show HN: Provepy – A Python decorator that proves your code using Lean and LLMs Show HN: Pardonned.com – A searchable database of US Pardons GitHub - patrickdappollonio/dux: Dux is a terminal UI that lets you run multiple AI coding agents side by side, each in its own git worktree, with full companion terminals, macros, commit generation, and a command palette that knows more tricks than you do. kMC Crystal Simulator Show HN: HyperFlow – A self-improving agent framework built on LangGraph GitHub - stef41/vibescore: 🎵 Grade your vibe-coded project. One command, instant letter grade across security, quality, dependencies, and testing. GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. imgur.com GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. GitHub - nowork-studio/toprank: Open-source Claude Code skills for SEO, SEM, Google Ads GitHub - tacomanator/sash: Lightweight macOS menu bar app for reliably cycling through windows of the current application. Appents | Social Media Management for Product-First Teams GitHub - pnhoang/youtube-spam-blocker: Automatically detects and hides spam messages in YouTube Live chat. Set rate limits, keyword filters, and block repeat offenders. GitHub - decisionnode/DecisionNode: CLI + Local MCP - A shared structured memory store across Claude Code, Cursor, Windsurf, Antigravity, and every MCP client. Semantically queryable. GitHub - AvaCodeSolutions/django-email-learning: An open source Django app for creating email-based learning platforms with IMAP integration and React frontend components. The $100K Gap in Kubernetes Security Tooling Function Calling Harness: From 6.75% to 100%
GitHub - abi/lilo
abi · 2026-04-25 · via Hacker News: Show HN

Lilo

Lilo is an agentic personal OS — your apps, your memories, your files, your agent, in one workspace.

Ask your agent to build apps, customize your OS, remember things, and tackle your TODOs using everything in your workspace.

Reach it from desktop, mobile, WhatsApp, Telegram, or email. Ships with a starter set of apps; reshape anything.

Join the Lilo Discord License: MIT

todo-list-demo.mp4

Features · Quick start · Configuration · Workspace apps · External messaging · Deployment


Features

🧱 Apps on demandShips with a starter set (Desktop launcher, Todo, Calories, Calculator, Wordpad, Minesweeper) and you can ask the agent to build more. All apps have full agentic capabilities.
🗂️ Full workspaceStore anything as files in the filesystem and preview markdown, code, images, and PDFs inline — accessible to both you and the agent.
💬 Talk to Lilo anywhereInbound message webhooks for Email (Resend), WhatsApp (Twilio), and Telegram. The agent replies in the same channel and keeps a persistent chat per contact.
🧠 MemoryRemembers details about you, your tasks, and your work.
🎨 Rich tool suiteImage generation (Replicate), web search & scraping (Firecrawl), headless browser automation (Browserbase), filesystem ops, shell execution, network fetch — all callable by apps and the agent when configured.
📱 Mobile-readyOptimized for phones. All apps render seamlessly on both.
🔐 Password-gated and privateOne env var locks down the entire web app and all backend APIs (REST + WebSocket). Webhooks stay accessible with their own provider-signed requests.
🧰 Model-agnosticPick between GPT 5.4 (OpenAI) and Claude Opus 4.7 (Anthropic) per chat. Switch mid-conversation.
🔄 Git-backed cloud syncOptionally sync your workspace to a git remote so the entire workspace (apps, data, and memories) is versioned and portable across devices.
⌨️ Keyboard-first UX⌘K / Ctrl+K command palette for instant app switching. Browser back/forward navigates between previously opened apps.

Quick start

Prerequisites

  • Node.js 20+
  • pnpm 10+
  • An API key for at least one of: OpenAI, Anthropic

1. Install

git clone https://github.com/abi/lilo.git
cd lilo
pnpm install

2. Configure

Create a .env.local at the repo root:

# Required
LILO_WORKSPACE_DIR=./workspace          # where the agent's files live
LILO_SESSIONS_DIR=./.lilo-sessions      # persistent chat session storage

# At least one chat model
OPENAI_API_KEY=sk-...                   # enables GPT 5.4
ANTHROPIC_API_KEY=sk-ant-...            # enables Claude Opus 4.7

# Recommended
LILO_AUTH_PASSWORD=choose-a-strong-password   # locks down the whole app

See Configuration for the full list.

3. Run

pnpm run dev   # backend (http://localhost:8787) + frontend (http://localhost:5800) + typechecks

Open http://localhost:5800. If you set LILO_AUTH_PASSWORD, you'll get a login screen on first visit.

Your workspace should be auto-bootstrapped from the bundled
[workspace-template/](./workspace-template), so you'll immediately have a
Desktop, TODO list, Calories tracker, and a handful of other apps to play with.


Configuration

All env vars are read from (in order of precedence):

  1. Shell-exported variables
  2. .env.local at the repo root
  3. .env at the repo root

Core

Variable Required Default Description
LILO_WORKSPACE_DIR Directory the agent works in. Auto-bootstrapped from workspace-template/ if empty.
LILO_SESSIONS_DIR Where persistent Pi chat sessions (chats/) and app sessions (apps/) are stored.
LILO_AUTH_PASSWORD unset (open) Single-password login for the web app + all APIs + WebSockets. Leave unset for a fully open local instance.
LILO_AUTH_SESSION_SECRET LILO_AUTH_PASSWORD HMAC secret for the session cookie. Rotate to invalidate all existing sessions.
PORT 8787 Backend HTTP port.

Chat models

At least one is required to actually use Lilo.

Variable Enables
OPENAI_API_KEY GPT 5.4, GPT 5.4 Mini
ANTHROPIC_API_KEY Claude Opus 4.7

Limit the chat dropdown/API to specific models with a comma-separated allowlist:

LILO_CHAT_MODEL_ALLOWLIST=gpt-5.4-mini

Supported model ids: claude-opus-4-7, gpt-5.4, gpt-5.4-mini.

Agent tools (optional)

Each one unlocks a corresponding agent tool. Missing keys just disable the tool — the agent keeps working without them.

Variable Tool
REPLICATE_API_KEY generate_images, remove_background
LILO_DEFAULT_IMAGE_MODEL Image model — nano-banana (default), nano-banana-2, flux-2-klein-4b
FIRECRAWL_API_KEY web_search, web_scrape
BROWSERBASE_API_KEY browser_automate
BROWSERBASE_PROJECT_ID Optional project id; usually inferred

Git sync (optional)

Point WORKSPACE_GIT_URL at a git repo to make LILO_WORKSPACE_DIR git-backed on boot. If the workspace is not already a git repo, Lilo initializes one and sets origin to this URL; if it is already a repo, Lilo keeps origin in sync with this value. This keeps your workspace (apps, data, and memories) versioned and portable across hosts. The frontend shows a manual "Sync" button that runs pull/rebase and push; it expects workspace changes to be committed first. Hide it with VITE_DISABLE_WORKSPACE_SYNC when you aren't using this flow.

Variable Scope Description
WORKSPACE_GIT_URL backend Git remote to configure as origin for LILO_WORKSPACE_DIR.
VITE_DISABLE_WORKSPACE_SYNC frontend Hide the Sync button in the UI (build-time Vite flag).

Frontend observability (optional)

Set at build time — Vite only inlines VITE_* vars.

Variable Description
VITE_ENABLE_SENTRY / VITE_SENTRY_DSN Opt in to Sentry for browser errors.
VITE_ENABLE_LOGROCKET / VITE_LOGROCKET_APP_ID Opt in to LogRocket session replay.

Backend observability (optional)

Variable Default Description
ENABLE_SENTRY false Opt in to Sentry for backend errors.
SENTRY_DSN unset Backend Sentry DSN.

Workspace apps

The most distinctive thing about Lilo: the agent builds its own apps. Each app lives as a directory of HTML + assets under $LILO_WORKSPACE_DIR/, runs in a sandboxed iframe, and can read/write its own files, open chats, and make HTTP calls through a built-in window.lilo API. Ask the agent "build me a habit tracker" and it scaffolds one — no build step.

Full guide: docs/workspace-apps.md (directory layout, the window.lilo API surface, and the in-viewer element picker).


External messaging

Lilo can be an email/SMS/Telegram chatbot. Each channel is an opt-in plugin — leave its env vars unset and it's disabled.

Email (Resend)

RESEND_API_KEY=re_...
RESEND_WEBHOOK_SECRET=whsec_...
LILO_EMAIL_TO=hi@yourdomain.com        # your bot's inbound address
LILO_EMAIL_FROM="Lilo <lilo@yourdomain.com>"
EMAIL_ALLOWED_EMAILS=you@yours.com,partner@theirs.com   # allowlist
  1. Set up a receiving domain in Resend.
  2. Create a webhook pointing to https://your-lilo/api/inbound-email with the email.received event.
  3. Send Lilo an email; it replies in-thread.

Replies set Reply-To: LILO_EMAIL_TO, so the recipient's reply round-trips back into the same inbox.

WhatsApp (Twilio)

TWILIO_ACCOUNT_SID=AC...
TWILIO_AUTH_TOKEN=...
TWILIO_WHATSAPP_FROM_NUMBER=whatsapp:+15555550123
WHATSAPP_ALLOWED_FROM=whatsapp:+15555550124

Point a Twilio WhatsApp webhook at https://your-lilo/api/inbound-whatsapp.

Telegram

TELEGRAM_BOT_TOKEN=123456:ABC-...

Point your Telegram bot webhook at https://your-lilo/api/inbound-telegram.

Each contact gets their own persistent chat, so the agent remembers your conversation across messages.


Deployment

Railway (recommended)

./scripts/setup-railway.sh

The interactive setup script will:

  • Link or create a Railway project named lilo
  • Prompt for the GitHub repo to connect
  • Set core env vars
  • Mount a persistent volume at /data for LILO_WORKSPACE_DIR + LILO_SESSIONS_DIR
  • Generate a public domain on port 8080

You still configure the optional message-channel keys (Resend / Twilio /
Telegram / Firecrawl / etc.) from the Railway dashboard.


Development

pnpm run dev            # run backend + frontend + live typechecks in parallel
pnpm run dev:backend    # port 8787
pnpm run dev:frontend   # port 5800
pnpm run dev:template   # like `dev` but with LILO_WORKSPACE_DIR pointed at the bundled template (useful for trying out the default apps without polluting your own workspace)
pnpm run build          # build both packages
pnpm run lint           # oxlint across the repo
pnpm run format         # oxfmt across the repo

Contributing

This is an open source project. Issues and PRs welcome — keep components small and one-file-per-concern (see AGENTS.md).

Join us on Discord to ask questions, share workspace apps you've built, or follow development.

License

MIT