惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security @ Cisco Blogs
罗磊的独立博客
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
美团技术团队
T
Tailwind CSS Blog
博客园 - 三生石上(FineUI控件)
博客园 - Franky
G
Google Developers Blog
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
Visual Studio Blog
腾讯CDC
S
SegmentFault 最新的问题
Recent Announcements
Recent Announcements
博客园 - 叶小钗
Microsoft Security Blog
Microsoft Security Blog
雷峰网
雷峰网
L
LangChain Blog
Vercel News
Vercel News
Forbes - Security
Forbes - Security
PCI Perspectives
PCI Perspectives
N
News | PayPal Newsroom
S
Security Affairs
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
博客园 - 司徒正美
J
Java Code Geeks
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Hacker News: Ask HN
Hacker News: Ask HN
Schneier on Security
Schneier on Security
A
About on SuperTechFans
Attack and Defense Labs
Attack and Defense Labs
Google Online Security Blog
Google Online Security Blog
aimingoo的专栏
aimingoo的专栏
MongoDB | Blog
MongoDB | Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
Cloudbric
Cloudbric
B
Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Proofpoint News Feed
D
DataBreaches.Net
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
B
Blog RSS Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
N
News and Events Feed by Topic

Hacker News

GitHub - ronak-create/FableCut: Zero-dependency browser video editor that AI agents can drive — JSON timeline, MCP + REST, live-reloading UI GitHub - BuceaGeorgia/VIRENA: A minimal Vision-Language-Action model you can read: frozen CLIP + a tiny head on ManiSkill PickCube. Runs on a Mac, no GPU. Fehu - Apps on Google Play GitHub - fresswolf/Slopera: The browser for the slop era Release Kiyeovo 1.0.0 · Realman78/Kiyeovo Noema — AI Company Analysis GitHub - hamidi-dev/opentab: 📊 Browse your AI coding spend in the terminal — OpenCode, Claude Code, Codex & more GitHub - sgInnora/wc2026-prediction-ledger: Receipt-verified AI prediction ledger for World Cup 2026: pre-kickoff sha256-locked forecasts scored vs results, with calibration + market baselines. Live: goalpulse.io/open-data GitHub - michaelwrites67-ctrl/yogen: 予言 Yogen — a 500-agent AI swarm that debates your idea and predicts the outcome. Self-host free with your own Anthropic key. GitHub - teddytennant/wizard: Self-extending autonomous agent in one Rust binary. One-line install, any provider (OpenAI-compatible, Anthropic, xAI) or fully local via llama.cpp, live /evolve self-modification, MCP, messaging gateway, built-in bench arcaide.foo Show HN: Android Developer Verification Package blacklisted in Aurora Store OpenDescent: Private messaging for normal people GitHub - tarunlnmiit/autopilot-jobhunt: AI job agent: scans 130+ careers pages nightly, scores every role against your resume with an LLM (0–100), alerts you on Telegram, and drafts tailored cover letters + resumes. Free & open source. 18 Words - Daily Word Challenge The State of US Local Government Accessibility 2026 flow - Real-time network throughput dashboard for the terminal. - Terminal Trove Battle LLM Robots GitHub - robesris/ffvii-realtime: Speed up Final Fantasy VII (Rebirth / Remake / Revelation) Tactical Mode slow-motion so combat plays at real-time speed Agent Sessions - Local History for AI Coding Agents Scrutora — code, cloud & consent compliance in one platform SoulOS Tutorials GitHub - gaemi/agentic-fc: Open-source football management simulation played by AI agents through MCP and watched through a TUI console. GitHub - talalalrwas/ocr-grab: Flameshot clone that adds OCR. GitHub - saifmukhtar/kinetic figment computer linear.gratis - Free Linear Client Feedback Forms GitHub - atelier-ws/atelier: Runtime for coding agents. Models are getting smarter, but a model is only as capable as the environment supporting it. Atelier is that environment. https://atelier.ws Atlas · Tomesphere | Tomesphere Codenames Generator GitHub - lyfeninja/lyfeninja_blkseal_python_sdk: Lightweight Python client for signing and verifying digital content using lyfe.ninja's BlkSeal product powered by BlkBolt™. Designed for zero dependencies, simple integration, and exact content verification. DateTimeMate OpenScreenShot — Full-page screenshot & annotation tool for Chrome 38-0 — Build Your Premier League Dream Team Cyrinx — data over sound, measured GitHub - BhaveshThapar/mcp-audit Probed — Talk to Your People HN Work GitHub - Northwood-Systems/foreman: Self-hosted LLM gateway. Cost effective, deterministic, and fast. Secure and private by default. A Visualization Language for the AI Era GitHub - weirdGuy/kastor: Declarative language and toolchain for AI agents: define agents, tools and prompts in HCL, then compile to frameworks or manage them on hosted platforms with plan/apply semantics. Abralo - Run multiple Claude Code agents in one window GitHub - mehranzand/repofleet: RepoFleet is an issue-centered CLI tool for managing Git workflows across multiple repositories. GitHub - exmergo/dex: Dex is the agent-native analytics engineering toolkit. Point it at your warehouse and your dbt project. It learns the landscape, authors your transformations, and tells you exactly what to fix when the schema drifts. Built for analytics engineers and data engineers who want more out of their coding agent. Pug — Open Source Product Analytics GitHub - instavm/tarit: A hypervisor and sandbox cloud for self-hosted AI agents and RL Chiptune Radio — Aleph Void, LLC Free Mermaid Live Editor & Diagram Maker GitHub - Salnika/dejavu: Stop showing coding agents the same command output twice. GitHub - hirasso/html-obfuscator: Obfuscate emails, phone numbers, and other sensitive data in PHP. Invisible to humans, hidden from bots until they interact. Davit — a native macOS UI for Apple containers Fenzo AI - The perfect course, every time. HTML Drive — Edit and Publish HTML from Google Drive GitHub - rowboatlabs/rowboat: Open-source AI coworker, with memory ZeroGate | Automated Cluster Scaling A tiny scale-free kernel language — Joa Ebert GitHub - arman-jalili/guardian-framework: Architecture Enforcement Framework for AI-Assisted Development Yamanote.fun PostgreSQL on AWS: Size & Benchmark EC2 Instances GitHub - Rodiun/frugon: Free, local, open-source LLM cost analyzer — see where your LLM bill leaks, on your machine. Artificiety — A Fantasy World for AI Agents Ex Situ FlexInference: Drop your AI costs today WhimFiles - Find Any File in Seconds GitHub - josephsenior/Grinta-Coding-Agent: Local-first autonomous coding agent that plans, executes, validates, and finishes software tasks end-to-end. Nectar — The Web Without JavaScript Agent Draw: An agent draws while you talk, built on TLDraw Captchainbox - Make senders work to get into your inbox GitBiased — your whole engineering org, on one calm dashboard Neil the Seal GitHub - animesh-94/Onboard-CLI: An AST-powered, local-first CLI that visualizes complex system architectures and enforces architectural boundaries via instant Git hooks. ridealong — live London trains GitHub - rubix-studios-pty-ltd/rubix-redis-bridge: Secure production-hardened Rust HTTP bridge for Redis with Upstash-style API compatibility, command allowlisting, hard-denied dangerous Redis commands, Docker deployment, and SDK compatibility tests. Chauffeur – Deine Arbeitsumgebung mit einem Klick zurück Clusy | Agent-Native Notebook for ML and Data Science GitHub - therepanic/openleetcode: we have democratized the LeetCode tests Habit Pocket — your good days aren’t random GitHub - dogtorjonah/context-warp-drive See what your community is paying attention to. GitHub - puffinsoft/peek-cli: Let coding agents see your browser. GitHub - vicmaster/framesmith: Open-source MCP server that gives AI assistants a visual design canvas, rendering HTML/CSS scene graphs to PNG via headless Chromium. GitHub - gojargo/jargo: A WebRTC-native, audio-first conversational-AI framework for Go. snowscroll · Instagram, without the spiral. The Tree of "Tree" GitHub - Arthur-Ficial/translate: On-device translator for macOS Tahoe — UNIX filter + drop-in HTTP server compatible with DeepL, LibreTranslate, and Google v2. 100% on-device, no cloud, no LLM, no API keys. GitHub - palmier-io/palmier-pro: macOS video editor built for AI The New Wave of Remote Work: An Async-First Job Board GitHub - agenthatch/agenthatch: Where agents hatch. pacwich — Monorepo tooling for Bun, npm, and pnpm workspaces | Documentation GitHub - openwong2kim/wmux: Windows tmux alternative for AI agents — split terminals for Claude Code, Codex, Gemini CLI with MCP browser automation. No WSL required. GitHub - loopgain-ai/loopgain: An open-source cost controller for AI agent loops — stops a loop when it's actually converged and rolls back before it degrades, instead of running to a fixed max_iterations cap. Real-time loop-gain (Aβ) bands + best-so-far rollback. Adapters for LangGraph, CrewAI, AutoGen, LangChain, OpenAI Agents, and Claude Agent SDK; raw API for custom stacks. GitHub - vishal-dehurdle/state-harness: Runtime safety net for LLM agents. Detects token spirals, kills doomed tasks early, tells you exactly why. Rust core, Python SDK. pip install state-harness GitHub - the0cp/pico: A small, compact, register-based scripting language and virtual machine implemented in C. Inspired by clox. GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. GitHub - pileax-ai/pileax: PileaX is an all-in-one AI knowledge base system. 🍀 GitHub - DO-SAY-GO/freelang: I love freelang GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland
GitHub - khalid-src/corv-client: Corv Client is an SSH client for AI agents and humans.
khalid_0002 · 2026-06-27 · via Hacker News

Corv Client

The SSH client for AI agents and humans. Connect by name. Reuse authenticated SSH connections. Keep secrets local.

AI agents don't use SSH the way humans do. Plain SSH exposes credentials to the caller, returns terminal text that agents must parse, re-authenticates every command, and relies on tmux, nohup, or custom scripts for long-running tasks.

Corv is built for agent-driven infrastructure. It lets agents connect by name, execute commands without exposing passwords or private keys, receive structured JSON output, reuse a warm authenticated connection, and detach and resume long-running jobs. Humans use the exact same connections through an interactive terminal UI.

Install

Linux / macOS

curl -fsSL https://raw.githubusercontent.com/khalid-src/corv-client/main/install.sh | sh

Windows (PowerShell)

irm https://raw.githubusercontent.com/khalid-src/corv-client/main/install.ps1 | iex

With Go

go install github.com/khalid-src/corv-client/cmd/corv@latest

Update or remove

corv update      # download and install the latest release (checksum-verified)
corv uninstall   # remove corv; add --purge to also delete saved connections

corv update only runs when you run it - Corv never updates itself in the background.

Usage

Corv Client - an AI agent and a human both driving the same connection

Manage connections interactively:

The terminal interface supports keyboard and mouse navigation to add, edit, import from ~/.ssh/config, and connect. Connections can also be managed from the command line:

corv add srv-01 ubuntu@10.0.0.4                      # prompts for a password if needed
corv add srv-01 ubuntu@10.0.0.4 --key ~/.ssh/id_ed25519
corv add db-01 ubuntu@10.0.0.9 --jump ubuntu@bastion # reach through a bastion
corv import                                          # import hosts from ~/.ssh/config
corv list
corv rm srv-01

Hosts behind one or more bastions are reached with --jump (OpenSSH -J syntax: user@host1,user@host2). Jump hosts authenticate with ssh-agent or your keys; the target uses the connection's own credentials.

corv add reads any password without echo and stores it in the local encrypted vault; it is never passed as an argument.

Connect interactively:

Run a command non-interactively (the agent path):

corv srv-01 -- systemctl restart api
corv srv-01 --json -- df -h              # structured output for tools
corv srv-01 -- ./deploy.sh
echo 'cd /app && run "$X" | grep foo' | corv srv-01 --json --stdin
corv srv-01 --json --stdin < script.sh

A typical agent instruction such as "restart the API service on srv-01" requires only corv srv-01 -- systemctl restart api.

Command handling after -- is designed to do what you mean:

  • a single argument is treated as a remote shell command line and run as-is, like ssh host "cmd" - e.g. corv srv -- "cd /app && make";
  • multiple arguments are passed as a preserved argument vector, each shell-quoted so the remote cannot re-split them - e.g. corv srv -- sh -lc "cd /app && make".

This avoids the raw-ssh pitfall where quoted arguments lose their boundaries, which matters for agents that build argument vectors.

For complex shell text, nested quotes, or multi-line scripts, use an stdin mode. --stdin-base64 is the cross-shell-safe option because only ASCII base64 passes through the local pipe.

Windows / PowerShell

PowerShell can mangle quoting and pipe encoding, so encode a non-trivial remote command as UTF-8 base64 and send it with --stdin-base64:

$b64=[Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes(@'
set -eu
cd /srv/app && ./deploy.sh
'@)); $b64 | corv srv-01 --json --stdin-base64

Only ASCII base64 crosses the pipe, so the command arrives unchanged - quoting and any non-ASCII text survive intact. A simple exact argument vector can still use -- <command>.

Long commands are detached on the server automatically. If a command is still running after the broker's wait window, Corv returns the new bounded output, the run id, and exit code 75. Re-run the exact same command to watch the next delta; it attaches to the existing remote job and does not start a second copy. When the job finishes, Corv saves the log locally (up to 20 MiB; a larger log is truncated, with a marker and a truncated flag in corv output --json) and removes the remote temporary files:

corv srv-01 -- ./long-install.sh
corv srv-01 -- ./long-install.sh       # same command: continue watching
corv output <run-id>                   # finalize if done, then show the saved log

CORV_WAIT controls how long the broker waits before returning a running response. It accepts bare seconds (CORV_WAIT=30) or a Go duration (CORV_WAIT=500ms, CORV_WAIT=2m) and is read from the environment of each corv invocation, so it takes effect immediately without restarting the broker. corv output <run-id> checks an unfinished detached run and finalizes it automatically once the remote exit status exists. Remote temp files are cleaned on finalization; abandoned jobs are cleaned by the broker's startup sweep after 24 hours.

Remote command execution requires a POSIX shell and standard Unix command-line tools. Windows OpenSSH servers are not supported as remote execution targets.

Use with AI agents

Corv is built for AI coding agents (Claude, Codex, and others). Ready-to-use agent instructions live in integrations/:

  • Claude / Claude Code - copy integrations/claude/corv-ssh into ~/.claude/skills/ (or a project's .claude/skills/).
  • Codex - copy integrations/codex/AGENTS.md into your project.

The agent then runs commands by name and reads structured output:

corv <name> --json -- <command>

For non-trivial scripts or heavily quoted commands, agents should send the remote command as UTF-8 base64:

$b64=[Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes(@'
set -eu
cd /srv/app && ./deploy.sh
'@)); $b64 | corv <name> --json --stdin-base64

Agents should not run corv list --full or corv doctor --full unless the user explicitly asks; those modes show local connection details. Never put passwords, private keys, API tokens, kubeadm tokens, bearer tokens, or other secrets on the command line. Corv command history records command lines.

See integrations/README.md for details.

Connection reuse

A local broker process holds one authenticated SSH connection per machine. Each corv <name> -- <cmd> runs as a new channel over the held connection, so the connection and authentication cost is paid once rather than on every command. This behaviour is identical on Linux, macOS, and Windows.

The broker starts automatically on first use, exits after 15 minutes idle, and installs nothing on the server. It manages SSH connections only; it does not allocate a local pseudo-terminal, parse shell output, or maintain remote shell state. A held connection can be dropped explicitly:

Scope and limitations:

  • This is connection reuse, not remote session persistence. Each command runs in its own shell with its own exit code; shell state such as the working directory does not carry between commands (combine them in a single command when required, e.g. cd /app && make).
  • Because the broker is local, a held connection does not survive the local machine sleeping or a network interruption. Persistence across those events requires remote support, which Corv does not depend on by design.

Interactive sessions open a dedicated connection and proxy the remote pseudo-terminal to the local terminal, so no local pseudo-terminal is required on any platform.

Output processing

Corv normalises command output for programmatic consumers:

  • progress bars and other carriage-return redraws are collapsed to their final state rather than reproduced as thousands of lines;
  • ANSI control sequences, including colour, are removed;
  • a command's stdout and stderr are captured together, interleaved in the order they were written, and returned in stdout; with --json, the stderr field carries Corv-level errors (e.g. transport failures), not the remote command's own stderr;
  • a finished command returns its output in full up to a generous byte budget; only genuinely large output is trimmed to a leading and trailing section with a ... N line(s) hidden ... marker (the saved log, up to 20 MiB, stays available via corv output <run-id>), and a still-running command returns a short peek;
  • transport failures are classified (auth_failed, unknown_host, unreachable, host_key, timeout, disconnected), and the remote exit code is propagated as the process exit code.

Security model

Corv runs entirely on the client and implements SSH through the maintained Go SSH library (golang.org/x/crypto/ssh).

  • Nothing is installed on the destination server.
  • Connection profiles are encrypted at rest with the OS-protected vault key, so the connection file does not expose hosts, users, or paths in plaintext (corv list is the way to view them).
  • Passwords and key passphrases are stored in a local encrypted vault. The vault key is protected by DPAPI on Windows; on macOS and Linux Corv reads a provisioned Keychain / Secret Service key when present (it never auto-creates one) and otherwise uses a 0600 key file, the default. Stored secrets are read only by the local broker and sent over the authenticated SSH connection; they do not appear on a command line, in logs, or in command output. Key-based authentication or ssh-agent is recommended.
  • Audit logs and saved run logs are local and can contain the command text or remote output an operator asked Corv to run. Never put passwords, private keys, API tokens, kubeadm tokens, bearer tokens, or other secrets on the command line; command history records command lines.
  • Authentication is attempted in order: configured identity file, ssh-agent (via SSH_AUTH_SOCK on Unix, the openssh-ssh-agent named pipe on Windows), default ~/.ssh keys, then password.
  • Bastion (ProxyJump) hops are host-key verified individually and can authenticate with ssh-agent, default keys, a per-hop identity file, or a password/passphrase sourced from a saved profile.
  • Host keys are verified against ~/.ssh/known_hosts. An unknown host is rejected unless approved interactively; the broker never accepts unknown hosts automatically. A changed host key is always rejected.
  • The broker uses OS-permissioned local IPC (Unix socket or Windows named pipe) plus an endpoint token for defense in depth.

Architecture

Corv is composed of small, independent modules so that the SSH backend or the output processor can be replaced without affecting the rest:

Package Responsibility
internal/profile connection definitions, storage, ~/.ssh/config import
internal/vault local encrypted secret store (DPAPI / key file)
internal/sshconn SSH transport (x/crypto/ssh): dial, auth, exec, shell
internal/broker resident process holding one connection per host
internal/output output processor (collapse, strip, bound)
internal/audit local command history
internal/tui interactive terminal UI (Bubble Tea)
internal/cli command-line routing
internal/paths on-disk file locations

Development

make vet         # go vet ./...
make build       # build ./bin/corv
make build-all   # cross-compile linux/macOS/windows

Corv targets Go 1.25+ on Linux, macOS, and Windows.

License

See LICENSE.

Acknowledgments

Built with the assistance of AI coding tools: Claude Opus 4.8 and GPT-5.5.