6 min read

OpenWork: An Open-Source Alternative to Claude Cowork (GitHub, Scanned)

A desktop app where AI agents work on your files with any model, as an open alternative to Claude Cowork.

OpenWork logo
✅
Scan: safe. Nothing malicious. Two things to know: the desktop app sends product analytics to PostHog until you turn them off in Settings, and its guided setup installs OpenCode by running opencode.ai's install script. Scanned Oct 3, 2026; the full report is below.

OpenWork is a desktop app for macOS, Windows and Linux in which AI agents do real work on the files on your computer, reading, writing and organizing them and carrying out multi-step tasks with skills and MCP tools. It is built on OpenCode, the open-source coding agent, and presented as an open alternative to Anthropic's Claude Cowork and OpenAI's Codex app, with the difference that you choose the model.

It works with more than 50 providers through your own API keys, a ChatGPT sign-in, or local models through Ollama and other OpenAI-compatible servers, and your files stay local unless you opt into the cloud features. Skills, Claude-compatible plugins and MCP servers carry over from a Cowork setup, and an OpenWork MCP lets you reuse the same skills from Claude Code, Codex or Cursor. For teams, a control plane called Den manages shared skills, MCP connections, model access and policies.

OpenWork is made by Different AI. The desktop app and core platform are MIT licensed, while Den, in the ee folder, is source-available and needs a subscription for production use above five users. The repository was created in January 2026 and has about 23,800 stars.

Who it is for

People who like the idea of Claude Cowork but want to use other models, local models or their existing API keys, and teams that want to share agent skills and connections across members under their own control.

Getting started

1. Download the app from openworklabs.com/download or the GitHub releases page, or build it from source (needs Node 24 and pnpm through corepack)

git clone https://github.com/different-ai/openwork.git && cd openwork && corepack enable && pnpm install && pnpm dev

2. Optional: use your OpenWork skills from Claude Code (signs you in to an OpenWork organization)

claude mcp add --transport http openwork https://api.openworklabs.com/mcp/agent

The README also suggests pasting an install prompt into an AI agent you already use, which then follows instructions fetched from openworklabs.com; installing the app yourself is the more transparent route. The OpenWork MCP is a hosted service that needs an OpenWork sign-in, whereas the desktop app needs no account to use locally.

Safety scan

We cloned different-ai/openwork at commit 29a2063 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No committed binaries across 4,456 files and about 2.1 million lines; over half of the lines are JSON data. The five secret hits are placeholders: PEM blocks in Helm and connector docs and an AKIAEV... example key in a Bedrock gateway test.
  • Pattern hits: apps/desktop/electron/runtime.mjs builds a curl https://opencode.ai/install | bash command, pinned to the OpenCode version in constants.json, for the guided engine install on macOS and Linux (it installs to ~/.opencode/bin and is refused on Windows). The others are an encoded PowerShell command in the Windows eval harness and systemctl lines in preview-environment build recipes.
  • We read the analytics code. Packaged builds send events to us.i.posthog.com unless analytics are switched off under Settings, Preferences, and every event is mirrored in a local inspector. The project publishes an outbound-network list, which says an enterprise install contacts nothing until it is linked to an organization. Cloud features talk to openworklabs.com.
  • pnpm-lock.yaml pins 1,903 packages with 58 advisories (1 critical, 28 high). The critical is a Next.js next/og bug in the Den web app under ee/, which does use next/og for its share images, so self-hosters of Den should update. Electron 43.2.0 sandbox advisories ship in the desktop app; axios, undici and nodemailer make up most of the rest.
  • 40 workflows. The three on pull_request_target check out only the base branch: jev-test-coverage-review.yml passes the PR to an AI reviewer as data using a repository secret, and the other two handle contract conflicts and reverts. Only 15 of 48 third-party actions are pinned to commits. Security policy, Dependabot, CodeQL, licence, contributing guide and code of conduct present.

What the scanner counted

CheckResult
Secrets5 candidates found and read; see the notes above.
Suspicious code5 pattern hits found and read; every one is listed under the raw findings.
Install-time code8 installer scripts (one can call sudo)
Committed binariesNone.
CI workflows40 workflows. 3 use pull_request_target, none check out the pull request head. 33 of 48 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often openworklabs.com, github.com, app.openworklabs.com, www.googleapis.com. No URLs to bare IP addresses.
Known vulnerabilities65 advisories across 2,673 pinned packages: 1 critical, 28 high, 26 moderate, 6 low, 4 unrated. .opencode/package-lock.json: 32 packages, 0 advisories; evals/pnpm-lock.yaml: 370 packages, 1 advisories; examples/microsandbox-openwork-rust/Cargo.lock: 593 packages, 6 advisories; pnpm-lock.yaml: 1,903 packages, 58 advisories.
Project hygieneHas security policy, automated dependency updates, CodeQL, licence file, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (5, redacted)
WhereRuleMatch
docs/org-install-links.md:146private-key-----B…--- (27 chars)
evals/specs/ai-gateway-bedrock-provider.e2e.test.ts:11aws-access-keyAKIAEV…EY1 (20 chars)
packages/docs/start-here/github-connector-helm.mdx:77private-key-----B…--- (27 chars)
packaging/helm/openwork-ee/README.md:802private-key-----B…--- (27 chars)
packaging/helm/openwork-ee/README.md:1183private-key-----B…--- (27 chars)
Pattern hits (5)
WhereRuleMatch
apps/desktop/electron/runtime.mjs:1811download-piped-to-shellreturn `curl -fsSL https://opencode.ai/install | bash -s -- --version ${version} --no-modify-path`;
ee/apps/den-api/src/routes/org/gateway-usage-limits.ts:40very-long-line4758 chars
evals/packages/hosts/src/windows-release.ts:25powershell-encodedreturn ["exec", sandbox, "--", `powershell -NoProfile -NonInteractive -ExecutionPolicy Bypass -EncodedCommand ${Buffer.from(script, "utf16le").toString("base64"…
packages/freestyle/src/build-recipes.ts:15persistence${world === "acme-web" ? `systemctl enable --now mysql redis-server
packages/freestyle/src/builder.ts:158persistencesystemctl enable --now openwork-preview-gateway
Installer scripts (8)
Worst known vulnerabilities (24 of 65)
AdvisorySeverityPackageSummary
GHSA-vcvr-r3jv-pc5jcriticalnext@16.3.3Next.js: Remote Code Execution in next/og ImageResponse
GHSA-m9gg-hp2v-232jhigh@grpc/grpc-js@1.14.4@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were author…
GHSA-3pq3-5fj3-cg6vhighaxios@1.18.1Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
GHSA-542g-h47m-68v8highaxios@1.18.1Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
GHSA-c29m-xwm3-cm6rhighaxios@1.18.1Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
GHSA-m8m8-qj5v-23w3highaxios@1.18.1Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
GHSA-mghh-pgcx-3jjjhighaxios@1.18.1Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
GHSA-r4gj-5m52-g5whhighaxios@1.18.1Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
GHSA-x97p-jq2g-jp4fhighaxios@1.18.1Axios: Prototype Pollution Gadget in axios toFormData Options
GHSA-6j4f-fj2g-mc7phighbrace-expansion@1.1.18brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@1.1.18brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-6j4f-fj2g-mc7phighbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-6j4f-fj2g-mc7phighbrace-expansion@5.0.9brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@5.0.9brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-9qh4-3jw8-366whighelectron@43.2.0Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
GHSA-gr2m-v5gq-v685highelectron@43.2.0Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
GHSA-j84w-jfhq-vhvjhighelectron@43.2.0Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
GHSA-qmv3-fv6v-rmhqhighelectron@43.2.0Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
GHSA-2gc4-cqfq-p2gvhighengine.io@6.6.7Socket.IO: Engine.IO Protocol Revision Mismatch DoS
GHSA-58mr-gqgx-xq4ghighfast-uri@3.1.6fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
GHSA-qw65-cvwx-89v3highfast-uri@3.1.6fast-uri vulnerable to authority injection via an unvalidated port in serialize
GHSA-ch52-4w7c-c8xphighhttp-cache-semantics@4.2.0http-cache-semantics max-stale handling can disclose cross-user cached responses
Workflows worth a look

By the numbers

Stars23.8K
Forks2,399
Contributors73
Commits5,679
Open issues286
Open pull requests309
Releases2,379
Latest releasev0.18.56
Licencecustom
Main languageTypeScript
Project age8 months
Last pushOct 3, 2026
Tracked files4,456
Lines of code2.1M
Checkout size142 MB

Lines by language: JSON 1.3M, TypeScript 686.2K, JavaScript 49.5K, Markdown 45.9K, YAML 11.2K, CSS 8,173.

Questions

Is OpenWork free?

The desktop app is MIT licensed and free, with no OpenWork account needed to use it locally; you pay only the model provider you connect, or nothing with a local model. The Den team control plane is free for organizations of up to five users and for 30-day evaluations, and needs a paid subscription for larger production use.

How is OpenWork different from Claude Cowork?

Cowork runs on Anthropic's models inside the Claude app. OpenWork is open source, built on OpenCode, and works with any of 50-plus providers or a local model. It can bring over Cowork skills, plugins and MCP servers, so switching does not mean starting again.

Do my files leave my computer?

The project says files stay local and the cloud features are optional. What does leave is whatever the agent sends to your chosen model provider as context, plus product analytics, which the desktop app sends to PostHog until you switch them off in Settings. Use a local model through Ollama if the files must stay on the machine entirely.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.