OpenWork is a desktop app for macOS, Windows and Linux in which AI agents do real work on the files on your computer, reading, writing and organizing them and carrying out multi-step tasks with skills and MCP tools. It is built on OpenCode, the open-source coding agent, and presented as an open alternative to Anthropic's Claude Cowork and OpenAI's Codex app, with the difference that you choose the model.
It works with more than 50 providers through your own API keys, a ChatGPT sign-in, or local models through Ollama and other OpenAI-compatible servers, and your files stay local unless you opt into the cloud features. Skills, Claude-compatible plugins and MCP servers carry over from a Cowork setup, and an OpenWork MCP lets you reuse the same skills from Claude Code, Codex or Cursor. For teams, a control plane called Den manages shared skills, MCP connections, model access and policies.
OpenWork is made by Different AI. The desktop app and core platform are MIT licensed, while Den, in the ee folder, is source-available and needs a subscription for production use above five users. The repository was created in January 2026 and has about 23,800 stars.
- Repository: github.com/different-ai/openwork
- Licence: custom (Other)
- Language: TypeScript. Stars: 23.8K. Forks: 2,399. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit 29a2063
Who it is for
People who like the idea of Claude Cowork but want to use other models, local models or their existing API keys, and teams that want to share agent skills and connections across members under their own control.
Getting started
1. Download the app from openworklabs.com/download or the GitHub releases page, or build it from source (needs Node 24 and pnpm through corepack)
git clone https://github.com/different-ai/openwork.git && cd openwork && corepack enable && pnpm install && pnpm dev2. Optional: use your OpenWork skills from Claude Code (signs you in to an OpenWork organization)
claude mcp add --transport http openwork https://api.openworklabs.com/mcp/agentThe README also suggests pasting an install prompt into an AI agent you already use, which then follows instructions fetched from openworklabs.com; installing the app yourself is the more transparent route. The OpenWork MCP is a hosted service that needs an OpenWork sign-in, whereas the desktop app needs no account to use locally.
Safety scan
We cloned different-ai/openwork at commit 29a2063 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No committed binaries across 4,456 files and about 2.1 million lines; over half of the lines are JSON data. The five secret hits are placeholders: PEM blocks in Helm and connector docs and an AKIAEV... example key in a Bedrock gateway test.
- Pattern hits: apps/desktop/electron/runtime.mjs builds a curl https://opencode.ai/install | bash command, pinned to the OpenCode version in constants.json, for the guided engine install on macOS and Linux (it installs to ~/.opencode/bin and is refused on Windows). The others are an encoded PowerShell command in the Windows eval harness and systemctl lines in preview-environment build recipes.
- We read the analytics code. Packaged builds send events to us.i.posthog.com unless analytics are switched off under Settings, Preferences, and every event is mirrored in a local inspector. The project publishes an outbound-network list, which says an enterprise install contacts nothing until it is linked to an organization. Cloud features talk to openworklabs.com.
- pnpm-lock.yaml pins 1,903 packages with 58 advisories (1 critical, 28 high). The critical is a Next.js next/og bug in the Den web app under ee/, which does use next/og for its share images, so self-hosters of Den should update. Electron 43.2.0 sandbox advisories ship in the desktop app; axios, undici and nodemailer make up most of the rest.
- 40 workflows. The three on pull_request_target check out only the base branch: jev-test-coverage-review.yml passes the PR to an AI reviewer as data using a repository secret, and the other two handle contract conflicts and reverts. Only 15 of 48 third-party actions are pinned to commits. Security policy, Dependabot, CodeQL, licence, contributing guide and code of conduct present.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 5 candidates found and read; see the notes above. |
| Suspicious code | 5 pattern hits found and read; every one is listed under the raw findings. |
| Install-time code | 8 installer scripts (one can call sudo) |
| Committed binaries | None. |
| CI workflows | 40 workflows. 3 use pull_request_target, none check out the pull request head. 33 of 48 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often openworklabs.com, github.com, app.openworklabs.com, www.googleapis.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 65 advisories across 2,673 pinned packages: 1 critical, 28 high, 26 moderate, 6 low, 4 unrated. .opencode/package-lock.json: 32 packages, 0 advisories; evals/pnpm-lock.yaml: 370 packages, 1 advisories; examples/microsandbox-openwork-rust/Cargo.lock: 593 packages, 6 advisories; pnpm-lock.yaml: 1,903 packages, 58 advisories. |
| Project hygiene | Has security policy, automated dependency updates, CodeQL, licence file, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (5, redacted)
| Where | Rule | Match |
|---|---|---|
| docs/org-install-links.md:146 | private-key | -----B…--- (27 chars) |
| evals/specs/ai-gateway-bedrock-provider.e2e.test.ts:11 | aws-access-key | AKIAEV…EY1 (20 chars) |
| packages/docs/start-here/github-connector-helm.mdx:77 | private-key | -----B…--- (27 chars) |
| packaging/helm/openwork-ee/README.md:802 | private-key | -----B…--- (27 chars) |
| packaging/helm/openwork-ee/README.md:1183 | private-key | -----B…--- (27 chars) |
Pattern hits (5)
| Where | Rule | Match |
|---|---|---|
| apps/desktop/electron/runtime.mjs:1811 | download-piped-to-shell | return `curl -fsSL https://opencode.ai/install | bash -s -- --version ${version} --no-modify-path`; |
| ee/apps/den-api/src/routes/org/gateway-usage-limits.ts:40 | very-long-line | 4758 chars |
| evals/packages/hosts/src/windows-release.ts:25 | powershell-encoded | return ["exec", sandbox, "--", `powershell -NoProfile -NonInteractive -ExecutionPolicy Bypass -EncodedCommand ${Buffer.from(script, "utf16le").toString("base64"… |
| packages/freestyle/src/build-recipes.ts:15 | persistence | ${world === "acme-web" ? `systemctl enable --now mysql redis-server |
| packages/freestyle/src/builder.ts:158 | persistence | systemctl enable --now openwork-preview-gateway |
Installer scripts (8)
- .devcontainer/setup-daytona-secrets-volume.sh, 103 lines
- .devcontainer/start-daytona-electron.sh, 87 lines
- .devcontainer/start-daytona-recording.sh, 97 lines
- .devcontainer/start-daytona-server.sh, 359 lines, uses sudo; talks to workers.local
- .devcontainer/start-daytona-vnc.sh, 42 lines
- .devcontainer/start-services.sh, 87 lines
- .github/actions/setup-browser/setup.sh, 44 lines, uses sudo; talks to dl.google.com
- scripts/support/setup-openwork-tls-repro.ps1, 395 lines
Worst known vulnerabilities (24 of 65)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-vcvr-r3jv-pc5j | critical | next@16.3.3 | Next.js: Remote Code Execution in next/og ImageResponse |
| GHSA-m9gg-hp2v-232j | high | @grpc/grpc-js@1.14.4 | @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were author… |
| GHSA-3pq3-5fj3-cg6v | high | axios@1.18.1 | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| GHSA-542g-h47m-68v8 | high | axios@1.18.1 | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization |
| GHSA-c29m-xwm3-cm6r | high | axios@1.18.1 | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| GHSA-m8m8-qj5v-23w3 | high | axios@1.18.1 | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection |
| GHSA-mghh-pgcx-3jjj | high | axios@1.18.1 | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location |
| GHSA-r4gj-5m52-g5wh | high | axios@1.18.1 | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF |
| GHSA-x97p-jq2g-jp4f | high | axios@1.18.1 | Axios: Prototype Pollution Gadget in axios toFormData Options |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@1.1.18 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@1.1.18 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@2.1.4 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@2.1.4 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@5.0.9 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@5.0.9 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-9qh4-3jw8-366w | high | electron@43.2.0 | Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions |
| GHSA-gr2m-v5gq-v685 | high | electron@43.2.0 | Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions |
| GHSA-j84w-jfhq-vhvj | high | electron@43.2.0 | Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled |
| GHSA-qmv3-fv6v-rmhq | high | electron@43.2.0 | Electron: Sandboxed preload code cache can be poisoned by a compromised renderer |
| GHSA-2gc4-cqfq-p2gv | high | engine.io@6.6.7 | Socket.IO: Engine.IO Protocol Revision Mismatch DoS |
| GHSA-58mr-gqgx-xq4g | high | fast-uri@3.1.6 | fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority |
| GHSA-qw65-cvwx-89v3 | high | fast-uri@3.1.6 | fast-uri vulnerable to authority injection via an unvalidated port in serialize |
| GHSA-ch52-4w7c-c8xp | high | http-cache-semantics@4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses |
Workflows worth a look
- .github/workflows/den-contract-conflicts.yml: pull_request_target
- .github/workflows/jev-test-coverage-review.yml: pull_request_target
- .github/workflows/revert-fastlane.yml: pull_request_target
By the numbers
| Stars | 23.8K |
|---|---|
| Forks | 2,399 |
| Contributors | 73 |
| Commits | 5,679 |
| Open issues | 286 |
| Open pull requests | 309 |
| Releases | 2,379 |
| Latest release | v0.18.56 |
| Licence | custom |
| Main language | TypeScript |
| Project age | 8 months |
| Last push | Oct 3, 2026 |
| Tracked files | 4,456 |
| Lines of code | 2.1M |
| Checkout size | 142 MB |
Lines by language: JSON 1.3M, TypeScript 686.2K, JavaScript 49.5K, Markdown 45.9K, YAML 11.2K, CSS 8,173.
Questions
Is OpenWork free?
The desktop app is MIT licensed and free, with no OpenWork account needed to use it locally; you pay only the model provider you connect, or nothing with a local model. The Den team control plane is free for organizations of up to five users and for 30-day evaluations, and needs a paid subscription for larger production use.
How is OpenWork different from Claude Cowork?
Cowork runs on Anthropic's models inside the Claude app. OpenWork is open source, built on OpenCode, and works with any of 50-plus providers or a local model. It can bring over Cowork skills, plugins and MCP servers, so switching does not mean starting again.
Do my files leave my computer?
The project says files stay local and the cloud features are optional. What does leave is whatever the agent sends to your chosen model provider as context, plus product analytics, which the desktop app sends to PostHog until you switch them off in Settings. Use a local model through Ollama if the files must stay on the machine entirely.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
