This article introduces 'Agent + Skill Store', a local AI agent tool that runs on your machine with a headless browser, sandboxed shell execution, and a plugin system for adding skills without cloud dependencies.
Hey folks, I've been working on this for a while and finally got it to a state I'm happy sharing. It's called Agent + Skill Store — a local AI agent that runs on your machine, drives a real headless browser, executes shell commands in a sandbox, and loads capabilities as drop-in "skills". Install is just: pip install agent-code Then agent-code to launch. Python 3.10+. What it does: Headless Chromium (DrissionPage) — no popup window, real JS rendering Sandboxed shell — allowlist + workspace jail, no pipes or path escapes Skills are folders: skills/my_skill/skill.py + skill.md, restart, done Stop/Continue buttons — halt mid-turn, resume from the last tool result Any OpenAI-compatible API — OpenAI, Together, Groq, DeepSeek, or local vLLM Multi-key rotation if you have several API keys Chat auto-save locally + optional cloud sync Bundled skills: filesystem, public_api (700+ free APIs), temp_mail Why I built it: I wanted an agent I could actually see what it was doing. Most of the existing ones hide everything behind a cloud service or open a separate browser window. This one has the browser headless and a chat GUI where you can watch every tool call as it happens. The skill system is the part I'm most happy with. Adding a capability is just dropping a folder in skills/ — no changes to the agent source. Each skill exports a few plain Python things: ```python SKILL = {"name": "greet", "description": "Say hello."} def hello(name: str = "world") -> str: return f"Hello, {name}!" TOOL_SCHEMAS = [{ "type": "function", "function": { "name": "hello", "description": "Return a greeting.", "parameters": { "type": "object", "properties": {"name": {"type": "string"}}, }, }, }] TOOL_CALLABLES = {"hello": hello} ``` Restart, and the LLM can call it. There's also a COMMANDS dict for user-facing slash commands like /email or /ping. Skill registry: There's a small registry server (self-hosted, GPL-3.0) where you can publish skills and install them from a GUI. Live instance is at skills-manager.freesrv.com — the client points there by default. You can also self-host it. Security notes (because this matters): The agent executes LLM-generated commands. I've sandboxed what I could — shell allowlist, workspace jail, no shell metacharacters, path validation in the filesystem skill, PBKDF2 on the registry server — but two things to know before running it: python and curl are in the shell allowlist. If you don't want the agent to touch arbitrary files or POST data to remote servers, remove them from ALLOWED_CMDS. Skills are arbitrary Python. Installing one is trusting its author. For truly untrusted use, run the whole thing in Docker. License: MIT for the client, GPL-3.0 for the server. Feedback welcome. Especially interested in: Whether the sandbox rules feel too tight or too loose for your use case What skills you'd want to see bundled next Any Linux distro where the GUI doesn't work Happy to answer questions.
AgentBuddy is a local-first, open-source AI workflow sandbox that enables persistent agent threads, real-time execution traces, and event-driven workflows, with Claude Code integration, aiming to keep AI development local and transparent.
Browser Use describes two patterns for isolating AI agents that execute code: isolating the tool vs isolating the agent. They implemented the agent isolation pattern using Unikraft micro-VMs on AWS, achieving secure, scalable, and disposable sandboxes.
AgentSkillOS is an open-source framework that enables developers to build AI agents by retrieving and orchestrating pipelines from over 200,000 available skills.
Google Cloud's Agent Plugin lets developers package skills, MCP servers, and tools into a single portable folder, enabling build-once-use-everywhere workflows for AI agents.
Skillerr is a tool that enables running AI agent skills safely and with full inspectability, addressing the risk of executing unknown code from third-party skills.