Automate — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Automate (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A smart NAS for AI. Notes · files · reminders · memory · 40+ tools. Plug it into OpenClaw / Claude Desktop / Cursor / Cline as a tool source, or use it standalone via its built-in web chat.
┌─ OpenClaw ─────┐ ┌─ notes / memory ── survives every chat
├─ Claude Desktop├──── MCP ────┐ ├─ files ─────────── your file vault (NAS)
├─ Cursor / Cline├──── HTTP ───┤ ├─ reminders ─────── push to your phone
├─ Kimi / GPT ├──── bridge ─┤ ├─ memory ────────── cross-session facts
└─ your scripts ┘ │ ├─ search.find ───── BM25 over notes+files
▼ │
┌──────────────────┐ ┌─ shell · script · browser
│ autoMate │ ── ┤ desktop · 31 SaaS APIs
│ (your machine) │ └─ your real Chrome (extension)
└────────┬─────────┘
▼
~/.automate/ · SQLite + FernetEvery AI vendor wants to be your chat tool. Most can call tools. None of them remember anything across vendors, store your files, or ping your phone when something matters.
autoMate is the layer behind the chat: a warehouse you own. Pick a chat client you like (OpenClaw for IM, Claude Desktop for serious work, Cursor for code), point it at autoMate via MCP, and that client can write into your notes, drop files, schedule reminders, search your library, and call your real-world tools — and tomorrow's client can read all of it back the same way.
| Mode | Who's the brain | When |
|---|---|---|
| As a tool inside another AI client | Your client (OpenClaw / Claude / Cursor / ...) | Most use cases — IM, coding, research |
| Standalone via autoMate's web chat | autoMate's own agent loop | Quick local queries, no other client |
Same backend. Same data. Pick the entry point.
After install, open Settings → Connect to AI clients and click "Copy install text". You get a single markdown blob with the URL + token already filled in, and per-client sections for OpenClaw, Claude Desktop, Cursor, Cline, generic MCP, and non-MCP gateways.
Three ways to use it:
for me." The text is written so an AI reader can find the right section and edit the right config.
bundle-mcp — the section spells it out.
After the client picks up the new server, it gets all autoMate's tools (search.find, notes.read, files.list, audio.transcribe, ...) plus a top-level automate tool that runs autoMate's own agent loop on demand.
See docs/channels.md for details.
| Path | Get | When |
|---|---|---|
pip install automate-hub | Python package | Have Python, want it small |
| Standalone binary (Win / macOS / Linux) | Releases | No Python, double-click |
| Docker | docker run -p 8765:8765 ghcr.io/yuruotong1/automate:latest | Headless box / NAS |
| Browser extension | extension/ | Drive your real Chrome |
| Android APK | Releases | Optional viewer for the hub |
After install:
automate # double-click on Windows/macOS does the same thingBrowser opens to http://127.0.0.1:8765. The wizard walks you through picking a model, pasting a key, and (optionally) wiring up an AI client.
Personal data
notes.* — markdown documents with tags, search, pinningfiles.* — content-addressed blob vault, deduplication, configurable storage path (point it at an external SSD or NAS mount)search.find — Coze-style hybrid retrieval (SQLite FTS5 BM25) across notes + files in one callreminders.* — scheduler thread fires Web Push to your PWAmemory.* — long-term key-value facts that any AI can read/writeaudio.transcribe — voice → text via Tencent ASR / OpenAI Whisper, with custom vocabulary mined from your notes (Pro tier)Local executors
shell.*, script.* (Python/Bash/Node), desktop.* (pyautogui)browser.* (Playwright, fresh Chromium tab)bx.* (your real browser via the Chrome extension)SaaS integrations — 31 platforms: GitHub · GitLab · Gitee · Notion · Slack · Linear · Jira · Confluence · Trello · Asana · Monday.com · HubSpot · Airtable · Stripe · Shopify · Telegram · Discord · MS Teams · Zoom · Twitter/X · SendGrid · Mailchimp · Twilio · Sentry · 飞书 · 钉钉 · 企业微信 · 微信公众号 · 微博 · 语雀 · 高德地图.
LLM providers — 25 in the catalog: OpenAI · Anthropic · Gemini · xAI Grok · Mistral · Cohere · OpenRouter · Groq · Together · Fireworks · DeepInfra · DeepSeek · Moonshot Kimi · 通义 · 豆包 · GLM · 百川 · Yi · MiniMax · 阶跃 · 混元 · 硅基流动 · Ollama · LM Studio · any OpenAI-compatible.
We don't ship per-platform bots ourselves. Run OpenClaw alongside autoMate — it has the official Tencent WeChat plugin for 微信个人助手 (no account-takeover, no ban risk), plus Telegram / WhatsApp / Slack / Discord / Signal / iMessage. autoMate plugs in as its tool source via the MCP setup above. The user talks in their chat platform → OpenClaw routes → OpenClaw's agent calls autoMate when it needs your data.
The legacy bots in automate/bots/ (telegram / wechat_oa / wecom) are frozen but still ship for backward compatibility.
autoMate/
├─ automate/ # the package
│ ├─ server/ # FastAPI app, REST + WS + MCP-over-HTTP
│ │ └─ mcp_bridge.py # FastMCP exposure, mounted at /mcp/
│ ├─ agent/ # NL → tool-call loop
│ ├─ providers/ # LLM provider catalog + clients
│ ├─ tools/ # shell · script · browser · desktop · bx
│ │ # plus notes · files · reminders · memory
│ │ # · search · audio
│ ├─ integrations/ # 31 SaaS connectors
│ ├─ frontend/ # static SPA — PWA installable
│ │ └─ local-store.js # IndexedDB store: notes / memory / files
│ ├─ channels.py # external IM gateway bridge
│ ├─ audio.py # transcription provider abstraction
│ ├─ auth.py # autoMate Cloud session (Pro tier hook)
│ └─ {notes,files,reminders,memory,push}.py
├─ android/ # native Android WebView app (APK)
├─ extension/ # Chrome MV3 extension
├─ docs/{channels,cloud,relay,mobile,sync}.md
├─ Dockerfile
└─ pyproject.toml127.0.0.1. Network access is opt-in (--host 0.0.0.0).key at ~/.automate/secret.key (chmod 600).
else sees them.
/mcp/ requires a Bearer token. Treat it like apassword — anyone with this token can call autoMate's tools, including shell.exec. Regenerate from Settings → Channels.
AUTOMATE_CLOUD_URL set,no data leaves your machine. See docs/cloud.md for the open-client / closed-server boundary.
v4.5.7 — autoMate is now an MCP-over-HTTP tool source for any OpenClaw / Claude Desktop / Cursor / Cline / Cline / Kimi setup. Settings gives you a one-click "Copy install text" for any AI client. Personal infra is filled out: Coze-style retrieval, audio transcription, configurable storage path, in-app auto-update, login hook for the upcoming autoMate Cloud Pro tier.
中文版: README_CN.md
MIT.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.