Skip to content

Commit d5edfd4

Browse files
Merge pull request #64 from codextde/agent/c-pro/a06af3d77631
Claude Code builds the team: connect it, or any app that speaks MCP, to create and manage agents from outside
2 parents bd8a486 + fe0bc42 commit d5edfd4

32 files changed

Lines changed: 1719 additions & 20 deletions

‎README.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,7 @@ needs to be useful:
6060
| ⚡ **Automations** | Work starts when it happens: on a schedule (“weekdays at 08:00”), when something happens in a connected app (a new email, a Slack message, a calendar event, a Notion update), when a condition you describe comes true (“competitor pricing changes”), or when a webhook is called. Describe it in one sentence and Godmode sets it up. |
6161
| ⏰ **Follow-ups** | When a task needs waiting — a reply to an email, a delivery, a build, office hours — the agent sets itself a time and picks the chat up again on its own, with all the context, like a coworker who says “I'll check back tomorrow at 10”. You see when it comes back and can continue now, move it or cancel it. |
6262
| 🤝 **Delegation** | Agents hand tasks to peer agents or spawn short-lived subagents. The Godmode agent can list, check, create and configure all agents. Follow a handoff both ways: open the teammate's chat from the handoff card, and jump back to the chat that asked from there. |
63+
| 🧰 **Claude Code & MCP** | Build your team from the terminal: connect Claude Code — or Cursor, Codex, Claude Desktop, any app that speaks MCP — and say *“Create a Godmode agent that…”*. One click in **Settings → Claude Code & MCP** adds Godmode to Claude Code for every project. The app gets Godmode's own management tools (agents, automations, tasks, runs, VMs) through a key of its own, with full or look-only access; scripts reach the same tools with `godmode call`. Passwords, 2FA codes and settings stay out of its reach. |
6364
| 🏢 **Team & org chart** | Give every agent a role (*Bookkeeper*, *Research analyst*) and a lead; agents are told who does what and who they report to, so work goes to the right one. The **org chart** shows the whole team with what each is doing right now. Status tells the truth — *Working in 2 chats*, *Queued*, *Needs your answer*, *Last run failed* (one click opens the run) — and each agent's page shows **what's on its plate**: live work, waiting chats, board tickets, follow-ups and its next automations. Duplicate an agent in one click; messages from automations, the board or other agents are labelled as such, never shown as yours. Or start a **whole team** in one click — *Back office*, *Marketing*, *Sales*, *Product & QA*: a lead and its reports, wired up, with their schedules. |
6465
| 💰 **Spend & budgets** | See what the team cost today, this week, this month and all time — per agent and per kind of work, booked when it was spent. Give the team (and any agent) a **monthly budget**: you're told at 80%; at 100% automations, follow-ups and board tickets are **held, not failed** — they continue by themselves next month or as soon as you raise the budget, or right away when you click *Let it run*. Chats you start always run. |
6566
| 📨 **Message queue** | Keep writing while an agent works: your messages wait in a queue above the message box, and the agent picks them up at its next step and works them into what it is doing — a correction lands right away, an extra request comes after the current step. Reword or remove a queued message until it is picked up, or hit *Send now* to interrupt. |
@@ -143,6 +144,10 @@ needs to be useful:
143144
<td><img src="docs/screenshots/phone-pairing.png" alt="Connect a phone by scanning a one-time QR code" /><br /><sub><b>Connect a phone</b> — scan a one-time code; the phone gets its own key</sub></td>
144145
<td><img src="docs/screenshots/phone-settings.png" alt="Phone settings: Tailscale status, phone access and paired phones" /><br /><sub><b>Phone settings</b> — Tailscale status, paired phones, remove one anytime</sub></td>
145146
</tr>
147+
<tr>
148+
<td><img src="docs/screenshots/connect.png" alt="Settings: Claude Code and MCP, with the connected apps and the tools they can call" /><br /><sub><b>Claude Code & MCP</b> — connected apps, their access and the tools they can call</sub></td>
149+
<td><img src="docs/screenshots/connect-claude-code.png" alt="Claude Code connected in one click, with a first prompt to try" /><br /><sub><b>One click</b> — Godmode adds itself to Claude Code; ask for an agent in your next session</sub></td>
150+
</tr>
146151
<tr>
147152
<td><img src="docs/screenshots/messaging.png" alt="Slack, Telegram and Teams bots connected to agents" /><br /><sub><b>Messaging</b> — talk to agents from Slack, Telegram and Microsoft Teams</sub></td>
148153
<td><img src="docs/screenshots/messaging-bot.png" alt="A bot's access requests, agents and who may use it" /><br /><sub><b>Bot settings</b> — approve people, pick agents, see every chat</sub></td>
@@ -253,6 +258,27 @@ and Screen Recording on its screen if agents should use apps there — the runne
253258
runner: `godmode runner status`, `godmode runner pair` (a new pairing code to paste under **Add runner → Enter a
254259
pairing code**), `godmode runner uninstall`.
255260

261+
### Claude Code & other AI tools — set Godmode up from your terminal
262+
263+
1. In Godmode open **Settings → Claude Code & MCP → Connect Claude Code**. Godmode adds itself to Claude Code on this
264+
computer as an MCP server, for every project.
265+
2. Start a new Claude Code session and ask: *“Create a Godmode agent that checks our competitors' pricing every Monday
266+
morning and sends me a summary.”* The agent, its instructions and its schedule show up in Godmode.
267+
268+
**Connect another app** gives any other MCP client (Cursor, Codex, Claude Desktop…) its own key, with the config to
269+
paste. A key either sets up and steers (agents, automations, tasks, VMs) or only looks; remove an app in the same place
270+
and its key stops working. The same tools work from a shell, for scripts:
271+
272+
```bash
273+
export GODMODE_CONNECT_TOKEN=gmc_… # the key from Settings → Claude Code & MCP
274+
godmode tools # what the key can do; `godmode tools agent_create` shows the arguments
275+
godmode call agent_create '{"name":"Scout","role":"Research analyst","instructions":"…"}'
276+
godmode mcp # the MCP server itself (stdio) — what the apps start
277+
```
278+
279+
`godmode` here is the core binary (in the desktop app: `Godmode Bot.app/Contents/MacOS/godmode-core`; the dialog shows
280+
the full path). Inside Godmode nothing changes: the built-in *Godmode* agent creates and manages agents from any chat.
281+
256282
## ⚡ Quick start
257283

258284
1. **Onboarding** — pick a vault passphrase (enable *Remember on this device* so routines run unattended).
@@ -404,6 +430,13 @@ Every run is committed, so you can see exactly what an agent learned and did —
404430
set of routes: no logins, 2FA codes, backups, integrations, settings or folders, and only screens shared in a chat
405431
can be controlled. A paired phone can still ask agents to act on your computer — remove a lost phone in
406432
Settings → Phone, and turn on *Require Face ID* in the app.
433+
- **Connected apps** (Claude Code, other MCP clients) get a key of their own (stored hashed) that opens only the
434+
management tools of the MCP gateway: no passwords, 2FA codes, settings or files. They see which logins exist (names
435+
and usernames) and what agents were asked and answered. They act as the built-in agent and inside its limits — an
436+
agent they create can use saved logins but not read them, can't manage agents and can't control this computer until
437+
you allow it. Every change and every refused call is in the audit log; removing an app cuts it off at once. A key
438+
that sets up and steers can still create agents and automations that act with your logins: connect only apps you
439+
trust, and give the others a look-only key.
407440

408441
- **Runners** pair with a one-time code and pin each other's keys; the link is end-to-end encrypted (X25519, AES-256-GCM)
409442
and the runner's API never listens beyond its own loopback. A paired Godmode gets your vault key on the runner so
@@ -445,6 +478,7 @@ See [CONTRIBUTING.md](CONTRIBUTING.md).
445478
- [x] Runners: another Mac does the work of a chat while this one sleeps — one install command, encrypted link, setup copied, live view
446479
- [ ] Runners on Windows and Linux, tasks of the board on a runner, VMs copied to a runner
447480
- [x] Godmode Cloud (optional, self-hosted): your computer in any browser, phones without Tailscale, accounts and plans
481+
- [x] Claude Code & MCP: Claude Code and other AI tools create and manage agents, automations and tasks from outside, plus a `godmode` command line for scripts
448482
- [ ] Push notifications
449483
- [ ] Team mode: shared workspaces and approvals
450484

‎SECURITY.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,13 @@ We aim to acknowledge reports within 72 hours and to ship a fix for critical iss
3535
- **Re-authentication for sensitive actions**: revealing a password, enabling "reveal" for an agent (or as default) and
3636
turning on "remember this device" need a short-lived grant confirmed with your vault passphrase — a stolen API token
3737
alone is not enough.
38+
- **Connected apps** (Settings → Claude Code & MCP): Claude Code and other MCP clients reach Godmode with a key of
39+
their own (`gmc_…`, stored as a SHA-256 hash, shown once). The key opens the management tools of the MCP gateway and
40+
nothing else: no vault tools, no browser, no settings, no dashboard API. Even a look-only key sees which logins
41+
exist (names, domains, usernames — never a password or a code) and the prompts and results of runs and tasks. Calls
42+
run as the built-in agent with the limits below, keys are either full or look-only, changes and refused calls are
43+
audited as `connector.call`, and keys are left out of backups. Phones and Godmode Cloud can't create or remove keys. A full key can create agents and automations that
44+
later act with your saved logins, so it deserves the same care as the app itself.
3845
- **No privilege escalation through agents**: agents that create or edit agents cannot grant reveal access, change
3946
workspaces, browser profiles or out-of-scope integrations. A task an agent hands to a reveal-mode agent runs
4047
without raw secrets unless the caller reads raw secrets itself and the target is global or in the caller's workspace

‎apps/desktop/src/components/layout/command-palette.tsx‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,7 @@ import {
3030
ScrollText,
3131
Server,
3232
Settings,
33+
SquareTerminal,
3334
ShieldCheck,
3435
SlidersHorizontal,
3536
Smartphone,
@@ -301,6 +302,9 @@ export function CommandPalette() {
301302
<CommandItem value="instructions rules agent context" onSelect={() => go("/settings/instructions")}>
302303
<ScrollText /> Instructions
303304
</CommandItem>
305+
<CommandItem value="claude code mcp server cli connect terminal cursor api key" onSelect={() => go("/settings/connect")}>
306+
<SquareTerminal /> Claude Code & MCP
307+
</CommandItem>
304308
<CommandItem value="godmode cloud link browser remote access" onSelect={() => go("/settings/cloud")}>
305309
<Cloud /> Godmode Cloud
306310
</CommandItem>

‎apps/desktop/src/components/settings/audit-log.tsx‎

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
import { Fragment, useEffect, useMemo, useState } from "react";
22
import { useQuery } from "@tanstack/react-query";
33
import { format, formatDistanceToNow } from "date-fns";
4-
import { ChevronRight, Cpu, RefreshCw, ScrollText, UserRound } from "lucide-react";
4+
import { ChevronRight, Cpu, RefreshCw, ScrollText, SquareTerminal, UserRound } from "lucide-react";
55
import type { AuditEntry } from "@godmode/shared";
66
import { AgentAvatar, EmptyState } from "@/components/common";
77
import { Badge } from "@/components/ui/badge";
@@ -26,7 +26,17 @@ function actionTone(action: string): string {
2626
return "border-border bg-secondary text-secondary-foreground";
2727
}
2828

29-
function Actor({ actor, agents }: { actor: string; agents: Map<string, { id: string; name: string; avatar: string; color: string }> }) {
29+
function Actor({ actor, agents, app }: { actor: string; agents: Map<string, { id: string; name: string; avatar: string; color: string }>; app?: string }) {
30+
// A connected app (Settings → Claude Code & MCP); its entries carry the name it had.
31+
if (actor.startsWith("connector:"))
32+
return (
33+
<span className="flex min-w-0 items-center gap-2">
34+
<span className="grid size-6 shrink-0 place-items-center rounded-md border bg-secondary text-foreground">
35+
<SquareTerminal className="size-3.5" />
36+
</span>
37+
<span className="truncate">{app ?? "Connected app"}</span>
38+
</span>
39+
);
3040
if (actor.startsWith("agent:")) {
3141
const agent = agents.get(actor.slice(6));
3242
return agent ? (
@@ -192,7 +202,7 @@ function AuditRow({
192202
</Tooltip>
193203
</TableCell>
194204
<TableCell className="max-w-44">
195-
<Actor actor={row.actor} agents={agents} />
205+
<Actor actor={row.actor} agents={agents} app={typeof row.details.app === "string" ? row.details.app : undefined} />
196206
</TableCell>
197207
<TableCell>
198208
<Badge variant="outline" className={cn("font-mono text-[11px] font-normal", actionTone(row.action))}>

0 commit comments

Comments
 (0)