feder-cr

invisible_dots

Community feder-cr
Updated

Open-source dots for the web: an AI agent with its own browser, one that does not get blocked.

invisible_dots

AI agents that each own a computer.

A virtual machine on your PC with a desktop, a shell, files, memory and skills that stay, and a browser that does not look automated. You decide what each one may do.

Quickstart · Guide · Architecture · Security · Privacy

A Dot is a persistent AI agent with a QEMU virtual machine of its own, on your own PC. Its disk, files, memory,skills and browser logins outlast every task. You talk to it from a web UI, the command line, an HTTP API orTelegram, and it runs on any model on OpenRouter, with your key.

Quickstart

You need Node 24+, Go 1.25+, Git and hardware virtualization (x86-64), plus an OpenRouter key.

Windows (PowerShell):

winget install -e --id OpenJS.NodeJS.LTS; winget install -e --id GoLang.Go; winget install -e --id Git.Git
git clone https://github.com/feder-cr/dots; cd dots
npm ci; npm run build --workspace @invisible-dots/cli
node apps/cli/dist/invisible-dots.mjs setup --all
node apps/cli/dist/invisible-dots.mjs server

Linux (Ubuntu 24.04):

curl -fsSL https://deb.nodesource.com/setup_24.x | sudo -E bash - && sudo apt-get install -y nodejs git && sudo snap install go --classic
git clone https://github.com/feder-cr/dots && cd dots
npm ci && npm run build --workspace @invisible-dots/cli
node apps/cli/dist/invisible-dots.mjs setup --all
node apps/cli/dist/invisible-dots.mjs server

setup --all installs QEMU and turns on the accelerator (KVM, or the Windows Hypervisor Platform), then builds ordownloads the Dot's images; run it again after a restart and it carries on. Then open http://127.0.0.2:3000,paste your OpenRouter key and create your first Dot. Every step and its failure modes:the guide's quickstart.

What to ask a Dot

Anything that needs a computer and a person's judgement, for as long as it takes:

Open a browser identity called research, go to https://example.com and tell me the page's title and its firstsentence. Leave the browser open.

Every morning, check one-way fares from Milan to Lisbon for the next two weeks, write them to~/workspace/fares.csv and tell me the cheapest day.

Log in to the shop with the shopping identity, download this month's invoices to ~/documents, and remember wherethe invoices page is for next time.

What a Dot has

A computer of its own A hardware-accelerated VM with a Linux desktop and a persistent disk. It sleeps when idle and wakes for the next message, task or automation.
A browser that is not blocked invisible_playwright_mcp: Firefox patched in C++, the fingerprint set inside the engine. Each identity keeps its own cookies and logins.
Memory and skills It writes its own notes and how-tos in its home folder, as Claude Code does, and reads them on the next task.
Permissions you set Every tool belongs to a permission: allow, ask or deny. An ask waits in your Inbox, survives a restart and runs the call once.
Tasks and automations A queue with priorities and start times, and its own recurring jobs, for which its computer is started on time.
Many ways to reach it Web UI, command line, HTTP API with live events, Telegram, and WhatsApp as an opt-in.
Nothing lost on a crash A restart or a kill -9 keeps every message and task you saw accepted, and a tool call cut short is never run twice.

Which one fits

A browser API or library A cloud sandbox for agents invisible_dots
Where the agent's work runs Your code drives a browser A machine in someone's cloud A VM on your own PC, one per agent
What stays between tasks What your code saves What the sandbox keeps, for its lifetime Its disk, files, memory, skills and browser logins
The browser Chromium, often over CDP Whatever the sandbox ships Firefox patched in C++, one identity per profile
Risky actions Your code decides Your code decides Allow, ask or deny per permission, answered from the Inbox or a chat
What you write Code Code A message or a task

How it works

flowchart LR
  UI["Web UI · CLI · Telegram"] --> API["invisible-dots server<br/>API, scheduler, database"]
  API -->|"start, stop, wake"| VM
  subgraph VM["One QEMU VM per Dot"]
    ENG["Engine<br/>(a nanobot fork)"] --> BR["Firefox identities<br/>over MCP"]
    ENG --> SH["Shell and files<br/>as the user dot"]
  end
  ENG -->|"model requests"| OR["OpenRouter"]
  BR --> WEB["The web"]

One server process on your PC runs the API, the queue, the approvals and one VM per Dot. Inside each VM the enginereasons with your model, runs commands as an unprivileged user and drives its browsers on the VM's desktop. The fullpicture: docs/architecture.md.

Security and privacy

  • Your OpenRouter key is never written to a Dot's disk or image: it is pushed after every start and held in memory.
  • A Dot's commands run as a user that cannot reach the engine, approve its own calls or become root; the one thingit may do as root is sudo dot-install an Ubuntu package.
  • A Dot's computer cannot reach the web UI, and the API refuses it without the token.
  • There is no server of ours and no telemetry: the Dots, their data and the database stay on your PC.

What protects you and where the limits are: security model and known limits,privacy.

[!NOTE]Alpha. Nothing is packaged yet: you build it from this repository, and the one thing published is the goldenimage CI builds from its pinned inputs. The real-VM acceptance run passes its 15 steps on Linux with KVM; Windowsruns the same code on the Windows Hypervisor Platform. What is not done yet:status.

Documentation

  • Guide: install, the web UI, the command line, the browser, channels, configuration, updating
  • Architecture: every component and why it is there
  • Troubleshooting and development and tests

Related projects

The pieces of this one. A Dot's browser isinvisible_playwright_mcp, oninvisible_playwright andinvisible_core; the engine is a fork ofnanobot.

Neighbours. cua gives agents computers through its own SDK and sandboxes;E2B runs agents' code in cloud sandboxes; OpenHandsis a platform for software-development agents; browser-use lets an LLMdrive a Chromium browser from Python; Open Interpreter runsthe code a model writes on your own machine. invisible_dots puts the agent, its computer and its browser on your PC,one VM per agent, behind permissions you set.

License

MIT, see LICENSE. Third-party components and their licenses: THIRD_PARTY_NOTICES.md.

Disclaimer

This project is provided as-is, with no warranties. Use it at your own risk and in compliance with the laws of yourjurisdiction. A Dot acts with your accounts and from your connection: respect the terms of the sites it visits andtheir robots.txt.

Built by Federico Elia

MCP Server · Populars

MCP Server · New