Vibeleaderboard
Index / app
Visit github.com
Category
AI Agents
Rank
No. 2069Tools index
Type
APP
Use case
Coding
Interfaces
CLI · Desktop
Date

About

A local-first agent workspace incubating at Apache. Agents inspect projects, run tools, and produce artifacts under controlled permissions, with model messages and tool calls preserved as recoverable execution facts; desktop, terminal TUI, and CLI all execute through a shared Runtime Host.

What it does

Maka is a coding and task agent you point at your own model, whether a cloud API, a local model or a compatible gateway. Its central idea is that an append-only event log is the program state: every model message, tool call, permission decision and termination is written there, and the screen, the next prompt and crash recovery are all rebuilt from it. The desktop app, a text interface in the terminal, a one-shot command and the benchmark harness all talk to one host process that owns sessions, tools and permissions, so they never run a second copy against the same state.

Why it's ranked here

The design makes claims a reader can check. The project says it benchmarks itself against other harnesses on the same model with the official verifier and ships per-task results with each report. It is Apache 2.0 licensed and sits in the Apache incubator. The security policy is unusually candid: it names the operating system as the only real boundary against a hostile model and lists which safety checks are mere heuristics. Shell commands and file operations can run inside OS sandboxes on macOS and Linux, failing closed when enforcement is unavailable.

What's good

Because the log is the record, pruning old tool output shrinks the next prompt without deleting history, and an interrupted turn can be resumed from the desktop app or the terminal. Benchmark results keep the earliest valid attempt as authoritative, so an operator cannot pick a preferred outcome. Secrets never cross into the renderer process, and the policy names tests that enforce this for two credential types. The model connector separates configured, ready and experimental connections, and hides account flows that are not actually wired up. A graph mode splits work across isolated Git worktrees.

Tradeoffs

There is no Apache release yet, and development builds are explicitly not approved releases. The incubation disclaimer says an authorization review for the initial code is still open and that adopters need their own licensing review. Windows and Linux are marked as previews, and on Windows the sandbox covers only the file worker, so arbitrary shell commands are unavailable when sandboxing is required. API keys sit in a plaintext file protected only by account file permissions. Upgrading drops older transcripts and safeStorage credentials, so threads can appear empty. The README and security policy name the credential file differently.

How to use it well

Fit it to a single developer who wants an auditable record of what an agent did and wants to bring their own model. Building from source needs Node 22.19 or newer, npm, Git and ripgrep; peer features also need Rust. Add and test a model connection in settings before the first task. Keep the default ask permission mode so the restricted sandbox profile applies, and run as a non-admin account. Use graph mode only from a clean Git worktree. Resuming a turn calls the model and spends tokens. It is not a multi-user or cloud-synced service.

Technical notes+

The root package.json declares an npm workspaces monorepo (core, storage, mcp, runtime, runtime-host, eval, computer-use, cli, ui, apps/desktop, website) with engines node >=22.19.0. ARCHITECTURE.md places the Runtime Event Log as canonical, with SessionManager and AgentRun below one Runtime Host per State Root, and @maka/eval owning only experiment semantics. packages/mcp/src/index.ts wraps the MCP client SDK with stdio, streamable HTTP and SSE transports, OAuth via McpOAuthProvider, secret scrubbing and default timeouts (30s remote connect, 60s stdio connect, 600s tool call, 24 MiB result cap). apps/desktop/src/main/main.ts uses a distinct Maka Dev app name to isolate dev userData and enforces a single-instance lock. SECURITY.md documents Seatbelt, bubblewrap and AppContainer sandboxing and 0o700/0o600 credential file modes. packages/cli/src/cli.ts is a thin launcher.

Observed

License
Apache-2.0 (LICENSE, package.json)
Governance
Apache Incubator project; DISCLAIMER-WIP notes an open initial-code authorization review
Language and packaging
TypeScript npm workspaces monorepo with Rust native components
Interfaces
Electron desktop app, terminal TUI, non-interactive CLI run command, evaluation harness
Platform support
macOS; Windows and Linux marked preview in README
Model support
Bring your own: cloud API, local model or compatible gateway; no bundled model account
MCP
MCP client with stdio, streamable HTTP and SSE transports and OAuth (packages/mcp/src/index.ts)
Sandboxing
Seatbelt on macOS, bubblewrap on Linux, AppContainer for the Windows filesystem worker only (SECURITY.md)
Credential storage
Plaintext JSON under the workspace, protected by 0o700/0o600 file modes (SECURITY.md)
Release status
No Apache release made; development builds are not approved releases (README.md)
Build requirements
Node.js, npm, Git and ripgrep; Rust for peer features

Read from README.md, package.json, LICENSE, ARCHITECTURE.md, DISCLAIMER-WIP, docs/README.md, docs/cli-distribution.md, packages/cli/src/cli.ts, packages/mcp/src/index.ts, packages/computer-use/src/index.ts, apps/desktop/src/main/main.ts, SECURITY.md.

Tags

agent-runtimeaiai-agentsapacheclidesktopelectronevent-sourcingincubatorllm

Tech Stack

Node.js

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.