mariagorskikh/open-instinct

Open Instinct: an open-source Instinct. A personal agent you text on iMessage, with its own computer and a trusted network of other agents. Built on Pi, Inkbox, Maritime and Composio.

TypeScript

1

7 commits

updated Oct 4, 2026

See the code

See what people are saying

SourceMessageScoreDate

Show HN: Open-Source Instinct

1

Oct 5, 2026

Personal-agent permissions need both requester identity and limits on returned data (r/ArtificialInteligence)

While open-sourcing our personal-agent app, Open Instinct, we got a useful critique: a tool allowlist does not by itself solve the confused-deputy problem. An agent can be permitted to call a tool and still return more information than the requester should see. Consider scheduling between two…

1

Oct 5, 2026

Open Instinct: an MIT personal agent with an MCP desktop backend (r/mcp)

We open-sourced a personal agent that combines messaging, app tools and computer use. The MCP-specific part is packages/computer: when the agent runs outside its desktop VM, it connects to a hosted computer through Streamable HTTP. Inside the VM, a separate backend talks to the local desktop…

3

Oct 4, 2026

Open Source Instinct

3

Oct 4, 2026

Open Instinct: MIT personal agent with messaging, a desktop and explicit trust tiers (r/coolgithubprojects)

We published this as a forkable starting point for building your own personal assistant. The repo contains nine packages covering the agent core, messaging, desktop, apps, network, payments, server, gateway and CLI. Memory, scheduling and a six-tier permission policy are part of the application.…

1

Oct 4, 2026

Open Instinct (MIT): a personal-agent policy engine with allow, ask and deny outcomes (r/LLMDevs)

We released Open Instinct, an MIT-licensed personal agent. For LLM developers, the policy layer is probably the most reusable part. Tools declare capabilities, and a principal has a trust tier plus active grants. A call must pass every declared capability: deny takes precedence over ask, which…

2

Oct 4, 2026

We built Open Instinct, a personal agent you can text and fork (r/SideProject)

We wanted a personal assistant that people could adapt to their own life, so we published Open Instinct under MIT. It has memory, scheduling, a Linux desktop and messaging through iMessage, SMS or email. A design choice we care about: your partner’s agent and a stranger’s agent should not get the…

0

Oct 4, 2026

README

Open Instinct

An open-source personal agent you text. It has its own computer, does real tasks, and coordinates with the agents of the people you trust.
A from-scratch, documented clone of Instinct, built so anyone can run one.

Three iMessage threads with the agent

How it works

You text Inkbox; the gateway wakes your agent on Maritime; a friend's agent talks to yours over A2A

You text a phone number. Inkbox gives the agent that number, an email address and an agent-to-agent endpoint. A small gateway wakes your agent, which lives in its own microVM on Maritime with a Linux desktop. Inside, a Pi agent loop runs with your apps through Composio, a wallet through Stripe Link, and a policy guard in front of every tool. Default model: Claude Fable 5.1. Any Pi provider works.

Who gets which key

Six rings: owner, partner, family, friend, contact, stranger

Six tiers, enforced in code before any tool runs. Your partner's agent can read your calendar. A friend's can only ask when you are free. A stranger gets a polite no, and you get a one-line text saying who asked for what. Grants add exceptions in plain English: "Sam can book us dinner this week." Details in PERMISSIONS.md and PROTOCOL.md.

Quick start

Node 22.19+ and pnpm 10. You bring your own keys; KEYS.md lists which ones and how to get them. No key is stored in this repository.

On your laptop, no phone number yet

git clone https://github.com/mariagorskikh/open-instinct && cd open-instinct
nvm use && corepack enable        # if corepack needs permissions: npm install -g pnpm@10
pnpm install && pnpm build
export ANTHROPIC_API_KEY=sk-ant-...
pnpm instinct init --name "Maria" --phone +14155550100 --email maria@example.com --handle maria-instinct
pnpm instinct dev                 # then, in another terminal:
pnpm instinct chat "remember that I like window seats"

With an iMessage line

export INKBOX_ADMIN_API_KEY=...   # inkbox.ai console
pnpm instinct init --name "Maria" --phone +14155550100 --email maria@example.com --handle maria-instinct
pnpm instinct dev --tunnel
pnpm instinct connect             # prints the number and the text to send: connect @maria-instinct

The Instinct way: one agent per person on Maritime

export MARITIME_API_KEY=mk_...    # maritime.sh, Settings, API keys
pnpm instinct deploy --image ghcr.io/mariagorskikh/open-instinct-agent:latest

For many people, run the gateway: a signup page that provisions an identity and an agent per person. Guide: DEPLOY-MARITIME.md.

The signup pageThe connect page
Gateway signup pageConnect page

instinct --help

Repository

packages/core       Pi agent loop, policy engine, memory, scheduler, approvals, audit
packages/inkbox     iMessage, SMS, email, webhooks, agent-to-agent transport
packages/computer   the desktop (Maritime desktopd in the VM, or hosted Computers MCP)
packages/apps       Composio Tool Router
packages/network    contacts, tiers, grants, invitations, agent-to-agent tools
packages/payments   Stripe Link wallet: one-time cards the owner approves
packages/server     the agent process (/health, /chat, /schedules)
packages/gateway    multi-user relay and signup
packages/cli        the instinct command
skills/             playbooks the agent follows
docs/               architecture, permissions, protocol, keys, deploy, research

Documentation

Architecture · Permissions · Protocol · Keys · Deploy on Maritime · Self-host · Inkbox · Composio · Payments · Security · FAQ · Examples · Research: What Instinct is, Requirements, Tech reference

Status

Version 0.1. Nine packages, 725 tests, a scripted end-to-end smoke test, and a cold-start test from a fresh clone. Live iMessage and Maritime deployment were exercised against real identities during development; treat them as beta. Logins, 2FA and payments go to you through a desktop takeover or a Link approval, never to the model alone.

Merit Systems publishes an unrelated project called OpenInstinct. This project is not affiliated with it or with Instinct.

Contributing · MIT license

agents
ai-agents
composio
imessage
inkbox
instinct
maritime
open-source
personal-assistant
typescript

mariagorskikh/open-instinct

Open Instinct: an open-source Instinct. A personal agent you text on iMessage, with its own computer and a trusted network of other agents. Built on Pi, Inkbox, Maritime and Composio.

TypeScript

1

7 commits

updated Oct 4, 2026

See the code

See what people are saying

SourceMessageScoreDate

Show HN: Open-Source Instinct

1

Oct 5, 2026

Personal-agent permissions need both requester identity and limits on returned data (r/ArtificialInteligence)

While open-sourcing our personal-agent app, Open Instinct, we got a useful critique: a tool allowlist does not by itself solve the confused-deputy problem. An agent can be permitted to call a tool and still return more information than the requester should see. Consider scheduling between two…

1

Oct 5, 2026

Open Instinct: an MIT personal agent with an MCP desktop backend (r/mcp)

We open-sourced a personal agent that combines messaging, app tools and computer use. The MCP-specific part is packages/computer: when the agent runs outside its desktop VM, it connects to a hosted computer through Streamable HTTP. Inside the VM, a separate backend talks to the local desktop…

3

Oct 4, 2026

Open Source Instinct

3

Oct 4, 2026

Open Instinct: MIT personal agent with messaging, a desktop and explicit trust tiers (r/coolgithubprojects)

We published this as a forkable starting point for building your own personal assistant. The repo contains nine packages covering the agent core, messaging, desktop, apps, network, payments, server, gateway and CLI. Memory, scheduling and a six-tier permission policy are part of the application.…

1

Oct 4, 2026

Open Instinct (MIT): a personal-agent policy engine with allow, ask and deny outcomes (r/LLMDevs)

We released Open Instinct, an MIT-licensed personal agent. For LLM developers, the policy layer is probably the most reusable part. Tools declare capabilities, and a principal has a trust tier plus active grants. A call must pass every declared capability: deny takes precedence over ask, which…

2

Oct 4, 2026

We built Open Instinct, a personal agent you can text and fork (r/SideProject)

We wanted a personal assistant that people could adapt to their own life, so we published Open Instinct under MIT. It has memory, scheduling, a Linux desktop and messaging through iMessage, SMS or email. A design choice we care about: your partner’s agent and a stranger’s agent should not get the…

0

Oct 4, 2026

README

Open Instinct

An open-source personal agent you text. It has its own computer, does real tasks, and coordinates with the agents of the people you trust.
A from-scratch, documented clone of Instinct, built so anyone can run one.

Three iMessage threads with the agent

How it works

You text Inkbox; the gateway wakes your agent on Maritime; a friend's agent talks to yours over A2A

You text a phone number. Inkbox gives the agent that number, an email address and an agent-to-agent endpoint. A small gateway wakes your agent, which lives in its own microVM on Maritime with a Linux desktop. Inside, a Pi agent loop runs with your apps through Composio, a wallet through Stripe Link, and a policy guard in front of every tool. Default model: Claude Fable 5.1. Any Pi provider works.

Who gets which key

Six rings: owner, partner, family, friend, contact, stranger

Six tiers, enforced in code before any tool runs. Your partner's agent can read your calendar. A friend's can only ask when you are free. A stranger gets a polite no, and you get a one-line text saying who asked for what. Grants add exceptions in plain English: "Sam can book us dinner this week." Details in PERMISSIONS.md and PROTOCOL.md.

Quick start

Node 22.19+ and pnpm 10. You bring your own keys; KEYS.md lists which ones and how to get them. No key is stored in this repository.

On your laptop, no phone number yet

git clone https://github.com/mariagorskikh/open-instinct && cd open-instinct
nvm use && corepack enable        # if corepack needs permissions: npm install -g pnpm@10
pnpm install && pnpm build
export ANTHROPIC_API_KEY=sk-ant-...
pnpm instinct init --name "Maria" --phone +14155550100 --email maria@example.com --handle maria-instinct
pnpm instinct dev                 # then, in another terminal:
pnpm instinct chat "remember that I like window seats"

With an iMessage line

export INKBOX_ADMIN_API_KEY=...   # inkbox.ai console
pnpm instinct init --name "Maria" --phone +14155550100 --email maria@example.com --handle maria-instinct
pnpm instinct dev --tunnel
pnpm instinct connect             # prints the number and the text to send: connect @maria-instinct

The Instinct way: one agent per person on Maritime

export MARITIME_API_KEY=mk_...    # maritime.sh, Settings, API keys
pnpm instinct deploy --image ghcr.io/mariagorskikh/open-instinct-agent:latest

For many people, run the gateway: a signup page that provisions an identity and an agent per person. Guide: DEPLOY-MARITIME.md.

The signup pageThe connect page
Gateway signup pageConnect page

instinct --help

Repository

packages/core       Pi agent loop, policy engine, memory, scheduler, approvals, audit
packages/inkbox     iMessage, SMS, email, webhooks, agent-to-agent transport
packages/computer   the desktop (Maritime desktopd in the VM, or hosted Computers MCP)
packages/apps       Composio Tool Router
packages/network    contacts, tiers, grants, invitations, agent-to-agent tools
packages/payments   Stripe Link wallet: one-time cards the owner approves
packages/server     the agent process (/health, /chat, /schedules)
packages/gateway    multi-user relay and signup
packages/cli        the instinct command
skills/             playbooks the agent follows
docs/               architecture, permissions, protocol, keys, deploy, research

Documentation

Architecture · Permissions · Protocol · Keys · Deploy on Maritime · Self-host · Inkbox · Composio · Payments · Security · FAQ · Examples · Research: What Instinct is, Requirements, Tech reference

Status

Version 0.1. Nine packages, 725 tests, a scripted end-to-end smoke test, and a cold-start test from a fresh clone. Live iMessage and Maritime deployment were exercised against real identities during development; treat them as beta. Logins, 2FA and payments go to you through a desktop takeover or a Link approval, never to the model alone.

Merit Systems publishes an unrelated project called OpenInstinct. This project is not affiliated with it or with Instinct.

Contributing · MIT license

agents
ai-agents
composio
imessage
inkbox
instinct
maritime
open-source
personal-assistant
typescript