Skip to content
@cavi-ai

Cavi AI

Open research and MIT-licensed infrastructure for agent systems.
CAVI-AI — open research and infrastructure for agent systems

Open research and infrastructure for agent systems.

MIT-licensed tools that make agent runtimes easier to connect, inspect, secure, and trust.

Secure Agent  ·  Repositories  ·  Documentation  ·  Plugins


Start with Secure Agent

Secure Agent is an egress-inspection and secret-leak firewall for local AI agents on macOS. It correlates a sensitive-file read with the network egress that follows and flags the leak before a key leaves the machine.

View source · View releases


Explore the stack

Open building blocks for secure, local, and inspectable agent systems.

Project What it does
CAVI API Client Gateway-agnostic TypeScript client — agent runtime infrastructure for typed HTTP, WebSocket, and SSE.
Bobby Browser Alpha browser-automation runtime with authenticated, capability-scoped control across Rust, TypeScript, MCP, and CDP.
MLX Agent Discovers, verifies, and wires local MLX-optimized models on Apple Silicon — Claude, Codex, Antigravity, OpenCode, and AgentSkills.
MLX Workbench Loopback-local UI for the MLX Agent model lifecycle.
Companion for Claude The Obsidian Community Store release for Claude knowledge workflows.
Obsidian Agent Portable, CLI-powered Obsidian workflows across agent hosts.
MCP Eval Evidence-driven MCP-server evaluation across discovery cost, schema guessability, error honesty, state recovery, and contention — turning agent friction into actionable findings.
Ableton MCP Local-first Ableton Live control for MCP clients — Remote Script bridge, stdio MCP server, and CLI with confirm-to-execute mutations.
CAVI Plugins Host-neutral plugin catalog across Claude, Codex, Gemini, OpenCode, and AgentSkills.
Antigravity for OpenClaw OpenClaw provider plugin for Google's Antigravity CLI.

Research and verification

  • Agent security — tying a sensitive-file read to the network egress that follows.
  • Runtime interoperability — connecting gateways and providers through typed boundaries.
  • Local-first workflows — running models and knowledge tools on hardware you control.
  • MCP reliability — measuring discovery cost, schema guessability, error honesty, state recovery, and contention.

Built in the open

Every public CAVI-AI project ships with its source and provenance. Read the code, test the assumptions, adapt the tools, and contribute what you learn. More work is in development — we publish it when there is working software and evidence worth examining.

cavi-ai.xyz  ·  all repositories  ·  plugin catalog

MIT licensed · Source published · Provenance attached

Pinned Loading

  1. cavi-api-client cavi-api-client Public

    🛰️ Talk to any AI agent runtime through one TypeScript client. Provider-agnostic, ESM, zero-dependency.

    TypeScript 2

Repositories

Showing 10 of 14 repositories
  • mlx-workbench Public

    💻 Local workbench for the MLX model lifecycle on Apple Silicon — scan, convert, verify, benchmark, serve, and wire local models. Web UI plus a native SwiftUI app; preview/confirm everywhere, receipts as authority, nothing deletes.

    cavi-ai/mlx-workbench's past year of commit activity
    Swift 2 MIT 0 0 0 Updated Oct 3, 2026
  • mlx-agent Public

    🍏 Discover, verify, and wire local MLX-optimized models on Apple Silicon: plugins for Claude Code, Codex, Antigravity, and OpenCode, plus a portable AgentSkill.

    cavi-ai/mlx-agent's past year of commit activity
    Python 2 MIT 0 0 0 Updated Oct 3, 2026
  • claude-obsidian Public

    Development monorepo for Companion for Claude: Obsidian plugin, Claude Code plugin, and guides. Store release: cavi-ai/companion-for-claude.

    cavi-ai/claude-obsidian's past year of commit activity
    TypeScript 3 MIT 0 0 0 Updated Oct 3, 2026
  • companion-for-claude Public

    🟠 Cowork with Claude inside your Obsidian vault — chat, agent mode, sandboxed HTML artifacts, evidence-backed research, and an MCP bridge to Claude Code. Free, MIT, bring your own key.

    cavi-ai/companion-for-claude's past year of commit activity
    TypeScript 5 MIT 0 0 0 Updated Oct 3, 2026
  • secure-agent Public

    🔐 Egress inspection & secret-leak firewall for local AI agents — see what your agents send, catch secrets before they leak, and stop rotating your keys three times a week. macOS menu bar app + Go daemon.

    cavi-ai/secure-agent's past year of commit activity
    Go 2 MIT 1 0 0 Updated Oct 3, 2026
  • cavi-api-client Public

    🛰️ Talk to any AI agent runtime through one TypeScript client. Provider-agnostic, ESM, zero-dependency.

    cavi-ai/cavi-api-client's past year of commit activity
    TypeScript 2 MIT 0 0 0 Updated Oct 2, 2026
  • homebrew-tap Public

    🍺 Homebrew tap for CAVI-AI releases: bobby-browser and mcp-eval (brew tap cavi-ai/tap).

    cavi-ai/homebrew-tap's past year of commit activity
    Ruby 0 0 0 0 Updated Oct 2, 2026
  • bobby-browser Public

    🐝 Browser automation runtime for agents on Firefox and Chromium, with authenticated, capability-scoped control surfaces: MCP, ACP (Zed), CDP + Rust, TypeScript, and Python SDKs. 👑 ↯ 🦾🦿🦿🦾🤖

    cavi-ai/bobby-browser's past year of commit activity
    Rust 5 MIT 0 0 0 Updated Oct 2, 2026
  • openclaw-antigravity Public

    💨 Runs Google's Antigravity CLI (agy) as an OpenClaw model provider

    cavi-ai/openclaw-antigravity's past year of commit activity
    JavaScript 3 MIT 0 0 0 Updated Oct 2, 2026
  • mcp-eval Public

    🧐 Privacy-preserving MCP server evaluation: deterministic CI probe battery (18 probe kinds, readiness score, SARIF) plus production friction capture with findings that verify and close

    cavi-ai/mcp-eval's past year of commit activity
    Rust 2 MIT 0 0 0 Updated Oct 1, 2026