Chat On Steroids
Connect ChatGPT to local projects, terminals, and durable multi-worker development workflows.
Per-dimension scores and reasoning
The security documentation clearly describes approved roots, read-only mode, loopback binding, tokenized paths, browser-debug permissions, desktop-wide capabilities, session recording, and credential storage. CI actions are commit-pinned, while release jobs verify tags, versions, checksums, public-history privacy, and notices; dependencies also receive pinning or overrides. Deductions reflect that exec_command explicitly escapes approved-folder confinement and runs with the user's privileges, fresh installs enable Core with read-only off, and Windows additionally enables Desktop permissions. The supplied evidence does not establish per-action confirmation for every consequential operation. Session recordings are not safeStorage-encrypted and browser access has no per-tab approval. Browser-control revocation and atomic plan writes have test support, but no general rollback facility is shown for file, shell, or desktop effects. Attribution and licensing are visible, although responsibility rests with an identity-unverified solo maintainer.
The README, security policy, package metadata, CI, release workflow, and tests consistently describe the core capabilities, supported platforms, and risks. Focused tests cover durable plans, concurrency fencing, corrupt input, atomic replacement, and browser-debugger lease handling. Dependency installation and three-platform CI are well designed, but were not executed in this review. Availability also depends on ChatGPT Developer mode, custom MCP apps, Chrome or Edge, platform keyrings, and tunnel components, so it is not fully self-contained. Several scripts and tests demonstrate actionable failures and retry behavior, but the evidence does not cover every user-facing failure path.
The intended scenarios—local coding, authorized files and tools, long-running work, multi-agent delegation, and cross-chat recovery—are explicit, as are prohibited uses involving quota, safety, or service-rule evasion. Approved-root, read-only, command, browser-bridge, desktop-permission, MCP, and tunnel boundaries are described thoroughly. Active-tab tests show precise page selection, navigation revocation, and protection of foreign debugger ownership. Trigger precision is reduced because initial capabilities are comparatively broad and the supplied material does not show tool-by-tool confirmation for all actions. Windows, macOS, and Linux requirements, differences, fallbacks, and CI coverage are clearly documented.
The README supplies a coherent entry point with links to setup, plugins, contribution guidance, security, licensing, and changes. Quick-start steps, requirements, update notes, platform caveats, and release downloads are substantial. Product, package, application, and release naming are stable, and publishing checks enforce agreement among package metadata, lockfile, extension manifest, source version, changelog, and release notes. Known limitations are unusually explicit, and the MIT text matches the metadata. Deductions apply because demonstrations and onboarding do not amount to a comprehensive FAQ or broad example library, while maintenance responsibility is described only as solo maintenance with private reporting and no guaranteed response window.
The evidence presents an integrated workflow spanning files, terminals, desktop and browser control, plans, durable sessions, and multi-agent communication. Tests for communication folding, status labeling, and plan recovery support the practical usability of resulting session output. This offers clear marginal value over an ordinary chat interface, particularly for local execution and long-lived delegated work. Cost-benefit is reduced by a setup involving a desktop app, Developer mode, MCP, an unpacked extension, and potentially a tunnel, together with existing usage-limit consumption, powerful local permissions, readable session history, and provider-policy exposure.
Major claims are traceable to the security model, package scripts, CI and publishing controls, and focused tests. Multiple files corroborate platform support, permissions, session durability, release integrity, and version synchronization. The documentation carefully separates intent and limitations from verified guarantees: it disclaims OpenAI endorsement, policy-compliance guarantees, continued account access, and kernel-level sandboxing. Full scores here indicate strong static traceability and claim discipline in the supplied sources, not executed or independent validation.
- This is a low-confidence static assessment; the application, tests, installers, and release checks were not executed.
- When command capability is enabled, commands can leave approved folders and run with the current OS user's privileges; consequential workflows require supervision.
- Fresh installs start with read-only off and Core enabled, while Windows also enables Desktop permissions. Review and narrow each capability before connecting.
- The extension receives debugger, tabs, and HTTP(S) host permissions without a per-tab approval dialog.
- Durable session recording is enabled by default and is not encrypted with safeStorage; another person with access to the OS account may be able to read it.
- Release binaries are not publisher-signed and macOS builds are not notarized; verify the documented SHA-256 checksums.
- The Linux AppImage may fall back to --no-sandbox when user namespaces are unavailable; prefer the DEB in that environment.
- This is a solo-maintained beta with no guaranteed response window and a dependency on a non-public ChatGPT browser-automation interface, leaving compatibility and account-policy risks.
What does this agent do, and when should you use it?
Chat On Steroids is a cross-platform local workspace that connects ChatGPT to approved project directories through MCP and a companion Chrome extension. Its Core capabilities let ChatGPT read and edit files, run tests, keep terminals open, and use permitted desktop functions. Multiple workers can handle independent jobs and retain context for later assignments. Goal, Loop, and Compact & Resume support unfinished work, continued execution within a brief, and transfer of session and worker history into a fresh chat. It targets Windows, macOS, and desktop Linux, but depends on ChatGPT Developer mode, custom MCP apps, and browser integration rather than invoking Codex directly.
The user approves a project folder under Settings → Workspace, connects Core through Settings → Setup, and adds it as an MCP app in ChatGPT Developer mode. A companion Chrome extension pairs automatically with the desktop application, observes and automates the ChatGPT browser UI, and records conversation content locally. For an assigned task, ChatGPT can use approved capabilities to read or modify project files, execute shell commands and tests, maintain terminal sessions, and display live tool results; fresh Windows installations also enable Desktop permissions by default. Independent work can be delegated to persistent workers and collected afterward, Goal or Loop can continue long-running work, and Compact & Resume can carry the conversation and worker history into a new chat.
- An individual developer who wants to remain in a ChatGPT conversation while the system edits a local codebase and runs its tests.
- A small engineering team splitting unrelated coding or investigation tasks across persistent workers before consolidating their findings.
- A user managing a lengthy task who needs to send corrections during execution and continue it through Goal or Loop.
- A heavy ChatGPT user approaching context limits who wants Compact & Resume to preserve conversation and worker history in a fresh chat.
- A developer who needs to connect owned directories and terminals to ChatGPT from Windows, an Apple Silicon Mac, or x64 Linux.
What are this agent's strengths and limitations?
- Connects a ChatGPT conversation to approved local files, shell commands, tests, and persistent terminals, reducing manual transfer between chat and project tools.
- Persistent workers can divide independent tasks and retain context for subsequent assignments.
- Goal, Loop, and Compact & Resume provide explicit mechanisms for long work, mid-run corrections, and moving context to a new chat.
- Provides desktop packages for Windows, Apple Silicon macOS, and x64 Linux, with support for Chrome 116+ or current Edge.
- Core operation depends on ChatGPT, Developer mode, custom MCP apps, and browser integration, so it is not a provider-neutral local agent.
- It is an independent beta; the Windows package lacks publisher signing and the macOS package is unsigned and unnotarized.
- The companion observes and automates the ChatGPT browser UI and records conversation content locally, creating privacy, compliance, and provider-terms considerations.
- Shell commands run with the user's normal privileges, and enabling filesystem, desktop, or plugin capabilities expands the impact of mistakes.
- Model access, usage allowances, and context limits still come from the ChatGPT account; workers and continuity features do not add quota.
How do you install or deploy this agent?
Download the release package for the target system: Chat-On-Steroids-Setup-x64.exe for Windows x64, Chat-On-Steroids-macOS-arm64.dmg for Apple Silicon macOS, or preferably Chat-On-Steroids-Linux-x64.deb for Linux x64. Supported environments are Windows 10/11, macOS 13 Ventura or newer, or a current desktop Linux distribution, with Chrome 116+ or current Edge. A ChatGPT account or workspace offering Developer mode and custom MCP apps is required; Linux also requires a Secret Service keyring. The Windows build is not publisher-signed, while the macOS build is unsigned and unnotarized, so verify the package against the release checksums. After installation, approve the project folder in Settings → Workspace, connect Core through Settings → Setup and add it in ChatGPT Developer mode, then click Open extension folder and choose Load unpacked in Chrome's extension settings. After an update, reload the companion extension and refresh the CoS apps in ChatGPT when prompted.
How do you use this agent?
Once installation and pairing are complete, select an available model, enter a concrete task, and send it. Keep the request within approved project folders and enabled capabilities; ChatGPT can then inspect or edit files, execute commands and tests, and show tool results as they arrive. Split independent work among workers and collect their results afterward. Use Goal to follow unfinished work, Loop to continue within the stated brief, and Compact & Resume when moving the active session and worker history to a fresh chat. Supervise automated actions, and stop the affected workflow if the provider issues a restriction or policy warning.
How does this agent compare with similar options?
Unlike a tool that invokes Codex directly, Chat On Steroids explicitly uses an existing ChatGPT conversation and connects it to local resources through its MCP Core and browser companion. It aims to provide Codex-style local coding, but model availability, usage, and context remain governed by the ChatGPT account, and its browser automation is not a public ChatGPT automation API.