DeepChat
A local-first desktop assistant unifying multiple models, tools, skills, and traceable agent sessions.
The workflows restrict GitHub permissions to contents: read, disable persisted checkout credentials, pin Actions by commit, and separate unsigned verification packages from credential-bearing distribution builds. The product documentation also describes per-conversation Skill enablement, permission modes, pending permission requests, Tape/Trace inspection, and visible tool parameters and results, giving substantive but incomplete support for least privilege, confirmation, and data-flow visibility. Deductions apply because the excerpts do not show the product's permission policy, confirmation defaults, or remote-endpoint authentication details. Encryption, obfuscation, and privacy protections are mainly README claims without key-storage or sensitive-data lifecycle implementation. Dependency controls include frozen-lockfile installs, exact toolchain versions, overrides, and offline smoke checks, but runtime and test assets are downloaded without hashes in the shown code, and one dependency is a direct CDN tarball. File operations, code execution, web automation, and remote control can have broad effects, while confirmation, scoping, and audit rules are underdocumented. Tape restoration, conversation forks, retry, and stop controls provide partial recovery but not general transactional rollback. Repository ownership, licensing, contribution routes, and upstream acknowledgements are clear, although publisher identity is unverified and supply-chain attribution and external-result citation behavior are not comprehensive.
The README, package manifest, and packaging workflows are broadly consistent about Electron, Node and pnpm requirements, platforms, plugins, Ollama, ACP/MCP, and build commands. The manifest exposes type checks, unit tests, end-to-end tests, plugin verification, and native-component smoke checks. Frozen-lockfile installation, a pinned package manager, and platform-specific verification adequately support ordinary dependency availability; deductions reflect reliance on network-fetched runtimes, test applications, and third-party providers without a documented mirror or general offline fallback. Workflow validation, missing-signing-secret errors, file checks, timeouts, and MCP error propagation are explicit, but end-user troubleshooting for model, network, permission, and remote-channel failures is limited.
The material explicitly covers everyday assistance, development, learning, content creation, and data analysis, with many cloud providers, local Ollama, MCP, ACP, importable Skills, multiple messaging channels, and Windows/macOS/Linux support. This fully establishes varied audiences, scenarios, and environment fit. Capability entry points and some boundaries are visible through conversation-scoped Skills, model selection, project folders, permission modes, and remote commands, but the security boundaries around files, code execution, browser control, and remote operation are not comprehensively defined. Trigger precision is thin because the README says the model decides when to search but supplies no trigger contract, false-trigger controls, conflict rules, or thresholds for sensitive actions.
The Japanese README has a detailed table of contents and coherent sections for features, quick starts, development, contribution, and licensing. Installation covers releases, the website, Homebrew, model setup, exact Node/pnpm requirements, platform builds, and common Windows symlink and distutils issues. DeepChat naming, organization attribution, package version, and artifact names are mostly stable, but the broad Agent/ACP/MCP/Skills/plugin surface lacks an explicit compatibility or stability policy. Several quick starts and command examples are present, though there is no systematic FAQ. Known limitations are scattered among build caveats rather than collected, and model differences, permissions, networking, and operational risks are not documented as limitations. The complete Apache-2.0 license matches the metadata, justifying full marks. Version 1.1.0 and a Releases link exist, but no revision-contained changelog or compatibility policy is supplied. ThinkInAIXYZ, issues, pull requests, and contribution guidance provide a maintenance path; the unknown publisher identity is not treated as suspicious, but no named maintainer, support lifetime, or security contact is shown.
Multi-window and multi-tab operation, Markdown and code rendering, images, Mermaid, artifacts, Trace inspection, tool-call display, retry, conversation forks, and remote commands provide strong evidence that outputs and workflows are directly usable. Combining local and cloud models, ACP/MCP, Skills, Tape, and messaging control in one desktop client offers credible marginal value, but most comparative advantages are feature assertions rather than supported benchmarks or user evidence. Apache-2.0 licensing, local-model support, cross-platform packages, and provider choice improve the apparent cost-benefit balance. Deductions reflect absent discussion of API and search fees, runtime downloads, resource consumption, channel setup, and maintenance costs, plus no static substantiation for claims of minimal cost or superior performance.
Platform, toolchain, version, build, and packaging claims are traceable to package.json and the workflows, while the Tape, ACP, MCP, and Skills positioning is repeated consistently in the README. Cross-source corroboration is adequate: build and platform claims align with scripts and Linux/macOS workflows, and licensing is confirmed by the separate LICENSE file. The supplied implementation and test excerpts are too narrow to corroborate the many product, security, and provider claims individually. Fact-inference separation is weak because phrases equivalent to industry-leading, excellent performance, security-focused, and minimal cost are mixed with factual feature descriptions without repository-contained comparison methods or evidence.
- This is a static review of only the supplied files; the application, tests, builds, and dependencies were not executed or audited, so runtime safety and correctness are unconfirmed.
- Before enabling file operations, code execution, CUA, MCP, ACP, or messaging-based remote control, verify permission defaults, per-action confirmation, scope restrictions, authentication, logging, and revocation.
- The shown implementation does not establish how API keys, remote-bot credentials, and local session data are stored, how encryption keys are managed, or how data is exported and deleted.
- Runtime and test assets are downloaded from the network, and the shown download helpers do not verify hashes; the direct CDN tarball and overall supply-chain integrity require separate review.
- Some README claims about security, privacy, performance, and low cost are promotional and should not be treated as tested or independently verified.
What does this agent do, and when should you use it?
DeepChat is an open-source, local-first AI agent desktop client for Windows, macOS, and Linux. Its Electron application brings cloud models, local Ollama deployments, MCP services, installable Skills, ACP agents, and remote messaging channels into one interface. Sessions follow the Tape.systems philosophy, preserving context, tool calls, requests, and results, while Trace previews expose request sequences, model metadata, entry selection, and token budgets. Users can run parallel conversations in multiple windows and tabs, work with project folders, and render Markdown, code, images, Mermaid diagrams, and Artifacts. It is best suited to users willing to manage their own model credentials and integrations in exchange for provider choice, inspectable long-running sessions, and local data storage.
A user configures a cloud provider using an OpenAI-, Gemini-, or Anthropic-compatible API, or connects a local Ollama deployment, then starts a DeepChat or ACP session from the model selector. A session can work with project folders and call MCP Resources, Prompts, and Tools over StreamableHTTP, SSE, Stdio, or inMemory transports; documented inMemory utilities include code execution, web retrieval, and file operations. Enabled Skills load task instructions, reference files, assets, and optional scripts into a conversation. DeepChat records the run in a Session Tape, and its Trace preview shows request ordering, provider and model metadata, the Tape view manifest, included or excluded entries, and token budgets. Outputs appear as chat responses, code blocks, images, Mermaid diagrams, or Artifacts, while Telegram, Feishu/Lark, QQBot, Discord, and WeChat iLink can remotely control bound sessions.
- An individual using both hosted APIs and Ollama can manage providers and run several conversations in parallel from one desktop application.
- A developer running a long coding or task workflow can use project folders, ACP agents, tool-call views, Tape, and Trace to inspect and resume the work.
- A team with internal utilities can expose them through MCP Resources, Prompts, or Tools using the supported HTTP, SSE, Stdio, or inMemory transports.
- A user handling code reviews, documents, PDFs, presentations, or spreadsheets can enable a relevant Skill per conversation and exchange Skills with compatible tools.
- Someone away from their workstation can use Telegram, Feishu/Lark, QQBot, Discord, or WeChat iLink to inspect status, switch sessions or models, answer pending interactions, and stop a run.
What are this agent's strengths and limitations?
- One desktop client supports numerous hosted providers, services using OpenAI/Gemini/Anthropic API formats, and locally deployed Ollama models.
- Session Tape and Trace preserve more than chat text: they expose request ordering, tool activity, provider metadata, entry selection, and token budgets for long-running work.
- MCP, installable Skills, and native ACP entries extend different layers of the system: tools, reusable task knowledge, and external agent runtimes.
- Remote channels can create and switch sessions, stop generation, answer pending questions or permission prompts, change models, and report runtime status.
- Packaged releases cover Windows, macOS, and Linux, and the repository uses the Apache-2.0 license.
- Hosted models, search APIs, and messaging integrations require network access, credentials, and potentially paid third-party services; local inference requires a separately managed Ollama setup.
- Providers, MCP services, Skills, ACP commands, and remote channels each add configuration and permission surfaces, making a full deployment more involved than a single-provider chat client.
- Source development requires pnpm and a separate runtime-install step; Windows may require Developer Mode, while macOS signing and packaging follow an additional process.
- The documented security design mentions reserved encryption interfaces and obfuscation capabilities, but does not establish that chat data is encrypted by default.
- The stated Codex and Claude Code interoperability concerns Skill import and export; it does not demonstrate that DeepChat runs natively inside those products.
How do you install or deploy this agent?
End users can download a Windows .exe, macOS .dmg, or Linux .AppImage/.deb from GitHub Releases, or use the project's official download site. On macOS, run brew install --cask deepchat. For source development, run pnpm install, followed by pnpm run installRuntime; if Python reports No module named 'distutils', run pip install setuptools, then start the application with pnpm run dev. Non-administrator Windows users must enable Developer Mode so pnpm can create symbolic and hard links. After launch, open Settings → Model Providers and supply a cloud-provider API key or configure local Ollama.
How do you use this agent?
Launch DeepChat and configure an API key or Ollama under Settings → Model Providers. Click “+” to create a conversation, choose a model in the selector, and send the first prompt. For specialized workflows, open Settings → Skills, install a Skill from a folder, ZIP file, or URL, and enable it for the relevant conversation. To use an external runtime, enable ACP under Settings → ACP Agents, activate a built-in agent or enter a custom ACP-compatible command, and select it like a model. Configure MCP services when tool access is needed; for messaging access, configure a channel under Settings → Remote and bind its endpoint to a DeepChat session.