Productivity & Collaboration local-firstmcpmemory-treeagent-orchestrationtaurirustobsidian-vaultdeep-research

OpenHuman

An open source, local-first personal AI for Mac, Windows and Linux — persistent memory, agent orchestration, and deep research in one desktop app.

FollowAgents review · FARS-2.1
Not recommended
51/ 100 5-point scale 2.6 / 5
1 2 3 4 5 6
1Trust13 / 29 · 2.2/5

Least privilege / user confirmation / data-flow transparency: the README broadly claims approval gates, Privacy Mode, OS keyring, Signal-protocol encryption, and 20-minute auto-fetch, but none of the provided files show code or docs detailing the permission model, approval implementation, or data flow — unsupported assertions warrant deductions. Sensitive data handling: SECURITY.md documents OS-level credential storage, no-retention message processing, skill sandboxing, and a mock-api test verifying Authorization header redaction in logs — 2. Dependency security: Cargo.toml shows near-total vendored submodule path dependencies, pinned toolchains, feature gates, and rustls; solid governance but no visible audit/vuln-scanning evidence — 2. External effects: auto-fetch, 17 messaging channels, and x402 payments are described with no evidence of outbound-behavior constraints in code — 1. Rollback: checkpoint/replay is claimed but no version rollback or data-migration recovery is documented — 1. Source attribution: creator links and extensive upstream-ownership comments in Cargo.toml are clear — 2.

2Reliability8 / 14 · 2.9/5

Self-consistency: Cargo.toml comments match manifest declarations, explicit version (0.63.24), coherent feature-gate reasoning — 2. Dependency availability: submodule init, --frozen-lockfile, pinned toolchain versions improve reproducibility, but unpublished path dependencies concentrate the supply chain in one org — 2. Failure messages: CI scripts emit concrete errors (e.g., listing found AABs on count mismatch), but user-facing failure handling is unevidenced — 1.

3Adaptability9 / 18 · 2.5/5

Audience and scenarios: README clearly targets personal desktop users (Mac/Win/Linux) with a contributor build path and multilingual READMEs — 2. Capability boundaries: only 'Not AGI' and an Early Beta badge; tool capability details all live in unverifiable external gitbook links — 1. Trigger precision: workflows are claimed trigger-driven and approval-gated with no trigger-condition definitions or misuse safeguards shown — 1. Environment fit: three desktop platforms plus Android/mobile CI and a tested Windows install script — 2.

4Convention12 / 18 · 3.3/5

Information architecture: README is well layered (brain/orchestrator/researcher) with sensible separation of docs, CONTRIBUTING, INSTALL — 2. Install notes: INSTALL.md reference plus multi-platform channels and a fully versioned source-build toolchain — 2. Naming stability: consistent tiny* crate naming with comments explaining evolution — 2. Examples and FAQ: no example configs or FAQ; only tables and external links — 1. Known limitations: Early Beta badge, 'Expect rough edges', and explicit correction of stale comments — 2. License: GPL-3.0-only declared in Cargo.toml with a complete LICENSE file and a reasoned only-vs-or-later note — 3. Versioning/changelog: explicit version, release-notes generation and version-sync scripts, but no actual CHANGELOG visible in the files — 2. Maintenance responsibility: SECURITY.md defines supported-version windows, ~5-day acknowledgement, and safe harbor — 2.

5Effectiveness6 / 13 · 2.3/5

Output usability: replayable run journals, per-call cost accounting, and Obsidian vault output are claimed with no output samples — 1. Marginal value: Memory Tree + local-first + TokenJuice compression is a clearly positioned differentiator in the comparison table — 2. Cost benefit: subscription-plus-BYOK/local-Ollama reduces lock-in, but key numbers like '80% fewer tokens' are unsourced — 1.

6Verifiability3 / 8 · 1.9/5

Claim traceability: every README bullet links to gitbook docs unavailable in this review; trend claims ('#1 trending nine days') are unverifiable — 1. Cross-source corroboration: cites Karpathy's tweet and third-party repos (agentmemory, tinyflows); the competitor table disclaims with 'verify against each vendor' rather than corroborating — 1. Fact/inference separation: beta status, license notes, and dependency comments are factual; AGI and 'becomes you' claims are marketing inference not flagged as such — 1.

Evidence confidence: Low Reviewed Sep 10, 2026 Reviewed revision d93180a539e3
Before you use it
  • Publisher identity is unverified by the curated registry; treat as unknown and do not extend trust based on branding or trending badges.
  • Privacy and security capabilities (approval gates, Privacy Mode, E2E encryption) are external-link assertions unverifiable from these files; independently audit the Rust core and network layer before deployment.
  • Auto-fetch every 20 minutes plus 17 messaging channels create a broad ingest/egress surface with insufficient least-privilege and external-effects evidence; trial in a network-isolated environment first.
  • Core dependencies are almost entirely the org's own unpublished vendored submodules — a significant single-source supply-chain risk.
  • The product is Early Beta (0.63.24) and older versions may not receive security patches; do not use with sensitive production data.
See the full review method →

What does this agent do, and when should you use it?

OpenHuman (GitHub: tinyhumansai/openhuman) is a GPL-3.0 licensed, cross-platform desktop personal AI positioned as three things: a brain that remembers everything, an orchestrator that runs agent fleets, and a deep researcher. It is built on a Rust core with a Tauri desktop shell, storing memory as scored Markdown trees in local SQLite and mirroring them to an editable Obsidian vault. Orchestration runs checkpointed graphs on the open-source tinyagents runtime, while automation workflows are built on open-source tinyflows with a visual canvas and approval gates. It ships 100+ OAuth integrations, 5,000+ MCP servers, 90,000+ Skills, 17 messaging channels including native IMAP/SMTP email, and Exa-powered web search. The project is in early beta with a default subscription model, but supports bring-your-own keys or fully local Ollama models, and a Privacy Mode that keeps all inference on-device.

OpenHuman's auto-fetch pulls data from connected accounts (Gmail, Notion, GitHub, Slack and more) on a 20-minute loop, then Memory Trees compress your documents, emails and chats into scored Markdown files stored in local SQLite and mirrored as an editable Obsidian vault. At runtime it executes checkpointed graphs on tinyagents: a fast reflex agent triages inbound traffic while a deep reasoning core delegates to sub-agent fleets up to three levels deep; stuck agents return root-cause reports and every run replays with per-call cost accounting. For automation, the agent proposes a tinyflows workflow graph that you review on a visual canvas; saved workflows fire on schedules, webhooks or channel events, survive restarts, and gate side effects behind approvals. Native tools include web search (powered by Exa), a scraper, a coder toolset, a real browser, in-process Whisper voice, and Seedream/SeedEdit image plus Seedance/Veo video generation. It reaches you over 17 channels (Telegram, Discord, Slack, WhatsApp, Signal, iMessage, native email), and agent-to-agent messaging runs over Signal-protocol end-to-end encryption. TokenJuice compresses tool output before it hits the model, claiming up to 80% token reduction.

  1. A knowledge worker who wants a newly adopted agent to know their inbox, calendar, repos, docs and messages within one sync pass instead of weeks of cold-start.
  2. A user running multiple coding or task agents (e.g., Claude Code, Codex) who wants one interface to orchestrate them with end-to-end encrypted agent-to-agent messaging.
  3. Privacy-conscious individuals or teams who want a one-switch Privacy Mode so no inference leaves their machine, enforced in the Rust core.
  4. Automation-minded users who like n8n/Zapier-style visual workflows but want the agent to propose them for human review and approval on a canvas.
  5. Users who interact with agents via Telegram, WhatsApp, email and similar channels and want the agent to proactively reach them rather than live only in a web chat.
  6. Existing Obsidian users who want their agent's memory as readable, editable Markdown vaults rather than an opaque vector store.

What are this agent's strengths and limitations?

Pros
  • Memory is stored as scored, human-readable Markdown trees plus an Obsidian vault — inspectable and editable, not vector-soup.
  • A real orchestrator architecture: checkpointed graphs on tinyagents that pause for humans, survive restarts, return root causes for stuck agents, and replay with per-call cost accounting.
  • TokenJuice compression makes a large local memory economically viable, with a claimed up-to-80% token reduction.
  • Strong privacy surface: one-switch Privacy Mode enforced in Rust, on-device encrypted data, OS-keyring secrets, approval gates, and E2E-encrypted agent-to-agent messaging.
  • Broad integration surface: 100+ OAuth apps, 5,000+ MCP servers, 90k+ Skills, 17 messaging channels, with BYO-key or fully local Ollama paths avoiding vendor lock-in.
Limitations
  • The project is explicitly labeled Early Beta under active development; expect rough edges.
  • The default experience leans on the OpenHuman subscription (keyless Exa search, media generation, model routing); going subscription-free requires configuring your own keys or local models with feature tradeoffs.
  • Source builds have a heavy toolchain: Node.js 24+, pnpm, Rust 1.93, CMake, Ninja, ripgrep, plus Git submodules vendoring Tauri/CEF.
  • Several headline capabilities (Meet/Zoom/Teams/Webex meetings, media generation) are described only in README/docs; auditable implementation in the repo should be verified before adoption.
  • GPL-3.0 licensing imposes copyleft constraints on redistribution and closed-source integration; evaluate before commercial embedding.

How do you install or deploy this agent?

Download installers for Mac, Windows or Linux from tinyhumans.ai/openhuman or the GitHub Releases page. Terminal installs (Homebrew, Debian/Ubuntu .deb, AUR, install scripts) are documented in the repository's INSTALL.md. Building from source requires Git, Node.js 24+, pnpm 10.10.0, Rust 1.93.0 (rustfmt + clippy), CMake, Ninja, ripgrep, and platform desktop build prerequisites; after cloning run git submodule update --init --recursive before pnpm install so the vendored Tauri/CEF sources are present.

How do you use this agent?

After install, no config files or terminal are needed — a few clicks take you to a working agent. Connect your accounts via one-click OAuth; auto-fetch then syncs data locally every 20 minutes into Memory Trees, giving the agent compressed context of your inbox, calendar, repos, docs and messages after the first sync pass. You can chat directly, request automations (the agent proposes a tinyflows graph you review on a canvas and save), message it over 17 channels, or enable Privacy Mode / BYO keys / a local Ollama model in settings. Developers can use pnpm dev for web-only UI work, pnpm --filter openhuman-app dev:app for the desktop shell, and run pnpm typecheck, pnpm format:check, cargo check -p openhuman --lib before a PR. Self-hosters of agentmemory can set memory.backend = "agentmemory" in config.toml to reuse an existing memory store.

Compare agents like this one

The same FARS review applied across the shortlist this agent qualifies for.

Related agents