Open Minis 是一款开源的端侧 AI 智能体,在手机沙盒中运行 Linux 环境,可操作文件、浏览器及原生应用,适合追求安全可控的移动端自动化用户。
热门评论
PH 用户
Hi Product Hunt 👋
I built Open Minis because every “AI assistant” on my phone could talk about my data but never actually touch it. The apps that could act were locked to one vendor’s model and one company’s cloud.
So Minis takes the opposite bet. The agent gets a real Alpine Linux sandbox running on the iPhone itself — an ARM64 fork of iSH on iOS, PRoot on Android. It has a filesystem, a package manager, Python, git, ffmpeg. On top of that, 30+ native offloads expose Apple frameworks as ordinary command-line tools, so the model reaches HealthKit or HomeKit the same way it reaches ls. Turns out models are very good at CLIs.
Three principles:
Local-first. Your keys and data stay on-device. No account, no telemetry, no server of mine in the path. Bring your own model. Claude, GPT, Gemini, DeepSeek, Kimi, Grok, OpenRouter, or anything OpenAI-compatible. Open Source, all of it, iOS and Android.
It’s free with no IAP. I’d genuinely love to hear where it breaks for you — the roadmap is mostly built out of issues people file.
PH 用户
the cli bet is the interesting part and i think it is right, models are genuinely good at command lines. what it costs you is that a command line does not tell the model what a command costs.
ls and rm are the same shape until you read the name. a health read and a home unlock are both just tools in a namespace. so the surface encodes capability and not effect, and effect is what you would actually want to gate on: does this read, does this write, does it move something in the physical world.
gal's question above is about reach. mine is about what happens after it reaches. no server in the path removes the leak risk and it also removes the log. if it does something dumb at 2am there is no server side record to reconstruct what it ran, and that is the half of no telemetry that never makes the slide.
are the 30+ offloads classified by effect anywhere, or is it one flat namespace where reading step counts and unlocking a door look identical to the model?
PH 用户
Local-first is doing some heavy lifting on this page. Keys and files stay on the phone, but the second the agent reads HealthKit and drops it into a prompt, that data is sitting on someone's inference server, and it's whichever provider the user picked rather than one you can vouch for. That's still a better story than every cloud wrapper, it just isn't no server in the path, and the people who care about that distinction are exactly who you're selling to. I'd say it plainly on the page: on-device execution, remote reasoning.
PH 用户
Giving the agent a real local shell instead of another chat layer is a great direction. Python, git, ffmpeg, and the native bridges make it feel genuinely useful on a phone, not just impressive in a demo. How do you handle permissions and approval when a task touches sensitive areas like HealthKit, Photos, or HomeKit?
I built Open Minis because every “AI assistant” on my phone could talk about my data but never actually touch it. The apps that could act were locked to one vendor’s model and one company’s cloud.
So Minis takes the opposite bet. The agent gets a real Alpine Linux sandbox running on the iPhone itself — an ARM64 fork of iSH on iOS, PRoot on Android. It has a filesystem, a package manager, Python, git, ffmpeg. On top of that, 30+ native offloads expose Apple frameworks as ordinary command-line tools, so the model reaches HealthKit or HomeKit the same way it reaches ls. Turns out models are very good at CLIs.
Three principles:
Local-first. Your keys and data stay on-device. No account, no telemetry, no server of mine in the path.
Bring your own model. Claude, GPT, Gemini, DeepSeek, Kimi, Grok, OpenRouter, or anything OpenAI-compatible.
Open Source, all of it, iOS and Android.
It’s free with no IAP. I’d genuinely love to hear where it breaks for you — the roadmap is mostly built out of issues people file.
ls and rm are the same shape until you read the name. a health read and a home unlock are both just tools in a namespace. so the surface encodes capability and not effect, and effect is what you would actually want to gate on: does this read, does this write, does it move something in the physical world.
gal's question above is about reach. mine is about what happens after it reaches. no server in the path removes the leak risk and it also removes the log. if it does something dumb at 2am there is no server side record to reconstruct what it ran, and that is the half of no telemetry that never makes the slide.
are the 30+ offloads classified by effect anywhere, or is it one flat namespace where reading step counts and unlocking a door look identical to the model?