Skip to content
RepoRanker
spinabot

spinabot/brigade

Credits + grant $14LibraryLive in production

Brigade - Your personal intelligence, built enterprise-grade

Brigade — Your personal intelligence, built enterprise-grade

★11.3k▲ 11224 since joining⑂ 68TypeScriptPush 4d agoListed 3mo ago33 open issuesMIT

www.brigade.spinabot.com

agent-runtimeaiai-crewautonomous-agentsbrigadebrigade-agentchatgptclawdbot
  • TypeScript98.9%
  • JavaScript0.5%
  • Python0.2%
  • PowerShell0.2%
  • Shell0.1%
View on GitHub

$14

$13.20 from converted credits; $0.80 granted by RepoRanker. Credits and grants are not card payments. This placement does not expire. Its rank holds until another repo spends more, and then this one moves down, never off. Taking the top of the board from here costs $4.

Report a problem

4 Reviews

JavaTypeScriptPython

Brigade is a substantial local-first AI agent system with far more depth than its landing page alone suggests. Its TypeScript codebase separates the gateway, terminal interface, model providers, Tideline memory, tools, channels, schedules, skills, and subagent coordination into clear modules. Support for multiple model providers, local Ollama endpoints, MCP, document processing, and optional connectors makes the project unusually flexible. Engineering discipline is also strong: strict type checking, hundreds of colocated test files, isolated test state, CI across two Node versions, release automation, CodeQL, dependency review, and custom supply-chain checks. The detailed README, changelog, contribution guide, MIT license, and security policy make the repository approachable despite its size.
The security documentation deserves particular credit for defining an honest single-operator trust model. It clearly states that extensions run as trusted code, shell approvals are guardrails, and the gateway is not a multi-tenant security boundary. That clarity conflicts somewhat with repeated “enterprise-grade” wording, which can imply stronger user isolation and administrative controls than Brigade currently provides. The prominent claim that keys and data never leave the machine also needs refinement. Brigade does not operate a telemetry service, but prompts and other data necessarily reach configured cloud model providers, Composio integrations, or Cloudflare when those features are used.
The public tunnel implementation thoughtfully keeps the gateway on loopback and places a token-checking proxy in front of it. Still, full access links place the token in the URL, where browser history and URL logs may expose it. Short-lived pairing tokens or header-based authentication would reduce that risk. The Cloudflare provider also appears to download the latest cloudflared binary automatically without checksum or signature verification, so pinning and verifying that executable would strengthen the supply chain. Finally, macOS and Windows CI smoke tests would better support the documented cross-platform claims, while making OSV findings enforceable above a chosen severity would complement the existing detection workflow. Overall, Brigade shows impressive scope, active maintenance, and unusually thoughtful engineering, with its largest opportunities centered on tightening a few security and privacy claims around an already capable implementation .

Brigade is a substantial local-first AI agent system with far more depth than its landing page alone suggests. Its TypeScript codebase separates the gateway, terminal interface, model providers, Tideline memory, tools, channels, schedules, skills, and subagent coordination into clear modules. Support for multiple model providers, local Ollama endpoints, MCP, document processing, and optional connectors makes the project unusually flexible. Engineering discipline is also strong: strict type checking, hundreds of colocated test files, isolated test state, CI across two Node versions, release automation, CodeQL, dependency review, and custom supply-chain checks. The detailed README, changelog, contribution guide, MIT license, and security policy make the repository approachable despite its size.
The security documentation deserves particular credit for defining an honest single-operator trust model. It clearly states that extensions run as trusted code, shell approvals are guardrails, and the gateway is not a multi-tenant security boundary. That clarity conflicts somewhat with repeated “enterprise-grade” wording, which can imply stronger user isolation and administrative controls than Brigade currently provides. The prominent claim that keys and data never leave the machine also needs refinement. Brigade does not operate a telemetry service, but prompts and other data necessarily reach configured cloud model providers, Composio integrations, or Cloudflare when those features are used.
The public tunnel implementation thoughtfully keeps the gateway on loopback and places a token-checking proxy in front of it. Still, full access links place the token in the URL, where browser history and URL logs may expose it. Short-lived pairing tokens or header-based authentication would reduce that risk. The Cloudflare provider also appears to download the latest cloudflared binary automatically without checksum or signature verification, so pinning and verifying that executable would strengthen the supply chain. Finally, macOS and Windows CI smoke tests would better support the documented cross-platform claims, while making OSV findings enforceable above a chosen severity would complement the existing detection workflow. Overall, Brigade shows impressive scope, active maintenance, and unusually thoughtful engineering, with its largest opportunities centered on tightening a few security and privacy claims around an already capable implementation.

PythonJavaScriptTypeScript

An ambitious multi-agent ecosystem that brings together isolated agents, shared memory, model switching, scheduled tasks, messaging, MCP, and external integrations. The local-first approach, separate workspaces, configurable permissions, and credential isolation make it especially compelling for developers who want more control over autonomous workflows.

The main weakness is that the security and reliability story could be more concrete. A formal threat model, permission matrix, credential-isolation diagram, backup and restore guidance, and clearer failure scenarios would significantly improve confidence. Overall, it feels best suited to technical users comfortable managing permissions and infrastructure, while its broad feature set may be unnecessary for someone seeking a simple AI assistant.

114634550211463455022mo ago
TypeScriptPythonShell

Brigade offers an ambitious self-hosted agent ecosystem: isolated agents arranged in an organization, shared long-term memory, model switching, scheduled work, messaging channels, MCP, and many external connectors. The emphasis on local ownership, approval for privileged actions, separate workspaces and credentials, and a choice between filesystem and self-hosted database storage is compelling. Tideline’s provenance-aware shared memory is particularly interesting for multi-agent coordination.

Because Brigade can act across messages, files, credentials, and scheduled jobs, its security and reliability documentation should be as concrete as its feature list. A formal threat model, connector permission matrix, backup and restore procedure, credential-isolation diagram, and failure-mode examples would materially improve trust. Signed releases and a prominent manual installation path would also complement the convenient installer. Brigade is best for technical users who want to operate an extensible, self-hosted agent system and are prepared to administer permissions carefully; it may be unnecessarily broad for someone seeking a simple chat assistant.