nanoMuse:同一个 Agent 装在你的所有设备上

nanoMuse: One Personal Agent Across All Your Devices

Tech-Experiment #Agent#多设备#Android#开源#本地AI
🇨🇳 中文

云端 Agent 有一条硬边界:只能碰到有 Web 界面或公开 API 的服务。银行 App、政务 App、企业内网工具——这些东西云上够不着。

nanoMuse 的解题思路是:把 Agent 放到你的设备本地,通过屏幕操控(Hands)绕过 API 缺失的限制,同时让你的所有设备共享同一段对话。

GPL-3.0,466 stars,浙江大学团队,2026-10-09 发布 v1.0.0。

GitHub: https://github.com/nano-muse/nanoMuse | arXiv: https://arxiv.org/abs/2610.08699


多设备共享一个 Agent

nanoMuse 的核心设计:每台设备本地跑一个 Agent,通过 Relay 中继同步同一段会话。登录同一账号的手机、电脑、网页端共享同一 Chat,可以用 @Mac 帮我打开 XXX App 看一下账单 这样的方式把任务发到指定设备上执行。

平台状态
Android 8.0+(arm64)正式发布,Hands 屏控可用
iPhone / iPadTestFlight Beta,Hands 不可用
Windows 10+(x64)正式发布
macOS 12+(Apple Silicon + Intel)正式发布,未公证
Linux x64AppImage / .deb / .tar.gz
Web 浏览器demo.nanomuse.dev
Dockerghcr.io/nano-muse/nanomuse:1.0.0

Android 版的关键技术

APK 内打包了一个完整的 Alpine Linux(通过 proot),含 shell、浏览器、MCP、Skills、定时任务,完全本地运行,不依赖外部容器。

屏控 Hands 通过 Android 无障碍服务驱动,可以操作任何 App 的界面——这是云端方案物理上做不到的。

限制:目前只支持 arm64 架构。


Relay:会话中继的隐私边界

Relay 负责两件事:账号注册和设备间会话文本传输。重要的区分:

  • 会话文本经过 Relay(如使用社区 Relay,则文本经过第三方服务器)
  • 文件和截图不经过 Relay,只留在执行任务的本地设备上

如果对隐私要求高,可以用 scripts/self-host.sh 或 Docker Compose 自托管 Relay,会话文本就完全在自己控制的服务器上。


Sentinel:不可撤销操作要确认

nanoMuse 内置 Sentinel 安全层:删除、发送、支付等不可撤销操作在执行前会主动征询用户确认,不会 Agent 自己就直接跑完。

这是 Agent 全自动操作真实 App 时的关键安全机制——工具调用结果没法 Ctrl-Z。


模型:完全自带

nanoMuse 不绑定任何模型提供商:

  • 带自己的 API Key(OpenAI、Anthropic 等)
  • 或者连接本地 Ollama 实例
  • 社区 Relay 有限量免费额度(Relay 会提供基础模型访问),额度耗尽后需自备

Memory 即 Markdown 文件

身份配置、用户偏好、唤醒计划均以 Markdown 文件存储在本地,用户可以直接读写。没有私有格式,没有数据库,改起来透明。


已知边界

  • iOS 屏控 Hands 暂不可用(TestFlight 阶段)
  • Android 只支持 arm64,Linux 只支持 x64
  • macOS 未通过 Apple 公证,首次需右键 → 打开
  • 不支持图片/视频模态的模型 Provider 会关闭对应功能
  • 论文(arXiv 2610.08699)没有 Benchmark 实验数据,优势是理论分析而非量化验证
  • 使用社区 Relay 时,会话文本经过第三方服务器

和云端 Agent(Muse 类产品)的核心区别

云端 Agent(如 Meta Muse)nanoMuse
App 覆盖有 Web/API 的服务任意 App(通过屏控)
数据流转所有操作在云端虚拟机文件/截图留本地
多设备云端单点每台设备本地跑,Relay 同步
模型选择厂商绑定BYO Key/Ollama
自托管不可Relay 可自托管

一句话说清楚

nanoMuse 把一个本地 Agent 同时部署到你的手机、电脑、平板和浏览器上,多设备共享同一段对话,Android 屏控可以操作没有 API 的封闭 App,Relay 可自托管,GPL-3.0。iOS 屏控暂不支持,整体仍是 v1.0 早期阶段。


GPL-3.0。浙江大学 Guangyi Liu、Yong Liu、Jiangning Zhang,v1.0.0”Keel”,2026-10-09 发布,arXiv 2610.08699。开源仅供学习参考。


🇬🇧 English

nanoMuse: One Personal Agent Across All Your Devices

Cloud agents have a hard boundary: they can only reach services with web interfaces or public APIs. Banking apps, government apps, enterprise internal tools — the cloud can’t touch them.

nanoMuse’s approach: put the Agent on the device itself, use screen-control (Hands) to work around the missing API layer, and let all your devices share a single conversation thread.

GPL-3.0, 466 stars, Zhejiang University team, v1.0.0 released 2026-10-09.

GitHub: https://github.com/nano-muse/nanoMuse | arXiv: https://arxiv.org/abs/2610.08699


Multi-Device, One Agent

Core design: each device runs a local Agent instance, synchronized through a Relay to share the same session. Devices logged into the same account (phone, PC, web) share one Chat. You can direct tasks with @Mac check the balance in XXX app to route execution to a specific device.

PlatformStatus
Android 8.0+ (arm64)Released, Hands (screen control) works
iPhone / iPadTestFlight Beta, Hands unavailable
Windows 10+ (x64)Released
macOS 12+ (Apple Silicon + Intel)Released, not notarized
Linux x64AppImage / .deb / .tar.gz
Web browserdemo.nanomuse.dev
Dockerghcr.io/nano-muse/nanomuse:1.0.0

Android: What’s Inside the APK

The APK ships a full Alpine Linux instance (via proot) — shell, browser, MCP, Skills, cron tasks, all running locally without an external container.

Hands uses Android accessibility services to operate any app’s UI — something that is physically impossible for a cloud agent to do.

Limitation: arm64 only.


Relay: The Privacy Boundary

The Relay handles account registration and session text relay. Important distinction:

  • Conversation text passes through Relay (community Relay = third-party server)
  • Files and screenshots stay on the local device that executed the task

Privacy-sensitive deployments: self-host the Relay with scripts/self-host.sh or Docker Compose — conversation text never leaves your servers.


Sentinel: Gating Irreversible Actions

nanoMuse has a built-in Sentinel security layer: delete, send, payment actions require explicit user confirmation before executing. The Agent doesn’t just run to completion unattended.

This is the essential safety mechanism for an Agent operating real apps — there’s no Ctrl-Z for tool call results.


Model: Fully BYO

No vendor lock-in:

  • Bring your own API key (OpenAI, Anthropic, etc.)
  • Connect to a local Ollama instance
  • Community Relay provides a limited free model quota; quota depletes → need your own key

Known Limits

  • iOS Hands not available (TestFlight stage)
  • Android arm64 only, Linux x64 only
  • macOS not notarized (right-click → Open on first launch)
  • Image/video modalities disabled if chosen model provider doesn’t support them
  • Paper (arXiv 2610.08699) has no benchmark experiments — theoretical analysis only
  • Community Relay: conversation text goes through third-party servers

TL;DR

nanoMuse deploys a local Agent across phone, PC, tablet, and browser simultaneously, sharing one conversation thread. Android screen-control reaches any app without an API. Relay is self-hostable. GPL-3.0. iOS screen-control not yet available; overall still early (v1.0).


GPL-3.0. Zhejiang University, Guangyi Liu, Yong Liu, Jiangning Zhang. v1.0.0 “Keel”, released 2026-10-09. arXiv 2610.08699. For reference only.

💬 评论与讨论

使用 GitHub 账号登录后发表评论

关于本站 · 免责声明

🍄 Mushroom Research Blog 是非营利、免费公开的个人科技观察博客与公众号 XStack18,不接受商业合作、不代表任何企业或机构立场,也不谋求商业利益。我们以个人视角客观中立地记录和分析 AI、Web3 等领域的最新模型发布与技术动态——不止转述新闻标题或二手信息,而是给出有独立思考的深入分析,希望帮更多人获得有价值的一手科技认知。

⚠️ 文中介绍的开源代码与模型,仅供学习交流与技术借鉴。它们大多仍处于早期阶段,有待进一步研究和验证,请勿直接用于工作或生产环境;如需采用,请先自行充分测试,并核实其许可证与安全性。
Open-source code and models featured here are shared for learning and reference only. Most are early-stage and still need further study and verification — please don't use them directly in your work or in production. Test them thoroughly and check their licenses and security first.

  1. 本站文章均为作者基于公开信息的个人研究与观点整理,不代表文中提及的任何公司、产品、模型的官方立场,未与其构成商业关联或合作关系。
  2. 科技行业信息更新极快,我们尽力保证内容准确、及时,但不对完整性、实时性做绝对保证,具体请以相关企业/项目官方公告为准。
  3. 文中引用的第三方商标、产品名称、图片、数据等版权归原权利人所有,我们会尽量注明来源;如你认为存在版权疑问或侵权,请通过下方邮箱联系我们,收到通知后会尽快核实处理(更正、加注来源或删除)。
  4. 文章内容仅为技术科普与个人观点,不构成投资、法律或其他专业建议,据此进行任何决策的后果需自行判断和承担。

📮 侵权 / 勘误 / 合作咨询:[email protected]