
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
A cat that babysits your AI agent so you don't have to. While Claude works, the cat sits on your terminal; when you're needed, the cat gets up.
A cat that babysits your AI agent, so you don't have to.
While Claude works, a real kitten sits on your terminal and keeps watch.
The moment you're needed — permission prompt, question, done — it rears up, meows, and steps aside.
One kitten, one continuous take — not a sprite sheet (see the FAQ for how it was made). By default catsit never touches your input; --guard is opt-in.
Full-quality kitten in kitty · Ghostty · WezTerm · iTerm2 — every other terminal gets the lo-fi living cat.
One continuous performance, one kitten — every transition connects.
| agent starts working walks in, settles down ![]() | still working sits and waits — if the cat is calm, you're not needed ![]() | 60s without your input curls up for a nap ![]() |
| you touch a key wakes up the slow way: yawn, stretch, sit ![]() | you're needed rears up with a meow (+ terminal bell) ![]() | steps aside walks off — an empty screen means it's your turn ![]() |
npx catsit --demo
Run it in kitty, Ghostty, WezTerm, or iTerm2 to meet the full-quality kitten. Anywhere else (Terminal.app, VS Code, tmux…) you get the lo-fi half-block version — same cat, chunkier pixels.
npx catsit claude
That's the whole setup. No config files, no hooks, no permissions to grant.
Agents made us babysitters. You can't look away — it might need a permission right now — so you sit there, watching a spinner, guarding a process that doesn't need you 95% of the time.
catsit inverts the notification. The cat's presence is the signal:
| The cat... | means |
|---|---|
| 🐈 walks in and sits down | the agent is working. You're not needed. Go do something else. |
| 😴 curls up asleep | you've been away a while. Still handled. |
| 🥱 wakes up with a yawn | you touched a key — it noticed, that's all. |
| ❗ rears up, meows, steps aside | permission prompt / question / finished — your turn. |
If you can see the cat, you can ignore the terminal. That's the deal.
By default catsit is watch-only: typing, message queueing, steering mid-task — every keystroke reaches your agent exactly as it would without catsit. The cat is pure signal.
--guard: gatekeeper mode (opt-in)Want the cat to actually stop you from micromanaging? catsit --guard claude:
🐟 hell…), so a blocked key
never looks like a bug. The first catch comes with a hint:
guarding · ctrl+g to shoo.ctrl+c, ctrl+d, esc, arrows, every control key — always pass
through instantly, even in guard mode.ctrl+g shoos the cat away for the rest of the session.| Terminal | You get |
|---|---|
| kitty, Ghostty, WezTerm, iTerm2 3.6+ | a real kitten — one continuous filmed performance floating above the text (kitty graphics protocol): it walks in, sits down, waits, rears up in a meow, and walks off |
| everything else (incl. tmux, VS Code, Terminal.app) | the same living kitten in chunky truecolor half-blocks — lo-fi, but it still walks, naps, and meows |
NO_COLOR / dumb terminals | a humble kaomoji (=˘ω˘=) |
catsit wraps your agent in a PTY and forwards every byte verbatim, while
mirroring the screen into a headless terminal (@xterm/headless).
When the cat is visible, each output flush becomes one atomic
repair → app bytes → cat → cursor restore batch inside a synchronized
update — the cat and the app can't corrupt each other, and nothing ever leaks
into your scrollback.
Working / needs-you state is fused from two channels: screen patterns
(ported from ccmanager's
production-tested detectors, MIT) and the Claude Code session transcript
(~/.claude/projects/…), whose turn_duration record is the reliable
"turn ended" signal. Permission prompts are detected from the screen itself.
Two runtime dependencies. Node 20+. macOS & Linux.
catsit <command> [args...] wrap any agent CLI (claude today; more soon)
catsit --demo bundled fake agent, for trying it out (guard on)
--guard gatekeeper mode: the cat swallows typing while
the agent works (ctrl+g shoos it)
--no-cat no overlay at all
--quiet no bell when the cat gets up
Is that a real cat? It's one continuous AI-generated performance (Kling) of one kitten on a green screen that doesn't exist — every state was generated with its first frame pinned to the previous state's last frame, so it never cuts, teleports, or slides. Details in assets/cat-frames/CREDITS.md.
Why "catsit"? The cat sits on your terminal, and it cat-sits your agent.
Can I still queue messages while Claude works? Yes — the default mode
never intercepts input, so typing-to-queue and steering work untouched.
--guard exists precisely for when you want to be stopped.
Codex / Gemini CLI / opencode? Planned — the detector is an interface, and the transcript channel is Claude-specific but optional. PRs welcome.
Windows? Not yet (ConPTY port planned).
Does it slow the agent down? Compositing costs ~0.1 ms per frame and nothing at all while the cat is off screen.
The "cute thing physically intervenes" mechanic was inspired by Cat Gatekeeper by ZOKUZOKU — a giant cat that blocks your doomscrolling. catsit is an independent project; different cat, different problem: it guards the agent, from you.
The kitten itself is an AI-generated continuous performance (Kling), cut into seamlessly chained beats — see assets/cat-frames/CREDITS.md. Terminals without graphics support play the same beats from a pre-baked low-res grid (half.bin) as half-block cells.
MIT © JinHyuk Sung
FAQs
A cat that babysits your AI agent so you don't have to. While Claude works, the cat sits on your terminal; when you're needed, the cat gets up.
The npm package catsit receives a total of 44 weekly downloads. As such, catsit popularity was classified as not popular.
We found that catsit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.