
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
wolfpack-bridge
Advanced tools
Self-hosted browser terminal manager for AI coding agents on your own machines
Wolfpack is a self-hosted browser terminal dashboard for AI coding agents: Claude Code, Codex, Gemini, shell commands, and custom agent wrappers. It runs on your own macOS/Linux machine — laptop, workstation, or cloud VM — and gives you a PWA command center for long-running agent terminal sessions across your Tailscale tailnet.
Sessions live in a Rust PTY broker, not the web server, so server restarts and redeploys do not kill your agents. There is no Wolfpack-hosted relay or account; remote access is normally handled by Tailscale.
curl -fsSL https://raw.githubusercontent.com/almogdepaz/wolfpack/main/install.sh | bash
wolfpack
The installer downloads the right pre-built binaries for your platform, runs setup, and can install Wolfpack as a login service. Supported: macOS arm64/x64 and Linux x64/arm64.
Want npm instead?
bunx wolfpack-bridge
# or
npx wolfpack-bridge
If setup gets weird, run:
wolfpack doctor
Uninstall is explicit:
wolfpack uninstall --yes
tailscale serve for HTTPS remote access.Local-only browser use works without Tailscale. Phone/remote use is where Tailscale earns its keep.
Use Wolfpack when you want a self-hosted alternative to juggling tmux panes, SSH windows, and cloud workspaces for AI agent sessions. It is an AI agent terminal orchestrator for developers who need persistent browser/mobile access to coding agents running on machines they control.
Wolfpack starts sessions by running a command in the selected project directory. Configure commands in Settings → Agents.
| Agent | Command |
|---|---|
| Shell | shell |
| Claude Code | claude |
| Codex | codex |
| Gemini | gemini |
| Custom wrapper | any command on PATH, for example opencode or my-agent --flag |
cmd validation intentionally rejects shell metacharacters for session commands. If you need complex setup, put it in a wrapper script on PATH and add that command.
wolfpack Start the server (runs setup on first launch)
wolfpack setup Re-run the setup wizard
wolfpack ls List active broker sessions
wolfpack attach [name] Attach the local terminal to an existing session
wolfpack kill <name> Kill a session
wolfpack session ... Scriptable read/send/wait helpers for automation
wolfpack doctor Diagnose broker, binaries, JWT, Tailscale
wolfpack service ... install / start / stop / restart / status / uninstall (add --broker to include broker)
wolfpack uninstall --yes Remove everything
Direct terminal attach: docs/cli-attach.md. Scriptable session control: docs/session-control.md.
Troubleshooting: docs/troubleshooting.md.
Wolfpack is self-hosted software for machines you control. Those machines can be local laptops, workstations, or cloud VMs.
Running coding agents is intentionally powerful: those commands execute with your local user permissions in the chosen project directory. Treat Wolfpack access like shell access to that machine.
┌─────────────┐ ┌───────────┐ ┌──────────────────────────────────────────┐
│ Phone / │ │ Tailscale │ │ Your machine / cloud VM │
│ Browser │◄──►│ (HTTPS) │◄──►│ │
│ (PWA) │ │ mesh VPN │ │ ┌──────────┐ unix ┌──────────────┐ │
└─────────────┘ └───────────┘ │ │ wolfpack │ socket │ wolfpack- │ │
│ │ server │◄───────►│ broker │ │
│ │ (Bun) │ │ (Rust, PTY) │ │
│ │ HTTP/WS │ │ owns agents │ │
│ └──────────┘ └──────────────┘ │
└──────────────────────────────────────────┘
wolfpack-broker, Rust daemon. Owns every PTY, keeps per-session output rings. One Unix-domain socket per host ($XDG_RUNTIME_DIR/wolfpack-broker.sock, fallback ~/.wolfpack/broker.sock). Wire protocol in docs/broker-protocol.md.Tailscale already gates who can reach the server. If you want an extra auth layer on top — useful if you share your tailnet with others, or for defense-in-depth — set a JWT secret:
export WOLFPACK_JWT_SECRET="$(openssl rand -base64 48)"
Tokens are HS256; the server validates, it does not issue — sign them with any JWT library using the same secret.
Optional: WOLFPACK_JWT_AUDIENCE, WOLFPACK_JWT_ISSUER, WOLFPACK_JWT_CLOCK_TOLERANCE_SEC (default 30s).
~/.wolfpack/config.json (mode 0600):
{
"devDir": "/Users/you/Dev",
"port": 18790,
"tailscaleHostname": "your-machine.tailnet-name.ts.net"
}
Per-server agent settings live in ~/.wolfpack/bridge-settings.json.
Wolfpack exposes repository-local agent skills in skills/:
wolfpack-plan — plan-file task header conventions that Ralph can parse.wolfpack-ralph — Ralph loop response contract, notifications, and sandbox/socket caveats.wolfpack-tailnet-control — discover, inspect, and control Wolfpack terminal sessions across Tailscale hosts.Copy or symlink these skill directories into an agent's skill path when you want that agent to opt in. Installation/update details: docs/agent-skills.md.
See CONTRIBUTING.md for dev setup, the asset pipeline, and PR conventions.
Bugs and feature requests: GitHub Issues. Questions and ideas: Discussions.
MIT
FAQs
Wolfpack is a self-hosted control room for persistent coding-agent terminals on your own machines.
The npm package wolfpack-bridge receives a total of 74 weekly downloads. As such, wolfpack-bridge popularity was classified as not popular.
We found that wolfpack-bridge demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.