Agents
Your own AI, running on your computer. Run an AI agent in the background and in a sandbox, and text it from your phone. It runs Link harness to start, Link's own small one, or OpenClaw or Hermes Agent, and you can switch without losing your settings, files or channels.
Needs: macOS, or Linux x86-64 with bubblewrap. A model on your computer is free; a hosted one needs an Anthropic, OpenAI or OpenRouter key, and the provider bills you.
lnk up agents # add `models` for a model on your computer
lnk agent start # pick a model, then it runs in the background
lnk agent connect telegram # or slack, discord, whatsapp, signal
lnk agent status # running and answering?Start your agent
lnk agent start
lnk agent start --model qwen3 # a model running on your computerThe first time, it asks which model your agent thinks with: one already
running on your computer, one it installs for you on an Apple Silicon
Mac, or an API key. For a model on your computer, add the
models part too (lnk up models). Your agent works in
~/Link/Agents/main/Home unless you choose another folder (--files).
It keeps running in the background, also after a restart. On a Mac it
keeps the Mac awake while it runs; --let-sleep doesn't. lnk agent stop stops it.
Text it from your phone
lnk agent connect telegram # or slack, discord, whatsapp, signallnk asks for what it needs and pairs you. From then on your agent
answers you, and only you.
- Telegram: make a bot with BotFather, paste its token, and send the
bot the code
lnkprints. - Slack:
lnkopens Slack's page for a new app, already filled in. Create it, paste its two tokens, and send the bot the code in a direct message. It needs no public address. - Discord: make an application at Discord's developer portal, turn
on its bot's Message Content intent, and paste its token. Add the bot
to a server of yours with the link
lnkgives you, and send it the code in a direct message. - WhatsApp: type the agent's number and yours, then scan the QR code from the agent's phone (Settings > Linked Devices). No business account. WhatsApp can restrict a number that runs a bot, so give your agent a number of its own.
- Signal: give your agent a number of its own, type it and yours, then scan the QR code from the agent's phone (Settings > Linked Devices).
lnk agent disconnect slack forgets a channel's tokens. The bot or app
stays yours to delete; unlink WhatsApp or Signal on the phone.
See how it's doing
lnk agent status
lnk agent logs -fstatus says whether it's running and answering, with its model, files
folder, phone and sandbox. logs -f follows what it's doing.
Switch harnesses
lnk agent use # list them
lnk agent use hermesFour harnesses: Link harness, the default, which answers you,
remembers the thread and calls the tools you give it, such as your
agent's memory; OpenClaw; Hermes Agent; and DeepSeek
Harness (lnk agent use deepseek). Your
model and key, files folder and channels come along. A harness that
doesn't speak one of your channels leaves it quiet until you switch
back. OpenClaw, Hermes and DeepSeek Harness keep their own memory and conversations; Link
harness keeps its conversations in your files folder, where every
harness's memory search finds them. Each harness has its own permissions.
Give it memory
lnk agent memory use
lnk agent memory offLink memory searches your agent's files and its conversations with
Link harness, keyless and on your computer: by words, and by meaning
once an embedding model is installed (lnk model install qwen3-embedding). Whichever harness runs your
agent reaches it as an MCP server, through its proxy, at
$LNK_MEMORY. Link harness searches it by itself: ask "what did I say
about driving to Albuquerque?" and it finds that conversation.
Run more than one agent
lnk agent new work
lnk agent list
lnk agent -a work connect telegramEach agent has its own files, harness, settings and channels, and its
sandbox keeps it out of the others' folders. With several, -a <name>
picks the one a command is about.
Choose what it can reach
lnk agent permissions # what's on, and what each opens
lnk agent allow read-home
lnk agent deny read-home
lnk agent allow host api.anthropic.com # only these hosts, then
lnk agent allow tcp github.com:22 # git over SSHYour agent reads and writes its own home and your files folder. The rest of your home folder, including your documents, your keys and Local Link's own settings, is out of its sight. It reaches the internet only through Link's filtering proxy, never your computer or your home network.
Anything more is a permission. network and developer-tools are on to
start; open, read-home, localhost and lan are off. lan gives it the network as it is, for a NAS or Home Assistant.
With a list of hosts, it reaches only those: keep its model's and its
channels' on it. A tool that needs your logins runs outside the sandbox
as an MCP server you add (lnk sandbox tool add, then lnk agent allow tool), and asks you before each call you didn't allow; OpenClaw and
Hermes find it in their own MCP settings.
Check the sandbox
lnk agent checkPlants bait, such as a secret file, a program with a secret, a spare port and on macOS a Keychain item, tries to reach each one from inside the sandbox, and tells you what got through, including the known gaps open on your computer.
See where it went, and stop it
lnk sandbox log # every call through its proxy
lnk sandbox pause main-link # cut one agent's way out
lnk sandbox resume main-link
lnk sandbox stop # cut every way out, and stop every agent
lnk sandbox stop --off # open them againThe log shows when, which agent, where to, whether it was allowed, and
the bytes each way, never what it sent. A proxy pauses its agent itself
when its calls look like no normal work, and lnk sandbox log shows
why.
Move it to a box
lnk agent move aws # to your box in aws, a new one if you have none
lnk agent move main here # and back
lnk agent exit home # on the box, reach the internet from your computerIts memory, files, settings and channels go with it. With exit home,
sites see your home address, and your agent has no internet while your
computer is off.
Back up your agent
lnk agent backup
lnk agent restorebackup copies your agent's files to your clouds, with what its harness
knows (memory, conversations, skills; never its keys), stopping it
meanwhile. restore puts back what the harness knew at that backup;
your files stay. For an agent whose machine is gone, lnk agent restore <name> brings the whole agent back from its
bucket.
Remove a harness
lnk agent show openclaw
lnk agent remove openclawshow lists where a harness lives: its home, and anything of it outside
that. remove deletes all of it, with its memory and conversations,
after asking. Your files and settings stay.
What works
- macOS, and Linux x86-64 with bubblewrap, including a server with no desktop: it keeps running after you log out.
- Three harnesses, Link harness, OpenClaw and Hermes, one running at a time per agent. Link harness keeps each conversation as files in your agent's files folder.
- A model on your computer: Link harness and Hermes work with Ollama, LM Studio, llama.cpp, vLLM and Jan; OpenClaw only with Ollama. Or a hosted model with your API key.
- Five channels: Telegram, Slack, Discord, WhatsApp and Signal, from you only: your direct messages, and your mentions in a group. Link carries all five for Link harness.
- The sandbox has known gaps with
lan:lnk agent checktells you which are open on your computer.
Every command and flag: lnk agent --help.
