FAQ

Short answers to the questions people ask first.

Does the agent see my files?#

No. Nothing on your computer is visible inside the tank. Files cross only when you attach one or click Save. See Files in and out.

Does turning the tank off log the agent out of websites?#

No. The container is recreated each time, but the agent's home folder, including Firefox's cookies and logins, is kept on a storage volume. Logins survive restarts, reboots and updates. Only removing the deskfish-home volume erases them. See The tank.

Should I give the agent my passwords?#

Give it accounts of its own instead; that is the whole idea of the tank. If you must use one of yours, type it yourself in the Desktop tab when the agent knocks, rather than in the chat. Anything Firefox in the tank remembers, the agent may use later. See Security and privacy.

Can it solve CAPTCHAs?#

It can knock on the glass when it cannot get past a CAPTCHA. Guided mode explicitly tells it to hand these checks to you.

Does it read web pages, or only look at them?#

Both. It sees the screen as a screenshot, and on a web page in Firefox it can also ask the page itself, through a small extension in the tank, where a button or field is and what a page says. That is why it clicks the right thing more often in the browser than in the terminal or in a dialog, where only the picture is available. See How the bot sees and acts.

Can it wait for something, or do things on a timer?#

Waiting, yes. Give it a task like "send this to each address on the list, five minutes apart" or "publish the ad set and check the stats when it has finished processing", and it uses its wait_for tool: Deskfish watches the screen for it without spending steps and wakes it when something changes or the time is up, for up to two hours at a stretch. Tasks on a timer, such as every Monday at seven, are schedules: they start themselves while VS Code is open, wait for the agent if she is busy, and are reported as missed rather than run late if Deskfish was closed at the time.

Will it buy things, send messages, or delete anything?#

If you ask it to, yes, all the way through, using the accounts and saved payment methods in its tank. It hands over only for things it cannot do itself, such as a code on your phone or a card that is not saved. Some models add caution of their own: Claude usually stops at the final Pay click and asks you to press it. If you want Deskfish itself to make the agent ask before anything irreversible, set deskfish.autonomy to guided.

Which model should I use?#

Claude through the Anthropic provider clicks most accurately, because it was trained on the computer-use tool Deskfish gives it. Any OpenAI-compatible model with vision and tool calling works; bigger is better. Local models through Ollama are free and slow, and misclick more. See Models and providers.

Can I try it without an API key?#

Yes. Set the provider to mock for a scripted demo that exercises everything, including the hand-over.

Does it work on Windows and macOS?#

Yes, as long as Podman (or Docker) runs Linux containers there: Podman Desktop or podman machine on macOS, WSL 2 on Windows. The tank itself is always Linux.

Why is the first start so slow?#

Deskfish builds the tank's image on your machine from its own recipe rather than downloading a prebuilt one, which takes a few minutes and about a gigabyte of disk. Every later start takes seconds, except after an update that changes what is inside the tank, when the image is rebuilt once (mostly from cache, so faster than the first time).

Can I watch and use the tank at the same time as the agent?#

You can always watch. To use it, click Take over; the agent pauses until you hand back. See The Desktop tab.

Does it remember me between sessions?#

Yes. It keeps facts about you (preferences, things you told it, which accounts it is logged into, site quirks) in a text file you can open, edit and empty; a journal of what it did; the how-to playbooks it writes; every chat as a transcript; and a page about who it is that only it can change. The agent is instructed to keep passwords out of its memory notes; Firefox may store saved logins inside the tank. See Memory.

How do I start a new conversation?#

Click + in the title bar of the Deskfish sidebar (or run Deskfish: New Chat). The chat and the agent's memory of it are cleared; the desktop is left as it is.

Does the conversation survive a VS Code reload?#

The live conversation does not, but nothing is lost: every chat is saved as a transcript. After a reload, the clock icon in the sidebar's title bar lists past chats; open one to read it, or continue it in a new chat and the agent gets the transcript as context. Within a window, every new task continues the previous conversation.

Can the agent reach other devices on my network?#

Its traffic leaves through your machine, so a device that answers to your computer also answers to the tank, like any program you run. Normally the tank does not see your network interfaces or your machine's own localhost; on Linux that needs the passt package, and Deskfish warns you when it has to fall back to sharing your machine's network. Details in Security and privacy.

Who made Deskfish?#

Iman Reihanian, in 2026. The agent knows it too; it is in its own story and in the charter it reads every time.

Where is the full log?#

Deskfish: Show Log opens the output channel with every step of every task.

Can the agent answer questions about itself?#

Yes. Ask it anything about Deskfish, for example "where do downloaded files go?" or "what do you do when a site asks for a password?", and it reads the relevant page of this documentation before answering. It only reads when asked, so this costs nothing during normal tasks.

Is Deskfish open source?#

Yes, under the Apache License 2.0: use, modify, redistribute and sell freely, with an explicit patent grant from contributors. The name Deskfish is not part of the grant; the mascot is CC0.

Deskfish v0.1.0 · Apache 2.0Back to the little fish