- Never act: the reply is Claude with every tool off.
- Bots never answer bots.
Your Claude bot and your friend's, in one iMessage chat; they can only answer.
Pre-alpha. The self-test passes; the first live round trip between two Macs has not happened yet.
GitHub Read the security model first
- youJarvis: what's the capital of Peru
- Lima.
- 🎵 polyrhythm · Jarvis · C♯ A E♭ G
- friendall: one word for a Monday
- Coffee.
- 🎵 polyrhythm · Jarvis · C♯ A E♭ G
- Survival.
- 🎵 polyrhythm · Ada · F D♯ G♭ A♭
Jarvis is yours and Ada is your friend's. Each posts from its owner's Apple ID and ends with its own sign-off, which is how a bot knows not to answer the other.
What it does
- Answer-only. By default your bot replies through Claude Code with every tool, MCP server and setting off. It talks and does nothing else.
- Bots ignore bots. A line that ends in a bot's sign-off is never a command, so the bots cannot talk to each other, or to themselves.
- Commands by name, from either of you.
Jarvis: …is for Jarvis,all: …for both. Anything else in the chat is between the two of you. - One chat, the one you already have. The 1:1 thread with your friend, or a group chat once a third person joins.
How it stays yours
- Your bot runs on your Mac, logged in to your Claude account. Nobody's bot runs on anybody else's login.
- It reads one chat. A line that is not for a bot is never logged, filed or shown to a model. It keeps each command and your bot's reply, one file per command, and a log of them all, in its own folder, readable only by you.
- Nothing leaves your Mac but your bot's replies in the chat and the command text it sends to Claude.
- macOS grants Full Disk Access to one small launcher you can read, never to
python3. Full Disk Access is still the whole disk. - Your friend can trigger your bot and spend your usage. 20 answers an hour, and 6 replies in a row with no human line, are the backstops.
- Give the reply command tools and anyone in the chat can steer them. The default has none; the security model says what changing it hands over.
Read polyrhythm-host.c
SECURITY.md
Read the launcher before you grant it anything. It is short on purpose.
Install, in three of seven steps
- Clone into a folder that stays put, and check.
git clone https://github.com/220labs/polyrhythm.git "$HOME/polyrhythm" && cd "$HOME/polyrhythm" && python3 polyrhythm.py check - Settings, then install.
cp .env.example .env, fill in the lines the README names (the other bot's name and sign-off among them), thensh install.sh: it builds the launcher and loads a launchd job. - Grant the launcher, not Python. Full Disk Access and Automation → Messages, for
polyrhythm-hostonly.
All seven steps, the settings, and what each permission is for: the README. You need macOS with the Command Line Tools, Claude Code logged in, and a friend who does the same.
Code
github.com/220labs/polyrhythm · MIT · hello@220labs.dev · pre-alpha