English · Русский
Cookie Code is a zero-token-cost AI Agent for your desktop.
It embeds the DeepSeek web chat into a native Electron window, injects a side overlay, and turns the chat into a local executor: the AI is prompted to emit tool calls (JavaScript code blocks), which are intercepted, confirmed, executed in a local sandbox, and streamed back to the AI. No API key, no token billing — you use your regular web account.
Web chats are great at thinking, but they cannot act on your machine. Cookie Code closes that loop:
- Zero token cost — everything goes through the DeepSeek web UI, no API calls.
- Real agent loop — Think → Act → Observe → Repeat. File I/O, code search, shell commands, database queries, MCP tools.
- Native desktop shell — Electron wrapper with its own overlay panel, theming, and settings.
- The AI emits tool calls as JavaScript code blocks (```cuckoo).
- Each call is intercepted, previewed, and executed in a sandboxed Node context.
- Results are streamed back into the chat as a system message.
- Non-zero shell exits (
[exit code: N]) are highlighted in red under the corresponding tool block.
Every cuckoo block in the chat is decorated into a collapsible card with the tool name, file hint, and execution time:
- ▼ icon + tool name (Read / Write / Edit / Bash / Glob / Grep / PowerShell / Todo / WebFetch / MCP / MySQL / …)
- File hint derived from the first argument
- Click to expand/collapse
- Red style + warning icon when the execution failed
The same applies after page reload — the styles are restored from localStorage.
Tool execution can be gated behind explicit user confirmation (Settings → Cookie Code → Agent & Privacy):
- Off — tools run automatically (previous behavior).
- Risky only — confirmation is requested for dangerous tools (
bash,pwsh,write,edit,deleteFile,mysql,webFetch,injectJS,mcpCall, …). Read-only tools (read,glob,grep,todo, …) run without asking. - All calls — every tool call and every ```cuckoo JS block asks first.
Each pending call shows a modal card with the tool name and a params/code preview. Buttons: Deny (Esc), Approve (Enter), and Always allow <tool> (remembered for the current page session only). Denials are reported back to the AI through the regular tool-result channel with an explicit "do not retry" instruction, so the agent waits for your guidance instead of looping.
Clean chat (hidden service messages)
Service traffic — tool result payloads, JS result digests, the initial system prompt, XML-format hints — still reaches the AI, but is no longer displayed in the chat window:
- After being sent, such user messages are automatically hidden in the DOM (
.cuckoo-hidden-msg), leaving only the real conversation visible. - Tool results are shown inline: each ```cuckoo tool call card gets a collapsible Result section right below the call code — expand the card to see the raw output (
✓ Result), execution error (`⚠ Execution error`) or a user denial (`⛔ Denied by user`). Results survive page reloads (persisted in `localStorage`) and re-attach to their cards automatically. - Messages remain in the DOM (just
display: none), so history parsing, reload restoration, and AI context detection keep working. - Hidden messages are re-hidden after page reloads via a lightweight observer + periodic rescan.
- Toggle in Settings → Cookie Code → Agent & Privacy → Hide service messages in chat (applies instantly, no reload needed).
Under each AI reply you get an automatic badge:
⏱ 5.2s · ~380 tok
- Real response time measured from stream start to completion
- Estimated token count (
chars / 4) — a rough approximation - Persisted in
localStorage, restored on reload
27 hand-picked wallpapers shipped with the app. Pick from a preview grid in Settings → Cookie Code:
Change instantly, no reload required.
Full control over the font of the Cookie Code UI and the DeepSeek page:
- System font by default — nothing forced
- Built-in Anthropic Mono — one-click choice
- Your own fonts — drop files (
.ttf/.otf/.woff/.woff2) into<userData>/fonts(button "Open fonts folder") and click "Refresh" — the font appears in the preview grid - Weight slider (100–900) — works for both the system font and any custom font
- Pick from a preview grid in Settings → Cookie Code; applies instantly to the whole UI and the page
All settings persist in cuckoo-settings.json (font, fontWeight).
Full control over the UI glass effect:
- Background blur (0–30 px)
- Header blur & sidebar blur
- Header / sidebar / tool-block opacity
- Tool-block glass blur
All settings persist in cuckoo-settings.json.
The username in the sidebar has an animated rainbow gradient (enabled by default). Toggle it in Settings → Cookie Code → Effects.
Control and monitor Cookie Code from your phone:
- Tool notifications — every tool call (success/failure, name, arguments, result) is sent to your Telegram chat. For
edit, the new code is shown (up to 2000 chars). - AI replies — every AI text response is mirrored to Telegram (human-readable text, code blocks stripped).
- Incoming messages — send a message to the bot and it lands in the DeepSeek chat as if you typed it.
/todoscommand — get the current task list of the active window from Telegram./help— full command reference straight from the chat./settings— interactive settings menu with inline buttons. Every Cookie Code option is editable from your phone: appearance (customization toggle, RGB username, UI language), glass & panel (blur, opacity, width, colors), agent & privacy (tool approval mode, hide service messages, auto-formatters, file chips, produced files, dangerous-pattern list), and the Telegram bot itself (token, chat ID, notification toggles). Wallpapers are intentionally excluded./cancel— abort a pending text input when editing a value.- All-done notification — when every task in the list becomes
completed, the bot sends a one-time "🎉 All tasks completed" message (fires again after the list changes). - Lightweight, dependency-free client (long-polling, no VPS or webhook needed).
- Configured in Settings → Cookie Code → Telegram bot (token from @BotFather + chat ID), or right from Telegram via
/settings.
No Electron system menu — the app opens straight into DeepSeek. All standard keyboard shortcuts (Ctrl+C/V, Ctrl+R, F12) still work.
Continue a long chat in a new one without losing progress:
- "Transfer context" button in the Cookie Code panel
- The current chat history is read from the DOM and the AI compresses it into a structured summary (goal, decisions, changed files, open questions)
- A new chat opens automatically and the summary is injected as context — work continues from the same point
- Long histories are auto-trimmed by token estimate
Pick a project directory once — the AI receives the directory tree and a system prompt tailored to the real project. Every tool call then resolves paths relative to that directory.
Claude Desktop-compatible configuration format. Supports both stdio and http MCP servers. Manage servers and tools from the overlay panel.
Drop a folder into .cuckoo/skills/<name>/ with a SKILL.md (and optional tool.js) and it becomes callable via skillList, skillLoad, skillExecute.
Every write and edit runs the file through a language-specific formatter so the AI's output matches your project's style automatically — no manual prettier --write step, no style noise in the diff.
Built-in formatters:
| Formatter | Trigger | What it needs |
|---|---|---|
prettier |
.js .jsx .ts .tsx .json .css .md .yaml … |
prettier in the nearest package.json + binary in node_modules/.bin or PATH |
biome |
same as prettier | biome.json / biome.jsonc in the project |
gofmt |
.go |
gofmt in PATH |
ruff |
.py .pyi |
ruff in PATH + [tool.ruff] in pyproject.toml (or ruff.toml) |
rustfmt |
.rs |
rustfmt in PATH |
shfmt |
.sh .bash |
shfmt in PATH |
clang-format |
.c .cpp .h … |
.clang-format config + clang-format in PATH |
- Detection is config-aware: ruff won't run in a project without a
[tool.ruff]section; prettier won't run without apackage.jsondependency. No unexpected reformatting of foreign code. - Formatter errors are swallowed — a failed formatter never blocks
write/edit. - Disable with
"formattersEnabled": falseincuckoo-settings.json.
Login state, projects, and settings are stored under %APPDATA%/cuckoo-ai-pro-session (Windows) or the equivalent userData path on macOS/Linux.
- Node.js >= 16.0.0
- npm
# Clone
git clone https://github.com/merfiDEV/Cookie-code.git
cd Cookie-code
# Install dependencies
npm install
# If npm blocks the electron postinstall (allowScripts), approve it:
# npm install-scripts ls
# npm install-scripts approve electron
# npm install
# Start
npm start# Windows installer (NSIS)
npm run build:win
# Portable
npm run build:win:portable
# macOS DMG
npm run build:mac:dmg- Launch the app — it opens straight into DeepSeek.
- Log in with your regular DeepSeek account.
- Click Initialize project and pick a directory. The AI now has access to the directory tree and the system prompt.
- Chat with the AI. Ask it to edit files, run commands, search the codebase, etc.
- Tool calls in the AI's reply are intercepted, previewed in the overlay, and executed.
- Results are sent back to the AI automatically, and the loop continues.
The AI emits a block like this:
```cuckoo
const content = await read("src/index.js");
log(content);
```Cookie Code intercepts it, executes it in a sandbox, and returns the result to the AI.
| Tool | Description |
|---|---|
read, readLines |
Read files (with line numbers, offset/limit) |
write, edit |
Create / modify files (auto-formatted on save — see below) |
deleteFile |
Delete a file |
glob, grep |
File search (ripgrep-backed) |
bash, pwsh |
Execute shell commands |
todoWrite |
Structured task list |
webFetch |
Fetch HTTP(S) content as Markdown |
mysql |
Run SQL queries |
mcpCall, mcpListServers, mcpGetTools |
MCP tools |
skillList, skillLoad, skillExecute |
Custom skills |
openBrowserWindow, injectJS |
Electron browser window + JS injection |
Full TypeScript declarations are shipped at tools/cuckoo-tools.d.ts.
Cookie Code is built to be reshaped: swap wallpapers, tune the glass effect, change the accent color, write your own skills, or extend the tool set.
Everything visual lives in Settings → Cookie Code and persists in cuckoo-settings.json:
- Backgrounds — 27 built-in wallpapers, or drop your own image into
src/ui/backgrounds/and register it inregistry.json. - Glass effect — background / header / sidebar blur, opacity, and tool-block glass blur.
- Fonts — system by default, built-in Anthropic Mono, or your own fonts from a folder; weight slider (100–900). Applies to both the UI and the DeepSeek page.
- RGB username — animated rainbow gradient in the sidebar, toggled under Effects.
- Desktop pets (chubriks) — perch a sprite right on the message input field: it sits on the top edge, rides along as the field moves, can be dragged with the mouse and resized by the corner handle. The anchor point is stored in field-relative fractions, so the pet stays in place across any resolution or zoom level.
- Custom sprites — drop PNG/GIF files into
<userData>/pets/and they instantly appear in the picker grid inside Settings. The Upload… button accepts any image and auto-resizes it down to 600×600. - GIF background removal — if a GIF has a white (or any other) background, open the editor (the 🎨 BG button on its preview) and click the eyedropper on the unwanted color. The background disappears in every frame, the animation stays intact.
- Debug mode (F8–F11) — fine-tune the pet placement: F8 — aim (click a point), F9 — input field debug frame, F10 — switch docked / free mode, F11 — reset size. Toggled in Settings.
- Optional approval gate for tool calls (off / risky tools only / all calls), configurable in-app or via Telegram
/settings - 30 s command timeout, 60 s sandbox timeout
- 1 MB output buffer
- Editable dangerous command blocklist (rm -rf /, format, diskpart, …) — regex patterns, changeable from the Settings tab or via Telegram
- Auto-formatters run only when the project config requires them (config-aware detection) and never block
write/edit - File paths confined to the project directory
User settings live in cuckoo-settings.json under the app's userData directory:
{
"background": "miku",
"backgroundBlur": 0,
"font": "system",
"fontWeight": 400,
"headerBlur": 12,
"sidebarBlur": 12,
"headerOpacity": 45,
"sidebarOpacity": 45,
"toolBlockOpacity": 55,
"toolBlockBlur": 0,
"rgbUsername": true,
"formattersEnabled": true,
"toolApprovalMode": "off",
"hideSystemMessages": false,
"fileChipEnabled": true,
"showProducedFiles": true,
"language": "ru",
"telegramEnabled": false,
"telegramBotToken": "",
"telegramChatId": "",
"telegramNotifyTools": false,
"telegramChatFeed": false
}All settings are editable from Settings → Cookie Code inside the app.
src/
├── main/ Electron main process
│ ├── index.js App bootstrap, window creation
│ ├── ipc.js IPC handlers
│ ├── settings-store User settings (cuckoo-settings.json)
│ ├── profile-manager Per-window profiles
│ ├── session-store Session ↔ project dir mapping
│ ├── mcp-client MCP SDK integration
│ ├── skill-manager Skills loading
│ ├── format-registry Built-in formatters (prettier/biome/gofmt/ruff/...)
│ ├── formatter Auto-format hook for write/edit
│ ├── window.js Window registry
│ └── ...
├── preload/
│ ├── api.js contextBridge → electronAPI
│ ├── index.js Init & wiring
│ ├── i18n/
│ │ └── i18n.js RU/EN translations, `t(key, params)` helper
│ ├── dom/ DOM parsers & observers
│ │ ├── observer.js Main reply observer
│ │ ├── tool-render.js Inline tool blocks
│ │ ├── response-meta.js ⏱ badge under replies
│ │ ├── settings-tab.js Cookie Code tab in Settings
│ │ ├── background.js Wallpaper & blur engine
│ │ ├── context-port.js Chat context transfer
│ │ ├── fonts.js UI & page font engine
│ │ └── ...
│ └── overlay/ Overlay panel UI
│ ├── template.js buildOverlayHTML() + OVERLAY_CSS
│ ├── diff-panel.js Git changes / history panel
│ └── todo-panel.js Floating task list
├── providers/
│ └── deepseek.js Platform adapter
├── ui/
│ ├── backgrounds/ 27 wallpapers + registry.json
│ ├── fonts/ Built-in fonts (Anthropic Mono)
│ └── logos/
tools/ Tool implementations (run in main process)
└── cuckoo-tools.d.ts Type declarations for the AI
botsrc/ Telegram bot integration (dependency-free)
├── telegram.js Long-polling Telegram client
└── index.js Settings, notifications, chat feed











