Agent skill

Desktop

by daseinlabs in daseinlabs/parsec

Route Claude Desktop's Cowork / Agent-mode traffic through the local parsec proxy so it gets curation and savings too.

MITAuto-check passed

Install Desktop

skills CLI
$ npx skills add daseinlabs/parsec --skill desktop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install daseinlabs/parsec desktop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/daseinlabs/parsec.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/plugin/skills/desktop .claude/skills/desktop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
desktop
GitHub stars
130
Token cost
~1.5k tokens
SKILL.md length
799 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Route Claude Desktop's Cowork / Agent-mode traffic through the local parsec proxy so it gets curation and savings too.

  • Works in 2 steps: It needs mitmproxy installed (brew… → It needs mitmproxy's CA trusted by the…
  • The user asks to use parsec with Claude Desktop
  • SKILL.md covers Check state first, Turn it on (first time), Day-to-day, once it is set up and Errors it returns, and what…, plus 2 more sections
  • Calls brew; reaches api.anthropic.com

What it does

Desktop is an agent skill from daseinlabs/parsec. Route Claude Desktop's Cowork / Agent-mode traffic through the local parsec proxy so it gets curation and savings too. Use when the user asks to use parsec with Claude Desktop, or to turn Desktop interception off.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent runtime optimization with Small Language Models. The licence is MIT.

When your agent uses it

  • The user asks to use parsec with Claude Desktop
  • Turn Desktop interception off

Example prompts

  • “/desktop”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. It needs mitmproxy installed (brew install mitmproxy on macOS). It is
  2. It needs mitmproxy's CA trusted by the OS. parsec never installs a root

What it can do on your machine

Read from SKILL.md and the folder at commit e97063c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.anthropic.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Desktop loads about 1.5k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 799 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from daseinlabs/parsec at commit e97063c, republished under its MIT licence (© daseinlabs). 799 words, ~1,482 tokens.

Download SKILL.mdSave it as .claude/skills/desktop/SKILL.md (or your agent's skills folder).
name
desktop
description
Route Claude Desktop's Cowork / Agent-mode traffic through the local parsec proxy so it gets curation and savings too. Use when the user asks to use parsec with Claude Desktop, or to turn Desktop interception off.

Claude Desktop has no endpoint setting — its embedded SDK is hardwired to api.anthropic.com — so parsec cannot capture it the way it captures Claude Code. The only route is process-scoped TLS interception via mitmproxy, which means this is opt-in and has two costs the user must agree to before you run anything:

  1. It needs mitmproxy installed (brew install mitmproxy on macOS). It is the one external tool parsec depends on, and only for this feature.
  2. It needs mitmproxy's CA trusted by the OS. parsec never installs a root certificate silently — it prints the exact command for the user to run.

Say both out loud before the first setup run. If the user is only asking "does this work with Claude Desktop?", answer with the scope note below and stop.

Check state first

${CLAUDE_PLUGIN_ROOT}/bin/parsec setup desktop --status

Changes nothing. It reports mitmproxy, the CA, macOS Network Extension approval, whether the addon and interceptor are in place, and the proxy port Desktop would be pointed at.

Turn it on (first time)

${CLAUDE_PLUGIN_ROOT}/bin/parsec setup desktop

Idempotent — safe to re-run after fixing whatever it complained about. It generates the CA, writes the managed addon, verifies the platform's interception mechanism is approved, restarts the proxy so it and the addon come from the same build, and starts mitmdump scoped to the Claude process only.

The restart matters: a proxy left running from an older binary does not serve /v1/models, which the addon redirects — Desktop's model picker would 404. If setup prints a WARNING: ... does not serve /v1/models, the installed binary itself is stale; tell the user to install the current build before relying on Desktop.

Flags, both off by default and both worth naming before you use them:

  • --install-ca — parsec runs the trust-store command itself instead of printing it. It will prompt for the user's password. Only pass this if the user has said yes to trusting the CA.
  • --autostart — keep Desktop routed across reboots by installing a boot service (launchd agent / systemd --user unit / Run key). Without it, the interceptor lasts until logout.

Then tell the user to quit Claude Desktop fully (⌘Q) and relaunch it — mitmproxy hooks the process at launch, so a Desktop that was already running stays unintercepted.

Day-to-day, once it is set up

Use these instead of re-running setup — they skip the CA and approval steps:

${CLAUDE_PLUGIN_ROOT}/bin/parsec desktop status
${CLAUDE_PLUGIN_ROOT}/bin/parsec desktop start [--autostart]
${CLAUDE_PLUGIN_ROOT}/bin/parsec desktop stop [--keep-autostart]
${CLAUDE_PLUGIN_ROOT}/bin/parsec desktop restart
  • status changes nothing — prefer it for any "is Desktop routed?" question.
  • restart is the fix when the routed proxy port moved; it re-renders the addon against the current port.
  • stop also removes the boot service unless --keep-autostart, so a stop stays stopped across a reboot.
Show full SKILL.md (374 more words)Show less

Errors it returns, and what they mean

  • "mitmproxy is not installed" — give them the install command it printed; nothing else has changed.
  • "Network Extension is installed but not approved" — macOS gates this. System Settings → General → Login Items & Extensions → Network Extensions → turn on "Mitmproxy Redirector". Re-run afterwards. This one matters: without approval mitmdump starts fine and captures nothing.
  • "Network Extension is not installed" — the user runs the mitmdump command it printed once by hand so macOS shows the approval prompt.
  • "mitmdump started but exited immediately" — read the tail of ~/.parsec/interceptor/mitmdump.log and report the real error rather than guessing.

If Desktop shows TLS/certificate errors after setup, the CA is not trusted — run the command --status prints.

Turn it off

${CLAUDE_PLUGIN_ROOT}/bin/parsec disable desktop

Stops the interceptor, removes the boot service and the managed addon, and prints the command to untrust the CA (it does not run that one either). Desktop goes direct again after a relaunch.

Scope note — be honest about this

This captures Cowork / Agent-mode inference — /v1/messages* plus /v1/models. Regular Desktop chat runs on a different wire (/api/*) and is deliberately untouched, as are login (/v1/oauth/*) and the Cowork bridge (/v1/environments/*) — redirecting those would break Desktop, not curate it.

The user's own credentials are never substituted: the addon sets no auth header, and the proxy forwards auth verbatim, exactly as for Claude Code. Desktop traffic is tagged x-parsec-tool: claude-desktop so its savings are separable in the ledger; that tag is dropped before anything leaves the machine.

The Code tab inside Desktop is not curated. Recent Desktop builds start Claude Code with their own ANTHROPIC_BASE_URL=https://api.anthropic.com, overriding ~/.claude/settings.json, so that traffic never reaches the proxy by the normal route. Intercepting it does not help either: the Code tab runs on Node, which ignores the macOS keychain and rejects mitmproxy's CA (the Client TLS handshake failed lines in ~/.parsec/interceptor/mitmdump.log). Tell users this plainly so they do not spend an hour chasing it; the terminal claude CLI is the curated path for Claude Code.

One thing to be straight about if asked: mitmproxy decrypts everything the Claude process sends, because it cannot know a request's host until after the TLS handshake. The addon only acts on the two Anthropic paths above, but the termination itself is process-wide. That is inherent to the mechanism.

© daseinlabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/plugin/skills/desktop of daseinlabs/parsec.

Open the folder on GitHubat commit e97063c

Compare with similar skills

Desktop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Desktop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Desktop this skilldaseinlabs/parsec130—~1.5kAutomated safety check: PassMIT
Routing Traffic With Route53 And Cloudfrontaws/agent-toolkit-for-aws2.8k—~455Automated safety check: PassApache-2.0
OmniRoute Routing CLIdiegosouzapw/OmniRoute74k—~342Automated safety check: PassMIT
OmniRoute Combo Routingdiegosouzapw/OmniRoute74k—~2.1kAutomated safety check: PassMIT
Intelligence Routeruvnet/ruflo74k—~874Automated safety check: NotesMIT
Setup Coworkasgeirtj/system_prompts_leaks69k—~3kAutomated safety check: PassCC0-1.0

Similar skills

  • Official

    Configures Amazon Route 53 to route traffic to a CloudFront distribution using a custom domain.

    2.8k GitHub stars~455 tokensUpdated today
    DevOps & CloudAuto-check passed
  • OmniRoute Routing CLI

    diegosouzapw/OmniRoute

    Creates, switches, and inspects OmniRoute model-routing combos, plus a suggestion command with cost and latency constraints.

    74k GitHub stars~342 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • OmniRoute Combo Routing

    diegosouzapw/OmniRoute

    Manages OmniRoute routing combos through its REST API: create and update combos, choose from 19 strategies, set fallback chains, test outcomes and read metrics.

    74k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Intelligence Route

    ruvnet/ruflo

    Route tasks via the 3-tier model selector and learned patterns; emits a routing rationale via hooksexplain

    74k GitHub stars~874 tokensUpdated today
    DevelopmentAuto-check: notes
  • Setup Cowork

    asgeirtj/system_prompts_leaks

    Guided Cowork setup — install a matching plugin, try a skill, connect tools.

    69k GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Configure Istio traffic management including routing, load balancing, circuit breakers, and canary deployments.

    40k GitHub starsUsed in 9 repos~1.7k tokens
    DevOps & CloudAuto-check passed

More from daseinlabs/parsec

All 8 skills in this repo
  • Login

    daseinlabs/parsec

    Sign in to Parsec so token savings show up in the user's dashboard.

    130 GitHub stars~502 tokensUpdated 3 days ago
    Auto-check passed
  • Setup

    daseinlabs/parsec

    Activate parsec — write the Claude Code routing env (ANTHROPICBASEURL → local proxy), install the savings status line, and start the proxy.

    130 GitHub stars~549 tokensUpdated 3 days ago
    Auto-check passed
  • Trim

    daseinlabs/parsec

    Stage a det+dir compaction of this session — a deterministic needed-set trim of the transcript plus a standing-directives block, injected automatically after /clear.

    130 GitHub stars~751 tokensUpdated 3 days ago
    Auto-check passed
  • Proxy

    daseinlabs/parsec

    Restart the local parsec proxy if it was killed mid-session — brings the supervisor back on the routed port so requests stop failing.

    130 GitHub stars~382 tokensUpdated 3 days ago
    Auto-check passed
  • Uninstall

    daseinlabs/parsec

    Cleanly remove parsec from this machine — undo Claude Code routing, stop the local proxy, delete downloaded models and data, then uninstall the plugin itself.

    130 GitHub stars~491 tokensUpdated 3 days ago
    Auto-check passed
  • Savings

    daseinlabs/parsec

    Show measured token savings — re-reads blocked and command loops broken by the parsec no-reread hook, from the local ledger, never estimated.

    130 GitHub stars~273 tokensUpdated 3 days ago
    Auto-check passed

Questions about Desktop

What does Desktop do?

Route Claude Desktop's Cowork / Agent-mode traffic through the local parsec proxy so it gets curation and savings too. Desktop is an agent skill from daseinlabs/parsec. Route Claude Desktop's Cowork / Agent-mode traffic through the local parsec proxy so it gets curation and savings too.

When should I use Desktop?

Desktop fits situations like: the user asks to use parsec with Claude Desktop; turn Desktop interception off.

How do I install Desktop in Claude Code?

Run `npx skills add daseinlabs/parsec --skill desktop -a claude-code`. Or copy the skill folder (packages/plugin/skills/desktop in daseinlabs/parsec) into .claude/skills/desktop in your project. Claude Code loads it when a task matches its description.

How do I install Desktop in Codex?

Run `npx skills add daseinlabs/parsec --skill desktop -a codex`. Or copy the skill folder (packages/plugin/skills/desktop in daseinlabs/parsec) into .agents/skills/desktop in your project. Codex loads it when a task matches its description.

Can I use Desktop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daseinlabs/parsec --skill desktop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/desktop, .gemini/skills/desktop, .github/skills/desktop and .opencode/skills/desktop in your project.

What does Desktop need to run?

Going by SKILL.md and its folder, Desktop needs the command-line tools its instructions call (brew).

Does Desktop access the network?

SKILL.md names 1 domain. In commands or code: api.anthropic.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Desktop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Desktop use?

Desktop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Desktop use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Desktop?

Skills that share tags, products or a category with Desktop: Routing Traffic With Route53 And Cloudfront (aws/agent-toolkit-for-aws, 2.8k stars), OmniRoute Routing CLI (diegosouzapw/OmniRoute, 74k stars), OmniRoute Combo Routing (diegosouzapw/OmniRoute, 74k stars) and Intelligence Route (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Desktop?

daseinlabs (a GitHub organization) maintains it in daseinlabs/parsec, which has 130 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: daseinlabs/parsec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.