Independent AI intelligence Two editions daily · ET
Fervor AI

Analysis · October 6, 2026 · repo

amontlabs/lcuCodex computer useChatGPT desktop appagent-harnessclaude-codecodexagent-security

lcu Puts Codex Computer Use Inside Claude Code, on a Runtime You Don't Own

amontlabs/lcu lifts OpenAI's desktop-control engine out of the Codex app and hands it to Claude Code, Codex CLI and Pi. The permission design is careful. The dependency underneath it is the part to think about.

The best computer-use engine on your laptop might already be installed, sitting inside an app you opened for something else. That is the premise of amontlabs/lcu, a project whose one-line description reads "Codex computer use, decoupled from the Codex app." It takes the runtime that lets Codex click, type and read the screen, and wires it into whichever agent harness you actually work in.

It went from v0.8.9 on October 4 to v0.9.6 on October 6, with eight tags in its releases feed across those three days, and it sat at #23 on Trendshift this afternoon. The timing is pointed. The same day v0.9.6 shipped, OpenAI published a post about advancing computer use with Ironclad. Computer use is becoming a product line, and lcu is a bet that the engine matters more than the app it ships in.

I think the bet is half right. The engineering is thoughtful, especially the permission model. The foundation is something lcu does not own.

What lcu actually does

lcu is a CLI and a set of harness adapters, not a model and not an MCP server. Per the README, "LCU exposes Codex's original computer-use runtime to your harness without requiring Codex authentication," but "the official ChatGPT desktop app must still be installed locally: it supplies the runtime and instructions, while LCU handles setup and harness integration." The desktop tools read windows, click, type and take screenshots.

The supported harnesses are Pi, Codex CLI and Claude Code, with experimental support for Oh My Pi and Hermes. On Claude Code the install is two lines through the plugin manager:

claude plugin marketplace add amontlabs/lcu
claude plugin install lcu@lcu

The manual route downloads a platform archive from the releases page (darwin-arm64, linux-arm64 or linux-x64) and runs setup for your harness:

~/.local/share/lcu/current/bin/lcu setup --agent claude-code

Requirements are specific. You need the official ChatGPT desktop app, Python 3.12 or newer, and your harness. On macOS that means Apple silicon and "the signed ChatGPT app, with Accessibility and screen-recording permissions." On Linux it means an Ubuntu 24.04-compatible glibc system, an active X11 desktop and D-Bus. Intel Macs, native Wayland and musl Linux are unsupported, and Windows 11 is deferred. The project is MIT licensed.

The permission design is the best part

Most computer-use wrappers I have read treat permission as a single yes or no: either the agent can drive your desktop or it cannot. lcu splits it in two, and says so plainly: "Your harness decides whether the agent may call LCU's tools... LCU decides, per app, whether that agent may touch it."

Layer one is your harness's normal tool approval. In Claude Code, that is the same approval flow you already use for shell commands.

Layer two is per-app approval, enforced "in every permission mode." The first time an agent tries to control an app, the runtime asks you to allow it, and for Claude Code lcu setup --agent claude-code installs a small mod, lcu-approve, that shows the question as a native "Computer use approval" pane in the Claude app and in the terminal, with Allow this conversation, Always allow and Deny. It needs the Claude app or Claude Code 2.1.287 or later. The README's key line is this: "Only you can answer: the model cannot see, press or fake the pane." The approval dialog lives outside what the agent can see or click, so a model cannot approve itself into a new app. lcu also refuses some apps outright. Apps that "Computer Use refuses outright (Terminal, iTerm2) are declined," and "browsers, password managers and other high-risk apps come with a warning." The README adds that "the app hosting the agent is never approved," which closes the obvious loop of an agent clicking around in its own host app.

You manage the allow list from a /computer-use-apps panel inside Claude Code or from the command line, and on macOS allowing or revoking an app asks for Touch ID or your password:

lcu apps
lcu apps allow Zed
lcu apps revoke Zed

There is also an unattended mode, and the README is careful about it. "lcu setup --approval auto is optional and meant for unattended machines (VMs, CI): it pre-allows LCU's two model tools in the harness, and leaves per-app approval in force." Auto mode removes the harness prompt, not the per-app gate. That is the right default, and it is rarer than it should be.

Why this matters past one repo

Computer use has mostly lived inside the vendor's own app. You got desktop control in Codex, or browser control in a vendor's extension, and the capability came bundled with that vendor's harness, approvals and billing. lcu shows the engine can be separated from the harness by a third party in a few days of releases.

That changes the shopping question for builders. If the engine travels, you can pick your harness for its other strengths (Claude Code's hooks, Pi's audio support, Codex CLI's workflow) and still get the desktop control you liked elsewhere. It also means the guardrails you rely on are now split across three parties: the harness vendor, the lcu maintainers and OpenAI's runtime.

Put this into practice

If you want to try lcu without regretting it, start narrow.

  1. Install it on a machine you can afford to lose. A spare Mac or a Linux VM with X11 is the right first home. Accessibility and screen-recording permissions on your main laptop are broad grants.

  2. Allow one app, not ten. Pick a single app that matters to your workflow, such as an editor or a design tool, and run lcu apps allow for that one. Leave browsers and password managers off the list even though lcu only warns about them.

  3. Keep harness approvals on during the first week. Skip --approval auto until you have watched the agent work. Use it later only on a VM or CI box, which is what the README says it is for.

  4. Pin a version. With eight tags in three days, behavior can change between your morning and afternoon. Note the version you tested and update deliberately with lcu update.

  5. Read OpenAI's terms for the ChatGPT app. lcu's README is blunt: "The OpenAI app and its instructions come from your local installation and retain their own terms." Running OpenAI's runtime under a Claude Code session is a use OpenAI did not design the app for. Decide whether you are comfortable with that before you build anything on it.

Honest limitations

You do not own the runtime. lcu depends on the runtime in your ChatGPT desktop install. The README says lcu "checks the installed app for compatibility," which is good, but a check that fails after a ChatGPT update still leaves you without desktop control until lcu catches up. You would find out the morning a workflow stops.

The terms belong to someone else. OpenAI's terms still apply to the runtime, and lcu cannot change them. If OpenAI decides that driving its runtime from another vendor's harness is out of bounds, there is nothing in this repo to stop that.

Your screen goes to your harness's model. Taking screenshots is one of the desktop tools, and as far as I can tell from the README those images go back to whichever model your harness runs, whether that is Claude, a Codex model or something in Pi. The README does not spell out that path. For anything involving client data on screen, answer that question before you start, not after.

Platform coverage is narrow. Apple silicon or a specific Linux setup with X11, Windows 11 still a "candidate," nothing on Wayland, and Codex CLI needs an update before setup to get the hook support lcu requires.

Chrome is experimental. The README says "Claude Code's Chrome support remains experimental because some interruptions do not trigger tab cleanup." Leftover tabs from an interrupted agent are a small mess on a test machine and a bigger one on a work profile.

It is days old. About 640 stars, a release cadence measured in hours, and no track record. Careful design on day three is a good sign. It is not the same as a year of people breaking it.

The engine is portable now. The trust is not.

lcu answers a question many builders have been circling: can computer use live outside the app that ships it? Yes, and with more thought about permissions than plenty of first-party tools show.

What it cannot answer is whether the foundation will hold. The runtime, its updates and its terms all belong to OpenAI. If you try lcu, try it the way you would try any borrowed tool: on a spare machine, with one app allowed, a pinned version, and a plan for the day it stops working.

Sources: amontlabs/lcu README and releases (v0.9.6, October 6, 2026); OpenAI, Advancing computer use with Ironclad (October 6, 2026); Trendshift daily board, read about 15:08 ET.


Medium metadata

  • SEO title: lcu: Codex Computer Use in Claude Code and Any Agent Harness
  • Meta description: amontlabs/lcu decouples Codex computer use from the Codex app for Claude Code, Codex CLI and Pi. How its two-layer permissions work, how to install it safely, and why the ChatGPT runtime dependency matters.
  • Tags: Claude Code, OpenAI Codex, AI Agents, Computer Use, Open Source
  • Canonical: import from the fervorai.dev URL