Chat On Steroids: a local MCP workbench that gives ChatGPT hands on your machine
Cross-platform local MCP capabilities for ChatGPT with Chrome integration, Goal, Compact & Resume, and durable multi-agent workflows.
At a glance
- What is it?
- Chat On Steroids is an Electron desktop app plus Chrome extension that exposes local MCP tools, worker chats and durable sessions to the ChatGPT you already use in the browser. It is powerful, permission-heavy and unsigned, so the decision hinges on how much of your filesystem and desktop you want a beta to touch.
- Who is it for?
- Adopt Chat On Steroids if you already pay for ChatGPT, work on a single machine you control, and want Codex-style tools (apply_patch, exec_command, write_stdin) plus worker chats without leaving the browser. Do not adopt it on a shared or managed machine, on Linux if you need computer control (the README states there is no Desktop backend there), or if your organization forbids unsigned binaries.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem: ChatGPT is a good engineer trapped in a text box
ChatGPT's developer mode lets the model call MCP servers, but the README's own framing is blunt about the usual outcome: most servers expose one narrow API. You get a single verb, not a workbench. Chat On Steroids targets the gap between a chat window and an actual development loop. The intended user is someone who already runs ChatGPT in Chrome, wants the model to read and patch files in approved folders, run commands as real processes, and keep working after the context window fills up.
The project also addresses a second, less obvious problem: continuity. Every tool call is recorded locally with its real result, and when a chat gets heavy, Compact & Resume asks the old chat for a handoff brief, opens a fresh one, and moves the same local session across. The new chat can query what the old one did. That is a different bet from simply raising a context limit. It assumes the transcript, not the model's memory, is the durable artifact.
Who it is not for is just as clear from the README. It is an Electron app that runs in the tray and hosts no model of its own, so it is useless without a ChatGPT account and a Chrome 116+ or current Edge browser for the full feature set. Without the companion extension you still get the MCP tools, but not session attribution, Compact & Resume, worker chats or the Goal loop.
How the pieces fit: Electron tray app, local MCP server, companion extension
The architecture has three moving parts. The Electron app is the host: it runs in the tray, owns the local MCP server, stores the transcript, and brokers everything else. The companion Chrome extension is the browser side: it gives the app visibility into your ChatGPT conversations, which is what makes session attribution, worker chats and the Goal loop possible. The MCP server is the contract surface the model actually calls.
The tool contracts are ports of the ones OpenAI's Codex CLI uses, which the README argues means the model already knows how to hold them. apply_patch handles multi-file patches, and the README states those are preflighted before anything is written. exec_command runs commands as real processes with interactive stdin, output budgets, and background results the model can collect later. write_stdin feeds those running processes.
Worker chats are ordinary ChatGPT conversations in your own browser, brokered by the app, so every worker is visible to you rather than hidden behind an API. One prime chat spawns a worker, hands it a task, reads its report, and can wake it again later. Multi-agent mode is on by default with two workers. A separate mechanism, session_finish, lets Astra receive the next task in the same turn without opening another model turn, and plans can be split into editable tasks or generated through a separate ChatGPT helper or the API. External MCP plugins live behind a separate connector: Settings → Plugins installs Blender MCP, Playwright, Memory and Web Fetch, and these run with their own OS/service permissions outside the approved-folder sandbox. That last sentence is the most important architectural caveat in the README.
Installing Chat On Steroids and getting the extension connected
There is no npm install for end users. The README points at the releases page, where installers are published per platform and CPU: an .exe for Windows x64 and ARM64, DMG and ZIP for macOS, AppImage and DEB for Linux. Every package ships with matching native dependencies, a pinned tunnel-client, ripgrep and the Chrome extension for that CPU. A standalone extension zip is attached for manual installs, and SHA256SUMS.txt lists every hash.
Because the builds are not publisher-signed and macOS builds are not notarized, SmartScreen, Gatekeeper or your browser will warn. The README's instruction is to verify the hash first, then use the normal run-anyway path. On Windows that is:
Get-FileHash .\Chat-On-Steroids-Setup-x64.exe -Algorithm SHA256 # WindowsOn macOS and Linux the equivalent commands are `shasum -a 256` and `sha256sum` against the DMG or AppImage. Compare the output to the entry in SHA256SUMS.txt before you launch anything.
After installing, the companion extension has to be loaded and reloaded. The 2.0.8 release note is explicit: it needs its matching companion extension, and you reload the unpacked extension after updating. If you use Edge, the README says to choose Settings → Browser & history → ChatGPT browser → Microsoft Edge, install the companion, and sign in to ChatGPT in that browser's active profile.
A fresh install is not inert. Per the README, Core capabilities start on except opt-in ChatGPT file saving, read-only mode is off, multi-agent mode is on with two workers, and on Windows the Desktop permissions start on. On macOS they start off; you enable them in Settings → Workspace and then grant Screen Recording and Accessibility in System Settings. The first real use, then, is not a command but a review: open Settings, look at the approved folders, and decide whether read-only mode should be on before you connect the extension.
The AppImage sandbox fallback and other real limitations
The most concrete failure mode documented in the README concerns Linux packaging. The AppImage uses electron-builder's static launcher, and on a host that disables unprivileged user namespaces, that launcher can fall back to starting Chromium with --no-sandbox so the app still opens. The README does not hide this; it tells Debian and Ubuntu users to prefer the DEB if they do not want that fallback. If you are running an AppImage on a hardened host and you did not notice the fallback, you have a weaker sandbox than you think.
Desktop control is uneven by platform. Linux has Core tools but no Desktop computer-control backend at all, so screen-related features are simply absent there. On Windows the Desktop permissions start on, which is the opposite default from macOS. Those defaults matter more than they look, because exec_command runs programs as your logged-in user. Folder approval is a boundary for the built-in tools, not a container.
External plugins sit outside that boundary entirely. The README states that external servers run with their own OS/service permissions, outside the approved-folder sandbox. Installing Blender MCP or Playwright through Settings → Plugins therefore widens the trust surface beyond what the folder list implies. The permission model is a set of switches plus read-only mode as a single kill switch, and it depends on you actually flipping them.
Finally, the update story is split. Windows and AppImage installs check GitHub for a newer release on start and every six hours, download it, verify its checksum and apply it when you quit or choose Install update, with staged downloads revalidated before installation. macOS and DEB installs link to the release page for manual installation. If you are on a Mac, you are the update mechanism.
How it differs from Claude Desktop, Cursor and plain MCP servers
The closest comparison is an editor with built-in agent tooling, such as Cursor. Cursor owns the editor, the model routing and the tool loop, and it works on the files you have open in a project. Chat On Steroids owns none of that. It keeps your existing ChatGPT subscription and browser session, and instead of an editor it gives the model a process-level toolset: apply_patch, exec_command, write_stdin, plus worker chats that are real browser conversations you can watch. The trade is that you depend on a Chrome extension and a desktop app staying in sync, which is exactly why the 2.0.8 note tells you to reload the unpacked extension.
Against a plain MCP server, the difference is scope and durability. A typical server exposes one API surface and forgets everything when the conversation ends. Chat On Steroids records every tool call locally with its real result and can carry that session into a fresh chat via Compact & Resume. It also adds a plugin layer for other MCP servers, so it can act as a broker rather than a replacement. The cost is a much larger trusted computing base: an Electron app, a browser extension, a tunnel-client, ripgrep and native dependencies, all shipped in one installer, none of it publisher-signed yet.
Against Claude Desktop's MCP support, the distinction is which assistant you are extending and how much desktop control you are handing over. Chat On Steroids is explicitly ChatGPT-first and adds Desktop permissions on Windows by default. That is a deliberate choice in favor of capability over caution, and it should be read that way.
Maintenance, licensing and what an upgrade actually costs
The repository is not archived, and the last push was on 2026-09-10, a week before this writing. Releases are frequent and closely spaced: v2.0.6 on 2026-09-06, v2.0.7 on 2026-09-07, v2.0.8 on 2026-09-08, and package.json on main reads 2.1.13. Frequent releases cut both ways. Fixes arrive quickly, and so does churn. The 2.0.8 note about reloading the unpacked extension after updating is the practical shape of that churn: desktop app and extension are versioned together, and a mismatch is a real failure mode.
The licence is MIT, which is permissive and imposes no copyleft obligation on your own code. That is a statement about the repository's licence file, not legal advice, and it does not cover the bundled third-party components. The repository carries a THIRD-PARTY-NOTICES.txt and a script that checks it (verify:notices), which suggests the maintainers are tracking bundled dependencies deliberately. It also ships a generated notice file rather than asking you to infer the dependency licences yourself. If you redistribute the app inside an organization, that file is where to start.
Upgrade cost depends on platform. Windows and AppImage users get automatic checksum-verified updates and can largely ignore the process. macOS and DEB users must download and install manually, which means the extension reload step is easy to forget. For anyone building from source, the verify:ci script chains ripgrep fetching, a privacy check on public history, notice generation checks, typecheck and two vitest passes, so a local build is not a one-command affair.
Editorial conclusion
Adopt Chat On Steroids if you already pay for ChatGPT, work on a single machine you control, and want Codex-style tools (apply_patch, exec_command, write_stdin) plus worker chats without leaving the browser. Do not adopt it on a shared or managed machine, on Linux if you need computer control (the README states there is no Desktop backend there), or if your organization forbids unsigned binaries. Before connecting, verify three things yourself: the SHA256 hash against SHA256SUMS.txt, the folder list under Settings, and whether read-only mode is on. The app is a beta with real permissions, and exec_command runs programs as your logged-in user.
Frequently asked questions
What does Chat On Steroids actually do?
It is a desktop chat workspace and local MCP server that gives ChatGPT tools to read, patch and run code in folders you approve, plus worker chats and sessions that survive a context reset. The README describes it as giving ChatGPT hands on your computer while you remain the permission boundary.
How do I install Chat On Steroids?
Download the installer for your platform and CPU from the releases page: an .exe for Windows, DMG or ZIP for macOS, AppImage or DEB for Linux. Verify the file against SHA256SUMS.txt first, since the builds are not publisher-signed and macOS builds are not notarized.
Does Chat On Steroids work without the Chrome extension?
Partly. The README states that without the companion extension you still get the MCP tools, but not session attribution, Compact & Resume, worker chats or the Goal loop.
Is Chat On Steroids safe to run?
The README calls it a beta with real permissions: read-only mode starts off, multi-agent mode starts on with two workers, and on Windows the Desktop permissions start on. It also warns that exec_command runs programs as your logged-in user, so review folder access before connecting.
Which platforms does Chat On Steroids support?
Windows 10/11, macOS 13 Ventura or newer, and current desktop Linux, on x64 or ARM64 matching the build you downloaded. Linux has Core tools but no Desktop computer-control backend, according to the README.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/totec448-spec-chat-on-steroids)