# uniTerm packs 30 protocols and an AI agent into one desktop app, and the agent can write its own skills

> A Go and Vue terminal client that speaks SSH, Telnet, Mosh, serial, RDP, VNC, SFTP, SMB, WebDAV, S3, eight database engines, and four container runtimes, with a sidebar agent that plans multi-turn shell commands and executes them in your active tab. The parts to read before you trust it are the four execution modes, the most permissive of which is called Bypass, and the self-update path.

**ys-ll/uniterm** — A lightweight all-in-one terminal with 30+ protocols — SSH, RDP, SFTP, databases, Kubernetes and more. With a built-in autonomous AI Agent that plans and runs multi-turn shell commands.

- Repository: https://github.com/ys-ll/uniterm
- Website: https://uniterm.net
- Stars: 636 · Forks: 89
- Language: Vue
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/ys-ll-uniterm

## Thirty protocols, and the Gitee mirror sits under a different account name

The coverage is organised by category rather than listed flat. Terminal access covers SSH, Telnet for legacy devices, Mosh for high-latency links, serial ports with configurable baud rate, data bits, stop bits, parity and local echo, raw TCP that transceives plain bytes on a socket, local shells including PowerShell, CMD and Git Bash, and WSL. File transfer adds SFTP, SCP as the fallback for servers that do not support SFTP, FTP and FTPS, SMB, WebDAV, S3, and Zmodem through rz and sz. Remote desktop is RDP, VNC, SPICE for KVM and QEMU guests, and X11 forwarding. Databases number eight, from MySQL and PostgreSQL through Oracle and SQL Server to Redis, MongoDB, Elasticsearch and rqlite. Containers are Kubernetes, Docker, Podman, nerdctl and WSLC. A server monitor reads CPU, memory, disk, network, processes, ports and interfaces live.

## Four execution modes, and the most permissive one is called Bypass

The agent is described as autonomous: it plans, executes, observes results, and iterates across several rounds of shell commands without manual intervention. That autonomy is bounded by a four-position execution mode control, and the names are worth reading carefully because they are ordered by how much the agent can do to your machine. Bypass is the most permissive. Dangerous only narrows it to commands the tool classifies as dangerous. Dangerous plus write adds ordinary write operations. Confirm all asks every time. A sidebar chat carries the conversation against an Anthropic or OpenAI-compatible API, supporting Claude, GPT and other compliant models, and history is saved per session so it survives a restart. Commands execute in whichever terminal tab is active, or in a pinned tab if you choose, and split panes each keep their own terminal context.

## The agent can save new skills to itself

Skills and commands are a first-class part of the interface. Reusable skill workflows and prompt-template commands attach to the AI input with a slash, the same convention the terminal itself uses, and there is a second mechanism layered on top of that: the agent can save new skills itself. That is the feature to think hardest about, because it means the set of procedures the agent will follow is not fixed by the application version. A skill written during one session persists into later ones, which is convenient for a repetitive task and is also a persistence mechanism you did not choose deliberately. Alongside it sits smart completion, which offers real-time suggestions from your own command history and rewrites typed commands with the model while you are in an SSH terminal. Together they mean the tool learns your shell habits in both directions.

## Cloud sync pushes encrypted settings into a repository you host

Settings can be synchronised without a server belonging to the project. The mechanism is your own decentralised private repository, on GitHub, GitLab, or Gitee, with the settings encrypted before they leave the machine and synchronised automatically, so the project claims no data loss and no leak while running its own infrastructure. That is a defensible design for a tool holding connection definitions, and it has a consequence worth stating: your configuration history lives in a repository you own, so access control and retention are your repository's settings rather than the application's. The rest of the personalisation layer is local. The connection manager groups, searches, creates and batch-operates server entries. Split panes are made by dragging tabs into the content area, with edges dragged to resize and rearrange. Keybindings are fully rebindable. There are 28 terminal themes, three interface themes, a custom background image, and a nine-language interface.

## The desktop shell is a Wails v3 beta, with two PTY implementations

The stack is visible in the manifest rather than described in prose. The Go module targets a specific toolchain patch and depends on a Wails v3 release that is still labelled beta, which is the shell that binds the Go backend to the Vue frontend. Terminal handling is split by platform rather than abstracted once: a Windows pseudo-console library on one side and a Unix PTY library on the other, with per-platform application files for Windows, macOS and Linux. Authentication reaches beyond passwords and keys. Windows SSPI and a Kerberos library are both present, along with SSH agent support and an SSH config parser, so a corporate environment with ticket-based auth is a considered case. An operating-system keyring library is also in the list, which is where connection secrets would go if you use them. Oracle and SQL Server are reached through pure Go drivers, so those two do not need a client library installed.

## The app updates itself and also speaks the Model Context Protocol

Two dependencies change how you should think about operating this application. The first is a self-update library, backed by a dedicated autotest file for the update path, which means new versions arrive without you downloading an installer by hand. The second is the official Model Context Protocol Go SDK, and the source tree has a module for MCP alongside a notification module with a platform-specific variant. So uniTerm is not only a client of agent tooling; it is a server of it, which is what lets an external agent drive sessions here. Both facts together mean the trust surface is larger than a terminal client of similar size suggests: the binary can rewrite itself, and the same process exposes an interface other programs can drive. Neither is documented as a security consideration in the feature list.

## Windows-only paths are marked in the table rather than the prose

Platform limits are recorded where you would look them up, which is the right place. In the protocol table, RDP is annotated as Windows only, as is WSL, while SSH, Telnet, Mosh, serial and raw TCP carry no such note. Several entries describe the reason a protocol exists rather than just naming it: Telnet is for legacy devices and embedded systems, Mosh is for high-latency or intermittent networks, SCP is the fallback for SSH servers without SFTP, SPICE is for KVM and QEMU virtual machines, and rqlite is described as a lightweight distributed database built on SQLite with Raft consensus. The release history shows the same care and one loose end: alongside versioned tags there is an Android technical preview tag dated 2026-09-18, sitting between two patch releases without a version number of its own.

## The name already belongs to a company and a bibliographic index

Worth knowing before you invest in it: this project competes for its own name. Searches for the term return a South African manufacturing business with branches in Durban and Cape Town, a Nigerian company, and a uniterm indexing system used in library science, where questions about who introduced it and what it means outrank anything about terminals. The repository itself mirrors to two hosts, GitHub and Gitee, which helps reach users who cannot reach one of them, though the Gitee account carries a shorter name than the GitHub organisation. The badge row under the title carries five links with nothing between the brackets, and the GitHub repository link appears twice. None of that affects the software, and all of it affects whether anyone finds it.

## Conclusion

Use it if you carry several kinds of remote access in one window, since consolidating protocols is the clearest reason it exists and the protocol table is specific enough to check against what you actually run. Two decisions belong to you before first use. Set the agent's execution mode deliberately rather than inheriting the default, because the most permissive option removes confirmation entirely. And decide how you want settings synced before you connect anything sensitive, since cloud sync pushes encrypted configuration into a git repository you host yourself.

## FAQ

### What protocols does uniTerm support?

Terminal access over SSH, Telnet, Mosh, serial, raw TCP, local shells, and WSL; file transfer over SFTP, SCP, FTP, FTPS, SMB, WebDAV, S3, and Zmodem; remote desktop over RDP, VNC, SPICE, and X11 forwarding; eight database engines including MySQL, PostgreSQL, Oracle, SQL Server, rqlite, Redis, MongoDB, and Elasticsearch; and containers through Kubernetes, Docker, Podman, nerdctl, and WSLC.

### What execution modes does the uniTerm AI agent have?

Four, ordered by how much the agent can do: Bypass, dangerous only, dangerous plus write, and confirm all. The agent plans, executes, observes results, and iterates across multiple rounds of shell commands on its own, running them in the active terminal tab or in one you pin.

### How does uniTerm cloud sync work?

Settings are encrypted and synchronised automatically through your own decentralised private repository, on GitHub, GitLab, or Gitee. Nothing runs on infrastructure belonging to the project, which means access control and retention for your configuration are governed by your repository settings.

### What is uniTerm built with?

A Go backend with a Vue frontend, joined by a Wails v3 desktop shell that is still on a beta release. Terminal handling uses separate pseudo-console and PTY implementations for Windows and Unix, and the module targets a specific Go toolchain patch.

### Does uniTerm have an Android version?

There is a release tagged android-tech-preview-1, titled Android Technical Preview 1, dated 2026-09-18, sitting between versioned patch releases. It is presented as a technical preview rather than a numbered release.

## Sources

- [License: Apache-2.0](https://github.com/ys-ll/uniterm/blob/main/LICENSE)
- [Project website](https://uniterm.net)
- [README](https://github.com/ys-ll/uniterm/blob/main/README.md)
- [Releases](https://github.com/ys-ll/uniterm/releases)
- [ys-ll/uniterm on GitHub](https://github.com/ys-ll/uniterm)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ys-ll-uniterm
