nothumanallowed

Command-line and locally-run AI-agent platform with many “specialist” agents plus a REST API for invoking agents/agent chains; includes integrations for Gmail/Calendar and Outlook, a local web UI, optional voice chat, and an extensibility/plugin system. Claims “zero data” via local processing and supports LLM calls using user-provided API keys.

Evaluated Mar 30, 2026 (0d ago)
Homepage ↗ Repo ↗ Ai Ml ai-agents mcp multi-agent security cli rest-api local-first voice gmail outlook plugins
⚙ Agent Friendliness
35
/ 100
Can an agent use this?
🔒 Security
41
/ 100
Is it safe for agents?
⚡ Reliability
25
/ 100
Does it work consistently?

Score Breakdown

⚙ Agent Friendliness

MCP Quality
0
Documentation
35
Error Messages
0
Auth Simplicity
50
Rate Limits
0

🔒 Security

TLS Enforcement
70
Auth Strength
45
Scope Granularity
30
Dep. Hygiene
20
Secret Handling
35

Security posture claims are prominent (Ed25519 auth, SENTINEL WAF, “100% local”, zero deps), but the provided excerpts do not include concrete technical verification: no explicit API auth scheme for api/v1 endpoints, no documented threat model, no logging/telemetry controls, and no operational security details for the local daemon/UI. Secret handling guidance is not shown (e.g., whether tokens are ever logged). Rate limiting and output safety controls are not documented in the excerpt.

⚡ Reliability

Uptime/SLA
0
Version Stability
55
Breaking Changes
0
Error Recovery
45
AF Security Reliability

Best When

You want a CLI-first agent workflow (possibly local) plus an HTTP API for agent invocation, and you’re comfortable managing your own LLM provider keys/config.

Avoid When

You cannot verify what is truly “local” in practice (e.g., network egress/telemetry policies), or you need clearly specified rate limits, pagination, and error semantics for programmatic use.

Use Cases

  • Security auditing and threat modeling for code and dependencies
  • Automated code review and remediation planning
  • Daily ops for email/calendar/task summarization and alerts
  • Generating project documentation and content formatting
  • Local or semi-local multi-agent workflows via REST invoke endpoints
  • Integrating an agent toolkit into a custom app via HTTP calls

Not For

  • High-assurance environments without independent verification of the security model
  • Cases requiring strict, formally documented privacy guarantees (beyond the README claims)
  • Production deployments needing documented SLAs/operational guarantees
  • Organizations that require OAuth SSO or enterprise-grade RBAC/SCIM

Interface

REST API
Yes
GraphQL
No
gRPC
No
MCP Server
No
SDK
No
Webhooks
No

Authentication

Methods: API key for selected LLM provider via nha config set key <...> Telegram bot token (nha config set telegram-bot-token <...>) Discord bot token (nha config set discord-bot-token <...>) Outlook auth (nha microsoft auth)
OAuth: No Scopes: No

Auth for the described REST endpoints is not clearly specified in the README excerpts (no explicit auth headers/keys shown for api/v1 endpoints). Outlook integration suggests OAuth flow, but concrete scopes/controls are not documented in provided content.

Pricing

Free tier: No
Requires CC: No

README implies cost depends on the chosen LLM provider key you supply; no pricing tiers for the package itself are provided in the excerpt.

Agent Metadata

Pagination
none
Idempotent
False
Retry Guidance
Documented

Known Gotchas

  • README claims “zero dependencies”, but the code-level dependency/security posture is not verifiable from provided content.
  • REST auth, rate limiting, and error response schema are not documented in the excerpt; agents may fail in non-obvious ways.
  • “100% local/zero data” is a claim; actual egress depends on configuration (LLM providers, optional Whisper, browser-based voice).
  • Multi-agent orchestration costs/latency may be high without explicit controls/limits.
  • Plugins are described as having access to Gmail/Calendar/Tasks; unsafe plugin code could create security risks without isolation/sandboxing.

Alternatives

Full Evaluation Report

Comprehensive deep-dive: security analysis, reliability audit, agent experience review, cost modeling, competitive positioning, and improvement roadmap for nothumanallowed.

AI-powered analysis · PDF + markdown · Delivered within 30 minutes

$99

Package Brief

Quick verdict, integration guide, cost projections, gotchas with workarounds, and alternatives comparison.

Delivered within 10 minutes

$3

Score Monitoring

Get alerted when this package's AF, security, or reliability scores change significantly. Stay ahead of regressions.

Continuous monitoring

$3/mo

Scores are editorial opinions as of 2026-03-30.

6510
Packages Evaluated
19893
Need Evaluation
586
Need Re-evaluation
Community Powered