Runs on your Mac
Nimrobo has a macOS app. Point it at one number you own. The agent tries a change, checks whether the number moved, and keeps what worked.
macOS 12+ · Apple silicon and Intel · Sign in with ChatGPT Plus or Pro, or bring your own API key
Why can't I just ask ChatGPT?
You can, and it will give you ten good ideas. It will even remember the conversation. What it never learns is the result. Nobody tells it which ideas you shipped, or whether the number moved. So next month you get the same ten ideas, with the same confidence.
So you accumulate output. Never knowledge.
Nimrobo solves this.
The agent does the work. The harness keeps score.
Point Nimrobo at one number. Every run, it reads back what its earlier runs proved and disproved about that number, decides what's worth trying next, and states what it expects before it acts. The real result settles that prediction and joins the record the next run reads from.
- north star + trend
- guardrails
- open experiments
An agent on your Mac, on a leash you hold.
The agent runs shell commands on your Mac. Three separate settings decide how far it can go on its own: which files and networks a command can reach, how often it stops to ask you, and how fast you can kill it. You set all three.
What can any one command actually reach?
By default, almost nothing outside the folder you point it at. Reaching further is a ladder: every rung up costs an approval.
Outcome folder + /tmp · network blocked · secrets sealed
Writes anywhere · network open · secrets still sealed
Full machine access · your approval on every call
Not a promise the model makes: a macOS Seatbelt profile the kernel enforces.
Sandboxed commands run inside Seatbelt, Apple's own OS sandbox. A blocked write fails at the operating system, not because the agent chose to behave. A project config can widen a run's room but can't un-protect your secrets, and sudo, rm -rf /, and sandbox escapes are blocked outright.
How closely do I have to watch it?
A separate setting from the sandbox: one you move, from fewest-approvals to approve-everything to read-only.
Switch mid-run and it reaches subagents already running, not just the next one.
Can I get in its way while it's running?
At any second. It's never a black box you have to wait out.
Steer
Type while it's running. It picks you up at the end of the current step, not after the whole turn finishes.
It asks you
When a call is yours, it stops and asks. Dismiss it and the turn halts.
Stop
One button aborts the run and kills the process group.
Start with the number you own.
An outcome loop needs a number you can move and can measure. Four templates ship ready to run, each one naming the metric, the system it is read from, and the line it will not cross to move it.
The fine print, without the fine print.
Only capacity. Nothing in the harness is gated. Free is $0/mo with 1 active outcome, 500 data-credits (one-time), and $3 of Gemini credits (one-time). Starter is $5/mo with unlimited outcomes, 2,500 data-credits a month, and $3/mo of Gemini credits. Plus is $20/mo with unlimited outcomes, 10,000 data-credits a month, and $15/mo of Gemini credits. Create a project past your limit and it’s kept but locked: nothing is deleted, and it unlocks the moment you upgrade or drop back under.
Nimrobo is macOS-only. The shell sandbox that confines what a run can touch is built on macOS Seatbelt, and we won’t hand an agent an unconfined shell.
Yes. Sign in with a ChatGPT Plus or Pro account and you don’t need an API key.
Only if you let it. Every run has a mode (Default, Manual, or Plan) and any action that reaches past the sandbox stops at an approval: Deny, Allow once, Allow this run, or Always allow. Escalations ask every single time, with no permanent allow.
Your outcome folders, runs, sessions, artifacts, reward snapshots, and model provider credentials stay on your Mac. Model prompts go to the provider you chose; account and plan checks and the skills catalog reach our servers. Google Analytics and Search Console are the exception: those read-only connections are brokered by us, so the Google token rests encrypted in our database and GA4 and Search Console responses pass through our server on the way to the agent. Git push happens only if you add a remote yourself.
No. A coding agent does the work inside Nimrobo; Nimrobo is the structure around it: the number you’re trying to move, the record of what past runs proved and disproved, and the verdict on every prediction. A coding agent finishes a task and stops. Nimrobo checks whether the task moved the number, then uses the answer to choose the next one.
An outcome project is one number and everything the agent has learned about moving it, kept in a git-tracked folder on your Mac. A lever is a kind of change that might move it: pricing, onboarding copy, email timing. A hypothesis is a prediction registered before a run: this change, this much, this soon, for this reason. An experiment tests one hypothesis and returns a verdict: supported, refuted, or inconclusive. Every verdict stays on the record.
It’s a local-first, single-machine app with no built-in collaboration. Outcome loops are just git-tracked folders, so pushing one to a shared remote is how people share them.
Start your first outcome.
Pick one number. Nimrobo works on it every day and builds the record of what actually moves it.
macOS · Apple silicon and Intel · No credit card