JARVIS – voice-controlled AI assistant
- Year
- 2026
- Role
- Solo – design, agent, infra
- Status
- Open source · built in public
Claude agentElectronwhisper.cppPowerShellWindows Task SchedulerTelegram Bot APIREST APIs
%
Local speech-to-text
Test suites, CI 11/11
Financial actions allowed
What it is
JARVIS is a personal AI butler that runs my mornings. A voice-controlled, Iron-Man-style HUD sits on top of a scheduled agent pipeline that runs fully unattended and reports back before I wake.
The interface is an Electron HUD driven by 100% local speech-to-text (whisper.cpp), so voice never leaves the machine. Underneath, a headless Claude agent executes a daily routine against real APIs.
In July 2026 it went open source: a config-driven install with no personal values in the tree (CI-enforced), templated personality files so a fork sounds like its owner, secret-scanning CI, and adversarial-review-gated merges.
The unattended pipeline
- —Aggregates my git history, notes, job alerts, and a real bank feed (aggregates only) into a single grounded morning brief, then delivers it to my phone over Telegram at 08:30 – email optional.
- —Two-way Telegram remote: request a briefing or status from my phone, and text quick notes that surface in the next morning’s brief – with command de-duplication and at-most-once semantics.
- —Runs on Windows Task Scheduler with no human in the loop – collectors are plain PowerShell, covered by unit tests, with a burst-window cache added 2026-08-21 for the Telegram collectors.
- —Integrates a jobs REST API (Jooble) for automated role discovery, with provider fallback and rate-aware querying.
- —Opt-in Night Shift task (off by default): stages prep sheets for career triggers – interview, assessment, deadline within 48h – from already-collected local data into a vault folder. Nothing is sent, nothing is applied automatically.
- —A deferred-intents system captures "someday" utterances, verifies them in code rather than trusting the model, and resurfaces them through the existing hourly opportunity alarm.
Safety and secrets
- —Hard-coded safety rules: no financial actions, and every send is self-only – the send lock fails closed if no owner is configured.
- —OAuth token management with DPAPI-encrypted credentials at rest.
- —Failure alarms so a broken run surfaces loudly instead of failing silently.
- —The Telegram remote chat surface is pinned to Read/Glob/Grep only at the command line – Bash, Write, Edit, WebFetch, and WebSearch are explicitly denied, enforced by a structural test that fails the build if that allowlist ever widens.
- —Opt-in weekly memory consolidation (Sunday 21:00, off by default) rewrites PATTERNS.md from the trailing week of debriefs, with contradiction flags computed in PowerShell, not by the model.
Bugs caught, not hidden
- —A command-injection bug shipped and was fixed 2026-07-15: a job-alert email subject line was interpolated straight into a shell command string. Caught by an adversarial review pass – not by the test suite – and the README documents it as such rather than omitting it.
- —A kill-switch parsing bug meant the safety off-switch could silently fail to parse under certain input; fixed with composed-in-script push text so the failure mode can’t go quiet again.
- —A duplicate-command bug produced five briefings from four texts; fixed with at-most-once command consumption plus a single-flight lock, backed by table-driven near-miss tests aimed at the exact edge that broke.
- —A "lied about being late" bug had the assistant report an on-time status when a run had actually slipped; fixed with an explicit -OnDemand flag rather than papering over the report path.
- —As of v3.0.0: 25 test suites, CI green 11/11, and gitleaks run over full history – the honesty is in the paper trail, not the pass rate.