Fewshell: A Self-Hosted SSH Copilot That Refuses to Run Commands Without Human Approval

Fewshell is a collaborative, self-hosted mobile+desktop SSH copilot designed for on-calls, DevOps, MLOps, AI researchers, sysadmins, and self-hosting enthusiasts. Its core design principle: AI will never run any command without human approval. There is no setting to enable command auto-approval – by design, to eliminate any risk of accidental misconfiguration.
Why It Exists
The author, an ex-Amazon Sr. SDE for Alexa AI now working on AI safety research for agentic RLVR, created Fewshell after seeing high-profile incidents where an AI agent deleted a production database. The tool is intended to be the opposite of an autonomous agent. Use cases include:
- Quickly restart, fix, or update an autonomous agent (e.g., OpenClaw) remotely, without using the agent itself (e.g., if it fails to start).
- Start a long-running command from desktop and check on it from mobile.
- Manage a self-hosted server and run admin commands on the go.
- Run serverless infrastructure and fix things remotely via a bastion.
- Keep a full transcript of every command you've ever run on your infrastructure, useful for postmortems.
- Share a terminal with a collaborator (e.g., two-person rule).
Architecture & Security
Fewshell is self-hosted, with no cloud dependency. Communication between client and server uses an SSH tunnel. Secrets are stored in the system keychain and are redacted before being sent to the LLM. The server holds secrets in memory for command use and replication across authenticated devices, and the private SSH key never leaves the client device.
Optional features include push notifications for long-running commands via a relay service, and SSH public key provisioning during initial device pairing.
Features
- Cross-platform GUI clients: iOS, macOS, Linux, Android (Windows planned).
- Built in Flutter – low memory footprint, native execution.
- Secret management: user and per-project secrets stored in keychain with per-secret LLM visibility control.
- Cross-device sync using your own server.
- Command snippet library for reusable commands injected into LLM context.
- Session archival – full transcripts for postmortems.
- BYOM (Bring Your Own Model): supports OpenAI, Anthropic, Google, DeepSeek, Ollama, Groq, xAI, OpenRouter, and more.
- Custom agent instructions: user and per-project system prompts with template variables.
Quick Start
tl;dr – Using SSH on mobile is painful. Modern AI is really good at shell commands, but letting AI control infrastructure is dangerous. Fewshell's three core principles: secure defaults (mandatory SSH and secrets management), must be self-hosted (cloudless desktop-mobile sync), and human-first (AI will not run any command without approval).
To get started, visit the GitHub repo or get.fewshell.com for download links.
📖 Read the full source: HN AI Agents
👀 See Also

Nexus Desktop App Automates MCP Setup for TTRPG Campaign Management
Tired of manually editing Claude Desktop config for every MCP? Nexus installs and configures Archivist, Foundry VTT, Notion, Obsidian, and NotebookLM for TTRPG campaign management.

gui.new: Tool for Claude to Render Visual Output as Shareable Links
gui.new is a tool that lets Claude render visual output as live shareable links instead of returning code blocks. It's built with Claude, uses Next.js on Vercel with Supabase, and requires no signup.

OpenClaw Skill Usage Tracker: Monitor Which Skills You Actually Use
A developer built a tool to track OpenClaw skill usage analytics, including invocation counts, breakdowns by agent and channel, and top skill rankings over different time periods.

Self-updating translation system for OpenClaw maintains domain glossaries automatically
A Python script wraps the Kimi2.5 API to translate .srt files while preserving block indices, timestamps, and segmentation. The system uses project profiles with glossary.json, style.md, and memory.jsonl files, and includes a cron job that scans official sources every 6 hours to update terminology.