Using Hacker Sidekick
This is the guide to what you can do in the app. Everything happens inside the folder (workspace) you open, and the AI agent works alongside you in that same folder — reading and editing files, running commands, driving the browser, and calling the tools you connect.
For install and sign-in, start with The app & first run.

Features
| Area | What's there |
|---|---|
| The agent & chat | The primary agent, chat tabs, the composer (@-mentions, /-commands), reading its work, sub-agents & workers, the task checklist. |
| Security modes & approvals | Per-conversation modes (Generalist, Pentester, DFIR, Blue Team, Exploit Dev) + custom modes, the approval gates, protected paths, and Rules of Engagement. |
| Browser control | The built-in Chromium browser the agent inspects and operates — DOM, network, storage, WebSockets, screenshots, traffic interception. |
| Terminals | Real shells, the visible Agent terminal, interactive processes, command history, and @terminal. |
| Files, editor & search | The Explorer, the editor (code, images, PDFs, SQLite, binaries), files outside the workspace, Search, Git, and the local semantic index. |
| MCP servers | Connect Model Context Protocol tool servers (local or remote); a public-intel server ships enabled. |
| Skills | Reusable playbooks the agent loads on demand; run them from the / menu. |
| Integrations | A bring-your-own-key catalog of security & workflow services; credentials stay server-side. |
| Watch mode | The passive monitor that advises on your activity but never acts. |
| Environment survey | The startup profile of your machine and installed tooling that the agent is made aware of (redaction-aware, default-on). |
| Keyboard shortcuts | Every hotkey, including the ones you can rebind in Settings. |
Usage, tokens & billing
Your plan includes a pool of tokens; the remaining tokens chip in the title bar tracks what's left, and clicking it shows the full breakdown. When you exhaust the included pool, optional auto top-up (on paid plans) keeps you going with metered tokens up to a cap you set — manage it via Top up in the account menu, or in the portal. Plans and billing live in the Account portal.
Privacy
We do not train our models on your data. Your prompts, code, and engagement context are used to complete your requests — not for training. The workspace index is stored locally on your machine.
See also
- The app & first run — install, sign-in, updates
- Keyboard shortcuts — every shortcut in one place
- Account portal — plans, usage, auto top-up
- Enterprise — private deployments
- Videos — recorded walkthroughs
