The outcome
Gain retrieval and tool use without granting arbitrary packages or models access to the device and private files.
Cherry Studio is a Desktop AI productivity workspace for multi-provider chat, assistants, knowledge bases, agents, web search, image generation, MCP, and local data management. Managing multiple model providers from one desktop app, comparing assistants, working with a local knowledge base, and extending personal workflows with carefully reviewed agents and MCP tools. This guide narrows that broad capability into one repeatable outcome, with checkpoints that keep the source material and your judgment in the loop.
Before you begin
Set the boundary before the tool starts.
Choose one real task, identify who will use the result, and decide what evidence or test will make the result acceptable. Gather only the source material needed for that task. If the work contains confidential, personal, regulated, or client-owned information, confirm that the platform and account are approved before sharing it.
AI should make the work easier to inspect. If the workflow removes the source, the owner, or the review step, redesign the workflow.
Step by step
A workflow you can repeat.
- 01
Define approved files, embedding provider, knowledge scope, MCP use case, package source, filesystem and network permissions, secrets, side effects, approvals, retention, and removal plan.
- 02
Create a minimal knowledge base from copies of approved documents, remove secrets and metadata, record owner and expiry, and verify whether embedding stays local or is sent remotely.
- 03
Review each MCP package, version and dependency, prefer built-ins or pinned trusted sources, set the smallest workspace root and environment variables, and deny shell or broad filesystem access.
- 04
Require interactive approval, inspect every proposed tool and argument, and test prompt injection, path traversal, symlinks, data exfiltration, untrusted URLs, malicious documents, duplicate actions, and denial.
- 05
Use call-chain traces to audit models, retrieval and tools, revoke exposed keys, update only after review, and remove obsolete MCP binaries, memory files, knowledge indexes, caches, and backups.
Working standard
What good use looks like.
- Use the smallest filesystem root.
- Pin and inspect MCP packages.
- Approve every consequential tool call.
Cherry Studio stores local workspace data and keys but sends prompts and selected content to configured providers and may call search, embedding, backup, MCP, agent, or mini-app services. Local storage is not automatic encryption or backup. Use official builds, dedicated keys, approved endpoints, device encryption, narrow filesystem roots, reviewed MCP packages and skills, human approval for actions, and tested encrypted backups before upgrades.
Official references
Check the current product documentation.
Features, plan limits, availability, and data controls change. These official pages are the starting points used for this collection.