osaurus-ai/osaurus
42.5
Weak · 28 September 2026
641k
lines of production code
Swift
with C
3
measurements over time
What this system is
Osaurus is a macOS-native AI orchestration platform that enables users to run local large language models and manage autonomous agent workflows. It provides a comprehensive suite of capabilities including on-device computer use automation, secure sandboxed plugin execution, and integration with external messaging channels like Discord, Slack, and WhatsApp. The system supports complex agent collaboration, delegation, and memory management, all secured by local cryptographic identities and encrypted storage.
Features
Add Siri, Spotlight, and Shortcuts support via App Intents
Users can now interact with Osaurus through system-level surfaces. The "Ask Osaurus" intent allows users to send a prompt to the currently active agent via Siri or Shortcuts and receive the reply directly. The "Run Osaurus Agent" intent lets users start a background run for a specific custom agent, with progress and results surfacing in the app's Work Mode. These capabilities are exposed through App Shortcuts for easy discovery in Spotlight and Siri.
App/osaurus/AppIntents, Packages/OsaurusCore/AppIntents · high confidence
Added Osaurus workspace with package references and Swift Package Manager mirrors
The Osaurus workspace has been introduced to manage the project structure, referencing the App, OsaurusCore, OsaurusCLI, and OsaurusRepository packages. It includes test schemes for the CLI and Core components and configures Swift Package Manager mirrors to redirect dependencies from Hugging Face and existing Osaurus repositories to the osaurus-ai organization.
osaurus.xcworkspace · high confidence
Background agent description generation and Claude Code CLI integration
Agents with blank descriptions now automatically receive a generated summary in the background, derived from their system prompt, so the orchestrator always has a purpose line. The inference engine also adds support for the locally installed Claude Code CLI, allowing Osaurus to act as a proxy for Claude Pro/Max subscriptions via an MCP bridge with secure, short-lived process grants.
Packages/OsaurusCore/Services/Inference · high confidence
Built-in Apple app tools replace legacy plugins
Agents can now use built-in tools for Calendar, Contacts, Mail, Messages, Notes, Reminders, Maps, Music, and Shortcuts, replacing the previous external osaurus-tools plugins. These tools are gated by a per-agent opt-in in the Abilities → Tools picker, and a one-time migration automatically enables the corresponding apps for agents that previously used the legacy plugin tools, ensuring continuity without manual reconfiguration.
Packages/OsaurusCore/Managers · high confidence
Bulk-add chats to projects and enhanced chat text selection
Users can now bulk-add existing ungrouped chats to a project via a new multi-select sheet, saving the need to move them individually in the sidebar. Additionally, the chat view now supports continuous drag-selection across multiple message blocks (paragraphs, code, tables), allowing you to select and copy text spanning different parts of a conversation, similar to other modern chat interfaces.
Packages/OsaurusCore/Views/Chat · high confidence
Chat draft persistence and multi-format export/import
Unsent composer text and attachments are now preserved when switching chats or agents, so you can return to a draft later without losing your work. The app also supports exporting chat sessions to Markdown, PDF, or a bundled Zip file, and importing conversations from ChatGPT, Claude, Grok, Gemini, and Open WebUI, with progress feedback and duplicate detection to make migrating or sharing history straightforward.
Packages/OsaurusCore/Managers/Chat · high confidence
Community compatibility leaderboard and eval scoreboards
The reports directory now includes a crowdsourced model compatibility leaderboard (COMPATIBILITY.md and COMPATIBILITY.json) that aggregates community contributions to show which models run on specific Mac hardware (e.g., Apple M4 Max/Pro) with verdicts like 'works' or 'partial', alongside a main eval scoreboard (SNAPSHOT.md and SNAPSHOT.json) that tracks pass rates, performance metrics, and domain-level results across models like Ornith and gemma-4. This change introduces a new workflow for community members to contribute their own eval results via single-file PRs, which are then folded into the leaderboard, while the core team maintains the main snapshot as an overwrite-based record of the latest runs.
reports · high confidence
Discord connection configuration and credential storage
The Discord integration now persists connection settings (such as guild/channel IDs, read/write permissions, and dispatch rules) to a local JSON file and stores the bot token securely in the system keychain. This change introduces the data models and storage mechanisms required to manage Discord agent channels, enabling users to configure which channels the agent can read from or write to and securely saving authentication credentials.
Packages/OsaurusCore/Models/Discord · high confidence
Expanded localization support with new language translations and string updates
The application now includes a comprehensive localization catalog (Localizable.xcstrings) that adds or updates translations for German, Korean, Russian, Simplified Chinese, and Traditional Chinese. This change ensures that UI elements, such as status indicators ('last seen'), actions ('Copy'), and context labels ('in sandbox'), are properly localized for these languages, improving accessibility and user experience for non-English speakers.
Packages/OsaurusCore/Resources · high confidence
Expanded screen context and agent database evaluation fixtures
Added synthetic fixtures to the evaluation suite to support more robust testing of screen context capture and agent behavior. The new ScreenContext fixtures cover a wider range of application states, including browser forms, chat compositions, code editors (Cursor, Xcode), file managers, and terminal sessions, providing detailed accessibility tree snapshots for validation. Additionally, a new AgentDB fixture provides a structured dataset of commit history and repository star counts to support agent database-related evaluations.
Packages/OsaurusEvals/Fixtures · high confidence
Improved AppleScript reliability with curated app knowledge and scripting dictionaries
The AppleScript subagent now injects structured, app-specific knowledge into its prompts to reduce scripting errors and improve task accuracy. This includes a curated catalog of idioms and gotchas for common apps (such as TextEdit, Safari, Notes, and Finder) and a service that distills each app's official scripting dictionary (sdef) into a bounded, model-readable summary. The system also features more robust target-app detection, correctly resolving vague user references like "the file" or "frontmost app" to the specific application context, ensuring the agent interacts with the right software.
Packages/OsaurusCore/AppleScript/Knowledge · high confidence
Initial project scaffolding and developer tooling configuration
The repository is initialized with essential configuration files to support development and release workflows. This includes a comprehensive \.gitignore\ to exclude build artifacts, local secrets, and large binary model files, alongside \.gitattributes\ to configure Git LFS for specific assets. Developer experience is standardized via \.swift-format\ and \.swiftlint.yml\ for code style, a \Makefile\ providing build, test, and benchmark targets, and a \lefthook.yml\ pre-push hook for linting. The project is also documented with \README.md\, \AGENTS.md\ (defining build and proof protocols), \COMMUNITY\_EVALS.md\ (for crowdsourced model compatibility testing), and an MIT \LICENSE\.
(repo-wide) · high confidence
Introduce Agent Database tools for data import, export, and self-scheduling
This change adds a new suite of agent-facing database tools (\db\_import\, \db\_export\, \db\_execute\, and \schedule\_next\_run\) located in \Packages/OsaurusCore/Tools/Database\. Users can now import tabular data (CSV, TSV, JSON, JSONL, XLSX) into agent-specific tables with automatic schema resolution and bulk loading, and export query results to disk in CSV, JSON, JSONL, or XLSX formats. The import pipeline enforces a 64 MB file size limit and handles type inference, while the export pipeline streams large result sets to avoid token limits. Additionally, agents can now schedule their own future wake-ups with specific instructions and context views, enabling autonomous, self-controlled workflows.
Packages/OsaurusCore/Tools/Database · high confidence
Introduce AppleScript Computer Use subagent with safety and accessibility controls
This change adds a new AppleScript subagent capability, exposing two tools: \applescript\ for automating tasks on the Mac (controlling apps, reading/writing state) and \mac\_query\ for read-only information retrieval. The implementation includes a new \AppleScriptAccessibility\ helper that preflights scripts for System Events UI scripting (keystrokes, clicks) to detect when the user's Accessibility permission is required and prompt for it if missing. It also introduces an \AppleScriptEffectClassifier\ that analyzes generated scripts to classify them as read, edit, or consequential, ensuring that state-mutating or destructive actions are gated by user confirmation or blocked in read-only mode. The dispatch layer normalizes arguments to handle edge cases like sibling-field conflicts and promotes string \contents\ to the expected object format, improving reliability for both automation and query tasks.
Packages/OsaurusCore/AppleScript/Tool · high confidence
Introduce Business Document Studio service with unified document adapters and in-place editing
The Documents service now provides a centralized Business Document Studio layer that unifies document inspection, bounded previews, and explicit export for CSV, workbooks, PDF, presentations, and text files. This is supported by new high-fidelity adapters (CSV, DOCX) and emitters that replace legacy handling, along with a new DocumentEditService that enables safe, validate-then-swap in-place edits for .docx, .xlsx, .pptx, and .pdf files. The change also adds a shared CSV row parser for workflow previews and a DocumentFileInspector for security metadata and HTML active-content detection.
Packages/OsaurusCore/Services/Documents · high confidence
Introduce Computer Use subagent with safety gates and verification
Adds the core \ComputerUseLoop\ and supporting infrastructure for the new Computer Use feature, enabling the model to drive macOS apps via a nested subagent. The implementation enforces safety through a per-action autonomy gate (requiring user approval for consequential actions), a \requireVerifiedChangeForDone\ check to ensure actions actually landed, and configurable \RunLimits\ (step caps, timeouts, and retry budgets). It also includes a trace log for debugging model responses and a telemetry system to track run metrics and pre-loop refusal stages.
Packages/OsaurusCore/ComputerUse/Loop · high confidence
Introduce MacDriver abstraction for Computer Use automation
The Computer Use feature now uses a new \MacDriver\ protocol to manage macOS automation, separating the harness logic from platform-specific implementation. This change introduces \NativeMacDriver\ to handle accessibility reads and input synthesis on a background queue to prevent UI hangs, and \MockMacDriver\ to support testing and demos with scripted snapshots. The driver defines a stable contract (\CUElement\, \CUSnapshot\, \CaptureTier\) for perceiving the screen and performing actions, enabling the Computer Use subagent to interact with applications reliably.
Packages/OsaurusCore/ComputerUse/Driver · high confidence
Introduce Memory V2 management UI with diagnostics and console
The Memory section has been replaced with a new v2 interface featuring a tabbed layout (Identity, Memories, Agents, Settings, and Diagnostics). Users can now inspect and manage stored memory via a dedicated Management Console that supports searching, filtering by agent, and viewing context previews. A new Diagnostics tab provides pipeline health status, backfill controls, and buffer probing tools to help diagnose memory ingestion issues. The previous memory views have been refactored into shared components for pinned facts, episodes, and agent details.
Packages/OsaurusCore/Views/Memory · high confidence
Introduce Projects as grouped chat containers with shared context
Users can now organize chat sessions into Projects, which act as named groupings that share common instructions, knowledge collections, and a default agent across all contained conversations. Each project can also specify a default folder bookmark and path, allowing new chats started from the project to automatically open in a specific directory while preserving the ability to move chats between agents or override folder settings. The underlying data model and persistence layer (ProjectStore) handle loading, saving, and deleting these project records as individual JSON files, ensuring that existing chat sessions remain intact when a project is removed.
Packages/OsaurusCore/Models/Project · high confidence
Introduce Watchers pane for automated file system monitoring
A new Watchers management view has been added, allowing users to create, edit, and delete file system watchers that monitor specific folders for changes and trigger work tasks automatically. The interface includes a grid of watcher cards with options to toggle status, run tasks immediately, or remove watchers, along with a dedicated editor sheet for configuring details such as watch paths, instructions, and responsiveness settings. Success feedback is provided via toast notifications for all management actions.
Packages/OsaurusCore/Views/Watcher · high confidence
Introduce core method modeling and scoring structures
Added the foundational data models for the methods subsystem, including the \Method\ struct to represent recorded tool-call sequences with metadata like source, tier, and usage stats. Introduced \MethodEvent\ to track lifecycle events such as loading, success, and failure, and \MethodScore\ to calculate and store performance metrics including a recency-weighted success rate. These types provide the underlying structure for method management and evaluation within the application.
Packages/OsaurusCore/Models/Method · high confidence
Introduce dedicated Image Generation settings and model management view
Users now have a dedicated Image Generation section in Settings, featuring a header with sub-tabs for global configuration and a Models browser. The Settings tab allows users to define default models for image generation and editing, as well as text-to-video models, while the Models tab enables browsing and downloading on-device image bundles (vMLXFlux / mflux) and importing from Hugging Face. This view mirrors the existing Voice/Privacy pattern, providing a centralized place to manage image and video generation capabilities and local model storage.
Packages/OsaurusCore/Views/ImageGeneration · high confidence
Introduce durable schedule automation with run history and persistence
Users can now create and manage scheduled AI chat interactions with support for multiple frequencies (once, every N minutes, hourly, daily, weekly, monthly, yearly, and cron). The system persists schedules to disk and maintains a detailed run history for each schedule, tracking status (running, succeeded, failed, cancelled, skipped), duration, token usage, and cost. This provides visibility into past executions and helps diagnose issues with scheduled tasks.
Packages/OsaurusCore/Models/Schedule · high confidence
Introduce local agent collaboration protocol service
Added a new \AgentCollaborationService\ and its in-memory transport layer within the OsaurusCore package to establish the agent collaboration contract. This service enables agents to register with specific capabilities, negotiate compatibility, and exchange structured envelopes for requests, handoffs, replies, and failure diagnostics, providing a local proving ground for the collaboration logic before any team UI or network bridge is integrated.
Packages/OsaurusCore/Services/AgentCollaboration · high confidence
Introduce native Telegram connection configuration model
Added a new \TelegramConnectionConfiguration\ model to manage non-secret settings for the native Telegram integration. This configuration supports defining readable and writable chat IDs, sender allowlists, and options to ignore self or bot messages. It also includes settings for long-polling behavior (limit and timeout) and integrates with the shared \AgentChannelInboundDispatchConfiguration\ to handle how incoming messages are routed to agents.
Packages/OsaurusCore/Models/Telegram · high confidence
Introduce native iMessage channel with on-demand helper and advanced action support
This change adds a new native iMessage agent channel to the core services, enabling the application to send, receive, and manage iMessages directly. The implementation relies on a pinned, on-demand downloaded helper binary (\imsg\) which is verified via SHA-256 digests before installation. Basic messaging features are available immediately, while advanced actions (such as replies, tapbacks, and rich media) are gated behind a private-API bridge that requires the operator to disable System Integrity Protection (SIP) and Library Validation. The service includes robust diagnostics, health monitoring, and automatic reconnection logic for the receive stream.
Packages/OsaurusCore/Services/IMessage · high confidence
Introduce on-device Privacy Filter with configurable PII detection and review workflow
This change adds a new Privacy Filter module to the core package, enabling the detection and redaction of personally identifiable information (PII) such as names, emails, addresses, and secrets before messages are sent. The system uses a local on-device machine learning model (with an optional Rampart model) and regex rules to identify sensitive data, masking code blocks to prevent false positives on identifiers. When PII is detected, users are presented with a review sheet to approve or skip redactions; approved items are replaced with stable placeholder tokens (e.g., \[PERSON\_1\]) in the outbound payload. The filter supports custom user-defined regex rules, handles both streaming and non-streaming responses, and includes a fail-closed safety mechanism that blocks sends if the model is unavailable or if redaction fails.
Packages/OsaurusCore/PrivacyFilter/Core · high confidence
Introduce per-agent encrypted database with export, import, and migration support
Agents now have a private, encrypted SQLite database (powered by SQLCipher) that persists structured data like trackers, logs, and CRDs across sessions. This feature includes a secure export/import system that packages the database, schema, and migrations into a passphrase-protected \.osaurus-agent\ bundle, allowing users to review and migrate agent data between devices. The system automatically manages schema evolution through numbered up/down migration files and provides a token-efficient schema snapshot to the agent's system prompt, enabling it to understand its own structure without exposing sensitive row data to cloud models.
Packages/OsaurusCore/Services/AgentBridge · high confidence
Introduce per-app refinement recipes for Computer Use
Added AppRecipe.swift to provide app-specific refinements for the Computer Use system. This new component defines structured recipes (e.g., for TextEdit, Finder, Safari) that supply context-aware signals to the action classifier—such as escalating specific dialog buttons like 'Don't Save' to 'consequential' actions—and provides ordered, human-readable task flows. These flows are injected as guidance hints into the model's prompt to improve reliability for common tasks like replacing text in TextEdit or navigating Finder, addressing regressions in state handling and completion accuracy.
Packages/OsaurusCore/ComputerUse/Recipes · high confidence
Introduce schedule automation history and management view
The SchedulesView now includes a dedicated history sheet for viewing past execution details of scheduled tasks, accessible via the new 'Show History' action on schedule cards. This change adds the capability to track and export execution summaries, enhancing the ability to monitor automated AI task performance over time.
Packages/OsaurusCore/Views/Schedule · high confidence
Introduce security foundation for Agent Channels
This change adds a security foundation for Agent Channels, including a credential vault for secure storage, a remote safety gate to enforce rate limits and content policies, a replay nonce store to prevent token reuse, a reply token service for scoped authentication, a write kill switch for global write control, and a policy evaluator for strict allowlisting. These components work together to secure channel interactions, prevent replay attacks, and provide operators with granular control over channel permissions and write access.
Packages/OsaurusCore/Services/Channels · high confidence
Introduce slash command system with built-in actions and user-defined persistence
Users can now invoke shortcuts by typing /name in the chat input. The system includes built-in commands for clearing conversations, switching AI models and agents, capturing screenshots, generating chat titles, and viewing help. User-defined commands are persisted as individual JSON files in the application's slash-commands directory, supporting creation, editing, and deletion via the new SlashCommandStore.
Packages/OsaurusCore/Models/SlashCommand · high confidence
Introduce structured document parsing foundation with format adapters
The document ingestion pipeline now uses a typed adapter system to parse files into structured representations rather than plain text. This change introduces protocols for reading (DocumentFormatAdapter), streaming (DocumentFormatStreamer), and writing (DocumentFormatEmitter) across formats like PDF, CSV, XLSX, PPTX, and DOCX. It adds a unified DocumentStructure model with format-neutral anchors to preserve source identity (e.g., page numbers, cell coordinates) and a BusinessDocumentSummary model to provide consistent metadata and display labels for different file types. Security metadata is now attached to parsed documents to track active content and external references, and per-format size limits are enforced to prevent memory issues.
Packages/OsaurusCore/Models/Documents · high confidence
Introduce structured model-facing models for Computer Use actions and UI views
Added \AgentAction\ and \AgentView\ models to the Computer Use subsystem. \AgentAction\ defines a constrained set of verbs (such as click, type, and wait) and their parameters, replacing raw driver tool calls with a single, schema-constrained envelope that the model proposes per step. \AgentView\ provides the model with a compact, numbered representation of the current application UI, hiding internal element IDs and exposing a \changed\ flag to help the model verify that actions have taken effect.
Packages/OsaurusCore/ComputerUse/Model · high confidence
Introduce user-curated knowledge collections with agent-facing summaries and indexing controls
Users can now organize markdown documents into named 'knowledge collections' that serve as curated, human-governed reference material for agents. Each collection includes a summary that helps agents decide when to consult the corpus, and supports fine-grained indexing via include/exclude glob patterns. The system distinguishes between explicit document types (from YAML frontmatter) and inferred types, and provides a mechanism for agents to flag stale content via tickets, which curators can then review and approve as proposals. To prevent UI hangs during startup or browsing, collection metadata loading and folder existence checks are performed off the main thread with caching.
Packages/OsaurusCore/Models/Knowledge · high confidence
Introduces Osaurus ID, shared-agent session bridging, and local credit balance API
The Router service now supports a new identity layer where users can claim and manage an Osaurus ID handle, with session tokens stored securely in the Keychain to avoid repeated master-key usage. It adds support for hosting inbound shared-agent runs, allowing remote teammates to drive local agents while maintaining a persistent, session-backed conversation history in the UI. Additionally, a new local read-only API endpoint exposes the user's credit balance, complete with strict authorization checks to prevent unauthorized local access.
Packages/OsaurusCore/Services/Router · high confidence
Introduces a new Agent Channel service layer with native integrations and audit capabilities
This change adds a comprehensive backend service layer for managing agent communication channels, introducing native support for Discord, Slack, Telegram, iMessage, and WhatsApp alongside a safe, configuration-driven Custom JSON runner. The new \AgentChannelConnectionService\ centralizes dispatch logic for these providers, while \AgentChannelConnectionManager\ handles configuration persistence and validation. To improve reliability, \AgentChannelCredentialAvailability\ caches credential checks to prevent main-thread hangs during Keychain access, and \AgentChannelAutoDestinationResolver\ automatically derives proactive posting destinations from existing channel write-allowlists. Additionally, an \AgentChannelAuditWorkbenchService\ provides redacted inbox views and JSON export capabilities for operators to monitor and audit channel activity.
Packages/OsaurusCore/Services/AgentChannel · high confidence
Introduces a unified Agent Channel model layer with native integrations and guided setup
This change adds the core data models and configuration structures for the new Agent Channels system, enabling users to connect agents to Discord, Slack, Telegram, iMessage, WhatsApp, and n8n. It defines the channel kinds, action policies (such as read, send, and reply capabilities), and inbound dispatch rules that determine how messages are routed to agents. The update includes a structured setup flow with distinct sections for connection, access, behavior, and verification, along with live proof readiness checks to ensure channels are properly configured before use. It also introduces presentation models for displaying channel destinations and status, ensuring a consistent user experience across different providers.
Packages/OsaurusCore/Models/AgentChannel · high confidence
Introduces a unified registry for evidence reports
A new in-memory registry service and associated data models have been added to centralize the tracking of locally-produced evidence artifacts. This change introduces typed summaries for eval, benchmark, runtime, live-proof, run-trace, and provider evidence, allowing the system to register, filter, and list reports based on their status, kind, and source. The registry acts as a projection over existing files, verifying artifact availability and handling metadata redaction, which provides a standardized way to view and manage evaluation results without moving the underlying data.
Packages/OsaurusCore/Models/Evidence, Packages/OsaurusCore/Services/Evidence · high confidence
Introduces a unified sub-agent delegation system with configurable policies and concurrency controls
This change introduces the core data models and persistence layer for a new sub-agent delegation feature. It adds \DelegationRecord\ to track sent and received agent runs (including status, duration, and token usage) and \SubagentConfiguration\ to define user policies for permission (Ask/Deny/Always Allow), image model residency, and AppleScript model keep-warm behavior. It also introduces \SpawnBatchConcurrencyContract\ to synchronize the maximum number of parallel sub-agents between the main Server settings and individual Spawn editors, ensuring consistent concurrency limits across the application.
Packages/OsaurusCore/Models/AgentDelegation · high confidence
Introduces agent collaboration protocol contract and participant adapters
Adds the foundational data models and protocol contract for agent collaboration, including the \AgentCollaborationProtocolContract\ (schema \osaurus.agent-collaboration.v1\, version 1) and types for participants, capabilities, and negotiation results. The \AgentCollaborationCapabilities\ model defines baseline required capabilities (such as correlation, provenance, request, handoff, and reply) and provides logic for capability negotiation and commonality checks. Additionally, computed extensions on \Agent\ and \RemoteAgent\ provide adapters that map existing agent records into the new collaboration participant format, enabling future local and remote agent teams to interact via this defined protocol.
Packages/OsaurusCore/Models/AgentCollaboration · high confidence
Introduces extensible document format registry and bootstrap
The document management layer now uses a centralized \DocumentFormatRegistry\ to route file ingestion and export tasks to specific adapters and emitters. This change replaces ad-hoc handling with a pluggable system where built-in formats (including PlainText, CSV, PDF, PPTX, RichDocument, and XLSX) are registered at launch via \DocumentAdaptersBootstrap\. The registry supports thread-safe lookups and allows plugins to register or override formats, enabling future extensibility for document handling without modifying core logic.
Packages/OsaurusCore/Managers/Documents · high confidence
Introduces local-first consent and autonomy gates for Computer Use actions
The Computer Use feature now enforces a local-first consent surface before executing gated actions. A new \ComputerUsePromptQueue\ manages pending confirmations, surfacing them as inline approve/deny overlays in the chat view. This system supports granular autonomy policies, allowing users to auto-approve subsequent actions of equal or lower effect within the same app for the duration of a run. It also handles cloud-vision consent requests and ensures that pending prompts are resolved as denied if a run is interrupted or torn down, preventing the loop from hanging.
Packages/OsaurusCore/ComputerUse/Feed · high confidence
Introduces new core agent data models and persistence layer
This change establishes the foundational data structures for the agent system, including the main Agent model, capability readiness states, and dispatch targets. It adds support for per-agent quick actions, starter templates, and invite-based sharing with cryptographic verification. The update also implements a robust agent store with background write serialization to prevent UI hangs, deep-link routing for agent details, and legacy migration paths for older persona data.
Packages/OsaurusCore/Models/Agent · high confidence
Introduces privacy-preserving cloud vision with on-device capture fallback
The Computer Use perception layer now enforces a strict privacy model for screen data. Screenshots are no longer sent raw; they must be scrubbed of text regions (using Vision OCR and configurable PII detection) before reaching any cloud model. Sending scrubbed frames to the cloud is strictly gated by explicit user consent (persisted or session-based) and requires Screen Recording permissions. If consent is denied, or if Screen Recording is unavailable, the system falls back to a local-only capture ladder (Accessibility tree, then on-device OCR/Vision), ensuring no pixels leave the device without user approval. The system also tracks the user's active application to provide better context when the AI app itself takes focus.
Packages/OsaurusCore/ComputerUse/Perception · high confidence
Introduces provider-neutral channel identity and security policy models
This change adds the foundational data models for managing remote agent channels across providers like Discord, Slack, Telegram, iMessage, WhatsApp, and n8n. It introduces ChannelIdentity to standardize provider-neutral identities with trust levels (untrusted, known, verified, owner) and ChannelSenderMetadata. It also defines ChannelSecurityPolicy for authorization (controlling read/write access by sender, group, or thread) and ChannelRemoteSafetyPolicy for operational safety (rate limiting, reply token requirements, and content risk assessment). These models enable consistent security gates and identity validation for all supported channel integrations.
Packages/OsaurusCore/Models/Channels · high confidence
Isolated per-chat working folders and unified document handling
Chat sessions now maintain their own independent working folders, replacing the previous process-wide singleton so concurrent chats can operate against different directories without interference. The \file\_read\ tool has been expanded to support binary-safe operations via a new \file\_copy\ tool, direct image rendering with Vision OCR for text-only models, and searchable extraction from documents like PDFs, Word files, and Excel workbooks. Additionally, \file\_write\ can now generate structured documents such as \.xlsx\, \.docx\, \.pdf\, and \.pptx\ from text or Markdown input.
Packages/OsaurusCore/Folder · high confidence
Native Browser Use replaces the legacy plugin with a built-in WebKit engine
The legacy \osaurus.browser\ plugin is replaced by a native, built-in browser capability. This change introduces a new WebKit-based runtime (\BrowserSession\) that runs asynchronously on the main actor, eliminating the previous synchronous C-ABI bridge and associated thread-blocking risks. A one-time migration (\BrowserPluginMigration\) automatically transfers existing agent WebKit profile UUIDs from the plugin's Keychain storage to the new native catalog, preserving cookies and sign-in states without user intervention. The new implementation includes a persistent session catalog, an idle session reaper, and a visible session window for login flows and manual inspection, while enforcing strict URL scheme policies (allowing only http/https) and confining screenshot outputs to the user's Downloads folder.
Packages/OsaurusCore/Services · high confidence
Native Discord integration for agent channels
Osaurus now supports connecting to Discord as a native channel, allowing agents to receive messages from and send messages to Discord servers. This change introduces a REST-based polling transport to ingest messages from allowlisted channels, a dedicated WebSocket runtime to maintain the bot's online presence status, and a connection service that manages bot identity, guild/channel discovery, and credential storage in the keychain. Users can configure bot tokens and access lists to enable bidirectional communication between the app's agent system and Discord.
Packages/OsaurusCore/Services/Discord · high confidence
Native Slack Agent Channel adapter with Socket Mode support
This change introduces a new native Slack integration for Agent Channels, replacing or supplementing previous mechanisms. It adds a dedicated Slack API client for managing authentication identities, conversations (including direct messages and private channels), and user profiles, alongside a connection service that handles diagnostics, token management, and sender allowlists. The adapter uses Slack's Socket Mode via WebSocket for reliable inbound message reception, featuring a robust transport runtime with health monitoring, backoff policies, and activity tracking. This enables users to connect their Slack workspaces directly to the agent system with improved reliability and detailed connection status reporting.
Packages/OsaurusCore/Services/Slack · high confidence
Native Telegram channel support with diagnostics
The application now includes a native Telegram agent channel, introducing a dedicated API client and connection service to handle bot interactions, message parsing, and webhook/long-polling management. This change adds comprehensive diagnostic capabilities, allowing users and operators to inspect connection status, token validity, chat permissions, and configuration states directly within the system.
Packages/OsaurusCore/Services/Telegram · high confidence
Native WhatsApp channel support via local bridge
Users can now connect their personal WhatsApp account to Osaurus using a local helper process (osaurus-wa) that bridges WhatsApp Web. This introduces a new configuration model (WhatsAppConnectionConfiguration) that defaults to a secure, opt-in state: receiving messages and sending replies are both disabled until explicitly enabled. Users can configure allowlists for specific chats and senders, control media ingestion, and manage read receipts. The helper handles QR code pairing and session management locally, exposing functionality via JSON-RPC for chat listing, sending messages and attachments, and watching for new inbound messages.
Packages/OsaurusCore/Models/WhatsApp, helpers · high confidence
Native WhatsApp channel support via local helper bridge
Users can now connect Osaurus to WhatsApp directly without relying on Meta Business webhooks or third-party relays. This change introduces a native WhatsApp agent channel that operates by installing and running a local \osaurus-wa\ helper (a whatsmeow-based WhatsApp Web bridge) on the user's machine. The connection is established via QR code scanning and passkey verification, allowing users to link their personal WhatsApp account. Once linked, the system can send and receive messages, attachments, and reactions through a local JSON-RPC transport, with all provider I/O handled by the helper process rather than external APIs.
Packages/OsaurusCore/Services/WhatsApp · high confidence
Native subagent kinds for AppleScript, Browser Use, Computer Use, Image, Video, and Text delegation
Osaurus now includes built-in subagent kinds for AppleScript, Browser Use, Computer Use, Image, Video, and Text delegation, replacing the previous osaurus.browser plugin with a native browser feature. These kinds provide per-agent enablement, dedicated or inherited model resolution, residency handoffs for local models, and bounded execution with safety gates (e.g., Computer Use and Browser Use share autonomy policies and consent overlays). AppleScript uses a dedicated model catalog and supports read-model splitting for queries, while Image and Video handle local/remote model selection and billing quotes. Text delegation supports spawning agents and workspace agents with RAM-admission pricing and digest limits.
Packages/OsaurusCore/Subagent/Kinds · high confidence
Native web search with pluggable providers and settings
The search service now supports a pluggable provider architecture, allowing users to configure both API-key-based providers and free, native scrapers (DuckDuckGo, Brave, Bing) through a new Search settings tab. The system executes a provider cascade: it first attempts configured API providers sequentially, then races free scrapers in parallel if no results are found, while also supporting premium hosted search via the Osaurus router with credit billing. This change introduces a declarative backend for custom API definitions, native HTML scraping backends, and a structured data store for efficient tool-to-tool handoff of large datasets like CSV or JSON.
Packages/OsaurusCore/Services/Search · high confidence
New 'What's New' modal with automatic release notes and deep-linking
A new 'What's New' modal has been introduced to automatically announce updates on the first launch after an app version change. The system tracks the last-shown version and aggregates release notes for any skipped versions into a single carousel. It includes specific announcements for Browser Use (0.22.9), Channels (0.22.13), Projects (0.22.23), the Orchestrator (0.24.0), and Raptor v0.5 (0.24.4). The modal supports runtime gating to hide pages that don't apply to the user's environment (e.g., sandbox-specific features) and provides deep-link actions to relevant settings pages, such as Browser settings, Channels management, and Projects.
Packages/OsaurusCore/Views/WhatsNew · high confidence
New API-compatible model definitions for Anthropic, Gemini, OpenAI, and OpenResponses
This change introduces a comprehensive set of new Swift data models in the \Packages/OsaurusCore/Models/API\ directory to support multiple API protocols. It adds \AnthropicAPI.swift\ for Anthropic Messages API compatibility (including prompt caching), \GeminiAPI.swift\ for Google Gemini compatibility (including thinking-mode metadata), \OpenAIAPI.swift\ for OpenAI Chat Completions and \/models\ endpoints, and \OpenResponsesAPI.swift\ for the Open Responses specification (including reasoning configuration and input item types). Additionally, it includes \EmbeddingAPI.swift\ for OpenAI/Ollama embedding endpoints, \ImageAPI.swift\ for OpenAI-compatible image and video generation, \FireworksAPI.swift\ for model catalog discovery, and \JSONDeterminism.swift\ to ensure stable JSON key ordering for caching and tool replay.
Packages/OsaurusCore/Models/API · high confidence
New Agent Channels settings pane with unified connection management
The Settings view now includes a dedicated Channels tab that centralizes the management of agent communication channels. This update introduces a unified 'Add Channel' flow supporting native integrations (Discord, Slack, Telegram, iMessage, WhatsApp, n8n) and custom HTTP connections, each with guided setup screens. Users can manage inbound routing rules to direct messages to specific agents, configure outbound destinations for proactive agent messages, and monitor transport health and activity logs directly within the settings interface.
Packages/OsaurusCore/Views/Settings · high confidence
New AppleScript Computer Use subagent with curated models and safety controls
A new AppleScript subagent has been added to enable on-device macOS automation using curated MLX-based models (Osaurus AppleScript 16B and 8B). The system now includes a model catalog that manages these specific automation models, distinguishing them from general chat models, and provides an execution mode policy that allows users to choose between explicit approval for every state-changing script (default) or automatic execution with visible warnings. The agent supports both AppleScript and JXA (JavaScript for Automation) and enforces strict validation on the generated scripts to ensure safe, reliable execution.
Packages/OsaurusCore/AppleScript · high confidence
New AppleScript Computer Use subagent with safe on-device execution
Osaurus now includes an in-process AppleScript executor that allows the agent to control macOS applications directly on the device. This new capability runs scripts via \NSAppleScript\ on a serial queue to prevent deadlocks, enforces a 45-second timeout per script, and includes a main-runloop heartbeat to ensure reliable communication with the OS in headless environments. It also features a literal-placeholder system to safely inject large text content into scripts without transcription errors, and provides a mock execution world for deterministic testing of computer-use behaviors.
Packages/OsaurusCore/AppleScript/Exec · high confidence
New AppleScript subagent for on-device computer use
This change introduces the core loop and tracing infrastructure for the new AppleScript subagent, enabling on-device automation and read-only queries. The \AppleScriptLoop\ implements a generate-classify-gate-execute cycle that classifies model-emitted scripts as read or edit, applies safety gates (blocking writes in query mode, enforcing user confirmation in automate mode), and executes them via \AppleScriptExecutor\, feeding results back to the model for iteration. It tracks detailed per-step transcripts and performance metrics (tokens, latency, success/failure counts) in \AppleScriptRunResult\. Additionally, \AppleScriptTraceLog\ provides an environment-gated (\OSAURUS\_APPLESCRIPT\_TRACE=1\) append-only trace of model requests and responses to \/tmp\, aiding in the diagnosis of multi-step marker leaks and model degeneration without altering the inference path.
Packages/OsaurusCore/AppleScript/Loop · high confidence
New Claude Marketplace integration with precomputed importability catalog
Osaurus now includes a dedicated service to browse and install plugins from the official Claude marketplace. To avoid rate-limit issues and UI lag when loading 200+ entries, the system uses a precomputed, bundled JSON catalog to classify which plugins contain importable components (skills, agents, commands, MCP) versus those that do not. This allows the Plugins Browse tab to render immediately without network probes, while install-time checks ensure only valid, importable plugins are installed. The feature also includes a format adapter registry for plugin-provided data formats and persists plugin-driven inference sessions in the chat history.
Packages/OsaurusCore/Services/Plugin · high confidence
New Claude plugin marketplace and GitHub import experience
The Plugins tab now features a dedicated Claude plugin marketplace with a browsable catalog, allowing users to discover, preview, and install plugins directly. A new GitHub import sheet enables importing plugins and skills from repositories, including support for MCP providers and dependency resolution. The UI includes new cards and detail views for both marketplace and installed Claude plugins, showing component counts (skills, agents, commands, MCP) and trust status. A GitHub token management card helps users avoid rate-limit errors by connecting a free GitHub account for higher API limits.
Packages/OsaurusCore/Views/Plugin · high confidence
New Computer Use diagnostics for autonomy gating and permissions
Added diagnostic tools in the Computer Use settings to help users understand and troubleshoot agent behavior. The new ComputerUseGateInspector allows users to simulate autonomy decisions (run, confirm, or reject) for specific actions, showing how policy, allowlists, and ceilings influence the outcome. The ComputerUsePermissionDoctor provides a read-only summary of system permissions (Accessibility, Screen Recording, Cloud Vision) and agent availability, indicating whether the environment is ready for Computer Use or if specific permissions are missing or inactive.
Packages/OsaurusCore/ComputerUse/Diagnostics · high confidence
New Credits management interface with top-up, redemption, and router controls
The Credits screen now provides a unified wallet experience for Osaurus Router services. Users can add credits via a top-up sheet that supports preset amounts ($5, $20, $100) and custom inputs, processing payments through Stripe Checkout. A new redeem code card allows users to enter promotional or referral codes, with immediate feedback on success, errors, or pending referral status. The view also includes a master toggle to enable or disable the Osaurus Router, with a confirmation dialog explaining that disabling it switches usage to local models. Additionally, users can access a detailed account usage center to view billing history and activity.
Packages/OsaurusCore/Views/Credits · high confidence
New Identity management interface with agent keys and recovery options
The Identity settings page has been rebuilt with a new UI structure. Users can now manage individual agent addresses, including rotating or revoking derived keys and managing scoped access keys. The interface also introduces a dedicated section for claiming and editing an Osaurus ID handle, with live availability checking. Additionally, a new recovery flow allows users to restore their identity from a 24-word mnemonic phrase, supporting fresh restores, drift repair, and identity replacement, while the master recovery phrase can now be viewed, copied, saved, or printed directly from the settings.
Packages/OsaurusCore/Views/Identity · high confidence
New Insights view for debugging API requests
A new Insights screen has been added to allow users to monitor and debug API requests. This view displays a list of request logs with filtering and search capabilities, and provides a detailed pane for selected logs. Users can inspect formatted prompts, full request and response JSON, model parameters, and metadata such as source, model, connection mode, and security status. The detail pane includes buttons to copy request and response data and supports navigation back to the log list.
Packages/OsaurusCore/Views/Insights · high confidence
New Router Account Usage Center view
Users can now access a dedicated Account Usage Center within the Router settings. This new interface provides a consolidated view of account status, including balance, request counts, and net credits, alongside a detailed ledger of billing entries. It also features a tool for running signed request diagnostics to help troubleshoot API issues and an option to export a support bundle containing account and usage data for assistance.
Packages/OsaurusCore/Views/Router · high confidence
New Server Settings sections for HTTP, cache, concurrency, and diagnostics
The Server → Settings tab now includes dedicated configuration cards for Advanced HTTP request limits, API authentication controls (rate limiting, timeouts, log levels), cache management (prefix, paged KV, SSD L2, compression), concurrency and batching, network connection (port, CORS, proxy), decode performance, and generation defaults. A new Live Activity section provides real-time BatchEngine diagnostics, showing active slots, cache hit rates, disk usage, and the actual speculative decoding depth and sampler settings used per model, resolving previous opacity around runtime behavior.
Packages/OsaurusCore/Views/Settings/ServerSettings · high confidence
New Stats Pack plugin for CSV, TSV, JSONL, and SQLite analysis
The OsaurusStatsPack introduces a first-party plugin pack that extends the in-process FormatAdapter ABI to support statistics and data-science workflows. It adds read-only adapters for CSV (with optional JSON schema sidecars), TSV, JSONL, and SQLite databases, enabling users to stream records from these formats without buffering entire files in memory. The pack registers these formats under identifiers like 'csv-schema' and 'sqlite', allowing hosts to explicitly opt-in to these capabilities while ensuring duplicate registration fails safely.
Packages/OsaurusPlugins · high confidence
New Transcription Mode with LLM-powered cleanup and system-wide text insertion
Voice input now includes a dedicated Transcription Mode that captures speech and types the result directly into any focused text field across the system, rather than just within the app. This mode features an LLM-based cleanup step that removes filler words and fixes punctuation, a Markdown stripper to prepare text for speech synthesis, and a floating overlay UI to monitor audio levels and processing status. It also handles accessibility permissions for keyboard simulation and manages clipboard operations to paste text reliably.
Packages/OsaurusCore/Services/Voice · high confidence
New Workspaces management interface with shared agent selection, audit trails, and pool billing
This change introduces the complete Workspaces UI within the OsaurusCore package, replacing previous onboarding flows with a persistent management experience. Users can now view and drill into workspace details (Overview, Members, Shared Agents, Audit), select shared agents for triggers via a new picker that displays owner and presence status, and review a tamper-evident audit log with verification and export capabilities. The interface also includes sheets for creating workspaces, joining via invite or deep link, and managing the shared credit pool through top-ups and auto-reload settings, all integrated into the existing Agents tab's visual language.
Packages/OsaurusCore/Views/Workspaces · high confidence
New access key management and OAuth infrastructure
This change introduces a new \AccessKeyLifecycleService\ that provides a unified API for creating, listing, and revoking user-facing access keys, including label validation and persistence checks. It also adds core OAuth support for desktop environments, featuring an RFC 8252-compliant loopback server (\OAuthLoopbackServer\) for handling authorization callbacks, a deterministic form encoder (\OAuthFormEncoding\) for token requests, and shared PKCE utilities (\PKCE\) to secure the authorization flow against CSRF and code interception.
Packages/OsaurusCore/Services/Auth · high confidence
New agent delegation dispatcher and residency handoff system
The agent delegation service now uses a new \AgentDelegationDispatcher\ that runs delegated tasks as real, persisted \ChatSession\ instances rather than ephemeral mini-loops, allowing children to retain the target agent's tools and memory while preventing recursion. A new \ChatResidencyHandoff\ manages local GPU memory by safely unloading the main chat model before a subagent runs and reloading it afterward, ensuring crash-free handoffs. Additionally, \NativeImageJobCoordinator\ and \AgentSubagentRunner\ provide structured orchestration for local image generation and bounded text subagent loops, while \WorkspaceDelegationEvaluator\ enables scripted evaluation of workspace agent delegation scenarios.
Packages/OsaurusCore/Services/AgentDelegation · high confidence
New benchmarking and LoCoMo memory ingestion scripts
Added a new benchmarking suite in scripts/benchmark to measure local LLM server performance (TTFT, latency, throughput) via the OpenAI-compatible API, including a shell wrapper (run\_bench.sh) for comparing Osaurus against Ollama and LM Studio. Also added scripts to ingest LoCoMo conversation data into the Osaurus memory system (ingest\_locomo.py) and a patch (easylocomo.patch) to update the LoCoMo evaluation framework with deterministic agent IDs and no-context evaluation support.
scripts · high confidence
New chat session data model and supporting utilities
This change introduces a new \ChatSessionData\ model to represent persistable chat sessions, adding fields for agent association, session source, pinning, archiving, working folder ownership, and LLM context-compaction summaries. It also adds several new models and utilities for the chat interface: \AgentTodo\ and \AgentTodoStore\ to parse and manage agent-generated markdown checklists; \AtFileMenu\ to provide a CLI-like filesystem completion menu in the chat input; \ChatFindMatcher\ to power in-conversation search (Cmd+F) with case-insensitive matching and navigation; \ChatInputHistory\ to enable terminal-style Up/Down arrow navigation through previous messages in the composer; \ChatExportOptions\ to manage user preferences for chat exports; \ChartSpec\ to define data models for chart rendering; \AlignmentPreparationState\ to track model alignment progress; and \ChatConfiguration\ to define user-facing chat settings like hotkeys, system prompts, and model overrides.
Packages/OsaurusCore/Models/Chat · high confidence
New common UI components and layout primitives
The Common views package now includes a suite of reusable SwiftUI components to standardize the application's visual language and improve layout consistency. This adds animated progress indicators (shimmer bars, typing indicators, status dots), a modern animated tab selector with badge support, and a unified capsule badge for status chips. It also introduces a robust code block renderer with syntax highlighting and caching, a flow layout for wrapping items, and glassmorphism styling for backgrounds and list rows. Additionally, new utilities include a fitted sheet frame modifier to prevent footer clipping on small screens, an IME-aware text field for better input method support, and an empty state view for model lists.
Packages/OsaurusCore/Views/Common · high confidence
New configuration models for Claude Code, Codex CLI, and MCP providers
The application now includes dedicated configuration models for integrating with the Claude Code CLI, the OpenAI Codex CLI, and remote Model Context Protocol (MCP) providers. Users can now use Osaurus to drive their local Claude Code installation as a subprocess, configure Osaurus as a model provider for the Codex CLI, and manage remote MCP providers with support for OAuth 2.1 authentication, HTTP and stdio transports, and sandboxed execution.
Packages/OsaurusCore/Models/Configuration · high confidence
New core data models for background tasks, permissions, and system integrations
This update introduces foundational data models that enable new agent capabilities and system integrations. It adds \BackgroundTaskModels\ to support agent requests that run independently of the chat window, including state tracking and activity feeds. A new \SystemPermission\ enum defines granular macOS permissions (such as Calendar, Mail, Messages, and Full Disk Access) required by built-in tools. The diff also includes models for a native iMessage channel (\IMessageConnectionConfiguration\), directory change detection (\DirectoryFingerprint\), and run auditing (\RunTrace\), alongside a unified toast notification system (\Toast\) for user feedback.
Packages/OsaurusCore/Models · high confidence
New cryptographic identity system with per-agent access keys and drift detection
The Identity package introduces a new cryptographic identity framework that manages a secp256k1 Master Key in iCloud Keychain and derives unique, device-scoped addresses for each agent. Users can now generate, list, and revoke \osk-v1\ access keys scoped to specific agents or the master identity, with automatic validation and revocation propagation via an epoch-based validator. The system includes a health check that detects identity drift (e.g., from Keychain resets) and identifies stale keys or mismatched agent addresses, ensuring that local identity state remains consistent with the server.
Packages/OsaurusCore/Identity · high confidence
New evaluation harness commands for regression, optimization, and reporting
The \osaurus-evals\ CLI now includes several new subcommands to support advanced evaluation workflows. The \agent-loop-lab\ command runs and compares agent-loop regression reports, while \optimize-context\ provides a staged context-optimization loop with census, candidate generation, and Pareto ranking. New reporting tools include \report\ for generating maintainer-facing eval artifact bundles, \scoreboard\ for aggregating watcher artifacts, and \scorecard\ for offline Computer Use report aggregation. Additionally, \diff\ and \matrix\ commands allow for pure file-based comparison of eval reports across domains and performance metrics, and \capture-screen\ enables local accessibility tree capture for screen-context tuning.
Packages/OsaurusEvals/Sources · high confidence
New hybrid search and orchestration for Methods
This change introduces the MethodSearchService and MethodService in the OsaurusCore package. MethodSearchService provides hybrid search (BM25 + vector) over methods using VecturaKit, including initialization, indexing, removal, and diagnostic capabilities. MethodService acts as the orchestrator for the methods subsystem, handling CRUD operations, scoring based on outcomes, and extracting tool and skill IDs from YAML bodies. Together, these services enable robust search and management of methods within the application.
Packages/OsaurusCore/Services/Method · high confidence
New knowledge curation workflow with proposal review and Git-backed collections
This update introduces a structured curation system for knowledge documents. Agents can now propose changes to knowledge files, which are held as pending proposals until a user reviews and approves them via the new KnowledgeCurationService. Approved proposals are written atomically to the collection folder, re-indexed for immediate searchability, and committed to Git if the collection is Git-backed. The system includes a new KnowledgeDiff tool for displaying line-level changes in the review sheet, a KnowledgeFolderWatcher to trigger incremental indexing on file changes, and a KnowledgeLinkResolver that makes knowledge document paths in chat clickable. Additionally, the KnowledgeIndexService now supports incremental indexing by content hash and excludes common build/dependency directories to improve performance and relevance.
Packages/OsaurusCore/Services/Knowledge · high confidence
New knowledge management interface with write history and approval previews
The Knowledge tab now features a dedicated Collections view for managing searchable corpora, alongside a new History tab that logs agent-generated content in grouped runs for easy review and reversion. A new preview component displays detailed diffs and operation types (create, replace, delete) within permission modals, allowing users to evaluate agent-suggested changes before approval.
Packages/OsaurusCore/Views/Knowledge · high confidence
New local networking and HTTP server infrastructure
The local networking layer has been rebuilt to support peer discovery and a robust HTTP API. BonjourAdvertiser and BonjourBrowser now enable automatic local discovery of paired agents via mDNS, including secure channel validation and IP fallbacks. A new HTTPHandler (powered by SwiftNIO) provides a high-performance local server with OpenAI, Anthropic, and OpenResponses-compatible endpoints, complete with protocol-specific error formatting, streaming coalescing, and request parsing. Global proxy support is now centralized in GlobalProxySettings, which caches configuration and reuses URLSession instances to prevent resource leaks. Additionally, HostAPIBridgeServer exposes a Unix domain socket for containerized host communication, and AgentRunUsage tracks per-turn token metrics.
Packages/OsaurusCore/Networking · high confidence
New model management views for AppleScript, Image Generation, and Hugging Face tokens
Added new SwiftUI views in the Model section to manage specific model types and credentials: \AppleScriptModelsView\ for configuring on-device AppleScript automation models and permissions, \ImageGenerationPanelView\ and \ImageModelsDownloadView\ for manual image generation/editing and managing image model bundles, \HuggingFaceTokenViews\ for managing Hugging Face access tokens to improve download speeds, and \ModelCacheInspectorView\ for inspecting and unloading cached runtime models. These views provide dedicated interfaces for these features, integrating with the existing model download and management infrastructure.
Packages/OsaurusCore/Views/Model · high confidence
New model runtime diagnostics, event streaming, and image generation services
The ModelRuntime service now exposes a comprehensive live diagnostics snapshot (BatchDiagnosticsSnapshot) for the Settings panel, detailing engine capacity, cache hit/miss rates, and disk cache pressure. It introduces a typed event pipeline (ModelRuntimeEvent) that streams granular generation progress—including reasoning text, prefill stages, and tool-call deltas—mapped from the underlying vmlx-swift engine. Additionally, a new ImageGenerationService bridges the native mFLUX engine, enabling on-device text-to-image and image editing capabilities with dedicated download, cancellation, and model management flows.
Packages/OsaurusCore/Services/ModelRuntime · high confidence
New on-device PII detection and redaction review interface
Users can now enable an opt-in, on-device AI model (Rampart) for personal information detection, with a dedicated Privacy settings tab to manage rules, providers, and model status. The system includes a rule builder for custom patterns, a download prompt for the \~37MB model, and a review sheet that appears before cloud sends to let users approve, skip, or always-approve detected PII, ensuring no unscrubbed text is sent without explicit consent.
Packages/OsaurusCore/PrivacyFilter/Views · high confidence
New pairing approval dialog with persistent access control
A new PairingApprovalView has been introduced to handle device pairing requests on the advertiser side. This UI component allows users to approve or deny pairing requests and includes a toggle to remember the device permanently, which prevents access expiration after 90 days. The view also displays the remote device's address and provides assurance that the connection will be end-to-end encrypted via the Osaurus Secure Channel.
Packages/OsaurusCore/Views/Pairing · high confidence
New plugin model layer and sandbox provisioning infrastructure
This change introduces the core data models and configuration structures for the plugin and sandbox subsystem. It adds \ExternalPlugin.swift\ to define the frozen C ABI host API struct and function pointers used to load and communicate with external plugins, ensuring ABI compatibility across versions. It introduces \SandboxPlugin.swift\ to define the JSON recipe format for sandbox plugins, including tool specifications, daemon specs, and secrets, while removing the legacy \mcp:\ field in favor of explicit MCP provider configuration. Additionally, it adds \SandboxConfiguration.swift\ for persisting sandbox settings (CPU, memory, network, per-agent environments), \ProvisioningJourney.swift\ to model the observable sandbox boot lifecycle with step-by-step progress and ETAs, \SandboxAgentMap.swift\ for persistent Linux username-to-agent UUID mapping, and \PluginHTTP.swift\ for HTTP request/response models and a per-plugin rate limiter.
Packages/OsaurusCore/Models/Plugin · high confidence
New provider credential prompt sheet with inline connection testing
Users can now authenticate provider credentials directly within a new, branded SwiftUI sheet that appears during chat-driven onboarding or connection tests. This view supports both API key entry (with optional extra fields like Azure endpoints) and OAuth flows, and includes an inline "Test connection" button that verifies credentials and displays the number of available models before saving. The interface uses consistent themed input fields and visual styling to match the Settings experience, ensuring a unified look and feel whether configuring providers manually or via the assistant.
Packages/OsaurusCore/Views/Provider · high confidence
New sandbox plugin management system with library, installation, and lifecycle controls
The plugin manager now supports a dedicated sandbox plugin ecosystem, introducing a central library for storing plugin recipes (with version history and rollback capabilities) and a manager for installing, configuring, and uninstalling these plugins within isolated Linux containers. This change adds full lifecycle management for sandbox plugins, including dependency installation, file seeding, and setup command execution, while decoupling plugin definitions from per-agent installation states to improve reliability and user control over agent capabilities.
Packages/OsaurusCore/Managers/Plugin · high confidence
New sandbox runtime architecture with live execution streaming and hardened egress
The sandbox service has been refactored to support a more robust and secure runtime. Live command execution (\sandbox\_exec\, \shell\_run\) now streams output directly to the chat UI via a new \LiveExecRegistry\ and \LiveExecSink\, allowing users to see real-time terminal output and terminate running jobs. Sandbox provisioning is now per-agent, with isolated Linux users and dedicated bridge tokens for secure host-guest communication. Network egress is strictly controlled via a new policy engine that supports open, allowlist, or no-network modes, with DNS rebinding protection and per-agent domain filtering. The sandbox image is now pinned by content digest to prevent tampering, and the system includes improved diagnostics, logging, and event bus capabilities for plugins.
Packages/OsaurusCore/Services/Sandbox · high confidence
New shared settings UI primitives for consistent styling and search highlighting
A new \SettingsPrimitives.swift\ file introduces reusable SwiftUI components (\SettingsSection\, \SettingsField\, \SettingsSubsection\, \StyledSettingsTextField\) that standardize the look and feel of the Settings interface. These primitives integrate with the theme manager for consistent styling and include built-in support for search landing anchors and visual highlighting, allowing settings controls to glow when matched by the search feature.
Packages/OsaurusCore/Views/Settings/Shared · high confidence
New skill management interface with dedicated editor sheet
The Skills view in Settings has been redesigned to provide a comprehensive management interface for creating, editing, and organizing skills. This update introduces a new \SkillEditorSheet\ that allows users to define specialized AI guidance through a split-pane interface, featuring a form for metadata (name, description, version, author, category, keywords) alongside a dedicated markdown instructions editor. The main \SkillsView\ now supports tabbed navigation to filter between all skills, custom user-created skills, and the Claude Plugins marketplace, along with search functionality and improved visual states for empty lists and progress indicators.
Packages/OsaurusCore/Views/Skill · high confidence
New slash command management interface
Users can now create, edit, and delete custom slash commands via a new management view accessible from the Commands tab in the sidebar. This interface allows users to define reusable prompt shortcuts that can be inserted into the chat input by typing a specific name preceded by a slash, with support for custom icons, descriptions, and templates.
Packages/OsaurusCore/Views/SlashCommand · high confidence
New storage layer for Agent Channels and Agent Database
The storage package now includes dedicated, encrypted SQLite backends for Agent Channels and the Agent Database feature. AgentChannelMessageStore provides durable, provider-neutral storage for channel messages and attachments, while AgentDatabase and AgentDatabaseStore manage per-agent SQLite instances with soft-delete, audit logging, and configurable storage quotas. ChatHistoryDatabase and ChatHistoryWriter have been refactored to support these new structures, and AttachmentBlobStore introduces content-addressed, encrypted spillover for large chat attachments to prevent database bloat.
Packages/OsaurusCore/Storage · high confidence
New theme model and library management with raw JSON editing
The application now features a comprehensive, user-customizable theme system. This includes a new data model supporting full color palettes, glass effects, typography, and background images, along with a local theme library that allows users to import, export, and manage themes. A key addition is the ability to edit theme configurations directly via raw JSON, which includes safeguards to prevent main-thread hangs from large image payloads. The system also introduces native macOS theme defaults that follow the system accent color and improves performance by offloading theme loading from the main thread.
Packages/OsaurusCore/Models/Theme · high confidence
New themed toast notification system with glass styling and global overlay support
The app now features a comprehensive, themed toast notification system. This includes a new \ThemedToastView\ for lightweight inline notifications and a robust \ToastContainerView\ that manages positioning, stacking, and animations for standard toasts. The system supports four notification types (success, error, warning, info) with distinct icons and accent colors, and utilizes a consistent glass-based visual style with hover effects. Additionally, a global \ToastWindowController\ provides system-level toast overlays that appear above all app windows, and a convenient \withToastOverlay()\ modifier allows easy integration of toast support into any view.
Packages/OsaurusCore/Views/Toast · high confidence
New tool search and indexing infrastructure
Introduced \ToolIndexService\ and \ToolSearchService\ to manage a unified tool index backed by SQLite and VecturaKit. This new system syncs tools from the \ToolRegistry\ into a searchable index, supporting hybrid search (BM25 + embeddings) to improve how tools are discovered and selected by the agent, while also providing diagnostic snapshots for troubleshooting tool exposure and search relevance.
Packages/OsaurusCore/Services/Tool · high confidence
New voice configuration models for transcription, TTS, and wake-word detection
This change introduces four new configuration models in the Voice package to manage voice features: SpeechConfiguration for FluidAudio transcription settings (including model version, input source, and stop modes), TTSConfiguration for text-to-speech options (supporting both on-device PocketTTS and OpenAI-compatible remote servers), TranscriptionConfiguration for global hotkey-triggered voice-to-text input, and VADConfiguration for wake-word agent activation. These models include persistence logic and default values, laying the groundwork for user-facing settings in these areas.
Packages/OsaurusCore/Models/Voice · high confidence
New voice input settings and controls
The Voice settings area now includes a dedicated Transcription Mode tab where users can configure a global hotkey for voice input, adjust pause and confirmation delays, and enable LLM-based transcription cleanup to remove filler words. A new HotkeyRecorder component allows users to record and display custom keyboard shortcuts, while the TranscriptionOverlayView provides a floating UI with waveform visualization and manual stop/cancel controls for transcription sessions.
Packages/OsaurusCore/Views/Voice · high confidence
On-device PII detection via lightweight Rampart model
Users now have a lightweight, on-device PII detection capability powered by the Rampart MLX BERT model (\~37MB), which serves as an alternative to the larger OpenAI privacy filter bundle. This change introduces a new model manager and privacy detector that download, cache, and load the model locally, performing named entity recognition directly on the device. The implementation ensures UI responsiveness by running downloads and MLX inference off the main thread, while also handling GPU resource contention via a dedicated gate to prevent conflicts with other Metal operations. The system supports progress tracking, cancellation, and removal of the cached model, and maps detected entities to standard categories for consistent redaction behavior.
Packages/OsaurusCore/PrivacyFilter/Rampart · high confidence
Osaurus CLI introduces benchmarking, declarative config, and MCP bundle support
The Osaurus CLI now includes several new capabilities: \osaurus bench\ provides standardized performance benchmarking (TTFT, prefill, decode) with optional per-model prefill tuning; \osaurus config\ enables declarative configuration management via export, plan (dry-run), and apply subcommands; \osaurus bundle load\ allows loading and running MCP Bundles (.mcpb files); and \osaurus doctor\ offers installation diagnostics with optional signature verification. These commands are part of a broader CLI restructuring that also includes \osaurus coord\ for local coordinator orchestration and \osaurus tools\ for plugin management.
Packages/OsaurusCLI · high confidence
Osaurus app bundle initialization and configuration
The Osaurus application now includes its core bundle configuration, introducing a new Metal-based animated orb shader for the UI, per-agent permission gating for system access (Calendar, Contacts, Reminders, Location, Automation, and Microphone), and a configurable keyboard shortcut where Command+N can start a new chat in the current window instead of opening a new window. The app also supports deep links for HuggingFace and Osaurus, Bonjour discovery for local agents, and includes generated open-source acknowledgments and localized strings for German, Korean, Russian, and Chinese.
App/osaurus · high confidence
Privacy filter model bundle download and verification
The privacy filter now downloads its detection model bundle (openai-privacy-filter-bf16-v1) from Hugging Face into a dedicated local directory. This process includes downloading required files like model weights and tokenizer, generating a local manifest with SHA-256 hashes for integrity verification, and providing UI-visible download progress and state management. The system verifies file integrity upon download and allows users to re-verify or remove the bundle if needed.
Packages/OsaurusCore/PrivacyFilter/Model · high confidence
Redesigned 3-screen onboarding flow with dedicated design system
The onboarding experience has been completely redesigned as a 3-screen flow (Welcome, Create Dino, Configure AI) running in a fixed 1000×640 dark window. This update introduces a dedicated design system (\OnboardingDesign\, \OnboardingComponents\, \OnboardingMotion\) that standardizes colors, typography, layout, and animations across the new screens. Users now select a specialty for their first 'Dino' (Everyday helper, Research & writing, or Coding & development) and choose a 'brain' source (Hosted, Local MLX, Bring-Your-Own-Key provider, or Claude Code CLI). The flow includes improved telemetry tracking for funnel drop-offs and brain source selection, and moves usage data consent to the first step to ensure accurate analytics capture.
Packages/OsaurusCore/Views/Onboarding · high confidence
Schedule automation history summaries and exports
Users can now view and export detailed history for scheduled automations. The new ScheduleHistoryService aggregates local run data with database records to generate summaries including recent run status, duration, and error diagnostics. These summaries are available as structured JSON or formatted Markdown tables, facilitating easier auditing and reporting of schedule performance.
Packages/OsaurusCore/Services/Schedule · high confidence
Share and import themes via deep links and a central library management center
Users can now share custom themes to the themes.osaurus.ai server and import them on other devices using deep links (osaurus://themes-install). This change introduces a new Theme Library Management Center that provides a summary of built-in, local, imported, and shared themes, along with validation reports and duplicate detection. The underlying service layer handles theme encoding, EIP-191 signing for ownership verification, and API communication for uploading and downloading theme JSON payloads.
Packages/OsaurusCore/Services/Themes · high confidence
Support for agent pairing via deep links
The app now handles \osaurus://\ deep links to initiate agent pairing. When a user opens a pairing URL, the system decodes the invite, validates its signature and expiration, and presents an approval sheet. Expired or invalid invites trigger error toasts instead of proceeding with the pairing flow.
Packages/OsaurusCore/Services/Pairing · high confidence
Support for importing and managing Claude plugins
Users can now import Claude plugins, which are installed as bundles of skills, agent schedules, slash commands, and MCP providers. The system provides a detailed install report so users can see exactly what was imported, what was skipped, and what requires attention (such as missing environment variables, OAuth sign-ins, or cron configurations). Plugin metadata is persisted locally to support rich UI cards and version checks, and sensitive configuration values are handled securely via the keychain.
Packages/OsaurusCore/Services/Skill · high confidence
Support for running MCP servers on the host or in a sandbox
Users can now configure MCP servers to run either directly on the host machine or within an isolated sandbox environment. The host runner spawns the configured command as a child process and connects to it via stdio pipes, while the sandbox runner executes the command inside a Linux container (requiring macOS 26 or later) to provide stronger isolation. Both modes include stderr capture for better error visibility and use shared spawn-limiting logic to prevent resource exhaustion during launch storms.
Packages/OsaurusCore/Services/MCP/Stdio · high confidence
Unified OAuth sign-in and provider connectivity diagnostics
Remote provider setup is streamlined with a new \OAuthSignInCoordinator\ that centralizes OAuth flows for OpenRouter (PKCE to API key) and ChatGPT/Codex (PKCE to tokens), replacing scattered inline implementations. A new \ProviderCredentialPromptService\ provides a reusable, modal credential sheet that safely handles API keys and OAuth tokens without exposing secrets to the LLM context. Additionally, a \ProviderConnectivityCenter\ aggregates health checks and diagnostics for all remote providers, surfacing connection status, authentication issues, and model availability directly in the Settings dashboard to help users troubleshoot provider problems.
Packages/OsaurusCore/Services/Provider · high confidence
Vendored SQLCipher 4.6.1 for encrypted local storage
Osaurus now includes a vendored copy of the SQLCipher 4.6.1 amalgamation (exposed as the \OsaurusSQLCipher\ SwiftPM target) to provide full database encryption. This replaces reliance on the system SQLite library for core storage operations, enabling AES-256 encryption via Apple's CommonCrypto provider without external OpenSSL dependencies. The integration includes specific header guards to prevent symbol collisions with Apple's system \SQLite3\ module in the Swift build environment.
Packages/OsaurusCore/SQLCipher · high confidence
Removals
Removal of default SwiftUI app entry point and content view
The default SwiftUI application structure has been removed from the osaurus module. Specifically, the \ContentView.swift\ file, which previously displayed a placeholder globe icon and greeting, and the \osaurusApp.swift\ file, which served as the \@main\ entry point launching that view, have both been deleted. This change eliminates the initial UI scaffold provided by the template.
osaurus · high confidence
Security
Hardened plugin installation with cryptographic verification and safe extraction
The plugin installation workflow now enforces strict security and reliability checks. Plugin artifacts are verified using SHA-256 checksums and minisign (Ed25519) signatures before installation, with support for TOFU (Trust On First Use) key pinning to prevent silent key rotation attacks. Archive extraction is now bounded and validated against path traversal, symlink, and resource exhaustion attacks, ensuring that only safe, verified content is published to the local plugin directory.
Packages/OsaurusRepository · high confidence
Behavioural changes
2 commits (0 fixes) modifying assets
A change to existing behaviour in assets — 2 commits, 1 file.
assets · medium confidence · unverified
Added benchmark results and OpenAI compatibility report
The results directory now includes a comprehensive set of benchmark artifacts, including a CSV and JSON summary comparing performance (TTFT, total time, throughput) across osaurus, ollama, and lmstudio servers using the llama-3.2-3b-instruct model. Additionally, an OpenAI compatibility report confirms successful streaming for both text generation and tool calling, supported by raw HTTP headers, raw stream payloads, and structured JSONL chunk files for text and tool streams.
results · high confidence
Agent loop stability and context budgeting overhaul
The chat service introduces a unified agent tool-loop driver that consolidates iteration budgets, deduplication, and next-step nudges into a single implementation, replacing scattered logic across chat, HTTP, and plugin surfaces. A new state machine tracks tool results to prevent redundant re-execution and stalls, while a context preview system prices draft agent capabilities against the model's window to warn users before sending. Additionally, reasoning policies are standardized to preserve explicit user choices across agent and tool requests, and voice activation now uses a background detector to avoid main-thread hangs.
Packages/OsaurusCore/Services/Chat · high confidence
Configurable autonomy policy for Computer Use actions
The Computer Use feature now replaces its previous hardwired behavior with a configurable autonomy policy. Users can select from five presets (Read-only, Cautious, Balanced, Trusted, Autonomous) that determine whether actions like editing or sending are auto-run, confirmed, or blocked. The system enforces a strictest-wins merge of global presets, per-app overrides, and per-agent ceilings, and includes an allowlist to restrict which apps can be controlled. Additionally, a context-sensitive classifier escalates actions to 'consequential' status when they involve irreversible commits or sensitive targets, ensuring that risky operations always require user confirmation.
Packages/OsaurusCore/ComputerUse/Policy · high confidence
Configured Swift Package Manager mirrors for Hugging Face repositories
The project now includes a \mirrors.json\ configuration file that redirects Swift Package Manager requests for \swift-transformers\ and \Jinja\ (originally hosted under \huggingface/swift-transformers\ and \huggingface/swift-jinja\) to the \osaurus-ai\ GitHub organization. This ensures that dependency resolution uses the maintained forks rather than the upstream Hugging Face repositories, supporting the hardening and lifecycle changes introduced in the \vmlx-swift-lm\ update.
App/osaurus.xcodeproj/project.xcworkspace · high confidence
Declarative configuration schema and apply pipeline for delegation, channels, and integrations
The declarative configuration system now supports a unified YAML-based approach for managing agent delegation, channel routing, and integrations. The new \DelegationSection\ allows users to configure spawn pools, permission defaults, and resource budgets for subagents, while explicitly handling the migration of removed keys like \image\_enabled\ and \spawnable\_models\ with helpful hints. Channel configurations for Discord, Slack, Telegram, iMessage, and WhatsApp are now manageable via declarative documents, covering read/write policies, allowlists, and inbound dispatch targets, with secrets like bot tokens handled securely via references. Additionally, user-defined slash commands and knowledge collections can be exported and applied, providing a consistent, idempotent way to manage these integrations alongside the existing agent and model configurations.
Packages/OsaurusCore/Configuration · high confidence
Evals harness relocated, hardened, and expanded with context-optimization and new test suites
The OsaurusEvals package has been moved to its own directory and significantly expanded. The CLI now supports running multiple suites in a single process, repeating cases, resuming interrupted runs, and generating detailed transcripts for failures. A new context-optimization harness allows staged ablation and strict promotion gates for prompt changes. New test suites cover AgentDB, AgentChannels, DefaultAgent, HTTPAPI, JudgeCalibration, Memory, MicroPerf, PrefixHash, PromptInjection, ReasoningChannel, SandboxDiagnostics, SandboxFrontier, ScreenContext, Schema, Subagent, ToolEnvelope, ToolResultGrounding, and WorkspaceDelegation. The entitlements have been updated to support Apple Containerization Linux VMs for sandbox testing. The browser plugin is superseded by a native browser capability for evals.
Packages/OsaurusEvals · high confidence
File watchers now support configurable responsiveness and workspace agent dispatch
The file system watcher model has been updated to allow users to control how quickly the system reacts to changes via a new \Responsiveness\ setting, offering six tiers from 'Fast' (200ms) to 'Extended' (10 minutes) to suit different workflows like screenshots, batch downloads, or long writing sessions. Additionally, watchers can now be configured to dispatch tasks to shared workspace agents rather than just local ones, enabling collaborative automation, while maintaining backward compatibility with existing local watcher configurations.
Packages/OsaurusCore/Models/Watcher · high confidence
Global proxy configuration now validates and rejects invalid ports
The new GlobalProxyConfiguration struct in OsaurusNetworking enforces strict validation on proxy settings, specifically rejecting ports outside the valid 1–65535 range (including 0 and values like 70000). This prevents invalid port numbers from being passed to the underlying CFNetwork proxy dictionary, ensuring that malformed proxy URLs are caught early with clear error messages rather than causing silent failures or network issues.
Packages/OsaurusNetworking · high confidence
Improved app stability and responsiveness through backgrounding and timeout controls
This update introduces several utility components to prevent main-thread hangs and ensure graceful shutdowns. A new \AsyncDeadline\ primitive enforces timeouts during app quit teardown, preventing the application from hanging indefinitely if a plugin or model load stalls. \ConfigDiskWriter\ offloads configuration file persistence to a background queue, keeping the UI responsive during frequent auto-saves. Additionally, \ActivityTracker\ handles periodic memory data purging off the main thread, and \FileDescriptorLimit\ raises the system file-descriptor limit at launch to prevent crashes under heavy load.
Packages/OsaurusCore/Utils · high confidence
Introduces Seatbelt sandbox fallback for macOS versions prior to 26
Adds a host-level sandboxing backend using \sandbox-exec\ for macOS versions below 26, allowing sandboxed commands to run confined by a deny-by-default Seatbelt profile when the Containerization VM is unavailable. This fallback ensures that older systems can still execute commands with path and network confinement, while macOS 26 and later continue to use the full VM isolation. The implementation includes a hardened runtime executor that manages process lifecycle, output collection, and inactivity timeouts, with specific handling for xcrun cache preparation to prevent hangs during sandbox entry.
Packages/OsaurusCore/Services/Sandbox/Seatbelt · high confidence
MCP OAuth sign-in now supports automatic discovery and dynamic client registration
The MCP OAuth integration has been upgraded to automatically discover authorization server metadata (RFC 9728/8414) and register the application as a public native client (RFC 7591) without requiring manual configuration. This change enables seamless sign-in for servers like Notion and Atlassian by handling canonical resource URL normalization, single-flight token refreshes, and secure loopback redirects, while also allowing manual overrides for providers that do not support automatic discovery.
Packages/OsaurusCore/Services/MCP/OAuth · high confidence
MCP provider diagnostics and reliability overhaul
The MCP service layer now includes comprehensive diagnostics and stability improvements. Users benefit from explicit provider probing that generates detailed health snapshots and diagnostic reports, visible in the Server Hub dashboard. Authentication failures are now classified specifically (e.g., distinguishing between missing tokens and rejected API keys) to provide clearer error messages. Tool discovery has been fixed to correctly handle paginated responses, ensuring no tools are silently dropped. Additionally, a global limit on concurrent MCP child processes prevents resource exhaustion, and HTTP transport timeouts have been adjusted to prevent premature disconnection of long-running tool calls or streaming sessions.
Packages/OsaurusCore/Services/MCP · high confidence
Memory system overhaul: improved stability, performance, and security
The memory subsystem has been significantly restructured to enhance stability, performance, and security. A new DistillationCoordinator ensures that heavy MLX model operations are serialized and yield to live chat, preventing app hangs and excessive cold loads. Memory consolidation now persists its last run state, ensuring background tasks like salience decay and eviction occur reliably after restarts. The memory context assembly has been optimized to inject only one relevant section per turn (defaulting to \~800 tokens) instead of five large sections, reducing token usage and improving response times. A new Memory Management Console provides users with tools to inspect, search, and disable specific memory items, with sensitive data automatically redacted. Security has been strengthened through per-agent partitioning of vector indexes to prevent cross-agent data leakage, and while full vector encryption is not yet wired up, the system relies on SQLCipher-encrypted source data to mitigate risks. Additionally, embedding services now strictly validate model requests to prevent silent corruption of vector indexes.
Packages/OsaurusCore/Services/Memory · high confidence
Memory system restructured into v2 with simplified configuration and management console
The memory system has been upgraded to v2, replacing the previous per-turn extraction model with a session-based distillation approach that produces a single digest per conversation. This change simplifies user configuration by collapsing 18 previous tunable settings into 8 core options, including a unified token budget and salience floor. The new architecture organizes memory into three persistent layers: Identity (stable user facts), Pinned Facts (salience-scored, promoted facts with decay), and Episodes (per-session summaries). Additionally, a new Memory Management Console has been introduced, providing an administrative view to inspect, search, and manage memory items (pinned facts, episodes, and transcripts) with privacy-safe redaction.
Packages/OsaurusCore/Models/Memory · high confidence
Native macOS driver for Computer Use brought in-core
The native macOS driver for Computer Use has been moved into the core package, replacing the previous external dependency. This change introduces a new input-routing layer that uses private SkyLight APIs for backgrounded input (avoiding cursor warping) with a Chromium-aware fallback strategy, and adds snapshot-scoped accessibility element caching to prevent stale UI interactions. It also includes a new screenshot capture path using ScreenCaptureKit with optional Set-of-Mark (SOM) annotations, allowing vision-first models to reason over annotated screenshots while maintaining stable element IDs for actions.
Packages/OsaurusCore/ComputerUse/Driver/Mac · high confidence
New Agent Management UI and Configuration Surfaces
This change introduces a comprehensive redesign of the Agent management experience, replacing the previous interface with a new set of SwiftUI views. Users can now reorder custom agents via a dedicated drag-and-drop sheet, manage agent capabilities through a grouped tool picker that distinguishes between built-in, plugin, MCP, and sandbox sources, and view a live context-usage estimate in the new Abilities Overview. The update also standardizes the visual identity across local and remote agent details with shared chrome components, adds support for custom agent avatars (including mascot selection and image caching), and introduces a 'Shared with' section for workspace collaboration.
Packages/OsaurusCore/Views/Agent · high confidence
New Cursor rules for settings cataloging and testing workflows
This change introduces new configuration files for the Cursor AI assistant to guide development practices. A new \settings-catalog.mdc\ rule enforces that all user-facing settings are registered in the \SettingsSearchIndex\ to ensure discoverability in Management search and the Orchestrator, requiring updates to anchors, guides, and self-find probes. A \testing-workflow.mdc\ rule defines when to run the full test suite (before PR submission) versus targeted tests (during development), including specific environment variables and commands. Additionally, \settings.json\ enables the Sentry plugin within Cursor.
.cursor · high confidence
New model management and discovery architecture
The app introduces a comprehensive model management system that centralizes catalog browsing, local model discovery, and update checking. Users can now filter the model catalog by type (LLM/VLM), size, parameter count, and hardware fit (e.g., 'Runs well' vs 'Hide not recommended'). The system automatically checks for official model updates from Hugging Face, displaying status badges for current, available, or verification-required models. A new caching layer ensures the model picker remains responsive and consistent, even when remote providers change or local models are downloaded/deleted. Additionally, speech model management is now handled separately, supporting FluidAudio Parakeet models with background disk state probing to avoid launch delays.
Packages/OsaurusCore/Managers/Model · high confidence
New tool management and approval infrastructure
The Tools section now features a redesigned catalog that groups tools into Built-in, Plugins, Connections, and Custom sections, with user-facing status indicators (Ready, Off, Needs attention) and filters for status and source. Tool enablement, permission policies (Auto, Ask, Deny), and requirement grants are now persisted in a dedicated configuration file with background coalescing to prevent main-thread hangs. Approval cards display the execution surface (Sandbox VM, Native Mac, or Remote MCP server) to inform consent, and a new global setting allows auto-allowing all tool calls. Detailed diagnostics are available for troubleshooting tool exposure and availability.
Packages/OsaurusCore/Models/Tool · high confidence
New unified Settings interface with global search and collapsible sidebar
The Settings window has been redesigned with a macOS System Settings-inspired layout, featuring a collapsible sidebar navigation that supports search filtering across all tabs. A new global search capability allows users to find specific settings from any tab, with a highlight effect to guide them to the matched control. The interface includes a new Acknowledgements view for third-party licenses, a unified header component for consistent styling, and a badge store to optimize performance by coalescing updates from various managers.
Packages/OsaurusCore/Views/Management · high confidence
OsaurusCore: New app lifecycle, out-of-process plugin host, and computer-use target resolution
OsaurusCore introduces a new AppDelegate that prevents macOS from terminating the app while the local LLM server is active, suppresses the SwiftUI Settings placeholder to avoid launch flashes, and raises file descriptor limits to prevent NIO crashes. It adds an out-of-process PluginHost that communicates via JSON-RPC over stdin/stdout, allowing the main app to kill and respawn wedged plugins without hanging the entire application. Additionally, it includes a TargetResolver for the Computer Use feature that maps model targets (marks or descriptions) to live UI elements, handling staleness and ambiguity through re-observation.
Packages/OsaurusCore · high confidence
Plugin ABI v6 introduces agent-scoped dispatch, inference, and structured memory management
The Osaurus Plugin ABI has been updated to version 6, introducing stricter security boundaries and new capabilities for plugin developers. Plugins can now initiate background tasks via \osr\_dispatch\_fn\ and perform AI inference via \osr\_complete\_fn\, both of which are strictly scoped to the invoking agent to prevent cross-agent data leakage. The ABI also standardizes memory ownership, requiring plugins to use the host-provided \free\_string\ callback for strings returned by host functions, and enforces a structured JSON error envelope for all host callbacks except configuration retrieval. Legacy entry points remain supported for backward compatibility, but new plugins should target v6 to access these features.
Packages/OsaurusCore/Tools/PluginABI · high confidence
Project structure reorganization and build configuration updates
The Xcode project has been reorganized, moving the project file to the App directory and introducing a new 'Frameworks' group to manage dependencies like OsaurusCore. The build configuration now includes local Swift package references for OsaurusRepository, OsaurusCLI, and OsaurusCore, and enables dead code stripping and symbol generation for optimized builds. Additionally, the project supports a wider range of languages including Simplified Chinese, Russian, and German, and updates the Xcode version check to 2630.
App/osaurus.xcodeproj · medium confidence
Redesigned sandbox provisioning and post-start onboarding experience
The sandbox dashboard now features a dedicated provisioning journey view that displays a detailed, step-by-step progress list with live status icons, byte-level progress, and an estimated time of arrival, replacing the previous single-line progress indicator. A new 'Post Start Tasks' card appears on the dashboard during the plugin verification phase to inform users that plugins are being restored, including specific plugin names and phases, before self-hiding upon completion. The main sandbox view has been optimized to load configuration immediately on appearance, eliminating the previous fade-in delay when switching tabs, and includes a new security banner prompting users to restart the sandbox to apply per-agent bridge token updates.
Packages/OsaurusCore/Views/Sandbox · high confidence
Removal of user-specific Xcode scheme configuration
The user-specific scheme management file (xcschememanagement.plist) has been removed from the project. This change eliminates local, per-user Xcode scheme settings, ensuring that scheme configurations are no longer tracked in version control and will default to shared or system settings for all users.
osaurus.xcodeproj · high confidence
Strict RAM admission and residency handoff for subagents
Subagent spawning now enforces a strict RAM-safety sequence (unload main model, load delegate, run, unload delegate, reload main) and prices child runs against their actual bounded request rather than a global retention cap. This prevents unaffordable GPU/RAM usage by ensuring delegated context windows, token limits, and tool-loop attempts are clamped to the agent's configured budgets, while residency handoffs guarantee the parent model is always restored even if a run fails.
Packages/OsaurusCore/Subagent · high confidence
Theme library management with sharing, importing, and performance fixes
Users can now share and import themes via deep links and web URLs through new Share and Import sheets, and manage their collection in a redesigned Themes gallery with filtering, search, and duplicate detection. The theme editor has been overhauled to include a live preview, raw JSON editing, and independent glass-effect toggles, while background image decoding is offloaded to a background cache to eliminate UI freezes and jitter during scrolling and editing.
Packages/OsaurusCore/Views/Theme · high confidence
Unified agent tooling and configuration surfaces
Osaurus introduces a consolidated set of built-in tools that standardize how agents interact with the system. Agent loop control is now handled by three core tools (\todo\, \complete\, \clarify\) that manage task checklists and session flow. Sandbox access is unified into a five-tool vocabulary (\sandbox\_read\_file\, \sandbox\_search\_files\, \sandbox\_write\_file\, \sandbox\_exec\, \sandbox\_install\) with a placeholder tool to handle container provisioning. Configuration is centralized into a single \osaurus\_config\ tool that replaces nine legacy per-domain write tools, while \osaurus\_inspect\ and \osaurus\_help\ provide read-only access to system state. Agent communication channels (Discord, Slack, etc.) are now exposed through a dedicated \AgentChannelTools\ module with strict permission policies, and a new \get\_current\_time\ tool allows local models to answer time-based queries without guessing.
Packages/OsaurusCore/Tools · high confidence
Updated Xcode scheme configuration for build and test actions
The Xcode scheme for the osaurus app has been updated to explicitly configure build and test actions. The build action now includes the OsaurusCoreTests target alongside the main app, with parallelization enabled. The test action is configured to run OsaurusCoreTests by default while skipping the osaurusTests and osaurusUITests targets, ensuring that core unit tests are executed during standard scheme-based testing workflows.
App/osaurus.xcodeproj/xcshareddata · high confidence
Fixes
Prevents crashes from Objective-C exceptions in Swift code
Added a new Objective-C helper function, \osr\_catch\_exception\, which wraps framework calls that may raise \NSException\ (such as non-thread-safe \NSPasteboard\ operations) in a \@try\/\@catch\ block. This allows Swift code to catch these exceptions as recoverable errors instead of having them terminate the process, addressing app hangs and crashes reported in Sentry.
Packages/OsaurusCore/ObjCSupport · high confidence
Replaced legacy Keychain storage with a hardened, typed, and non-blocking secret management system
The Keychain service layer has been completely rewritten to eliminate main-thread hangs and improve error visibility. The new implementation introduces typed outcomes for reads, writes, and enumerations, distinguishing between definitive failures (item not found) and transient issues (locked keychain, access denied), which prevents false 'missing credential' warnings and allows for specific user-facing recovery instructions. To resolve UI freezes, all synchronous Keychain mutations are now offloaded to a serial background queue, and presence checks are cached to avoid repeated blocking decryption calls during chat composition. The system also supports an in-memory store for testing and live-proof modes, and includes a read-through migration to recover plugin secrets that were lost during previous agent-scoping changes.
Packages/OsaurusCore/Services/Keychain · high confidence
Test coverage
Added comprehensive test coverage for AppleScript subagent behaviors; Added comprehensive test coverage for Identity subsystem; Added comprehensive test coverage for core tooling and agent capabilities; Added comprehensive test coverage for storage and database subsystems; Added comprehensive test coverage for subagent delegation, residency, and budget enforcement; Added comprehensive test coverage for the Computer Use driver; Added comprehensive test coverage for the Osaurus Router; Added comprehensive test coverage for the PrivacyFilter pipeline; Added configuration tests for agent routing, migration, and declarative schema validation; Added model-layer test coverage for Anthropic API, Claude Code integration, and model management; Added provider tests for Anthropic streaming, MCP tool management, and OpenAI Codex OAuth; Added test coverage for Computer Use privacy, autonomy, and perception components; Added test coverage for Discord connection and gateway presence runtime; Added test coverage for MCP OAuth and provider diagnostics; Added test coverage for Telegram connection configuration and API client behavior; Added test coverage for agent delegation dispatcher, image generation, and concurrency controls; Added test coverage for agent identity, capability readiness, and description backfill logic; Added test coverage for knowledge document editing, curation, and indexing; Added test coverage for native browser use and chat agent loop budgeting; Added test coverage for onboarding configuration, telemetry, and crash reporting; Added test coverage for plugin lifecycle, background task scheduling, and ABI handshake; Added test coverage for the native iMessage agent channel; Added test coverage for the native search engine and declarative provider backends; Added test coverage for theme system core logic; Added test fixture for Computer Use proof lane; Added tests for Agent Channel core logic and security hardening; Added tests for Agent Channel security and remote safety gates; Added tests for Computer Use authorization and evidence pack logic; Added tests for Computer Use diagnostics and gate inspection; Added tests for Computer Use loop robustness and history management; Added tests for Insights address abbreviation, connection activity, P2P source, and wire body round-trip; Added tests for agent power management, sheet fitting, and alert center logic; Added tests for clipboard diagnostics redaction and plugin tool state management; Added tests for document format adapters, registry, and studio services; Added tests for feature and memory telemetry event shapes; Added tests for inline math scanning, search crash prevention, and workspace explainer layout; Added tests for per-app recipe matching and effect classification; Added tests for schedule execution anchoring and history management; Added tests for support diagnostics bundle redaction and fixture generation; Added tests for the Evidence Report Registry service; Added tests for the agent collaboration protocol contract; Added tests for voice transcription normalization, TTS chunking, and OpenAI-compatible TTS client; Added unit tests for Computer Use model decoding and view logic; Added unit tests for OsaurusCore request decoding and tool registry configuration; Added unit tests for Slack connection security and configuration; Added unit tests for core utility components; Added unit tests for sandbox tool execution, file routing, and provisioning diagnostics; Added unit tests for skill and plugin management logic; Added unit tests for the Memory subsystem; Expanded test coverage for OsaurusCore networking components; Expanded test coverage for core service behaviors; Expanded test coverage for folder file operations; Expanded test coverage for the OsaurusEvalsKit harness; New deterministic evaluation harnesses for agent capabilities and runtime behavior; Removed placeholder unit test file; Stabilize parallel test execution with process-wide serialization locks.
Dependencies
Dependency updates and new package manifests
This change updates several Swift and Go dependencies and introduces new Swift Package Manager manifests for the Osaurus CLI, Core, Evals, Networking, Plugin Test Kit, Stats Pack, and Repository modules. Key version bumps include sentry-cocoa (9.15.0 → 9.18.0), Sparkle (2.9.1 → 2.9.3), grpc-swift-2 (2.4.0 → 2.4.1), grpc-swift-protobuf (2.3.0 → 2.4.0), swift-certificates (1.19.0 → 1.19.1), async-http-client (1.33.1 → 1.34.0), IkigaJSON (2.4.3 → 2.5.2), and swift-argument-parser (1.7.1 → 1.8.2). The Go helper for WhatsApp integration now uses go 1.25.0, updates go-sqlite3 to v1.14.49, and bumps golang.org/x/crypto to v0.54.0. A new benchmark requirements file pins httpx to \>=0.27.0,\<0.28.
(dependencies) · high confidence
Housekeeping
Added empty Secrets configuration file
An empty Secrets.xcconfig file has been added to the App directory, likely serving as a placeholder for build configuration secrets that are excluded from version control.
App · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 45 → 43 (-2.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 92 → 78 (-14.1)
- Architecture 96 → 88 (-7.3)
- Maturity 72 → 81 (+9.7)
- Readiness 27 → 60 (+33.2)
- Security 39 → 70 (+31.1)
- Domain Modelling 100 (new)
- Event-Driven 10 (new)
- Performance 100 (new)
Resolved (51)
- Dimension evaluation failed
- High IaC: DS-0002 (sandbox/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 31 more
New (4759)
- AccessKeysSection.accessKeyRow (cognitive 16) (Packages/OsaurusCore/Views/Settings/ServerView.swift)
- AccessibilityManager.focusedWindowHasContent (cognitive 25) (Packages/OsaurusCore/ComputerUse/Driver/Mac/Accessibility.swift)
- AccessibilityManager.traverse (cognitive 22) (Packages/OsaurusCore/ComputerUse/Driver/Mac/Accessibility.swift)
- AccessibilityManager.traverse (cyclomatic 19) (Packages/OsaurusCore/ComputerUse/Driver/Mac/Accessibility.swift)
- AccessibilityManager.traverseElement (cognitive 49) (Packages/OsaurusCore/ComputerUse/Driver/Mac/Accessibility.swift)
- AccessibilityManager.traverseElement (cyclomatic 41) (Packages/OsaurusCore/ComputerUse/Driver/Mac/Accessibility.swift)
- ActivateWorkspaceSheet.body (cognitive 18) (Packages/OsaurusCore/Views/Workspaces/WorkspaceSheets.swift)
- ActivateWorkspaceSheet.body (cyclomatic 16) (Packages/OsaurusCore/Views/Workspaces/WorkspaceSheets.swift)
- AgentAction.argumentsJSON (cognitive 28) (Packages/OsaurusCore/ComputerUse/Model/AgentAction.swift)
- AgentAction.argumentsJSON (cyclomatic 23) (Packages/OsaurusCore/ComputerUse/Model/AgentAction.swift)
- AgentAction.semanticProblem (cognitive 23) (Packages/OsaurusCore/ComputerUse/Model/AgentAction.swift)
- AgentAction.semanticProblem (cyclomatic 22) (Packages/OsaurusCore/ComputerUse/Model/AgentAction.swift)
- AgentBundleService.resolveImportIdentity (cognitive 16) (Packages/OsaurusCore/Services/AgentBridge/AgentBundleService.swift)
- AgentBundleService.resolveImportIdentity (cyclomatic 17) (Packages/OsaurusCore/Services/AgentBridge/AgentBundleService.swift)
- AgentCapabilityReadiness.subagent (cognitive 25) (Packages/OsaurusCore/Models/Agent/AgentCapabilityReadiness.swift)
- AgentCapabilityReadiness.subagent (cyclomatic 19) (Packages/OsaurusCore/Models/Agent/AgentCapabilityReadiness.swift)
- AgentCard.body (cognitive 16) (Packages/OsaurusCore/Views/Agent/AgentsView.swift)
- AgentChannelAutoDestinationResolver.derivedBindings (cognitive 18) (Packages/OsaurusCore/Services/AgentChannel/AgentChannelAutoDestinationResolver.swift)
- AgentChannelConnectionCenterView.applyNativeBadges (cyclomatic 16) (Packages/OsaurusCore/Views/Settings/AgentChannelConnectionCenterView.swift)
- AgentChannelConnectionDraft.validationFindings (cognitive 27) (Packages/OsaurusCore/Views/Settings/AgentChannelCustomConnectionSheet.swift)
- …and 4739 more
Changes since last survey
- 300 commits — 255 feature/other, 45 fixes
By area
- Packages/OsaurusCore — 266 commits
- docs/appcast.xml — 22 commits
- Packages/OsaurusEvals — 7 commits
- (repo) — 1 commit
- Packages/OsaurusCLI — 1 commit
- reports/community — 1 commit
- scripts/build — 1 commit
- scripts/ci — 1 commit
Notable commits
- fix: Add Osaurus ID in Identity and fix Workspaces constant refresh (#2749)
- fix: Advance the vmlx-swift pin to 1315fdcb (DeepseekV3 MoE f32 residual fix) (#2573)
- fix: Fix Orchestrator row selection and fit the chat window to small screens (#2730)
- fix: Fix RAM admission measurement, capacity and token-budget contracts (#2752)
- fix: Fix SSD cache sizing and current-chat capacity notices (#2836)
- fix: Fix app hang from standardizedFileURL in LocalVisionEvidence (#2844)
- fix: Fix app hang in ChatSession.sessionRouterCacheStats getter (#2830)
- fix: Fix app hang in SelectableNSTextView.hitTest (#2827)
- fix: Fix context compaction: chat-model fallback, visible failures, always-available Compact button (#2843)
- fix: Fix covariant Self default argument in ProductHuntLaunchCampaign init (#2906)
- fix: Fix daily schedule double-fire and launch replay (#2770)
- fix: Fix description backfill after in-flight prompt edits (#2897)
- fix: Fix embedding discovery in configured models directory (#2570)
- fix: Fix integer setting editing and persistence, search, and follow-up parsing (#2893)
- fix: Fix resident child RAM admission and external model residency tracking (#2784)
- fix: Fix sequential spawn capacity after active file-cache growth (#2535)
- fix: Fix stale agent completion and heal misaligned model bundles (#2567)
- fix: Fix timing export choices for restored chats (#2902)
- fix: Fix: Prevent main thread hang when opening MarkdownLinkText URLs (#2864)
- fix: Pin runtime with composite and recurrent disk-cache fixes (#2896)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
osaurus-ai/osaurus was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 74e83c6c52c1da2421e594147294277de829bc06 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-eb9197011364.