unicity-aos/aos-ce
78.1
Strong · 29 September 2026
64k
lines of production code
Rust
with Swift
2
measurements over time
What this system is
This system is an open-source Agent Operating System (AOS) that provides a modular, capsule-based runtime for executing AI agents with sandboxed tool access. It manages the full lifecycle of agent interactions, including LLM provider integration, conversation context compaction, and secure session state persistence. The platform supports native macOS and Linux deployments with a command-line interface and a dedicated tray application for user approvals and private input handling.
Features
AOS Command Center and native private input console
The AOS bootstrap crate now includes a terminal-based Command Center console for reviewing agent requests and handling private input. This adds new CLI commands (\aos status\, \aos principals\, \aos native-setup\) and a \command\_center\ module that launches the native macOS Command Center app on start. The console handles approval requests and private input (secrets, text, arrays) via a secure Unix socket, enforcing strict file permissions and user ownership for credentials.
crates/unicity-aos-bootstrap · high confidence
AOS Community Edition initial release with signed channels and native macOS Command Center
AOS Community Edition is now available as an open agent operating system, dual-licensed under MIT or Apache 2.0. The release introduces a signed, authenticated installation pipeline supporting stable, dev, and nightly channels, with native Linux musl archives and macOS filesystem app installation. A new macOS Command Center provides a native menu-bar interface for permission approvals and private input, integrated with the \aos mcp serve\ command via a local interaction socket. The product includes a bounded Rhai script runtime, semantic surface catalogs, and a Forge tool for building capsules. The installer supports idempotent upgrades and state migration from standalone Astrid runtimes, while legacy private permissions are repaired during upgrades to ensure secure runtime state.
(repo-wide) · high confidence
Initial release of Unicity AOS capsule components
This change introduces the initial set of Unicity AOS capsule components, including the CLI proxy, context engine, agent injector, filesystem tools, and the forge development tooling. Each capsule is defined by a \Capsule.toml\ manifest specifying its WASM target, IPC subscriptions, and publish capabilities, and is supported by CI workflows that build the WASM artifacts and package them into installable \.capsule\ archives.
capsules · high confidence
Introduce Context Engine capsule for session compaction
The new Context Engine capsule manages conversation context windows by compacting messages when they exceed a token budget. It exposes IPC topics for compacting sessions and estimating token counts, and supports pluggable interceptor hooks that allow other capsules to protect specific messages or skip compaction entirely. The default compaction strategy preserves recent turns and protected messages while removing the oldest non-protected messages to stay within the target token limit.
capsules/capsule-context-engine, crates, distros/community · high confidence
Introduce MCP broker with approval, grant, and discovery subsystems
Added the \aos-mcp-broker\ crate, establishing a new broker-side front door for MCP interactions that sits alongside the existing agent-runner path. This includes an approval bridge (\approval.rs\) that relays host-side capability-approval requests to the Claude shim and manages the result drain after a decision is made, and a grant-decision module (\grant\_decision.rs\) that persists user consent for capsule access to prevent session wedges. The broker also implements tool discovery (\discovery.rs\) with a KV-backed cache (\cache.rs\) to short-circuit descriptor lookups, and an execution layer (\execute.rs\) that handles tool dispatch with timeout-bounded result drains. Additionally, a hook gate (\hook\_gate.rs\) was added to evaluate native tool calls via the \before\_tool\_call\ event, applying the same policy decisions as the broker's MCP tool plane.
crates/aos-mcp-broker · high confidence
Introduce OpenAI-compatible LLM provider capsule
Added a new \capsule-openai-compat\ component that enables the system to connect to any OpenAI-compatible Chat Completions API (such as OpenAI, Groq, Together, Mistral, DeepSeek, and Fireworks). This capsule subscribes to generation requests, forwards them via HTTP, parses SSE streaming responses, and publishes standardized stream events. It includes logic to discover available models from the upstream provider, handles environment-based configuration for base URLs and API keys, and ensures robust handling of whitespace-only credentials to prevent authentication errors.
capsules/capsule-openai-compat · high confidence
Introduce Unicity AOS agent capsule ecosystem
This change introduces the initial set of agent capsules for the Unicity AOS product, providing the core capabilities for agent interaction and tool execution. The \capsule-agents\ and \capsule-memory\ modules inject project-specific instructions (AGENTS.md) and cross-session memory (memory.md) into the system prompt. The \capsule-cli\ establishes the connection layer, binding CLI clients to principals and demuxing traffic by session to prevent cross-talk. The \capsule-fs\, \capsule-http\, and \capsule-shell\ modules provide agents with sandboxed tools for file operations, HTTP fetching, and secure shell command execution. Finally, \capsule-session\ manages conversation history and thread metadata, while \capsule-router\ and \capsule-users\ handle tool dispatch and user identity resolution respectively.
(repo-wide) · high confidence
Introduce Unicity CE distribution manifest
The Unicity CE distribution is now available as a curated bundle of capsules for the agent operating system experience. The new \Distro.toml\ manifest defines the complete set of components, including uplinks (CLI, MCP, registry), core infrastructure (session, identity, router, context-engine), tools (shell, http, fs), and extensions (skills, agents, memory). It also specifies the minimum compatible Astrid runtime version (\>=2026.9.4) and provides configuration variables for optional LLM providers like OpenAI. The distribution is dual-licensed under MIT or Apache 2.0.
distros/community/unicity-ce · high confidence
Introduce headless native Rust reference shell for the Adaptive Workspace
The \adaptive-shell\ crate provides a deterministic, headless Rust runner for the AOS Adaptive Workspace, enabling users to validate activity placement, layout, and theming without a browser or native window backend. It includes an Activity Atlas for live deterministic previews and direct placement (Master, Stack, Tab, Float, New-activity), supports desktop (master-plus-stack, grid, single, focus) and phone (one-card) layout rules, and exposes 62 semantic component identities with Fieldglass dark, light, and high-contrast themes (including density, text scale, and reduced-motion settings). Users can run deterministic snapshots via CLI flags (\--headless\, \--fixture desktop\|phone\|theme-lab\, \--theme\, \--density\, \--scale\, \--reduced-motion\, \--json\) to verify stable node identity, keyed reconciliation, and backend-neutral display lists.
apps/adaptive-shell · high confidence
Introduce native OpenAI LLM provider and ReAct orchestration capsule
Added the \capsule-openai\ native provider, which implements the OpenAI Responses API (\/v1/responses\) with support for streaming, structured outputs, and tool calling, including a static model catalog for GPT-5.x and o-series models. Added the \capsule-react\ ReAct loop coordinator, which manages the reasoning-and-action cycle, handles session state persistence, and orchestrates interactions with the LLM provider and tool router.
capsules/capsule-openai, capsules/capsule-react · high confidence
Introduce native macOS menu-bar shell for AOS
Adds a new macOS menu-bar application (AOS Tray) that serves as a local companion for the AOS runtime. The app provides a native UI for inspecting runtime status and capsule libraries, managing volume mounts, and handling private input requests (text, secrets, selections, arrays) via a dedicated native window. It supports automatic login item registration, reconnection logic for volume-backed credentials, and explicit binary/home configuration without relying on system PATH or auto-starting daemons.
apps/aos-tray · high confidence
Introduce prompt builder capsule with plugin hook interception
The new \capsule-prompt-builder\ capsule now assembles LLM prompts by intercepting plugin hooks via IPC. It fires a \before\_build\ hook to collect plugin responses (such as system context additions or full prompt overrides), merges them according to defined semantics (e.g., last non-null system prompt wins, concatenated context prefixes), and returns the final assembled prompt to the react loop. The implementation includes configurable timeouts for hook responses and handles edge cases like empty overrides or slow plugins.
capsules/capsule-prompt-builder · high confidence
New LLM Provider Registry capsule for model discovery and selection
The capsule-registry capsule introduces a centralized registry for discovering available LLM providers via IPC fan-out and managing the active model selection. It exposes IPC topics for querying providers, getting/setting the active model, and receiving change events, while also providing a CLI interface for model management. The implementation includes robust validation for request IDs to prevent topic injection, deduplication of provider entries, and a multi-pass resolution algorithm for selecting models by canonical ID, bare model name, or qualified ID.
capsules/capsule-registry · high confidence
New capsule release validation script
A new Python script, \scripts/capsule\release.py\, has been added to validate Community Edition capsule source and release artifacts. This tool enforces release contracts by verifying that capsule directories are allowed, ensuring Cargo and Capsule manifests match, checking that package identities follow the \aos-\\ convention, and validating the structure and safety of the resulting capsule archives.
python · high confidence
New manifest validation and comprehensive Forge documentation
The capsule-forge tool now includes a new \validate\_manifest\ function that performs pragmatic linting on \Capsule.toml\ files, checking for required package fields, valid semantic versions, correct component definitions, and proper capability types (lists vs booleans) to catch common author mistakes early. This is accompanied by a complete set of new documentation guides covering the AOS architecture, capsule anatomy, manifest structure, IPC routing, security boundaries, and the meta-harness workflow, providing agents with authoritative reference material for building and managing capsules.
capsules/capsule-forge · high confidence
New release infrastructure and validation scripts
The scripts directory now includes a comprehensive suite of new tools to support the AOS release pipeline. This includes \build-command-center.sh\ for assembling and signing the macOS Command Center app, \build-capsule-assets.sh\ for building capsule packages, and \channel\_transaction.py\ / \channel\_publication.py\ for managing atomic channel updates. Security and compatibility are enforced via \check\_glibc.py\, \check\_static\_elf.py\, and \musl\_release\_metadata.py\. Additionally, \aos-filesystem.sh\ handles macOS filesystem provider setup, \bind-rehearsal-consumed-artifacts.sh\ manages rehearsal artifacts, and \nightly\_version.py\ automates nightly versioning. A frozen shape fixture (\astrid-094-frozen-shape.json\) and its generator (\create-astrid-094-fixture.py\) ensure consistent runtime environments.
scripts · high confidence
Dependencies
Unicity AOS runtime and capsule dependencies pinned to Astrid 2026.9.4
The Unicity AOS runtime and its associated capsules now depend on the Astrid SDK and core libraries at version 2026.9.4. This update aligns the AOS product with the latest Astrid release, ensuring compatibility with the current runtime environment and providing access to the latest features and fixes available in the Astrid ecosystem.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 79 → 78 (-0.7)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 88 → 86 (-1.4)
- Architecture 100 → 99 (-0.6)
- Maturity 71 → 71 (+0.1)
- Readiness 80 → 77 (-3.1)
- Security 92 → 88 (-4.0)
- Event Sourcing 100 (new)
- Performance 100 (new)
Resolved (20)
- Documentation: no architecture or design documentation (apps/adaptive-shell/README.md)
- Documentation: no architecture or design documentation (capsules/capsule-prompt-builder/README.md)
- Documentation: no installation or build instructions (capsules/capsule-prompt-builder/README.md)
- Documentation: no usage examples (capsules/capsule-prompt-builder/README.md)
- Duplicated block (10 lines × 2) (crates/aos-mcp-broker/src/approval.rs)
- Duplicated block (11–13 lines × 2) (crates/unicity-aos-bootstrap/src/main.rs)
- Duplicated block (13 lines × 2) (crates/aos-mcp-broker/src/broker.rs)
- Duplicated block (13 lines × 2) (crates/aos-mcp-broker/src/execute.rs)
- Duplicated block (16 lines × 2) (crates/aos-mcp-broker/src/approval.rs)
- Duplicated block (5 lines × 2) (crates/unicity-aos-bootstrap/src/migration.rs)
- Hotspot: apps/adaptive-shell/src/fixtures.rs (apps/adaptive-shell/src/fixtures.rs)
- Hotspot: apps/adaptive-shell/src/input.rs (apps/adaptive-shell/src/input.rs)
- Hotspot: apps/adaptive-shell/src/main.rs (apps/adaptive-shell/src/main.rs)
- Hotspot: capsules/capsule-cli/src/lib.rs (capsules/capsule-cli/src/lib.rs)
- Hotspot: capsules/capsule-hook-adapter-oracle/src/lib.rs (capsules/capsule-hook-adapter-oracle/src/lib.rs)
- Hotspot: capsules/capsule-hook-bridge/src/lib.rs (capsules/capsule-hook-bridge/src/lib.rs)
- Hotspot: capsules/capsule-openai/src/lib.rs (capsules/capsule-openai/src/lib.rs)
- Hotspot: capsules/capsule-react/src/lib.rs (capsules/capsule-react/src/lib.rs)
- Hotspot: crates/unicity-aos-bootstrap/src/migration.rs (crates/unicity-aos-bootstrap/src/migration.rs)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (crates/unicity-aos-bootstrap/src/distro_trust.rs)
New (89)
- Ambiguous verb semantics for process execution. 'spawn' typically implies backgrounding, 'exec' implies replacing the current process, and 'run' is ambiguous (could be either). Having three distinct methods with overlapping argument signatures (args: I) creates confusion about which one to use for standard background execution vs foreground blocking vs process replacement.
- App::key (cyclomatic 19) (crates/unicity-aos-bootstrap/src/console/mod.rs)
- CapsuleLibraryView.body (cognitive 22) (apps/aos-tray/Sources/AOSTray/CapsuleLibraryView.swift)
- Confusingly similar names for potentially distinct paths. 'runtime_home' and 'run_root' sound semantically identical or closely related (home vs root of the run directory). Without documentation, it is unclear if these refer to the same logical directory structure or different layers of the filesystem hierarchy.
- Coverage not measured — Swift suite
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Documentation: no project overview (capsules/capsule-openai-compat/README.md)
- Documentation: no project overview (capsules/capsule-prompt-builder/README.md)
- Documentation: no project overview (capsules/capsule-shell/README.md)
- Duplicated block (10 lines × 2) (apps/aos-tray/Sources/AOSTrayCore/CommandCenterVolume.swift)
- Duplicated block (10 lines × 2) (crates/unicity-aos-bootstrap/src/cli/principals.rs)
- Duplicated block (10 lines × 2) (crates/unicity-aos-bootstrap/src/mcp/mod.rs)
- Duplicated block (10 lines × 2) (scripts/capsule_release.py)
- Duplicated block (11 lines × 2) (crates/unicity-aos-bootstrap/src/cli/principals.rs)
- Duplicated block (15 lines × 2) (apps/aos-tray/Sources/AOSTrayCore/CommandCenterVolume.swift)
- Duplicated block (16 lines × 2) (apps/aos-tray/Sources/AOSTrayCore/PrincipalDiscovery.swift)
- Duplicated block (17–18 lines × 2) (apps/aos-tray/Sources/AOSTrayCore/PrincipalDiscovery.swift)
- Duplicated block (17–18 lines × 2) (scripts/musl_release_metadata.py)
- Duplicated block (19–22 lines × 2) (scripts/release_metadata.py)
- Duplicated block (22 lines × 2) (apps/aos-tray/Sources/AOSTray/LibraryPrincipalForm.swift)
- …and 69 more
Changes since last survey
- 23 commits — 8 feature/other, 15 fixes
By area
- crates/unicity-aos-bootstrap — 7 commits
- (root) — 6 commits
- apps/aos-tray — 5 commits
- crates/aos-mcp-broker — 2 commits
- .github/workflows — 1 commit
- capsules/capsule-identity — 1 commit
- scripts/sign-command-center.sh — 1 commit
Notable commits
- fix: fix(approval): bind grants to pending requests (#171)
- fix: fix(bootstrap): refresh selected authenticated Distro capsules (#186)
- fix: fix(bootstrap): separate runtime minimum from release identity (#183)
- fix: fix(desktop): launch Command Center with AOS (#188)
- fix: fix(identity): require approval before persistence (#172)
- fix: fix(install): verify signed inventory without external b3sum (#194)
- fix: fix(macos): keep AOS usable without unsupported desktop components (#202)
- fix: fix(mcp): bind results to discovered providers (#174)
- fix: fix(release): make upgrades and first-run setup reliable (#179)
- fix: fix(release): notarize Command Center with Apple ID credentials (#196)
- fix: fix(release): resolve Command Center signing in temporary keychain (#197)
- fix: fix(runtime): bound default musl compiler parallelism (#195)
- fix: fix(tray): reconnect when volume-backed credentials return (#184)
- fix: fix(update): provide an authenticated read-only channel check (#198)
- fix: fix(upgrade): repair legacy private permissions (#190)
- change: feat(console): present local approvals with nonblocking MCP status (#193)
- change: feat(desktop): add native AOS Command Center and private input (#167)
- change: feat(desktop): mount and open principal files from Command Center (#185)
- change: feat(init): add calm onboarding progress (#181)
- change: feat(mcp): handle native multi-round input requests (#168)
- …and 3 more
Architecture
- Unchanged — 0 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
unicity-aos/aos-ce was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit af23fd5944195b8fab2dc238304175a8355d0857 — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-705631bb727e.