astrid-runtime/astridPublic

Astrid is a portable, capability-secure operating system for composable software.

AI summary: A highly isolated, WebAssembly-based agent runtime designed for multi-tenant, zero-trust AI workloads.

Stars
10.3K
Forks
133
Watchers
22
Open issues
145
Open PRs
19
Contributors
~4
Commits
518
Branches
131

RustApache-2.0Created Feb 15, 2026Last push 8d agoLatest release v0.10.4

Star history

since Apr 12, 2026
05K10KApr 2026May 2026Jun 2026Jul 2026
10.3K stars as of Jul 29, 2026, tracked back to Apr 12, 2026. Historical curve reconstructed from public GitHub event archives, calibrated to the current total.

Contribution activity

commits per day, last 52 weeks
AugSepOctNovDecJanFebMarAprMayJunJulMonWedFri2025-08-02: 0 commits2025-08-03: 0 commits2025-08-04: 0 commits2025-08-05: 0 commits2025-08-06: 0 commits2025-08-07: 0 commits2025-08-08: 0 commits2025-08-09: 0 commits2025-08-10: 0 commits2025-08-11: 0 commits2025-08-12: 0 commits2025-08-13: 0 commits2025-08-14: 0 commits2025-08-15: 0 commits2025-08-16: 0 commits2025-08-17: 0 commits2025-08-18: 0 commits2025-08-19: 0 commits2025-08-20: 0 commits2025-08-21: 0 commits2025-08-22: 0 commits2025-08-23: 0 commits2025-08-24: 0 commits2025-08-25: 0 commits2025-08-26: 0 commits2025-08-27: 0 commits2025-08-28: 0 commits2025-08-29: 0 commits2025-08-30: 0 commits2025-08-31: 0 commits2025-09-01: 0 commits2025-09-02: 0 commits2025-09-03: 0 commits2025-09-04: 0 commits2025-09-05: 0 commits2025-09-06: 0 commits2025-09-07: 0 commits2025-09-08: 0 commits2025-09-09: 0 commits2025-09-10: 0 commits2025-09-11: 0 commits2025-09-12: 0 commits2025-09-13: 0 commits2025-09-14: 0 commits2025-09-15: 0 commits2025-09-16: 0 commits2025-09-17: 0 commits2025-09-18: 0 commits2025-09-19: 0 commits2025-09-20: 0 commits2025-09-21: 0 commits2025-09-22: 0 commits2025-09-23: 0 commits2025-09-24: 0 commits2025-09-25: 0 commits2025-09-26: 0 commits2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 7 commits2026-02-12: 3 commits2026-02-13: 3 commits2026-02-14: 3 commits2026-02-15: 1 commit2026-02-16: 10 commits2026-02-17: 9 commits2026-02-18: 14 commits2026-02-19: 4 commits2026-02-20: 4 commits2026-02-21: 11 commits2026-02-22: 9 commits2026-02-23: 8 commits2026-02-24: 0 commits2026-02-25: 2 commits2026-02-26: 1 commit2026-02-27: 1 commit2026-02-28: 1 commit2026-03-01: 0 commits2026-03-02: 2 commits2026-03-03: 0 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 7 commits2026-03-07: 6 commits2026-03-08: 2 commits2026-03-09: 0 commits2026-03-10: 2 commits2026-03-11: 8 commits2026-03-12: 11 commits2026-03-13: 21 commits2026-03-14: 20 commits2026-03-15: 12 commits2026-03-16: 3 commits2026-03-17: 6 commits2026-03-18: 5 commits2026-03-19: 3 commits2026-03-20: 7 commits2026-03-21: 8 commits2026-03-22: 5 commits2026-03-23: 5 commits2026-03-24: 5 commits2026-03-25: 6 commits2026-03-26: 3 commits2026-03-27: 1 commit2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 0 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 0 commits2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 0 commits2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 3 commits2026-04-17: 0 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 0 commits2026-04-21: 1 commit2026-04-22: 2 commits2026-04-23: 2 commits2026-04-24: 1 commit2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 0 commits2026-04-28: 1 commit2026-04-29: 0 commits2026-04-30: 1 commit2026-05-01: 0 commits2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 0 commits2026-05-05: 0 commits2026-05-06: 0 commits2026-05-07: 0 commits2026-05-08: 0 commits2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 7 commits2026-05-15: 11 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 1 commit2026-05-19: 2 commits2026-05-20: 0 commits2026-05-21: 0 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 6 commits2026-05-26: 0 commits2026-05-27: 0 commits2026-05-28: 3 commits2026-05-29: 12 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 2 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 2 commits2026-06-05: 15 commits2026-06-06: 3 commits2026-06-07: 2 commits2026-06-08: 4 commits2026-06-09: 0 commits2026-06-10: 4 commits2026-06-11: 3 commits2026-06-12: 0 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 4 commits2026-06-16: 14 commits2026-06-17: 6 commits2026-06-18: 2 commits2026-06-19: 4 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 5 commits2026-06-23: 11 commits2026-06-24: 22 commits2026-06-25: 0 commits2026-06-26: 3 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 0 commits2026-06-30: 2 commits2026-07-01: 2 commits2026-07-02: 9 commits2026-07-03: 11 commits2026-07-04: 8 commits2026-07-05: 0 commits2026-07-06: 1 commit2026-07-07: 1 commit2026-07-08: 7 commits2026-07-09: 1 commit2026-07-10: 6 commits2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 4 commits2026-07-14: 4 commits2026-07-15: 10 commits2026-07-16: 1 commit2026-07-17: 5 commits2026-07-18: 0 commits2026-07-19: 3 commits2026-07-20: 8 commits2026-07-21: 5 commits2026-07-22: 1 commit2026-07-23: 4 commits2026-07-24: 14 commits2026-07-25: 1 commit2026-07-26: 1 commit2026-07-27: 4 commits2026-07-28: 1 commit2026-07-29: 5 commits2026-07-30: 0 commits2026-07-31: 0 commits2026-08-01: 0 commits
517 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    10,306 stars

  • Well documented

    High community health score

  • Permissive license

    Apache-2.0

  • Continuous integration

    Automated checks passing

  • Repeat trending

    4 trending appearances

What astrid does

Astrid functions as an operating system kernel for AI agents. Rather than running agent code directly on the host, it orchestrates stateless 'capsules' compiled to WebAssembly (WASM). These capsules run inside Wasmtime sandboxes with no syscalls, no file descriptors, and no host memory access by default. The core daemon acts merely as a dumb event router enforcing a strict capability-based IPC bus. It guarantees strong tenant isolation via a per-principal design where agents get separate KV namespaces, secret stores, quotas, and cryptographically signed audit chains. This architecture ensures that compromised tools or prompt injection attacks cannot access the host machine or read data from other agents running on the same daemon.

Astrid is built for platform engineers, security teams, and AI researchers who need to deploy agentic workflows in production environments where strict isolation, auditability, and zero-trust execution are mandatory.

  • WASM sandboxing: Executes agent tools as stateless WebAssembly components using Wasmtime, completely eliminating ambient authority and arbitrary syscalls.
  • Zero-trust kernel: Operates a strict IPC event bus where every external effect (network, filesystem) is gated by explicit, granular capability tokens.
  • Per-principal isolation: Runs each agent identity as an isolated tenant with its own secure KV store, secrets, resources, and access lists.
  • Cryptographic audit chains: Records every decision and host call in a hash-linked, ed25519-signed JSONL log to mathematically prove execution history.
  • Hot-reloadable capsules: Allows developers to install, upgrade, or remove WASM tools on a live daemon without requiring a process restart.

Where teams use it

Secure multi-tenant AI agents

Enterprise platforms deploy Astrid to run hundreds of different user agents securely on the same machine without risking cross-tenant data leaks.

Untrusted tool execution

Security engineers use Astrid to sandbox LLM-generated code or third-party plugins in environments where prompt injection is a known risk.

Verifiable agent compliance

Financial and healthcare organizations leverage the cryptographically signed audit chain to prove exactly which actions an autonomous agent took.

Self-modifying AI systems

Advanced research agents utilize the Astrid SDK to dynamically write, compile, and hot-load new WASM tool capsules safely on the fly.

Getting started: astrid init --distro @yourorg/your-distro astrid chat

README

main branch

Astrid

A portable, capability-secure operating system for composable software.

CI CodeQL License: MIT OR Apache-2.0 MSRV Rust 2024 The Astrid Book


Astrid treats a component the way an operating system treats a process. Every ability is a sealed WebAssembly capsule: it can be composed with other capsules, granted only explicit authority, and replaced without expanding its reach. Astrid is independent of any particular product, model provider, agent loop, user interface, or distribution.

The kernel underneath is small and deliberately dumb. It routes events, enforces capabilities, runs the sandbox, and records the audit trail; it holds no model, tool schema, or business logic. A jailbreak, poisoned tool, or plain bug still cannot read a file, reach a network, or spawn a process outside its grant. Authority is a capability the kernel enforces, not an instruction the model is trusted to follow.

Quick start

brew tap astrid-runtime/tap && brew install astrid
astrid init --distro @yourorg/your-distro
astrid start
astrid status
astrid capsule list

Astrid Runtime does not select or bundle a product distro. Choose a distro you trust and pass its name, repository, local Distro.toml, or signed .shuttle archive explicitly with --distro. Operators running an uncomposed runtime can skip init and start the daemon directly.

Start with the Book for the architecture or the Contributor Handbook to contribute.

Why Astrid exists

Agent frameworks put trust in the prompt. Astrid puts it in the runtime. An agent is untrusted code executing on your machine with access to your files, your network, and your credentials. Telling it to behave is not a security boundary. An OS-grade boundary is.

  • Cryptographic capability model. Every file path, network host, and tool is a signed ed25519 grant scoped to a resource pattern, principal-bound, expiry-checked, and globally revocable. No grant, no access.
  • WASM sandbox with no ambient authority. Capsules run in Wasmtime with no syscalls, no file descriptors, and no host memory. Every external effect is a capability-checked host call over a WIT-typed ABI.
  • The kernel is dumb. It instantiates an event bus, loads capsules, and routes IPC bytes under a capability ACL. It has no LLM handles, no conversation state, and no tool registry. All intelligence lives in capsules, so a capsule bug cannot corrupt shared kernel state.
  • Per-principal everything. Each identity gets isolated capsule access, KV data, secrets, home directory, quotas, and audit chain. One principal can never read another's namespace, and it fails closed if the caller cannot be resolved.
  • Signed, hash-linked audit chain. Each entry seals the hash of the one before it and is signed. Break the chain and the tampering shows.
  • Live capsule lifecycle. Install, upgrade, and remove capsules on a running daemon. No restart.

How it works

Frontends (the CLI, the HTTP gateway, Discord, and so on) are uplinks: protocol clients that connect to the daemon over a Unix domain socket and speak in IPC events. There is no Frontend trait. An uplink publishes events and receives responses like any other bus participant.

flowchart TB
    CLI[CLI] -->|IPC events over Unix socket| Kernel
    HTTP[HTTP gateway] -->|IPC events| Kernel
    Discord[Discord] -->|IPC events| Kernel
    Uplinks[Other uplinks] -->|IPC events| Kernel

    subgraph Runtime[Astrid]
        Kernel[Kernel: astrid-daemon<br/>dumb event router<br/>event bus - capability ACL - audit chain - Wasmtime sandbox]
        Capsules[WASM Component capsules: wasm32-unknown-unknown<br/>providers - orchestrators - tools - fs - http - sessions - registry - identity]
    end

    Kernel -->|capability-checked host calls<br/>astrid:* WIT ABI| Capsules
Loading

Capsules communicate exclusively through the bus. Each declares what it needs and what it provides in a Capsule.toml manifest with typed [imports]/[exports] tables; the kernel resolves the dependency graph by topological sort and boots capsules in order. Tools are an IPC convention, not a kernel concept: a tool capsule intercepts tool.v1.execute.<name>, and the kernel never sees a tool schema.

The host ABI is the WebAssembly component model with versioned astrid:* WIT packages: fs, io, kv, ipc, net, http, sys, process, approval, identity, elicit, and uplink. Guests import only what their manifest allows, and every call is capability-gated at the boundary.

The security model

Astrid's security is decomposed. There is no single gate every action funnels through. A capsule has no ambient authority, and authorization is enforced by independent, per-area mechanisms, each fail-closed and each enforced where the effect actually happens.

flowchart TB
    Action[A capsule action] --> Sandbox[WASM sandbox<br/>no syscalls, file descriptors, or host memory<br/>external resources are capability-checked host calls]
    Action --> Manifest[Manifest gate<br/>declared file, network, and process allow-list<br/>empty is deny-all; path traversal and SSRF defenses]
    Action --> IPC[IPC ACL<br/>declared publish and subscribe topics only<br/>per-principal routing]
    Action --> Capability[Capability token<br/>ed25519, principal-bound, scoped, expiring, revocable<br/>per-device tokens can be subset-scoped]
    Action --> Approval[Approval gate<br/>once - session - always - deny<br/>allow always mints a token; local egress elicits consent]
    Action --> OS[OS sandbox<br/>bwrap on Linux - seatbelt on macOS for native subprocesses]
    Action --> Audit[Audit chain<br/>signed, hash-linked JSONL decisions and calls<br/>split per principal and independently verifiable]
Loading

These mechanisms are real and independently tested. There is no unified interceptor orchestrating them. The five-layer gate chapter of The Astrid Book walks each layer against the source.

Install

Homebrew (macOS and Linux):

brew tap astrid-runtime/tap
brew install astrid

From crates.io (requires Rust 1.95+):

cargo install astrid

From source:

git clone https://github.com/astrid-runtime/astrid
cd astrid && cargo build --release   # binary at ./target/release/astrid

Astrid installs four binaries that work together. You only ever invoke astrid; it starts and manages the rest.

Binary Role
astrid CLI uplink. Connects to the daemon over the Unix socket. TUI, headless mode, capsule and agent management.
astrid-daemon The kernel process. Loads capsules, routes IPC, enforces capabilities, runs the sandbox.
astrid-build Capsule compiler and packager. Builds to wasm32-unknown-unknown.
astrid-emit Stdio-to-bus bridge for external hook producers.

Initial setup

astrid init --distro <source> fetches a distro (a curated capsule bundle), presents any selection groups declared by that distro, and prompts for its required configuration. Secrets are stored per principal in the secret store, never passed on the command line. init writes a Distro.lock pinning every capsule by BLAKE3 hash, so the same explicit distro input reproduces the same fleet.

astrid init --distro @yourorg/your-distro          # repository distro
astrid init --distro ./Distro.toml                  # local manifest
astrid init --distro ./bundle.shuttle --offline     # signed bundle, no network
astrid init --distro @yourorg/your-distro --yes     # non-interactive defaults

When a distro includes an LLM provider, onboarding can discover that provider's live model list from its /v1/models endpoint. If the distro also includes an agent loop, confirm that it is ready before starting a session:

astrid doctor    # daemon up? capsules ready? an LLM available?
astrid chat      # interactive session; the daemon auto-starts on first use
astrid models    # list the current provider's models (a registry-capsule verb)

Headless and scripting

astrid -p "summarize the git log"                    # single prompt, prints and exits
git diff HEAD~1 | astrid -p "write a commit message" # stdin is appended to the prompt
astrid -p "fix all failing tests" --yes              # auto-approve tool requests
astrid -p "continue" --session "$SID"                # resume by id or name

Daemon lifecycle

astrid start     # persistent daemon (survives terminal close)
astrid status    # PID, uptime, connected clients, loaded capsules
astrid ps        # loaded capsules and their lifecycle state
astrid stop      # graceful shutdown
astrid update    # authenticate, verify, and install the latest release

Per-principal isolation

Each principal (agent identity) is a fully isolated tenant: its own capsule access, KV namespace, secrets, home directory, quotas, and audit chain. New principals inherit nothing by default.

astrid agent create ci-bot                     # clean-slate, least-privilege agent
astrid agent create staging --clone production # full profile + state replica
astrid agent modify ci-bot \
  --add-capsule astrid-capsule-fs              # grant access to a capsule's tools
astrid caps show ci-bot                        # inspect capability grants
astrid quota set -a ci-bot --memory 128MB      # per-principal resource limits
astrid pair-device issue --scope use-only      # scope a device token to a subset

Capsule access is enforced kernel-side at dispatch. A principal can only invoke capsules explicitly granted to it, and two principals installing the same capsule bytes share one content-addressed on-disk artifact while getting separate in-memory runtime instances.

Write a capsule

A capsule is a WASM process described by a manifest. The scaffold generates a first-try-compiling project targeting wasm32-unknown-unknown, plus an AUTHORING.md guide.

astrid capsule new my-capsule    # scaffold Capsule.toml, Cargo.toml, src/lib.rs, .cargo/config.toml
cd my-capsule
astrid capsule build             # compile and package
astrid capsule install .         # hot-loaded into the running daemon, no restart

Capsule authors depend on astrid-sdk, which mirrors the std module layout (fs, net, process, env, time, log) and adds Astrid modules (ipc, kv, http, hooks, uplink, identity, approval). The #[capsule] proc macro generates the WASM ABI boilerplate: exports, serialization, and dispatch for tools, commands, hooks, and lifecycle entry points.

use astrid_sdk::prelude::*;

#[derive(Default)]
struct Weather;

#[capsule]
impl Weather {
    #[astrid::tool]
    fn forecast(&self, args: ForecastArgs) -> Result<Forecast, SysError> {
        let key = env::var("WEATHER_API_KEY")?;
        let body = http::get(&format!("https://api.example.com/wx?q={}", args.city))?;
        Ok(serde_json::from_slice(&body)?)
    }
}

Building capsules is a first-class workflow in Astrid. The Forge (astrid capsule new plus authoring tools and runtime-served guidance) is the on-ramp; the direction is an agent that writes, builds, and installs its own capsules within the capability sandbox.

Reproducible builds and deterministic tests are consumers of Muninn's verified computation memory: complete source and toolchain closures become derivation inputs, so an unchanged fleet build is a verified lookup while install, signing, and publication remain fresh authorized effects.

Live capsule lifecycle

astrid capsule install @org/capsule-name   # install and hot-load
astrid capsule update my-capsule           # hot-swap the running instance
astrid capsule remove my-capsule           # live-unload, no restart
astrid capsule list --verbose              # installed capsules with capability metadata
astrid capsule tree                        # imports/exports dependency graph

What's new in 0.9

Five bodies of work plus a security-hardening pass. See CHANGELOG.md for the full list.

  • Live capsule lifecycle. Hot-load on install, hot-swap on upgrade, live-unload on remove, all without a daemon restart.
  • Per-principal isolation, hardened end-to-end. Principal-view-aware capsule loading with content-addressed artifact reuse, kernel-side tool-surface access enforcement, and per-device capability scope threaded through the HTTP gateway.
  • LLM provider and model binding. Multi-provider onboarding with live model discovery, plus gateway routes and astrid models / astrid doctor for per-principal model management and loop-readiness checks.
  • Conversation threads over the HTTP gateway. List, fetch, update, delete, and full-text search threads, plus a per-principal live conversation feed with cross-principal isolation enforced at the bus.
  • astrid:http@1.1.0 and operator-configurable limits. Per-request timeouts, redirect policy, body caps, https-only, and subresource integrity; seven previously-hardcoded ceilings become operator knobs.
  • Security. Local-egress consent (transport-origin marker, runtime elicitation, per-capsule and per-principal grants), an SSRF airlock that closes IP-literal and redirect bypasses, and a hardened supply-chain path (Sigstore attestation, CodeQL, pinned Action SHAs, least-privilege tokens).

Documentation

Development

cargo build --workspace
cargo test --workspace -- --quiet
cargo clippy --workspace --all-features -- -D warnings
cargo fmt --all -- --check

All crates enforce #![deny(unsafe_code)] except astrid-sys and astrid-sdk, where WASM FFI requires it. Clippy runs at pedantic level and integer-overflow arithmetic is a lint error. Release binaries for macOS and GNU/musl Linux (x86_64 and aarch64) are built on tag push and signed with keyless Sigstore. Self-managed updates authenticate the exact archive and its pinned Astrid release-workflow identity before independently checking the BLAKE3 manifest and extracting any bytes. Homebrew and Cargo remain responsible for updates they install; signed SHA-256 manifests remain available for their compatibility requirements. GitHub build-provenance attestations are published as additional evidence and are not substituted for the updater's release-archive signature. See the self-update security model.

Contributing

Contributions are welcome. Astrid uses a tiered contributor system that protects security-critical code while keeping the door open to new contributors. Every pull request must be linked to a GitHub issue. See CONTRIBUTING.md for the issue-first workflow and tier descriptions.

Changes to any contract surface (the host ABI, the IPC protocol, the capability model, the manifest schema, or the SDK public API) go through the RFC process in the RFCs repository before implementation.

License

Dual-licensed under MIT and Apache 2.0, at your option.

Copyright (c) 2025-2026 Joshua J. Bouw and Unicity Labs.

View on GitHub

Recent activity

commits and pull requests

Recent open issues

view all

Discussions

all 3

Releases and announcements

20 total
  1. v0.10.4v0.10.4Jul 20, 20261.7K downloads

    ### Removed - **Capsule manifests no longer embed the agent-specific `[[skill]]` protocol.** Skills remain a user-space concern that agent runtimes can discover over IPC or advertise through product registries without teaching the Astrid kernel or generic capsule archive about an AI workflow format. Builders still preserve files under `assets/` and legacy `skills/` as opaque, symlink-free capsule data without generating manifest metadata. ### Fixed - **`astrid capsule check` no longer treats embedded Rust examples as live tools.** The scanner now parses Rust attributes instead of matching source text, so scaffold templates and documentation strings cannot create phantom unrouted-tool failures. - **Interrupted immutable-release drafts recover without replacing uploaded assets.** Release uploads are sequential, and reruns authenticate every existing payload and signature before adding only the missing files. Closes #1285. ## Install **From source (requires Rust 1.95+):** ``` cargo install astrid ``` **Pre-built binaries:** Download the archive for your platform, extract, and add to PATH: ``` tar xzf astrid-*-$(uname -m)-*.tar.gz sudo mv astrid-*/astrid a

  2. v0.10.2v0.10.2Jul 19, 202655 downloads

    ### Fixed - **`astrid mcp serve` now waits for the authenticated principal's broker to answer before exposing MCP stdio.** Non-default capsule views intentionally warm after global daemon readiness; an immediate client `tools/list` could previously publish before the broker subscribed, lose the non-durable bus request, and hang for the full 55-second reply deadline. Startup now proves the generic broker path with an idempotent `tools/list` probe and reissues it when the principal's `capsules_loaded` signal arrives, without hardcoding a product capsule name. ## Install **From source (requires Rust 1.95+):** ``` cargo install astrid ``` **Pre-built binaries:** Download the archive for your platform, extract, and add to PATH: ``` tar xzf astrid-*-$(uname -m)-*.tar.gz sudo mv astrid-*/astrid astrid-*/astrid-daemon astrid-*/astrid-build astrid-*/astrid-emit /usr/local/bin/ ``` Astrid Runtime does not bundle a product distro. To compose it with a distro you trust, run: ``` astrid init --distro <name, @org/repo, path, or .shuttle> ``` --- **With many thanks from the following Astrinauts** 🚀 - Joshua J. Bouw

  3. v0.10.1v0.10.1Jul 17, 2026248 downloads

    ### Fixed - **Runtime service discovery is product-neutral.** CLI and unique compatible model/session interfaces authenticate live source IDs. Closes #1267. ## Install **From source (requires Rust 1.95+):** ``` cargo install astrid ``` **Pre-built binaries:** Download the archive for your platform, extract, and add to PATH: ``` tar xzf astrid-*-$(uname -m)-*.tar.gz sudo mv astrid-*/astrid astrid-*/astrid-daemon astrid-*/astrid-build astrid-*/astrid-emit /usr/local/bin/ ``` Astrid Runtime does not bundle a product distro. To compose it with a distro you trust, run: ``` astrid init --distro <name, @org/repo, path, or .shuttle> ``` --- **With many thanks from the following Astrinauts** 🚀 - Joshua J. Bouw

  4. v0.10.0v0.10.0Jul 17, 2026153 downloads

    ### Added - **Native process requests now honor their declared environment and working directory.** Every spawn tier starts from a small host environment allowlist, applies validated guest variables, rejects session-token injection, confines relative working directories to the capsule workspace, and can resolve `HOME=home://...` or a `home://...` working directory after host-side policy checks. The native child receives the resolved path, but the process host API does not return it directly. Principal-home reads require an explicit read capability; the OS sandbox makes writable only the capsule's declared `home://` write roots for that principal. Recv-driven capsules now install the same per-principal home/tmp overlays as interceptor invocations. - **Capsule installation has an explicit non-interactive configuration path.** `astrid capsule install --yes` resolves lifecycle fields from repeatable `--var KEY=VALUE` inputs, `ASTRID_VAR_<KEY>` environment variables, or manifest defaults, and fails instead of silently choosing an enum value or empty secret when a required value is absent. Secret automation can use the environment form so credentials do not

  5. Astrid stable channelchannel-stableJul 17, 2026pre-release2.8K downloads

    Signed mutable channel pointer; immutable generations are retained as assets.

Code frequency

additions and deletions
+122.4K-122.4KWeek of 2026-02-08: +87,348 linesWeek of 2026-02-08: -564 linesWeek of 2026-02-15: +122,447 linesWeek of 2026-02-15: -98,490 linesWeek of 2026-02-22: +36,200 linesWeek of 2026-02-22: -38,319 linesWeek of 2026-03-01: +6,728 linesWeek of 2026-03-01: -15,097 linesWeek of 2026-03-08: +40,893 linesWeek of 2026-03-08: -30,931 linesWeek of 2026-03-15: +18,515 linesWeek of 2026-03-15: -22,691 linesWeek of 2026-03-22: +7,770 linesWeek of 2026-03-22: -8,699 linesWeek of 2026-03-29: +0 linesWeek of 2026-03-29: -0 linesWeek of 2026-04-05: +0 linesWeek of 2026-04-05: -0 linesWeek of 2026-04-12: +1,961 linesWeek of 2026-04-12: -1,493 linesWeek of 2026-04-19: +10,588 linesWeek of 2026-04-19: -3,018 linesWeek of 2026-04-26: +5,286 linesWeek of 2026-04-26: -910 linesWeek of 2026-05-03: +0 linesWeek of 2026-05-03: -0 linesWeek of 2026-05-10: +8,809 linesWeek of 2026-05-10: -1,002 linesWeek of 2026-05-17: +3,448 linesWeek of 2026-05-17: -1,710 linesWeek of 2026-05-24: +28,300 linesWeek of 2026-05-24: -10,716 linesWeek of 2026-05-31: +12,782 linesWeek of 2026-05-31: -15,669 linesWeek of 2026-06-07: +4,445 linesWeek of 2026-06-07: -295 linesWeek of 2026-06-14: +14,383 linesWeek of 2026-06-14: -3,960 linesWeek of 2026-06-21: +49,164 linesWeek of 2026-06-21: -15,390 linesWeek of 2026-06-28: +35,731 linesWeek of 2026-06-28: -10,113 linesWeek of 2026-07-05: +6,235 linesWeek of 2026-07-05: -935 linesWeek of 2026-07-12: +24,386 linesWeek of 2026-07-12: -3,906 linesWeek of 2026-07-19: +27,646 linesWeek of 2026-07-19: -1,688 linesWeek of 2026-07-26: +50,661 linesWeek of 2026-07-26: -6,208 linesFeb 8, 2026Jul 26, 2026
+603.7K lines added, -291.8K removed over the last year.

Commits per week

last 52 weeks
640Week of 2025-08-02: 0 commitsWeek of 2025-08-09: 0 commitsWeek of 2025-08-16: 0 commitsWeek of 2025-08-23: 0 commitsWeek of 2025-08-30: 0 commitsWeek of 2025-09-06: 0 commitsWeek of 2025-09-13: 0 commitsWeek of 2025-09-20: 0 commitsWeek of 2025-09-27: 0 commitsWeek of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 16 commitsWeek of 2026-02-15: 53 commitsWeek of 2026-02-22: 22 commitsWeek of 2026-03-01: 15 commitsWeek of 2026-03-08: 64 commitsWeek of 2026-03-15: 44 commitsWeek of 2026-03-22: 25 commitsWeek of 2026-03-29: 0 commitsWeek of 2026-04-05: 0 commitsWeek of 2026-04-12: 3 commitsWeek of 2026-04-19: 6 commitsWeek of 2026-04-26: 2 commitsWeek of 2026-05-03: 0 commitsWeek of 2026-05-10: 18 commitsWeek of 2026-05-17: 3 commitsWeek of 2026-05-24: 21 commitsWeek of 2026-05-31: 22 commitsWeek of 2026-06-07: 13 commitsWeek of 2026-06-14: 30 commitsWeek of 2026-06-21: 41 commitsWeek of 2026-06-28: 32 commitsWeek of 2026-07-05: 16 commitsWeek of 2026-07-12: 24 commitsWeek of 2026-07-19: 36 commitsWeek of 2026-07-26: 11 commitsAug 2, 2025Jul 26, 2026
517 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 2 commitsSun 1:00 — 1 commitsSun 2:00 — 3 commitsSun 3:00 — 0 commitsSun 4:00 — 5 commitsSun 5:00 — 1 commitsSun 6:00 — 1 commitsSun 7:00 — 0 commitsSun 8:00 — 0 commitsSun 9:00 — 0 commitsSun 10:00 — 0 commitsSun 11:00 — 0 commitsSun 12:00 — 1 commitsSun 13:00 — 0 commitsSun 14:00 — 0 commitsSun 15:00 — 2 commitsSun 16:00 — 3 commitsSun 17:00 — 0 commitsSun 18:00 — 4 commitsSun 19:00 — 3 commitsSun 20:00 — 5 commitsSun 21:00 — 0 commitsSun 22:00 — 0 commitsSun 23:00 — 4 commitsMon 0:00 — 6 commitsMon 1:00 — 5 commitsMon 2:00 — 1 commitsMon 3:00 — 5 commitsMon 4:00 — 1 commitsMon 5:00 — 2 commitsMon 6:00 — 0 commitsMon 7:00 — 0 commitsMon 8:00 — 1 commitsMon 9:00 — 0 commitsMon 10:00 — 0 commitsMon 11:00 — 0 commitsMon 12:00 — 0 commitsMon 13:00 — 1 commitsMon 14:00 — 4 commitsMon 15:00 — 8 commitsMon 16:00 — 1 commitsMon 17:00 — 6 commitsMon 18:00 — 2 commitsMon 19:00 — 6 commitsMon 20:00 — 7 commitsMon 21:00 — 2 commitsMon 22:00 — 5 commitsMon 23:00 — 4 commitsTue 0:00 — 5 commitsTue 1:00 — 4 commitsTue 2:00 — 2 commitsTue 3:00 — 4 commitsTue 4:00 — 7 commitsTue 5:00 — 7 commitsTue 6:00 — 3 commitsTue 7:00 — 1 commitsTue 8:00 — 0 commitsTue 9:00 — 0 commitsTue 10:00 — 0 commitsTue 11:00 — 0 commitsTue 12:00 — 1 commitsTue 13:00 — 0 commitsTue 14:00 — 1 commitsTue 15:00 — 1 commitsTue 16:00 — 7 commitsTue 17:00 — 2 commitsTue 18:00 — 8 commitsTue 19:00 — 3 commitsTue 20:00 — 3 commitsTue 21:00 — 0 commitsTue 22:00 — 1 commitsTue 23:00 — 4 commitsWed 0:00 — 5 commitsWed 1:00 — 1 commitsWed 2:00 — 13 commitsWed 3:00 — 8 commitsWed 4:00 — 3 commitsWed 5:00 — 6 commitsWed 6:00 — 5 commitsWed 7:00 — 3 commitsWed 8:00 — 5 commitsWed 9:00 — 0 commitsWed 10:00 — 0 commitsWed 11:00 — 0 commitsWed 12:00 — 2 commitsWed 13:00 — 0 commitsWed 14:00 — 3 commitsWed 15:00 — 7 commitsWed 16:00 — 5 commitsWed 17:00 — 3 commitsWed 18:00 — 9 commitsWed 19:00 — 5 commitsWed 20:00 — 2 commitsWed 21:00 — 4 commitsWed 22:00 — 6 commitsWed 23:00 — 6 commitsThu 0:00 — 4 commitsThu 1:00 — 4 commitsThu 2:00 — 4 commitsThu 3:00 — 1 commitsThu 4:00 — 3 commitsThu 5:00 — 2 commitsThu 6:00 — 0 commitsThu 7:00 — 1 commitsThu 8:00 — 0 commitsThu 9:00 — 1 commitsThu 10:00 — 0 commitsThu 11:00 — 0 commitsThu 12:00 — 0 commitsThu 13:00 — 1 commitsThu 14:00 — 3 commitsThu 15:00 — 2 commitsThu 16:00 — 5 commitsThu 17:00 — 3 commitsThu 18:00 — 6 commitsThu 19:00 — 2 commitsThu 20:00 — 1 commitsThu 21:00 — 4 commitsThu 22:00 — 6 commitsThu 23:00 — 10 commitsFri 0:00 — 9 commitsFri 1:00 — 10 commitsFri 2:00 — 10 commitsFri 3:00 — 10 commitsFri 4:00 — 6 commitsFri 5:00 — 5 commitsFri 6:00 — 6 commitsFri 7:00 — 3 commitsFri 8:00 — 1 commitsFri 9:00 — 1 commitsFri 10:00 — 2 commitsFri 11:00 — 0 commitsFri 12:00 — 1 commitsFri 13:00 — 0 commitsFri 14:00 — 4 commitsFri 15:00 — 3 commitsFri 16:00 — 5 commitsFri 17:00 — 2 commitsFri 18:00 — 13 commitsFri 19:00 — 9 commitsFri 20:00 — 6 commitsFri 21:00 — 10 commitsFri 22:00 — 6 commitsFri 23:00 — 4 commitsSat 0:00 — 5 commitsSat 1:00 — 4 commitsSat 2:00 — 6 commitsSat 3:00 — 2 commitsSat 4:00 — 1 commitsSat 5:00 — 1 commitsSat 6:00 — 4 commitsSat 7:00 — 1 commitsSat 8:00 — 0 commitsSat 9:00 — 0 commitsSat 10:00 — 0 commitsSat 11:00 — 1 commitsSat 12:00 — 1 commitsSat 13:00 — 1 commitsSat 14:00 — 1 commitsSat 15:00 — 4 commitsSat 16:00 — 5 commitsSat 17:00 — 3 commitsSat 18:00 — 4 commitsSat 19:00 — 2 commitsSat 20:00 — 2 commitsSat 21:00 — 4 commitsSat 22:00 — 6 commitsSat 23:00 — 3 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Jun 6, 2026daily#19+55
Jun 5, 2026daily#13+30
Jun 4, 2026daily#3+93
Jun 3, 2026daily#3+66
  • affaan-m/ECC

    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

    238.5K stars · JavaScript

  • affaan-m/ECC

    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

    234.7K stars · JavaScript

  • NousResearch/hermes-agent

    The agent that grows with you

    227K stars · Python

  • ultraworkers/claw-code

    An agent-managed museum exhibit, built in Rust with Gajae-Code / LazyCodex — developed and maintained with no human intervention.

    195K stars · Rust

  • ultraworkers/claw-code

    An agent-managed museum exhibit, built in Rust with Gajae-Code / LazyCodex — developed and maintained with no human intervention.

    194.9K stars · Rust

  • ultraworkers/claw-code

    An agent-managed museum exhibit, built in Rust with Gajae-Code / LazyCodex — developed and maintained with no human intervention.

    194.9K stars · Rust