开源 · 可嵌入的 Agent Runtime

把 A3S Code接进现有产品

工具调用先过权限再执行;每一步运行都记进事实日志;改过文件的回合,要有绑定到这次修改的验证通过才算完成。用 Rust / Node.js / Python / Go SDK 嵌进你的产品,或在仓库里直接跑 a3s code。

a3s codeCLI
curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/A3S-Lab/a3s/main/install.sh | sh
a3s code
a3s code~/workspace/a3s

a3s-code v9.1.0·openai/gpt-5·12 skills·~/workspace/a3s

Type a message · / for commands · Shift+Tab cycles agent/plan/reviewer/auto/yolo · /ask = plan (read-only) · Ctrl+G reviews diffs · Ctrl+C twice to exit

You

不联网检查这个仓库的发布风险,并生成报告

ArtifactHTML · 18.4 KB
release-risk-report/index.htmlOpen viewRemoteUI
RemoteUIready
发布风险报告2 risks · 12 checks
A3S Code

检查完成。3 个子智能体并行完成;报告制品已生成,可通过 RemoteUI 打开。

  1. 读取项目约束与发布配置

  2. 并行检查代码、测试与文档

  3. 生成报告制品并打开 RemoteUI

◇ high

agentctx:12%a3sgit:(main)gpt-5 (128k context)
WHY A3S CODE

模型想动文件或跑 Shell 时,先过你的规则

工具参数不会直接落地。Runtime 先做参数、权限和确认检查;需要确认的调用会停在事实日志里,直到你的应用给出答复。执行过程以事件流回给应用。

01

统一检查文件、Shell、Git 与外部请求

模型或前置钩子提交工具参数后,Runtime 会再次校验 Schema,再检查 Workspace 能力和权限规则。需要用户确认的调用会停在事实日志里,直到宿主给出答复。

hookspolicyHITLsandbox
02

确定性投影大输出,保留完整证据

固定策略可以保留头尾、折叠重复行并采样 JSON。模型收到投影内容;应用同时得到字节、哈希和损失证据,Artifact 保留完整原文。

transformevidenceartifact
03

界面订阅 AgentEvent

文本、工具调用、计划、确认和生命周期变化都有明确的事件类型。终端、IDE 和网页可以消费同一条事件流。

AgentEventEventEnvelopeV1
04

改过文件,要有验证才算完成

修改了 Workspace 的回合,只有在存在绑定到该修改 effect digest 的 Passed 验证报告,或宿主豁免覆盖该 digest 时才算完成。助手文本不算证据。

completion gateverificationdigest
A3S CODE / DISTINCTIVE CAPABILITIES

五个关键瞬间,看懂一次任务如何安全地变聪明

从执行前确认到代码语义,从按需发现平台能力到找回过去会话:选择一个场景,查看真实 A3S Code TUI 中的交互顺序与边界。

查看完整 TUI 指南
a3s code~/workspace/a3s

测试通过后,将 main 分支推送到 origin

Preparinggit push origin main
◇ high

agentctx:12%a3sgit:(main)gpt-5 (128k context)
HOW IT RUNS

用 Python 看完一次完整调用

下面的例子就是仓库里的 a3s_code API。点步骤,看 Session、权限、事件流和持久化是怎么加上去的。每个 Session 运行一个折叠事实日志的 Actor;默认是 coding_actor,Meta Harness 可以重新组合它。

查看 Meta Harness 说明
当前负责的层接入方式
runtime.pyPYTHON
from contextlib import closing
from pathlib import Path
from a3s_code import Agent
workspace = str(Path.cwd())
with closing(Agent.create("agent.acl")) as agent:
pass
当前负责的层Agent 与 Session
runtime.pyPYTHON
from contextlib import closing
from pathlib import Path
from a3s_code import Agent, LocalWorkspaceBackend, SessionOptions
workspace = str(Path.cwd())
options = SessionOptions()
options.planning_mode = "disabled"
options.workspace_backend = LocalWorkspaceBackend(workspace)
with closing(Agent.create("agent.acl")) as agent:
with closing(agent.session(workspace, options)) as session:
pass
当前负责的层上下文、记忆与模型
runtime.pyPYTHON
from contextlib import closing
from pathlib import Path
from a3s_code import Agent, LocalWorkspaceBackend, SessionOptions
workspace = str(Path.cwd())
options = SessionOptions()
options.planning_mode = "disabled"
options.auto_compact = True
options.auto_compact_threshold = 0.8
options.max_context_tokens = 128_000
options.workspace_backend = LocalWorkspaceBackend(workspace)
with closing(Agent.create("agent.acl")) as agent:
with closing(agent.session(workspace, options)) as session:
pass
当前负责的层权限与执行检查
runtime.pyPYTHON
from contextlib import closing
from pathlib import Path
from a3s_code import (
Agent,
LocalWorkspaceBackend,
PermissionPolicy,
SessionOptions,
)
workspace = str(Path.cwd())
options = SessionOptions()
options.planning_mode = "disabled"
options.auto_compact = True
options.auto_compact_threshold = 0.8
options.max_context_tokens = 128_000
options.permission_policy = PermissionPolicy(
allow=["read*", "ls*", "glob*", "grep*", "code_*"],
deny=["write*", "edit*", "patch*", "bash*", "git*"],
default_decision="deny",
)
options.workspace_backend = LocalWorkspaceBackend(workspace)
with closing(Agent.create("agent.acl")) as agent:
with closing(agent.session(workspace, options)) as session:
pass
当前负责的层项目文件与工具
runtime.pyPYTHON
from contextlib import closing
from pathlib import Path
from a3s_code import (
Agent,
EventType,
LocalWorkspaceBackend,
PermissionPolicy,
SessionOptions,
)
workspace = str(Path.cwd())
options = SessionOptions()
options.planning_mode = "disabled"
options.auto_compact = True
options.auto_compact_threshold = 0.8
options.max_context_tokens = 128_000
options.permission_policy = PermissionPolicy(
allow=["read*", "ls*", "glob*", "grep*", "code_*"],
deny=["write*", "edit*", "patch*", "bash*", "git*"],
default_decision="deny",
)
options.workspace_backend = LocalWorkspaceBackend(workspace)
with closing(Agent.create("agent.acl")) as agent:
with closing(agent.session(workspace, options)) as session:
for event in session.stream(
"Find the authentication entry points. Do not change files."
):
if event.type == EventType.TEXT_DELTA and event.text:
print(event.text, end="", flush=True)
elif event.type == EventType.TOOL_START:
print(f"\n→ {event.tool_name or 'tool'}")
elif event.type == EventType.ERROR:
raise RuntimeError(event.error or "A3S Code run failed")
当前负责的层事件、记录与恢复
runtime.pyPYTHON
from contextlib import closing
from pathlib import Path
from a3s_code import (
Agent,
EventType,
FileSessionStore,
LocalWorkspaceBackend,
PermissionPolicy,
SessionOptions,
)
workspace = str(Path.cwd())
options = SessionOptions()
options.planning_mode = "disabled"
options.auto_compact = True
options.auto_compact_threshold = 0.8
options.max_context_tokens = 128_000
options.permission_policy = PermissionPolicy(
allow=["read*", "ls*", "glob*", "grep*", "code_*"],
deny=["write*", "edit*", "patch*", "bash*", "git*"],
default_decision="deny",
)
options.workspace_backend = LocalWorkspaceBackend(workspace)
options.session_store = FileSessionStore(".a3s/sessions")
with closing(Agent.create("agent.acl")) as agent:
with closing(agent.session(workspace, options)) as session:
for event in session.stream(
"Find the authentication entry points. Do not change files."
):
if event.type == EventType.TEXT_DELTA and event.text:
print(event.text, end="", flush=True)
elif event.type == EventType.TOOL_START:
print(f"\n→ {event.tool_name or 'tool'}")
elif event.type == EventType.ERROR:
raise RuntimeError(event.error or "A3S Code run failed")
runs = session.runs()
if runs:
current = runs[-1]
print(f"\nrun={current['id']} status={current['status']}")
session.save()
WHAT YOU GET

Runtime 本身提供什么

Rust crate 默认只带编码 Harness。Advanced 评估、server 和无头搜索是 Cargo feature;发布的 Node.js 与 Python 包包含 advanced-harness 和 server。基础搜索不需要 Embedding 或向量库。

工具调用

工具列表由 Workspace 和权限共同确定

文件、搜索、Shell、Git、Web、Batch、QuickJS、结构化输出和子任务,只有在当前 Workspace 支持且规则允许时才会提供给模型。

filesshellgitwebprogramtask
模型

更换模型适配器,不改 Session API

支持 Anthropic、智谱、OpenAI-compatible API,也可以注入自己的 LlmClient。

streamingtoolsstructured output
任务记录

Run、事件与快照使用稳定格式

每次 Run 都追加到 .a3s/effect-log 下的事实日志,恢复时折叠日志决定下一步,已保存的模型回合不会重发。SessionSnapshotV1 把会话、Run、Trace、Artifact 和验证结果按同一代提交。

fact logSessionSnapshotV1auditable
扩展

工具、上下文与存储都有扩展接口

MCP、Skills、ContextProvider、MemoryStore、SessionStore、Workspace 服务和自定义工具都可以替换或扩展。

MCPSkillstraits
工作区检索

异步构建,会话关闭时完整释放

增量 BM25、可选宿主 Embedding、内存向量分区和 Hybrid RRF 共用一个有界文本目录;不需要向量数据库,非文本文件不会进入切块或向量化。

BM25semanticRRFCPU rerank
USE IT YOUR WAY

终端直接跑,或嵌进四种 SDK

在仓库里用 a3s code;要做 IDE、Runner 或自有界面,用 Rust / Node.js / Python / Go。

Terminal

a3s code

开箱即用的终端界面,可以查看推理、工具调用、确认提示、任务进度和 Diff。

a3s code
Rust

a3s-code-core

完整的异步 Runtime API,以及用于接入自定义能力的公共 Trait。

cargo add a3s-code-core
Node.js

@a3s-lab/code

通过 N-API 提供原生绑定,覆盖会话、事件流、工具、存储、编排和 MCP。

npm install @a3s-lab/code
Python

a3s-code

通过 PyO3 提供原生包,同时支持同步和异步 API。

python -m pip install a3s-code
Go

sdk/go/v9

纯 Go API 通过长驻桥接进程提供会话、事件流、工具、验证和 MCP,无需 CGO。

go get github.com/A3S-Lab/Code/sdk/go/v9
WHAT STAYS YOURS

Runtime 管执行;账号和界面归你

  • Core 只提供 Agent Runtime,不是托管服务,也不规定 UI。
  • 终端界面来自独立的 A3S CLI。
  • 账号、凭据、部署,以及哪些业务工具能直接调,都由你的应用决定。
查看架构说明
TRY IT

先在已有仓库里跑一次

装好 a3s code,找个项目试一下。要嵌进产品时,再选 Rust、Node.js、Python 或 Go。