Platform-native execution
Target-specific executables, runtime assets, native argv, and standard process status.
- binary
- bin/convert
- assets
- runtime/assets
- target
- darwin-arm64
Install native tools and cognitive capabilities as one exact dependency graph. Review every change, then cut over to the next capability generation once.
Development preview: protocols and persisted state may still change. Do not use it in production.
The installer detects the current platform, resolves the stable A3S-Lab/CLI GitHub Release, verifies SHA-256, and atomically replaces the user-scoped binary.
$curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/A3S-Lab/a3s/main/install.sh | shTool, MCP, OKF, A3S Flow, Skill, and UI belong to one package graph. They share identity, dependencies, grants, and retirement boundaries instead of bypassing lifecycle control independently.
Target-specific executables, runtime assets, native argv, and standard process status.
Workflows, knowledge, instructions, and UI bind to content digests. Text never grants itself authority.
A Tool is a Runtime-managed workload. It is not converted into a private action protocol or disguised as an MCP tool.
One durable operation journal keeps the reviewed plan, exact graph, grants, and idempotent checkpoints on the same recovery path.
Refresh the signed catalog without package payloads.
Freeze versions, dependency edges, and source evidence.
Show impact, grants, and the exact plan digest.
Verify the archive, ACL manifest, and content in a bounded root.
Prepare hosts for all six surfaces in dependency order.
Publish a new generation; drain and retire in reverse.
CLI, TUI, and agent management MCP share one Plugin Manager. Use owns packages and evidence, Runtime owns workloads, and hosts own policy, credentials, and rendering.
Read the architecture guideFlow, Skill, UI, OKF, tool output, and remote content are data. Authority comes only from host policy, explicit grants, and generation-bound receipts.
Pin TUF roots, signed metadata, length, and SHA-256 while rejecting rollback and expired state.
Resolve again before apply. Version, content, grant, or provider changes require another review.
Grants, Runtime bindings, generation leases, and snapshots point to the same package generation.
Linux and macOS run the full workspace gates. Windows x86_64 currently runs a narrower Preview compile and facade gate.
Verify the current implementation and boundaries before connecting this development preview to an A3S host. The roadmap keeps every unfinished release gate visible.