Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,7 @@ explicit open gates, not a claim of universal completeness.

## What is here

- **54 component records** across native clients, context, retrieval, memory, collaboration, browser work, verification, isolation, usage accounting, research hosting, backtesting, backup, dependency inventory and local observability; adoption scope remains receipt-specific.
- **57 component records** across native clients, context, retrieval, memory, collaboration, browser work, verification, isolation, usage accounting, research hosting, backtesting, backup, dependency inventory and local observability; adoption scope remains receipt-specific. The original token study retains its 52-component scope.
- **19 researched alternatives** with adoption decisions, model requirements and prospective commands.
- A [six-candidate portability comparison](adoption/research.md), with 41 selected primary source files and a native uv adoption decision.
- **Four extended catalog layers** covering foundations/memory/RAG, agents/hosting/operations, data, and strategy/engine research; source review remains distinct from native execution.
Expand Down
10 changes: 8 additions & 2 deletions adoption/manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,10 @@
"current_job_recovery": "blueprints/convergence-practice/job-recovery/README.md",
"current_codex_session_recovery": "blueprints/convergence-practice/native-recovery/README.md",
"current_gpu_trial": "blueprints/convergence-practice/gpu-inference/README.md",
"current_claude_session_recovery": "blueprints/convergence-practice/native-recovery/claude/README.md"
"current_claude_session_recovery": "blueprints/convergence-practice/native-recovery/claude/README.md",
"current_supplemental_native_tools": "evidence/receipts/upstream-native-tools-20260920.json",
"current_memory_maintenance": "evidence/receipts/native-ai-memory-maintenance-20260920.json",
"current_native_workflow_analyzer": "evidence/receipts/native-linux-zizmor-20260920.json"
},
"recipe_map": {
"affaan-m/ECC": "recipes/README.md",
Expand Down Expand Up @@ -112,7 +115,10 @@
"skfolio": "blueprints/us-equities/research-evaluation/README.md",
"edgartools": "blueprints/us-equities/catalyst-provenance/README.md",
"zizmor": "blueprints/convergence-practice/ci-security/README.md",
"llama-cpp": "blueprints/convergence-practice/gpu-inference/README.md"
"llama-cpp": "blueprints/convergence-practice/gpu-inference/README.md",
"beads": "recipes/README.md",
"skills-ref": "recipes/README.md",
"otel-tui": "recipes/README.md"
},
"profiles": [
{
Expand Down
23 changes: 23 additions & 0 deletions blueprints/convergence-practice/ci-security/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,29 @@ unsafe fixture returns exit 14 with `template-injection`, `unpinned-uses` and

Replay with the selected native executable available:

The later [native Linux receipt](../../../evidence/receipts/native-linux-zizmor-20260920.json)
closes the executable gap on its recorded source Linux/WSL host with upstream
`uv tool install zizmor==1.30.1` in an isolated tool environment. Importing that
receipt does not qualify macOS, VelaNext or another host. The workflow-directory scan returned exit 0
and no findings; the unchanged inert fixture returned exit 14 with all three
diagnostics above. Both exact native acceptance tests passed with no skips.
The installed binary was independently hashed; this follow-up did not repeat
the CI wheel archive verification or execute any workflow.

Run the direct upstream command from either client's native shell, choosing an
owned cache directory:

```sh
uv tool install zizmor==1.30.1
env -u GH_TOKEN -u GITHUB_TOKEN -u ZIZMOR_GITHUB_TOKEN \
zizmor --offline --no-config --no-ignores --no-progress \
--persona regular --strict-collection --format json \
--cache-dir "$OWNED_CACHE" "$PROJECT_ROOT/.github/workflows"
```

Install once; subsequent workflow edits need only the relevant scan. Acceptance
can be replayed with the repository's native fixture tests:

```sh
python3 -m unittest -v tests.test_workflow_security
python3 scripts/validate_convergence.py blueprints/convergence-practice/ci-security/experiment.json --root . --json
Expand Down
2 changes: 1 addition & 1 deletion catalogs/us-equities/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ per-repository token-saving value.

**Dated decision catalog: September 20, 2026.** The north star is native, token-efficient research → reproducible backtesting → Alpaca paper automation. This is an examined selection across layers, not a universal final SOTA ranking or a claim that every listed framework runs together.

The catalog has **152 baseline repository decision cards covering 147 unique GitHub repositories**, and **20 model entries**. The [combined repository index](repository-index.md) now contains **505 repository identities**, including all 342 public stars and 163 beyond that snapshot. Its [typed decision union](decision-index.json) validates baseline cards, component/candidate records and explicitly registered research supplements together; 1,051 source pointers preserve their different evidence depths. The historical 453-row index remains dated reference material.
The catalog has **152 baseline repository decision cards covering 147 unique GitHub repositories**, and **20 model entries**. The [combined repository index](repository-index.md) now contains **505 repository identities**, including all 342 public stars and 163 beyond that snapshot. Its [typed decision union](decision-index.json) validates baseline cards, component/candidate records and explicitly registered research supplements together; 1,054 source pointers preserve their different evidence depths. The historical 453-row index remains dated reference material.

The newest [security-identity review](security-identity-review.md) examines Alpaca,
Zipline, Qlib, NautilusTrader, LEAN and WRDS. It separates engine identity/lifetime
Expand Down
31 changes: 26 additions & 5 deletions catalogs/us-equities/decision-index.json
Original file line number Diff line number Diff line change
Expand Up @@ -164,10 +164,10 @@
"repositories": 505,
"public_star_repositories": 342,
"beyond_public_stars": 163,
"references": 1052,
"references": 1055,
"repositories_by_record_type": {
"catalog_card": 147,
"component_record": 54,
"component_record": 57,
"legacy_candidate": 19,
"public_star": 342,
"research_supplement": 103,
Expand Down Expand Up @@ -482,6 +482,7 @@
"aliases": [],
"public_star": true,
"record_types": [
"component_record",
"legacy_candidate",
"public_star",
"star_review"
Expand All @@ -505,7 +506,13 @@
"kind": "legacy_candidate",
"path": "manifests/candidates.json",
"pointer": "/candidates/14",
"decision": "Demo-only portable-format linter; native client extensions differ. Existing official Codex quick_validate helper already passed for selected task-checkpoint skills."
"decision": "On-demand reference/demo portable-format linting, properties and prompt metadata; does not certify production native client extensions."
},
{
"kind": "component_record",
"path": "manifests/stack.json",
"pointer": "/components/55",
"id": "skills-ref"
}
]
},
Expand Down Expand Up @@ -4462,6 +4469,7 @@
"aliases": [],
"public_star": true,
"record_types": [
"component_record",
"legacy_candidate",
"public_star",
"star_review"
Expand All @@ -4485,7 +4493,13 @@
"kind": "legacy_candidate",
"path": "manifests/candidates.json",
"pointer": "/candidates/12",
"decision": "conditional backlog tool; defer installation until durable dependency/claimable-task queue is a real requirement"
"decision": "Use for selected-project persistent task dependencies and claims; ai-memory remains durable knowledge. Initialization skips agent instructions and hooks."
},
{
"kind": "component_record",
"path": "manifests/stack.json",
"pointer": "/components/54",
"id": "beads"
}
]
},
Expand Down Expand Up @@ -12957,14 +12971,21 @@
"aliases": [],
"public_star": false,
"record_types": [
"component_record",
"legacy_candidate"
],
"references": [
{
"kind": "legacy_candidate",
"path": "manifests/candidates.json",
"pointer": "/candidates/18",
"decision": "Conditional: use a deliberate local instrumented session or deterministic workflow when runtime latency/events are being diagnosed; no persistent exporter proposed."
"decision": "Use for explicit local telemetry diagnosis; no persistent exporter or provider-session claim."
},
{
"kind": "component_record",
"path": "manifests/stack.json",
"pointer": "/components/56",
"id": "otel-tui"
}
]
},
Expand Down
11 changes: 6 additions & 5 deletions docs/ecosystem/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -64,11 +64,12 @@ The two retrieval replay highlights are separately identified as recorded
evaluations, with their own denominators and limits. Current acceptance on the
browser's host stays unknown: a static HTML file probes no accounts or services.

The [current primary-source review](source-review.json) records native Claude Code
features, existing retrieval and memory options, and local inference gates. It
does not install anything or change accepted pins. In particular, ai-memory 2.3.2
remains a candidate for an isolated migration/scope trial; native 2.3.1 state was
not upgraded by this work.
The [dated primary-source review](source-review.json) records native Claude Code
features, existing retrieval and memory options, and local inference gates. That
review installed nothing and left ai-memory 2.3.2 as a candidate. The later
[maintenance receipt](../../evidence/receipts/native-ai-memory-maintenance-20260920.json)
records its bounded update on the source Linux/WSL host after a private backup.
Importing that receipt does not upgrade or qualify macOS, VelaNext or another host.

The [Tavily receipt](tavily-receipt.json) records CLI 0.1.8, eight official skills
at a full source commit, native authentication and one three-result search.
Expand Down
2 changes: 1 addition & 1 deletion docs/ecosystem/index.html

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs/ecosystem/manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"schema_version": 1,
"snapshot_date": "2026-09-20",
"repository_url": "https://github.com/seathatflowsinourveins/native-agent-stack",
"source_revision": "f9b0c49cf25288b373ad6dbeaa4f1e4a98bc45ba",
"source_revision": "73186541090c4a23b098642fada5c9183cc2bed3",
"layers": [
{
"id": "agents",
Expand Down
13 changes: 11 additions & 2 deletions docs/landscape.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,13 +30,22 @@ The timestamp-bearing GitHub star refresh found 337 repositories. WeKnora and Te

- **WeKnora 0.8.0:** document warehouse, maintained Wiki and nine remote connectors with scheduled sync. No local folder watcher was established. Add it for a real document corpus/UI/connector requirement; SocratiCode already covers local code updates.
- **Tech Leads Club agent-skills:** selective skill source with MIT code and separately licensed CC-BY 4.0 maintainer skill content. Existing selected upstream skills suffice without another bulk catalog.
- **Dagu 2.16.6 / Beads:** durable workflows or dependency queues when the work requires them. A normal native agent session is not evidence of a persistent job system.
- **otel-tui 0.7.5:** useful for an actual OTLP producer and tracing investigation; no global telemetry exporter was added.
- **Dagu 2.16.6 / Beads 1.3.0:** use for tasks that need durable workflows or dependency queues. The September 20 Beads installation passed a scoped native lifecycle, claim persistence and dependency blocking/unblocking; it skips extra agent instructions/hooks and leaves ai-memory responsible for durable knowledge.
- **otel-tui 0.7.5:** now installed from the checksum-verified upstream release. Its native TUI received and displayed a synthetic loopback trace, then closed; production/native-provider telemetry and a persistent exporter were not part of that acceptance.
- **Agent Skills skills-ref 0.1.0:** installed from the official pinned source with `uv sync --locked`; validation, properties and prompt metadata passed on a selected skill. Upstream calls this a reference/demo implementation; it does not certify native client extension semantics.
- **ai-memory 2.3.2 maintenance:** native version, running executable, supported status, scoped search and configured direct MCP passed after an upstream backup and checksum-verified release replacement. Existing client hooks/routing remain intact; previous provider-task receipts retain their original version.
- **Hindsight, EverOS, MemPalace, OpenViking, Cognee, Claude-mem, Mem0, Graphiti and LightRAG:** different archive, consolidation, resource-memory or graph designs. Many require extra models/accounts/databases. They remain explicit alternatives, not simultaneous default capture layers.
- **Syft 1.52.0 / OSV-Scanner 2.6.0:** current supply-chain candidates for a project with dependency/package artifacts. This publication has stdlib validation and upstream recipes, not a vendored runtime environment. No vulnerability-free certification is inferred from its secret scan.

The full candidate manifest includes native prospective commands and their prerequisites. They are marked unexecuted where appropriate.

The [supplemental native receipt](../evidence/receipts/upstream-native-tools-20260920.json)
and [memory maintenance receipt](../evidence/receipts/native-ai-memory-maintenance-20260920.json)
record the September 20 additions on their source Linux/WSL host separately from
the earlier landscape review. Importing these receipts does not qualify macOS,
VelaNext or another host. No lifetime token-savings counter or universal ranking
is inferred from adoption.

## Recent models and runtime compatibility

The dated publisher shortlist includes Qwen 3.8, DeepSeek V4.1 Flash, GLM 5.3, Kimi K3, Nemotron 3 Embed, Jina reranker 3.5, UEmbed 2B and CORE reranker 2B. Dates and certainty are retained individually. Very large sparse models still require storing their full weights; active parameter counts do not establish local fit. Hosted Astra/Opus do not provide downloadable HF weights or generic API credentials through a coding subscription.
Expand Down
52 changes: 45 additions & 7 deletions docs/token-practice.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,14 @@
Recorded September 20, 2026. Read this guide on demand when selecting a context
lane, interpreting native counters, or designing a measured comparison.

The dated token-practice review covered **52 component records** and **504
repository identities: 342 public stars and 162 beyond stars, with 1,037 typed
references**. Later additions appear in the [current explorer](ecosystem/index.html).
The earlier audit and full-catalog TOON receipt retain the 502-repository
input that was actually measured. These are bounded catalog counts, not universal SOTA, 52 successful
E2E runs, or savings from every repository. Supporting runtimes and historical
alternative installations retain separate scope.
The current catalog has **57 component records** and **505 repository identities:
342 public stars and 163 beyond stars, with 1,055 typed references**. The dated
token-practice review retains its **52-component** scope and its then-current
504-repository, 1,037-reference catalog. The earlier audit and full-catalog TOON
receipt retain the 502-repository input actually measured. These counts do not
establish a universal ranking, successful full-stack runs for every component,
or savings from every repository. Supporting runtimes and historical alternative
installations retain separate scope.

## Default practice

Expand Down Expand Up @@ -175,6 +176,43 @@ when importing new matched-task or retrieval evaluations.

## Coverage and future acceptance

### Supplemental native adoption on September 20

The [supplemental receipt](../evidence/receipts/upstream-native-tools-20260920.json)
adds three upstream tools installed on the recorded source Linux/WSL host to the
current catalog. Importing this receipt does not qualify macOS, VelaNext or another
host. Beads 1.3.0 completed
23 native operations and ten checks, including persistent claims, dependency
blocking/unblocking and closing all three fixture issues. skills-ref 0.1.0 at
commit `69ef37e9424c0a7ea9dd2293b559e43ec8176379` validated a selected skill,
returned its expected properties and rendered its complete prompt metadata.
otel-tui 0.7.5 accepted one OTLP trace over loopback HTTP and displayed its service,
single span and 10 ms latency; its owned process then closed successfully.

Use the [upstream native recipes](../recipes/README.md#supplemental-native-task-and-inspection-tools)
from either client's ordinary native shell. Beads is available for tasks that
need a persistent dependency queue; initialize only the selected project with
agent-instruction and hook generation skipped. skills-ref is explicitly a
reference/demo validator and does not certify native client extensions. otel-tui
is an on-demand local viewer with no persistent producer configuration implied.
The three tools do not expose verified lifetime token-savings counters; their
installation and functional results are not evidence of provider savings.

The separate [ai-memory 2.3.2 maintenance receipt](../evidence/receipts/native-ai-memory-maintenance-20260920.json)
records an official checksum-verified update on that source Linux/WSL host after
a private upstream backup. It does not upgrade or qualify another runtime.
The running service executable, supported native status, scoped search and direct
MCP status passed. Existing hooks, client configuration and project scope were
preserved. Earlier model-task and 52-component study receipts remain unchanged;
these additions did not repeat provider trials or rewrite historical baselines.

The selected zizmor 1.30.1 analyzer also gained a [native Linux follow-up](../evidence/receipts/native-linux-zizmor-20260920.json):
official isolated `uv tool install`, zero findings on the current workflows,
expected exit 14 and three findings on an inert unsafe fixture, and two native
acceptance tests with no skips. Its earlier Mac/CI receipts remain dated. This
closes command availability on the recorded source Linux/WSL host without adding
a component or savings claim. Other hosts retain their separately dated evidence.

The [coverage receipt](../evidence/receipts/token-practice-coverage-20260920.json)
preserves all 52 classifications and 70 captured operations: 66 expected process
checks passed and four failed attempts remain. This is not 52 full-stack passes.
Expand Down
Loading