Skip to content

Across Agents Assistant

Across Agents Assistant app icon

Supervised engineering loops for coding agents.

A beginner-friendly macOS workspace for describing a result, letting agents work, and approving evidence-backed delivery.

Quality workflow status Security workflow status License: AGPL-3.0

Across Work home with a focused task composer and recent work

Start With One Result

Open a project and describe the result you want. Text, files, images, and microphone input all use the same Work entry. Across keeps workflow choice, model routing, retries, and evidence machinery out of the way until they matter. If Autopilot is installed, it can resolve the goal to one compatible workflow; otherwise the task stays an ordinary host task. Scenario simulation is one optional workflow selected from task intent, not a permanent AAA task type.

The recommended first task is Repository Quality Copilot. Enter a repository quality goal in Work, or run:

across-autopilot loop run --spec repo-quality-copilot --json

It produces a readable repository report, structured evidence, release notes, and optional memory suggestions for review.

A Product That Grows With You

The base app opens projects, accepts text or voice goals, discovers configured local agents and models, manages permissions, and provides a deterministic no-key learning path. First-party plugins add durable execution, memory, and supervised workflow capabilities only after they are installed and healthy.

Component What it adds Current release
Across Agents Assistant macOS workspace, generic task entry, approvals, devices, settings, and plugin lifecycle v0.17.1
Across Context shared memory, provenance, review, forgetting, context packs, and governed Worker experience v0.12.0
Across Orchestrator task execution, remote Workers, quality gates, sandbox policy, and evidence receipts v0.12.2
Across Autopilot goal-driven workflow resolution, LoopSpec supervision, repair, and release readiness v0.6.0

Install or repair the three optional components from Settings → Plugins. Packaged builds carry verified plugin payloads, so the one-click path does not require the user to install Git, npm, Node, or Python.

Agent Runtime Proof v1.0.1 is supported through AAA's generic local MCP plugin import. It remains an independently installed external plugin rather than a fourth first-party managed component.

Product Tour

Run History Loop Engineering
Compact run history with review state and results Loop Engineering readiness, policy, and evidence
Devices & Workers Plugin Center
Approved local and remote Worker devices One-click managed first-party plugins, all ready

What v0.17.1 Includes

  • Uses only Across-owned Goal Contract and Goal review terminology across source, release checks, and public product surfaces.
  • Adds a release-blocking product-language guard that checks all four Across source trees during coordinated acceptance.
  • Keeps the v0.17 Goal Contract behavior and released producer plugin versions unchanged.

Previous v0.17.0 release

  • Added versioned Goal Contracts with immutable revisions, explicit human confirmation, stale-evidence invalidation, and host-authoritative execution checks before any Orchestrator dispatch.
  • Added Goal review and recovery paths that keep required acceptance criteria, execution bindings, receipts, and revalidation visible without allowing a runtime to self-approve delivery.
  • Integrated Context v0.12.0, Orchestrator v0.12.2, and Autopilot v0.6.0 as symmetric managed plugins. Their released contracts preserve governed memory, crash-safe terminal receipts, required-criterion binding, and human review as the final trust boundary.
  • Refreshed the four-platform Worker catalog and scenario-simulation pack from the producer releases, including published SHA-256 verification.

Previous v0.15.0 release

  • Local stdio MCP plugins can now be imported from a standard .mcp.json manifest, persisted across AAA restarts, replaced atomically by stable server ID, and rolled back when a replacement cannot start.
  • Imported plugins fail closed: AAA rejects embedded environment values, defaults tools to read-only, requires explicit MCP safety annotations, and protects built-in server IDs. Agent Runtime Proof v1.0.1 is the first formally accepted external plugin using this generic path.
  • Orchestrator v0.10.12 preserves artifact freshness, remote Worker claim, review-state, and stable policy-error invariants. Autopilot v0.5.4 adds bounded lease, preparation, interruption, and dead-executor recovery.
  • Context remains at v0.11.1; its current release already satisfies the required governed-memory contract.

Previous v0.14.5 release

  • Eligible read-only, low-risk host MCP tools can now be exposed to local task agents through a private task-scoped bridge, including direct Agent runs and Orchestrator-managed work.
  • The bridge fails closed: it filters tools by policy, validates task ownership and lifecycle, preserves byte-transparent MCP traffic, and cleans up private local proxy paths when the task ends.
  • Reproducible formal builds now bundle Orchestrator v0.10.11, which keeps read-only task reports in Orchestrator-owned storage instead of writing into the inspected project, while preserving the same host-facing task contract.
  • The bundled Orchestrator version remains aligned across the payload, declared by the host install source, source mirror, Live E2E workflow, and Worker catalog.
  • Context remains at v0.11.1 and Autopilot at v0.5.3; neither producer required a code change for this release.

Previous v0.14.3 release

  • Managed Orchestrator integration now uses v0.10.10 across the bundled payload, install source, source mirror, Live E2E workflow, and verified Worker release catalog.

  • Context remains at v0.11.1 and Autopilot at v0.5.3; neither producer had code changes that would justify an empty release.

  • Source-only acceptance now reuses its prepared backend environment and reports packaged-plugin provenance as an explicit installed-App boundary, while retaining mandatory compatibility verification for packaged runs.

  • Clean-checkout release acceptance now bootstraps the AAA and Orchestrator Python environments before any dependent gate and accepts standard Git worktrees as valid repositories.

  • Managed producer pins advance to Context v0.11.1 and Orchestrator v0.10.10, whose acceptance fixtures no longer depend on calendar time or repository checkout location.

  • An immutable, content-addressed promotion package that binds the complete run, task set, verified receipts, plugin provenance, compatibility evidence, and release readiness before a separate human approval can authorize promotion.

  • Atomic managed-plugin lifecycle transactions for Context, Orchestrator, and Autopilot, including dependent-runtime drain, reconnect, rollback, and provenance verification across repair, upgrade, uninstall, and failure paths.

  • Portable MCP compatibility validation and raw-receipt verification before redaction, with fail-closed task-set, approval-chain, and compatibility contracts that do not trust caller-supplied evidence.

  • Updated managed producer pins for Context v0.11.1, Orchestrator v0.10.10, and Autopilot v0.5.3.

  • One generic Work entry with goal-driven Autopilot resolution; starter cards and scenario-specific host fields no longer define the task model.

  • Approved remote macOS or Linux Workers over direct IP links, including LAN or point-to-point connections, plus an optional public relay path when direct reachability is unavailable.

  • Expiring enrollment, mutual TLS, device revocation, resource leases, cancellation, bounded model grants, signed artifacts, and local evidence verification without copying host model credentials to the Worker.

  • A unified Run History and a compact review surface with one result verdict, progressive evidence disclosure, and explicit accept or revision actions.

  • A faster cached Loop Engineering snapshot, actionable checks, global achievements, configured-agent-only capability views, and the current borderless Apple-style page hierarchy.

  • Managed plugin install, repair, upgrade, rollback, and uninstall coverage for all three first-party plugins, including runtime reconnect and provenance verification after a formal app rebuild.

  • Packaged Autopilot now delegates Orchestrator work through the host-owned private socket, avoiding nested packaged-process startup limits while keeping the standalone CLI fallback. Completed runs retain Orchestrator and Context identifiers so the app can trace one goal across planning, execution, memory, and review.

  • Live Worker cards now follow the authenticated capability manifest after an in-place update, and formal rebuilds reclaim any stale AAA-owned Worker network child before replacing managed plugin payloads.

Full release history lives in CHANGELOG.md.

Trust Boundaries

Across is designed around human-approved delivery:

  • Credentials, macOS permissions, raw approval decisions, and final promotion stay with the host app.
  • Task execution and durable task state belong to Across Orchestrator.
  • Shared memory and pending review belong to Across Context.
  • Autonomous iteration stops at a reviewable promotion package by default.
  • Normal product state stays under ~/.across; packaged runtime does not import plugin implementation files from development checkouts.
  • On systems without native filesystem isolation, restrictive read-only execution is blocked instead of being reported as enforced.

Build From Source

Requirements:

  • macOS 14 or newer
  • Xcode command line tools
  • Swift 5.10 or newer
  • Python 3.10 through 3.13

Clone, build, install, and open the formal local app:

git clone git@github.com:fantasyce/across-agents-assistant.git
cd across-agents-assistant
bash scripts/build_and_run.sh

The canonical local app is:

/Applications/Across Agents Assistant.app

Do not keep a second long-lived copy under ~/Applications. Local runtime data, model credentials, logs, databases, build products, and permissions must stay outside Git.

This is currently a source-first open-source release. The repository does not publish a notarized downloadable app. A source build is ad-hoc signed for local use; Developer ID signing and notarization are separate distribution steps. The AAA app also does not currently provide in-app update checks or one-click self-update. Developer ID distribution, Apple notarization, and AAA app self-update are intentionally deferred until the project owner approves that distribution investment. Managed plugin install, update, repair, and uninstall remain supported inside AAA and do not depend on this deferred app-distribution work.

Development Checks

Run the public repository and backend gates:

bash scripts/open_source_check.sh
PYTHONPATH=backend/src backend/.venv/bin/python -m pytest backend/tests --ignore=backend/tests/e2e -q

Run Swift checks:

bash scripts/run_swift_behavior_checks.sh
bash scripts/verify_swift_package_lock.sh
swift build --package-path macOS-Client --skip-update
swift test --package-path macOS-Client --skip-update

Live E2E requires a released external Orchestrator command:

ACROSS_AGENTS_ORCHESTRATOR_COMMAND=/path/to/across-orchestrator \
ACROSS_AGENTS_LIVE_E2E_EVIDENCE_PATH="$(mktemp /tmp/across-live-e2e.XXXXXX)" \
  bash scripts/run_live_e2e.sh all

The formal open-source sequence is producer-first:

  1. Across Orchestrator
  2. Across Context
  3. Across Autopilot
  4. Across Agents Assistant

See OPEN_SOURCE_RELEASE_HANDBOOK.md for the complete merge, CI, tag, Live E2E, rollback, and local-refresh procedure.

Agent-Readable Entry Points

Contributing

Use Discussions for questions and workflow ideas, and Issues for reproducible bugs and scoped feature requests. Read CONTRIBUTING.md, CODE_OF_CONDUCT.md, and SECURITY.md before contributing or reporting a security issue.

License

Across Agents Assistant is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0-only).

About

Local-first macOS control room for supervised engineering loops across coding agents.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages