Frozen baseline:
0.4.16· current app line:0.14.xUpdated:2026-09-10Language: English-first Stack: Electron + Rust host core + pi Agent Harness + user-installable plugins
The baseline is a frozen decision artifact, not a complete list of every
feature in the current app. The current implementation adds Goal contracts,
standalone MCP/Skills/Subagents, plugin marketplace and launcher flows, session
import, scheduled tasks, next-turn composer configuration, and host-owned
session collaboration messages. The host wire protocol is v11; storage schema
is v16 (see 00-baseline.md).
docs/spec/
├── 00-baseline.md
├── 01-product/
├── 02-architecture/
├── 03-runtime/
├── 04-ux/
├── 05-security/
├── 06-delivery/
├── 07-plugins/
└── 08-meta/
00-baseline.md01-product/00-overview.md01-product/01-product-scope.md06-delivery/01-mvp-milestones.md
00-baseline.md02-architecture/01-architecture.md02-architecture/05-remote-agent-control.mdwhen implementing remote control03-runtime/05-host-core-rust.md03-runtime/02-agent-runtime.md03-runtime/01-ipc-protocol.md03-runtime/19-remote-agent-control-protocol.mdwhen implementing remote control03-runtime/11-provider-model-system.md07-plugins/01-plugin-system.md
../plugin-development.md07-plugins/01-plugin-system.md07-plugins/02-plugin-manifest-schema.md07-plugins/03-plugin-api.md07-plugins/10-plugin-devex.mdexamples/plugins/hello
- Electron shell
- English-first product/docs
- Rust host backend core
- pi agent engine in Node sidecar
- Host RPC = stdio JSON-RPC NDJSON
- SQLite owned by Rust only
- Default mode = Agent; operating selector = Agent | Plan | Goal. Plan and Goal are contract states of the same Agent and are not strict read-only security profiles because Bash follows the selected permission mode
- SubmitPlan writes exact Markdown bytes to a new host-owned
.pi/plan/*.mdartifact; title/question stay structured inplan_approvals, approval opens the artifact, is approve/reject only, and expires after 30 absolute minutes withPLAN_APPROVAL_TIMEOUT - Protocol v11 and storage schema v16 are authoritative for Plan/Goal
checkpoints,
plan_approvalsexecution fields, startup interruption, shell identity, and host-owned session collaboration. v11 withdraws the A2A method domain added in v10. - Local permission approvals have no automatic deadline; Bash timeout 60s by default
- Local user-installable plugins (market later)
- Tag releases = macOS arm64 and Intel x64, Windows x64, and Linux x64 (D126/D285)
- Universal provider/model coverage (native + OpenAI-compatible + custom)