{"_id":"@aos-agent/agent-core","_rev":"4-aed55d29f6402abfc9b33a11d20f09a0","name":"@aos-agent/agent-core","dist-tags":{"latest":"0.85.1"},"versions":{"0.84.2":{"name":"@aos-agent/agent-core","version":"0.84.2","keywords":["ai","agent","llm","transport","state-management"],"author":{"name":"Mario Zechner"},"license":"MIT","_id":"@aos-agent/agent-core@0.84.2","maintainers":[{"name":"aosagent","email":"guanwenpeng2001@gmail.com"}],"homepage":"https://github.com/guanwenpeng2001-bot/AOS-Agent#readme","bugs":{"url":"https://github.com/guanwenpeng2001-bot/AOS-Agent/issues"},"dist":{"shasum":"a06ed2f23e77ca84283793d147b77a1bd74b471d","tarball":"https://registry.npmjs.org/@aos-agent/agent-core/-/agent-core-0.84.2.tgz","fileCount":198,"integrity":"sha512-2Vc18OHZc/ZiimfhuVzarWLRMa4jnmOC9w0ZheDzlkVbg1DocXWg+sFx7Lnu88ppdnjxLxKTkVRxfLNg2Emjkg==","signatures":[{"sig":"MEQCIGu5psZw6Z82LSIn9VK6Ewuqtz9FxzTYDEnnhxAG7CwPAiBr0DCF2AFOa9a0TsA1yCQAjUbnHOb0nUJqHtcnTzgUPQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1882586},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.19.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node.d.ts","import":"./dist/node.js"},"./package.json":"./package.json","./session/testing":{"types":"./dist/harness/session/testing/index.d.ts","import":"./dist/harness/session/testing/index.js"}},"scripts":{"test":"vitest --run","build":"tsgo -p tsconfig.build.json","clean":"shx rm -rf dist","test:harness":"vitest --run --config vitest.harness.config.ts","prepublishOnly":"npm run build","coverage:harness":"vitest --run --config vitest.harness.config.ts --coverage","check:telemetry-docs":"node scripts/generate-telemetry-docs.ts --check","generate-telemetry-docs":"node scripts/generate-telemetry-docs.ts"},"_npmUser":{"name":"aosagent","email":"guanwenpeng2001@gmail.com"},"repository":{"url":"git+https://github.com/guanwenpeng2001-bot/AOS-Agent.git","type":"git","directory":"packages/agent"},"_npmVersion":"12.0.2","description":"General-purpose agent with transport abstraction, state management, and attachment support","directories":{},"_nodeVersion":"24.18.1","dependencies":{"diff":"8.0.4","yaml":"2.9.0","ignore":"7.0.5","typebox":"1.3.7","@aos-agent/ai":"^0.84.2","@aos-agent/telemetry":"^0.84.2"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.1.9","typescript":"5.9.3","@types/node":"24.12.4","@vitest/coverage-v8":"4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/agent-core_0.84.2_1786323412929_0.3447281301709191","host":"s3://npm-registry-packages-npm-production"}},"0.84.3":{"name":"@aos-agent/agent-core","version":"0.84.3","keywords":["ai","agent","llm","transport","state-management"],"author":{"name":"Mario Zechner"},"license":"MIT","_id":"@aos-agent/agent-core@0.84.3","maintainers":[{"name":"aosagent","email":"guanwenpeng2001@gmail.com"}],"homepage":"https://github.com/guanwenpeng2001-bot/AOS-Agent#readme","bugs":{"url":"https://github.com/guanwenpeng2001-bot/AOS-Agent/issues"},"dist":{"shasum":"c5807cd6a0bc686a674d1d284e5fc06ee96219e9","tarball":"https://registry.npmjs.org/@aos-agent/agent-core/-/agent-core-0.84.3.tgz","fileCount":198,"integrity":"sha512-Xr+dFqKg7sx3/7TzJ+HKcfqhmQ/NzUXehgXkNtkO17m0TGCtig19KnQIWVNFuIkxkmobFJ17STTJXNRyEL9rqQ==","signatures":[{"sig":"MEYCIQClMxH7AU0iy+xJi/N3wIB4c0YYUuBBoDELivnS9zt0UgIhAJxYLXa0CJCIFC4cZcHEnXa7Q2Sukl+3g7RAbovVw5ZN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aos-agent%2fagent-core@0.84.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1882586},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.19.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node.d.ts","import":"./dist/node.js"},"./package.json":"./package.json","./session/testing":{"types":"./dist/harness/session/testing/index.d.ts","import":"./dist/harness/session/testing/index.js"}},"gitHead":"d92430128236cc1f285dcbb4f03ddd56ed81f8da","scripts":{"test":"vitest --run","build":"tsgo -p tsconfig.build.json","clean":"shx rm -rf dist","test:harness":"vitest --run --config vitest.harness.config.ts","prepublishOnly":"npm run build","coverage:harness":"vitest --run --config vitest.harness.config.ts --coverage","check:telemetry-docs":"node scripts/generate-telemetry-docs.ts --check","generate-telemetry-docs":"node scripts/generate-telemetry-docs.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:412625a0-728f-4c8d-868f-a64917e9bba3"}},"repository":{"url":"git+https://github.com/guanwenpeng2001-bot/AOS-Agent.git","type":"git","directory":"packages/agent"},"_npmVersion":"11.5.1","description":"General-purpose agent with transport abstraction, state management, and attachment support","directories":{},"_nodeVersion":"24.18.0","dependencies":{"diff":"8.0.4","yaml":"2.9.0","ignore":"7.0.5","typebox":"1.3.7","@aos-agent/ai":"^0.84.3","@aos-agent/telemetry":"^0.84.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.1.9","typescript":"5.9.3","@types/node":"24.12.4","@vitest/coverage-v8":"4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/agent-core_0.84.3_1786383884901_0.5240499179485469","host":"s3://npm-registry-packages-npm-production"}},"0.85.0":{"name":"@aos-agent/agent-core","version":"0.85.0","keywords":["ai","agent","llm","transport","state-management"],"author":{"name":"AOS Agent"},"license":"MIT","_id":"@aos-agent/agent-core@0.85.0","maintainers":[{"name":"aosagent","email":"guanwenpeng2001@gmail.com"}],"homepage":"https://github.com/guanwenpeng2001-bot/AOS-Agent#readme","bugs":{"url":"https://github.com/guanwenpeng2001-bot/AOS-Agent/issues"},"dist":{"shasum":"5c25b7c8b6d718c86194d28e46d48e6013c9c60a","tarball":"https://registry.npmjs.org/@aos-agent/agent-core/-/agent-core-0.85.0.tgz","fileCount":434,"integrity":"sha512-oJo46xBXEa/7P73LIppYKkrtd5cKw0RpZ9mbEZGNJMJxaHRjN7iNeup6M4Yjv3yJMSE6yJRtQ9s58PsSyMYKjA==","signatures":[{"sig":"MEYCIQDsebyz2ZcsgIFXo3vv2Ncb19HVcP22tG4i3wtj8uV48gIhAPcChu3ITJEKSKWtZbyQEmP5E5hb+zFXLOmgumxy63nN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQD9cnea0vTVjpIWVGip9QC4Z+KYGuuGcdQpVAN8a6HM1QIhALZOp5aXgK0MhzUtFOPJhz1ZqzbCkJyPUL0ja108X2s3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aos-agent%2fagent-core@0.85.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8386046},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.19.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node.d.ts","import":"./dist/node.js"},"./package.json":"./package.json","./session/testing":{"types":"./dist/harness/session/testing/index.d.ts","import":"./dist/harness/session/testing/index.js"}},"gitHead":"a305bd6d376b447cbdc0b92711a54e9778d24695","scripts":{"test":"vitest --run","build":"tsgo -p tsconfig.build.json","clean":"shx rm -rf dist","test:harness":"vitest --run --config vitest.harness.config.ts","prepublishOnly":"npm run build","coverage:harness":"vitest --run --config vitest.harness.config.ts --coverage","check:telemetry-docs":"node scripts/generate-telemetry-docs.ts --check","generate-telemetry-docs":"node scripts/generate-telemetry-docs.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:412625a0-728f-4c8d-868f-a64917e9bba3"}},"repository":{"url":"git+https://github.com/guanwenpeng2001-bot/AOS-Agent.git","type":"git","directory":"packages/agent"},"_npmVersion":"11.5.1","description":"General-purpose agent with transport abstraction, state management, and attachment support","directories":{},"_nodeVersion":"24.19.0","dependencies":{"diff":"8.0.4","yaml":"2.9.0","ignore":"7.0.5","typebox":"1.3.7","@aos-agent/ai":"^0.85.0","@aos-agent/telemetry":"^0.85.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.1.9","typescript":"5.9.3","@types/node":"24.12.4","@vitest/coverage-v8":"4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/agent-core_0.85.0_1788326607950_0.6972861468272995","host":"s3://npm-registry-packages-npm-production"}},"0.85.1":{"_id":"@aos-agent/agent-core@0.85.1","bugs":{"url":"https://github.com/guanwenpeng2001-bot/AOS-Agent/issues"},"dist":{"shasum":"616222e61722d9ab23a534851fb0aca1bc9fabd1","tarball":"https://registry.npmjs.org/@aos-agent/agent-core/-/agent-core-0.85.1.tgz","fileCount":434,"integrity":"sha512-LyOjtMtgjLeLCn3nq8Ig4NWUqjWX4Wv2Ug3y9vaFP/oZJ5yfF69YSAQwXCTANWMIQ6aIL9lDJqKBt5SdBDTQCQ==","signatures":[{"sig":"MEUCIQCpiDq4IIERT8MB2ci6jCVbVsQ/EMRRqNpJfIwN68oE5gIgWXf9VNYNdlpstTpeo8VA2QOp3B5Dv0aFTWdjDfLuNJg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCNeBQKi+PMZccc3loNU713HGZz198VnPSxj9/bPHmabAIgWpsZaESL7dgr3VtWDnIS1eTF3mDzZbuLixq+3hUtHxs="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aos-agent%2fagent-core@0.85.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8391825},"main":"./dist/index.js","name":"@aos-agent/agent-core","type":"module","types":"./dist/index.d.ts","author":{"name":"AOS Agent"},"engines":{"node":">=22.19.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node.d.ts","import":"./dist/node.js"},"./package.json":"./package.json","./session/testing":{"types":"./dist/harness/session/testing/index.d.ts","import":"./dist/harness/session/testing/index.js"}},"gitHead":"8fc01dea402bced66d545cf6febddcd944d8943b","license":"MIT","scripts":{"test":"vitest --run","build":"tsgo -p tsconfig.build.json","clean":"shx rm -rf dist","test:harness":"vitest --run --config vitest.harness.config.ts","prepublishOnly":"npm run build","coverage:harness":"vitest --run --config vitest.harness.config.ts --coverage","check:telemetry-docs":"node scripts/generate-telemetry-docs.ts --check","generate-telemetry-docs":"node scripts/generate-telemetry-docs.ts"},"version":"0.85.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:412625a0-728f-4c8d-868f-a64917e9bba3"}},"homepage":"https://github.com/guanwenpeng2001-bot/AOS-Agent#readme","keywords":["ai","agent","llm","transport","state-management"],"repository":{"url":"git+https://github.com/guanwenpeng2001-bot/AOS-Agent.git","type":"git","directory":"packages/agent"},"_npmVersion":"11.5.1","description":"General-purpose agent with transport abstraction, state management, and attachment support","directories":{},"maintainers":[{"name":"aosagent","email":"guanwenpeng2001@gmail.com"}],"_nodeVersion":"24.20.0","dependencies":{"diff":"8.0.4","yaml":"2.9.0","ignore":"7.0.5","typebox":"1.3.7","@aos-agent/ai":"^0.85.1","@aos-agent/telemetry":"^0.85.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.1.9","typescript":"5.9.3","@types/node":"24.12.4","@vitest/coverage-v8":"4.1.9"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-core_0.85.1_1788452034945_0.7595971290527195"}}},"time":{"created":"2026-08-10T00:56:52.797Z","modified":"2026-09-03T16:13:55.441Z","0.84.2":"2026-08-10T00:56:53.078Z","0.84.3":"2026-08-10T17:44:45.127Z","0.85.0":"2026-09-02T05:23:28.102Z","0.85.1":"2026-09-03T16:13:55.090Z"},"bugs":{"url":"https://github.com/guanwenpeng2001-bot/AOS-Agent/issues"},"author":{"name":"AOS Agent"},"license":"MIT","homepage":"https://github.com/guanwenpeng2001-bot/AOS-Agent#readme","keywords":["ai","agent","llm","transport","state-management"],"repository":{"url":"git+https://github.com/guanwenpeng2001-bot/AOS-Agent.git","type":"git","directory":"packages/agent"},"description":"General-purpose agent with transport abstraction, state management, and attachment support","maintainers":[{"name":"aosagent","email":"guanwenpeng2001@gmail.com"}],"readme":"# @aos-agent/agent-core\n\nStateful agent with tool execution and event streaming. Built on `@aos-agent/ai`.\n\n## Installation\n\n```bash\nnpm install @aos-agent/agent-core\n```\n\n### SQLite session backends\n\nThe SQLite session backend and the `node:sqlite` adapter live in a separate package, `@aos-agent/session-backend-sqlite-node`, so the core package does not pull in runtime builtins or native SQLite dependencies by default. The backend accepts a runtime-specific SQLite factory, allowing other session backends to ship as their own packages in the future.\n\n## Quick Start\n\n```typescript\nimport { Agent } from \"@aos-agent/agent-core\";\nimport { createModels } from \"@aos-agent/ai\";\nimport { anthropicProvider } from \"@aos-agent/ai/providers/anthropic\";\n\nconst models = createModels();\nmodels.setProvider(anthropicProvider());\nconst model = models.getModel(\"anthropic\", \"claude-sonnet-4-6\");\nif (!model) throw new Error(\"Model not found\");\n\nconst agent = new Agent({\n  initialState: {\n    systemPrompt: \"You are a helpful assistant.\",\n    model,\n  },\n  streamFn: models.streamSimple.bind(models),\n});\n\nagent.subscribe((event) => {\n  if (event.type === \"message_update\" && event.assistantMessageEvent.type === \"text_delta\") {\n    // Stream just the new text chunk\n    process.stdout.write(event.assistantMessageEvent.delta);\n  }\n});\n\nawait agent.prompt(\"Hello!\");\n```\n\n## Core Concepts\n\n### AgentMessage vs LLM Message\n\nThe agent works with `AgentMessage`, a flexible type that can include:\n- Standard LLM messages (`user`, `assistant`, `toolResult`)\n- Custom app-specific message types via declaration merging\n\nLLMs only understand `user`, `assistant`, and `toolResult`. The `convertToLlm` function bridges this gap by filtering and transforming messages before each LLM call.\n\n### Message Flow\n\n```\nAgentMessage[] → transformContext() → AgentMessage[] → convertToLlm() → Message[] → LLM\n                    (optional)                           (required)\n```\n\n1. **transformContext**: Prune old messages, inject external context\n2. **convertToLlm**: Filter out UI-only messages, convert custom types to LLM format\n\n## Event Flow\n\nThe agent emits events for UI updates. Understanding the event sequence helps build responsive interfaces.\n\n### prompt() Event Sequence\n\nWhen you call `prompt(\"Hello\")`:\n\n```\nprompt(\"Hello\")\n├─ agent_start\n├─ turn_start\n├─ message_start   { message: userMessage }      // Your prompt\n├─ message_end     { message: userMessage }\n├─ message_start   { message: assistantMessage } // LLM starts responding\n├─ message_update  { message: partial... }       // Streaming chunks\n├─ message_update  { message: partial... }\n├─ message_end     { message: assistantMessage } // Complete response\n├─ turn_end        { message, toolResults: [] }\n└─ agent_end       { messages: [...] }\n```\n\n### With Tool Calls\n\nIf the assistant calls tools, the loop continues:\n\n```\nprompt(\"Read config.json\")\n├─ agent_start\n├─ turn_start\n├─ message_start/end  { userMessage }\n├─ message_start      { assistantMessage with toolCall }\n├─ message_update...\n├─ message_end        { assistantMessage }\n├─ tool_execution_start  { toolCallId, toolName, args }\n├─ tool_execution_update { partialResult }           // If tool streams\n├─ tool_execution_end    { toolCallId, result }\n├─ message_start/end  { toolResultMessage }\n├─ turn_end           { message, toolResults: [toolResult] }\n│\n├─ turn_start                                        // Next turn\n├─ message_start      { assistantMessage }           // LLM responds to tool result\n├─ message_update...\n├─ message_end\n├─ turn_end\n└─ agent_end\n```\n\nTool execution mode is configurable:\n\n- `parallel` (default): preflight tool calls sequentially, execute allowed tools concurrently, emit `tool_execution_end` as soon as each tool is finalized, then emit toolResult messages and `turn_end.toolResults` in assistant source order\n- `sequential`: execute tool calls one by one, matching the historical behavior\n\nIn parallel mode, tool completion events follow tool completion order, but persisted toolResult messages still follow assistant source order.\n\nThe mode can be set globally via `toolExecution` in the agent config, or per-tool via `executionMode` on `AgentTool`. If any tool call in a batch targets a tool with `executionMode: \"sequential\"`, the entire batch executes sequentially regardless of the global setting.\n\nThe `beforeToolCall` hook runs after `tool_execution_start` and validated argument parsing. It can block execution and attach `terminate: true` to the blocked result. The `afterToolCall` hook runs after tool execution finishes and before `tool_execution_end` and final tool result message events are emitted.\n\nTools, blocked `beforeToolCall` results, and `afterToolCall` overrides can return `terminate: true` to hint that the automatic follow-up LLM call should be skipped. The loop only stops early when every finalized tool result in that batch sets `terminate: true`. Mixed batches continue normally.\n\nThe `Agent` class accepts `shouldStopAfterTurn` in `AgentOptions`. Low-level loop callers can set the same hook in `AgentLoopConfig`:\n\n```typescript\nconst stream = agentLoop(\n  prompts,\n  context,\n  {\n    model,\n    convertToLlm,\n    shouldStopAfterTurn: async ({ message, toolResults, context, newMessages }) => {\n      return shouldCompactBeforeNextTurn(context.messages);\n    },\n  },\n  undefined,\n  models.streamSimple.bind(models),\n);\n```\n\n`shouldStopAfterTurn` runs after `turn_end` is emitted and after the assistant response and any tool executions have completed normally. If it returns `true`, the loop emits `agent_end` and exits before polling steering or follow-up queues, and before starting another LLM call. It does not abort the provider stream, does not cancel running tools, and does not alter the assistant message stop reason. The `AgentOptions` callback also receives the active run's `AbortSignal` as its second argument.\n\nWhen you use the `Agent` class, assistant `message_end` processing is treated as a barrier before tool preflight begins. That means `beforeToolCall` sees agent state that already includes the assistant message that requested the tool call.\n\n### continue() Event Sequence\n\n`continue()` resumes from existing context without adding a new message. Use it for retries after errors.\n\n```typescript\n// After an error, retry from current state\nawait agent.continue();\n```\n\nThe last message in context must be `user` or `toolResult` (not `assistant`).\n\n### Event Types\n\n| Event | Description |\n|-------|-------------|\n| `agent_start` | Agent begins processing |\n| `agent_end` | Final event for the run. Awaited subscribers for this event still count toward settlement |\n| `turn_start` | New turn begins (one LLM call + tool executions) |\n| `turn_end` | Turn completes with assistant message and tool results |\n| `message_start` | Any message begins (user, assistant, toolResult) |\n| `message_update` | **Assistant only.** Includes `assistantMessageEvent` with delta |\n| `message_end` | Message completes |\n| `tool_execution_start` | Tool begins |\n| `tool_execution_update` | Tool streams progress |\n| `tool_execution_end` | Tool completes |\n\n`Agent.subscribe()` listeners are awaited in registration order. `agent_end` means no more loop events will be emitted, but `await agent.waitForIdle()` and `await agent.prompt(...)` only settle after awaited `agent_end` listeners finish.\n\nThe loop is bounded by default. `maxIterations` protects against unbounded provider turns, repeated tool-call fingerprints stop duplicate calls, and unchanged progress tokens stop dead loops. When a convergence bound stops a run, `agent_end.terminationReason` is `max_iterations`, `duplicate_tool_call`, or `dead_loop`.\n\n### Production error categories and retry safety\n\nThe production loop classifies failures into stable categories:\n\n- `transient_provider`: a provider or transport failure that may be retried when the outcome is known to be safe.\n- `permission_or_parameter`: permission, schema, or parameter validation rejected the operation; do not retry unchanged input.\n- `side_effect_unknown`: the operation may have reached a tool, MCP server, sandbox, or provider before failing; the outcome must be reconciled before another attempt.\n- `cancelled`: the caller aborted the operation.\n- `deadline`: the operation exceeded its deadline.\n- `unknown`: a failure that does not match a stable category.\n\nClassifications also expose a stable operation (`model`, `tool`, `mcp`, or `sandbox`), phase, side-effect state, and `safeToRetry`/`retryable` flags. The exported error codes are `provider_unavailable`, `permission_denied`, `invalid_request`, `side_effect_unknown`, `cancelled`, `deadline_exceeded`, and `lease_expired`; an unclassified failure may have no stable code.\n\nRetries are bounded and apply only when a retry policy is enabled. A transient provider failure is retryable only before visible output and when no side effect is possible. Model retries use that rule directly; tool, MCP, and sandbox retries additionally require an explicit safe replay decision. Permission/parameter failures, cancellation, deadlines, unknown failures, and any `side_effect_unknown` result are terminal for automatic retry. Never blindly retry after `side_effect_unknown`; inspect or reconcile the external operation first because repeating it may duplicate a side effect.\n\nHigher-level connector retry circuits must preserve this boundary: even an\notherwise idempotent or resumable operation records a terminal stop decision\nwhen its durable side-effect state is `side_effect_unknown`.\n\n## Agent Options\n\n```typescript\nconst agent = new Agent({\n  // Initial state\n  initialState: {\n    systemPrompt: string,\n    model: Model<any>,\n    thinkingLevel: \"off\" | \"minimal\" | \"low\" | \"medium\" | \"high\" | \"xhigh\" | \"max\",\n    tools: AgentTool<any>[],\n    messages: AgentMessage[],\n  },\n\n  // Convert AgentMessage[] to LLM Message[] (required for custom message types)\n  convertToLlm: (messages) => messages.filter(...),\n\n  // Transform context before convertToLlm (for pruning, compaction)\n  transformContext: async (messages, signal) => pruneOldMessages(messages),\n\n  // Steering mode: \"one-at-a-time\" (default) or \"all\"\n  steeringMode: \"one-at-a-time\",\n\n  // Follow-up mode: \"one-at-a-time\" (default) or \"all\"\n  followUpMode: \"one-at-a-time\",\n\n  // Required stream function\n  streamFn: models.streamSimple.bind(models),\n\n  // Session ID for provider caching\n  sessionId: \"session-123\",\n\n  // Dynamic API key resolution (for expiring OAuth tokens)\n  getApiKey: async (provider) => refreshToken(),\n\n  // Tool execution mode: \"parallel\" (default) or \"sequential\"\n  toolExecution: \"parallel\",\n\n  // Bound provider/tool turns and stop repeated or dead loops.\n  loopConvergence: {\n    maxIterations: 100,\n    maxDuplicateToolCalls: 3,\n    maxNoProgressIterations: 5,\n  },\n\n  // Optional operation deadline. Use one form; deadlineAt takes precedence.\n  deadlineMs: 60_000,\n  // deadlineAt: Date.now() + 60_000,\n\n  // Preflight each tool call after args are validated. Can block execution.\n  beforeToolCall: async ({ toolCall, args, context }) => {\n    if (toolCall.name === \"bash\") {\n      return { block: true, reason: \"bash is disabled\", terminate: true };\n    }\n  },\n\n  // Postprocess each tool result before final tool events are emitted.\n  afterToolCall: async ({ toolCall, result, isError, context }) => {\n    if (toolCall.name === \"notify_done\" && !isError) {\n      return { terminate: true };\n    }\n    if (!isError) {\n      return { details: { ...result.details, audited: true } };\n    }\n  },\n\n  // Stop gracefully after a completed turn, before queued messages are polled.\n  shouldStopAfterTurn: async ({ context }, signal) => {\n    return shouldCompactBeforeNextTurn(context.messages, signal);\n  },\n\n  // Custom thinking budgets for token-based providers\n  thinkingBudgets: {\n    minimal: 128,\n    low: 512,\n    medium: 1024,\n    high: 2048,\n  },\n});\n```\n\n## Agent State\n\n```typescript\ninterface AgentState {\n  systemPrompt: string;\n  model: Model<any>;\n  thinkingLevel: ThinkingLevel;\n  tools: AgentTool<any>[];\n  messages: AgentMessage[];\n  readonly isStreaming: boolean;\n  readonly streamingMessage?: AgentMessage;\n  readonly pendingToolCalls: ReadonlySet<string>;\n  readonly errorMessage?: string;\n}\n```\n\nAccess state via `agent.state`.\n\nAssigning `agent.state.tools = [...]` or `agent.state.messages = [...]` copies the top-level array before storing it. Mutating the returned array mutates the current agent state.\n\nDuring streaming, `agent.state.streamingMessage` contains the current partial assistant message.\n\n`agent.state.isStreaming` remains `true` until the run fully settles, including awaited `agent_end` subscribers.\n\n## Methods\n\n### Prompting\n\n```typescript\n// Text prompt\nawait agent.prompt(\"Hello\");\n\n// With images\nawait agent.prompt(\"What's in this image?\", [\n  { type: \"image\", data: base64Data, mimeType: \"image/jpeg\" }\n]);\n\n// AgentMessage directly\nawait agent.prompt({ role: \"user\", content: \"Hello\", timestamp: Date.now() });\n\n// Continue from current context (last message must be user or toolResult)\nawait agent.continue();\n```\n\n### State Management\n\n```typescript\nagent.state.systemPrompt = \"New prompt\";\nagent.state.model = getModel(\"openai\", \"gpt-4o\");\nagent.state.thinkingLevel = \"medium\";\nagent.state.tools = [myTool];\nagent.toolExecution = \"sequential\";\nagent.loopConvergence = { maxIterations: 100, maxDuplicateToolCalls: 3 };\nagent.deadlineMs = 60_000;\nagent.beforeToolCall = async ({ toolCall }) => undefined;\nagent.afterToolCall = async ({ toolCall, result }) => undefined;\nagent.shouldStopAfterTurn = async ({ context }) => shouldCompactBeforeNextTurn(context.messages);\nagent.state.messages = newMessages; // top-level array is copied\nagent.state.messages.push(message);\nagent.reset();\n```\n\n### Session and Thinking Budgets\n\n```typescript\nagent.sessionId = \"session-123\";\n\nagent.thinkingBudgets = {\n  minimal: 128,\n  low: 512,\n  medium: 1024,\n  high: 2048,\n};\n```\n\n### Control\n\n```typescript\nagent.abort();           // Cancel current operation\nawait agent.waitForIdle(); // Wait for completion\n```\n\n### Events\n\n```typescript\nconst unsubscribe = agent.subscribe(async (event, signal) => {\n  if (event.type === \"agent_end\") {\n    // Final barrier work for the run\n    await flushSessionState(signal);\n  }\n});\nunsubscribe();\n```\n\n## Steering and Follow-up\n\nSteering messages let you interrupt the agent while tools are running. Follow-up messages let you queue work after the agent would otherwise stop.\n\n```typescript\nagent.steeringMode = \"one-at-a-time\";\nagent.followUpMode = \"one-at-a-time\";\n\n// While agent is running tools\nagent.steer({\n  role: \"user\",\n  content: \"Stop! Do this instead.\",\n  timestamp: Date.now(),\n});\n\n// After the agent finishes its current work\nagent.followUp({\n  role: \"user\",\n  content: \"Also summarize the result.\",\n  timestamp: Date.now(),\n});\n\nconst steeringMode = agent.steeringMode;\nconst followUpMode = agent.followUpMode;\n\nagent.clearSteeringQueue();\nagent.clearFollowUpQueue();\nagent.clearAllQueues();\n```\n\nUse clearSteeringQueue, clearFollowUpQueue, or clearAllQueues to drop queued messages.\n\nWhen steering messages are detected after a turn completes:\n1. All tool calls from the current assistant message have already finished\n2. Steering messages are injected\n3. The LLM responds on the next turn\n\nFollow-up messages are checked only when there are no more tool calls and no steering messages. If any are queued, they are injected and another turn runs.\n\n## Custom Message Types\n\nExtend `AgentMessage` via declaration merging:\n\n```typescript\ndeclare module \"@aos-agent/agent-core\" {\n  interface CustomAgentMessages {\n    notification: { role: \"notification\"; text: string; timestamp: number };\n  }\n}\n\n// Now valid\nconst msg: AgentMessage = { role: \"notification\", text: \"Info\", timestamp: Date.now() };\n```\n\nHandle custom types in `convertToLlm`:\n\n```typescript\nconst agent = new Agent({\n  streamFn: models.streamSimple.bind(models),\n  convertToLlm: (messages) => messages.flatMap(m => {\n    if (m.role === \"notification\") return []; // Filter out\n    return [m];\n  }),\n});\n```\n\n## Tools\n\nDefine tools using `AgentTool`:\n\n```typescript\nimport { Type } from \"typebox\";\n\nconst readFileTool: AgentTool = {\n  name: \"read_file\",\n  label: \"Read File\",  // For UI display\n  description: \"Read a file's contents\",\n  parameters: Type.Object({\n    path: Type.String({ description: \"File path\" }),\n  }),\n  // Override execution mode for this tool (optional).\n  // \"sequential\" forces the entire batch to run one at a time.\n  // \"parallel\" allows concurrent execution with other tool calls.\n  // If omitted, the global toolExecution config applies.\n  executionMode: \"sequential\",\n  execute: async (toolCallId, params, signal, onUpdate) => {\n    const content = await fs.readFile(params.path, \"utf-8\");\n\n    // Optional: stream progress\n    onUpdate?.({ content: [{ type: \"text\", text: \"Reading...\" }], details: {} });\n\n    // Optional: add `terminate: true` here to skip the automatic follow-up LLM call\n    // when every finalized tool result in the batch does the same.\n    return {\n      content: [{ type: \"text\", text: content }],\n      details: { path: params.path, size: content.length },\n    };\n  },\n};\n\nagent.state.tools = [readFileTool];\n```\n\n### Error Handling\n\n**Throw an error** when a tool fails. Do not return error messages as content.\n\n```typescript\nexecute: async (toolCallId, params, signal, onUpdate) => {\n  if (!fs.existsSync(params.path)) {\n    throw new Error(`File not found: ${params.path}`);\n  }\n  // Return content only on success\n  return { content: [{ type: \"text\", text: \"...\" }] };\n}\n```\n\nThrown errors are caught by the agent and reported to the LLM as tool errors with `isError: true`.\n\nReturn `terminate: true` from `execute()`, a blocked `beforeToolCall`, or `afterToolCall` to hint that the agent should stop after the current tool batch. This only takes effect when every finalized tool result in the batch is terminating. The hint is runtime-only; emitted `toolResult` transcript messages remain standard LLM tool results.\n\n## Proxy Usage\n\nFor browser apps that proxy through a backend:\n\n```typescript\nimport { Agent, streamProxy } from \"@aos-agent/agent-core\";\n\nconst agent = new Agent({\n  streamFn: (model, context, options) =>\n    streamProxy(model, context, {\n      ...options,\n      authToken: \"...\",\n      proxyUrl: \"https://your-server.com\",\n    }),\n});\n```\n\n## Low-Level API\n\nFor direct control without the Agent class:\n\n```typescript\nimport { agentLoop, agentLoopContinue } from \"@aos-agent/agent-core\";\n\nconst context: AgentContext = {\n  systemPrompt: \"You are helpful.\",\n  messages: [],\n  tools: [],\n};\n\nconst config: AgentLoopConfig = {\n  model: getModel(\"openai\", \"gpt-4o\"),\n  convertToLlm: (msgs) => msgs.filter(m => [\"user\", \"assistant\", \"toolResult\"].includes(m.role)),\n  toolExecution: \"parallel\",  // overridden by per-tool executionMode if set\n  beforeToolCall: async ({ toolCall, args, context }) => undefined,\n  afterToolCall: async ({ toolCall, result, isError, context }) => undefined,\n};\n\nconst userMessage = { role: \"user\", content: \"Hello\", timestamp: Date.now() };\n\nconst streamFn = models.streamSimple.bind(models);\nfor await (const event of agentLoop([userMessage], context, config, undefined, streamFn)) {\n  console.log(event.type);\n}\n\n// Continue from existing context\nfor await (const event of agentLoopContinue(context, config, undefined, streamFn)) {\n  console.log(event.type);\n}\n```\n\nThese low-level streams are observational. They preserve event order, but they do not wait for your async event handling to settle before later producer phases continue. If you need message processing to act as a barrier before tool preflight, use the `Agent` class instead of raw `agentLoop()` or `agentLoopContinue()`.\n\n## Public API\n\n### Loop and durable contracts\n\nThe following exports are the cross-package loop contract retained for\n`aos-agent`. Each description names the primary consumer; lower-level\napplications may also compose these contracts directly.\n\n**`ScopedExecutionGateway`.** Executes provider work under an admitted scope; the coding-agent in-process Subagent provider consumes it.\n\n**`validateAsk`.** Validates an Ask record before persistence; the coding-agent Ask store consumes it.\n\n**`validateGoal`.** Validates a Goal aggregate; the coding-agent goal store consumes it.\n\n**`validatePlan`.** Validates a Plan and its ordered stages; the coding-agent goal store consumes it.\n\n**`validateStage`.** Validates one Stage in a Plan; the coding-agent goal store consumes it.\n\n**`validateTaskResultRef`.** Validates a durable Task result reference; the coding-agent goal store consumes it.\n\n**`validateTodo`.** Validates a Todo owned by a Stage; the coding-agent goal store consumes it.\n\n**`AcceptanceCriterion`.** Describes one condition a Goal or Task must satisfy; the coding-agent orchestration store consumes it.\n\n**`AcceptanceFact`.** Records evidence against an acceptance condition; the coding-agent scheduler, prompt adapter, and orchestration store consume it.\n\n**`Ask`.** Represents a durable question in the orchestration loop; the coding-agent Ask store, query API, and scheduler messaging consume it.\n\n**`AskReply`.** Represents the answer attached to an Ask; the coding-agent Ask store consumes it.\n\n**`AskStatus`.** Enumerates the lifecycle state of an Ask; the coding-agent Ask store consumes it.\n\n**`Goal`.** Defines the desired orchestration outcome and its acceptance contract; the coding-agent goal store and query API consume it.\n\n**`Plan`.** Defines the staged route to a Goal; the coding-agent goal store and query API consume it.\n\n**`PlanStatus`.** Enumerates Plan lifecycle states; the coding-agent goal store consumes it.\n\n**`Stage`.** Defines one ordered unit of a Plan; the coding-agent goal store and query API consume it.\n\n**`StageStatus`.** Enumerates Stage lifecycle states; the coding-agent goal store consumes it.\n\n**`TaskResultRef`.** Points from orchestration state to a settled Task result; the coding-agent goal store consumes it.\n\n**`Todo`.** Defines a concrete pending action within a Stage; the coding-agent goal store and query API consume it.\n\n**`TodoStatus`.** Enumerates Todo lifecycle states; the coding-agent goal store consumes it.\n\n**`ServiceContract`.** Describes a service requirement exposed through orchestration queries; the coding-agent query API consumes it.\n\n**`SessionLedger`.** Provides typed fact and intent access over one canonical Session; coding-agent Connector, Scheduler, Subagent, and session services consume it.\n\n**`LayeredResultSettlement`.** Validates and writes Dispatch, Attempt, TaskResult, and Run settlement through the canonical ledger; coding-agent Scheduler, Subagent, RPC, and runtime composition consume it.\n\n**Task result producers.** `aggregateTaskResultProducers`, `loadDurableTaskResultToolRecords`, `loadDurableFinalAssistantText`, `writeTaskResultArtifact`, and `isValidationCommand` derive bounded settlement inputs from durable tool receipts, assistant checkpoints, and content-addressed artifacts. `DurableTaskResultToolRecord`, `FileChangeArtifactWrite`, `TaskResultProducerInput`, and `TaskResultProducerOutput` describe that producer boundary; `TASK_RESULT_SUMMARY_MAX_LENGTH` is its summary limit.\n\n**`persistTaskEnvelopeBeforeResolver`.** Persists an immutable Task before dependency resolution or provider effects; coding-agent product-run, prompt, and Subagent composition consume it.\n\n**`CanonicalRunResult`.** Projects the canonical settled Run and receipt; coding-agent lifecycle, audit, Automation, and RPC surfaces consume it.\n\n**`DispatchStartResult`.** Reports the admitted Dispatch and Attempt start state; the coding-agent Scheduler dispatch path consumes it.\n\n**`isSideEffectRetryable`.** Decides whether an idempotency declaration permits replay for a side-effect state; coding-agent Scheduler host policy consumes it.\n\n**`Idempotency`.** Describes an operation's replay guarantee; coding-agent Scheduler and tool-pipeline consumers use it for retry decisions.\n\n**`SideEffectState`.** Records whether an operation had no, known, or unknown side effects; coding-agent Worker, Connector, and settlement consumers use it.\n\n**`TaskEnvelopePublicProjectionSchema`.** Validates the safe public subset of a Task envelope; coding-agent Subagent context-fork consumes it.\n\n**`createAttempt`.** Constructs a validated Attempt from an admitted Dispatch; coding-agent Connector, Scheduler, Subagent, and prompt ingress consume it.\n\n**`createTaskEnvelope`.** Constructs an immutable Task envelope; coding-agent product-run, prompt, and Subagent composition consume it.\n\n**`projectTaskEnvelope`.** Produces a safe Task projection for child context; coding-agent Subagent context-fork consumes it.\n\n**`validateAttempt`.** Validates an Attempt before execution or settlement; coding-agent Connector, Scheduler, and Subagent consumers use it.\n\n**`validateDispatch`.** Validates a Dispatch before execution or settlement; coding-agent Scheduler, Subagent, and AgentHarness consumers use it.\n\n**`validateSpawnAgentIntent`.** Validates a child-agent spawn intent before settlement; the coding-agent Subagent supervisor consumes it.\n\n**`validateTaskEnvelope`.** Validates a Task envelope and immutable references; coding-agent Scheduler, Subagent, and runtime consumers use it.\n\n**`validateTaskEnvelopePublicProjection`.** Validates a safe child-facing Task projection; coding-agent Subagent context-fork consumes it.\n\n**`Attempt`.** Identifies one provider execution attempt under a Dispatch; coding-agent Connector, Scheduler, and Subagent consumers use it.\n\n**`Dispatch`.** Binds a Task, provider, and execution authority; coding-agent Connector, Scheduler, Subagent, and AgentHarness consumers use it.\n\n**`TaskArtifactProjection`.** Describes artifacts safe to include in child context; coding-agent Subagent context-fork and fork protocol consume it.\n\n**`TaskEnvelope`.** Carries the immutable Task contract into execution; coding-agent Scheduler, Subagent, Connector, and settlement consumers use it.\n\n**`TaskEnvelopePublicProjection`.** Carries the safe child-facing subset of a Task; coding-agent Subagent context-fork consumes it.\n\n**`MemoryError`.** Provides stable errors for scoped memory operations; coding-agent Subagent memory consumes it.\n\n**`ScopedMemoryStore`.** Reads and writes memory within provenance and scope boundaries; coding-agent Subagent composition consumes it.\n\n**`MemoryProvenanceBoundary`.** Describes the allowed provenance of scoped memory; coding-agent Subagent memory and context-ledger consumers use it.\n\n**`bashExecutionToText`.** Converts a Bash execution message into model-facing text; repository smoke tooling consumes it.\n\n**`convertToLlm`.** Converts Agent messages into provider messages; AgentHarness, compaction, and repository smoke tooling consume it.\n\n**`createCompactionSummaryMessage`.** Creates the transcript message that carries a compaction summary; coding-agent session composition consumes it.\n\n**`createCustomMessage`.** Creates a typed custom Agent message; repository smoke tooling consumes it.\n\n**`formatPromptTemplateInvocation`.** Formats prompt-template arguments into an Agent message; AgentHarness and resource consumers use it.\n\n**`parseCommandArgs`.** Parses command-style resource arguments; AgentHarness resource consumers and smoke tooling use it.\n\n**`Result`.** Provides the success-or-error constructor used by Foundation operations; agent-core and coding-agent contract implementations consume it.\n\n**`ResultValue`.** Describes the typed success-or-error value produced by Foundation operations; agent-core and coding-agent contract implementations consume it.\n\n**`parseFoundationMutation`.** Decodes a durable Foundation mutation from storage; JSONL storage, migration, audit, and coding-agent lifecycle consumers use it.\n\n**`DurableLedgerError`.** Provides stable durable-ledger failure codes; ledger, settlement, and coding-agent lifecycle consumers use it.\n\n**`invalidDurableRecord`.** Constructs a stable invalid-record error without leaking raw data; durable state and coding-agent lifecycle consumers use it.\n\n**`FoundationLedgerState`.** Folds durable Foundation records, revisions, leases, and retention in memory; agent-core storage backends and coding-agent lifecycle, storage, and audit services consume it.\n\n**`AcquireWriterLeaseOptions`.** Configures acquisition of the ledger's single-writer lease; Session storage and coding-agent manager storage consume it.\n\n**`AppendFoundationRecordResult`.** Reports an appended record and resulting revision; Session, ledger writer, storage, and tool-pipeline consumers use it.\n\n**`DurableLedgerApi`.** Defines the durable record, query, lease, and retention storage interface; agent-core backends and coding-agent Scheduler/session services implement or consume it.\n\n**`FoundationFactRecord`.** Represents an immutable durable fact; ledger, settlement, storage, and coding-agent lifecycle consumers use it.\n\n**`FoundationObjectResult`.** Represents the current folded state of a Foundation object; Session, ledger, storage, and coding-agent consumers use it.\n\n**`FoundationRecord`.** Represents any durable Foundation fact or intent record; Session, codec, storage, and coding-agent consumers use it.\n\n**`FoundationRecordQuery`.** Filters durable Foundation record reads; Session, ledger, storage, and coding-agent consumers use it.\n\n**`FoundationRetentionPolicy`.** Defines retention limits for durable Foundation records; storage and coding-agent session management consume it.\n\n**`LedgerWriterLease`.** Identifies the active single-writer authority and revision; Session, ledger writer, storage, and coding-agent consumers use it.\n\n**`ProvisionedFoundationRecord`.** Represents a durable record with assigned revision metadata; Session, ledger, and storage consumers use it.\n\n**`ReleaseWriterLeaseOptions`.** Configures release of a writer lease; Session storage and coding-agent manager storage consume it.\n\n**`RenewWriterLeaseOptions`.** Configures renewal of a writer lease; Session storage and coding-agent manager storage consume it.\n\n**`SetRetentionPolicyOptions`.** Configures a retention-policy update; Session storage and coding-agent manager storage consume it.\n\n**`SessionLedgerWriter`.** Serializes canonical ledger mutations under one Session and writer identity; agent-core artifact, context, memory, and settlement services plus coding-agent Scheduler and Subagent consumers use it.\n\n### Transport protocol and security contracts\n\n**`PROTOCOL_VERSION`.** Current Foundation transport protocol version; coding-agent RPC transport negotiation consumes it.\n\n**`negotiateProtocol`.** Negotiates compatible protocol version and features between client and server; coding-agent RPC and WebSocket transport consumers use it.\n\n**`validateEndpointSecurity`.** Validates endpoint security configuration before binding a transport; coding-agent RPC transport setup consumes it.\n\n**`authenticateConnection`.** Verifies the transport-provided bearer or mTLS proof; coding-agent RPC transport handshake consumes it.\n\n**`EndpointKind`.** Identifies a transport endpoint kind (`stdio`, `tcp`, or `websocket`); coding-agent RPC transport addressing consumes it.\n\n**`EndpointSecurityVerdict`.** Summarizes loopback, auth, TLS, and remote-access posture for an endpoint; coding-agent transport security checks consume it.\n\n**`ProtocolCapabilities`.** Describes supported protocol versions and feature flags; coding-agent RPC initialize negotiation consumes it.\n\n**`ProtocolFeature`.** Names one negotiated protocol capability; coding-agent RPC transport feature gating consumes it.\n\n**`ProtocolNegotiation`.** Carries the negotiated protocol version and enabled features; coding-agent RPC clients and hosts consume it.\n\n### Complete exported-name index\n\nThis index is checked against the public API whitelist. It provides searchable\ndocumentation evidence for every retained package-root export; the sections\nabove and the rest of this README provide behavioral guidance for the primary\ncontracts.\n\n```text\nAcceptanceCriterion, AcceptanceFact, AcquireWriterLeaseOptions, Agent, AgentBinding, AgentContext, AgentEvent, AgentHarness, AgentHarnessFoundationExecution, AgentHarnessOptions, AgentHarnessTool, AgentInstance, AgentLoopConfig, AgentMessage, AgentOperationError, AgentOperationSignal, AgentState, AgentTool, AgentToolResult, AgentToolUpdateCallback, AppendFoundationRecordResult, ArtifactDigest, ArtifactRef, ArtifactRefSchema, ArtifactStoreProvider, Ask, AskReply, AskStatus, Attempt, AttemptReceipt, AttemptReceiptUsage, BindingEpoch, BranchBounds, Budget, BudgetSchema, BudgetUsage, BudgetUsageSchema, CanonicalRunResult, ChildAgentProvider, ChildSpawnRequest, ChildSpawnResult, ConnectorCapabilitySnapshot, ContextForkMode, ContextSnapshot, ContextSnapshotRecord, ContextSnapshotSource, Dispatch, DispatchExecutionResult, DispatchStartResult, DurableEventCategory, DurableEventEnvelope, DurableLedgerApi, DurableLedgerError, EXTERNAL_ERROR_CODES, EXTERNAL_ERROR_MESSAGES, EndpointKind, EndpointSecurityVerdict, Entry, EntryOrder, EntryQuery, EventCorrelationRef, ExecutionCorrelation, ExecutionEnv, ExecutionProviderDescriptor, ExecutionToolContext, ExternalAgentConnector, ExternalErrorCode, FOUNDATION_ERROR_CODES, FOUNDATION_TOOL_RESULT_CUSTOM_TYPE, FileError, FileSystem, Fingerprint, FingerprintSchema, ForkOptions, FoundationEnvelope, FoundationError, FoundationErrorCode, FoundationEventEnvelope, FoundationFactRecord, FoundationJsonValue, FoundationLedgerState, FoundationObjectResult, FoundationObserver, FoundationProviderCapability, FoundationProviderExecutionOptions, FoundationRecord, FoundationRecordQuery, FoundationRetentionPolicy, FoundationToolGatewayAuthority, Goal, HarnessCompactionHookInput, HarnessCompactionHookResult, HarnessCompactionResult, HarnessContextPreparationInput, HarnessModelCallBoundaryInput, HarnessTool, Idempotency, InMemoryArtifactBlobStore, InMemorySessionRepo, InMemorySessionStorage, LanePointer, LaneRecord, LayeredResultSettlement, LedgerWriterLease, LogItem, LogOptions, McpCapabilityBinding, McpSelection, McpToolRoute, MemoryError, MemoryProvenanceBoundary, MessageEntry, ModelProfile, ModelRoute, ModelRouteSchema, NOOP_TELEMETRY_CONTEXT, NewRecord, ObserverCursor, OperationStartedRecord, OtlpHttpTelemetryContext, OtlpHttpTelemetryDiagnostic, OtlpHttpTelemetryOptions, OtlpHttpTelemetryStats, PROTOCOL_VERSION, Plan, PlanStatus, PluginContract, PrepareNextTurnContext, ProfileContract, ProtocolCapabilities, ProtocolFeature, ProtocolNegotiation, ProvisionedEntry, ProvisionedFoundationRecord, PublicExecutionError, PublicExecutionErrorCategory, QueueMode, QuotaAttribution, QuotaProvider, QuotaReservation, ROLE_RESOLUTION_ORDER, RecordQuery, ReleaseWriterLeaseOptions, RenewWriterLeaseOptions, ResourceSelector, ResourceSelectorSchema, Result, ResultProvenance, ResultValidation, ResultValue, RevisionReference, RevisionReferenceSchema, RoleDefinition, RoleRegistry, RoleRevision, RunOutcome, RunReceipt, SandboxOperationProvider, SandboxOperationRequest, SchedulerClaimEventPayload, SchedulerDeadlockEventPayload, SchedulerDispatchEventPayload, SchedulerHandoffEventPayload, SchedulerQueueEventPayload, SchedulerTaskExecutorProvider, SchedulerWakeEventPayload, ScopedExecutionGateway, ScopedMemoryStore, ScopedModelGateway, ServiceContract, Session, SessionCreateOptions, SessionError, SessionLedger, SessionLedgerWriter, SessionLedgerWriterOptions, SessionMetadata, SessionRepo, SessionSearch, SessionSearchHit, SessionSearchOptions, SessionStats, SessionStorage, SetRetentionPolicyOptions, SettleTaskResultInput, SideEffectState, Stage, StageStatus, StepAttemptRecord, StreamFn, TaskArtifactProjection, TaskContextPackage, TaskEnvelope, TaskEnvelopePublicProjection, TaskEnvelopePublicProjectionSchema, TaskExecutorAttemptContext, TaskExecutorProvider, TaskResult, TaskResultRef, TelemetryContext, ThinkingLevel, Todo, TodoStatus, ToolExecutionMode, ToolExecutionResult, ToolGateway, ToolGatewayProvider, ToolGatewayRequest, ToolGatewayRoute, ToolGatewayRouteCatalog, ValidationResult, VersionedReference, WorkerReceipt, WorkerReceiptRef, agentLoop, agentLoopContinue, artifactDigestFromId, assertJsonSerializable, authenticateConnection, bashExecutionToText, budgetExhaustionReason, canonicalFoundationJson, cloneDeepFrozen, contextSnapshotFromJSON, convertToLlm, createAgentInstance, createAgentOperationSignal, createAttempt, createBashTool, createBindingEpoch, createCompactionSummaryMessage, createConnectorCapabilitySnapshot, createContextSnapshot, createCustomMessage, createDurableEvent, createEditTool, createExecutionCorrelation, createFoundationToolGateway, createFoundationToolGatewayAuthority, createHostTerminalGateAuthority, createModelProfileRevision, createOrderedBindingEpoch, createReadTool, createRoleRevision, createSandboxOperationToolGatewayProvider, createTaskEnvelope, createWriteTool, decodeLegacyFoundationRecordV1, executeOperation, fingerprintFoundationValue, formatPromptTemplateInvocation, formatSkillInvocation, formatSkillsForSystemPrompt, getFileSystemResultOrThrow, getOrThrow, invalidDurableRecord, isSideEffectRetryable, isToolGatewayRoute, isValidArtifactDigest, isValidArtifactId, isValidationCommand, loadDurableFinalAssistantText, loadDurableTaskResultToolRecords, negotiateProtocol, newFoundationId, ok, parseCommandArgs, parseExactShape, parseFoundationMutation, persistTaskEnvelopeBeforeResolver, projectMcpSelectionToSelector, projectTaskEnvelope, redactText, resolveAgentBinding, resolveMcpSelection, selectorsNarrow, serializeExactShape, setDefaultStreamFn, sha256HexValue, streamProxy, toError, truncateHead, validateAgentBinding, validateAgentInstance, validateAndVerifyToolReceipt, validateArtifactRef, validateAsk, validateAttempt, validateAttemptReceipt, validateAttemptReceiptForProvider, validateAttemptReceiptUsage, validateBindingEpoch, validateBudget, validateBudgetUsage, validateChildMcpSelection, validateChildSpawnRequest, validateConnectorCapabilitySnapshot, validateConnectorCapabilitySnapshotForProvider, validateDispatch, validateDurableEvent, validateEndpointSecurity, validateEventPayloadForCategory, validateExactShape, validateExecutionCorrelation, validateFingerprint, validateFoundationProviderCapability, validateFoundationToolResultEntry, validateGoal, validateImmutableAgentBinding, validateMcpSelection, validateMcpSelectionForBinding, validatePlan, validateProviderJson, validatePublicExecutionError, validateQuotaAttribution, validateQuotaReservation, validateRoleRevision, validateRunReceipt, validateSandboxOperationRequest, validateSecretFreeModelProfile, validateSpawnAgentIntent, validateStage, validateTaskEnvelope, validateTaskEnvelopePublicProjection, validateTaskResult, validateTaskResultRef, validateTodo, validateToolExecutionResult, validateToolGatewayRequest, validateVersionedReference, validateWorkerReceipt, validateWorkerReceiptForProvider\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}