@anturno/curlos
v0.4.0
Published
CurlOS — read-only review workspace runtime (open → inspect → close)
Downloads
658
Maintainers
Readme
CurlOS
CurlOS is an Eve-first, read-only review workspace runtime for code-review
agents. Open or reuse a pinned GitHub pull-request diff in a bounded
in-memory /workspace, inspect with typed readFile / glob / grep, then
close when Eve tears down the sandbox. No guest network, no model-facing shell
— credentials never enter the workspace.
The supported runtime is Eve. Its /sandbox, /eve, and /github
adapters own the review lifecycle; the low-level policy and checkout seams are
internal implementation details.
What you get
open/reuse → inspect → close— one Eve session owns checkout, reads, cache reuse, and teardown- Host-side checkout — providers materialize blobs on the host; only decoded
bytes cross into
/workspace - Hard caps — file count, bytes, matches, and output stay bounded; skips show
up on
manifest.skipped - Canonical Eve tools —
createCurlOsEveToolexposes boundedread_file/glob/grepregistrations without duplicated schemas - Diff-native GitHub adapter — changed files only, removed files excluded, blob requests deduplicated, and byte budgets enforced atomically
import { openGitHubDiffCurlOs } from "@anturno/curlos/github";
import { curlOsForSandbox } from "@anturno/curlos/eve";
const session = await openGitHubDiffCurlOs(channel, await ctx.getSandbox());
const review = curlOsForSandbox(await ctx.getSandbox());
await review.readFile({ filePath: "src/ok.ts", limit: 80 });Why it exists
Review agents need to read untrusted trees, not run them. CurlOS is that workspace contract: small enough to reason about, strict enough for shared-host deployments. Curl is the reference Eve consumer and uses the diff-native GitHub path.
Get started
docs/getting-started.md · docs/api.md
npm install @anturno/curlos eve just-bashLimits and threat model: contract. Exports: API.
For local changes, run bun run check, bun run typecheck, bun test, and
bun run pack:check. Published package supports Node ≥ 20; repo scripts use
Bun. For a reproducible contributor environment, open the repository with the
devcontainer. CurlOS has no required
runtime environment variables or local database/services; see
.env.example.
Docs
- Getting started
- API
- Contract
- Architecture
- Maintainer runbooks
- Curl — reference PR review agent (Eve)
- Contributing
- Security
- Changelog
