@assemblyline-agents/runtime
v10.3.2
Published
Vendor-neutral, filesystem-first framework for durable AI agents.
Maintainers
Readme
@assemblyline-agents/runtime
The Assembly Line runtime: the durable engine that executes compiled agents.
It orchestrates agent runs and turns, channel ingress and delivery, connections (MCP clients, OpenAPI clients, connection auth and stores), builtin tools and tool execution, checkpoints, scheduling, concurrency control, attachments, sandbox integration, and telemetry. Its usage subsystem records idempotent provider receipts, keeps unavailable values explicit instead of estimating them, exposes arbitrary-period aggregates, and reconciles provider control totals. Accounting is behavior-neutral: observation failures are warned but never gate a model request or response. State, blob, and sandbox behavior are pluggable through adapter interfaces implemented by packages such as @assemblyline-agents/postgres, @assemblyline-agents/s3, and @assemblyline-agents/docker. Hosts like @assemblyline-agents/node embed this runtime to serve agents.
Production hosts execute authored tools in the agent-selected Node.js 22
sandbox by default, without importing their modules into the host. Scoped
tool-context operations are brokered back to the host. Authored tools receive
only declared non-secret ctx.config; they never receive ctx.channel.env or
a generic credential map. Live bridge envelopes are published atomically so
large sandbox file reads cannot expose partial JSON responses. An embedding
host may explicitly select direct
execution only for reviewed code in its trusted computing base. Framework
built-ins, connections, and trusted host stubs remain direct.
Oversized model-facing tool results are retained privately in the blob store.
The runtime returns a bounded preview with a read_tool_result reference;
agents page through the complete projection without rerunning tools. Fields
hidden by an authored toModelOutput remain hidden. See
tool-result retrieval.
The runtime owns a just-in-time credential broker. Each connection receives only its declared configuration and a credential accessor that rejects unrelated names. Credential use and host-side source-to-sink transfers emit value-free audit metadata. See the developer guide for the complete configuration and credential boundary.
Accepted skill and durable-memory changes are mirrored by default into a runtime-owned Git audit repository under the artifact root. The live stores remain authoritative, and the repository is never exposed as a model tool or filesystem surface.
Install
npm install @assemblyline-agents/runtimePart of Assembly Line
This package is part of Assembly Line, a vendor-neutral, filesystem-first framework for durable AI agents. See the developer documentation in docs/developers/ for setup, agent authoring, and deployment guides.
License
MIT
