The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Wasmagent Js listing page.
WasmAgent adds a verifiable evidence layer to agent tool use: protect tool calls, record what happened, audit the result, and admit trusted traces into downstream systems.
Protect → Record → Audit → Admit · Sync — agent↔UI shared state
Pick your entry point:
| Goal | Install |
|---|---|
| Protect tools — runtime firewall, policy enforcement, taint tracking | npm add @wasmagent/mcp-firewall |
| Record evidence — signed AEP records after every agent run | npm add @wasmagent/aep |
Admit from traces — compliance scoring produces ComplianceEvalRecords for downstream training | npm add @wasmagent/aep @wasmagent/compliance |
| Sync state — reducer-backed agent↔UI shared state, agent reads projections + writes intent | npm add @wasmagent/core (/shared-state subpath) |
Trust Pack — 30-minute end-to-end: docs/quickstarts/trust-pack-30min.md
Three paths — pick the one that fits your use case:
Wrap any MCP server: vet tools before execution, enforce policy per call, track taint across results.
→ Security pack · OWASP Agentic Top 10 · Attack demos
Emit a signed evidence record after every agent run — consumable by trace-pipeline for audit and training.
→ AEP schema · trace-pipeline 10-min tutorial
Run agent-generated code in an isolated WASM kernel — no host-process access.
→ Kernel comparison · Getting started
Reducer-backed collaborative state where the LLM reads projections, dispatches semantic actions, and respects affordances — all through standard tools.
The semantic action stream doubles as AEP evidence — every dispatch is a provenance-ready record (see #141 for the full confluence design).
📚 Docs · Getting started · Kernels · OWASP governance · Security pack · Changelog
WasmAgent uses a five-tier maturity scale to prevent "shipped" from becoming a vague claim:
| Tier | Meaning | Semver guarantee | Production use |
|---|---|---|---|
| stable | Public API locked; breaking changes require major-version bump | Yes | Yes |
| beta | Functional and used in production, but a specific limitation is documented (e.g. first-line filter only, contract still evolving) | Minor/patch only | Yes, with caveats documented |
| alpha | Schema versioned; fields may be added without a breaking-change bump | No | Informed use |
| demo | Demonstration or example code; not hardened for production | No | No |
| research | Research-grade prototype; interfaces may change without notice | No | No |
Packages not listed here (model adapters, UI cards, etc.) follow the same scale — see each package's README or package.json wasmagent.stability field.
| Package | Maturity | Notes |
|---|---|---|
@wasmagent/core | stable | Public API; semver guaranteed |
@wasmagent/kernel-quickjs | stable | |
@wasmagent/kernel-remote | stable | |
@wasmagent/mcp-gateway | stable | Published 0.1.0; gateway composes all firewall layers |
@wasmagent/mcp-firewall | beta | First-line filter, not adversarial-grade — keyword bag + lightweight n-gram classifier; use defence-in-depth |
@wasmagent/aep | beta | v0.2 signature contract (Ed25519) shipped; schema versioned |
@wasmagent/otel-exporter | alpha | GENAI_SEMCONV, AEP↔OTel bridge |
@wasmagent/aisdk / @wasmagent/mastra-sandbox | alpha | API stable, may add fields |
@wasmagent/compliance | alpha | Schema versioned; may add fields without breaking |
@wasmagent/mcp-policy | alpha — private | Not yet published to npm |
@wasmagent/mcp-attestation | alpha — private | Not yet published to npm |
@wasmagent/evals-runner | alpha | |
@wasmagent/devtools | alpha |
WasmAgent is a portable, governable agent runtime for safe code execution, verifiable rollouts, and post-training data loops.
| Repo | Role |
|---|---|
| wasmagent-js (this repo) | Embedded Agent Runtime / WASM Kernel / policy / verifier / adapters |
| bscode | Cloudflare flagship demo and deploy template for safe coding agents |
| trace-pipeline | Public datafactory and eval-trust backend for rollout data |
Three wedges where wasmagent stands apart from generic agent frameworks:
| Wedge | What it means |
|---|---|
| Sandboxed execution | Three isolation tiers — VmKernel / WASM (QuickJS·Pyodide·Wasmtime) / microVM — with a single CapabilityManifest and MCP runtime firewall across all |
| Runtime compliance | TaskSpec → ConstraintIR → ComplianceEvalRecord — every run produces an auditable, cross-repo training contract, not just a log |
| Trace-to-training contract | Verifiable rollout branching, objective scoring, DPO/PPO export — the loop from runtime evidence to training data is first-class, not an afterthought |
| # | Axis | Status |
|---|---|---|
| 1 | Multi-provider adapters — one Model interface across Anthropic, OpenAI, Doubao, DeepSeek, Kimi, Qwen, GLM, MiniMax, local llama.cpp | shipped |
| 2 | Three isolation tiers — VmKernel (in-process) / QuickJS·Pyodide·Wasmtime (WASM) / RemoteSandboxKernel (microVM) — same CapabilityManifest across all | shipped |
| 3 | Cross-runtime + offline — Node / edge / browser / air-gapped laptop; @wasmagent/model-local + WASM kernel = zero outbound traffic | shipped |
| 4 | Memory layers — MemoryBlockSet (prompt-cache stable) + observational memory + Checkpointer + 4 KV backends | shipped |
| 5 | Durable workflows — LocalWorkflowEngine + CloudflareWorkflowEngine — observable, terminable, resumable | shipped |
| 6 | Code-mode MCP — N tools → 2 tools (docs_search + execute_code); 13.6% token cost at N=30 | shipped |
| 7 | Devtools + OTel — local Studio, gen_ai.* semantic conventions (Datadog / Honeycomb / Grafana) | shipped |
| 8 | Goal-directed loop — agent synthesises success criteria, verifies, retries with hints | shipped 2026-06-18 |
| 9 | Adaptive execution — registered fallbacks (L1) → synthesised tool (L2) → relaxed goal (L3) | shipped 2026-06-18 |
| 10 | MCP runtime firewall — @wasmagent/mcp-firewall: descriptor snapshot, static vetting (injection / exfiltration / rug-pull / taint), per-call policy, consent ledger | shipped 2026-06-25 |
Full comparison with Vercel AI SDK, LangGraph.js, OpenAI Agents JS, Mastra, CF Agents SDK: docs/compare.md
GitHub Action — enforce policy in CI:
→ MCP Guard guide · Attack demos
| Capability | Guide |
|---|---|
| Shared state — reducer-backed agent↔UI sync, projections, affordances | packages/core/src/shared-state/ |
| MCP firewall — vetTool, ScopeLease, ApprovalReceipt | docs/guides/mcp-guard.md |
| AEP v0.2 evidence — causal chain, scope lease, taint, memory refs | packages/aep/src/types.ts |
| OWASP MCP Top 10 crosswalk | docs/security/standards-crosswalk.yaml |
| OWASP security demo (10 scenarios) | examples/owasp-demo/ |
| Security benchmark runner | examples/security-benchmark/ |
| AEP ↔ OTel bidirectional mapping | packages/otel-exporter/src/aep-otel-bridge.ts |
| AgentTeam delegation chain | packages/core/src/agents/AgentTeam.ts |
| Claim dashboard | node scripts/verify-claims.mjs --html → docs/claims/claims.html |
| Quality runners (self-consistency, reflect-refine, parallel fork-join) | docs/guides/quality-runners.md |
| Durable runtime (checkpoints, SSE resume, HITL) | docs/guides/durable-runtime.md |
| Observational memory — ~22% tokens on 50-turn traces | docs/guides/observational-memory.md |
| Goal-directed agent with verifiers | docs/guides/goal-directed.md |
| Production APIs (retry, evals, OTel, React hook) | docs/api/production-apis.md |
| API stability policy | docs/api/stability-policy.md |
First-class adapters: Anthropic · OpenAI · Doubao · DeepSeek · Kimi · Qwen · GLM · MiniMax · local llama.cpp
Full provider reference and proxy/custom endpoint setup: docs/guides/openai-compat-recipes.md
| Project | Role |
|---|---|
| bscode | Flagship Cloudflare deploy template — wires every wasmagent-js capability into a real edge product |
| trace-pipeline | Training data factory — converts ranked rollouts into DPO/PPO datasets |
Upstream integration status (PRs filed to Vercel AI SDK, Mastra,
LangChain.js, ElizaOS, MCP registry, …) is tracked in
docs/distribution/upstream-prs.md.