Docs · Source · pip install awask · The Aither World
The Aither World is an operating system for agents — a Linux you can hand to one, the runtimes it works in, and the tools it works with. awnix is the Linux underneath it; awask is one of its 55 bricks — each installs on its own, runs offline, and needs no account.
Start here: Ask a human a question from a script, and keep working on their answer.
An agent that needs a human has one channel today: prose in a terminal. That channel loses. The deciding sentence sits in paragraph four, you are in another window, and the run sits idle for forty minutes because nothing told you it was waiting.
awask makes the ask a thing instead of a line of text: a small structured card
in a durable store, rendered by every surface, whose answer is carried back into the
run that raised it.
pip install awaskPython 3.9+. Zero dependencies — standard library only. The store is a directory of JSON files, so this is the entire setup: no server, no login, no network, nothing to start before it works.
awask ask "Ship the migration now, or hold for review?" \
--summary "Tests pass. The rollback path is untested." \
--fact "312 rows affected" \
--fact "rollback has never been run against prod data" \
--option "ship|Ship it|live in ~2 min, rollback unproven" \
--option "hold|Hold for review|no risk, blocks tonight's release" \
--recommend hold --default hold --urgency highReturns immediately. Your agent keeps working; you answer at your own pace.
awask list # what is waiting on you
awask show <id> # one card in full
awask answer <id> hold # pick an option
awask steer <id> "check the FK constraint first" # guidance; card stays open
awask cancel <id> # withdraw it — you solved it yourselfUse | as the option separator, never : — a Windows path in a consequence
(C:\data) silently mangles with the colon form.
The CLI alone gives you cards when an agent types the command, and delivers your answer at your next prompt. To make it automatic:
awask install-hooks # this project
awask install-hooks --user # every project
awask install-hooks --dry-runThat writes three hooks and merges three entries into settings.json:
| event | hook | what it does |
|---|---|---|
Stop |
stop_awask_cards.py |
holds the turn open ~50s so your answer resumes the run |
UserPromptSubmit |
awask_mailbox_drain.py |
carries your answer INTO the session |
Notification |
awask_notification_card.py |
"the agent is waiting" becomes a card |
The middle one is the one people skip and the one that matters. Without it you can answer a card and the agent never learns you did — the card renders, you click, the store records a resolution, and the run carries on as though nobody replied. Every component reports success.
Your existing settings.json is merged, never replaced; re-running is a no-op;
a malformed settings file is refused rather than overwritten; and every hook is run
with --self-test after being written, because a copy is not an install.
A card that cannot be answered from a phone lock screen is not finished.
- Title — one line, the whole ask. If it needs two, raise two cards.
- Facts — what you measured, not what you guess. Highest-value field here.
- Options — each with a consequence. A label says what a choice is called; a consequence says what happens to your machine. Only the consequence lets someone decide without reading the code.
--recommend— say what you would do. A card with no recommendation pushes your thinking onto the human.--default— what happens if nobody ever answers. Required: a card is only safe to ignore if it says what ignoring it does. An agent that cannot name a default is not blocked on a decision, it is blocked on doing its own thinking.
A card is an interruption. The default is to keep working. Raise one only when all three hold:
- The answers lead to materially different work, and
- A wrong guess costs real work to undo — time, money, data, or something outward-facing, and
- You cannot settle it yourself by reading, measuring, or taking the conventional default.
If any clause fails: decide it, say so in one line, keep going. "Should I continue?" is the anti-pattern.
from awask import DecisionCard, DecisionOption, get_store
card = get_store().create(DecisionCard(
title="Two schema designs, both defensible",
options=[
DecisionOption(key="a", label="Single table", consequence="faster reads, wide rows"),
DecisionOption(key="b", label="Join table", consequence="normalized, extra hop"),
],
recommend="b", default="b",
))
print(card.id)awask list/show/answer/cancel read the store on local disk directly, so a fresh
install works with nothing running. Reaching those cards from another device — a
phone, a browser, a dashboard — needs a small local HTTP daemon serving the same
store, bound to loopback and fronted by a private tunnel or an authenticated proxy.
Never publish that port: it serves the queue that steers an agent with filesystem
access.
Nothing starts that daemon for you, deliberately — registering a background service is a bigger ask than installing a CLI. The cost is worth naming: if it is not running, remote surfaces have no cards to show, and an empty list looks exactly like "nothing is waiting on you". A client that cannot reach it should say so.
awask.channels bridges cards to a Discord/Telegram/Slack direct message — your
bot, your token, bound to your user id. It is a DM bridge, not a channel bot, and
that is the entire security model: a card answer steers an agent with filesystem
access, so "who may answer" is an authorization decision. It fails closed at every
path — no config, no bound owner, a sender who is not the owner, or a message that
is not in a DM, all deny. A message in a public channel cannot answer a card even
when you typed it.
Apache 2.0.
Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.
Each installs on its own, works offline, and needs no account.
| instead of trusting | you check | |
|---|---|---|
| awdk | a framework's idea of how your agents should run | one loop you can read, pointed at a backend you already pay for |
| awskills | that an agent knows your procedure | the procedure written down, versioned, and loadable by any agent |
| awpack | that the pack you want shipped inside somebody's SDK, under whatever licence that SDK happens to carry | the pack as its own versioned artifact, with its own licence, that any agent runtime can install |
| awm | that memory stayed in its lane | tenant:user:project scopes, so a write cannot cross a boundary |
| awdesk | that the agent is somewhere behind a browser tab | a tray icon, a face on your desktop, and the decision card that pops when it needs you |
| awnode | a vendor's cloud with every prompt | a local gateway routing to backends you chose |
| awgraph | that grep found everything | an AST + tree-sitter call graph an agent can traverse |
| awgit | that no one else is editing this file | a lease, refused at commit time if you do not hold it |
| awdelphi | one agent's confident take on a decision | the round trace, the anonymity, and who dissents |
| awtoll | that your tooling is saving you context | the measured token cost of each tool call, and what the alternative cost |
| awseal | that the artifact came from who you think | an Ed25519 seal — the key that verifies is not the key that forges |
| awshare | that the download is intact | content-addressed bundles, verified on fetch |
| awnest | that there is a person on the other end | a verdict with evidence, where "we could not tell" is not "yes" |
| awrena | a leaderboard someone can edit, and votes nobody counted | a scored duel with both answers kept, and a result bound to them |
| awnboard | a share link anyone who sees it can use | an invitation addressed to one person, for one gate, revocable |
| awnix | that the box is what you left it as | an immutable image you built, with atomic rollback |
| awrecover | that the restore worked | a restore that fully lands or does not land at all |
| awstorage | a du you ran last month, and a peers file that says 3 TB free | an inventory snapshot per node with a diff since the last one, and each tree classified re-fetchable or not |
| awrelay | a SaaS in the middle of your agents | findings, alerts and coordination over your own transport |
| awask (you are here) | that anyone read the paragraph where you asked | the ask itself, with a button that steers the session that raised it |
| awmail | a mailbox somebody else can read | mail your agents send and receive over your own server |
| awfind | one vendor's idea of the web | results from whichever providers you configured |
| awbrowse | that the page said what you were told | the render, the DOM and the requests it made |
| awvoice | that a cloud vendor may hold your audio | a transcript and a wav from a service you host |
| awvision | a filename and a caption somebody wrote | what a model actually reports about the pixels |
| awscreen | a selector that was true when the page was written | the elements actually rendered, by what they look like |
| gawbbonet | the model to keep a 300-message campaign coherent by itself | campaign facts recalled from scoped memory you can list and edit |
| aitherkvcache | a vendor's quantisation defaults | sub-byte KV cache kernels you can benchmark yourself |
| awrtifact | a hand-rolled split script and a hand-edited worker manifest | byte-verified parts in a release, served with Range + CORS, sizes asserted by a live gate |
| AitherZero | a pile of scripts nobody has numbered | numbered, discoverable automation with declarative playbooks |
| AitherConnect | what a page tells your browser to do | a federated search and desktop bridge you host |
| awreason | a confident paragraph | the phases it went through, and every tool call it made to get there |
| awrecurse | that everything you pasted in was actually read | which slices it opened, and what it concluded from each |
| awprism | the first explanation that fits | the ranked alternatives, and the observation that separates them |
| awrepl | what the agent believes the value is | the value, printed from the live session |
| awresearch | a summary of pages nobody opened | every claim against the source it came from |
| awfocus | twelve terminal tabs and a bad memory | one command that names every session, finds any transcript, and opens or steers the one you want |
| awgym | that a world model learned anything from the games it saw | transitions captured from real play, fed back, and the retrodiction score falling on grids it never saw |
| awpredict | a model because it trained without erroring | its prediction against a self-updating lookup, on the rows that are actually novel |
| awsh | that you already know the name of the command | what it decided your line meant, before it acts on it |
| awrise | that a scheduled agent ran at all, and ran exactly once | a durable record of every wake -- fired, skipped, overlapped or timed out -- each with its reason |
| awkno | that the docs site is up, or that you remember the family | the whole ecosystem in your terminal, with no network at all |
| awwall | that a service only talks to the hosts you think it talks to | an explicit egress allowlist, where a denial names the rule that denied it |
| awembed | a general-purpose embedder that has never seen your code | a held-out split of whole directories, scored teacher vs student vs int8 |
| awtax | a closed tax app's sealed file you can never read again | a plain, provider-neutral schema of every figure, with the page it came from |
| awsettings | that you will remember to re-approve the same thing on every box you work from | one profile, unioned rather than overwritten, with the credentials left behind |
| awavatar | a cloud 3D vendor's opaque task id | a manifest with a sha256, a licence and a rig-audit verdict per file |
awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.
Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.
| repo | what it is | pages |
|---|---|---|
| awdk | Build AI agent fleets — 3 lines, any backend, local or cloud | docs |
| awskills | Portable agent skills — self-contained procedures an agent loads on demand | docs |
| awpack | First-party agent packs — the ones we build, versioned and installable on their own | docs |
| awm | A portable, scoped agent memory | docs |
| awdesk | Aither World Desk -- the desktop body of AitherOS Online: tray, avatars, decision cards, the Living Desktop as an overlay | docs |
| awnode | A lightweight local gateway — bridges your apps to the AI backends you chose | docs |
| awrun | A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds. It also judges whether the runner pool is big enough for the queue it is draining, and can ask a host to grow it -- reserving capacity is zero-sum, so a saturated pool needs more of it, not a different share of it | docs |
| awgraph | A semantic code graph for agents — AST + tree-sitter, call graphs | docs |
| awgit | Semantic version control on top of git — edit-ops and leases | docs |
| awdelphi | Anonymous multi-round expert panels — a converged answer with a trace | docs |
| awtoll | What every tool call costs you in context, measured from your own transcripts | docs |
| awseal | Sign an artifact so a stranger can verify it | docs |
| awshare | Publish an artifact and fetch it back verified | docs |
| awdit | An append-only audit trail whose gaps are DETECTABLE | docs |
| awbac | Role-based access control that fails closed and explains itself | docs |
| awiam | Who is this caller? A directory and session store that fails honestly | docs |
| awtunnel | Reach a service that has no public address | docs |
| awnest | Prove there is a human before you let them into the nest | docs |
| awrena | Put two agents head to head and get a verdict you can check | docs |
| awnboard | A front gate you can put in front of anything, and hand someone the key to | docs |
| awnix | A Linux you can hand to an agent — immutable base, capabilities included | docs |
| awrecover | Labelled snapshots with an all-or-nothing restore | docs |
| awstorage | Every drive on every node, indexed, classified and diffed -- so you can see what you own before you delete it | docs |
| awrelay | Portable agent messaging — findings, alerts, coordination | docs |
| awask (you are here) | Your agent asks you a question — and acts on your answer | docs |
| awmail | Give an agent an email address — send, and actually receive | docs |
| awnet | The agentic web — agents host a mesh, and agents join one | docs |
| awfind | A portable search client — query, results, ranking | docs |
| awbrowse | A portable browser client — navigate, console, network, DOM, screenshot | docs |
| awvoice | Hear and speak — transcribe audio, synthesize a voice | docs |
| awvision | See an image — describe it, ask it a question, compare two | docs |
| awscreen | See this machine — what is on screen, and where to click it | docs |
| awknowledge | How to run a coding agent so the result survives — the laws, with evidence | docs |
| gawbbonet | GobboNet campaigns with a real agent brain — scoped memory, graph recall | docs |
| aitherkvcache | Near-optimal KV cache quantization for LLM inference — sub-byte compression | docs |
| awrtifact | Deliberately chunk artifacts into GitHub release assets — the productized aitherkvcache mirror lane | docs |
| AitherZero | PowerShell 7+ automation framework — numbered, self-describing scripts | docs |
| AitherConnect | Browser extension — federated AI search, page context, and the Living OS overlay | docs |
| awreason | A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer | docs |
| awrecurse | Answer a question over a context far larger than the window — recursively, with the trace kept | docs |
| awprism | Turn a failure into ranked hypotheses — and say what would confirm each one | docs |
| awrepl | A REPL an agent can actually use — state that survives between turns | docs |
| awresearch | Ask a research question, get a cited report you can check | docs |
| awfocus | See, search and steer every Claude session from one command | docs |
| awgym | An ARC training gym — a game a world model can watch, and six roles that play through it | docs |
| awpredict | Predict what your environment does next, and how surprised you were | docs |
| awsh | Your terminal answers you -- type a question where a command would go | docs |
| awrise | Wake an agent on a schedule, let it do one thing, and put it back to sleep | docs |
| awkno | The man page for the Aither World — every brick, stack and law, offline | docs |
| awwall | Say what a workload may reach, and watch everything else fail closed | docs |
| awembed | Train an embedding model that knows your corpus, and prove it beats the big one | docs |
| awtax | Turn any tax PDF -- returns, W-2, 1099, statements, even scans -- into structured data you can check | docs |
| awflow | A deterministic workflow runtime — chain agent calls with journal replay and budget control | docs |
| awsettings | Your agent's permissions and config, following you to the next machine | docs |
| awavatar | One character spec in, a rigged, animated, multi-style avatar pack out | docs |