Skip to content

Repository files navigation

awrepl

Docs · Source · pip install awrepl · The Aither World

The Aither World is an operating system for agents — a Linux you can hand to one, the runtimes it works in, and the tools it works with. awnix is the Linux underneath it; awrepl is one of its 55 bricks — each installs on its own, runs offline, and needs no account.

Start here: Give an agent a live session it can keep poking at, so the next question is asked of the object instead of of its own memory.

A REPL an agent can actually use — state that survives between turns.

pip install awrepl
from awrepl import ReplSession

session = ReplSession("agent-1")
result = session.execute("items = [1, 2, 3]")
result = session.execute("print(len(items))")
print(result.stdout)  # "3"
session.close()
awrepl run "print('hello')"
awrepl serve                    # Interactive session
awrepl --session myagent run "x = 42"
awrepl --self-test              # Verify the contract

The problem it exists for

An agent given one-shot shell commands rebuilds its whole world on every call, so it guesses instead of looks. Every variable it wanted is gone the moment the command exits. This REPL keeps state.

You ask the live object, not the agent's memory.

# Turn 1
session.execute("data = load_file('config.json')")

# Turn 2 (later, different agent instance)
session.execute("print(data['server'])")  # data is STILL there

⚠️ This is NOT a sandbox

Critical: awrepl executes arbitrary code with the privileges of the process that started it.

It does not protect against:

  • Filesystem access — code can read/write/delete files
  • Network access — code can make HTTP requests, connect to services
  • Subprocess execution — code can launch processes and scripts
  • Resource exhaustion — timeouts can be circumvented (see below)
  • Memory/disk consumption — unbounded allocations are possible

Real isolation requires a container (Docker/Podman) or VM. awrepl is a session manager, not a sandbox. Shipping something that looks like a sandbox and is not would be actively dangerous — so this is stated plainly.

Use awrepl only:

  • In trusted environments (your own machine, internal tools)
  • When running code you wrote or thoroughly reviewed
  • Behind proper auth and network boundaries if exposed as a service
  • With resource limits imposed at the OS/container level if needed

If you need to run untrusted code, use a container or virtual machine. Do not rely on awrepl alone.


API

ReplSession

A persistent Python interpreter backed by a subprocess worker.

from awrepl import ReplSession, ExecResult

session = ReplSession(
    session_id="my-session",
    timeout_ms=30000,           # per-call timeout
    max_output_bytes=65536,     # output cap before truncation
)

# Execute code
result: ExecResult = session.execute("x = [1, 2, 3]")

ExecResult fields:

  • stdout (str): Captured stdout
  • stderr (str): Captured stderr
  • value (str|None): repr() of the last expression, if any
  • exception (str|None): Error message if execution failed
  • traceback (str): Full traceback on exception
  • duration_ms (float): Wall-clock time for execution
  • truncated (bool): Output was truncated due to size limit
  • truncated_bytes (int): How many bytes were dropped

Methods:

# Execute code in the persistent namespace
result = session.execute("code", timeout_ms=30000)

# Get all bound variables (type and short repr)
variables: dict[str, str] = session.variables()
# {"x": "list: [1, 2, 3]", "name": "str: 'Alice'"}

# Inspect a single variable (type, repr, docstring, etc.)
info: dict = session.inspect("x")
# {"type": "list", "repr": "[1, 2, 3]", "dir": [...], "len": 3}

# Clear all user-defined variables (keeps builtins)
session.reset()

# Close the session and terminate the worker
session.close()

# Use as a context manager
with ReplSession("temp") as s:
    s.execute("x = 42")

SessionPool

Manage multiple REPL sessions indexed by ID.

from awrepl import SessionPool

pool = SessionPool(timeout_ms=30000, max_output_bytes=65536)

# Create a session (auto-generate ID)
sid1 = pool.create_session()

# Create a session with a custom ID
sid2 = pool.create_session("agent-2")

# Get a session
session = pool.get_session(sid2)
session.execute("x = 42")

# List all session IDs
sessions = pool.list_sessions()

# Delete a session
pool.delete_session(sid1)

# Close all sessions
pool.close_all()

Each session has its own namespace — one agent's variables don't affect another.


CLI

# Execute code once (ephemeral session)
awrepl run "print(1 + 2)"

# Use a persistent session across multiple calls
awrepl --session myagent run "x = 42"
awrepl --session myagent run "print(x)"  # Prints 42

# Output as JSON
awrepl run "42" --json
# {"stdout": "", "stderr": "", "value": "42", "exception": null, ...}

# Interactive REPL (basic, stdin-based)
awrepl serve

# Session-based interactive REPL
awrepl --session agent serve

# Verify the REPL contract (no network required)
awrepl --self-test

Options:

  • --session ID — Use a specific session (creates if needed)
  • --json — Output result as JSON
  • --traceback — Show full traceback on exception

How it works

awrepl runs a Python subprocess (python -i-style worker) and communicates via JSON over pipes. The worker:

  • Maintains a single persistent namespace
  • Executes code and captures stdout/stderr
  • Handles timeouts and output truncation
  • Survives syntax errors and exceptions

Multiple ReplSession instances can run in parallel, each with its own worker subprocess, enabling concurrent agents to maintain separate state.

Why subprocess, not in-process exec()?

  • In-process execution lets agent code crash or corrupt the host process
  • Subprocess isolation means a fatal error in agent code doesn't kill the agent
  • Each session gets its own Python interpreter with its own memory space
  • Timeouts are more reliable (can interrupt the subprocess)

Platform support: Linux, macOS, Windows (tested on all three). Uses only Python standard library — no external dependencies.


--self-test

Every install can prove the contract, with no service and no network:

$ awrepl --self-test
  PASS  Variables persist across calls
  PASS  Syntax error doesn't kill session
  PASS  Exception doesn't kill session
  PASS  Output truncation works
  PASS  variables() lists bound names
  PASS  Pool sessions are isolated

SELF-TEST: awrepl ok (6/6)

The test asserts:

  1. Variables defined in one call are readable in another (the whole point)
  2. A syntax error doesn't terminate the session
  3. An exception is reported, but the session survives
  4. Output longer than max_output_bytes is truncated with a flag
  5. variables() lists bound names correctly
  6. Sessions in a pool don't see each other's variables

The bug this package exists to prevent

An agent with access to a live object can look at it instead of guessing about it from memory.

Without awrepl:

# Agent's turn 1: I ran this, but I don't remember the result
code = "data = load_json('config.json')"
result = subprocess.run(["python", "-c", code])
# Stdout gone, no access to `data`

# Agent's turn 2: Guess based on memory (but agent memory is compressed/forgotten)
# "What was in that file again? Let me re-run the whole thing..."

With awrepl:

# Agent's turn 1: Run code, data persists
session.execute("data = load_json('config.json')")

# Agent's turn 2: Look at it
vars = session.variables()  # {"data": "dict: {...}"}
info = session.inspect("data")  # {"type": "dict", "len": 5, "keys": [...]}

Cuts through the memory layer. What you ask is what you get.


Limitations and design choices

Timeouts: The timeout_ms parameter exists, but relies on the subprocess signal handler. Some heavy operations (deep recursion, infinite loops in C extensions) may not be interruptible. Use OS-level resource limits (cgroups, ulimit) for hard guarantees.

Namespace pollution: The namespace persists, so a large object assigned to x stays in memory until reset() or the session closes. Plan for that.

No remote execution: This is a local subprocess REPL. For distributed execution, wrap it in an HTTP service or use it alongside a message queue.


The aw family

Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.

Each installs on its own, works offline, and needs no account.

instead of trusting you check
awdk a framework's idea of how your agents should run one loop you can read, pointed at a backend you already pay for
awskills that an agent knows your procedure the procedure written down, versioned, and loadable by any agent
awpack that the pack you want shipped inside somebody's SDK, under whatever licence that SDK happens to carry the pack as its own versioned artifact, with its own licence, that any agent runtime can install
awm that memory stayed in its lane tenant:user:project scopes, so a write cannot cross a boundary
awdesk that the agent is somewhere behind a browser tab a tray icon, a face on your desktop, and the decision card that pops when it needs you
awnode a vendor's cloud with every prompt a local gateway routing to backends you chose
awgraph that grep found everything an AST + tree-sitter call graph an agent can traverse
awgit that no one else is editing this file a lease, refused at commit time if you do not hold it
awdelphi one agent's confident take on a decision the round trace, the anonymity, and who dissents
awtoll that your tooling is saving you context the measured token cost of each tool call, and what the alternative cost
awseal that the artifact came from who you think an Ed25519 seal — the key that verifies is not the key that forges
awshare that the download is intact content-addressed bundles, verified on fetch
awnest that there is a person on the other end a verdict with evidence, where "we could not tell" is not "yes"
awrena a leaderboard someone can edit, and votes nobody counted a scored duel with both answers kept, and a result bound to them
awnboard a share link anyone who sees it can use an invitation addressed to one person, for one gate, revocable
awnix that the box is what you left it as an immutable image you built, with atomic rollback
awrecover that the restore worked a restore that fully lands or does not land at all
awstorage a du you ran last month, and a peers file that says 3 TB free an inventory snapshot per node with a diff since the last one, and each tree classified re-fetchable or not
awrelay a SaaS in the middle of your agents findings, alerts and coordination over your own transport
awask that anyone read the paragraph where you asked the ask itself, with a button that steers the session that raised it
awmail a mailbox somebody else can read mail your agents send and receive over your own server
awfind one vendor's idea of the web results from whichever providers you configured
awbrowse that the page said what you were told the render, the DOM and the requests it made
awvoice that a cloud vendor may hold your audio a transcript and a wav from a service you host
awvision a filename and a caption somebody wrote what a model actually reports about the pixels
awscreen a selector that was true when the page was written the elements actually rendered, by what they look like
gawbbonet the model to keep a 300-message campaign coherent by itself campaign facts recalled from scoped memory you can list and edit
aitherkvcache a vendor's quantisation defaults sub-byte KV cache kernels you can benchmark yourself
awrtifact a hand-rolled split script and a hand-edited worker manifest byte-verified parts in a release, served with Range + CORS, sizes asserted by a live gate
AitherZero a pile of scripts nobody has numbered numbered, discoverable automation with declarative playbooks
AitherConnect what a page tells your browser to do a federated search and desktop bridge you host
awreason a confident paragraph the phases it went through, and every tool call it made to get there
awrecurse that everything you pasted in was actually read which slices it opened, and what it concluded from each
awprism the first explanation that fits the ranked alternatives, and the observation that separates them
awrepl (you are here) what the agent believes the value is the value, printed from the live session
awresearch a summary of pages nobody opened every claim against the source it came from
awfocus twelve terminal tabs and a bad memory one command that names every session, finds any transcript, and opens or steers the one you want
awgym that a world model learned anything from the games it saw transitions captured from real play, fed back, and the retrodiction score falling on grids it never saw
awpredict a model because it trained without erroring its prediction against a self-updating lookup, on the rows that are actually novel
awsh that you already know the name of the command what it decided your line meant, before it acts on it
awrise that a scheduled agent ran at all, and ran exactly once a durable record of every wake -- fired, skipped, overlapped or timed out -- each with its reason
awkno that the docs site is up, or that you remember the family the whole ecosystem in your terminal, with no network at all
awwall that a service only talks to the hosts you think it talks to an explicit egress allowlist, where a denial names the rule that denied it
awembed a general-purpose embedder that has never seen your code a held-out split of whole directories, scored teacher vs student vs int8
awtax a closed tax app's sealed file you can never read again a plain, provider-neutral schema of every figure, with the page it came from
awsettings that you will remember to re-approve the same thing on every box you work from one profile, unioned rather than overwritten, with the credentials left behind
awavatar a cloud 3D vendor's opaque task id a manifest with a sha256, a licence and a rig-audit verdict per file

awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.

The Aitherium ecosystem

Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.

repo what it is pages
awdk Build AI agent fleets — 3 lines, any backend, local or cloud docs
awskills Portable agent skills — self-contained procedures an agent loads on demand docs
awpack First-party agent packs — the ones we build, versioned and installable on their own docs
awm A portable, scoped agent memory docs
awdesk Aither World Desk -- the desktop body of AitherOS Online: tray, avatars, decision cards, the Living Desktop as an overlay docs
awnode A lightweight local gateway — bridges your apps to the AI backends you chose docs
awrun A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds. It also judges whether the runner pool is big enough for the queue it is draining, and can ask a host to grow it -- reserving capacity is zero-sum, so a saturated pool needs more of it, not a different share of it docs
awgraph A semantic code graph for agents — AST + tree-sitter, call graphs docs
awgit Semantic version control on top of git — edit-ops and leases docs
awdelphi Anonymous multi-round expert panels — a converged answer with a trace docs
awtoll What every tool call costs you in context, measured from your own transcripts docs
awseal Sign an artifact so a stranger can verify it docs
awshare Publish an artifact and fetch it back verified docs
awdit An append-only audit trail whose gaps are DETECTABLE docs
awbac Role-based access control that fails closed and explains itself docs
awiam Who is this caller? A directory and session store that fails honestly docs
awtunnel Reach a service that has no public address docs
awnest Prove there is a human before you let them into the nest docs
awrena Put two agents head to head and get a verdict you can check docs
awnboard A front gate you can put in front of anything, and hand someone the key to docs
awnix A Linux you can hand to an agent — immutable base, capabilities included docs
awrecover Labelled snapshots with an all-or-nothing restore docs
awstorage Every drive on every node, indexed, classified and diffed -- so you can see what you own before you delete it docs
awrelay Portable agent messaging — findings, alerts, coordination docs
awask Your agent asks you a question — and acts on your answer docs
awmail Give an agent an email address — send, and actually receive docs
awnet The agentic web — agents host a mesh, and agents join one docs
awfind A portable search client — query, results, ranking docs
awbrowse A portable browser client — navigate, console, network, DOM, screenshot docs
awvoice Hear and speak — transcribe audio, synthesize a voice docs
awvision See an image — describe it, ask it a question, compare two docs
awscreen See this machine — what is on screen, and where to click it docs
awknowledge How to run a coding agent so the result survives — the laws, with evidence docs
gawbbonet GobboNet campaigns with a real agent brain — scoped memory, graph recall docs
aitherkvcache Near-optimal KV cache quantization for LLM inference — sub-byte compression docs
awrtifact Deliberately chunk artifacts into GitHub release assets — the productized aitherkvcache mirror lane docs
AitherZero PowerShell 7+ automation framework — numbered, self-describing scripts docs
AitherConnect Browser extension — federated AI search, page context, and the Living OS overlay docs
awreason A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer docs
awrecurse Answer a question over a context far larger than the window — recursively, with the trace kept docs
awprism Turn a failure into ranked hypotheses — and say what would confirm each one docs
awrepl (you are here) A REPL an agent can actually use — state that survives between turns docs
awresearch Ask a research question, get a cited report you can check docs
awfocus See, search and steer every Claude session from one command docs
awgym An ARC training gym — a game a world model can watch, and six roles that play through it docs
awpredict Predict what your environment does next, and how surprised you were docs
awsh Your terminal answers you -- type a question where a command would go docs
awrise Wake an agent on a schedule, let it do one thing, and put it back to sleep docs
awkno The man page for the Aither World — every brick, stack and law, offline docs
awwall Say what a workload may reach, and watch everything else fail closed docs
awembed Train an embedding model that knows your corpus, and prove it beats the big one docs
awtax Turn any tax PDF -- returns, W-2, 1099, statements, even scans -- into structured data you can check docs
awflow A deterministic workflow runtime — chain agent calls with journal replay and budget control docs
awsettings Your agent's permissions and config, following you to the next machine docs
awavatar One character spec in, a rigged, animated, multi-style avatar pack out docs
<script src="aither-constellation.js"></script>

About

A REPL an agent can actually use — state that survives between turns.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages