v0.5.0 is out: downloads open, and an honest list of what it does not do yet
2026-09-28 — the first downloadable 20131 build line is published: tag v0.5.0 on the public repository, 11 release assets, each externally verified at publish time (anonymous GET 200 plus SHA-256 cross-check against the release checksums). This post is a changelog: what is in these binaries, and what is deliberately not.
What ships in v0.5.0
- Agent discovery — fingerprint families for major coding agents and MCP servers across three platforms: /proc on Linux, a ps snapshot view on macOS, Toolhelp32 snapshots plus PEB command lines on Windows. Ancestor-chain attribution, honest scan coverage counters, and a known-gaps declaration written into every run
- A strict event model — a versioned line format with per-field validation; malformed events are rejected before they can touch the log, with zero bytes written
- Policy evaluation — a deterministic evaluator (priority order, first match wins, default effect, zero event mutation) plus a rule engine v0 with twelve built-in rules covering the credential-reading, mass-deletion, privilege-path and remote-pipe-execution shapes from the published threat model
- Local audit — append-only JSONL, owner-only permissions, size and daily rotation, and a privacy redaction layer that every OS-sourced string passes before it is logged (credentials, key-value secrets, key-file paths)
- A read-only control surface — status, audit-tail, and timeline subcommands; the collector itself performs no network I/O at all (dependency closure is machine-checked in CI)
- A frozen 40-case evaluation set — 90% detection on the danger class, zero false positives on the benign class, zero credential leaks, one interruption against the watch-only baseline; reproducible via the in-repo gate scripts
What this build deliberately does not do
- It does not block. Phase 0 means observe, evaluate, audit: a high-risk action is recorded with a would_block verdict and then still proceeds. Enforcement ships per roadmap phase — no dates promised here
- It is unsigned. No paid developer ID, no notarization, so SmartScreen and Gatekeeper will prompt on first launch; the accepted paths through those prompts (and the cases where platform policy can block outright with no workaround) are documented on the download and install pages
- The macOS Intel row has not been run on real Intel hardware yet — it ships CI-signed and stays marked pending verification
- Observation has stated gaps: protected processes can hide command lines, and a process that launches between scans is caught on the next pass, not the previous one
How to get it
- Downloads page: the full ten-build matrix (agent-collector and hello-collector for Windows, Apple Silicon, Intel, Linux x86_64 and arm64) with per-file SHA-256 and first-run guidance
- Install script: one plain-text file that probes your platform, fetches exactly one release asset over HTTPS, verifies it against the release SHA256SUMS before unpacking anything, refuses loudly on a mismatch, and never asks for root, never installs a service, never pipes remote code into a shell
- Source, release notes, and issues: github.com/411160007/20131-agentruntime, tag v0.5.0
Landed after the tag
One more thing is true but is not in these bytes: the hook- and MCP-proxy observation adapters merged to main shortly after v0.5.0 was cut. They are not part of this release and will ship in a later build, announced here first — the same discipline as everything else on this blog: the changelog follows the code, not the other way around.