Install 20131 v0.5.0 (Early Access)
Everything here follows the honesty rules of the downloads page: this build line is a Phase 0 monitor — it observes, evaluates, and records; a would_block verdict is logged, not enforced — and the binaries are unsigned by choice of budget, not accident. If you are deciding whether to run it, read the limits first.
Verify before you run (all platforms)
- The downloads page lists a SHA-256 for every file, mirrored in the release SHA256SUMS.txt
- Check yours after download: sha256sum -c SHA256SUMS.txt on Linux, shasum -a 256 -c SHA256SUMS.txt on macOS, certutil -hashfile <file> SHA256 on Windows compared against the table
- An ad-hoc signature proves the bytes were not modified after signing — it says nothing about the publisher. The hashes are what tie your file to this page
Linux (x86_64 or arm64)
- Download the .tar.gz for your architecture from the downloads page and extract it — the archive holds the binary, LICENSE, NOTICE, and a CHECKSUM.txt covering its own contents
- Run it: agent-collector-0.5.0-linux-<arch> --once --out agent-audit.jsonl does one discovery pass and writes a local audit log; --interval 30s keeps watching
- No dependencies, no root: a single static binary reading procfs in user mode. Uninstalling is deleting the file and its log — nothing else was written to your system
macOS (Apple Silicon or Intel)
- Pick the arm64 or amd64 row on the downloads page. Both carry an ad-hoc code signature that is machine-checked at build time; neither has a paid Developer ID or notarization
- First launch will be blocked by Gatekeeper. The supported path: run the binary once, then open System Settings → Privacy & Security → the blocked item → "Open Anyway" → confirm. The exception persists after that
- A community-reported Terminal route exists (xattr -d com.apple.quarantine on the file, then run) — it is not an official Apple path and we have not verified it on current macOS, so we mark it as unverified rather than recommend it
- Intel note: the darwin/amd64 row is CI-signed but has not been run on real Intel hardware yet — it stays marked pending verification until there is a field report to cite
Windows 10/11 (x64)
- Unzip the .exe.zip from the downloads page and run the .exe — there is no installer, and user-mode observation needs no admin rights
- SmartScreen will likely appear: click "More info", then "Run anyway"
- Why the prompt exists: Early Access builds are unsigned, and since Microsoft's 2024 rule change even a paid EV certificate no longer buys an instant pass — buying signing today would not remove the prompt
- The honest limits: a Windows 11 install with Smart App Control enabled blocks unsigned software outright, and managed enterprise policy may block it entirely. There is no workaround we could give you even if we wanted to — the call belongs to your platform, by design. With the published hashes you can verify a build obtained through any route
The one-script route (macOS and Linux)
install.sh does the download-and-verify dance for you, with the safety properties stated up front: it fetches exactly one release asset over HTTPS, verifies it against the release checksums before unpacking anything, refuses on a mismatch, never uses root, never installs services or scheduled tasks, and never pipes remote code into a shell. It is a plain-text file — reading it first is encouraged.
curl -fsSL https://20131.com/install -o install.sh bash install.sh # agent-collector into ./20131-install bash install.sh hello-collector # the minimal skeleton binary instead DRYRUN=1 bash install.sh # print the chosen URL, download nothing
On Windows the script stops by design and prints the zip link plus the SmartScreen path instead of trying to be clever.
After installing
- The audit log is written locally, owner-only readable, and the collector binary performs zero network I/O — what it sees never leaves the machine
- Timeline and tail views: agent-collector audit-tail and agent-collector timeline render the log in the terminal
- Capability and gap tables per platform and per agent are on the Supported OS and Supported Agents pages — worth reading before interpreting what the monitor records
- Full build matrix and checksums: the downloads page — https://20131.com/en/download/