curator

module
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 12, 2026 License: Apache-2.0

README

Curator

Curator is an agent environment manager (AEM): a single tool that manages what an AI coding agent gets in a project. Skills and their transitive dependencies, executable commands, MCP server requirements, per-agent delivery, and the security gates around all of it. Declarative, reproducible, verifiable.

Curator is implemented in Go and follows a published protocol specification for skill packages, project manifests, installation semantics, and the audit registry, so environments it manages interoperate with other conforming tools. The specification lives in the Relux Works organization; sections are cited across this repository as Spec §N.M.

Status

v0.1 development complete: all twelve phases of docs/implementation-plan.md are done, including the interoperability golden gate (byte-equality against fixtures produced by an independent conforming implementation). CI runs tests on ubuntu, macos, and windows plus lint, a naming gate, and the interop gate. Work is tracked on the in-repo task board under .task-board/.

Install

# Homebrew (macOS, Linux)
brew install relux-works/tap/curator

# installer script (macOS, Linux)
curl -fsSL https://raw.githubusercontent.com/relux-works/curator/main/install.sh | sh

# Scoop (Windows)
scoop bucket add relux-works https://github.com/relux-works/scoop-bucket
scoop install curator

# Go toolchain
go install github.com/relux-works/curator/cmd/curator@latest

Debian and RPM packages ship with every release, together with SBOMs and cosign signatures. macOS binaries are Developer ID signed (Relux Works, LLC). Verify any downloaded artifact:

gh attestation verify <artifact> --owner relux-works

What Curator manages

  • Skill packages: SKILL.md plus context directories, with a machine manifest (csk-skill.json, schemas 1 through 5) declaring commands, runtime layout, capabilities, and dependencies.
  • Project manifests: Skillfile.json with exact git references; non-committed development substitutions.
  • Resolution: transitive dependency closures unified to one commit and one source identity per name, with activation modes.
  • Installation: context and runtime separation, install markers with content hashes, a commit-keyed runtime store, command shims, managed per-agent adapters.
  • Scopes: project, global, and hybrid (machine-stored, per-project activation).
  • MCP requirements: read-only verification of declared MCP servers against agent configuration surfaces.
  • Security: source allowlists, declared capabilities, no code execution at install time, and an audit registry client (Ed25519 signed records, deny-wins federation, snapshot verification).

Development

The repository uses an in-repo task board (.task-board/, epics, stories, and tasks as files) and the agent tooling connected under agents/. Go testing follows the closed-loop tooling of skill-go-testing-tools (including tuitestkit for terminal UI phases).

Contributing

See CONTRIBUTING.md for the working agreements: board-first workflow, discrete signed commits, spec-first rule.

License

Apache License 2.0. See LICENSE and NOTICE.

Directories

Path Synopsis
cmd
curator command
Command curator is the agent environment manager CLI (Spec §15).
Command curator is the agent environment manager CLI (Spec §15).
internal
adapters
Package adapters mirrors installed context into the directories each agent reads, with a managed-entries ledger per adapter root (Spec §10).
Package adapters mirrors installed context into the directories each agent reads, with a managed-entries ledger per adapter root (Spec §10).
audit
Package audit implements the machine-local audit gate (Spec §12): the decision semantics, local revocations, operator pins, a blocking canary, a small deterministic detector set, and a verdict cache.
Package audit implements the machine-local audit gate (Spec §12): the decision semantics, local revocations, operator pins, a blocking canary, a small deterministic detector set, and a verdict cache.
capabilities
Package capabilities parses the capability declaration of Spec §5.5.
Package capabilities parses the capability declaration of Spec §5.5.
closure
Package closure resolves the transitive dependency closure of a project manifest (Spec §8.3, §8.4).
Package closure resolves the transitive dependency closure of a project manifest (Spec §8.3, §8.4).
config
Package config loads the machine configuration (Spec §7.1) and applies the enforced system configuration with locked keys (Spec §7.2).
Package config loads the machine configuration (Spec §7.1) and applies the enforced system configuration with locked keys (Spec §7.2).
devsub
Package devsub parses Skillfile.dev.json, the non-committed development substitution manifest (Spec §6.2).
Package devsub parses Skillfile.dev.json, the non-committed development substitution manifest (Spec §6.2).
envfiles
Package envfiles generates the PATH helper files of a project or the global scope (Spec §14.2).
Package envfiles generates the PATH helper files of a project or the global scope (Spec §14.2).
gitignore
Package gitignore enforces the managed .gitignore block (Spec §6.3).
Package gitignore enforces the managed .gitignore block (Spec §6.3).
gitops
Package gitops shells out to system git for clone, fetch, ref resolution, and snapshot extraction (Spec §8.2).
Package gitops shells out to system git for clone, fetch, ref resolution, and snapshot extraction (Spec §8.2).
hashing
Package hashing computes the deterministic content hash of an installed tree (Spec §8.5).
Package hashing computes the deterministic content hash of an installed tree (Spec §8.5).
identifiers
Package identifiers validates the identifier alphabet of Spec §5.2 and the source path rule of Spec §6.1.
Package identifiers validates the identifier alphabet of Spec §5.2 and the source path rule of Spec §6.1.
identity
Package identity computes the canonical source identity of git artifacts and matches identities against the machine allowlist (Spec §8.2).
Package identity computes the canonical source identity of git artifacts and matches identities against the machine allowlist (Spec §8.2).
install
Package install orchestrates a project installation in the normative phase order of Spec §8.1.
Package install orchestrates a project installation in the normative phase order of Spec §8.1.
locale
Package locale analyzes and renders skill localization (Spec §4.3).
Package locale analyzes and renders skill localization (Spec §4.3).
manifest
Package manifest parses the project manifest Skillfile.json, schema 1 (Spec §6.1), and edits skill declarations in place.
Package manifest parses the project manifest Skillfile.json, schema 1 (Spec §6.1), and edits skill declarations in place.
marker
Package marker reads and writes install markers (.csk-install.json) and implements the up-to-date and tamper-detection semantics of Spec §8.5.
Package marker reads and writes install markers (.csk-install.json) and implements the up-to-date and tamper-detection semantics of Spec §8.5.
mcp
Package mcp verifies declared MCP server requirements against the configuration surfaces of the target agent environments (Spec §11).
Package mcp verifies declared MCP server requirements against the configuration surfaces of the target agent environments (Spec §11).
registry
Package registry implements the audit registry client (Spec §13): canonical bytes, Ed25519 verification against pinned keys, deny-wins federation, snapshot verification with persisted monotonic versions, record caching with TTL and offline grace, and record submission.
Package registry implements the audit registry client (Spec §13): canonical bytes, Ed25519 verification against pinned keys, deny-wins federation, snapshot verification with persisted monotonic versions, record caching with TTL and offline grace, and record submission.
runtimestore
Package runtimestore keeps command runtimes once per machine, keyed by skill and commit, and writes command shims (Spec §8.6).
Package runtimestore keeps command runtimes once per machine, keyed by skill and commit, and writes command shims (Spec §8.6).
scopes
Package scopes implements the global and hybrid install scopes, the consumer registry, and runtime garbage collection (Spec §8.7, §9).
Package scopes implements the global and hybrid install scopes, the consumer registry, and runtime garbage collection (Spec §8.7, §9).
shell
Package shell prints the shell hooks of Spec §14.1: upward search for the project env file with PATH save and restore, plus optional global env sourcing.
Package shell prints the shell hooks of Spec §14.1: upward search for the project env file with PATH save and restore, plus optional global env sourcing.
skillcheck
Package skillcheck validates one skill package without a consuming project (Spec §15, curator skill check).
Package skillcheck validates one skill package without a consuming project (Spec §15, curator skill check).
skillspec
Package skillspec parses and validates the skill machine manifest csk-skill.json, schemas 1 through 5 (Spec §5), including the legacy agents/runtime.json fallback (Spec §5.10).
Package skillspec parses and validates the skill machine manifest csk-skill.json, schemas 1 through 5 (Spec §5), including the legacy agents/runtime.json fallback (Spec §5.10).
snapshot
Package snapshot maintains the commit-keyed immutable snapshot cache under the machine home: cache/<source>/<commit>/snapshot (Spec §8.2).
Package snapshot maintains the commit-keyed immutable snapshot cache under the machine home: cache/<source>/<commit>/snapshot (Spec §8.2).
ui
Package ui renders installed state as a terminal view (plan P11).
Package ui renders installed state as a terminal view (plan P11).
verr
Package verr defines the validation error type shared by protocol parsers.
Package verr defines the validation error type shared by protocol parsers.
version
Package version resolves the Curator build version.
Package version resolves the Curator build version.
whitelist
Package whitelist copies the model-facing context of a skill snapshot (Spec §4.2).
Package whitelist copies the model-facing context of a skill snapshot (Spec §4.2).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL