Download v0.5.0 (Early Access)
The first Early Access build line is out: v0.5.0, shipped on GitHub Releases, with all 11 release assets externally verified at publish time (anonymous GET 200 + SHA-256 cross-check). What this build is: a local, zero-telemetry security monitor — it discovers agents, records what they do into a local JSONL audit log, and evaluates actions against policy. What it is not yet: a blocker. Phase 0 records a would_block verdict instead of stopping the action; enforcement ships per roadmap phase.
All builds (v0.5.0)
| Build | Platform | Package | SHA-256 |
|---|---|---|---|
| agent-collector | Windows 10/11 (x64) | agent-collector-0.5.0-windows-amd64.exe.zip | ac4c353dea95c7d1fc68d1b9957ff6f0e0a82a8d919c44ca2cbaa2064afee3fd |
| agent-collector | macOS (Apple Silicon) | agent-collector-0.5.0-darwin-arm64.tar.gz | b6ef05f1c81c43805dfe88e30f898d2a4da4e4f267d77ec9c8f9772e57ccfba2 |
| agent-collector | macOS (Intel) — real-hardware verification pending | agent-collector-0.5.0-darwin-amd64.tar.gz | 31810e4296c94922e9a1cbd3415741d6d34597722081c75110d5b71968213913 |
| agent-collector | Linux (x86_64) | agent-collector-0.5.0-linux-amd64.tar.gz | e67bb367d0e6f9201fe1473d6ace0b8d9cd0601c9cf019562cef21174ac361db |
| agent-collector | Linux (arm64) | agent-collector-0.5.0-linux-arm64.tar.gz | ee7857cdde1b84e532edfee4f0ff69c440b10a2b5b2146ac7fa1e5cccb05f44f |
| hello-collector | Windows 10/11 (x64) | hello-collector-0.5.0-windows-amd64.exe.zip | c26b8ae62c09882f509f2bc200c23862f5dc97d5cd3c6add49825001795b46c4 |
| hello-collector | macOS (Apple Silicon) | hello-collector-0.5.0-darwin-arm64.tar.gz | 69d757fa3fb535e95a625c57b1315fa2203751c87126ad4b7878d21869c6b382 |
| hello-collector | macOS (Intel) — real-hardware verification pending | hello-collector-0.5.0-darwin-amd64.tar.gz | 993208872e29e09cfbdb1cb9dd2630d9e09b3b3b052ea7b46b422c477af628b9 |
| hello-collector | Linux (x86_64) | hello-collector-0.5.0-linux-amd64.tar.gz | 970ae6c34588ce19ccd80a4929f1ea35d27686079066e472081baf515dec5ffe |
| hello-collector | Linux (arm64) | hello-collector-0.5.0-linux-arm64.tar.gz | 2239444b3c0142eec3b9f78f64549bb0088e7df1cd1e78c96579e5eb35d9addb |
| all builds | any | SHA256SUMS.txt | lists the 10 hashes above, one per line |
agent-collector is the discovery collector with a read-only control surface (status / audit-tail / timeline). hello-collector is the minimal single-binary skeleton that demonstrates the same policy-evaluation pipeline. Both ship at the same version, on the same release rhythm, for every platform in the matrix.
Windows
- Unzip and run agent-collector-0.5.0-windows-amd64.exe — no installer, and user-mode observation needs no admin rights
- SmartScreen will likely appear on first launch: click "More info", then "Run anyway"
- Why the prompt exists at all: Early Access builds are unsigned. Microsoft changed the rules in 2024 — paid EV certificates no longer buy an instant SmartScreen pass either, so buying signing today would not remove the prompt
- The honest limits: a Windows 11 install with Smart App Control enabled blocks unsigned software outright, managed enterprise policy may block it entirely, and download reputation can reset with every release. For those cases there is no workaround we could give you even if we wanted to — the call belongs to your platform, by design
macOS
- Pick Apple Silicon (M-series) or Intel above; both carry an ad-hoc code signature, machine-checked at build time
- First launch will be blocked by Gatekeeper, because we ship no paid Developer ID and no notarization. The supported path: run the binary once, then open System Settings → Privacy & Security → the blocked item → "Open Anyway" → confirm. The exception persists after that
- Terminal alternative (a community-reported path, not an official Apple one — verify it against your current macOS version): xattr -d com.apple.quarantine <file>, then run
- Intel note: darwin/amd64 builds are signed through our CI, but we have not run them on real Intel hardware yet. That row stays marked "pending verification" until there is a field report we can honestly cite
Linux
- A single static binary, amd64 or arm64: extract the .tar.gz and run — no dependencies, zero-privilege procfs monitoring
- Verify before running: download SHA256SUMS.txt alongside the archive and check it
Verify what you downloaded
An ad-hoc signature proves the bytes were not modified after signing — it vouches for nothing about the publisher. That is exactly why the hashes matter. Check yours against the table above (which mirrors the release file) before executing anything:
sha256sum -c SHA256SUMS.txt # Linux shasum -a 256 -c SHA256SUMS.txt # macOS certutil -hashfile <file> SHA256 # Windows — compare with the table tar -tzf <asset>.tar.gz # expect: binary + LICENSE + NOTICE + CHECKSUM.txt sha256sum -c CHECKSUM.txt # inside each extracted archive, second layer
Stated plainly
- Early Access: all plans are free during the Early Access period. Pricing text on this site is served from one remote config; no card and no account is involved anywhere in this build
- Files are hosted on GitHub Releases. This page applies no regional restrictions; the direct GitHub access experience from mainland China networks is something we have not measured ourselves, so reachability there may vary — with the hashes on this page in hand, a build obtained through any route can still be verified
- The audit log is written locally, owner-only permissions, and the binary performs no network I/O at all
- Per-platform capability and current gaps are documented honestly on the Supported OS and Supported Agents pages — worth reading before interpreting any alert the monitor raises
Source code, release notes, and issues: github.com/411160007/20131-agentruntime (tag v0.5.0).