# AgentOS > Open-source TypeScript agent framework from Framers Lab, installed from npm as @framers/agentos. It runs agents with long-term memory, multi-agent teams, graph workflows with checkpoints, guardrails and approval gates across 11 model providers. - Canonical: https://www.anchorterminal.com/tools/agentos - Markdown: https://www.anchorterminal.com/tools/agentos.md (~6,100 tokens) - Slim: https://www.anchorterminal.com/tools/agentos.min.md (~1,380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/agentos.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade BB · 75.3/100 · rank #46 of 629 · #5 in Agent frameworks & SDKs · agent-ready · confidence medium** ## Assessment A TypeScript agent framework with typed tools, six multi-agent strategies, checkpointed graphs, approval gates and no telemetry of its own. It is at 0.12.12 after 98 releases in 90 days, two of them breaking on 7 October 2026. No MCP client was found in the package, and code tools an agent writes run in an in-process node:vm context. ## Facts | Field | Value | | --- | --- | | Vendor | Framers Lab, Inc. (https://agentos.sh) | | Kind | Agent framework | | Category | Agent frameworks & SDKs (https://www.anchorterminal.com/categories/frameworks) | | Auth | API key · The framework has no account of its own. Each model provider takes its own key from the environment or from the agent's configuration, and the Claude and Gemini CLI providers use an existing local sign-in. | | Pricing | Free (Free · OSS) · Free and Apache 2.0, with no paid tier of AgentOS found. You pay your model provider. The terms page says the maintainers give no service-level agreement for self-hosted use (https://agentos.sh/legal/terms/, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the repository or on agentos.sh (checked 2026-10-08). | | Licence | Apache-2.0 | | Packages | npm: `@framers/agentos` | | Source | https://github.com/framerslab/agentos | | Docs | https://docs.agentos.sh | | llms.txt | https://agentos.sh/llms.txt | | Last release | 2026-10-08 | | GitHub stars | 677 (as of 2026-10-08) | | npm downloads / week | 5,328 | | Languages | TypeScript, Node 22 or newer | | Version | 0.12.12 on 8 October 2026. First published to npm on 12 December 2025 | | Models | 11 providers per the README. OpenAI, Anthropic, Gemini, Groq, Ollama, OpenRouter, Together, Mistral, xAI, and the Claude and Gemini CLIs | | MCP client | Not found in the package source or the docs sitemap | | Multi-agent | `agency()` with six strategies. sequential, parallel, debate, review-loop, hierarchical, graph | | Durable state | Checkpoints at node boundaries with `graph.resume()` and fork. The shipped store is in memory, and a persistent one is an `ICheckpointStore` you write | | Human approval | `hitl.approvals` with five triggers and six handlers, plus a human step in workflows. Off unless configured | | Guardrails | Five security tiers and six packs per the README. The injection and jailbreak classifiers are a separate extension package | | Sandbox | Agent-written code tools run in an in-process node:vm context with a wall-clock timeout and no memory limit. Off by default | | Tracing | OpenTelemetry API spans, metrics and logs, opt-in. The host application starts the SDK | | Telemetry | None found in the source. The privacy page says the core does not phone home | | Releases in 90 days | 98 versions on npm, 27 of them on 7 and 8 October 2026 | | Capabilities | agent.framework, agent.multi-agent, agent.durable | | Tags | framework, typescript, open-source, llms-txt, free, no-card | | JSON | https://www.anchorterminal.com/api/v1/tools/agentos.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 77 | 15.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 92 | 14.9 | | Agent ergonomics | 13% | 16.2 | 74 | 12.0 | | Security & auth | 14% | 17.5 | 81 | 14.2 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 87 | 7.6 | | Transparency & trust (editorial 80, provenance 48) | 7% | 8.8 | 64 | 5.6 | | Negative events | up to −15 | up to −15 | 2026-10-08. The README, which is also the npm page, says forged tools run in a "hardened `node:vm` sandbox". The project's own CI fails the build if its architecture docs use that word for the same executor, with the message that the documentation claims an isolation the executor does not have, and the docs quote Node's statement that node:vm is not a security mechanism. The site's security page also says npm audit runs in CI, and no workflow runs it. Sandbox mode is off by default and the docs are candid, so 2 points. https://github.com/framerslab/agentos/blob/master/.github/workflows/ci.yml | -2 | | **Total** | | | | **75.3 → BB** | ### Why each score - Reliability 77: Official npm package with Node 22 or newer stated (20). A public CI workflow builds, lints, type-checks and runs the tests with coverage, and the 12 most recent runs on master, all on 8 October 2026, passed (25). 16 open issues and pull requests in total, most filed by the maintainer, with one outside suggestion from 12 September unanswered (20). Written release rules give a breaking change a minor version and a changelog note, but feature commits ship as patches and two breaking minors, 0.11.0 and 0.12.0, landed on 7 October (12). Version 0.12.12, not declared stable (0). Local-software reading. - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 92: Typed TypeScript API with a TypeDoc reference (25). llms.txt on agentos.sh and docs.agentos.sh (10). The guides say which surface to reach for, for example agency-level approval for most apps and workflow nodes for an explicit graph, and the tool-forging page states what its sandbox does not do (16). Tools take Zod schemas (15). 22 runnable examples and a cookbook, with CLI error codes documented but no single page for the library's error classes found (11). A dated changelog generated on every release and written version rules (15). Framework reading. - Agent ergonomics 74: An agent is about five lines with the provider detected from the environment, and capability discovery selects tools by meaning, but no MCP client was found in the package source or the docs sitemap, which this line is read on for a framework (12). Session history is capped at about 120K tokens by default, with `history.maxTokens`, `reseed()` and `maxSteps` (20). Typed error classes and a `fallbacksUsed` field on results, with error documentation spread across pages (14). Checkpoints replay or re-run a node by its declared effect class on resume, and providers fall back in order, though the shipped checkpoint store is in memory (18). Few required options, TypeScript only (10). - Security & auth 81: No analytics or telemetry code found in the source, and the privacy and security pages say the runtime sends nothing to the vendor. OpenTelemetry is opt-in and the host starts the SDK (30). Approval gates on five triggers, five security tiers and a rule that composed tools chain a side-effecting step only when the host lists it. Agent-written code runs in an in-process node:vm context, off by default, and no gate is on unless configured (17). SECURITY.md names model output, tool results and retrieved content as untrusted input, and the injection classifier is a separate extension package (11). OpenTelemetry spans, a usage ledger and a reasoning trace (15). SECURITY.md with a private advisory form, acknowledgement in 5 business days and disclosure at 90 days. No security.txt, no bounty and no published advisory found, and the site's security page gives a different acknowledgement time of 48 hours (8). Framework reading. - Payments & pricing 60: No payment protocol (0). Self-hosted rule. The package is free under Apache 2.0 with nothing to buy (20), installs with no card (20) and needs no account (20). No paid tier of AgentOS was found. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 87: 0.12.12 on 2026-10-08 (30). 98 versions on npm in the 90 days to 8 October (20). Little outside traffic to judge by. Two outside issues were closed with five comments each, one outside suggestion has been open without a reply since 12 September, and nearly all pull requests come from one maintainer (15). The npm package is current (15). CI and coverage run on every push, but the workflows have no `npm audit` step and the repository has no Dependabot configuration file (7). - Transparency & trust 64: Apache 2.0 (30). The privacy page and the security page agree that the core collects nothing and that the operator is the data controller. Both describe a self-hosted package, and the entity is written three ways, as Framers Lab, Inc., Frame.dev and Framers (22). SECURITY.md says only the latest version gets fixes, and breaking changes carry changelog notes, but no deprecation policy or notice period was found (8). No telemetry is sent and the site says so (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/agentos.md (JSON https://www.anchorterminal.com/fixes/agentos.json) ### What we couldn't check - The scout's facts held on 8 October 2026 (677 stars, 0.12.12, Apache 2.0). Its entry did not mention that no MCP client was found - Whether an MCP client exists in a sibling package. None was found in @framers/agentos, in the dependencies of @framers/agentos-extensions 1.0.3 or in the docs sitemap, and we did not clone the extensions repository - The npm time index lists versions 1.0.0 to 1.0.3 from 11 December 2025 that are no longer in the registry. We found no note explaining their removal - Whether Dependabot is enabled in the repository settings, as the security page says. No configuration file is in the repository - The site footer gives MIT for extensions, and @framers/agentos-extensions 1.0.3 declares Apache-2.0 on npm - unchecked: the vendor's LongMemEval figures (85.6 per cent on S, 70.2 per cent on M). They are the vendor's claims and were not reproduced - unchecked: frame.dev and the hosted Voice Chat Assistant terms, which cover a separate product - Which security tier, if any, applies to a plain `agent()` call. The `tier` field is optional and we did not trace the default ### Sources - npm registry document for @framers/agentos (versions and dates): (seen 2026-10-08) - npm weekly downloads: (seen 2026-10-08) - repository clone (README, docs, workflows, CHANGELOG, LICENSE, source): (seen 2026-10-08) - GitHub API, repository statistics: (seen 2026-10-08) - GitHub API, CI runs on master: (seen 2026-10-08) - CI workflow, including the documentation wording check: (seen 2026-10-08) - security policy: (seen 2026-10-08) - release rules: (seen 2026-10-08) - tool forging and sandbox mode: (seen 2026-10-08) - human approval: (seen 2026-10-08) - checkpointing: (seen 2026-10-08) - observability: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - docs llms.txt and sitemap: (seen 2026-10-08) - terms guidance: (seen 2026-10-08) - privacy guidance: (seen 2026-10-08) - security page: (seen 2026-10-08) - security.txt (404): (seen 2026-10-08) - OSV query for @framers/agentos (no records): (seen 2026-10-08) - RDAP for agentos.sh: (seen 2026-10-08) ## Who's behind it (provenance 48/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Framers Lab, Inc. | 20/20 | | Domain age | agentos.sh, registered 2025-10-26 (under a year) | 0/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | read, states 2 of the 7 things a reader expects | 5.7/10 | | Privacy policy | read, states 2 of the 8 things a reader expects | 5.5/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | agentos.sh/llms.txt names Framers Lab, Inc. as the company behind AgentOS. The site footer reads Frame.dev and the licence file reads Copyright (c) 2025 Framers. The terms and privacy pages are guidance for a self-hosted open-source package, each last updated on 6 November 2025. agentos.sh/.well-known/security.txt and docs.agentos.sh/.well-known/security.txt return 404. The repository has .github/SECURITY.md. RDAP gives agentos.sh a registration date of 2025-10-26. The npm maintainers are manicteam (team@manic.agency) and jdunnfive. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://agentos.sh/legal/terms/), read 2026-10-08, dated 2025-11-06, states 2 of the 7 things a reader expects. - Gives the date it was last updated. Last updated 2025-11-06. - Not found in the text. Names the governing law or courts. - Not found in the text. States a limit on its liability. - Not found in the text. Says how the agreement or account can be ended. - Not found in the text. Says how changes to the terms are announced. - Not found in the text. Lists what users may not do. - Also in the text (2026-10-08). The hosted Voice Chat Assistant run by Frame.dev has its own Terms of Service, separate from this page about self-hosted AgentOS. "If you use the managed Voice Chat Assistant service operated by Frame.dev, that product is governed by its own Terms of Service." **Privacy policy** (https://agentos.sh/legal/privacy/), read 2026-10-08, dated 2025-11-06, states 2 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2025-11-06. - Not found in the text. Says what personal data is collected. - Not found in the text. Says how long data is kept. - Not found in the text. Says who else receives the data. - Not found in the text. Says whether personal data is sold or shared for advertising. - Not found in the text. Says what rights people have over their data. - Gives a privacy contact. Gives an email address, hidden from our reader by the page. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). The self-hosted core project collects no analytics and sends no end-user data to Frame.dev. "The core project does not phone home, collect analytics, or transmit end-user data to Frame.dev." ## Live (updated 2026-10-08 15:57 UTC) - github `framerslab/agentos` v0.12.19, released 2026-10-08 - npm `@framers/agentos` 0.12.18 - security.txt: none - Always current: https://www.anchorterminal.com/api/v1/live/agentos.json ## Probe metrics A library has no endpoint to probe. Reliability is assessed from its tests, release history and issue tracker; performance waits for the task suite run through it. See https://www.anchorterminal.com/benchmark/#kinds ## Strengths - Apache 2.0, with no analytics or telemetry code found in the source and a privacy page that says the core sends nothing to the vendor - Approval gates on five triggers (named tools, agents, forged tools, the final return, strategy overrides) with CLI, Slack, webhook and LLM-judge handlers - CI with a test suite passed on each of the 12 most recent pushes to master on 8 October 2026 - Breaking changes get a minor version and a changelog note under written release rules - llms.txt on both sites, a TypeDoc API reference and 22 runnable examples in the repository ## Weaknesses - Version 0.12.12, with 27 releases on 7 and 8 October 2026 and breaking minors 0.11.0 and 0.12.0 on the same day - No MCP client found in the package source or the docs sitemap - Agent-written code tools run in an in-process node:vm context, which Node says is not a security mechanism. The mode is off by default - The README calls that sandbox hardened, a word the project's CI bars from its architecture docs - The only checkpoint store shipped is in memory, so resuming after a crash needs a store you write ## Before you call it (notes for agents) 1. Pin an exact version of @framers/agentos. Feature commits ship as patch releases while it is 0.x, and breaking changes ship as minors 2. Leave emergentConfig.allowSandboxTools off unless forged code runs through an executor that isolates. The default executor shares the host process 3. Pass your own ICheckpointStore to compile() for runs that must survive a restart. The default store is in memory 4. Set hitl.approvals.beforeTool for tools that write, and choose a handler. No approval gate is on by default 5. Use Node 22 or newer, and set a provider key such as OPENAI_API_KEY or ANTHROPIC_API_KEY. The provider is detected from the environment ## Get started Install: ```bash npm install @framers/agentos ``` ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | OpenAI Agents SDK | AA | 86.2 | 1 | agent.framework, agent.multi-agent, agent.durable | no | https://www.anchorterminal.com/tools/openai-agents-sdk.md | | Pydantic AI | A | 83.7 | 3 | agent.framework, agent.multi-agent, agent.durable | no | https://www.anchorterminal.com/tools/pydantic-ai.md | | Microsoft Agent Framework | A | 82.2 | 6 | agent.framework, agent.multi-agent, agent.durable | no | https://www.anchorterminal.com/tools/microsoft-agent-framework.md | | Docker Agent | BB | 76.5 | 30 | agent.framework, agent.multi-agent, agent.durable | no | https://www.anchorterminal.com/tools/docker-agent.md | | Agent Development Kit (ADK) | BB | 74.7 | 57 | agent.framework, agent.multi-agent, agent.durable | no | https://www.anchorterminal.com/tools/google-adk.md | | Agno | BB | 72.8 | 81 | agent.framework, agent.multi-agent, agent.durable | no | https://www.anchorterminal.com/tools/agno.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - @framers/agentos 0.12.12 on 2026-10-08, the 98th release in the 90 days to that date, with 27 on 7 and 8 October and 558 versions since 12 December 2025 (source: ) - While the package is 0.x, feature and fix commits release a patch and a breaking change releases a minor, under written rules (source: ) - Agent-written code tools run in an in-process node:vm context, off by default, and the docs quote Node's statement that node:vm is not a security mechanism (source: ) - The privacy page says the core project does not phone home, collect analytics or send end-user data to Frame.dev (source: ) - Approval gates cover five triggers with six handler factories, among them CLI, Slack, webhook and an LLM judge (source: ) - No MCP client was found. The only match for MCP in the package source is a comment in the capability-discovery code (source: ) ## Compare - [AgentOS vs Agno](https://www.anchorterminal.com/compare/agentos-vs-agno.md): BB 75.3 vs BB 72.8 - [AgentOS vs Claude Agent SDK](https://www.anchorterminal.com/compare/agentos-vs-claude-agent-sdk.md): BB 75.3 vs BB 72.1 - [AgentOS vs CrewAI](https://www.anchorterminal.com/compare/agentos-vs-crewai.md): BB 75.3 vs B 67 - [AgentOS vs Docker Agent](https://www.anchorterminal.com/compare/agentos-vs-docker-agent.md): BB 75.3 vs BB 76.5 - [AgentOS vs Agent Development Kit (ADK)](https://www.anchorterminal.com/compare/agentos-vs-google-adk.md): BB 75.3 vs BB 74.7 - [AgentOS vs LangGraph](https://www.anchorterminal.com/compare/agentos-vs-langgraph.md): BB 75.3 vs BB 70.6 - [AgentOS vs Microsoft Agent Framework](https://www.anchorterminal.com/compare/agentos-vs-microsoft-agent-framework.md): BB 75.3 vs A 82.2 - [AgentOS vs OpenAI Agents SDK](https://www.anchorterminal.com/compare/agentos-vs-openai-agents-sdk.md): BB 75.3 vs AA 86.2 - [AgentOS vs Pydantic AI](https://www.anchorterminal.com/compare/agentos-vs-pydantic-ai.md): BB 75.3 vs A 83.7 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on agentos.sh or one of its subdomains, or the README of github.com/framerslab/agentos. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "agentos", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html AgentOS on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![AgentOS on Anchor Terminal](https://www.anchorterminal.com/badges/agentos.svg)](https://www.anchorterminal.com/tools/agentos) ``` Plain link: ```html AgentOS on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say AgentOS is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/agentos-dark.png - Light: https://www.anchorterminal.com/assets/share/agentos-light.png