A component that didn't declare wasi:http literally cannot make a network call, even if the operator sets --http-policy open. Permissive operator can't escalate past the declaration; lazy author can't reach past the grant. The intersection is the floor on damage.
Handing a third-party tool to your AI agent is the same problem as handing a third-party binary to cron. ACT caps the blast radius with a capability ceiling: component declares needs at build time, operator grants at runtime, host enforces the intersection.
Fix merged in jco (Bytecode Alliance's wasm-to-JS transpiler): wasip3-async components crashed with ReferenceError: STREAM_TABLES is not defined. Generator called .name() instead of intrinsic(), declaration never emitted. ~2 hours to merge. github.com/bytecodeallian…
- mcp-bridge wraps a remote MCP server (NAT-translated session-ids).
- openapi-bridge loads any OpenAPI 3.x spec at session-open and exposes every operation as a typed tool.
- act-http-bridge proxies a remote ACT-HTTP fleet.
Wrap any MCP server, any OpenAPI 3.x API, or any remote ACT-HTTP fleet as a sandboxed wasm component.
Three new ACT bridges in 0.7 — same capability ceiling, same signed-OCI provenance as any hand-written tool.
Every #OWSHackathon project runs on Node.js.
Ours runs on Android. 📱
Built ACT-OpenWallet — OWS as a WebAssembly component.
• One .wasm file, zero dependencies
• 8 chains, policy engine
• WASM sandbox = keys never leave the component
@OpenWallet#WebAssembly
Hermes Agent is now #1 on the Global @OpenRouter token rankings.
While our journey together has just begun, we'd like to take this opportunity to thank our contributors, supporters, and users for all they have done to get us this far.
The artifact is one `.wasm` that runs anywhere — Linux, macOS, Windows, Pi, browser tab. Same SHA256 everywhere.
One component serves MCP agents, HTTP APIs, CLI, browser. No per-platform wheels, no native shims, one supply-chain path to audit.
Today's MCP servers ship as `npx`, `uvx`, or `curl | bash` — ambient-permission native processes running as you.
Your agent's tool can read your SSH keys, your .env files, your shell history, your browser cookies.
There's a better way.
16K Followers 191 FollowingIn The World of AI is a captivating YouTube channel that explores the fascinating world of Artificial Intelligence (AI), Machine Learning, LLMs, & etc.
209K Followers 3K FollowingFollow for posts about GitHub repos, DSPy, and agents
Subscribe for top posts
DM to share your AI project (Due to volume of DMs I'll prioritize subscribers)
4.9M Followers 4 FollowingOpenAI’s mission is to ensure that artificial general intelligence benefits all of humanity. We’re hiring: https://t.co/dJGr6LgzPA
1.3M Followers 35 FollowingWe're an AI safety and research company that builds reliable, interpretable, and steerable AI systems. Talk to our AI assistant @claudeai on https://t.co/FhDI3KQh0n.