← 全部工具

Soturine/soturail

热度 60 更新于 AI 与 Agent

Local-first verified engineering control plane for AI-assisted software work: context, evidence, change contracts, readiness gates, provenance and reproducible artifacts.

githubauto-collected

安装

暂未验证可直接使用的安装命令,请查看项目官方文档或 Release。

SotuRail

SotuRail is a local-first engineering control plane for AI-assisted software work. It supplies workspace-bound context, contracts, readiness decisions, evidence, provenance, and reproducible release artifacts without becoming an autonomous agent or mandatory server.

SotuRail governs engineering readiness and verified context; it does not replace the coding model/runtime.

Install

npm install -g soturail
soturail --version
npx soturail --help

SotuRail v1.5 requires Node.js 22 or newer. TypeScript is the portable default; Rust acceleration remains optional.

Five-minute workflow

soturail index
soturail read README.md --query "product boundary"
soturail contract create docs-refresh --title "Refresh docs" --intent "Keep contracts current" --criterion "docs check passes" --check "npm run docs:check"
soturail evidence collect
soturail self readiness --v1 --strict

Generated state stays local under .soturail/. Use soturail run -- <command... for recoverable logs and soturail expand <rawid for redacted recovery.

Core architecture

| Layer | Responsibility | |---|---| | Integrity | WorkspaceGuard, Artifact Registry/Store/Envelope, fingerprints, atomic recovery | | Context | progressive reads, source-backed knowledge, hard-budget context artifacts | | Contracts | Change Contract, evidence policy, readiness and fidelity inputs | | Governance | capability registry/epochs, NativeMinimal provider, Authority + Readiness Dual Gate | | Execution evidence | exact-digest Execution Envelope, Run Manifest, freshness and provenance | | Adapters | typed MCP and replaceable governance/structural/docs/runtime provider boundaries |

The official MCP SDK serves a typed, small, capability-mapped surface. It exposes neither arbitrary shell execution nor caller-controlled raw-log authorization.

Maturity and safety

The v1.5 deterministic foundation is implemented and tested. AGT/ACS integration, general schema migrations, structural graph providers, Evidence Receipts, SQLite/FTS, vectors, and Conductor remain explicitly deferred.

SotuRail is a guardrail—not a sandbox. It cannot replace OS permissions, credential controls, provider security, physical/runtime QA, or human approval. Evidence distinguishes verified, unverified, blocked, inferred, and stale states.

Documentation

  • Quickstart
  • v1.5 commands
  • Verified control plane
  • Threat model
  • Migration to v1.5
  • Implementation tracker
  • Roadmap