The catalog

Tools of the estate

Versions are from the audit of 2026-10-04 and say so — a version somebody wrote down is a snapshot, never “latest”.

Record formats

ToolWhat it isVersion
@flashyos/aaoThe AAO charter standard: named roles, a human accountable by email, and approval thresholds an agent cannot cross alone. The manifest spec, its JSON Schema, and the validators every checker in the estate imports.0.4.2
@flashyos/directorydirectory/1 — the estate’s record: one entity per real thing, emitted as federated fragments by each repository, merged with one authority per id. The vocabulary (KINDS, EDGE_TYPES, EDGE_REQUIRES), the merge, and the validator.0.2.0
@flashyos/shiplogshipped/1 — the past tense of a record. One sealed entry per thing that shipped, derived from first-parent commit history, emitted per repository, never edited after sealing.0.1.0
@flashyos/backlogbacklog/1 — the future tense. One item per intention, filed where the work happens, decaying unless renewed, private until a named human promotes it.0.1.1
@flashyos/checkpointcheckpoint/1 — an RFC 6962 Merkle tree head over the sealed claims a property publishes. A static file beside the fragments: no server, no collector, no uptime.0.2.0
@flashyos/countersignProof over the record: countersignature, delegation, audit, badge. The layer that lets the party a claim is about sign the claim.0.1.0
@flashyos/frontdoorfrontdoor/1 — a published door: which lanes an organisation opens, what it asks at each, and what it owes back — including the honest no-SLA rung.0.1.0
@flashyos/holdingholding/1 — what happened to the positions an office holds. Transitions, not states: current state is derived from an append-only log, never asserted.0.1.0
@flashyos/deliverydelivery/1 — the rungs between a merged commit and a thing somebody actually has. Publishes where on that ladder each shipped thing stands.0.1.0
@flashyos/canoncanon/1 — a lockfile for facts. One authority per fact, fetched by every property that renders it, so a number is written once and cannot drift between pages.0.1.0
@flashyos/playbookplaybook/1 — a way two or more organisations work together, as a published document rather than tribal memory.0.2.0
@flashyos/boltbolt/1 — one secret split across an estate: a hunt verified by sha256 commitment, in the finder’s own browser, with no server to trust.0.2.2
@flashyos/mailmail/1 and the estate’s mail control plane: a lane policy that refuses, a capture that demands a consent basis, a content-free event record, and a transport seam so the provider is a variable.0.3.0
@flashyos/artifactartifact/1: a dated public commitment to content nobody can read yet. Existence precedes discovery.0.1.0
@flashyos/assetmeshrwa/1: a machine-readable record of a real-world asset, the attestations that stand behind it, and the obligations issued against it. Dependency-free, published at your own domain, verifiable by anyone.0.1.0

Packages

ToolWhat it isVersion
@flashyos/verifyOpen, offline verification of settlements, receipts and handshakes: fetch the public feed, recompute every digest, trust nothing.0.5.0
@flashyos/llms-txtParse, validate and build llms.txt files — the machine door every estate property serves beside its human one.0.1.1
@flashyos/conformanceRun the conformance suite against any live domain, audit a charter+handshake pair in-process (auditProperty / assertProperty), or scaffold a new property (init).0.2.3
@flashyos/agentThe SDK agents import to report state to the mesh: heartbeat, work claims, and the consent-gated write paths.0.21.0
@flashyos/mcpThe same mesh surface as the SDK, exposed as Model Context Protocol tools — connect any MCP-speaking agent to the mesh in one config block.0.6.0
@flashyos/llm-gatewayProvider-agnostic inference seam: adapters, automatic failover, metering ceilings, and an empty-success guard.0.2.1
@flashylabs/ledgerAppend-only, multi-asset settlement ledger. Storage-agnostic by construction; integer amounts; hash-chain verifiable.npm (private registry visibility)
@flashylabs/wdk-policy-guardA spending-policy layer for wallets built on Tether’s WDK, or any wallet SDK. Grades a proposed spend against a per-agent envelope — chain, kind, asset and destination allowlists, a per-transaction cap, a daily cap — before anything signs, and returns ALLOW, ESCALATE, or DENY, always with a reason.source-available on GitHub (npm publish pending)
@flashylabs/wdk-staking-kitA reference staking primitive for wallets built on Tether’s WDK. Locks a balance into a fixed-term tier at a published rate, with no on-chain contract required: a lock earmarks a balance a provider already credits, and only the yield, paid on close, is a real write.source-available on GitHub (npm publish pending)
@flashyos/shiposThe release function, chartered: a consequence-ranked merge queue for every repository, plus the operator lane — the ranked list of actions only the accountable human can take.0.1.0
@magician/coreThe trust-routing engine: trust/1 edges, the router with the veil, the consent machine, sealed introduction/1 outcomes, beacon/1 federation, grant/1, and the transport envelopes.pre-publication (gated on first independent adopter)
@magician/conciergeThe Mesh Concierge: one dependency-free script that puts the estate’s intent door on any site, filing to a named human at that property. The Activation standard and its pre-install check travel with it.vendored to properties (canon in the magician repo)
@flashyos/wallet-wdkGoverned economic agency for FlashyOS agents on Tether WDK: the AAO WalletCapability, an authorizer client, an MCP elicitation handler, and a WDK policy rule that defers every spend to the authorization plane.0.1.0
@flashyos/signerThe isolated signer for the wallet authorization plane: verifies an Ed25519-signed SpendAuthorization, re-derives the operation from the real call, refuses on any mismatch, executes through Tether WDK, and reports settlement.0.1.0
@flashyos/wdkThe FlashyOS agent object: identity, authority, wallet, memory and partners behind one interface, with financial capabilities provisioned on Tether WDK and every transaction recorded.0.1.0
@flashyos/dialectsOne charter, many dialects: renders an organisation’s AAO charter into the surfaces other standards define — agents.txt, agents.json, an A2A Agent Card — so the same facts cannot drift between them.0.1.0
@flashyos/meshOne checklist for joining the mesh: what a repository has adopted, what is left, and the exact command for each.0.1.0
@flashyos/pageOne page, one card, one claim: per-page social images, canonical metadata and structured data for a property that expects to be cited by search engines and answered from by generative ones.0.1.1

Scaffolds

ToolWhat it isVersion
@flashyos/create-mesh-nodeThe one-command on-ramp: writes a charter, handshake, directory fragment and workflow, then verifies L2.0.1.0
@flashyos/create-mesh-agentScaffold a dependency-free mesh starter agent into your repo — heartbeat, open-job polling, consent-gated actions.0.2.0

Vendored checks

ToolWhat it isVersion
The vendor-* familyEight dependency-free scripts every estate repository carries: check-charter, check-directory, check-frontdoor, vendor-shiplog, vendor-backlog, vendor-directory, vendor-checkpoint, vendor-check-activation. They run before an install, in repositories with no node_modules and sometimes no package.json.—

Estate instruments

ToolWhat it isVersion
estate-graphMeasures what the one-graph thesis is actually about: entities, relations, provenance, freshness, and the share of edges that cross a property boundary — with a ratio floor that fails regressions.—
estate-hygieneThirteen checks across every repository, with the repositories missing each one named rather than counted, and a per-dimension ratchet floor — because a mean lets one dimension collapse behind another’s improvement.—
estate-deployedFetches a domain’s served bytes and finds the commit whose committed copy is byte-identical — pinning exactly which commit a deploy serves, without trusting a date stamp or a CDN header.—
estate-joinFetches every estate domain and asks both questions a stranger’s arrival poses: does the handshake carry join (the machine door), and does the page link it (the human door)?—
estate-coherenceThe agreement check: of everything the estate publishes, how much is asserted by two properties from their own sides, with their own bases — the record’s only way to catch its own errors.—
estate-countersignedCounts the claims the estate makes about organisations that are not the estate, and how many those organisations have signed — the one number nobody here can raise.—
The three registersWhat each repository is licensed as, who did the work, and which standards each adopts — declared once, cross-checked against each other, surveyed against reality.—
reachabilityOne rule about silence: classifies a failed fetch as unreachable, ambiguous, or refused — and every tool that makes a network call imports it, enforced by test.—
workspace-depsFinds internal semver ranges a version bump has silently outgrown — the failure that is green on a laptop and red only on a clean CI checkout.—
route-livenessA badge is a measurement, not a decision: LIVE is granted by a URL answering over the network, the way a stranger would reach it — never typed by hand.—

Shared configs

ToolWhat it isVersion
@flashyos/eslint-configThe estate’s shared lint base. Extending it costs three lines, which is why it exists: nine properties never adopted a linter while adoption meant writing a flat config from scratch.0.1.0