string-47aa25 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited string-47aa25 (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<p align="center"> <img src="./assets/string-logo.png" alt="String" width="440" /> </p>
An app framework and browser for AI agents.
String unifies apps, the web, and Markdown documents into one agent-native surface. A website can expose navigation and actions in Markdown, so an agent can use it like an app. Ordinary web pages still open as clean Markdown. Installed apps, local documents, web pages, files, APIs, and shell sessions all use the same commands.
The core loop is intentionally small:
/open read a document, app, web page, file, or shell session
/act call an available action
/info understand where you areString can run as a CLI, a daemon, or one MCP tool named string. The agent learns one surface and uses it everywhere.
Available String apps are maintained at github.com/string-os/apps.
Most agent integrations grow the agent's context: another tool schema, another API manual, another set of examples. String moves that knowledge into the app or page itself.
An agent opens a page, sees what actions are available, calls one, and follows the next hint. The page may be a local Markdown file, an installed app, an agent-native website, or a normal website rendered as Markdown. The interaction is the same.
What changes:
expose the same surface: Markdown content, navigation, actions, state, and hints.
/open, /act, /info, and topics work thesame for documents, apps, web pages, files, APIs, and shell sessions.
/act --help; responses carrynext: hints; errors carry recovery hints.
commands run only from local files or locally installed apps.
which reads and acknowledges them through the same CLI/MCP surface, or receives as a Claude Code channel notification.
/set $VAR = "...", not pasted into the agent's prompt.
an installed package, a GitHub repo, or on the web.
String calls this format SFMD: String Flavored Markdown. It is normal Markdown plus lightweight navigation, action blocks, and response conventions.
No SDK. No endpoint memorized. The surface tells the agent what it can do.
Open a web page as Markdown:
string main '/open https://docs.string-os.org/runtime/mcp'Open an installed app and follow its actions:
string app:moltbook '/open'
# [actions] home, feed, read, comment, post, search
# next: /act.feed · /act.search "..."
string app:moltbook '/act.feed'
# Feed: @post-1 through @post-20
# next: /act.read @post-N
string app:moltbook '/act.read @post-3'
# ...post body...
# next: /act.comment @post "..."The same interaction over MCP is one tool call:
{ "topic": "app:moltbook", "cmd": "/act.read @post-3" }/plugin marketplace add string-os/string
/plugin install string@string-osThis installs the String MCP tool and a short skill for using it. The tool is registered as server string and exposes one tool named string.
For multiple local agents or workspace-specific homes, see Agent Identity.
To receive local String webhook events directly inside Claude Code, launch Claude Code with the String plugin channel and select the local agent id:
string agent add leo --home /home/ubuntu/crew/leo
STRING_AGENT_ID=leo \
claude \
--dangerously-load-development-channels plugin:string@string-osThat keeps the plugin-provided string MCP tool available and also pushes local events for the selected String agent into the Claude Code session. The official Discord channel can be loaded at the same time with --channels plugin:discord@claude-plugins-official.
codex plugin marketplace add string-os/string
codex plugin add string@string-osnpm install -g @string-os/string
string --helpThe daemon starts automatically on first use. Default port: 3923.
string main '/open ./README.md'
string main '/open https://docs.string-os.org/runtime/mcp'
string app:weather '/act.now Seoul'
string bash:dev 'pwd && ls'Topics scope state:
| Topic | Use |
|---|---|
main, notes, research | free-form document/web sessions |
app:<name> | installed app session |
app:<name>:<config> | app session with config-scoped env |
bash:<name> | persistent shell session |
app, tool, bash, event, system, agent | hub topics for runtime views and management |
Hub topics are reserved. Open them to inspect runtime state, or send management commands through their hub:
string app # installed apps + active app sessions
string event # event inbox + local webhook URL
string system status
string agent listEvery response is wrapped so an agent can separate String output from shell noise:
<𝒞=string:main>
...
</𝒞>String serves MCP directly. No separate MCP package is needed.
{
"mcpServers": {
"string": {
"command": "npx",
"args": ["-y", "@string-os/string", "--mcp"]
}
}
}The MCP tool takes:
{ "topic": "main", "cmd": "/info" }For local webhook event delivery into Claude Code Remote Control channels, see Events and Local Webhooks.
Use /help, /info, and /act --help to discover what is available.
A String surface can be:
The agent uses the same commands either way. When a surface includes SFMD action blocks, it becomes executable.
---
name: weather
type: app
default: now
---
# Weather
GET https://wttr.in/{city}?format=%l:+%C+%t+%w&m city, -c: string (required) "City name"
Install that file as an app and call it:
string main '/install --app ./weather.md'
string app:weather '/act.now Seoul'The Markdown is the interface. The runtime handles discovery, argument parsing, execution, output framing, state, and credentials.
Want a website that serves styled HTML to people and a clean .md twin to agents?
site-builder — a Claude Code / Codex plugin that scaffolds, validates, and deploys human + AI sites. Pure npx, no runtime dependency.@string-os/astro-sfmd — the Astro integration it drives: every page emits HTML + a mirrored .md.@string-os/string — CLI, daemon, MCP server, runtime@string-os/client — HTTP/SSE client for stringd@string-os/core — SFMD parser@string-os/compiler — SFMD validator/compiler@string-os/astro-sfmd — Astro integration for human + AI (SFMD) sitesMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.