ADOS EXTENSION SYSTEM

One manifest, two halves, a signed archive

The extension platform behind every ADOS extension. A single manifest ships a signed agent plugin, written in Python or Rust, and a sandboxed Mission Control panel. Capability permissions gate both halves.
1
Manifest, both halves
3
SDKs: Python, Rust, TypeScript
Signed
.adosplug archives
Sandbox
Capability-gated

HOW IT FLOWS

One manifest, two halves

  1. Manifest

    manifest.yaml

  2. Agent plugin

    subprocess

  3. Mission Control panel

    iframe

  4. Signed archive

    .adosplug

  5. Install

    permissions granted

  1. Manifest: manifest.yaml
  2. Agent plugin: subprocess
  3. Mission Control panel: iframe
  4. Signed archive: .adosplug
  5. Install: permissions granted

Agent half

Agent plugins on the companion computer

The agent half runs as its own subprocess, written in Python or Rust. It requests capabilities up front, and the host only grants what the operator approves. Plugins read telemetry, drive hardware, and add on-vehicle behavior without touching the core.

  • ✓Subprocess-per-plugin isolation
  • ✓Explicit, per-capability permissions
  • ✓Python and Rust runtimes, one wire protocol
my-drone.local:8080
The plugin catalog in the drone agent's web interfaceThe plugin catalog in the drone agent's web interface

GCS half

Sandboxed panels in Mission Control

The GCS half loads in a sandboxed iframe and mounts into a named UI slot. It talks to the host over a message channel with signed capability tokens, so a panel can only reach what it was granted. Custom tabs, overlays, and controls slot in with no host fork. A first-party module can run inline instead, and only after its signature verifies against an enrolled first-party key.

  • ✓Sandboxed iframe, no host access by default
  • ✓Capability tokens per message
  • ✓Named UI slots for tabs and overlays
command.altnautica.com
A plugin workspace inside Mission Control

Trust

Signed, sandboxed, permissioned

An extension is a signed archive. Third-party halves always run sandboxed, and every capability is granted explicitly at install.

Security model
Archive
.adosplug, signed
Signature
Ed25519 over the archive digest
Agent sandbox
Subprocess + capabilities
GCS sandbox
iframe + tokens
Permissions
Explicit, per-capability
SDKs
Python + Rust + TypeScript
follow-me/manifest.yaml (excerpt)
schema_version: 3
id: com.altnautica.follow-me
version: "0.2.9"
risk: high
agent:
  runtime: python
  entrypoint: "follow_me:FollowMePlugin"
  isolation: subprocess
  permissions:
    - id: vision.detection.subscribe
    - id: flight.guided_setpoint
gcs:
  entrypoint: "gcs/plugin.bundle.js"
  isolation: iframe
  permissions:
    - id: ui.slot.node-detail-tab
  contributes:
    tabs:
      - id: follow-me-tab
        slot: node.detail.tab

Build an extension

Both halves ship from one manifest and one signed archive. Browse the open-source registry to see it in action.

Browse the registry
Get Early Access