One manifest, two halves, a signed archive
HOW IT FLOWS
One manifest, two halves
Manifest
manifest.yaml
Agent plugin
subprocess
Mission Control panel
iframe
Signed archive
.adosplug
Install
permissions granted
- Manifest: manifest.yaml
- Agent plugin: subprocess
- Mission Control panel: iframe
- Signed archive: .adosplug
- Install: permissions granted
Agent half
Agent plugins on the companion computer
The agent half runs as its own subprocess, written in Python or Rust. It requests capabilities up front, and the host only grants what the operator approves. Plugins read telemetry, drive hardware, and add on-vehicle behavior without touching the core.
- ✓Subprocess-per-plugin isolation
- ✓Explicit, per-capability permissions
- ✓Python and Rust runtimes, one wire protocol


GCS half
Sandboxed panels in Mission Control
The GCS half loads in a sandboxed iframe and mounts into a named UI slot. It talks to the host over a message channel with signed capability tokens, so a panel can only reach what it was granted. Custom tabs, overlays, and controls slot in with no host fork. A first-party module can run inline instead, and only after its signature verifies against an enrolled first-party key.
- ✓Sandboxed iframe, no host access by default
- ✓Capability tokens per message
- ✓Named UI slots for tabs and overlays

Trust
Signed, sandboxed, permissioned
An extension is a signed archive. Third-party halves always run sandboxed, and every capability is granted explicitly at install.
- Archive
- .adosplug, signed
- Signature
- Ed25519 over the archive digest
- Agent sandbox
- Subprocess + capabilities
- GCS sandbox
- iframe + tokens
- Permissions
- Explicit, per-capability
- SDKs
- Python + Rust + TypeScript
schema_version: 3
id: com.altnautica.follow-me
version: "0.2.9"
risk: high
agent:
runtime: python
entrypoint: "follow_me:FollowMePlugin"
isolation: subprocess
permissions:
- id: vision.detection.subscribe
- id: flight.guided_setpoint
gcs:
entrypoint: "gcs/plugin.bundle.js"
isolation: iframe
permissions:
- id: ui.slot.node-detail-tab
contributes:
tabs:
- id: follow-me-tab
slot: node.detail.tabBuild an extension
Both halves ship from one manifest and one signed archive. Browse the open-source registry to see it in action.
Browse the registry