Install
$ agentstack add skill-theseus-run-theseus-server-runtime ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Server Runtime
Use this skill for packages/theseus-server. For runtime host, systems, sinks, projections, active registry, tool catalog, or SQLite runtime stores, use the runtime-engine skill instead.
Read First
packages/theseus-server/src/handlers.tspackages/theseus-server/src/index.tspackages/theseus-server/src/serialize.tspackages/theseus-runtime/src/index.tspackages/theseus-runtime/src/live.ts
Boundaries
- Handlers stay at the transport boundary. They call
TheseusRuntimeand map runtime errors to RPC errors. TheseusRuntimeowns dispatch lifecycle, tool hydration, current capsule binding, registry updates, and persistence side effects.- Tool catalog code lives in
packages/theseus-runtime. Do not let handlers hydrate tools directly. - Serialization belongs in
serialize.ts; do not scatter wire-shape conversion through runtime logic. - SQLite persistence belongs behind runtime store/capsule services or runtime projections, not server handlers.
- Server may assemble layers and providers. It must not become the runtime.
- Do not add plugin routing, dynamic extension loading, or extension registry
semantics in server. Server exposes/adapts runtime commands and queries; it does not define the harness extension model.
Error Rules
- Runtime errors should be typed tagged errors.
- Handler error mapping should be explicit and stable for clients.
- Do not leak raw causes through RPC responses unless the API contract says so.
Verification
- Run
bun run typecheckafter runtime, handler, or RPC schema changes. - Run relevant server/core tests when dispatch lifecycle, persistence, or serialization behavior changes.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: theseus-run
- Source: theseus-run/theseus
- License: MIT
- Homepage: https://www.theseus.run
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.