Proposal (rationale)
The fixed corpus is predominantly Python and treats provider, tool, and composition protocols from inside libraries. It does not center a native local harness whose public contract spans desktop, CLI, API, model providers, agent-client providers, MCP extensions, reusable recipes, and session-isolated execution.
goose is selected to test that surface and add a Rust
implementation. The earlier block/goose URL currently redirects to the Agentic AI Foundation
organization; the extraction must pin and record the canonical ownership at read time rather than
silently using an obsolete URL.
Decision
proposed — 2026-08-15. Captured as the local extensibility child of
WI-018, after WI-019.
Plan
Requirements
- Pin canonical repository SHA, licence, date, measured scale, and the crates/UI boundary actually read.
- Trace one local request from CLI or API through provider selection, tool discovery, an MCP extension call, result return, session state, and user-visible control.
- Distinguish direct model providers from ACP-backed agents and MCP-backed capabilities, including who owns the loop and continuation in each case.
- Trace permission, confirmation, secret, environment-variable, working-directory, and optional sandbox boundaries.
- Examine one recipe or repeatable workflow and state what it persists, parameterizes, and isolates by session identity.
- Map results to skills, neighbour, handoff, session, protocol escape-hatch, and agent-facing-interface candidates.
Impacts
- One durable/local-product extraction and index row.
- Implementation evidence that complements the normative MCP study in WI-025; neither item may substitute a product’s behaviour for the protocol contract.
Approach
Read the local CLI path as primary and use the desktop/API only to establish shared versus separate runtime state. Follow one first-party or minimal test MCP extension rather than surveying the extension ecosystem. Treat ACP as a change of loop ownership and make that boundary explicit.
Acceptance criteria / tests
- One request and MCP tool result are traced through named Rust symbols and executable tests.
- Provider, ACP, and MCP roles are distinguished by ownership, state, and failure propagation.
- Permission, secret, filesystem, and sandbox defaults are evidenced rather than inferred from UI labels.
- One recipe/session path establishes what prevents or permits cross-run collisions.
- Opinion is labelled; protocol and catalogue synthesis remain WI-025/WI-028; gates and site links pass.
Out of scope
- Auditing third-party MCP extensions or provider implementations.
- Comparing model quality or extension popularity.
- Treating optional macOS sandbox behaviour as the cross-platform default.
- Catalogue, module, or CLI changes.
Execution
Not started.
Review
Not started.