af360
It watches the things you have built. Point it at the folders where your
projects live and it keeps an eye on them: work you have not saved, projects
with no backup anywhere, sites that have gone down, dates about to pass. When
something needs you, it says so in one line. When nothing does, it says that
too.
Everything happens on your own machine. No account, no sign-in, no server of
ours, nothing uploaded.
What this package is, and what it is not
This npm package is af360 for a terminal and for an AI agent. It carries
three things:
- the CLI below, which answers from the last look around;
- the MCP server (
af360 mcp), so an agent can ask about your estate
instead of guessing;
- the Windows bridge, so a connected GitHub token is encrypted by Windows
(DPAPI) rather than kept in plain text.
It is not the af360 desktop app. There is no window here: no sealed af360
window, no tray icon, and it does not watch anything while it is closed. It
looks when you ask it to and then it stops.
The full Windows app is on the Microsoft Store:
https://apps.microsoft.com/detail/9MZLSM8JB83W
Getting started
You need Node.js 20.11 or newer. Then, in a terminal:
npx af360
To keep it around:
npm install -g af360
The commands
af360 how everything is right now, in one line
af360 open open the cockpit in your browser
af360 scan look around now and print what turns up
af360 ask ask what af360 last saw, without opening the window
(estate, projects, ahead, verify - add --json for the
same answer an AI agent gets)
af360 build which build of af360 this is (--verify re-reads the files)
af360 doctor is af360 already running? (add --fix to clear a leftover)
af360 mcp answer an AI agent's questions about this estate (read-only;
started by the agent's app, not usually typed by hand)
af360 --help this list
af360 --version which af360 this is
The bare af360 is instant on purpose: it prints the result of the last look
around and exits. It starts nothing and scans nothing. Use af360 scan when
you want it to actually go and look.
Pointing an AI agent at it
af360 mcp is an MCP server on stdio. It is read-only: it answers from
what af360 last saw and re-scans for nobody, so no agent can make af360 walk
your disk however often it likes. Configure it the way your agent's app
configures any other MCP server, with the command af360 mcp.
What it does not do
- No accounts. There is nobody to sign in as.
- No servers of ours. af360 runs on your machine and answers only your
machine. It listens on 127.0.0.1 and [::1] and refuses everything else.
- Nothing is uploaded. Not your paths, not your project names, not
anything it finds. Your settings sit in a plain file at
~/.af360/config.json
that you can read and delete.
- It never writes to your projects. It looks, it does not touch. It runs no
git command that changes anything.
- One exception, stated plainly: once a day af360 can ask the public npm
registry whether a newer af360 exists, and print one line if there is. It
sends nothing about you or your machine. Switch it off in Settings, or set
AF360_NO_UPDATE_CHECK=1.
Working on af360 itself
These commands work the same in Git Bash, Command Prompt and PowerShell.
Forward slashes work everywhere, including on Windows.
npm install # install the toolchain
npm run dev # development server, opens your browser
npm run build # production build
npm run package # assemble dist/, the payload that ships to npm
npm start # run the built app the way a user gets it
npm pack # build the tarball, publish nothing
Setting an environment variable is the one thing each shell spells
differently:
| Git Bash | AF360_NO_OPEN=1 npm run dev |
| Command Prompt | set AF360_NO_OPEN=1 && npm run dev |
| PowerShell | $env:AF360_NO_OPEN=1; npm run dev |
npm run dev and npm start both go through scripts/launch.mjs, which is
the only supported way to start af360. It binds loopback only, mints a session
token, and refuses to start a second copy on top of a running one. If port 3000
is busy with something that is not af360, it explains and moves to the next
free port.
How it is put together
app/ the rooms and the API
components/ Shell, the cockpit hook, folder picker
lib/ the engine: attention, disk radar, url health, expiry, insights
lib/attention THE attention engine - one computation feeds every surface
scripts/serve the launcher core: loopback bind, session token, port choice
bin/af360.mjs the CLI
shell/ the Windows window and the DPAPI bridge, in C#
docs/ the rulings, the ledger, the security model, the comp
The rule of the codebase: attention state derives from item statuses, in one
place. A calm headline above an item that needs you is impossible by
construction, not by discipline.
Security
af360 runs a local HTTP server that knows your disk, so it is built to be
hostile-proof from the inside out: loopback-only binding on both addresses, a
per-session token on every API call, Host and Origin validation, no CORS, and
every byte read off your disk treated as untrusted input. The threat model is
written down in docs/SECURITY-MODEL.md, and SECURITY.md says how to report
a problem.
af360 by Afeleos