cd /news/ai-infrastructure/anolisa-agentic-os-with-runtime-secu… · home topics ai-infrastructure article
[ARTICLE · art-105404] src=github.com ↗ pub= topic=ai-infrastructure verified=true sentiment=· neutral

Anolisa – Agentic OS with runtime, security, observability and token compression

Alibaba released ANOLISA, an open-source agentic operating system layer for AI Agent workloads, featuring a terminal interface (cosh-ng), token compression (Token-less), observability (AgentSight), and runtime security. In one observed coding task, Token-less saved 317K tokens (40.5%) based on AgentSight measurements, with tool responses reduced by 65.8% and tool schemas by 47.3%.

read3 min views1 publishedAug 21, 2026
Anolisa – Agentic OS with runtime, security, observability and token compression
Image: Michielbdejong (auto-discovered)

A gentic N exus O perating L ayer & I nterface S ystem A rchitecture

The operating system layer for Agent workloads.

Let Agents drive the system straight from your terminal, and strip the tool responses that reach the model before they cost you — while keeping the Shell, Agent framework, and sandbox you already run.

中文版 · Website · Quick Start · User Guide · Contributing

ANOLISA is a server-side operating layer for AI Agent workloads. It addresses three practical constraints of Agent execution: terminal entry, Token cost, and execution environments. Keep the Shell, Agent framework, and sandbox you already use. ANOLISA CLI provides a single installation entry point, while each capability can be enabled independently.

New to ANOLISA? Choose your first outcome in the Quick Start →

Agent entry Context efficiency Runtime & security
Shell copilot
Tool-output compression
Checkpoint and rollback
System and DevOps expertise
Trace and Token visibility
Focused Skill views
Kernel tuning
Cross-session memory
Sandbox and verification
Sandbox lifecycle

01 · AGENT INTERFACE

cosh-ng is an AI-native Linux terminal: it keeps familiar Bash/Zsh behavior, then adds an Agent that can understand intent, use tools and Skills, and ask for approval before risky work. Shell commands and natural language share one terminal instead of forcing users into a separate chat application.

02 · CONTEXT EFFICIENCY

Token-less removes redundancy from tool schemas and responses before they reach the model. Agent Memory reuses useful context across sessions. SkillFS keeps the current Skill view focused and makes other Skills discoverable when needed. AgentSight shows where Tokens are spent.

On Linux, AgentSight uses eBPF to observe an Agent without changing its code. Follow user input through model and tool calls, with Token use and sub-agent branches in the same view.

agentsight-demo-en-ebpf-cover-1080p.mp4 | #

Install Token-less and connect it to Claude Code:

curl -fsSL https://get.agentic-os.sh | bash
export PATH="$HOME/.local/bin:$PATH"
anolisa install tokenless
anolisa adapter enable tokenless claude-code

Restart Claude Code, run one tool-heavy task, then inspect the result:

tokenless stats summary
tokenless stats list --limit 5

Open the full Token-less Quick Start → · Read the user manual

tokenless-context-efficiency-hd.mp4 | #

In one observed coding task, Token-less saved 317K Tokens (40.5%), based on AgentSight measurements. Results vary by workload.

debug

and trace

are dropped by the field blacklist, metadata

as null, and tags

/ extra

as empty values. Compression runs between the Agent and the model, so no Agent framework code changes. Dropped array items stay retrievable through a <<tokenless:KEY>>

marker, which keeps the compression reversible.

Tool responses Tool schemas Full pipeline
65.8% fewer Tokens
47.3% fewer Tokens
62.9% fewer Tokens
ResponseCompressor · 46.85 µs SchemaCompressor · 11.44 µs 198.91 µs

Savings apply to the tool responses entering the context, not to the whole session bill. The Token-less user manual explains how to estimate the effect for a given workload.

03 · EXECUTION RUNTIME

ANOLISA is building out the Agent execution environment: Agent Sec Core isolates risky operations, and ws-ckpt keeps recovery points for workspace changes.

When a signed Skill changes, the Agent reports drifted

before using it again. A rescan records blocking findings as deny

.

Try the Agent demo → · Skill Ledger guide

skill-ledger-demo-en-with-cover.mp4 | #

Choose a runtime or security starting point → · Start with ANOLISA CLI

ANOLISA CLI is the common installation entry point. cosh-ng is installed in system mode; Token-less and other capabilities can be added independently.

curl -fsSL https://get.agentic-os.sh | bash

sudo anolisa --install-mode system install cosh-ng
anolisa install tokenless

Run cosh

to enter the AI-native terminal. Token-less can also optimize tool calls from an existing Agent without changing its framework.

Quick Start · Installation · User Guide · Troubleshooting · Build from Source · Changelog

Open an issuefor bugs and feature requests.- Read CONTRIBUTING.mdbefore submitting a pull request. - Report vulnerabilities through the Security Policy.

ANOLISA is released under the Apache License 2.0.

── more in #ai-infrastructure 4 stories · sorted by recency
── more on @alibaba 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anolisa-agentic-os-w…] indexed:0 read:3min 2026-08-21 ·