Standalone agent runtime

Build agents in Forge.
Run trusted packages locally.

Forge Executor is the narrow local distribution for verified Forge agents. It accepts signed .forge-agent packages, checks the developer identity and package contents, installs them in quarantine, and runs them through the same governed capability and approval boundaries as full Forge.

Executor is not an authority shortcut.

A valid signature proves authorship and package integrity. It does not grant credentials, certification, commissioning, approvals, automatic routing, connector access or production authority.

1

Product boundary

Authoring and execution remain separate

✦

Full Forge + Studio

Creates, grounds, refines, evaluates and exports agent definitions. Studio owns the authoring experience; exports use the portable forge.agent-package.v2 contract.

▶

Forge Executor

Verifies, imports, lists and executes reviewed packages on a workstation. It is deliberately not a second authoring surface and cannot manufacture missing capabilities or lifecycle evidence.

One interoperable format.

Packages may originate in Forge Studio or from agent JSON authored with Claude, Codex or Antigravity. The package carries the agent definition, capability contract, profile snapshot and portable skill files. Secrets, runtime memory, caches, approvals, certifications and production authority are excluded.

2

Signed package flow

Identity → inspect → trust → quarantine

1

Create a developer identity once

./forge agent keygen \
  --developer-id <developer-id> \
  --display-name "<display name>"

The Ed25519 private key remains under ~/.config/forge with mode 0600. Share only the public identity.

2

Package and sign the agent

./forge agent package agent.json \
  --output agent.forge-agent \
  --workspace <workspace> \
  --skill-dir .claude/skills

export uses the same signing path; sign signs an existing validated package.

3

Inspect before trusting

./forge agent inspect agent.forge-agent

Inspection validates the archive, manifest, content digests, signature status, dependencies and portable file names without installing or enabling anything.

4

Verify identity out of band

forge agent trust add developer-identity.json \
  --fingerprint "ed25519:sha256:<verified fingerprint>"

The executor administrator must compare the fingerprint over a separate trusted channel. Package content alone is never sufficient evidence for trust.

5

Install into quarantine

forge agent install agent.forge-agent
forge agent list

A trusted import starts disabled, decommissioned and excluded from automatic routing. Bundled skills are installed disabled. Dependency review, qualification and commissioning remain separate steps.

In a source checkout, use ./forge agent …. In an installed distribution, the command is normally ~/Library/Application Support/Zynga Forge/bin/forge.

3

Trust and revocation

Local administrators own the trust decision

Trust is explicit

The local trust store binds one developer id to one Ed25519 fingerprint and public key. Conflicting identities, unknown developers, malformed packages and unsigned packages fail closed or remain quarantined.

Trust is revocable

forge agent trust list
forge agent trust revoke <developer-id-or-fingerprint>

Revocation prevents future packages from that identity from entering the trusted installation path. It does not silently delete audit evidence.

Private keys never travel with an agent.The developer signing key is not committed, copied into the package or stored by the executor. The package contains only the public identity and an Ed25519 signature over its content-addressed manifest.
4

Runtime behavior

Exact executors, bounded context, no ambient authority

✓

Governed execution

An agent may use only registered capability executors available in the selected runtime. Missing bindings block honestly. Outward writes still require the established approval, credential and connector gates.

◫

Durable local context

Executor memory is isolated by workspace, agent and exact run context. It is bounded, compacted, resettable and redacted before persistence. Recalled observations are context only and never authority.

↻

Evidence-only retrieval reuse

Forge may reuse exact local retrieval results in a bounded process-local cache while the canonical and derived index revisions still match. Revision changes invalidate reuse. Semantic answer caching is disabled.

◇

Provider-owned model cache

Transformer KV-cache ownership remains with Ollama or the selected cloud model provider. Forge neither claims nor guarantees persistence of provider KV state.

Memory is secret-safe by policy, not a credential store.

Common bearer tokens, API keys and model-key patterns are redacted; oversized turns are bounded. Credentials continue to live in the configured secret/Keychain boundary.

5

Readiness checklist

What must be true before an agent can run

✓

Package is trusted and intact

Manifest, file digests, Ed25519 signature and independently verified developer fingerprint all pass.

✓

Dependencies are available

Required skills, models, connectors and exact runtime executors are installed and healthy.

✓

Lifecycle gates are complete

The imported definition has been reviewed, qualified, certified, published and explicitly commissioned where required.

✓

Effects remain governed

Credentials are present only for the intended connector, approvals match the exact effect, and dry-run evidence has been reviewed before any outward mutation.

6

Troubleshooting

Fail closed, then resolve the exact blocker

Unknown or revoked developer

Do not bypass verification. Confirm the public identity and fingerprint through the trusted channel, then add trust—or request a new package from an active identity.

Package installs but cannot route

This is expected immediately after import. The agent is decommissioned and auto-routing is off. Complete dependency review and the normal qualification/commissioning workflow.

Missing executor or connector

Bind and qualify the exact capability or keep the stage manual. Never relabel an unbound stage as AUTO merely to clear readiness.

Context must be removed

Reset the exact agent/run context through the executor runtime control. Reset is scoped; it does not clear another agent or workspace.

Implementation-level package details: Forge agent package interoperability.