Full Forge + Studio
Creates,
grounds, refines, evaluates and exports agent definitions. Studio owns the authoring
experience; exports use the portable forge.agent-package.v2 contract.
Forge Executor is the narrow local distribution for verified Forge agents.
It accepts signed .forge-agent packages, checks the developer identity and package
contents, installs them in quarantine, and runs them through the same governed capability and
approval boundaries as full Forge.
A valid signature proves authorship and package integrity. It does not grant credentials, certification, commissioning, approvals, automatic routing, connector access or production authority.
Product boundary
Creates,
grounds, refines, evaluates and exports agent definitions. Studio owns the authoring
experience; exports use the portable forge.agent-package.v2 contract.
Verifies, imports, lists and executes reviewed packages on a workstation. It is deliberately not a second authoring surface and cannot manufacture missing capabilities or lifecycle evidence.
Packages may originate in Forge Studio or from agent JSON authored with Claude, Codex or Antigravity. The package carries the agent definition, capability contract, profile snapshot and portable skill files. Secrets, runtime memory, caches, approvals, certifications and production authority are excluded.
Signed package flow
./forge agent keygen \
--developer-id <developer-id> \
--display-name "<display name>"The Ed25519 private key remains
under ~/.config/forge with mode 0600. Share only the public identity.
./forge agent package agent.json \
--output agent.forge-agent \
--workspace <workspace> \
--skill-dir .claude/skillsexport uses the same signing path;
sign signs an existing validated package.
./forge agent inspect agent.forge-agentInspection validates the archive, manifest, content digests, signature status, dependencies and portable file names without installing or enabling anything.
forge agent trust add developer-identity.json \
--fingerprint "ed25519:sha256:<verified fingerprint>"The executor administrator must compare the fingerprint over a separate trusted channel. Package content alone is never sufficient evidence for trust.
forge agent install agent.forge-agent
forge agent listA trusted import starts disabled, decommissioned and excluded from automatic routing. Bundled skills are installed disabled. Dependency review, qualification and commissioning remain separate steps.
In a source checkout, use ./forge agent …. In an installed
distribution, the command is normally
~/Library/Application Support/Zynga Forge/bin/forge.
Trust and revocation
The local trust store binds one developer id to one Ed25519 fingerprint and public key. Conflicting identities, unknown developers, malformed packages and unsigned packages fail closed or remain quarantined.
forge agent trust list
forge agent trust revoke <developer-id-or-fingerprint>Revocation prevents future packages from that identity from entering the trusted installation path. It does not silently delete audit evidence.
Runtime behavior
An agent may use only registered capability executors available in the selected runtime. Missing bindings block honestly. Outward writes still require the established approval, credential and connector gates.
Executor memory is isolated by workspace, agent and exact run context. It is bounded, compacted, resettable and redacted before persistence. Recalled observations are context only and never authority.
Forge may reuse exact local retrieval results in a bounded process-local cache while the canonical and derived index revisions still match. Revision changes invalidate reuse. Semantic answer caching is disabled.
Transformer KV-cache ownership remains with Ollama or the selected cloud model provider. Forge neither claims nor guarantees persistence of provider KV state.
Common bearer tokens, API keys and model-key patterns are redacted; oversized turns are bounded. Credentials continue to live in the configured secret/Keychain boundary.
Readiness checklist
Manifest, file digests, Ed25519 signature and independently verified developer fingerprint all pass.
Required skills, models, connectors and exact runtime executors are installed and healthy.
The imported definition has been reviewed, qualified, certified, published and explicitly commissioned where required.
Credentials are present only for the intended connector, approvals match the exact effect, and dry-run evidence has been reviewed before any outward mutation.
Troubleshooting
Do not bypass verification. Confirm the public identity and fingerprint through the trusted channel, then add trust—or request a new package from an active identity.
This is expected immediately after import. The agent is decommissioned and auto-routing is off. Complete dependency review and the normal qualification/commissioning workflow.
Bind and qualify the exact capability or keep the stage manual. Never relabel an unbound stage as AUTO merely to clear readiness.
Reset the exact agent/run context through the executor runtime control. Reset is scoped; it does not clear another agent or workspace.
Implementation-level package details: Forge agent package interoperability.