# alibaba/anolisa: an agentic OS layer for terminal entry, token cost and sandboxed execution

> ANOLISA bundles a shell copilot, tool-output compression, eBPF tracing, checkpoint/rollback and sandboxing into one installable layer for AI agent workloads. The README is explicit about what it compresses and what it keeps; it is much quieter about how the pieces fail.

**alibaba/anolisa** — ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.

- Repository: https://github.com/alibaba/anolisa
- Website: https://agentic-os.sh/
- Stars: 658 · Forks: 111
- Language: Rust
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/alibaba-anolisa

## What ANOLISA actually solves, and for whom

ANOLISA is a server-side operating layer for AI agent workloads. The README names three practical constraints it targets: terminal entry, token cost, and execution environments. The framing is deliberately additive. You keep the shell, agent framework, and sandbox you already run, and enable each capability independently through one CLI installation entry point.

The intended user is an engineer running agents on Linux or macOS who is already paying for tokens and already has some sandbox story. The component table splits the project into three columns. Agent entry covers cosh-ng (a shell copilot), OS Skills, and ktuner for kernel tuning. Context efficiency covers Token-less for tool-output compression, Agent Memory for cross-session context, SkillFS for focused skill views, and AgentSight for trace and token visibility. Runtime and security covers ws-ckpt for checkpoint and rollback, Agent Sec Core for sandbox and verification, and Blaze for sandbox lifecycle.

That breadth is the first thing to weigh. Nine named components with independent enablement is not a single product; it is a collection with a shared installer. Whether that is a feature or a maintenance burden depends on how many of the nine you actually need. If you only want token compression, the README's own three-minute path suggests you can stop there.

## How Token-less compresses tool responses before they reach the model

The mechanism is a proxy sitting between the agent and the model. The README states compression runs between the Agent and the model, so no agent framework code changes. That placement is what makes the component framework-agnostic, and it is also what constrains it: anything the proxy does not understand passes through untouched.

The compression is field-aware rather than purely statistical. The README describes a field blacklist that drops debug and trace, treats metadata as null, and treats tags and extra as empty values. Dropped array items stay retrievable through a <<tokenless:KEY>> marker, which the README calls the mechanism that keeps compression reversible. Reversibility matters because an agent that later needs the dropped item can ask for it by key instead of re-running the tool.

The README reports a measured result: in one observed coding task, Token-less saved 317K Tokens (40.5%), based on AgentSight measurements, with the caveat that results vary by workload. It also gives a breakdown table with 65.8% fewer tokens for tool responses, 47.3% fewer for tool schemas, and a full pipeline figure that is truncated in the README. Treat the single-task number as an illustration of what is possible, not a planning figure. The schema reduction is the more portable claim, since tool schemas are more uniform across workloads than tool responses are.

## Installing ANOLISA and connecting Token-less to Claude Code

The README gives one installation entry point: a curl pipe to get.agentic-os.sh, followed by adding the local bin directory to PATH and using the anolisa CLI to install individual components.

```bash
curl -fsSL https://get.agentic-os.sh | bash
export PATH="$HOME/.local/bin:$PATH"
anolisa install tokenless
anolisa adapter enable tokenless claude-code
```

The first line fetches and runs the installer. The second makes the anolisa binary reachable in the current shell; without it the next command will not resolve. The third installs only the Token-less component, which is the README's own example of enabling a capability independently. The fourth wires Token-less into Claude Code through an adapter, which is how the proxy gets between that agent and the model.

After restarting Claude Code and running one tool-heavy task, the README suggests inspecting the result with two commands:

```bash
tokenless stats summary
tokenless stats list --limit 5
```

The summary gives aggregate numbers; the list shows the five most recent entries. If the list is empty after a tool-heavy run, the adapter is the first thing to check, since the README's flow assumes the enable step succeeded before the restart. The README points to a full Token-less Quick Start and a user manual on agentic-os.sh for anything beyond this path.

## AgentSight, eBPF and what tracing costs you

AgentSight is the observability component, and on Linux it uses eBPF to observe an agent without changing its code. The README describes following user input through model and tool calls, with token use and sub-agent branches in the same view. This is the component that produces the measurements quoted elsewhere in the README, so the token-saving claims and the tracing capability share a dependency.

That dependency cuts both ways. eBPF observation is genuinely non-invasive, which is why it can trace an agent you did not write and cannot modify. It also means AgentSight is a Linux story. The README's platform badge lists Linux and macOS, but the eBPF sentence is scoped to Linux, and the installation docs are the place to confirm what macOS gets. If your agents run on macOS, do not assume the kernel-level view transfers.

There is a second cost the README does not quantify: eBPF programs attach to kernel hooks, so the tracing surface depends on kernel version and configuration. A container with a restricted kernel or a managed runtime that blocks BPF will not give AgentSight what it needs. The README does not document a fallback tracing mode, so plan to verify kernel support before you build a workflow around the trace view.

## Where ANOLISA is the wrong tool

The clearest limitation is platform. The badge says Linux and macOS, but the deepest capability, AgentSight's eBPF tracing, is described as a Linux feature. Windows is not listed. If your agent fleet is Windows-based, this is not a partial fit; it is the wrong layer.

The second limitation is architectural. ANOLISA deliberately does not replace your shell, agent framework, or sandbox. That is a reasonable stance, and it also means ANOLISA cannot fix problems that live inside those components. If your agent framework makes a bad tool call, Token-less will compress the response, not prevent the call. If your sandbox is misconfigured, Agent Sec Core is described as providing sandbox and verification, but the README does not claim it repairs an existing sandbox's policy.

The third is the compression itself. Field blacklisting is a heuristic, and the README's own description shows it acting on specific keys: debug, trace, metadata, tags, extra. If your agent reads a field whose name happens to fall under a blacklist rule, or if a downstream consumer does not understand the <<tokenless:KEY>> marker, compressed output can be lossy in a way that surfaces as a confusing agent failure rather than an error. The README documents reversibility as a property of the marker; it does not document a dry-run mode for previewing what would be dropped before enabling compression on a production agent.

## How ANOLISA differs from a single-purpose agent proxy

The closest alternative approach is a standalone LLM proxy or gateway that sits between agent and model and handles routing, logging, and caching. The difference is scope. A gateway is one process with one job; ANOLISA is a layer whose compression component happens to occupy that same position in the data flow, but which also ships a shell copilot, an eBPF tracer, checkpoint/rollback, and sandbox lifecycle management.

That difference matters in two directions. A dedicated gateway will generally be simpler to operate and easier to reason about, because its failure modes are confined to request handling. ANOLISA's Token-less component is comparable in placement but is documented as part of a larger system with adapters per agent framework, which is more moving parts for the same compression outcome.

The reverse case is where ANOLISA wins: if you want the trace view and the compression numbers to come from the same observation path, AgentSight and Token-less are designed to be used together, and the README's own benchmark attribution says the token savings were measured by AgentSight. With separate tools you would be reconciling two sets of logs. The README does not document an integration with third-party observability backends, so if you already have a tracing stack, expect to run AgentSight alongside it rather than instead of it.

## Maintenance, releases and the Apache-2.0 licence

The repository is not archived, and the last push was on 2026-09-10. Recent releases are versioned per component rather than for the project as a whole: sight/v0.12.1 (agentsight v0.12.1) on 2026-09-10, tokenless/v0.8.1 on 2026-09-09, and memory/v0.2.7 on 2026-09-09. The differing major and minor numbers are the practical upgrade cost: components version independently, so an upgrade is a set of decisions rather than one. A tokenless bump from 0.8.x does not imply anything about agent-memory at 0.2.x, and the CHANGELOG.md and CHANGELOG_zh.md files at the repository root are where the per-component changes are recorded.

The primary language is Rust, which matters for the build story: the top-level entries include a Makefile, docker/, scripts/, specs/, src/, and tests/, so building from source is a supported path alongside the curl installer. The README does not document a rollback procedure for a component upgrade, and it does not state a support window or an LTS policy. Plan your own pinning.

The licence is Apache-2.0, with a NOTICE file at the repository root. Apache-2.0 is permissive and includes an explicit patent grant, which is generally the reason projects choose it over MIT for infrastructure code. This is not legal advice; if you redistribute ANOLISA or a modified version, read the NOTICE and the licence text rather than relying on a summary.

## Conclusion

ANOLISA is worth trying if you run agents on Linux or macOS, already have a shell and sandbox you like, and want token savings plus tracing without rewriting your agent framework. Skip it if you run Windows, need a formally verified sandbox, or want one integrated product rather than nine independently enabled capabilities. Before adopting, verify three things: that your kernel supports the eBPF hooks AgentSight needs, that the compression defaults in Token-less preserve the fields your agent actually reads, and that the reversibility marker <<tokenless:KEY>> is understood by whatever downstream tool consumes the compressed output.

## FAQ

### What is alibaba/anolisa and what does it do?

ANOLISA is a server-side operating layer for AI agent workloads, described in the README as addressing terminal entry, token cost, and execution environments. It bundles a shell copilot (cosh-ng), tool-output compression (Token-less), eBPF tracing (AgentSight), checkpoint and rollback (ws-ckpt), and sandbox components, each enabled independently through the anolisa CLI.

### How do I install ANOLISA and connect it to Claude Code?

The README's quick start runs the installer from get.agentic-os.sh, adds $HOME/.local/bin to PATH, then runs anolisa install tokenless and anolisa adapter enable tokenless claude-code. After restarting Claude Code and running a tool-heavy task, tokenless stats summary and tokenless stats list --limit 5 show the results.

### Does ANOLISA work on macOS and Windows?

The README's platform badge lists Linux and macOS, and Windows is not listed. AgentSight's eBPF-based tracing is described specifically as a Linux capability, so the deepest observability feature should not be assumed to work on macOS.

## Sources

- [alibaba/anolisa on GitHub](https://github.com/alibaba/anolisa)
- [License: Apache-2.0](https://github.com/alibaba/anolisa/blob/main/LICENSE)
- [Project website](https://agentic-os.sh/)
- [README](https://github.com/alibaba/anolisa/blob/main/README.md)
- [Releases](https://github.com/alibaba/anolisa/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/alibaba-anolisa
