Metadata-Version: 2.4
Name: pilot-daemon
Version: 0.12.0
Summary: AI-powered autonomous computer agent — full system control
License-Expression: MIT
Requires-Python: >=3.11
Requires-Dist: aiofiles>=24.1
Requires-Dist: aiohttp>=3.10
Requires-Dist: aiosqlite>=0.20
Requires-Dist: caldav>=1.0.0
Requires-Dist: cryptography>=43.0
Requires-Dist: httpx>=0.27
Requires-Dist: icalendar>=5.0.0
Requires-Dist: keyring>=25.0
Requires-Dist: mcp<3,>=2.0
Requires-Dist: numpy==2.2.6
Requires-Dist: psutil>=5.9
Requires-Dist: pydantic>=2.6
Requires-Dist: river==0.23.0
Requires-Dist: scikit-learn>=1.3.0
Requires-Dist: scipy<1.16,>=1.14.1
Requires-Dist: tiktoken>=0.7
Requires-Dist: tomli-w>=1.0
Requires-Dist: tomli>=2.0; python_version < '3.12'
Requires-Dist: websockets>=13.0
Provides-Extra: all
Requires-Dist: beautifulsoup4>=4.12; extra == 'all'
Requires-Dist: brainflow<6,>=5.22; extra == 'all'
Requires-Dist: chromadb>=0.5; extra == 'all'
Requires-Dist: easyocr>=1.7; extra == 'all'
Requires-Dist: faiss-cpu>=1.7.0; extra == 'all'
Requires-Dist: kokoro>=0.9.4; extra == 'all'
Requires-Dist: mediapipe>=0.10.11; extra == 'all'
Requires-Dist: mne<2,>=1.10; extra == 'all'
Requires-Dist: openai-whisper>=20231117; extra == 'all'
Requires-Dist: opencv-python>=4.9.0.80; extra == 'all'
Requires-Dist: openpyxl>=3.1; extra == 'all'
Requires-Dist: paramiko>=3.4; extra == 'all'
Requires-Dist: pillow>=10.0; extra == 'all'
Requires-Dist: playwright>=1.40; extra == 'all'
Requires-Dist: pocket-tts>=1.0; extra == 'all'
Requires-Dist: pyautogui>=0.9; extra == 'all'
Requires-Dist: pylsl<2,>=1.17; extra == 'all'
Requires-Dist: pynput>=1.7; extra == 'all'
Requires-Dist: pypdf>=4.0; extra == 'all'
Requires-Dist: pyperclip>=1.8; extra == 'all'
Requires-Dist: python-docx>=1.0; extra == 'all'
Requires-Dist: secretstorage>=3.3; (sys_platform == 'linux') and extra == 'all'
Requires-Dist: sentence-transformers>=2.2.0; extra == 'all'
Requires-Dist: soundcard>=0.4.3; (sys_platform == 'win32') and extra == 'all'
Requires-Dist: sounddevice>=0.4; extra == 'all'
Requires-Dist: soundfile>=0.12; extra == 'all'
Requires-Dist: wasmtime>=18.0; extra == 'all'
Requires-Dist: zeroconf>=0.131; extra == 'all'
Provides-Extra: automation
Requires-Dist: pillow>=10.0; extra == 'automation'
Requires-Dist: pyautogui>=0.9; extra == 'automation'
Requires-Dist: pyperclip>=1.8; extra == 'automation'
Provides-Extra: browser
Requires-Dist: playwright>=1.40; extra == 'browser'
Provides-Extra: dev
Requires-Dist: mne<2,>=1.10; extra == 'dev'
Requires-Dist: pillow>=10.0; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.24; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: ruff>=0.5; extra == 'dev'
Provides-Extra: documents
Requires-Dist: beautifulsoup4>=4.12; extra == 'documents'
Requires-Dist: openpyxl>=3.1; extra == 'documents'
Requires-Dist: pypdf>=4.0; extra == 'documents'
Requires-Dist: python-docx>=1.0; extra == 'documents'
Provides-Extra: full
Requires-Dist: chromadb>=0.5; extra == 'full'
Requires-Dist: faiss-cpu>=1.7.0; extra == 'full'
Requires-Dist: pyperclip>=1.8; extra == 'full'
Requires-Dist: secretstorage>=3.3; (sys_platform == 'linux') and extra == 'full'
Requires-Dist: sentence-transformers>=2.2.0; extra == 'full'
Requires-Dist: zeroconf>=0.131; extra == 'full'
Provides-Extra: llamacpp
Requires-Dist: llama-cpp-python>=0.3; extra == 'llamacpp'
Requires-Dist: pynvml>=11.5; extra == 'llamacpp'
Provides-Extra: network
Requires-Dist: zeroconf>=0.131; extra == 'network'
Provides-Extra: neural
Requires-Dist: brainflow<6,>=5.22; extra == 'neural'
Requires-Dist: mne<2,>=1.10; extra == 'neural'
Requires-Dist: pylsl<2,>=1.17; extra == 'neural'
Provides-Extra: pty
Requires-Dist: ptyprocess>=0.7; (sys_platform != 'win32') and extra == 'pty'
Provides-Extra: ssh
Requires-Dist: paramiko>=3.4; extra == 'ssh'
Provides-Extra: supervision
Requires-Dist: pynput>=1.7; extra == 'supervision'
Provides-Extra: vision
Requires-Dist: easyocr>=1.7; extra == 'vision'
Requires-Dist: mediapipe>=0.10.11; extra == 'vision'
Requires-Dist: opencv-python>=4.9.0.80; extra == 'vision'
Requires-Dist: pillow>=10.0; extra == 'vision'
Provides-Extra: voice
Requires-Dist: kokoro>=0.9.4; extra == 'voice'
Requires-Dist: openai-whisper>=20231117; extra == 'voice'
Requires-Dist: pocket-tts>=1.0; extra == 'voice'
Requires-Dist: soundcard>=0.4.3; (sys_platform == 'win32') and extra == 'voice'
Requires-Dist: sounddevice>=0.4; extra == 'voice'
Requires-Dist: soundfile>=0.12; extra == 'voice'
Provides-Extra: wasm
Requires-Dist: wasmtime>=18.0; extra == 'wasm'
Description-Content-Type: text/markdown

# Heliox OS Daemon

Python backend for the Heliox OS AI System Control Agent. It provides the
append-only experience ledger, durable task loop, temporal context, companion
coordination, hybrid world model, verified online learning, strategy/evolution
harnesses, 21-specialist mesh, Planner/Executor/Verifier, security layers, and
the 157-action system interface.

The optional neural-intent research path runs acquisition and decoding in the
separately authenticated `pilot-neurod` sidecar. It supports synthetic,
playback, BrainFlow, and local LSL sources, but can emit only signed bounded
intent for dedicated navigation or compiled reversible Tier 0/1 goals. It has
no physical, destructive, arbitrary-command, or approval authority. See
[Neural Intent Research Controls](../docs/NEURAL_INTENT.md).

```bash
pip install "pilot-daemon[neural]"
pilot-neurod --source synthetic --synthetic-frequency 12
pilot-neurod-benchmark brainflow-synthetic --seconds 2
pilot-neurod-benchmark eegbci --subject 1 --runs 6 10 14
```

The benchmark commands need no headset. Their JSON output identifies evidence
as `synthetic` or `recorded_eeg`; neither result is live brain-control evidence.

Typed and spoken requests enter the same observable interaction state machine.
Interactive browser and desktop goals use a bounded observe, act, and verify
loop with fresh screen evidence, target-window re-acquisition, and explicit
no-progress limits. Native application launch is fail-closed and platform
specific: Windows resolves installed-app records and shortcuts, macOS uses
Launch Services, and Linux accepts verified executables or desktop entries.
Issuing a launch command is never treated as proof that the user's goal is
complete.

Bounded read-only health-review requests use the local
`system_health_review` action to collect current CPU, memory, disk, battery,
and process evidence without a model call. Cloud planning supports Gemini,
OpenAI, OpenRouter, Claude, and Meta; OpenRouter accepts automatic routing or
an exact catalog model ID such as DeepSeek V4 Pro. Provider keys remain in the
operating-system credential store.

Planning can also use an existing Codex/ChatGPT or Claude Code subscription
through that provider's official CLI. Heliox delegates login to the CLI and
never reads its OAuth state. The adapter is text-only and cannot execute tools:
Codex runs ephemeral in a sterile read-only directory with user rules ignored;
Claude runs without tools, browser integration, slash commands, or persistent
sessions. Returned plans still pass through the normal policy, approval,
execution, and verification pipeline.

An opt-in benchmark measures this path without executing actions:

```bash
python benchmarks/subscription_planning_suite.py --provider codex
```

The report separates Heliox prompt size from provider input, cached input,
uncached input, output, and latency. Running it consumes the provider account's
subscription allowance.

See the [main README](../README.md) and
[Architecture](../docs/ARCHITECTURE.md) for the full runtime contract.

## SSH Agent (Remote Host Execution)

Heliox includes an optional `SshAgent` for `ssh_command` and `ssh_script`
actions against preconfigured, allowlisted hosts through Paramiko.

### Install

```bash
pip install "pilot-daemon[ssh]"
```

### Configure allowed hosts

Open **Settings > Integrations > SSH**, add a named host alias, hostname, port,
username, private-key PEM, and optional passphrase, then use **Test connection**.
Strict known-host verification is enabled by default. The authenticated daemon
stores only non-secret host metadata in `config.toml`; private keys and
passphrases go directly to Windows Credential Manager, macOS Keychain, or a
Secret-Service-compatible Linux keyring. Raw credential-storage RPCs are not a
supported user setup path.

Keys and passphrases are never logged and are retrieved only when needed. SSH
actions retain the dedicated `ssh_agent` gateway profile, exact host allowlist,
confirmation, irreversibility, audit, and verification behavior.
