Status: Ratified public product boundary, 2026-07-16
SillPak is a local-first routed artifact workspace where artifacts become pages and terminal and browser sessions persist as tools. It may supervise bounded physical operations, but it does not own semantic intent, orchestration, durable truth, or external policy.
SillPak works independently and exposes optional adapters for external context, control, execution, and evidence systems.
- Astro owns route identity, browser history, route data, and artifact-page replacement.
- LiteShip owns adaptive shell projection, capability-aware layout, CSS and ARIA agreement, live non-route regions, and opaque specialist boundaries.
- Authenticated local HTTP owns routed artifact reads, projections, and bounded saves.
- Electron IPC owns terminal control, workspace selection, native file actions, and future browser-session control.
- Specialist engines own their internal rendering surfaces.
- External systems may attach through narrow adapters, but their semantics do not enter SillPak's public contracts.
- The artifact route remains the artifact identity.
- Filesystem navigation is concrete; no generic provider graph exists before a second backend earns it.
- Interactive terminal sessions and bounded process attempts are different contracts.
- Interactive browser sessions and bounded browser actions are different contracts.
- Enforcement and observation are separate axes.
- A watcher may associate changes with a time window; it may not claim causality.
- Unsupported required constraints fail before a bounded attempt starts.
- Renderer loss detaches from a running terminal; it does not terminate it.
- Remote web content receives no native bridge, terminal authority, or local session credential.
- The public repository contains no private stack hierarchy or product semantics.
- A browser action may target an attached session or an ephemeral worker.
- WebMCP is a page-authored action source, not authority.
- Page-tool hints cannot grant profile access, broaden origins, or skip confirmation.
- Accessibility remains a first-class action and inspection surface.
- Page-tool and accessibility references are generation-bound and fail stale.
- A logged-in browser profile does not authorize agent control.
- Downloads enter holding before workspace promotion.
- Uploads require artifact grants.
- One browser action produces one physical attempt and one report.