A group of open projects is packaging the runtime pieces around agents: workers, sandboxes, computer-use surfaces, and enterprise skills.
OpenWorker, AutoSaddler, OpenComputer, and ClaudeForce approach different layers, but together they show why a model endpoint is not an operating system. Real work needs an environment, tools, credentials, procedures, state, and a boundary around side effects.
These projects belong in a validation radar rather than a winner list. The next step is hands-on testing against one bounded task: inspect permissions, isolation, observability, recovery, and artifact output. A toolkit earns trust when its failure states are as visible as its demo path.