a0BLOCK
A0: the programming language built for AI, not for people. Compiler in TypeScript; programs compile to native code, wasm, JVM, .NET, Metal, and SystemVerilog.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The programming language built for AI, not for people. a0lang.com · Docs
A0 is a compact, exactly specified language that models write and edit through revision-checked structured edits. A model reads only what an edit touches, writes only the changed lines, and nothing invalid lands. One program compiles to native machine code (A0's own AArch64 code generator, or C), the browser (wasm32), JavaScript, the JVM, .NET, Metal GPU kernels, and clocked SystemVerilog, and every target is verified against one oracle.
Measured on the repository's benchmarks (Apple M3, 8 cores, results/*.json). The machine was not quiet: results/exec-benchmark.json records a 1/5/15-minute load average of 6.4-8.0 for the main and arm64 runs and 32-40 for the JavaScript remeasurement; a quiet-machine rerun is pending:
The site a0lang.com is itself two A0 programs (site/page.a0, site/docs.a0).
See DESIGN.md for intent and semantics, MODEL_GUIDE.txt for the AI-facing language instructions, STATUS.md for the current results, loss ledger, known limits, and next actions (session history in docs/history/), and results/ for machine-readable evidence.
Install
A0 is a single self-contained binary: no Node, no Bun.
# macOS / Linux: Homebrew (this repository is the tap; no separate tap repo
5677cec7d82cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add a0 --env A0_KEY_LEGEND=${A0_KEY_LEGEND} -- npx -y [email protected]{
"mcpServers": {
"a0": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"A0_KEY_LEGEND": "${A0_KEY_LEGEND}"
}
}
}
}Exposed tools (7)
4 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
a0_apply | write | |
a0_check | read | |
a0_emit | read | |
a0_open | read | |
a0_program | read | |
a0_run | write | |
a0_save | write |
Trust audit
BLOCKgrade F · trust 58/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (22)
return exec(fn, args, options);
env.set(node.id, exec(callee, node.args.map(read), options));
state = exec(body, [state, i, ...extra], options);
if (exec(pred, [state, i, ...extra], options) !== true) break;
state = exec(body, [state, i, ...extra], options);
docs.wasm
page.wasm
.pre-commit-hooks.yaml
.vscodeignore
readFileSync(new URL(`../../${path}`, import.meta.url), 'utf8');['up.a0', '../../x.a0'],
import type { Type, Value } from '../../src/core.js';import { runTool } from '../../src/toolchain.js';import type { Type, Value } from '../../src/core.js';tree-sitter-cli
vscode-languageclient, @types/node, @types/vscode, @vscode/vsce, esbuild, typescript
@modelcontextprotocol/sdk, @noble/hashes, geist, vscode-languageserver, vscode-languageserver-textdocument, z3-solver, zod, @anthropic-ai/mcpb
<main id="app" data-program="/docs.wasm" aria-live="polite"><header class="top"><nav class="nav"><a class="brand pixel" href="/">A0</a><div class="links"><a href="/docs/">Docs</a><a href="/#benchmarks
**Decision by the rule** (`results/shipped.json`; surface the guide to MCP-only clients only if `B0` wins against `T0` on both model sizes: acceptance not lower, tokens per accepted edit lower with th
You do not need write access, a paid service, an API key or a particular machine. Everything the checks need is free and runs locally.
curl -fsSL https://raw.githubusercontent.com/Joe-Simo/a0/main/install.sh | sh
curl -fsSL https://raw.githubusercontent.com/Joe-Simo/a0/main/install.sh | sh
Gates applied: no_behavioural_pass.
5677cec7d82cfull audit observations/trust-audit/mcp-server/joe-simo__a0.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 5677cec7d82c | BLOCK | F | 58 | first audit |
Questions
What is the a0 MCP server?
A0: the programming language built for AI, not for people. Compiler in TypeScript; programs compile to native code, wasm, JVM, .NET, Metal, and SystemVerilog.
What tools does a0 expose?
7 in total: 4 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is a0 safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (58/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does a0 need?
It reads A0_KEY_LEGEND from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does a0 run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as a0 at 0.8.16.
How current is this page?
The grade is for one exact copy of the source (5677cec7d82c), read on 2026-10-07. The repository is watched and re-audited when it changes.