What did OpenAnolis publish on 10 October?

The dated object is the Alibaba Cloud Community blog post stamped October 10, 2026, titled “People and Agents Finally Share One CLI — Announcing ANOLISA v1.0,” bylined OpenAnolis. The lede calls ANOLISA v1.0 an Agentic OS on Alibaba Cloud Linux that lets humans and AI agents securely share a single CLI while managing skills, tokens, and memory.

ANOLISA is framed as a layer on top of Alibaba Cloud Linux—a “system housekeeper” for agents—rather than a replacement distribution. The post says it adds native entry points, capabilities, and guardrails so agents can run with formal standing similar to a human user on the same machine. That framing matters for operators: this is an OS-layer product story, not a chat-app release.

Shared shells and agent sandboxes are a crowded category this week. For NVIDIA’s runtime-control angle, see OpenShell for agent runtime controls. For an AWS sandbox that keeps agent tools off the host desktop, see Strands Box on Dogwood.

How does the shared CLI (cosh) work in the post?

The pain point the authors describe is familiar: an agent installs dependencies, edits configs, and batches files in its own session while a human sits in a separate terminal with no shared state. Taking over means losing context the agent already built. Alternatively, a chat box replaces the shell and forces users to abandon aliases and muscle memory.

ANOLISA v1.0’s answer is Copilot Shell, branded cosh. The post says bash/zsh stay as they are; agent steps run in the same session in front of the user; natural language and the command line share one context. When a command runs normally, cosh stays out of the way. When a command fails, it steps in to classify permission problems, typos, or missing commands. A getting-started line says one `cosh-switch` command moves you onto the upgraded shell in Alibaba Cloud Linux 4 Agentic Edition.

We opened the linked help URL for cosh and received an empty body (likely an interstitial or captcha). Treat operational install steps as vendor documentation to re-check in a browser session, not as commands we executed.

A Bash shell session in a terminal window showing command history and a prompt. No people appear.
Bash session screenshot by Autechre, CC BY 4.0 via Wikimedia Commons (File:Bash_Session.png). No people appear. Archival shell UI; not ANOLISA’s cosh and not an Alibaba Cloud console. Photo: Alqiwa. CC BY 4.0 · Cropped and resized.

What else ships besides the shared shell?

Skill supervision moves from “remind the agent to behave” to system-enforced policy. Components named in the release table include skillfs, AgentSight, and AgentSecCore. The system decides which Skills an agent can see, which stay hidden, and which roll back to a trusted earlier version. Install or change a Skill and the post says the system rescans automatically. Responses to threats include block, rollback, one-time confirm, or long-term trust. A security dashboard puts LLM calls, tool executions, and blocks on one timeline.

Token comparison mode (component Tokenless) runs the same session and task twice—compression off and on—and shows per-step and overall token deltas. The post’s Qwen Code claim is specific: “real-world tests on mainstream coding sessions cut wasted tokens by 30%,” with out-of-the-box support and no manual configuration. That figure is Alibaba/OpenAnolis’s; we did not reproduce it.

Workspace snapshots (ws-ckpt) add scheduled automatic snapshots, rollback preview of file differences, and plugin install/uninstall. An incompatible change renames the snapshot identifier parameter to `-s` / `--snapshot` (with `-i` retained as a hidden alias). Memory migration (agent-memory) packages an agent’s built-up memory for handoff to another agent or model, with multi-agent isolation and privacy masking by default.

ANOLISA v1.0 components from the 10 October OpenAnolis post, not our install
CapabilityComponent namedWhat the post claimsWhat that is not
Shared terminalCopilot Shell (cosh)One session for human and agent; failure hintsA new programming language or IDE
Skill securityskillfs / AgentSight / AgentSecCoreSystem-enforced show/hide/rollback; Codex CLI support notedPrompt-only “please be safe” guidance
Token compareTokenlessDry-run compression compare; 30% Qwen Code claimAn independent third-party bill audit
Snapshotsws-ckptScheduled snaps, rollback preview, `-s` flagFull VM or cluster disaster recovery
Memory handoffagent-memoryPackage memory across agents; isolation by defaultA public model-weight download
Screenshot of a terminal client main window with menus and a text session area. No people appear.
ZOC main-window screenshot released as CC0 via Wikimedia Commons (File:Zoc_Main-Window_Screenshot.png). No people appear. Contextual terminal-client UI; not ANOLISA and not cosh. Photo: Shimodax. CC0 · Cropped and resized.

Who can use it, and what are the limits?

Availability in the post is tied to Alibaba Cloud Linux 4 Agentic Edition, with the stack based on Alibaba Cloud Linux 4.0.3.0. Readers outside that distribution should not assume a drop-in package for generic Ubuntu or RHEL without checking Alibaba’s release notes. The post points to ANOLISA Release Notes and a cosh getting-started help page; as noted, our automated fetch of the cosh help URL returned no usable body text.

System-enforced skill gates matter because prompt-only agent safety is easy to bypass. For a credential-theft demo through a coding CLI, see ProjectDiscovery’s backdoored-model Codex CLI report. For packaging tools as MCP skills that an agent client can load, see Cloudflare API MCP skills.

Limits to keep in the vendor column: we have not measured whether cosh’s failure hints are accurate, whether Skill rescans catch malicious packages in the wild, or whether the 30% Qwen Code token cut holds on workloads outside the sessions Alibaba describes. Memory migration’s privacy masking and isolation claims are architectural descriptions, not red-team results we ran.

What should a Linux agent team verify first?

If you already run agents on Alibaba Cloud Linux, the practical check list from the blog is concrete: enable Agentic Edition where offered, run `cosh-switch`, execute a known-good command to confirm the shell stays quiet, then force a typo and see whether the failure classifier matches your expectations. Separately exercise Skill install, a deliberate policy block, and the security dashboard timeline.

For token comparison, run one coding session with compression off and on using the post’s dry-run path before changing production budgets. Keep the Qwen Code 30% line as a vendor datapoint until you log your own cacheRead/cacheWrite or tokenizer counts. For snapshots, confirm scheduled intervals and preview a rollback on a disposable workspace before trusting restore points on shared hosts.

This article is an evidence review of the OpenAnolis community blog page we opened on 10 October 2026. We did not provision an Alibaba Cloud Linux instance, install ANOLISA, or migrate agent memory.

A wooden desk with a laptop, notebook, and coffee cup, photographed from above. No people appear.
Desk working technology photograph by Intel Free Press, CC0 via Wikimedia Commons (File:Apple-desk-working-technology_(24031281740).jpg). No people appear. Contextual workspace photo; not Alibaba Cloud offices and not an ANOLISA install. Photo: www.Pixel.la Free Stock Photos. CC0 · Cropped and resized.

Common questions

Is ANOLISA a new large language model?

No. The 10 October post presents it as an Agentic OS layer on Alibaba Cloud Linux—shared CLI, skill security, token tooling, snapshots, and memory—not as a foundation-model release.

Did Ai Lookout verify the 30% Qwen Code token savings?

No. That percentage is stated in the OpenAnolis post for Qwen Code coding sessions. Treat it as a vendor claim until you measure your own workloads.

Where is ANOLISA available?

The post says ANOLISA v1.0 is active in Alibaba Cloud Linux 4 Agentic Edition, based on Alibaba Cloud Linux 4.0.3.0, with `cosh-switch` as the entry to the upgraded shell. Confirm current SKUs in Alibaba’s release notes.

THE TAKEAWAY

What to remember

ANOLISA v1.0 is a 10 October OpenAnolis announcement for a shared human/agent CLI and OS-side skill, token, snapshot, and memory controls on Alibaba Cloud Linux. Use it as a product brief; keep performance and security percentages in the vendor column.

Sources & further reading

  1. People and Agents Finally Share One CLI — Announcing ANOLISA v1.0 ↗
How this story was made

Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.

Our editorial standards
Back to all stories