Open Source Radar — October 9: plugins, sandboxes, tokens

Today's open-source signal is infrastructure rather than hype: Microsoft's code sandbox reaches 1.0, Anthropic's knowledge-worker plugins keep climbing, a beloved token counter flips its default, and LocalLLaMA squeezes a usable 2B model into about 700 MB.
knowledge-work-plugins (Python, ~27,900 stars, Apache-2.0) — Anthropic's repository of role-shaped plugins for Claude Cowork is the top AI repository on today's daily trending page, and the stars keep coming: roughly 2,100 more than when we checked it on September 28. Each plugin encodes a whole job function — sales, customer support, finance, legal, data, bio-research — as markdown and JSON: skills the model loads automatically, commands, and MCP connectors into tools like Slack and HubSpot, so adapting one to your company means editing text rather than writing code. The repo's posture hardened recently too: it now auto-closes out-of-scope external pull requests, which tells you this is a curated Anthropic surface, not a community grab bag. Reach for it when you want an entire role living in the assistant, not just a single task.
mxc (Rust, ~1,900 stars, MIT) — Microsoft's MXC is a sandboxed execution container built for one category of code: untrusted input, which on an AI machine means model output, plugins, and tools. The 1.0 SDK shipped October 7 and the repo hit Hacker News today. You embed the SDK in your app, declare policy in JSON — what the workload may read, write, and reach over the network — and it picks a platform-appropriate backend (process sandbox on Windows, Bubblewrap on Linux, Seatbelt on macOS, with micro-VMs as a heavier option) before launching the code inside. The pitch is containment as a library instead of a Dockerfile, and use it the moment an agent's shell commands run somewhere that isn't already a disposable container.
ttok (Python, ~400 stars) — Simon Willison's token counting and truncation tool hit version 1.0 today, and the reason for the version bump is the story: it now defaults to the GPT-5 family tokenizer instead of GPT-4's. OpenAI hasn't confirmed which tokenizer GPT-6 actually uses — there's an open issue about it — but Willison cites an experiment showing the GPT-5.5 through GPT-6 models report identical token counts across a shared fixture set, which is why he's comfortable making the switch. It's the quickest way to answer "how many tokens is this?" before you paste anything into a context window, and if you manage context by eye, you're guessing.
Qwen3.5-2B-RCOL (Hugging Face, Apache-2.0) — A quantization release buzzing on LocalLLaMA today: dynamic low-bit builds of Qwen's 3.5-2B model that fit in roughly 700 MB of memory. The RCOL method — an experimental cut-down version of ISTALab's RCO technique — decides which quant type each part of the model gets by actually measuring how far each choice pushes the output away from the full-precision original, instead of trusting the usual per-layer error proxies that rank tensors backwards once compression gets aggressive. Per the model card's own measurements, its tightest build hits a KL divergence of 0.25 against the full model at about the same size where a standard quant scores 1.49 — a claimed gap wide enough to take seriously, though the numbers are the author's, not an independent benchmark. Use it to keep a small model running on hardware where every megabyte counts.
Worth watching this week.
Microsoft's sandbox, Anthropic's plugins, Simon's tokenizer — which of these earns a slot in your stack first? Tell us in the comments. Sources: Knowledge Work Plugins (GitHub) · MXC (GitHub) · ttok (GitHub)




