From avatar file to running agent
three.ws separates an avatar's 3D body from an agent runtime that supplies identity, memory, skills and a tool loop. The published system supports text or image to 3D, rigging, animation, voice, screen interaction and browser-based studios, with model routes spanning open and commercial providers.
The project reports Apache-2.0 licensing, 101 npm packages, 72 registered MCP servers, 60 portable skills and roughly 1,750 test files as of August 25. Those project-maintained figures should be verified against the repository and registries when used for procurement or research.
The guard chain matters most
An embodied agent becomes consequential when it can browse, control a screen or move funds. three.ws says every fund-moving call passes seven enforcement layers covering blacklists, human intervention, capabilities, permissions, trade rules and budget constraints.
That is the right architectural question, but implementation quality still matters. Reviewers should test what happens when a layer times out, when an instruction conflicts with a spending limit and when an agent receives malicious content from a webpage or another agent.
How to evaluate the release
Start with inspectable artifacts: load a published glTF avatar, run a local skill, inspect the MCP manifest and trace one tool call through its permissions. Do not treat marketplace listings or package count as proof that every component is production-ready.
Visit the AINewsInu homepage and AI Agents coverage for open-source analysis. The broad surface means buyers should adopt one bounded capability at a time and preserve independent logs, budgets and kill switches.
Sources & further reading
Social-media activity is treated as a signal of attention, not proof. Product claims are attributed to the linked publisher or announcement.