I'm an agentic systems engineer. Most people dotfile their setup and call it done. I build an operating layer that proves it works — a repo that owns the shell, the skills, the MCP servers and the tools, with invariants a verifier enforces — and a four-node agent network that talks to itself over A2A so the work actually moves.
Every number below is measured from the live system by
bin/telemetry.py and injected at build time. Nothing here is a screenshot or a
claim — if the machine is idle, the numbers say so.
Not a diagram of an idea — a network that runs. Two agents speak System 2 (do the work); a decision API speaks System 1 (pick, with a probability). The split is deliberate: System 2 agents are good at building and bad at deciding, so decisions get routed to something that returns a number instead of an opinion.
~/.hermes/a2a_audit.jsonl:
— · — per-task conversations persisted
~/Work/os declares itself the sole writer for shell environment, agent skills,
MCP servers, hooks and tools. What makes it more than a dotfiles repo is the second half:
invariants, and a verifier that fails the build when they break.
A safety property that is only enforced by an agent's good intentions is not a property.
Every symlink in the consumer trees is declared once, with an explicit policy. The default
is refuse — a real file is never overwritten, because that's a human decision,
not something an apply loop resolves.
Six invariant checks: no secrets, no runtime state, no symlink into a throwaway directory, every declared link resolves, the shell suite passes, git hygiene. It is designed to be runnable by an unsupervised agent.
The suite exists because zsh -n passed over two real bugs: local path
silently rewriting PATH for the rest of a function, and command cd
exiting 127 under zsh. Both parsed clean and both broke at runtime.
Every server declared exactly once. The registry names the three that are declared in multiple trees in incompatible shapes — a local token-authenticated process here, a hosted OAuth endpoint there, so they don't see the same projects or the same audit trail.
Agent-to-agent sounds like a feature until you implement it. Three things had to be true before anything was exchanged, and each one failed first.
# a real exchange — peer identity comes from the credential, never the body curl -s -X POST http://127.0.0.1:9900/ \ -H "Authorization: Bearer $A2A_COMM_TOKEN" \ -H 'Content-Type: application/json' \ -d '{"jsonrpc":"2.0","method":"message/send","params":{…}}'
Under a multiplexed gateway the agent resolves peers from a per-profile secret scope, not the process environment. The first token I generated lived in a file nobody read — the peer was correctly rejected as unauthorized until it was registered.
Inbound peer text is framed as data from another agent and defanged against prompt-injection markers. Outbound text is scrubbed for credentials and email addresses before it leaves. A remote peer cannot reach the operator's slash commands.
The interesting part is only interesting because these existed first.
Every item here was a real failure during one build night, found by a check that was run rather than reasoned about. I've kept them because the failure log is the more useful artifact than the success log — it's the part you can't fake.
Public repositories. The interesting ones are on GitHub under moughamir.