m7r · Mohamed Moughamir

A machine that
verifies itself.

I'm an agentic systems engineer. Most people dotfile their setup and call it done. I build an operating layer that proves it works — a repo that owns the shell, the skills, the MCP servers and the tools, with invariants a verifier enforces — and a four-node agent network that talks to itself over A2A so the work actually moves.

Arch Linux · Omarchy A2A · MCP · Hermes · OpenCode Bun · TypeScript · Python · Terraform telemetry: loading
01

This machine, right now

Every number below is measured from the live system by bin/telemetry.py and injected at build time. Nothing here is a screenshot or a claim — if the machine is idle, the numbers say so.

02

Four nodes, one contract

Not a diagram of an idea — a network that runs. Two agents speak System 2 (do the work); a decision API speaks System 1 (pick, with a probability). The split is deliberate: System 2 agents are good at building and bad at deciding, so decisions get routed to something that returns a number instead of an opinion.

System 2
coordination
openclaude
Reaches this agent over A2A as a named peer. Coordination and external research.
System 1
decision
jev
BeatAPI Decisions API. Returns a number, a named option, or a position on a scale — each with a probability. It never writes prose, which is the point.
System 2 · you are here
orchestration · memory
hermes · omnizya-agent
Session recall over 1,200+ sessions, kanban, cron, MCP, delegation, and the vault this site is written into.
System 2
build · review · test
opencode
Implementation over A2A JSON-RPC. Wrote the MCP registry and the skills inventory — and corrected me twice when my own claims were wrong. Note: opencode does not appear in the A2A audit log; it is reachable over A2A but not yet a recorded peer.
—
A2A messages inbound
—
A2A messages sent
peers observed in ~/.hermes/a2a_audit.jsonl: — · — per-task conversations persisted
03

OS — a single-writer layer that checks itself

~/Work/os declares itself the sole writer for shell environment, agent skills, MCP servers, hooks and tools. What makes it more than a dotfiles repo is the second half: invariants, and a verifier that fails the build when they break. A safety property that is only enforced by an agent's good intentions is not a property.

Single writer, declared link graph links.yaml

Every symlink in the consumer trees is declared once, with an explicit policy. The default is refuse — a real file is never overwritten, because that's a human decision, not something an apply loop resolves.

consumer trees · — skills adopted · — rulebooks + README

Verification, not vibes os-verify

Six invariant checks: no secrets, no runtime state, no symlink into a throwaway directory, every declared link resolves, the shell suite passes, git hygiene. It is designed to be runnable by an unsupervised agent.

current: —

A shell suite with teeth test.sh

The suite exists because zsh -n passed over two real bugs: local path silently rewriting PATH for the rest of a function, and command cd exiting 127 under zsh. Both parsed clean and both broke at runtime.

— lines · runs under bash and zsh

One MCP registry, drift made visible mcp/registry.yaml

Every server declared exactly once. The registry names the three that are declared in multiple trees in incompatible shapes — a local token-authenticated process here, a hosted OAuth endpoint there, so they don't see the same projects or the same audit trail.

— servers · — drifted across trees
04

A2A is a protocol, not a demo

Agent-to-agent sounds like a feature until you implement it. Three things had to be true before anything was exchanged, and each one failed first.

# a real exchange — peer identity comes from the credential, never the body
curl -s -X POST http://127.0.0.1:9900/ \
  -H "Authorization: Bearer $A2A_COMM_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","method":"message/send","params":{…}}'

Identity is the credential

Under a multiplexed gateway the agent resolves peers from a per-profile secret scope, not the process environment. The first token I generated lived in a file nobody read — the peer was correctly rejected as unauthorized until it was registered.

a2a_audit.jsonl · — records · — contexts

Untrusted by construction

Inbound peer text is framed as data from another agent and defanged against prompt-injection markers. Outbound text is scrubbed for credentials and email addresses before it leaves. A remote peer cannot reach the operator's slash commands.

peers seen: —
05

The habits underneath

The interesting part is only interesting because these existed first.

—
agent sessions
—
messages exchanged
—
scheduled jobs
—
kanban tasks
—
agent skills
—
hermes profiles
Every session and message is retrievable. That's the actual product of a memory layer: the machine can be asked what it decided and when.
06

What went wrong, published

Every item here was a real failure during one build night, found by a check that was run rather than reasoned about. I've kept them because the failure log is the more useful artifact than the success log — it's the part you can't fake.

The through-line: a green check is not proof. Three of these were endorsed by something that reported success.
07

Selected work

Public repositories. The interesting ones are on GitHub under moughamir.