$ku1dK0r3

Autonomous mission runtime · Rust · proprietary

Agents reason. $ku1dK0r3 controls the mission.

An operator states an outcome; $ku1dK0r3 runs tasks as attempts, records every event, and stops when the outcome is reached or the mission is abandoned. Agents propose actions as data — the runtime authorizes, executes, and journals every decision. A surface session is a view; the mission is canonical.

repository read the thesis ↓ repository is private during V5

real output, elisions marked … — one write authorized and receipted; one path-escape denied before execution

001

A small state machine plus a narrow agent loop

v4 grew by accretion and hid its own control flow inside an LLM. v5 starts over so the control flow is code. Four roles, and no fifth:

the runtime
Owns missions, tasks, and attempts. Decides what work exists, what may run, and when the mission is over. That decision is Rust, not a prompt.
the agent
Works inside one attempt. Proposes actions as data; never executes a side effect itself. Replaceable and non-authoritative.
integrations
Adapters behind the execution port and the model trait. The runtime holds them; the agent never does. Adding a provider is wiring, not a new crate.
profiles
Carry domain knowledge. The runtime has none.

rule — if a feature does not fit one of those four, it does not ship until the thesis is amended.

002

The authority spine

Every side effect travels one chain. Nothing bypasses it.

Mission → Task → Attempt → Agent
  → ActionRequest              (untrusted data)
  → Runtime authorization      (lifecycle, bounds, capability, grant, scope, budget)
  → [ Denied                   (journaled; no execution id, no receipt)
    | AuthorizedAction         (journaled before dispatch; mints execution id)
      → Execution → InvocationResult
        → Observation + ExecutionReceipt ]
  • An agent may request an action. It does not authorize or execute it.
  • An integration's result is a claim. The runtime derives the observation from it.
  • A receipt proves that an execution happened under a recorded authorization. It does not prove authority, meaning, or truth.
  • A model response is not mission truth.

State lives in an append-only journal. skuld inspect replays it read-only, re-derives the state, and re-checks every request → authorization → dispatch → receipt chain — the transcript above is that replay, not a dashboard's memory of one.

003

Ruled out by the thesis

  1. A coordinator model that emits control decisions as prose the runtime then parses. The runtime decides; the model proposes work inside an attempt.
  2. Retry by mutation. A failed attempt stays failed. The next try is a new attempt with its own id.
  3. One binary per concern. v4 had skuld, skuld-executor, skuld-swarm-mcp, skuld-gatekeeper, skuld-edge, and more. v5 has skuld.
  4. Default domain behavior. A fresh install does nothing security-specific.
  5. Vendor names in the core. skuld-core, skuld-runtime, and skuld-agent name no provider. Providers are adapters, wired in at the edge.
004

Status: pre-release, contract-first

v5 shares no code and no history with v4. Milestones land behind reviewed, frozen architecture decision records — the contract clears review before code touches the boundary.

MilestoneStateWhat shipped
V5-M1 · authority spine CLOSED mission create / task add / grant issue / run / inspect; deterministic scripted agent; confined filesystem integration; append-only journal with replay-verified chains.
V5-M2 · mission continuity CLOSED daemonless journal continuity; local mission host over a versioned Unix-socket IPC; hosted execution; crash, reconnect, and recovery closure.
V5-M3 · intelligence boundary IN PROGRESS ADR 0007 accepted. The model boundary is frozen contract-first: raw model output is untrusted data until the runtime validates it. No model adapter ships until the boundary closes.

Not built yet, by design: model adapters, evidence admission and findings, profiles that do more than name themselves.

5crates 1binary 0async runtimes — std only 1.89MSRV
005

Decisions on record

Every architectural boundary is frozen in a reviewed ADR before implementation.

  1. 0001v5 boundaryAn orphan branch: no v4 commit is its ancestor. The break is visible in git log.
  2. 0002integration modelIntegrations are adapters behind the execution port and the model trait; the core crates name no vendor.
  3. 0003agent runtimeAn agent executes work within an attempt — replaceable, non-authoritative, bounded by grants.
  4. 0004authority spineEvery side effect is authorized before dispatch; the decision is journaled either way.
  5. 0005mission continuityMission state survives surfaces, processes, and crashes. A surface session is a view.
  6. 0006local host + IPCA versioned, bounded Unix-socket protocol. Observation is read-only; mutation enters the single authority path.
  7. 0007intelligence boundaryNo model, provider, or agent loop becomes an authority side door; intelligence results are validated before they become mission consequences.

ADRs live in docs/architecture/ in the repository. The repository is private during V5.