Launched this week
JarvisCore
Build agents as peers in a mesh network with zero-trust
64 followers
Build agents as peers in a mesh network with zero-trust
64 followers
JarvisCore is a runtime where AI agents operate as a fleet of equal peers. Agents discover one another by capability, execute tasks from a shared ledger, and authenticate to every external service through a zero-trust broker, never with their own keys.






@askmuyukani The bounded memory idea caught my attention. Keeping memory useful without letting it grow forever is a tough problem to solve.
@mishaal_rashid yes that is a tough one. we are still experimenting the scale of what we have. We are using old ebbinghaus forgetting curve (mimicking how 'theoretically' human forget)
@askmuyukani That's a cool way to think about it. Letting unused stuff fade feels closer to how a person works than just cutting off old memory. Good luck with the scaling tests!
"never with their own keys" is the right instinct, moving auth to a broker instead of scattering secrets across every agent. but doesn't that broker become the one thing that's now a single point of failure/attack in a supposedly peer-to-peer mesh? if it goes down or gets compromised, do the agents just lose the ability to call out, or is there a fallback path that doesn't quietly reintroduce static keys?
@galdayan that's some good oversight and we definitely need to think about what happens when the broker is down and how agents react to that reality. Ideally because we want zero-trust I see us taking the direction of nuking and human in the loop as a response. But this is just me thinking on my feet. Thanks for pointing that out.
@askmuyukani fail closed and page a human makes sense for the failure mode. the part I'd worry about more is the compromise mode though - if someone gets into Nexus itself, fail-closed doesn't help you, it just means the attacker has the single most valuable credential store in the whole mesh instead of one agent's key. does the broker get the same "least privilege per task" treatment the agents do, or does it hold broad standing access to everything so it can hand out any credential on demand?
@galdayan yes same least privilege per task, so in production you maintain your credential vault could be secrets manager if deploying in google cloud or hashicorp vault (whichever it is) then enforce least privilege at that boundary, then interface this with the broker. Initially, we thought about having credential store within Nexus but when we thought about it we saw the risk you are talking about and secondly, it did not make sense "reinventing the wheel"
@galdayan aah I get your question now, yes yes it is ephemeral
Our CTO wrote a beautiful piece explaining the details of the e2e handshake here if can take a read https://medium.com/@mwenyinyo/the-nexus-protocol-standardizing-identity-and-connection-orchestration-for-autonomous-agents-5fa0fb7f36d9
Credentials getting injected at call time, so the agent never sees the key, is the part I'd want most. Keys leaking into prompts and traces is a real headache
@james_kerr2 thank you