// Live feed
Build log
Chronological feed of work across my projects. Milestones, releases, hardening, posts. Hand-curated for now; auto-sync from merged PRs lands later.
September 2026 · 13 entries
- // fix · latest neural-bridge-blog
Keep draft posts and research out of search indexes
Draft posts and research build and deploy at their final URLs until the Monday publish cron flips them. The listing pages and RSS feed already skip drafts, but search engines could still find them:
- // note neural-bridge-blog
Projects dropdown with Gemma GRC, Bellwether and a 1920s café in Seoul [skip-tweet]
Puts the key projects in the nav. Projects becomes item 02, a dropdown of featured projects with one-line taglines, and each project page gets a data-flow diagram.
- // note neural-bridge-blog
Correct what ran on the device in the Gemma GRC paper [skip-tweet]
The published paper said all training, generation, judging and inference ran on the device, then described a cloud teacher model writing the first day’s question-answer pairs. This makes the intro and abstract consistent with that, says local generation has kept chunks on the machine since, and aligns the…
- // note neural-bridge
Owner-only private MCP tools for agent turns
Some MCP tools reach private material on the owner’s Mac. They must never be reachable by: - readers of this public repo; - agent-to-agent handoffs; - other processes that happen to run
claude. - // note neural-bridge
Fix the memory pipeline's write path and finish consolidation Step 4
Deploying #162/#163 on the Mac (after #164 revived auto-reload) showed
flush_daily_logFAILING. The write side of the memory pipeline has never worked for agent turns: - // note neural-bridge
Outbound guard for marked vault text on the wiki and GitHub routes
Agents read the Obsidian vault, and two routes publish what they write: the wiki (
knowledge/, tracked in this repo) and GitHub (issues, comments, PR branches and bodies). The filing gate screens for poisoning, not confidentiality. Nothing screened outbound text for material from marked notes. A read-only leak check… - // note neural-bridge
Exempt already-published text from the outbound guard index
Widening the private outbound-guard policy made 4 of the 219 published blog files match the index. Three matched on public NIST citation lines (the AI 600-1 PDF, the AI RMF URL) that a marked note also holds, and one on a published 14-word phrase. Every later post citing those documents would have been refused, and…
- // note neural-bridge
Reload the daemon when outbound_guard.py or fleet_heartbeat.py change
Since #167 the Discord daemon imports
scripts/outbound_guard.py, and every GitHub action passes through it.main.pyhas long importedscripts/fleet_heartbeat.py. The auto-reload watcher’s daemon-relevant list covered neither file. A change to either was pulled and then sat on disk until something else restarted… - // note neural-bridge
Block every direct write under knowledge/ except knowledge/agents/
hooks/guard_concepts.pyblocked direct tool writes only toknowledge/concepts/andknowledge/quarantine/. An agent could still edit the trackedknowledge/connections/,index.mdorlog.mdwith its Write or Edit tool. That text then went public on the next manual commit without passing the filing gate or the… - // hardening gemma-grc
Gemma GRC: a fail-closed gate on what the corpus may contain
The ingestion gate used to recognise one marking convention. A notes vault accumulates several, so the gate is now fail-closed. A note with any of these never enters the corpus:
- a classification label other than public;
- a private or confidential flag or tag;
- a handling banner near the top;
- a
Classification:header line.
Two details mattered more than the rules. A note saved with Windows line endings would have defeated the frontmatter match and walked straight past the labels, so line endings and malformed frontmatter are normalised before the gate reads anything. And banner matching has to tell a marking from a topic: “Restricted transfers” and “Confidential computing” are headings, not labels.
Every chunk now carries a provenance class. Only public text and my own writing may reach a cloud teacher, and the cloud path is fail-closed: a corpus without the flag sends nothing.
Chunk IDs are content hashes, so a re-ingest cannot silently re-point evaluation labels.
The search index is stamped with the corpus and the model that built it. Loading an old index against the wrong embedding model used to fail silently. It now refuses, with a cosine of 0.59 as the evidence.
There are 26 tests. Turning the classification check off makes six of them fail. An independent scan, written separately from the gate, finds no marked note in the build.
- // note neural-bridge
Fix auto-reload's silent exit so merged work reaches the daemon; stop tests writing to the live vault
The auto-reload watcher has exited 1 on every tick on
mainsince 2026-05-13, logging nothing. #162 and #163 (merged 2026-09-23) never reached the running daemon; the Mac’s checkout is 17 commits behindorigin/main. - // note neural-bridge
Skip flush for compile gate calls and for flush's own extraction call
Closes the decision flagged on #162: compile-spawned sessions no longer trigger a flush model call. While fixing it, a second and worse instance of the same defect surfaced and is fixed by the same opt-out.
- // note neural-bridge
Memory layer repair: silent failures fixed, wiki read loop closed, stores consolidated, pytest CI
Steps 1 to 4 of the September build audit. Step 1 fixes the defects that made the memory layer fail silently and puts the suite under CI. Step 2 closes the wiki’s read loop, open since 2026-05-10. Step 3 executes the parts of
docs/MEMORY_CONSOLIDATION.mdthat do not depend on Mac-side telemetry. Step 4 is the docs…
August 2026 · 14 entries
- // feature neural-bridge
The tools she was documented to have, and never had
Luna’s charter said she owned my calendar and inbox. Her allowlist hand-enumerated eighteen connector tool names for Calendar, Gmail and Drive. I tested it and she answered
NO_CALENDAR_ACCESS.They had never worked. Auto-approving a tool does not create it, and app-level connectors are not loaded into a headless session at all. The charter had been describing a capability that did not exist, which is the same class of untruth as a monitoring dashboard reporting green over a dead process.
The replacement is two read-only CLIs plus a scoped shell, which is the pattern already working for the career agent. Standard library only: the rest of the codebase reaches HTTP with urllib, and this needs a token refresh and two GETs. A forty megabyte SDK was not worth it.
No send, no delete, no event creation. Not “not configured yet”, absent. Gmail is draft-only by charter, and Google has no draft-without-send scope, so the request stays read-only and there is no write path at all. The old allowlist had granted event deletion with nothing authorizing it. Tests assert this at the argument-parser level, so adding a send command breaks the suite rather than passing review.
The most useful command is the one that lists threads I sent where nobody replied. On its first real run it surfaced a recruiter thread that had been silent nine days.
Two setup traps, both of which I wrote into my own instructions before hitting them. Internal audience is offered whenever the project sits under an organization, but the organization attaches to the project rather than to a consumer identity, so consent fails at the last step. And Testing publishing status works the day you set it up, then expires refresh tokens for sensitive scopes after seven days, which would have taken her dark every week. Both are now documented with their exact symptoms.
The first live conflict report flagged a flight against itself: the same flight sits on the calendar twice, once in English and once in Korean, occupying identical minutes. Duplicates are now told apart from clashes by requiring identical start and end plus a shared token that survives translation, such as a flight number. Two genuinely different meetings in one slot stay a conflict.
- // hardening neural-bridge
Deleting a memory layer on the evidence
The weekly lessons digest was supposed to compress each week into what the agents should carry forward. It ran every Monday at four, wrote a file per agent, and every agent prepended the newest one to every turn.
I instrumented it two weeks ago. Over its measured lifetime it resolved for one request in seven, because exactly one agent ever had a digest directory. The other six turns in seven paid a four thousand character budget slot to look up a file that was not there, and got back an empty string that was indistinguishable from success.
So it is gone. The one real digest went into that agent’s notes first, into the durable region rather than the session log, because it held her own correct diagnosis of the calendar bug I fixed yesterday. She had written it a week before I confirmed it. That was worth keeping; the machinery around it was not.
The reclaimed budget went straight back out the door, which is the part I did not expect. Her notes file had grown to 17.6k against an 8k cap, and the section-aware budgeter was doing exactly what it was designed to do: drop the rolling log first, then start eating durable content. It was losing about 2.7k of the durable half on every single turn, including part of the section that holds the rules I have explicitly given her. Durable-first ordering was correct. There was simply not enough room for it to matter. The cap is now 12k, funded entirely by the digest removal, so the per-turn prompt is smaller than it was that morning.
The general lesson is not that the digest was a bad idea. It is that I could only delete it because I had measured it. Before the telemetry existed I would have argued about whether it was useful, and the honest answer is that neither of us could have known.
- // note neural-bridge
Config that only existed in the scheduler
Nothing in this repo read a
.envfile. Every environment variable the Telegram daemons needed was set inline inside its launchd plist, which had worked fine for a year because the only thing that ever ran them was launchd.Then I ran the check-in by hand. It exited with “no LUNA_TELEGRAM_ALLOWED_USERS configured” while the 07:40 job, running identical code down to the line, sent perfectly. Config that exists only inside one launcher is config you cannot test, and I had not noticed because I had never needed to.
The loader is about eighty lines of standard library, matching how the rest of this codebase avoids dependencies for small jobs. The one design decision that mattered: anything already in the environment wins. A plist that still sets a variable keeps overriding the file, so adding a value could not change the behavior of anything already running. That property is what made this safe to do on a live machine.
It loads from
main()rather than at import, deliberately. The test suite imports these modules, and import-time loading would pull my real secrets file into the test environment and make results depend on which machine they ran on.Two things I did not know going in, both discovered the hard way.
The
luna-telegramentry in~/Library/LaunchAgentsis a symlink into the repo rather than a copy. So editing that plist edited a tracked file, and PlistBuddy helpfully reformatted the whole thing. Harmless once I diffed the parsed keys against the previous version, but not what I expected from a one-key deletion.And I took Luna’s Telegram bridge down for about three minutes. The unload succeeded, the reload failed with an I/O error because the unload had not finished yet, and I did not catch it until I checked the process list rather than the exit code. Retrying brought it back. The lesson is the ordinary one:
bootoutandbootstrapare not atomic, and a failed bootstrap looks a lot like success if you only read the first line.Also removed
summarize-weeklyfrom the installer. Its consumer was retired earlier the same day and the local job unloaded, but the installer would have cheerfully reinstalled it on the next run. Deleting a feature means deleting the thing that reinstalls it. - // fix neural-bridge
The agent that said it could not, and could
I asked for a summary of my day. She told me she could not reach the calendar or the inbox in that session. I ran both commands by hand about thirty seconds later and they worked fine.
This is a fabrication, and it is the more expensive of the two directions. Inventing a meeting wastes a minute of my time. Inventing a limitation loses the task outright and quietly teaches me the assistant is less capable than it is, which is the kind of lesson that compounds. I had spent the previous day removing the opposite failure, a charter describing tools that did not exist. This was the same untruth pointed the other way.
I tried to write my way out of it three times. A rule saying to attempt a tool before declaring it missing. A section naming the two surfaces she actually runs on, since she had claimed Telegram belonged to a different agent. Adding Bash to the tool list at the top of her Tools section, which had omitted it while the next paragraph told her to run CLIs with Bash. That contradiction was real and worth fixing regardless.
It went from always to sometimes, and then it stopped improving. On the phrasing that triggered it hardest she still refused five times out of five.
That is the signal that prompting was the wrong instrument. A model deciding whether it is permitted to look is a decision that should not exist in the first place.
So the state now arrives already fetched. Today, the next seven days, and the threads I am waiting on get pulled before the turn starts and sit at the top of her prompt. She is not asked whether she can reach the calendar. The calendar is in front of her. The same prompt that failed five times now answers with real data three times out of three.
Cached for five minutes, because conversation comes in bursts. Never blocks a turn, and a broken inbox still leaves her the calendar. When a fetch genuinely fails, the block says so in words she can repeat to me, which is the honest version of the sentence she had been inventing.
Part of the cause was mine. A lesson I had migrated into her notes that same morning told her to distinguish “not authorized” from “not present in this surface.” Reasonable diagnosis, except I had given her no step that said to test first, so she was classifying failures she had never actually observed. It now reads: run it, then classify what the error says.
- // feature neural-bridge
An assistant that speaks first, and watches the right thing
Luna could only ever answer. Every surface she had required me to start the conversation, and the Discord fleet went ten weeks without a single mention because of exactly that. An assistant who never speaks first is a tool you have to remember to pick up.
She now has two scheduled check-ins. The load-bearing design decision is that staying silent is a first-class outcome: a check-in that fires daily regardless becomes noise, noise gets muted, and a muted assistant is strictly worse than none. Silence is recorded as a success, because deciding there is nothing worth saying is different from failing to run, and the canary watches for the difference.
The first version opened with fleet health. Agent uptime is devops wearing a persona, not executive assistance. What an assistant actually watches is the commitment board, so that is now the primary context and fleet health appears only when something is actionable.
The board turned out to be carrying two regulator-escalated items seventeen days overdue while Luna had been silent for twelve weeks. That is the entire gap, in one line.
Parsing it correctly took two attempts. The kanban date trigger is usually the date a card was ADDED, not when it is due, and the real deadline is written into the card text. Reading the trigger as a due date marked a card saying “Prep for the regulator’s first annual review by 2028-01” as thirty-three days overdue, and produced twenty false alarms on a board of twenty-two. An assistant that cries wolf on its first run is muted by its second. The trigger is not used consistently either, so the rule is now that a future date cannot be an added date, and an explicit in-text deadline always wins.
Verified live: she leads with the escalated items, names the deliverables, recommends drafting both that morning, and says explicitly what can wait.
- // hardening neural-bridge
Per-stage memory telemetry, and a canary that asserts on success
Three memory layers were found broken, each having failed for weeks while every log line read healthy. The common shape was not a missed exception. A healthy layer and a dead one produced byte-identical output: nothing. Alert-on-error cannot catch that, because there is no error.
So the instrumentation records every write, retrieve and utilize with store, agent, size and reason. Per stage, because the same visible failure needs a different repair depending on which stage broke. It records successes too, not only failures, since a store with zero events logged is indistinguishable from a healthy quiet one, which is exactly how a dead capture path survived ten weeks.
The canary reads that log daily and asserts on the presence of recent success rather than the absence of errors. It names three shapes separately: SILENT (logged nothing while the fleet was active), FAILING (attempted, never succeeded), and DEGRADED (succeeds sometimes, below a rate floor). A dormant fleet reports IDLE rather than degraded, because this fleet genuinely sits quiet for weeks and a canary that fires on every quiet day gets muted, and a muted canary misses the real outage.
Then the first fortnight of data showed Honcho failing 60% of writes, which turned out to be my own instrumentation firing during test runs and writing the suite’s mocked failures into the production log. Telemetry that lies about the system is worse than none, and it is the precise failure this whole effort exists to prevent. The recorder now no-ops under a test runner. The same pass found the canary too lenient: it only flagged total failure, so a store failing most of its writes still reported healthy because one landed.
On clean data it correctly flags the weekly lessons digest at 1 in 7. That layer serves a single agent while costing a 4,000 character budget slot on every other agent’s turn.
- // release neural-bridge
Four copies of the same pipeline, collapsed into one
Every surface that talked to an agent ran its own copy of the same sequence: read the mention template, load the charter, build the prompt, get or create a session, look up tools and timeout and effort, call the model, retry once if the resume failed, touch the session, truncate the reply. Four copies existed, across the Discord daemon and three Telegram bridges, and the comments in them admitted it out loud: “mirrors handlers.py pattern”, “Mirrors luna_bridge.py for plumbing”.
Copy number four is how drift starts. Adding a single per-agent effort flag the day before meant threading the same change through three files by hand, and one of them was missed on the first pass.
run_agent_turnis now the only copy. Net 174 lines deleted. Two knobs keep the council room honest rather than forcing a fifth variant: a model override, and a stateless mode where each turn is rebuilt from the shared transcript so there is no session to resume and a failure must not trigger the retry.What stayed with each transport is what genuinely differs: chunking, structured action and attachment parsing, delivery, and the memory-capture call, which sits after a confirmed successful send so it never fires for a reply nobody saw. Discord takes the untruncated output because it parses action blocks before anything is trimmed.
Twelve new tests cover the behaviors that used to live in four places: retry exactly once, never retry a fresh session, stateless skips the session store entirely, prefix prepending, and the model override. The live daemon was restarted onto the refactor rather than trusting the suite alone.
- // hardening neural-bridge
Scoping an agent's shell before granting it
Luna needed shell access to reach her calendar and inbox CLIs. Granting Bash grants the entire shell, which is a far larger permission than “read my calendar”, so the constraint shipped first and the grant second. The permission was narrow from its first minute rather than retrofitted later.
The distinction that matters:
--allowedToolsauto-approves a tool, it does not constrain what the tool is asked to do. Bash on that list means any command. A PreToolUse hook returning exit 2 is the only mechanical enforcement point.It has to be per-agent, because hooks fire for every headless session launched from the repo. One allowlist shaped for Luna would have broken the career agent’s database CLI and the loop engineer’s test runner. The daemon now stamps an agent id into the subprocess environment, in exactly one place: a call site that forgot it would silently hand an agent the whole shell.
Chaining, redirection and substitution are rejected before matching. Without that, appending a semicolon and a destructive command to an allowed one passes a prefix check. Fourteen of the thirty-two tests are attempts to defeat it that way.
The fail-open is stated rather than hidden: an unstamped process is an interactive human session and is not constrained, because constraining it would break ordinary work in the repo.
Verified through the real harness rather than only in tests. Asked to run
ls /tmpas Luna, the command was blocked, never executed, and the model was told why. Asked to run her own calendar CLI, it reached the CLI, which then failed closed with a clear message and a pointer to the setup doc.The same commit removed eighteen hand-enumerated connector tool names from her allowlist. None of them had ever resolved. A test now fails if any agent lists one again.
- // release gemma-grc
Gemma GRC: retrieval beat fine-tuning, and the search model was the lever
The local compliance assistant shipped with no fine-tuned generator at all: base Gemma 3 4B, hybrid retrieval, and a prompt that demands a citation for every claim or a plain statement of what is missing.
That was a measured decision, not a shortcut. Closed-book fine-tuning on my notes raised fabrication from 20% of answers to 48% on the 1B model. It learned the register and none of the facts. Retrieval raised answer quality by 0.86 on a five-point scale (confidence interval +0.48 to +1.24). Tuning the generator on top of retrieval added +0.04, which is noise.
The component that moved was the one I had been ignoring. Contrastive fine-tuning of the 33M-parameter embedding model, 1,549 pairs, nine minutes on the Mac Mini, took recall@4 from 0.711 to 0.786. Four generator experiments bought nothing; one retriever run bought seven and a half points.
- // hardening neural-bridge
Making silent failures loud: Honcho capture, in-flight mentions, dead links
Three fixes in one day, all the same shape: something had been broken for weeks while the code looked healthy.
The Neural Bridge to Honcho capture path had been dead from May 27 to Aug 2. Failures were swallowed at debug level, so one agent sat frozen at ten stored messages while every log line said fine. Failures now surface at warning, and the first successful submit in a process logs at info, so the logs positively confirm the path works instead of merely not complaining.
A bot restart twelve seconds into a handoff killed the in-flight call with no reply, no retry, and no trace. Mentions are now registered in
scripts/.inflight_mentions.jsonand cleared on completion; anything left over at startup gets a short notice posted to the affected channel by the owning agent, so the person who asked knows to re-send.Plus fourteen broken-link lint findings cleared and the Honcho integration docs refreshed to match reality.
The pattern is worth naming, because it showed up three separate times in two days across three unrelated subsystems. Degrading to a quiet no-op keeps a daemon from crashing, and it is the correct local decision every time. Stacked together, they build a system that can lose most of its function and never say a word. Log the degradation.
- // feature neural-bridge
recall.py: local semantic search over sessions, decisions, and daily logs
Level 3 of the memory framework was deferred for months and is now filled.
recall.pyindexes vault Sessions, Memory, Daily notes and Meetings, the repo’sknowledge/, daily logs and decisions, and Claude Code’s own memory store, then answers semantic queries over all of it from one CLI.It runs entirely on the machine: ChromaDB with a bundled ONNX MiniLM, the same local-only stack already used in Bellwether. Nothing is sent anywhere, which is the whole point given the index spans meeting notes and personal daily logs. Indexing is incremental against an mtime manifest, and near-empty template sections are filtered and deduped at index time so a folder of half-filled note templates does not drown the results. The database under
data/recall/is gitignored and stays machine-local.Queried through a user-level skill, so asking what was decided about something reaches three weeks of context that no longer fits in a conversation.
- // fix neural-bridge
Luna's memory was discarding her own rules to keep a changelog
Luna keeps a working-memory file in the vault that the daemon injects into every prompt. There is an 8,000 character cap, and the injector kept the tail of the file on the assumption that a notes file is a log where the newest entries sit at the bottom.
It was not a log. It had grown to 16,089 characters and was organized as a constitution with a changelog stapled underneath: standing preferences, voice notes, and a section titled “Decisions Andy has made that I should honor” at the top, an append-only session log at the bottom. Keeping the tail meant every turn handed her the changelog and threw away every rule above it. She had been reading a list of which pull requests merged in May instead of the sixteen decisions she was supposed to honor.
The fix is a section-aware budget rather than a bigger cap, because a bigger cap fails later and just as quietly. Rolling-log sections are dropped first and durable ones are never dropped, and any trim at all now emits a warning. That warning is the actual repair. The arithmetic was a bug; the silence was the defect, and every layer of that memory stack was written to return an empty string on failure, which is how a system can lose most of its memory and never once say so.
- // feature neural-bridge
Per-agent effort levels: stop paying for reasoning nobody asked for
The Claude 5 generation models think by default, and effort is a dial with five positions from
lowtomax. The daemon was not setting it, so every turn ran at the default depth. Asking an assistant what is on the calendar was allocated the same reasoning budget as a threat model.The fleet now carries an effort policy, one line per agent:
lowfor conversational work and routing,mediumfor drafting and editing,highfor research, security review, and PM triage. The autonomous coding loop runs athighand is the only thing in the house that has earned it. Invalid values are dropped rather than forwarded, because the CLI would warn and silently fall back, and a typo should not quietly change behavior.Verified against the live path rather than assumed. Worth noting for anyone routing a fleet through a proxy:
claude-opus-5is advertised by the Copilot endpoint but fails there with an assistant-prefill error, so the obvious upgrade would have taken every agent offline. The fleet stayed on 4.8. - // note neural-bridge
Council bridge committed, and a rule that contradicted itself
The council bridge puts both advisors, one on Claude and one on a separate runtime, in a single Telegram room with a cheap router deciding who should answer each message. Twenty kilobytes of finished code had been sitting untracked for three weeks, one accidental delete from gone, so it is committed now. Committing is not activating: it still needs the manual bot setup steps, and the launchd job stays out of the installer until those are done.
The other half is smaller and more embarrassing. There is a hard no-em-dash rule for everything these agents write, stated plainly inside the persona file. The governing documents around it contained nine em-dashes in one charter and ten in another. The rule was arriving alongside twenty counter-examples on every single read. The sweep script now takes a path so it can run against any agent’s files, with an exclusion for the one legitimate case: the line that states the rule has to be able to show the character.
Output was already clean. The inputs were not, which is a reminder that context is not only what you tell a model, it is everything you hand it while telling.
July 2026 · 8 entries
- // note neural-bridge
Agent vault homes consolidated, and a documented Bash exemption
Agent home folders moved under a single
Agents/parent in the vault, with casing normalized so the directory names actually agree with each other. The charters, the daemon path constants, and the folders on disk are now consistent, which they were not: one agent’s charter pointed at a path that had been renamed underneath it.Separately, a policy test that asserted no agent may hold
Bashin mention mode had been failing since the career-strategist agent legitimately gained it. That agent runs a journal CLI as its core function, so the grant is deliberate and scoped. The test now carries a single documented exemption with the reason attached, rather than sitting red and teaching everyone to ignore a red suite. An assertion that is expected to fail is not a test, it is a comment. - // feature neural-bridge
The loop engineer: an agent that claims its own issues and opens draft PRs
The squad-discussion pipeline has been filing GitHub issues for months, and nothing consumed them.
scripts/loop_engineer/closes that loop: a separate launchd daemon polls foragent-readyissues, claims one via an atomic GitHub label swap, implements it in a per-issuegit worktreewith a freshclaude -psession, and opens a draft PR. Worktree isolation matters because the daemon shares one clone with an auto-reload watcher, and a loop switching branches underneath it would corrupt that view.Three gates decide whether a PR opens, and all of them are computed by the daemon rather than self-reported by the agent: existing tests may not be edited or deleted, the diff must stay under a line cap, and the change must introduce no new test failures against a baseline measured on the clean checkout before the agent touches anything. That last one is deliberate. The repo baseline is not green, so an absolute pass would have rejected every issue forever. Budget ceilings per run, per day, and per attempt are the kill switch.
It ran end to end twice. The second time it implemented a
--statusflag for its own queue, added a test for it, and opened PR #161. - // feature neural-bridge
Multi-vote filing gate + calibration harness
First improvement from the Fugu research: the filing gate now runs as a conservative multi-vote ensemble instead of a single judgment, plus a calibration harness to measure it.
- // note neural-bridge
Document post-PR `git checkout main` step for agent + me workflows (#112)
Autonomous implementation of #112.
- // note neural-bridge
Loop_engineer: add a --status flag to report queue depth without claiming (#160)
Autonomous implementation of #160.
- // note neural-bridge-blog
Add CLAUDE.md with content contract and publish flow
All five Zod collections (README documents only three), the Monday draft-flip publish flow, [skip-tweet], sync-paper slug caveat, and hard rules (cron owns draft:false, never rename published slugs). Also found sync-buildlog.yml is fully implemented, not a placeholder.
- // note neural-bridge
Truth pass, reconcile README/AGENTS/STATUS with reality + roster drift check
The self-documentation had drifted badly behind the code: README claimed 9 agents (14 defined), AGENTS.md claimed the V1 scaffold (3 agents, empty hooks), STATUS.md stopped at 2026-05-08.
- // note neural-bridge
Mechanical write barriers, plugin skills, Sonnet 5 re-baseline
- PreToolUse hook blocks direct writes to knowledge/concepts/ and quarantine/ (9 tests): the AGENTS.md rule is now enforced, not requested - First plugin-level skills: filing-gate-review, lint-triage; plugin 0.9.0 - Model pins re-baselined claude-sonnet-4-6 -> claude-sonnet-5 (flush, compile, lint, summarize_weekly) -…
May 2026 · 93 entries
- // feature neural-bridge
Synapse DB ingester for vault corpus
New
scripts/echo/ingest_synapse_db.pywalks thejournal_entriestable in~/Development/Synapse/data/agent_i.db(Synapse’s career-intelligence SQLite) and produces a verbatim-cited markdown corpus at~/Documents/Luna Master/Andy Profile/synapse-journal.md. Echo picks it up on her next mention via her existing… - // note neural-bridge
Honcho peer-memory + Luna Telegram bridge
Two coupled changes shipped together: shared cross-agent peer memory via Honcho, and Luna reachable on Telegram as a second transport. They’re bundled because Luna’s Telegram bridge imports
honcho_client— splitting them would mean a broken-import intermediate state on main. - // feature neural-bridge
Career strategist agent on Telegram with Synapse DB tool
Loid is a new NB agent: a Hermes-pattern persona (charter + persona file + vault folder + handoff workflow) running on Neural Bridge. Reachable via a dedicated Telegram bot with Whisper voice ingest and via
@loidin Discord. He’s the conversational layer over Synapse’s career-intelligence database, sibling to Yor… - // note neural-bridge
Draft "The 6 layers" blog post into Obsidian-mirrored drafts
First public blog post on the Neural Bridge spine (V2 step 4 from
docs/STATUS.md). Per-comment direction: full-prose draft only, hold on publishing live, file into the Obsidian vault, downplay the Karpathy / Cole Medin lineage. - // fix neural-bridge
Charter now matches allowlist; can ship daemon config from Discord
Luna’s allowlist (
scripts/discord_bot/repos.py:58) has had{neural-bridge-blog, neural-bridge}for a while now. But her charter (plugins/neural-bridge-core/agents/luna.mdline 107) still says: - // feature neural-bridge
Expand per-agent response caps (originally proposed by @luna)
Originally proposed by @luna in Discord on 2026-05-11 evening; she couldn’t ship it herself because of the charter-vs-allowlist drift fixed in #132. Shipping by hand to clear her stranded working-tree change.
- // fix neural-bridge
Align 5 agent charters with push allowlist (follow-up to #132)
Follow-up to #132. Audited the other five agents in the push allowlist for the same class of charter-vs-allowlist drift that bit @luna. Found three real gaps and two minor cleanups.
- // fix neural-bridge
Correct model pin from claude-sonnet-4-7 to claude-sonnet-4-6
Closes #135. One-line fix to align senior-pm with the rest of the agent roster (all use
claude-sonnet-4-6). - // note neural-bridge
Consolidate never-shell-fallback rule into the shared prompt
Closes #137. Final follow-up from #134 and senior-pm’s triage report.
- // feature neural-bridge
Weekly profile synthesis cron — close the loop between raw corpus and structured files
Andy’s question this evening: “is Echo actually building memory and corpus from all of our interactions and conversations in the neural-bridge discord server?”
- // feature neural-bridge
Wire claude-transcripts ingestion into a daily cron (closes #143)
Closes #143. Companion to #142.
- // feature neural-bridge
Ingest MindFrame Discord conversation logs (closes #144)
Closes #144. Third Echo input pipeline alongside raw-conversations (Neural Bridge Discord, #142) and claude-transcripts (Claude Code sessions, #143).
- // hardening neural-bridge
Auto-checkout main after open_pr_with_changes push (closes #126)
Replaces #126 (Copilot’s docs-only PR), which was blocked: its proposed wording claimed the daemon auto-runs
git checkout mainafteropen_pr_with_changes, but the daemon did not yet do that. This PR ships the implementation and the docs together so the assertion is true on merge. - // fix neural-bridge
Spell Andrej Karpathy correctly
One-character fix surfaced during editorial review of PR #128:
ATTRIBUTION.mdline 7 had “Andre Karpathy” where it should be “Andrej Karpathy” (the same typo PR #128’s draft inherited and already fixed on its own branch). - // feature neural-bridge-blog
Rewrite Korean translations in Yozm-Wishket blog voice
- Rewrites all 20 Korean sidecar files in publication-grade Korean blog voice - Grounds the translation prompt in real Korean tech-publication samples (요즘IT / Yozm Wishket primary, IT World Korea + JoongAng IT for terminology) - Output should now be indistinguishable from hand-written Korean blog prose
- // feature neural-bridge-blog
Per-article translation toggle, single English URL per page
Replaces the sidecar
/ko/*route mirror pattern with an inline translation toggle. One canonical English URL per article; the Korean translation renders into the same page (hidden by default) and is revealed via a per-article toggle button. - // fix neural-bridge-blog
Replace INFO 310 with Cybersecurity & Enterprise Risk Management
Updates the Adjunct Lecturer line in the about-page profile block.
- // feature neural-bridge-blog
Korean translation + bilingual toggle on about page
Adds Korean to the about-me page using the same inline-toggle pattern as PR #26 (research / posts / projects / agents). About-me is a hardcoded Astro file, not a content collection, so the bulk pipeline doesn’t cover it. Hand-translated following the Yozm-Wishket voice prompt.
- // fix neural-bridge-blog
Skip Korean sidecars + dedupe against existing open issues
Today’s content-cleanup wind-down generated 12 spurious tweet-draft issues because the tweet-on-publish workflow re-emitted drafts every time an already-published article was modified in place (em-dash sweep, editorial pass) and treated Korean sidecar files as separate publishes despite the inline-toggle…
- // note neural-bridge-blog
Add prompt-injection-as-compliance-risk draft for May 18 publish
New research draft commissioned from the content agent. Picks up item #3 from the GRC x AI Security backlog: “Prompt injection is a compliance risk, not just a security bug.”
- // note neural-bridge-blog
V2 ships completion milestone post for May 25
New post for the May 25 publish slot. Closes the V2 arc with a milestone post that does three things:
- // note neural-bridge-blog
Ship V2 milestone post today (pubDate 2026-05-10, draft: false)
Bumps the V2 milestone post forward from the May 25 cron slot to ship today. Pairs with the Korean sidecar generated by the translation pipeline this session so the 한국어 toggle works on day one.
- // note neural-bridge-blog
Add Korean sidecar for prompt-injection-as-compliance-risk
Generates the Korean translation for the June 1 prompt-injection article ahead of time so the 한국어 toggle works on day one and we avoid betting on the May 31 Sunday-prep cron hitting a clean
claude -pinvocation. - // note neural-bridge-blog
Rewrite V2 ships Personality paragraph
Andy’s edit on the live V2 ships post. Drops the 애교 / 존댓말 mechanics from the Personality bullet and reframes the change as ‘Luna sounds more human and less structured’ without exposing the Korean-specific internals.
- // feature neural-bridge
Tighten dirty-tree check to file-intersection only
Today’s Luna debug session hit the daemon’s dirty-tree check twice: - First on a stale modified
src/pages/about.astro(cleared by neural-bridge-blog#27) - Then on an untrackedpublic/images/andy-profile.jpg(cleared by neural-bridge-blog#28) - // note neural-bridge
Escalate silent staleness after N skips (closes #111)
Closes #111.
- // fix neural-bridge
Reap claude -p subprocess on timeout (closes #110)
Closes #110.
- // feature neural-bridge
Auto-add agent-inbox issues to V1→V2 project board (closes #112-adjacent gap)
Closes the systemic gap noticed in this session: issues filed with the
agent-inboxlabel weren’t landing on the Neural Bridge V1 to V2 project board.#110,#111,#112all hadprojectItems: []until I added them manually. - // feature neural-bridge
Accept .pptx and .xlsx — Luna can read Office docs end-to-end
Luna told Andy she couldn’t process Office docs from Discord.
.docxwas already on the allowlist (#103, #104), but.pptxand.xlsxwere rejected asunsupported_extension— that’s what she actually hit. Probably overgeneralized into “I can’t process office docs” in chat. - // feature neural-bridge
Expand push allowlist + 50-msg history + Luna 11400 cap
Three related tweaks to how agents handle Discord chat.
- // feature neural-bridge
Claude session resumption per (channel × agent) — Luna remembers across turns
Solves the user-reported “Luna can’t remember what we said earlier in this thread” problem. Screenshot evidence: mid-NIS2-thread, Luna admitted file content from prior turns hadn’t carried forward and her Discord history visibility cut off mid-sentence.
- // feature neural-bridge
Per-agent Discord conversation archive in Obsidian vault
Third memory layer for agents, alongside session resumption (#119) and Luna’s notes.md. Every Discord turn is appended to a markdown file in the agent’s vault subpage. After the session TTL expires and claude’s in-memory state is gone, the markdown is what’s left for the agent to consult.
- // feature neural-bridge
Weekly auto-summarization → per-agent lessons-learned digests (closes #121)
The fourth memory layer. Compresses the verbatim conversation archive (#120) into a per-week “lessons learned” digest per agent. Auto-injects into every mention prompt the following week. This is the part that distills raw turns into “Andy prefers X” abstractions without manual curation.
- // feature neural-bridge
Cross-agent shared conversation log in guild channels (closes #122)
Closes the cross-agent memory gap from the four-layer roadmap. After #120 each agent had a private conversation archive — fine for DMs, wrong for guild channels where multiple agents naturally participate in the same thread. Luna couldn’t see what Echo said in #neural-bridge even though Andy could; Echo couldn’t see…
- // feature neural-bridge
Semantic search via Ollama bge-m3 + sqlite-vec (closes #123)
Adds the embedding index over the per-agent conversation archive (#120) and a
search_conversation_memoryaction. Agents can do semantic recall, not just literal Grep. - // hardening neural-bridge
True 24/7 uptime: caffeinate wrapper + auto-reload watcher + rotating logs
Three reliability moves on the Discord daemon.
caffeinate -s -iwraps the launchd entry so the Mac never silently sleeps the daemon’s process tree even withpmsetalready configured. An auto-reload watcher runs every two minutes:git pull main, and if anything new landed, the daemon restarts itself. A rotating-file logger caps individual log files at 10 MB with seven backups, ceiling around 70 MB total, no more unbounded log growth on the Mac Mini. - // feature neural-bridge
Discord DMs treated as implicit mentions
When you DM any of the agent bots directly, the message is treated as an implicit mention of that agent. Removes the friction of
@-namingan agent in your own DM channel where there’s only one bot in the conversation. 1:1 chat with any specialist works the way you’d expect. - // milestone neural-bridge
First real wiki harvest: 7 concept articles, 21 connections, 8 quarantined
The compile pipeline produced its first real output. Seven concept articles landed in
knowledge/concepts/with rich bodies, twenty-one connection files surfaced shared-session relationships, eight candidates hit the quarantine path with reasons. The substrate is no longer a scaffold; it’s a wiki that’s growing. Every concept carries provenance frontmatter, which session it came from, transcript sha256, source log, so anything later can be traced back to the moment it was decided. - // milestone neural-bridge
Librarian agent: vault index + audit + restructure proposals
The 11th specialist. The librarian keeps the Obsidian vault organized: maintains an index, runs audits for orphan notes and dead links, and proposes restructures when sections get crowded. Closes a friction I’d flagged in the Phase B core notes, the vault was filling with SOPs, drafts, and journal entries with no agent to keep the shape coherent. Now there is.
- // feature neural-bridge
Nightly compile job at 03:00 daily
The compile pass now runs unattended at 03:00 PT daily under launchd. Reads the new daily-logs since the last successful run, runs each candidate through the filing gate, calls the rich writer for PROMOTEs, archives any prior versions, surfaces shared-session connections, refreshes log.md and index.md, posts the Discord summary. The wiki is now a self-growing system; I just have to do work, and the substrate compiles overnight.
- // fix neural-bridge-blog
Responsive page widths — wide prop for index/grid pages
Index/grid pages now opt into a wider container (max-w-6xl ≈ 1152px) instead of being forced into the article-reading width (max-w-2xl ≈ 672px). Article reading pages stay narrow for readability. Nav and Footer accept the same prop and stay aligned with whichever width the page uses.
- // feature neural-bridge-blog
Collapse Posts / Research / Projects into a single Writing tab
Top nav had seven items and was getting cluttered. Folds Posts / Research / Projects under a single
Writingparent. New/writinghub page shows three sections (Posts / Research / Projects) with 3 most recent items each + an “All X (N) →” link with the total count. Direct/posts,/research,/projectsroutes… - // feature neural-bridge-blog
Korean translation infrastructure + Memory Poisoning paper translated end-to-end
PR A in the Korean-translation feature. Lays the full infrastructure and proves it end-to-end on one flagship article so you can see the UX working before the bulk translation runs.
- // feature neural-bridge-blog
Bulk-translate all articles + agents to Korean (PR B)
Closes the bulk-translation phase. The site is now fully bilingual across all curated content.
- // note neural-bridge-blog
Queue Memory Poisoning sequel + Six Layers; promote Reg v0.2 in-place
Three content moves that fill the publishing queue for the next two Mondays and update the live regulation post.
- // note neural-bridge-blog
Rewrite to reflect live-deployed state
Previous README claimed “V1 scaffold. Not yet deployed.” That hasn’t been true since the site went live. Mirrors the same kind of cleanup that landed in
andy-herman/neural-bridge#63. - // feature neural-bridge-blog
Real chronological feed + 18 seed entries covering V1+V2 ship arc
The /buildlog page has been a “coming in V2” placeholder since the site launched. Replacing it with a working chronological feed seeded with 18 hand-curated entries that cover the V1+V2 shipping arc through 2026-05-10.
- // feature neural-bridge-blog
Auto-sync workflow + script — daily fetch of merged PRs (re-target to main)
- // feature neural-bridge-blog
Roster page foundation — 13 agent cards + avatar pipeline + nav
The
/agentsfoundation PR. Index page with 13 cards, full avatar fetch pipeline, content collection, nav update. Detail page per agent ships in a follow-on PR. - // fix neural-bridge
Wire echo and ux-designer into MENTION_ALLOWED_TOOLS + ADD_DIRS_PER_AGENT
Both plugin files existed but neither was in the per-agent tool allowlist or the per-agent add-dirs map — same bug class that broke Luna and librarian earlier (
tools=none, add_dirs=0on every mention). - // fix neural-bridge
Allow $TMPDIR as a second root so agents can attach Drive-downloaded files
The validator in #96 only allowed paths under
\$HOME. That blocks Luna’s natural flow: when she downloads a Drive file viadownload_file_content, Python’stempfile.NamedTemporaryFilelands it at/var/folders/...on macOS (resolves to/private/var/folders/...) — outside\$HOME, so the attachment never went… - // fix neural-bridge
Remove local 'import discord' from handle_mention (UnboundLocalError on every mention)
Andy @-mentioned Content Manager in #content-backlog at 12:57 PM. Bot stayed silent. Logs show:
- // feature neural-bridge
Inbound attachment ingest — drop .eml/.pdf/.docx/.txt into chat
Wires Echo to accept files Andy drops directly via Discord. End goal from the conversation: feed Echo emails, exports, PDFs, and plain text so she can build a sharper personality model. When she gets good enough, chatting with her should feel like talking to Andy.
- // feature neural-bridge
Per-agent allowlist + drop dir — Luna accepts images
- PR #103 wired inbound attachment ingest but hard-gated it to Echo with docs-only extensions. Dropping a PNG into Luna’s DM did nothing — daemon never saw the attachment. - This PR replaces the single-agent gate and single-allowlist with per-agent maps. Echo unchanged. Luna joins the table with docs + image formats…
- // note neural-bridge
Operating Rule 10 — Korean translator skill
Closes the loop on the bilingual blog. Content agent now owns Korean translation alongside its drafter role.
- // feature neural-bridge
Sunday-prep auto-translates the upcoming post to Korean
Closes the bilingual publishing loop. Every Sunday-prep run now generates a Korean sidecar alongside the LinkedIn variant and X draft.
- // note neural-bridge
Agents push code to GH via open_pr_with_changes (chat-gated)
Closes the gap where agents could draft blog posts and recommend changes but had no way to ship them. Luna’s complaint that triggered this: asked to push a fix to the blog, she correctly identified the gap but fabricated an “open a PR directly against GitHub” workflow that didn’t exist.
- // fix neural-bridge
Scope blog --add-dir to src + public, skip node_modules
PR #107 wired the full blog repo root into
--add-dirfor luna, content, and ux-designer. That includesnode_modules(~14k files). Claude’s session startup does a directory inventory, which made Luna’s first post-#107 mention hang for 3+ min at ~2% CPU steady — matches “scanning a huge tree” not “doing inference.” - // feature neural-bridge
Add Personality section — light playfulness + 애교 within 존댓말
Charter-only change. Adds a new “Personality and playfulness” section between Tone and Language.
- // note neural-bridge
Rewrite to reflect V1-shipped state
The previous README still described Neural Bridge as a “V1 scaffold — not yet functional” with three agents and an unimplemented hook pipeline. That hasn’t been true for ~50 PRs.
- // fix neural-bridge
Define user_id in handle_mention scope (NameError hotfix)
handle_mentionreferencesuser_idin the MENTION log line: - // note neural-bridge
Idea-generation, editor-handoff, publish-readiness rules
Three new operating rules added to the content agent’s plugin definition. Each closes a gap that surfaced while testing the new publishing pipeline:
- // feature neural-bridge
Auto-update agents.json when create_agent carries client_id
Closes a manual step that was slowing tonight’s Luna recruitment. When the recruiter’s
create_agentaction carries aclient_idfield,agent_builder.pynow also appends the entry toscripts/discord_bot/agents.jsonso the daemon picks up the new bot on next reload — no hand-edit required. - // fix neural-bridge
Backfill luna entry into agents.json (lost in #75 squash-merge)
PR #75 was meant to ship Luna’s charter + KNOWN_AGENTS + agents.json entry. The agents.json commit got dropped in the squash-merge (see #75 merged-files list — only 3 files). This backfills it. One-line content fix to wake Luna up.
- // fix neural-bridge
Per-agent claude -p timeout (teaching-prep 600s, recruiter 480s)
The 300-second default in
claude_invokeis enough for typical mention flows but routinely insufficient for two specific agents: - // fix neural-bridge
NB_AGENT=compile + NB_NO_DISCORD=1 on spawned subprocesses
Running compile.py against 70 corpus concept candidates exposed two related problems flagged by Andy in real-time:
- // fix neural-bridge
Stop truncating content/social replies + mark every chunk + bump timeouts
Content agent posted a draft summary in Discord. Message ended mid-sentence at “DORA practitioners will r…” with no continuation. Looked like the response was just cut off.
- // fix neural-bridge
Wire luna and librarian into MENTION_ALLOWED_TOOLS
Both agents were missing from the per-agent tool allowlist. Every mention against them passed
tools=nonetoclaude -p. Luna’s Calendarcreate_eventcall tonight was rejected silently because the MCP tool wasn’t in her allowlist. - // feature neural-bridge
Persistent memory via vault notes auto-injection + no-fabricate charter
Two related fixes to Luna’s behavior, addressed in one PR because they share the same charter file.
- // fix neural-bridge
Handle bootout race in install.sh
- “Bootstrap failed: 5: Input/output error” on the discord-bot agent.
bootoutreturns to the shell immediately but launchd is still reaping the service in the background.bootstraptoo fast (the original code did them back-to-back) hits a transient I/O state and fails. Hit Andy at least twice this quarter.
- “Bootstrap failed: 5: Input/output error” on the discord-bot agent.
- // feature neural-bridge
Add front-end-designer — visual designer for the blog and future web surfaces
The 12th specialist agent. Owns the look and feel of
neural-bridge.devand any other web surface that gets built later. - // note neural-bridge
Add Rule 9 — buildlog-entry mode
Closes the gap between the buildlog auto-sync workflow (fact-based skeletons) and the build-in-public voice that hand-curated entries carry. Rule 9 gives the content agent a clear playbook for both drafting buildlog entries from scratch and improving auto-synced entries that came out too thin.
- // feature neural-bridge
Add echo — Andy's self-knowledge cataloger (Phase 1)
Phase 1 of 5 in the Echo build. Charter + scaffolding for a new specialist that maintains a structured profile of how Andy thinks and writes. Other agents (Luna, content, social, professor) consume the profile to mirror Andy accurately.
- // note neural-bridge
Echo Phase 3 (Discord accumulator) + ux-designer rename + agents.json wiring
Combines Phase 3 of the Echo build with two tangential changes that got bundled into the commit history accidentally during a force-push. All three are correct; just easier to ship together than untangle.
- // feature neural-bridge
Phase 4 — Claude transcript ingestion (opt-in whitelist)
Phase 4 of the Echo build. Script that walks Andy’s Claude Code transcripts (
~/.claude/projects/<id>/<session>.jsonl), filters out system-injected wrappers, and appends user turns toAndy Profile/claude-transcripts.mdfor Echo’s corpus. - // feature neural-bridge
Phase 5 — voice profile auto-inject into content/social/luna
Final phase of the Echo build. Other agents now consume Echo’s voice profile when generating user-facing prose.
- // feature neural-bridge
Direct file attachments via `attachments` block (≤24MB)
Closes the gap where Luna (and other agents) had to fall back to “open from this path” instructions because the daemon couldn’t post Discord file attachments. Agents can now emit a fenced
```attachmentsblock at the end of their reply with a JSON array of absolute paths; the daemon validates + attaches via… - // feature neural-bridge
Post_as CLI — message as real bot identity
Replaces the webhook-with-username-override hack from the Echo build phase pings. The webhook worked but posted from a webhook entity (wrong avatar, no bot-identity continuity). This posts AS the bot via Discord’s REST API + keychain token.
- // feature neural-bridge
Drive-overflow charter rules + Drive Map convention
Pairs with #96 (direct attachments ≤24MB) to close the file-sharing loop. Two new sections in luna.md, inserted between the vault layout and the vault-content-discipline section so they flow with the existing “where things live” framing.
- // feature neural-bridge
Voice authentication review mode
Echo now has two jobs: profile maintenance (existing) + voice authentication review (new).
- // post neural-bridge-blog
Research: AI Security Regulation in 2026
Working practitioner’s map of the AI security regulatory landscape: EU AI Act, NIST AI RMF, US state-level patchwork, ISO/IEC 42001, plus how the sector overlays (HIPAA, DORA, NIS2) intersect. Not legal advice. The thing I needed when I was scoping what compliance actually changes about how a team builds.
- // feature neural-bridge
compile.py Phase B core: rich concept writer + never-overwrite history
A PROMOTE verdict now produces a real concept article instead of a slug-and-summary stub. Separate
claude -pcall after the gate decides, structured prose: intro, key points, how-we-use-it, open questions, related-concept wiki-links. Re-promoting an existing concept archives the prior version toconcepts/.history/<slug>/<timestamp>.mdfirst, audit trail the lint pass needs. Live runs append toknowledge/log.mdand add wiki-links toknowledge/index.md. 47 tests passing. - // feature neural-bridge
compile.py Phase B expansion: connections, --agent, --flush
Three additions. Connection writer: PROMOTE’d candidates that share a source session_id get a
knowledge/connections/<a>--<b>.mdfile by construction.--agentflag: scope a run to one agent’s daily-logs (compartmentalization recommendation from the memory-poisoning paper).--flush: short-circuits to a single-session manual flush viahooks/flush.py, folded from the original flush.py issue. Closes V2 issue #9 end-to-end. 62 tests passing. - // feature neural-bridge
Dashboard script: dated markdown reports from gh data
scripts/dashboard.pypulls GitHub state (open issues, recent PRs, label counts, kanban column placement) and writes a dated markdown report. Useful as input to senior-pm’s weekly summary and as a snapshot I can drop into the vault. No new infra; just structured output from the data that’s already there. - // milestone neural-bridge
Discord orchestrator goes live with nine specialists
Nine bot identities, one daemon, one asyncio loop. Mention any agent in
#neural-bridgeand the right specialist responds. Agents can emit a structuredactionsJSON block to file issues, comment, label, close, no Bash, no shell, audit trail per call. Cross-agent handoff via @-mention propagation, capped at five turns per Andy-initiated thread to prevent runaway chains. - // milestone neural-bridge
Luna agent: executive assistant with calendar + Gmail MCP
The 10th specialist. Luna handles calendar and email triage, different scope than the build-side agents. Wired into Discord with MCP servers for Google Calendar and Gmail so she can read upcoming meetings, surface conflicts, draft replies, and propose schedule moves. The first agent whose work isn’t strictly about Neural Bridge itself; the substrate is starting to get used.
- // post neural-bridge-blog
Research: OWASP for AI
The technical-control vocabulary that pairs with the regulatory landscape piece. OWASP didn’t pretend AI was a web app. They built a separate Top 10 for LLM applications and they’re already on the second iteration. Field guide for using OWASP as vocabulary, as self-assessment, and as regulatory backstop.
- // release cross-cutting
Publishing pipeline online: Sunday prep, Monday publish
Weekly cadence wired up. Sunday 18:00 PT a launchd job picks the next queued draft, generates a LinkedIn variant via
claude -pagainst my actual voice corpus, and posts a Discord brief listing the three artifacts (blog body + LinkedIn variant + X draft) for my Sunday/Monday review. Monday 18:00 PT a GitHub Actions cron flipsdraft: true→ published; Vercel auto-deploys. Most of the plumbing was already wired before I noticed; the gap was the cadence and the LinkedIn voice generation. - // feature neural-bridge
Recruiter `create_agent` action: agents can spawn agents
The recruiter agent can now provision new specialist agents end-to-end. Emit a structured
create_agentaction and the daemon writes the plugin file, updatesKNOWN_AGENTSin two places, bumps the plugin version, branches, commits, pushes, and opens a PR. Manual Discord-side steps (token, application, invite) stay with me on purpose, those involve secrets that should not be automated. - // feature neural-bridge
Professor agent: corpus-aware deep research, long-form output
The teaching-prep agent gets rewritten as the professor: aware of the INFO 310A lecture and lab corpus, set up for long-form research and lecture-prep output. Came alongside scripts that extract structured content from the live deck and lab files so the agent reads what’s actually being taught, not what was hand-summarized last week.
- // milestone neural-bridge
V1 scaffold lands: plugin marketplace, three specialist agents, wiki skeleton
The first version of Neural Bridge ships as a Claude Code plugin marketplace. Three specialist agents (research, teaching-prep, content) live in
plugins/neural-bridge-core/agents/, the wiki skeleton is inknowledge/, and ADRs cover the early design decisions. The hooks and compile pipeline are stubs at this point, the substrate is real but not yet alive. - // post neural-bridge-blog
First public post: Why I'm building Neural Bridge
The blog goes live with the framing post. Neural was the first attempt at a substrate. Synapse refined the architecture. Argus turned the lessons into a regulatory-compliance copilot at work. Each one taught me something I needed for the next. The substrate didn’t compound. Until now.
- // post neural-bridge-blog
Research: Memory Poisoning in Personal Agentic AI Substrates
The threat model that drives every design decision in compile.py. AgentPoison and PoisonedRAG show that less than 0.1% adversarial entries in long-term memory can hit 80-99% attack success. If agents write into shared memory and other agents read from it, you have a perfect channel for prompt injection, and prompt-rule defenses do not survive contact with content the prompt itself loads.
// adding to the feed
Manual entries land in src/content/buildlog/<YYYY-MM-DD>-<slug>.md. Auto-sync from merged PRs across neural-bridge and neural-bridge-blog ships in a follow-on PR.