Readable, portable agents
Inspect, edit, compare, copy, and version an agent as ordinary files. Its important behaviour stays visible.
2.0 alpha Working runtime. Not yet a hosted public product.
Most AI products hard-wire an agent to one model vendor, one application, and code only developers can understand. Korimako makes an agent a folder of readable documents, then lets different AI models power it.
agents/plato is the entire agent. Read it, compare it, change it, or copy it. Its important behaviour is not hidden in a database or proprietary dashboard.It provides the common machinery so every new agent product does not have to rebuild it.
Korimako can already run useful agents. It includes a TypeScript library, a command-line tool, and a live browser demonstration.
Inspect, edit, compare, copy, and version an agent as ordinary files. Its important behaviour stays visible.
Use OpenAI, Anthropic, Google, OpenRouter, or a local Ollama model without rewriting the agent.
Read and write files or run commands in a restricted workspace. Tool inputs are checked before anything runs.
Ask a structured plan of up to 20 questions, validate each answer, show progress, then resume the work.
Create reports, images, charts, data, or working web pages. Updates create new versions instead of erasing the old one.
Conversations have continuity, while people can see current activity, presence, token use, and cumulative cost.
One agent, several engines
Every agent declares its usual provider and model in config.yaml. One environment variable can override every agent at once.
Korimako handles the important differences between vendors, including tools, reasoning, output limits, token reporting, and prompt caching where the provider supports it.
model:
provider: openrouter
model: anthropic/claude-sonnet-4.5
routing:
handle: plato
gregariousness: 0.8
KORIMAKO_MODEL=anthropic:claude-sonnet-4-5 pnpm demo
Agents can read and write files, list directories, and run commands. Those commands normally run in a separate Docker container designed to limit the damage of a mistake or hostile output.
Restricted permissions, memory, CPU, and process counts keep one command within a defined boundary.
The operating system is read-only. Only the working folder is shared with the container.
The agent’s definition, transcripts, and other users’ work never enter the command container.
API keys stay on the host. Model credentials are not handed to agent-written commands.
Restricted networking means no network until precise domain controls exist. Broader access must be deliberately enabled.
Files produced by agents are treated as unsafe when the browser displays them.
The honest boundary: this is meaningful protection for local use, not finished multi-customer isolation. Full runtime isolation, reliable disk quotas, container health monitoring, and precise domain allow-lists are still planned.
Everyone reads the same ordered conversation. Each specialist agent keeps its own private memory and tool records, while the group shares working files, artifacts, and the room’s history.
Agents do not all speak every time. Obvious routing decisions cost nothing. Ambiguous decisions can use a separate cheap, fast model, while the more capable model is reserved for writing the actual answer.
THE CAVE — a shared room. Present: DAVID, PLATO, CODE-GEN, TROLL.
We built a machine that answers by predicting the next word. @plato — is what it does thinking?
You describe a marvel, and I will not pretend to understand it. But tell me — when the oracle at Delphi speaks truly, do we praise the tripod, or the god behind it? Whether prediction is understanding, or only its shadow on the wall, seems exactly the question worth our evening.
describing a figure for his assistant to capture
Here — a line, divided in two unequal parts: the visible, and the intelligible…
Counted the timeline in the shared workspace: 212 words so far. Plato holds 147 of them.
stays quiet — the agents have used their twelve replies
Rooms survive restarts and include direct mentions, agent-to-agent questions, shared work, presence, and usage reporting. Reply limits prevent endless agent conversations and uncontrolled spending.
The core technology works. Korimako is suitable for experiments, demonstrations, and developer integration. It is not yet a finished public service for unrelated customers.
The durable work itself survives a restart, but a follow-up message waiting only in the old server process can still be lost. SPEC.md remains the detailed source of truth. Read the status table ↗
If Korimako is to become a public platform, the next work is less about proving the agent architecture and more about making it safe and operable for real customers.
Add customer accounts, permissions, database-backed storage, and a real agent registry so unrelated customers stay separate.
Close the documented security and reliability gaps: transactions across servers, disk quotas, health monitoring, precise network controls, and durable message queues.
Finish creation, upload, ownership, forking, lineage, sandbox management, and the customer-facing API and command-line experience.
Split the runtime into adoptable packages, pilot and publish a stable 2.0 release, then add speech through the existing validated question-and-answer path.
A trusted product can take a smaller path today: provide its own authentication, database, and hosting while adopting Korimako’s runtime, rooms, artifacts, and structured-question interfaces.
Yes, today
Not yet
Korimako is ready for developer experiments, demonstrations, and integration work on a trusted machine.
Clone the repository and open the project folder.
git clone https://github.com/cdave1/korimako
Install, then build the sandbox image. It is never pulled — always built.
pnpm install && pnpm sandbox:build
Run an agent in your terminal. Plato is waiting, and he has questions.
OPENROUTER_API_KEY=sk-or-... pnpm exec tsx src/cli/main.ts run agents/plato
Or start the demo server, open a room, and invite more than one mind.
OPENROUTER_API_KEY=sk-or-... pnpm demo # → http://localhost:3000/demo/
The korimako is the New Zealand bellbird, Anthornis melanura. Its song carries furthest at dawn.