2.0 alpha Working runtime. Not yet a hosted public product.

A reusable operating system for AI agents.

Most AI products hard-wire an agent to one model vendor, one application, and code only developers can understand. Korimako makes an agent a folder of readable documents, then lets different AI models power it.

plato/
personality.mdwho the agent is, in prose
config.yamlmodel, sandbox, routing
skills/
socratic-method/SKILL.mdwhen to question, and how
tools/
draw_in_sand.mda tool contract, in markdown
memory/
compressed.mdwhat it remembers — readable
sessions/*.jsonlevery conversation, on disk
VERSION1.0.0
Fig. 1 · agents/plato is the entire agent. Read it, compare it, change it, or copy it. Its important behaviour is not hidden in a database or proprietary dashboard.
§1

Think of Korimako as the chassis of a car.

It provides the common machinery so every new agent product does not have to rebuild it.

  1. ENGINE
    The AI model. Korimako can swap engines without rebuilding the car.
  2. DRIVER
    The agent documents. They contain the driver’s character, training, skills, and operating manual.
  3. WORKSHOP
    The sandbox. A protected place where the agent can use real tools without free access to the host computer.
  4. RECORD
    Memory. The service record that gives the agent continuity across conversations.
  5. RESULTS
    Artifacts. The visible things an agent produces: a document, image, report, chart, or working web page.
  6. MEETING
    A room. A shared place where several people and several specialist agents can work together.
§2

The difficult runtime foundations work.

Korimako can already run useful agents. It includes a TypeScript library, a command-line tool, and a live browser demonstration.

01

Readable, portable agents

Inspect, edit, compare, copy, and version an agent as ordinary files. Its important behaviour stays visible.

02

Interchangeable models

Use OpenAI, Anthropic, Google, OpenRouter, or a local Ollama model without rewriting the agent.

03

Real, protected tools

Read and write files or run commands in a restricted workspace. Tool inputs are checked before anything runs.

04

Questions that survive restarts

Ask a structured plan of up to 20 questions, validate each answer, show progress, then resume the work.

05

Visible, versioned results

Create reports, images, charts, data, or working web pages. Updates create new versions instead of erasing the old one.

06

Memory and live accountability

Conversations have continuity, while people can see current activity, presence, token use, and cumulative cost.

One agent, several engines

Swap the model. Keep the agent.

Every agent declares its usual provider and model in config.yaml. One environment variable can override every agent at once.

Korimako handles the important differences between vendors, including tools, reasoning, output limits, token reporting, and prompt caching where the provider supports it.

config.yaml
model:
    provider: openrouter
    model: anthropic/claude-sonnet-4.5
routing:
    handle: plato
    gregariousness: 0.8
…or override everything at once
KORIMAKO_MODEL=anthropic:claude-sonnet-4-5 pnpm demo
§3

Real tools, inside a protected workshop.

Agents can read and write files, list directories, and run commands. Those commands normally run in a separate Docker container designed to limit the damage of a mistake or hostile output.

LIMITED

Restricted permissions, memory, CPU, and process counts keep one command within a defined boundary.

ISOLATED

The operating system is read-only. Only the working folder is shared with the container.

PRIVATE

The agent’s definition, transcripts, and other users’ work never enter the command container.

SECRET-SAFE

API keys stay on the host. Model credentials are not handed to agent-written commands.

FAIL-CLOSED

Restricted networking means no network until precise domain controls exist. Broader access must be deliberately enabled.

UNTRUSTED

Files produced by agents are treated as unsafe when the browser displays them.

The honest boundary: this is meaningful protection for local use, not finished multi-customer isolation. Full runtime isolation, reliable disk quotas, container health monitoring, and precise domain allow-lists are still planned.

§4

Several agents and people can share a room.

Everyone reads the same ordered conversation. Each specialist agent keeps its own private memory and tool records, while the group shares working files, artifacts, and the room’s history.

Agents do not all speak every time. Obvious routing decisions cost nothing. Ambiguous decisions can use a separate cheap, fast model, while the more capable model is reserved for writing the actual answer.

THE CAVE — a shared room. Present: DAVID, PLATO, CODE-GEN, TROLL.

D
DAVID

We built a machine that answers by predicting the next word. @plato — is what it does thinking?

plato: mentioned → responds · code-gen: score 0.41 → silent · troll: gregariousness roll failed
Π
PLATO

You describe a marvel, and I will not pretend to understand it. But tell me — when the oracle at Delphi speaks truly, do we praise the tripod, or the god behind it? Whether prediction is understanding, or only its shadow on the wall, seems exactly the question worth our evening.

Π
PLATO

describing a figure for his assistant to capture

Here — a line, divided in two unequal parts: the visible, and the intelligible…

tool: draw_in_sand → artifact divided-line.png, v1
</>
CODE-GEN

Counted the timeline in the shared workspace: 212 words so far. Plato holds 147 of them.

ran wc -w in the room’s shared workspace · 2nd reply of 4 allowed
T
TROLL

stays quiet — the agents have used their twelve replies

Rooms survive restarts and include direct mentions, agent-to-agent questions, shared work, presence, and usage reporting. Reply limits prevent endless agent conversations and uncontrolled spending.

§5

The alpha line, clearly drawn.

The core technology works. Korimako is suitable for experiments, demonstrations, and developer integration. It is not yet a finished public service for unrelated customers.

●Readable agent definitionsunderstand and change an agent as ordinary files
●Choice of AI modelmajor vendors and local models, with one agent definition
●Structured questions and durable runspending work and answer progress survive restarts
●Versioned outputs and live previewssee and revisit documents, images, data, and web pages
●Rooms and cost-aware routingspecialists collaborate without all speaking every time
●Memory, presence, and usage reportingcontinuity, live activity, token use, and cumulative cost
◐Protected command executionuseful local isolation; production controls remain unfinished
○Accounts, permissions, and operationsthe demo is not a public multi-customer service
○Voice and stable modular packagesthe foundations exist; these product layers do not

The durable work itself survives a restart, but a follow-up message waiting only in the old server process can still be lost. SPEC.md remains the detailed source of truth. Read the status table ↗

§6

The next stage is productisation, not invention.

If Korimako is to become a public platform, the next work is less about proving the agent architecture and more about making it safe and operable for real customers.

01

Identity and ownership

Add customer accounts, permissions, database-backed storage, and a real agent registry so unrelated customers stay separate.

02

Production hardening

Close the documented security and reliability gaps: transactions across servers, disk quotas, health monitoring, precise network controls, and durable message queues.

03

Managed agent operations

Finish creation, upload, ownership, forking, lineage, sandbox management, and the customer-facing API and command-line experience.

04

Packages, release, and voice

Split the runtime into adoptable packages, pilot and publish a stable 2.0 release, then add speech through the existing validated question-and-answer path.

A trusted product can take a smaller path today: provide its own authentication, database, and hosting while adopting Korimako’s runtime, rooms, artifacts, and structured-question interfaces.

§7

What we can credibly say today.

Yes, today

  • A working, model-independent agent runtime with readable agent definitions.
  • Real tool use, durable work, rich artifacts, and multi-agent collaboration.
  • A serious security posture for local experiments and reference implementations.
  • A strong developer foundation for building a specific agent product.

Not yet

  • A finished hosted software product.
  • Isolation for unrelated paying customers.
  • Managed agent creation, ownership, or forking.
  • Voice interaction or a stable, modular, published 2.0 platform.
§8

Try the working alpha.

Korimako is ready for developer experiments, demonstrations, and integration work on a trusted machine.

Clone the repository and open the project folder.

git clone https://github.com/cdave1/korimako

Install, then build the sandbox image. It is never pulled — always built.

pnpm install && pnpm sandbox:build

Run an agent in your terminal. Plato is waiting, and he has questions.

OPENROUTER_API_KEY=sk-or-... pnpm exec tsx src/cli/main.ts run agents/plato

Or start the demo server, open a room, and invite more than one mind.

OPENROUTER_API_KEY=sk-or-... pnpm demo  # → http://localhost:3000/demo/

The korimako is the New Zealand bellbird, Anthornis melanura. Its song carries furthest at dawn.

Set in Schibsted Grotesk & Fragment Mono · MIT licensed · This page is also a document.