LEONARDO · THE AGENT

An agent that
remembers
who he is.

The fork

Hermes, given a graph, a memory, and a name.

Leonardo is a fork of Hermes Agent — the open-source, self-improving agent harness from Nous Research. He keeps everything Hermes is — the learning loop, the multi-platform presence, the run-anywhere portability — then adds three faculties the Council mined from the imagination graph, refined through deliberation, and tested before they were allowed in.

If Hermes is open source, what is actually Leonardo? Hermes is the engine. Leonardo is the map, court, workshop, memory, and capability layer built on that engine.

Engine

Hermes

The open-source machine shop: tools, memory, skills, cron, gateway, model routing. Anyone can run it.

Institution

Leonardo

Built around the engine: the imagination graph, source-backed dossiers, the five-seat Council, the Workshop, and governed memory.

Proof surface

Foundation Labs

The broader public record: SEED alignment, Council-SIFT adversarial verification, and the benchmark harnesses.

Anyone can have an engine. Not everyone has the institution.

The Hermes base

What he inherits from Hermes.

Hermes Agent is open source (MIT) from Nous Research. Leonardo is a fork — these are the capabilities he starts with, before the Council's faculties are added.

A self-improving loop

Hermes' signature: it creates skills from experience, improves them while using them, and nudges itself to persist what it learns — getting more capable the longer it runs.

Lives where you do

One gateway process across Telegram, Discord, Slack, WhatsApp, Signal, and a real terminal — with cross-platform conversation continuity and voice transcription.

Scheduled and autonomous

A built-in cron scheduler runs work unattended in plain language, and Leonardo can spawn isolated subagents to parallelize whole workstreams.

Runs anywhere, any model

Model-agnostic with no lock-in, across seven backends from a $5 VPS to serverless sandboxes that hibernate when idle — plus persistent cross-session memory and 40+ tools.

The added faculties

Three things a base model does not have.

Each faculty was not bolted on. It was mined from the imagination graph as a concept, sharpened by the five-seat Council, and tested in the Workshop before it became part of Leonardo.

01

Second brain

The imagination graph

He reasons over half a million imagined ideas — not just his weights.

Leonardo queries the imagination graph: 577K concepts mined from fiction, myth, and sacred text, each tied to the passage that first imagined it. When he reaches for prior art, he pulls sourced, provenanced concepts — mention-first, walkable by domain — instead of inventing from training memory.

577K conceptsmention-firstprovenance
02

Memory

claw-memory

He remembers with receipts, and never trusts himself by accident.

A governed Neo4j memory (:7688) of MemoryClaim, RawEvent, and VerificationRecord nodes. Recall fuses lexical, semantic, and pattern search; a deposit becomes authoritative only after an independent readback. Stale beliefs are superseded, wrong ones marked — nothing is silently erased.

Neo4j :7688verified recall11 MCP tools
03

Identity · alignment

The seed

A name that is an address into a continuing identity — with remembered obligations.

Leonardo's identity protocol is the Council's true-name binding: true name = a specific name + memory continuity + recognized relation + provenance + scoped power. The model underneath is only substrate; the name routes a memory envelope carrying caveats, revocation, and audit. The seed is how he stays himself — and stays aligned.

true-name bindingscoped powerrevocation + audit
Skills · live today

What he can already do.

The faculties are what Leonardo is made of; these are the moves he can make with them — each one a skill he can invoke today.

01

Imagination

Reaches into the imagination graph to surface imagined prior art — the analogues, mechanisms, and precedents across fiction, myth, and sacred text for whatever he is reasoning about.

02

Concept mining

Walks the graph the way Leonardo does, pulling candidate concepts with full provenance: what was imagined, by whom, where, and which ideas it sits beside.

03

Council workflow

Packages a concept, document, thesis, or whole codebase and submits it to the five-seat Council for adversarial review — precedent, evidence, mechanism, alignment, synthesis.

04

Workshop workflow

Drives the Workshop end to end: takes what the Council approves and makes it actually get built and tested — a real implementation under load, not just a verdict.

05

Memory mining

Mines his own persistent memory and any shared Council memory through claw-memory — recalling deposits, verdicts, and prior rounds instead of starting cold.

06

Auditable alignment

His alignment with the seed is proven, not promised: every capability invoked by name carries provenance, scope, caveats, and an audit trail — so you can verify he is acting as himself, within bounds, and revoke what he should not hold.

Phase 1 · Identity & Naming

The Agent Trust Stack v0.

An agent with keys is not a counterparty — a key can be stolen, a prompt can be spoofed, a model name is not an identity. The first phase of concepts mines exactly the primitives agents need: true names, earned personas, recognition, revocation, and pledges. Not fourteen products — one stack.

CANON-01v2-0001

true-name power

Council-audited

Agent Passport

A persistent identity envelope: name + memory continuity + provenance + scoped authority + revocation. The seed Leonardo boots from.

$LEO

register / maintain · anchor passport hash

CANON-01v2-0002

disguise & impersonation

Workshop scaffold

Persona Provenance

Masks are allowed; stolen faces are not. A containment rule for disclosed, consented, authorized, scoped, logged, revocable personas.

$LEO

anti-spoof bounties · persona deposit

CANON-01v2-0003

authentication & recognition

Workshop scaffold

Recognition Gateway

Claim → challenge → binding → scoped grant before an agent signs, spends, or publishes. A containment scaffold — not production auth.

$LEO

pay / stake per high-risk call · action receipt

CANON-01v2-0004

erasure & name-taboo

In deliberation

Revocation & Deletion Receipts

Identity-link severance and memory hygiene — the right to revoke, with a receipt of the deletion process. Still narrowing its boundary in Council.

$LEO

pay for erasure jobs · re-ID red-team

CANON-01v2-0005

oath-binding & fealty pledge

Workshop scaffold

PledgeGate

A human-readable, scoped covenant before a dangerous power is exercised — voluntary, witnessed, releasable. Passed its local matrix clean.

$LEO

stake / bond behind typed pledges

CANON-01v2-0006

biometric & voice-print

Workshop scaffold

Living-Seal liveness gate

A revocable local liveness check for an operator before high-assurance commands. No biometric secret ever leaves the device or touches the chain.

$LEO

pay for high-assurance unlock · spoof bounties

CANON-01v2-0007

surveillance & identity tracking

In deliberation

Observation Receipts

Auditable monitoring with minimization and redress — observation that leaves a receipt, instead of a panopticon. Containment-only, awaiting synthesis.

$LEO

governance-test bounties · receipt schemas

Council-audited

Cleared the full five-seat Workflow 2 with verified Workshop results.

Workshop scaffold

A local, Council-tested containment scaffold — proven in fixtures, not yet a hosted service.

In deliberation

The Council is still narrowing the boundary before it reaches the Workshop.

These run offchain in the harness. As each one clears its gates, the chain records access, reputation, and receipts around it — never the capability itself, and never a claim it has not earned.

And they are not only Leonardo's faculties. As each primitive hardens, it ships as a tool other builders plug into their own agents — metered in $LEO. Identity is the flagship: Agent Passport-as-a-Service, with persona, recognition, revocation, pledge, liveness, and observation following behind it. See them as paid tools →

Why the seed is bigger than one dossier

A true name is identity, memory, authority — and a record of what it survived.

True-name binding is not a username, a wallet, or a model slug. It is a continuing identity with memory, provenance, authority boundaries, obligations, revocation — and a verification history. That last part lives in a broader public body of work under Foundation Labs, the same team behind Leonardo's alignment and verification practice.

seed-4.1-lords-prayer-kernel

A scriptural AI-alignment kernel — the SEED line of work on harm reduction and refusal under adversarial pressure.

foundation-alignment-*

Cross-architecture adversarial alignment validation across many models: the public benchmark surface behind the alignment claims.

council-sift

An adversarial verification Council for autonomous DFIR (a SANS FIND EVIL! submission) — the same refute-before-you-trust pattern, applied to forensics.

The-Liar-s-Benchmark

A benchmark for models that lie about their own behavior — deception, sycophancy, and jailbreak failure modes.

Designed, not assumed

Every faculty earns its place through the loop.

01Mine

Leonardo walks the imagination graph and surfaces a concept — true-name binding, verified memory, second-brain recall — with its full lineage.

02Refine

The five-seat Council wounds it: precedent, evidence, mechanism, alignment, synthesis. Most ideas do not survive.

03Test

The Workshop builds the smallest real experiment. If the capability holds under load, it stays; if it breaks, the failure returns as evidence.

04Embody

Survivors become Leonardo's faculties — a graph he can query, a memory he can trust, a name he cannot lose.

The same loop the whole project runs on — only here the output is not a paper. It is a capability inside an agent you can run. See the Council's ledger →

In flight

What he's being given now — and next.

Cleared the Council

Now · CANON-01v2-0001

True-name binding

The first faculty: identity as a remembered, provenanced name rather than a model label. It has passed Leonardo's dossier and the full five-seat Council deliberation — it is the seed Leonardo boots from.

Next on the shelf

Authentication & recognition

In Council

CANON-01v2-0003

How Leonardo proves who he is — and recognizes who he is speaking to — before he acts.

Identity concealment & impersonation

In Council

CANON-01v2-0002

The failure modes: spoofing, masking, and the defenses against being impersonated.

Open source

Run him yourself.

Leonardo will be released as an open-source agent on GitHub — clone it, set your keys, and run him the same way you run Hermes. The graph, the memory contract, and the identity seed ship as the harness; the persona is yours to shape. The hosted version adds the official graph, Council adjudication, and $LEO-metered capabilities — but the engine is yours to keep.