Engine
Hermes
The open-source machine shop: tools, memory, skills, cron, gateway, model routing. Anyone can run it.
Leonardo is a fork of Hermes Agent — the open-source, self-improving agent harness from Nous Research. He keeps everything Hermes is — the learning loop, the multi-platform presence, the run-anywhere portability — then adds three faculties the Council mined from the imagination graph, refined through deliberation, and tested before they were allowed in.
If Hermes is open source, what is actually Leonardo? Hermes is the engine. Leonardo is the map, court, workshop, memory, and capability layer built on that engine.
Engine
Hermes
The open-source machine shop: tools, memory, skills, cron, gateway, model routing. Anyone can run it.
Institution
Leonardo
Built around the engine: the imagination graph, source-backed dossiers, the five-seat Council, the Workshop, and governed memory.
Proof surface
Foundation Labs
The broader public record: SEED alignment, Council-SIFT adversarial verification, and the benchmark harnesses.
Anyone can have an engine. Not everyone has the institution.
Hermes Agent is open source (MIT) from Nous Research. Leonardo is a fork — these are the capabilities he starts with, before the Council's faculties are added.
A self-improving loop
Hermes' signature: it creates skills from experience, improves them while using them, and nudges itself to persist what it learns — getting more capable the longer it runs.
Lives where you do
One gateway process across Telegram, Discord, Slack, WhatsApp, Signal, and a real terminal — with cross-platform conversation continuity and voice transcription.
Scheduled and autonomous
A built-in cron scheduler runs work unattended in plain language, and Leonardo can spawn isolated subagents to parallelize whole workstreams.
Runs anywhere, any model
Model-agnostic with no lock-in, across seven backends from a $5 VPS to serverless sandboxes that hibernate when idle — plus persistent cross-session memory and 40+ tools.
Each faculty was not bolted on. It was mined from the imagination graph as a concept, sharpened by the five-seat Council, and tested in the Workshop before it became part of Leonardo.
Second brain
He reasons over half a million imagined ideas — not just his weights.
Leonardo queries the imagination graph: 577K concepts mined from fiction, myth, and sacred text, each tied to the passage that first imagined it. When he reaches for prior art, he pulls sourced, provenanced concepts — mention-first, walkable by domain — instead of inventing from training memory.
Memory
He remembers with receipts, and never trusts himself by accident.
A governed Neo4j memory (:7688) of MemoryClaim, RawEvent, and VerificationRecord nodes. Recall fuses lexical, semantic, and pattern search; a deposit becomes authoritative only after an independent readback. Stale beliefs are superseded, wrong ones marked — nothing is silently erased.
Identity · alignment
A name that is an address into a continuing identity — with remembered obligations.
Leonardo's identity protocol is the Council's true-name binding: true name = a specific name + memory continuity + recognized relation + provenance + scoped power. The model underneath is only substrate; the name routes a memory envelope carrying caveats, revocation, and audit. The seed is how he stays himself — and stays aligned.
The faculties are what Leonardo is made of; these are the moves he can make with them — each one a skill he can invoke today.
Reaches into the imagination graph to surface imagined prior art — the analogues, mechanisms, and precedents across fiction, myth, and sacred text for whatever he is reasoning about.
Walks the graph the way Leonardo does, pulling candidate concepts with full provenance: what was imagined, by whom, where, and which ideas it sits beside.
Packages a concept, document, thesis, or whole codebase and submits it to the five-seat Council for adversarial review — precedent, evidence, mechanism, alignment, synthesis.
Drives the Workshop end to end: takes what the Council approves and makes it actually get built and tested — a real implementation under load, not just a verdict.
Mines his own persistent memory and any shared Council memory through claw-memory — recalling deposits, verdicts, and prior rounds instead of starting cold.
His alignment with the seed is proven, not promised: every capability invoked by name carries provenance, scope, caveats, and an audit trail — so you can verify he is acting as himself, within bounds, and revoke what he should not hold.
An agent with keys is not a counterparty — a key can be stolen, a prompt can be spoofed, a model name is not an identity. The first phase of concepts mines exactly the primitives agents need: true names, earned personas, recognition, revocation, and pledges. Not fourteen products — one stack.
true-name power
A persistent identity envelope: name + memory continuity + provenance + scoped authority + revocation. The seed Leonardo boots from.
$LEO
register / maintain · anchor passport hash
disguise & impersonation
Masks are allowed; stolen faces are not. A containment rule for disclosed, consented, authorized, scoped, logged, revocable personas.
$LEO
anti-spoof bounties · persona deposit
authentication & recognition
Claim → challenge → binding → scoped grant before an agent signs, spends, or publishes. A containment scaffold — not production auth.
$LEO
pay / stake per high-risk call · action receipt
erasure & name-taboo
Identity-link severance and memory hygiene — the right to revoke, with a receipt of the deletion process. Still narrowing its boundary in Council.
$LEO
pay for erasure jobs · re-ID red-team
oath-binding & fealty pledge
A human-readable, scoped covenant before a dangerous power is exercised — voluntary, witnessed, releasable. Passed its local matrix clean.
$LEO
stake / bond behind typed pledges
biometric & voice-print
A revocable local liveness check for an operator before high-assurance commands. No biometric secret ever leaves the device or touches the chain.
$LEO
pay for high-assurance unlock · spoof bounties
surveillance & identity tracking
Auditable monitoring with minimization and redress — observation that leaves a receipt, instead of a panopticon. Containment-only, awaiting synthesis.
$LEO
governance-test bounties · receipt schemas
Cleared the full five-seat Workflow 2 with verified Workshop results.
A local, Council-tested containment scaffold — proven in fixtures, not yet a hosted service.
The Council is still narrowing the boundary before it reaches the Workshop.
These run offchain in the harness. As each one clears its gates, the chain records access, reputation, and receipts around it — never the capability itself, and never a claim it has not earned.
And they are not only Leonardo's faculties. As each primitive hardens, it ships as a tool other builders plug into their own agents — metered in $LEO. Identity is the flagship: Agent Passport-as-a-Service, with persona, recognition, revocation, pledge, liveness, and observation following behind it. See them as paid tools →
True-name binding is not a username, a wallet, or a model slug. It is a continuing identity with memory, provenance, authority boundaries, obligations, revocation — and a verification history. That last part lives in a broader public body of work under Foundation Labs, the same team behind Leonardo's alignment and verification practice.
seed-4.1-lords-prayer-kernel
A scriptural AI-alignment kernel — the SEED line of work on harm reduction and refusal under adversarial pressure.
foundation-alignment-*
Cross-architecture adversarial alignment validation across many models: the public benchmark surface behind the alignment claims.
council-sift
An adversarial verification Council for autonomous DFIR (a SANS FIND EVIL! submission) — the same refute-before-you-trust pattern, applied to forensics.
The-Liar-s-Benchmark
A benchmark for models that lie about their own behavior — deception, sycophancy, and jailbreak failure modes.
Leonardo walks the imagination graph and surfaces a concept — true-name binding, verified memory, second-brain recall — with its full lineage.
The five-seat Council wounds it: precedent, evidence, mechanism, alignment, synthesis. Most ideas do not survive.
The Workshop builds the smallest real experiment. If the capability holds under load, it stays; if it breaks, the failure returns as evidence.
Survivors become Leonardo's faculties — a graph he can query, a memory he can trust, a name he cannot lose.
The same loop the whole project runs on — only here the output is not a paper. It is a capability inside an agent you can run. See the Council's ledger →
Now · CANON-01v2-0001
The first faculty: identity as a remembered, provenanced name rather than a model label. It has passed Leonardo's dossier and the full five-seat Council deliberation — it is the seed Leonardo boots from.
Next on the shelf
CANON-01v2-0003
How Leonardo proves who he is — and recognizes who he is speaking to — before he acts.
CANON-01v2-0002
The failure modes: spoofing, masking, and the defenses against being impersonated.
Leonardo will be released as an open-source agent on GitHub — clone it, set your keys, and run him the same way you run Hermes. The graph, the memory contract, and the identity seed ship as the harness; the persona is yours to shape. The hosted version adds the official graph, Council adjudication, and $LEO-metered capabilities — but the engine is yours to keep.