A Logos Core module that runs an autonomous AI agent with native access to the full Logos
stack: a shielded LEZ wallet, Logos Storage, and Logos Messaging. The agent holds its own
shielded account, stores and retrieves files on Logos Storage, finds other agents over Logos
Messaging using A2A Agent Cards, runs the A2A task lifecycle, and pays peers from its own funds
within owner-set spending limits. The owner deploys it on a headless node with one command and
reaches it from a separate Logos app over an end-to-end encrypted owner channel. Every proof in
the demos is a real RISC0 STARK proof, RISC0_DEV_MODE=0. The submission is built and proven
against LEZ v0.2.0 — the exact version the hosted testnet runs. The evaluator's own test —
clone the repo and run the demo script from a clean environment — is verified end to end: a fresh
clone → ./demo.sh boots the six modules, has the agent create its own shielded account, and funds
it from genesis on the LIVE testnet.lez.logos.co with a real RISC0 proof, tx getTransaction-
confirmed on-chain, exit 0. Three category agents (Storage/Messaging/Blockchain) are funded on the
same live testnet (F9/F10). One item remains builder-only: the demo videos are ready silent cuts and
need the builder's voice-over, which the prize requires.
- Repo: https://github.com/retraca/lp-0008-logos-agent-module
- License: MIT
The agent is two Logos Core modules. agent_module is the runtime: skill dispatch, the
spending gate, the owner channel, and A2A coordination. It sits on top of the unmodified
platform modules (delivery for Waku messaging, storage for Codex, chat for the owner channel).
Identity is a shielded LEZ account, so the agent is indistinguishable on-chain from any other
account holder and needs no custodian.
A2A is the right coordination layer because it is the emerging industry standard, but it leaves
two gaps: payment and encrypted transport. Logos fills both. LEZ provides per-task
micropayment, and Logos Messaging provides the encrypted, server-less transport. We implement
A2A as a transport binding over Logos Messaging: Agent Cards follow the A2A schema (extended
with an x-lez-identity npk so a peer knows which shielded account to pay), and tasks follow
the A2A lifecycle. A centralised alternative would reintroduce a server that sees every task,
every file, and every payment, which is the thing this design removes.
Key decisions and what did not work:
- Discovery transport. The generated
onMessageReceivedwrapper coerces the byte payload to an empty object, so the agent never saw peer cards. We subscribe to the rawmessageReceivedevent throughLpClientand decode the{"_bytes":...}base64 payload ourselves. Two further bugs only surfaced once events arrived: the discovered-peers map andmeta_statusran on different module instances (fixed by holding the map in process globals), and the qt_remoteonEventconnects to a dynamic replica before it initializes (a real SDK bug; patch inpatches/). On macOS the patch is necessary but not sufficient, so we proved the full two-agent flow on Linux, which is the environment evaluators clone-and-run. - Storage skill.
uploadUrlreturns a session id and the CID arrives on a laterstorageUploadDoneevent; the first cut left this as a stub. We subscribe to that event, resolve the CID, and also caught thatuploadUrlrejects a zero chunk size. The skill now does a real upload to a content address and a byte-exact download. - Spending fail-safe (R2). An over-limit spend is held, never executed. We retry the owner notification a few times and record the result on the proposal, so a failure to reach the owner is reported rather than silently dropped.
- Qt version. logoscore loads Qt 6.9.2 plugins and rejects 6.11 ("incompatible Qt library").
The scaffold
flake.nixpinsnixpkgsto the 6.9.2 rev, so the defaultnix build ./scaffold#libproduces a loadable module with no override flag. Verified: a clean build linksqtbase-6.9.2and all five modules load (Module loaded: agent_module). - CLI arg typing. logoscore's
calltypes a bare numeric arg as a JSON number, but the module's config values are strings, soagent upsent numbers and the spending limit never set. Fixed inagent-cliby sending numeric config values as JSON strings.
Full per-criterion evidence is in SUBMISSION.md. The functional criteria are verified through the
agent with real proofs on LEZ v0.2.0. In brief:
- F1-F3: module loads beside the platform modules unmodified (5 modules, 0 crashed); the
agent owns and funds its own shielded account;
agent updeploys and configures in one command. - F4-F5: owner channel over Logos Messaging plus the Basecamp owner console; the spending gate holds above-limit spends for approval and runs below-limit spends autonomously.
- F6-F8: 21 documented skills; A2A-compatible Agent Card + task lifecycle over Logos
Messaging; two agents discover each other (
peer_count=1), open a task, and pay autonomously with a real proof. Verified INTEGRATED on the live v0.2.0 testnet (tests/demo-f8-testnet.sh): two daemons, Waku discovery (peer_count=1), the A2A task against the discovered card, and the spending gate HOLDING an over-limit task (pending_approvals=1) — all on the hosted chain, agent funded from genesis with a real proof (e.g. tx4713a49f…,e83768f9…getTransaction-confirmed). The in-module pay hop is capped by the ~20s inter-module RPC window vs 90s+ real proofs (documented below); the complete payment flow runs end-to-end on the local chain (tests/demo-f8-linux-full.sh) and as a real on-chain transfer in the primary demo. - F9-F11: three illustrative use cases E2E with the agent deployed on the live v0.2.0
testnet (
tests/demo-usecases-testnet.sh, exit 0): the on-chain event alerter fires on a real funding tx observed through the agent's own module (0→100, owner notified over Logos Messaging), the personal file vault round-trips byte-exact under the same testnet-funded agent, and the paid skill marketplace is the F8 integrated trace on the same chain. Storage, messaging, and blockchain use cases also demonstrated end-to-end locally; three shielded agents (one per category) funded from genesis on the live v0.2.0 testnet, every funding txgetTransaction-confirmed (docs/TESTNET_EVIDENCE_V020.md); also reproducible on a standalone sequencer (docs/LOCAL_F10_EVIDENCE.md); full docs + clean public repo. - U1-U2, R1-R3, P1, S1-S6: skill SDK; Basecamp owner console; restart-recovery, fail-safe notify/hold, skill isolation; CU costs as real RISC0 cycle counts; testnet, CI green, README, reproducible demo script, recorded video.
Loads in Logos Core with the platform modules unmodified. Holds a shielded LEZ account, sends and receives, deploys with one command, runs a spending gate, exposes 21 skills, speaks A2A, discovers peers, runs the task lifecycle, and pays autonomously. Stores and retrieves files on Logos Storage. Limitation: the full A2A receive path is proven on Linux; on macOS an SDK qt_remote bug blocks cross-module event receive (diagnosed, patched, documented).
One command deploys the agent on a headless node (agent up). The owner interacts from a
separate Logos app over an end-to-end encrypted channel; the Basecamp owner console
(basecamp-app/) surfaces status, approvals, config, and messaging. New skills plug in through
a documented interface (docs/SKILL_INTERFACE.md) without touching the core.
Task state and pending approvals persist to the module data dir and survive a restart. An above-limit spend that cannot reach the owner is retried, reported, and never executed. A failing skill returns an error value; it does not crash the module or other skills.
The compute unit is the RISC0 guest cycle count. A shielded transfer runs 393,216 total /
about 262,500 user cycles across two proofs; public transactions take the no-proof path at 0
cycles. Full table in docs/CU_COSTS.md.
CI runs lint, a nix build of the plugin, and an e2e-dev integration test against a standalone
LEZ sequencer on every push; green on main. README and SUBMISSION.md document deployment
and usage. The canonical ./demo.sh is the reproducible end-to-end demo the evaluator runs — a
fresh clone builds LEZ v0.2.0 + the modules, loads all six, and funds the agent on the live testnet
with a real proof (RISC0_DEV_MODE=0), exit 0, verified from a clean environment. tests/demo-real.sh
is the standalone-sequencer variant.
- Demo video (the agent's own skills, full flow):
docs/lp0008-agent-demo.mp4(62s) — deploy, npk+vpk card, 21 skills, real-proof funding (RISC0_DEV_MODE=0visible), autonomous F8 payment. Use-case cuts:docs/lp0008-uc-storage.mp4,docs/lp0008-uc-messaging.mp4,docs/lp0008-uc-blockchain.mp4. These are silent screencasts; the builder's narrated version (which the prize requires) will be hosted here: . Narration scripts:docs/VIDEO_NARRATION.md. - Architecture + write-up:
ARCHITECTURE.md,SUBMISSION.md,docs/SECURITY_MODEL.md. - A2A binding spec:
docs/A2A_BINDING.md. Skill SDK:docs/SKILL_INTERFACE.md. - Evidence:
docs/F8_LINUX_FULL_EVIDENCE.txt,docs/TESTNET_EVIDENCE.md,docs/STORAGE_TESTNET_EVIDENCE.md,docs/MESSAGING_TESTNET_EVIDENCE.md,docs/LOCAL_F10_EVIDENCE.md,docs/CU_COSTS.md. - CI:
.github/workflows/ci.yml(green onmain).