Skip to content

Agent-Kernel Integration

Role in Mnemose

agent-kernel is the remote host execution substrate that lets Mnemose operate against customer machines without embedding host access directly inside the always-on control-plane services.

Mnemose interacts with the kernel through two bounded-context surfaces:

  1. @mnemose/mcp-mnemose-kernels exposes kernel.list and kernel.invoke as MCP tools to platform personas.
  2. services/kernel-broker maintains enrolled remote kernels, validates approved sessions, and forwards JSON-RPC invocations over mTLS WebSocket.

Control Flow

platform-ops persona
-> mcp-mnemose-kernels
-> Mnemose command spine
-> kernel-broker
-> remote agent-kernel
-> host capability tool

Read-only kernel tools can run without an approved elevated session. Mutating tools such as fs_write, cmd_exec, and shell_* require a KernelSession approval with a tier and TTL that the broker enforces before dispatch.

Transport Modes

ModeUsed ByNotes
stdio MCPLocal development and direct runtime spawningSuitable when the agent process owns the kernel lifecycle
WebSocket MCPRemote Mnemose-managed kernelsRequires enrollment token exchange and mTLS certificate issuance

Session and Audit Model

  • enrollKernel provisions a new kernel identity and bootstrap token.
  • requestKernelSession requests temporary access for mutating tool use.
  • approveKernelSession or denyKernelSession records the control-plane decision.
  • revokeKernel retires an enrolled host.
  • Every dispatched invocation is written to the Mnemose event log as a durable audit event.

Documentation Sources

LocationPurpose
apps/agent-kernel/README.mdInstallation, tool catalog, CLI, troubleshooting
apps/agent-kernel/docs/index.mdProject orientation and generated-doc entry point
apps/agent-kernel/docs/architecture.mdRust workspace and transport architecture
services/kernel-broker/src/server.tsBroker-side request handling and session enforcement
packages/kernel-protocol/src/index.tsShared Mnemose TypeScript schemas for broker and control-plane flows

Constraints

  • Mnemose and agent-kernel communicate over protocol boundaries, not shared runtime code.
  • Broker-issued policy is authoritative for remote dispatch; the kernel enforces its own immutable startup permission tier in addition to broker checks.
  • API documentation for Mnemose-side schemas belongs in the TypeDoc output for @mnemose/kernel-protocol.