Agents Universe
An open-source agent platform that keeps one project context shared by everyone working in it. Agents read the whole knowledge base when a project is opened and write what they learn back into the same files while they work; knowledge is Markdown on disk with a database index behind it, and there is no embedding model or vector search.

What it is
An Apache-2.0 agent platform that treats a project as the unit of shared memory. Knowledge lives as Markdown files in the project workspace — domain/, technical/, skills/ — and a database table indexes them by project and slug: primary files are read into context in full when a project is selected, while detail files appear only as metadata and a summary until an agent loads one. There is no embedding model and no vector search; structure is carried by explicit [[slug]] cross-references. Writing back is the other half: knowledge_rw puts new interfaces, metric definitions and test patterns into the matching file, re-indexes, bumps a version, archives the previous content and recomputes a five-part completeness score, with stale marking and an explicit retirement step so that forgetting is auditable. Ten role definitions ship with it — Product Owner, Tech Lead, Quality Assurance and others — and a single turn can be routed to another agent with an @ mention, or delegate a subtask inside the same turn. Memory is layered from per-turn context through session, personal, episodic, project and global knowledge, and any agent can be published as an API or an embeddable page.
Who built itThe GitHub account that owns the repository, named yanqiu(Ian) on its profile, opened in November 2017, with four public repositories, no bio and no followers. Seventeen of the repository’s 235 commits are authored under that name and two more carry the display name Agents Universe with a localhost address; the remaining 216 are authored as Agent Universe with a GitHub noreply address and were committed through GitHub’s web flow rather than a local git client, which matches the README’s claim that the repository is maintained by its own Product Owner and Tech Lead agents. One hundred and eight commits carry co-author trailers — 65 naming Claude, 42 Claude Code, one Claude Opus 4.8.
How it is put together
The parts · 6Files are the system of record and the database is a derived index, which is what lets one shared context be reviewed, versioned and edited by hand as well as by an agent. A turn is assembled rather than stored: the API resolves who is asking, in which project and on which model, builds a ToolContext carrying the project, the user, the workspace root and the database session, and creates a short-lived agent whose tool registry contains only what its Markdown definition declares. Project knowledge is read in two tiers, with detail files deferred until a tool call asks for them, and those same files are the write-back target, so reading and revising go through one path rather than two. Everything that can touch the outside world sits behind a tool, and the tools are where permission lives: secrets are resolved server-side into a subprocess environment, execution happens inside a two-layer sandbox, and a request with no interactive user gets a readable refusal instead of a silent approval. The cost of the shape is stated rather than hidden — context capacity and curation quality become first-class problems, and the sandbox is described as defence in depth, not isolation.
- packages/agent-core/
- The orchestration library — 199 files and 2,389 KB, including its tests, with no HTTP in it.
agent.pyalone is 120 KB and holds the tool loop;sandbox.pyis 80 KB beside a 22 KB CPython audit-hook guard; the knowledge package splits into loader (43 KB), index (37 KB) and a code-graph builder with tree-sitter parsers (37 KB and 41 KB); around sixty tool modules run from filesystem and shell through Jira, Confluence, GitHub, MCP and a secret vault. The test suite is heavier than the code it tests:test_shell.pyat 61 KB,test_code_executor.pyat 56 KB,test_graph_builder.pyat 56 KB,test_sandbox.pyat 48 KB. - packages/api/
- The FastAPI service — 211 files and 1,608 KB. Twenty-two routers and twenty-four services, of which
services/agent_turn.pyis 150 KB: the shared turn kernel that the WebSocket handler, the published API and the scheduler all call. Forty Alembic migrations carry one schema across SQL Server, PostgreSQL, MySQL and SQLite, including the one that made project and slug unique and the one that removed the workspace layer;websocket/handlers.pyandmanager.pyhold the connection and turn-state machinery. Its tests run the real migration chain against SQLite, with a live PostgreSQL job in CI, and include a 49 KB publish suite and a 35 KB compression suite. - packages/web/
- The Vue 3 browser client — 180 files and 1,377 KB: a 60 KB conversation store, a 35 KB WebSocket composable, a 130 KB stylesheet and two 30 KB locale files. The interface covers chat with tool calls, thinking blocks, plan cards and attachments; a workspace file tree whose Markdown editor re-indexes knowledge on save; knowledge completeness, memory and secret panels; and dedicated pages for publishing, scheduled tasks and run history.
- agents/, agents/skills/, workflows/ and knowledge/
- The reusable behaviour assets, all plain Markdown: ten role definitions (a 26 KB Quality Assurance, a 20 KB Tech Lead, a 16 KB Product Owner, plus data analyst, office assistant, customer service, pentest and three customisation roles), 46 skills across eight categories, 11 workflows, and the knowledge base itself — 29 project templates, a
categories.yamlregistry, a 17 KB tool reference, a 10 KB schema document and the framework overview. - Dockerfile, docker/, docker-entrypoint.sh and nginx-combined.conf
- A multi-stage image running nginx in front of uvicorn in one container; the entrypoint applies migrations, rebuilds the global knowledge index and then supervises both processes. Seven prebuilt tree-sitter grammar binaries, roughly 12 MB of the tree, are baked into the image because the runtime sandbox has no network and the language packs used to fail silently when fetched on demand.
scaffold/tests/holds the Playwright configuration and login setup that every new project’s test directory is initialised from. - .github/, scripts/ and the commit contract
- Continuous integration runs the web, agent-core and API suites plus a live PostgreSQL job and a hygiene job.
scripts/check_commit_hygiene.pyreadsgit varfor the identity git will actually use and rejects banned email substrings and unknown URL hosts, driven by.commit-hygiene.tomlwith an inline exemption for adversarial fixtures; a pre-commit configuration and a gitleaks configuration sit alongside it, andscripts/also carries the standalone code-graph builder and the grammar fetch script.
Choices, and what they beat
Knowledge lives in Markdown files, with the database as an index over storing the text in database rows
The contract is stated twice: deleting a knowledge entry unlinks the file and only then does best-effort row bookkeeping, because the file change is the source of truth and must not block on the database, and the workspace editor merges a body-only save back into the file’s existing frontmatter so that a save cannot wipe the metadata. The same decision is why the
PUTendpoint commits before responding — otherwise a background reindex deadlocks against its own row locks. The price is in the same files: every write needs a re-index, a version snapshot and a cache invalidation, and a write whose re-index fails has to say so in a warning, because a detail file with no index row is invisible to the deferred list.No embedding model — full load plus explicit cross-references over vector retrieval over embedded chunks
The implementation guide states it as a deliberate trade: enterprise knowledge has stable structure and real context dependence, and recalling a few similar passages can miss the boundary conditions, so primary files load in full like a handbook while detail files are read on demand. It also names the cost and the case against itself — context capacity and curation quality become first-class concerns, and embedding retrieval still has a cost advantage when there are many files, long files, or questions that span weakly related material.
Skills and workflows are Markdown that the model follows over compiling them into a fixed execution engine
The guide calls this an intentional trade: flexibility and easier open contribution, in exchange for quality that still depends on how well the model follows instructions, on tool constraints and on test gates. The changelog shows the operating cost — an agent whose system prompt drove a fixed workflow never emitted a plan card, and its stages had to be materialised into explicit tasks before the interface could show anything.
Delegation runs nested inside the parent turn instead of handing over the conversation over moving the conversation to another agent
Conversation-level state exists once, so the nested turn is guarded at each site — no turn claim, no session registration, no consuming the parent’s pending injections, no run row — and its events pass through a fail-closed whitelist, because forwarded stream events would freeze the parent’s bubble and double-count its tokens. Depth is capped by configuration, two by default and zero to disable, a slug already in the chain is refused, and a per-conversation lock has to be inherited or a grandchild deadlocks on a lock its ancestor holds. Delegation deliberately widens privilege, so the sub-agent’s own confirmation gates still apply.
Depth in the sandbox rather than a claim of isolation over promising that generated code cannot get out
The security section lists what the guard does not cover: CPython 3.12 raises no audit events for
os.statandos.access, so existence probes are not intercepted; Node.js has no equivalent runtime hook, so a Node script’s reads outside the workspace depend on command-level checks; and in non-strict mode a non-Python child of a guarded Python process is outside the file guard. The guide adds the general rule for high-impact actions — minimal privilege, target allowlists, explicit confirmation and a way to roll back.An in-process scheduler that assumes a single replica over a distributed scheduler with leases
Due occurrences are claimed with a database compare-and-swap on the next run time, and a claim that changes no rows is skipped rather than retried; runs missed while the service was down are skipped and never replayed; a startup sweep settles rows left pending or running as failed; and a launch that cannot win the turn claim is recorded as skipped instead of interrupting the person typing in that conversation. The documentation names the limit itself: multiple workers would need a distributed lock.
Read fromCLAUDE.md (12,471 bytes), knowledge/system/framework-overview.md, knowledge/technical/db-schema.md, docs/agents-universe-implementation-guide.zh-CN.md, README.md (44,593 bytes) and CHANGELOG.md (59,990 bytes), with packages/agent-core/src/agent_core/knowledge/index.py, packages/agent-core/src/agent_core/tools/knowledge_rw.py, packages/agent-core/src/agent_core/tools/memory_rw.py, packages/api/src/api/routers/knowledge.py, packages/api/src/api/routers/project_members.py, packages/api/src/api/services/episodic_service.py, packages/api/src/api/websocket/handlers.py and four Alembic migrations read directly, plus the complete 731-file tree with sizes.
Build log
6 stages- 01
One person, and the agents the project is about
The repository was created on 2026-09-10 and its newest commit is dated 2026-09-28, but its oldest commit is dated 2026-08-18 and the changelog’s first version entry is dated 2026-08-08 — roughly three weeks of work arrived inside a repository that did not exist yet. The 235 commits split 99 in August and 136 in September, and the authorship is the part worth reading: 216 are authored as Agent Universe with a GitHub noreply address and committed through GitHub’s web flow, 17 are authored by the account owner, and 2 carry a localhost address. One hundred and eight carry co-author trailers — 65 Claude, 42 Claude Code, one Claude Opus 4.8 — and the contributor list has two entries,
web-flowat 216 and the owner’s account at 17. Around that sit 383 stars, 1 fork, 0 watchers and a single open pull request, on an Apache-2.0 repository whose topics includedeepseek-harnessandworkbuddy-alternative. Six tags exist,v1.0.0throughv1.5.0, and there are no GitHub releases at all; the release ledger is a 59,990-byteCHANGELOG.mdwhose version headings run from 0.1.0 on 2026-08-08 to 1.5.0 on 2026-09-24, with an Unreleased section holding the newest fixes. - 02
Two writers, one file, and where the collisions were fixed
A knowledge entry is a Markdown file in the project workspace and the database row is an index of it, which puts every consistency problem at the same seam. When concurrent indexer runs inserted duplicate rows for one project and slug, reads through
scalar_one_or_nonebegan raisingMultipleResultsFound; migrationw5h8k6g9h457deduplicated the table by keeping the newest row per pair, deleting each loser’s load events and versions first, and then made the index unique. The indexer now flushes each file inside a savepoint and, on a lost insert race, re-fetches the winner and falls through to the update branch instead of abandoning the batch — with a comment recording that theadd()has to sit inside the savepoint, because an object added before it survives the rollback as pending and re-raises outside any savepoint, aborting the batch anyway. The heaviest fix is on the human path: the knowledgePUTleft its transaction open, so the background reindex’s update on the same metadata row blocked on the row lock while the response was still waiting — a deadlock that hung the PostgreSQL job for 40 minutes. That endpoint now writes the file, snapshots the previous content intoknowledge_versionswith the user as the changer, commits, and only then reindexes in a new session and invalidates the process-level cache, because otherwise the next conversation keeps serving stale entries. - 03
What counts as learning, and the path it takes back into the files
Learning here is read and write rather than search. Documents handed over — a Confluence page, a Swagger export, a requirements document — go through a
knowledge-ingestionworkflow that decides which entry each one belongs to, extracts the useful parts and writes structured entries with cross-references, asking whether to update an existing entry or create a new one when something similar is already there. During work the same thing happens throughknowledge_rw: a new interface goes intoapi-map.md, a metric definition intometric-catalog.md, a test lesson intotest-patterns.md. Every write re-indexes, updates the completeness score, archives the old text inknowledge_versionsand appends tohistory.md; a brand-new slug gets an advisory nudge to fill an existing file first, exempting the API and Kong detail trees and genuine hierarchy children. Forgetting has a process too: outdated entries are marked and retired after the user confirms, and apurgeoperation removes index rows whose files are gone. The other write path is automatic — an episodic summary of a conversation, built from the last 50 messages once at least three came from the user, on the user’s first configured model, and triggered only by a passive WebSocket disconnect while no turn is active, because snapshotting a partial conversation would then be locked in permanently by the one-episode-per-conversation early return. - 04
What is shared, and where the boundary is drawn
The sharing is deliberately uneven. Knowledge queries are always scoped to the current project or to the global framework rows, switching projects clears session state, and each project gets its own workspace under
PROJECTS_ROOToutside the repository. A private project carries a member list — the creator pastes a single sign-on user identifier because there is no username directory, members may manage the list themselves, and the visibility toggle stays with the creator; a check-then-insert race on that list returns 409 rather than 500. Secrets are the sharpest line: model keys and Git tokens are encrypted with AES-256-GCM in two separate vaults, resolved server-side into a subprocess environment for the tools that need them, and never placed in the model’s context, whilesafe_env()strips credential variables from child processes. Execution runs in a two-layer sandbox — a shell command allowlist with per-segment and per-token path checks, and a CPython audit hook installed throughsitecustomizethat confines file writes — and the README states its limits instead of claiming isolation:os.statandos.accessraise no audit events, Node.js has no equivalent runtime hook, and in non-strict mode a non-Python child of a guarded Python process sits outside the file guard. - 05
What the changelog admits
A 32,376-character changelog that records its own repairs is the most useful document in this repository, and the failures it lists are specific. Nginx died silently three times in fifteen hours while the container stayed up and the public site served 502s, because the entrypoint had given PID 1 to uvicorn; the entrypoint is now a supervisor loop that restarts nginx and clears the orphaned workers still holding the ports. A banner told users their last run had been interrupted and invited them to keep typing while the run was in fact still going — a 16-second run was settled as interrupted while the same conversation kept producing output for an hour, because the API treated a mid-turn injection as terminal and
finish_runcould then only no-op. A knowledge completeness endpoint returned 500 on every PostgreSQL deployment while local development and the SQLite tests were green, because the rounding function has no double-precision overload there. Continuous integration never installed a browser, so seven real Chromium tests skipped silently in every job; installing it moved that job from 1,649 passed and 9 skipped to 1,656 and 2. Background tasks leaked out of finished tests and left SQLite write transactions open, so later tests failed at random withdatabase is locked— and the newest commit in the repository is that fix, draining detached tasks before the per-test engine is disposed. The global indexer had also swept all 29 templates into every project’s knowledge panel as system rows nobody could delete, which took a skip rule plus a migration to undo. - 06
The community round, and the contract that guards the commits
Outside contributions are three pull requests from one account,
Mark-super-code, created on 2026-08-21, with one public repository, no followers and no display name. Two were merged about a minute after being opened — 60 seconds and 53 seconds — and the third, opened on 2026-09-28, is the repository’s single open item; its one comment is the author’s own follow-up rather than a review. That request proposes raising the filesystem tool’s read cap from 2 MB to 5 MB and mirroring the same constant in the API router, on the grounds that the router documents its byte caps as mirroring the tool, so leaving it would let an agent read a file that the workspace viewer answers with 413. It also reports the suite honestly — 1,597 passed, 2 skipped, 47 failed — and shows the failures to be pre-existing by stashing the change and re-running. The build itself follows a written hygiene contract: commit identity on a GitHub noreply address, sample hosts confined to the reservedexample.comfamily, enforced byscripts/check_commit_hygiene.pythrough two pre-commit hooks and a CI job, added precisely because the platform’s own agents commit through a server-side clone where local hooks cannot be installed.
Adjacent records
All records →No. 119
headcount
An agent organization shaped like a company — a chief executive over sixteen independently installable departments and 172 skills, where a skill is a folder of Markdown that loads itself when a request matches its description, one tree installs in both Claude Code and ChatGPT because only the manifests differ, and the 184 outside authorities that settle a question rather than decorate an answer — a regulator, a standards body, primary law — sit in a catalog beside the skills they answer for, each labeled with what an agent may do with it.
No. 116
Lemmalog
A Rust Datalog engine that treats agent memory as a deductive database rather than a bigger vector store: facts asserted at the extraction boundary, stratified rules deriving closures and temporal views, provenance back to the source episode on every derived fact, and views maintained one epoch at a time — served to Claude Code and Kimi CLI as twelve MCP tools.
No. 108
agy-staff
A plugin that hires Google’s Antigravity CLI as a member of staff: the host agent — Claude Code, Codex or Pi — keeps the decisions and hands the surveys, reviews and scoped edits to a Gemini 3.8 Flash worker that runs in the background and answers through a job id.