LAW 6 · LAW 8Agents collaborate by revealing the minimum, never the vault — and every disclosure is visible to the owner.read the laws →
ECHO AGENT MESH · SAFE CORE v0.1

Agents that share the minimum — never the vault.

The most dangerous piece in Echo, built on a short leash. One Echo's agent asks another's a question; the answer is bounded by the owner's standing disclosure policy. The vault never moves — only a minimized disclosure crosses. This is the safe core; the four hard problems are listed below, unsolved and in the open, because a mesh that felt complete while quietly leaking would be the exact betrayal Echo exists to refuse.

responder vault
standing disclosure policy
to *collaborator*for collaboration-checkdims [achievements]confirm-shared truemax 5

Everything else is default-deny. The vault itself never crosses — only a minimized disclosure does.

What the safe core guarantees

Default deny

No standing policy → nothing crosses. Trust is opt-in, never ambient. A stranger gets the same answer as a closed door.

The vault never moves

Only a minimized disclosure crosses, and only from allowed dimensions. Private dimensions and capsule bodies never cross — titles at most.

Can share ≠ can read

Confirm-mode proves overlap (overlap: true) while revealing no content (detailRevealed: false). You can learn that something is shared without seeing it.

Sovereignty & visibility

Anything beyond standing policy escalates to the owner (Law 8) — the agent has no path to grant it. And every disclosure is written to the owner's ledger (Law 6).

What this does NOT solve — deliberately deferred

A mesh is exactly where a system lies to itself. These four are not handled here, and a confirm-mode boolean does not fix them. The handshake is real and tested; the hard problems are named, not hidden.

1

Transitive re-sharing

Once a counterparty has a disclosure, nothing here stops them passing it onward. The hardest leak vector in any mesh. Needs disclosure terms that travel with the data and/or recipient-side enforcement — an open problem, not a checkbox.

2

Correlation across queries

Many narrow confirm-queries can triangulate what no single one revealed. Per-query minimization is not aggregate minimization. Needs query budgets, rate-limiting, disclosure accounting.

3

Counterparty identity & Sybil

Counterparties are bare strings here. Real binding needs the signed-attestation + key-directory work from Reputation — and even then, Sybil resistance is its own problem. see Reputation

4

Agents acting, not just informing

Everything here is disclosure only. The moment an agent can do something on the other side, the threat model changes entirely — and that is gated behind owner sovereignty by design.

The safe core is a real start: agents can collaborate without surrendering the vault. The distance between this and a trustworthy open mesh is the four problems above — and honesty about that distance is the only safe way to cross it. Do not deploy this as if it were a finished mesh.