Each vendor
Hub
UI, models, accounts, billing, cloud, policy, and customer relationships remain with the Hub owner.
Sourceskfd-agent-hub-profilekfd-3Back to libkungfu.devarchitecture / complete model
Follow the full path from recorded action and plural-Hub cooperation to runtime qualification, release trust, and public evidence.
01 · Guided synthesis · site-owned
A session is a useful interaction boundary. It is not enough to preserve admitted state, causal experience, continuing responsibility, or an accepted project result across agents, machines, repositories, and days.
State and worldline
A Fact Cut preserves admitted state. An Episode preserves the causal worldline that actually occurred between cuts.
Sourceskungfu-action-runtimekfd-7Action coordinates
Direction, declared perspective, and bounded authority remain independently addressable before action is treated as responsible.
Sourceskungfu-action-runtimekfd-7Work topology
The Agent Work profile organizes continuing change and bounded responsibility without redefining the lower cross-domain coordinates.
Sourceskungfu-project-cut-loopAccepted project state
Evidence crosses the admission boundary only through explicit settlement; the resulting Project Cut states what the project has officially become.
Sourceskungfu-project-cut-loopAgent supply chain
Hub vendors keep the commercially valuable product layer. KFD defines portable cooperation boundaries, libkungfu preserves local runtime facts and Episodes, and Buildchain binds shipped claims to exact artifacts.
Each vendor
UI, models, accounts, billing, cloud, policy, and customer relationships remain with the Hub owner.
Sourceskfd-agent-hub-profilekfd-3Open protocol
Independent Hubs can exchange bounded responsibility without adopting one control plane or one mandatory cloud.
Sourceskfd-agent-hub-profileLocal runtime
The reference runtime preserves admitted Facts, causal Episodes, recovery, and inspectable projections below the Hub product.
Sourceskungfu-action-runtimeRelease trust
Release passports keep product claims congruent with exact source, artifacts, verification, provenance, and promotion evidence.
Sourcesbuildchain-release-passportbuildchain-kfd-supportkfd-2Claim boundary: The KFD Agent Hub profile is alpha. It defines an interoperability contract; it does not prove external vendor adoption, plural-Hub deployment, stable certification, or an industry standard. Sourceskfd-agent-hub-profile
Agent Supply Chain
Kungfu is an open Agent Supply Chain protocol stack for discovering how Agent products cooperate, binding claims to exact software artifacts, establishing purpose-bound trust, preserving durable work facts, and carrying that work across independently owned Hubs.
Owner: KFD
Discover how products cooperate through inspectable value, constraints, choices, commands, Exit, and records.
Input: Product-owned value, constraints, choices, commands, Exit, and record declarations
Output: A stable human-and-agent discovery surface for bounded cooperation
Known limit: KFD-3 discovery is inspectable product guidance, not a hidden prompt or forced adoption mechanism.
npm:@kungfu-tech/kfd@1.0.0-alpha.41#README.md
Owner: Buildchain
Bind product-owned declarations to exact source, build, artifact, checks, and promotion evidence.
Input: KFD-3-discoverable product declarations and an exact source cut
Output: Artifact-bound provenance, checks, and promotion evidence
Known limit: Buildchain does not create product facts or make the receiver's trust decision.
npm:@kungfu-tech/buildchain@2.14.14-alpha.4#dist/site/product-mechanism.json
Owner: KFD and receiver
Assess claims for a declared purpose while retaining residual risk and decision ownership.
Input: Exact-artifact evidence, a declared purpose, and receiver policy
Output: A purpose-bound assessment with residual risk and decision ownership
Known limit: KFD-2 is purpose-, cut-, and evidence-bound; it is not a company reputation score or universal trust certificate.
npm:@kungfu-tech/kfd@1.0.0-alpha.41#decisions/KFD-2.md
Owner: Kungfu and adopter
Preserve admitted work facts, Episodes, roots, export, and recovery evidence while applications own domain facts.
Input: Receiver-admitted work facts, commands, Episodes, and roots
Output: Ordered durable records, export, recovery, and qualification evidence
Known limit: Applications retain authority over domain facts; libkungfu owns admitted runtime records and ordering within its declared boundary.
git+https://github.com/kungfu-systems/kungfu.git#7eeb5bd1b45492f4da27eaacbe63eddfd6245176:docs/qualification/vendor-agent-hub-embedding.md
Owner: KFD profile and each Hub
Carry bounded responsibility objects across independently owned products with receiver-owned admission.
Input: Bounded responsibility objects with rooted evidence and explicit authority
Output: Portable envelopes, conformance results, and receiver-owned admission decisions
Known limit: The public profile enables independent implementations but does not prove a second independent production Hub.
npm:@kungfu-tech/kfd@1.0.0-alpha.41#protocols/agent-hub/manifest.json
Claim boundary: Kungfu does not claim that a multi-Hub ecosystem already exists. It proves that Agent discovery, software provenance, trust, durable work state, and portability no longer need to be rebuilt or locked inside each Hub.
02 · Upstream authority · Kungfu
libkungfu does not model everything. It preserves the coordinates needed to act without losing intent, evidence, authority, or continuity.
A rooted view of accepted state, not every observed or proposed claim.
Pursuit preserves intent. Atlas preserves the declared perspective and sources. Warrant bounds permission.
An immutable intersection receipt over the Fact cut, Pursuit, Atlas, Warrant, action, and resource.
The runtime may invoke tools or external systems, but success signals do not settle meaning.
Causal occurrence, artifacts, receipts, consequences, recovery state, and verification roots.
Local policy evaluates evidence and admits, rejects, degrades, or conflicts new claims.
The successor cut begins the next action loop without rewriting prior occurrence.
03 · Upstream authority · KFD
Each Hub keeps its product, identity, policy, storage, models, and customer relationship. KFD standardizes only the responsibility exchange boundary.
Participant-owned control plane
Replaceable transport
Local call · IPC · file · HTTP · gRPC · message bus · removable media
Participant-owned control plane
KFD does not own: No global identity provider, Hub registry, database, transport, clock, or mandatory KFD cloud.
Delivery≠Admission
A receipt proves bytes arrived; the receiver still owns the verdict.
Occurrence≠Completion
An Episode happened; success remains an independently assessed claim.
Authentication≠Authority
Controlling an identity does not prove permission, truth, or fact admission.
04 · Guided consequence
KFD does not require every participant to share one implementation. It preserves the minimum responsibility semantics needed for independent systems to cooperate without guessing.
Sourceskfd-agent-hub-profilekfd-3Exact profile coordinates and capability intersection
Receiver-owned admission and non-amplifying Warrants
Content roots, predecessor causality, and idempotency keys
Visible conflict roots and append-only successor exchanges
Typed partial, redacted, reference-only, or withheld disclosure
Binding-neutral payload digests and export/import
Dogfood · public evidence
A fixed 30-day snapshot connects public work, exact Cuts, independent review, and production delivery.
Audit the complete evidence chainOne native authority · three host languages
These commands run after building the exact source candidate. Each card links to the single reviewed implementation.
Node
node quickstart/episode.mjs ./runtime
Read the exact source
Python
python quickstart/episode.py ./runtime
Read the exact source
C
cc quickstart/episode.c -lkungfu -o episode && ./episode ./runtime
Read the exact source
Package availability
No public registry install is claimed yet. Use the exact reviewed source candidate for evaluation.
@kungfu-tech/coreNode binding over the native libkungfu authority
Status: source-candidate
@kungfu-tech/opencode-kungfuReplaceable OpenCode reference adapter
Status: source-only-private-package
Data and authority boundary
Observed evidence · exact candidate
SIGKILL restart recovered one unsealed Episode; export, import, and both fsck checks passed
This is a first-party reference adopter, not external vendor adoption, certification, or OpenCode endorsement.
Release trust
Principles
KFD defines the shared rules: what can count as a fact, when a product claim can be trusted, and how intelligent participants should cooperate.
Open KFDFirst load-bearing layer
Buildchain turns those principles into executable release infrastructure: version decisions, release passports, provenance, rollback, and propagation.
Open BuildchainRuntime substrate proof
Core shows how libkungfu turns runtime events into retained, observable evidence while keeping visibility, durability, and authority boundaries explicit.
Open CoreFuture products
Future Kungfu products belong on kungfu.tech as the user-facing product home. libkungfu.dev explains the generation mechanism those products should be able to trace back to: declared facts, Buildchain release evidence, and inspectable KFD decisions.
Projection source: The site owns first-screen framing, cross-surface synthesis, reading order, progressive disclosure, navigation, and visual composition. Every technical or release claim must bind to immutable upstream evidence or a pinned package; core specs, KFD semantics, CLI parameters, workflow inputs, release state machines, schemas, and provenance remain upstream-owned.