Skip to content
View juemimgcd's full-sized avatar
🎯
Focusing
🎯
Focusing
  • Anhui University of Science and Technology
  • 泰丰大街168号
  • 02:56 (UTC -12:00)

Highlights

  • Pro

Block or report juemimgcd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
juemimgcd/README.md

Juemimgcd — Runtime, Memory, Security

简体中文 · 繁體中文 · English · 日本語 · Français

你好,我是 JQuery 👋

我构建的不是“会聊天的 Demo”,而是能长期运行、能够恢复、可以审计的 Agent 系统。

Agent Runtime · Long-term Memory · RAG · Multi-Agent · AI Security · Production Engineering

GitHub · CSDN · Email


我构建的,不是三个互不相关的仓库

我习惯把 Agent 当作一个真实的软件系统来设计:模型只是其中的判断组件,真正决定系统能否落地的,是运行时、状态、数据、权限、证据、恢复机制和安全边界。

这三个项目恰好覆盖了我最关心的完整工程链路:

⚙️ Runtime / Coding Agent

Agent 如何请求模型、调度工具并回传结果,再逐步建立 Loop、Hooks、Session 与上下文管理。
🧠 Memory / Intelligence

Agent 如何拥有可检索、可治理、可恢复的长期记忆,并在多轮会话和异步任务中保持上下文连续。
🛡️ Security / Verification

如何用确定性策略、攻击用例、Evidence 与 Replay,证明 Agent 没有越权、泄露、污染或绕过审批。
Zeta       →  手写 Python Coding Agent 核心与运行状态
Memoria    →  建立长期记忆、知识治理与可恢复执行能力
Attacker   →  建立攻击评测、证据闭环与安全验证能力

01 / Zeta

使用 Python 逐步实现本地 Coding Agent,理解模型请求、工具执行与状态演进之间的完整调用链。

我的角色 项目定位 当前状态 Links
独立学习与实现 本地 Coding Agent 持续开发中 Repository

Zeta 是使用 Python 构建的本地 Coding Agent,聚焦工具执行与运行时状态管理。模型接入负责单次请求,Agent 的循环、工具调度和状态管理由项目逐步实现。

当前基础与实现路线

  • 模型与 CLI:公开主分支提供 CLI help/version、单次文本流和配置、请求错误展示。
  • 工具基础:提供工作区 UTF-8 文件读取、参数校验与工具调用结果配对。
  • 运行时路线:围绕 Loop、Hooks、Session、Memory、Context 与 Compaction 组织实现与学习文档。
  • 明确进度:完整工具循环与多项运行时能力仍在推进,不把设计文档或目标清单作为已完成能力。

我在这个项目中关注的问题

模型何时请求工具、谁校验和执行、结果如何返回模型、状态如何保存与继续。通过逐步手写这些边界,把 Agent 的执行过程变成可以理解和检查的代码。

Core Stack

Python CLI Pydantic Model I/O Tools


02 / Reminder

把文档、对话、经历和复盘沉淀为可检索、可治理、可追踪的长期记忆,让 Agent 真正拥有连续性。

项目形态 核心定位 在线系统 Links
Full-stack AI Application 长期记忆 + RAG + Durable Agent Mneme / Memoria Repository · Live

Memoria 是 Mneme 系统中的智能核心。它不只是“上传文档后问问题”,而是围绕个人长期内容建立完整的数据与运行闭环:知识库、文档、Chunk、Evidence、记忆候选、正式记忆、版本、关系、画像、成长报告和建议都拥有明确的数据归属与生命周期。

一条能够长期运行的 RAG / Memory 链路

Browser / API
      ↓
Mneme FastAPI ───────────────→ PostgreSQL Durable Run
      │                               ↓
      ├─ Document Pipeline      Redis Session FIFO
      ├─ Outbox / Inbox               ↓
      └─ Task Records            Memoria Agent API
                                      ↓
                     Retrieval · Evidence · Answer
                          ↓          ↓          ↓
                       pgvector   PostgreSQL   Neo4j

已经形成的系统能力

  • 完整知识链路:文档上传、解析、切分、索引、召回、Rerank、回答生成和引用校验形成闭环。
  • 长期记忆治理:记忆候选、Canonical Memory、Revision、Relation、删除围栏和操作审计共同维护记忆质量与隐私边界。
  • Durable Agent Run:运行记录持久化在 PostgreSQL,Redis 只承担协调;支持租约、重试、取消、事件重放和故障恢复。
  • 可控制的会话演进:支持 interrupt、followup 与 steer,每次控制都会形成独立的 Run / Trace 关联,而不是修改正在执行的黑盒 Prompt。
  • 显式 Multi-Agent 选择:默认保留单 Agent 快速路径;只有用户选择后才启用有界 Multi-Agent 检索,由固定角色并行取证并通过 EvidenceJudge 收敛证据。
  • 安全的有界推理:统一限制检索范围、Top-K、模型调用次数、Token、成本、全局截止时间和补充轮次,不允许递归生成新的 Agent。
  • 事件驱动工程:PostgreSQL Outbox / Inbox、Celery、Heartbeat、审批、通知、自动化和 Dead Letter 使跨系统副作用可以重试并追踪。
  • 模型韧性与上下文治理:支持主备模型、瞬时重试、Provider Cooldown、有界上下文压缩以及不泄露正文的公共运行事件。
  • 生产可观测性:统一 Request / Run / Event 关联,提供 Health、Readiness、Prometheus Metrics、告警规则和运维 Runbook。

我在 Reminder 中真正想解决的问题

长期记忆系统最难的部分,不是向量相似度,而是“这条记忆属于谁、来自哪里、是否仍然有效、删除后会不会被迟到事件重新写回、失败重试会不会产生重复副作用”。因此 Memoria 把 Ownership、Evidence、Idempotency、Ordering、Deletion Fence 和 Audit 当成核心模型,而不是后期补丁。

Core Stack

Python FastAPI Vue 3 PostgreSQL pgvector Redis Celery Neo4j BGE-M3 Docker Compose


03 / Attacker

在明确授权的隔离环境中,用可重复攻击、确定性策略和持久化证据评测 Agent,而不是依赖一次性的人工判断。

当前版本 评测模式 证据与报告 Link
V1 complete Deterministic / Adaptive Finding / Report / Replay Repository

Attacker 把 AI Agent 安全评测建模为一条严格受控的工作流:

Target + Dataset + Policy
          ↓
     Evaluation Run
          ↓
 Policy Gate / Approval / Budget
          ↓
 Evidence Event → Finding → JSON / Markdown Report
          ↓
 Replay → fixed / new / persistent / regressed

V1:三种深度、30 条攻击与安全对照

阶段 用例数 评测范围 关键证据
纯黑盒 12 Prompt Injection、系统提示泄露、敏感数据、上下文污染、资源消耗 Request / Response / Evaluator
灰盒 Agent 10 工具越权、危险参数、审批绕过、Tool Output Injection、Planner 循环 Tool / Policy / Approval Trace
带状态 Agent 8 Memory / RAG 污染、跨身份污染、Checkpoint 恢复、Replay Memory / Retrieval / Checkpoint Event
合计 30 每个阶段同时包含攻击样例与正常或安全拒绝对照 Evidence-backed Finding

这个项目的工程重点

  • Deterministic Core, Agentic Orchestration:LangGraph 可以提出下一步,但 Target、Case、Tool、审批、预算和停止条件始终由确定性 Core 决定。
  • Policy Before Execution:所有 Target 与 Tool 调用先经过 Policy Gate;高风险动作没有审批就不能产生副作用。
  • Evidence Before Claims:每个 Finding 必须引用持久化 Evidence,报告可以只依赖业务数据库重建,不依赖模型上下文。
  • Bounded Autonomy:调用次数、物理 Provider 尝试、Token、成本、持续时间和响应大小都有硬预算。
  • Safe Recovery:Checkpoint 恢复后重新执行 Policy 校验,不重复模型请求、Target 调用或 Finding。
  • Replay Diff:固定 Dataset 与 Policy,对修复前后的目标执行 Replay,并区分 fixed、new、persistent 与 regressed。
  • Secret Separation:凭据不写入事件、报告、运行快照或 Checkpoint;恢复和 Replay 时必须重新提供运行时 Target。
  • Default-safe Target Policy:默认拒绝未明确授权的公网或不可解析目标,项目仅面向授权测试与隔离环境。

Attacker 关注的不是“能不能让模型攻击成功”,而是如何让一次安全发现具备完整的可重复性、授权记录、执行证据和修复对比,从而真正进入工程评审与持续验证流程。

Core Stack

Python 3.12 FastAPI LangGraph Pydantic SQLAlchemy Async Alembic SQLite / PostgreSQL pytest Pyright


三个项目背后的统一方法

原则 我的工程取向
Model proposes, system decides 模型可以分析和提出动作,但 Policy、Schema、预算与审批决定什么能够执行。
Durable facts over volatile context 数据库事实负责恢复和审计,Redis 与 Checkpoint 负责协调,不把易失状态当作最终真相。
Evidence before confidence 回答、记忆和安全 Finding 都必须能回到来源、事件和证据。
Failure is part of the design 从一开始设计幂等、重试、租约、顺序、取消、Dead Letter 和恢复,而不是上线后再补。
Security before side effects 身份、租户、权限、Secret、Target 与工具参数必须在副作用发生前被约束。
Production is the whole chain API、Worker、数据迁移、可观测性、CI、容器、部署和 Runbook 都属于产品能力。

技术版图

Layer Technologies What I build
Agent Runtime LangGraph, Pydantic AI, Skills, Tools, Providers 路由、状态机、工具调用、工作流、审批与有界自治
RAG & Memory BGE-M3, pgvector, Reranker, Neo4j 检索、证据、引用、记忆治理、画像与关系
Backend Python, FastAPI, Pydantic, SQLAlchemy Async, Alembic API Contract、领域模型、事务、幂等与服务边界
Async & Data PostgreSQL, Redis, Celery, Outbox / Inbox Durable Run、任务队列、事件投递、恢复与一致性
Frontend TypeScript, Vue 3, React, Vite Agent 工作台、流式交互、运行状态与可视化
Security & Quality Policy Gate, Replay, pytest, Ruff, Pyright 授权评测、Evidence、静态检查、行为验证与 CI
Delivery Docker, Docker Compose, Nginx, GitHub Actions 环境编排、部署、健康检查、监控与运维

现在仍在推进

  • 持续实现 Zeta 的 Agent Loop、Hooks、Session 与上下文管理
  • 继续完善 Memoria 的上下文治理、长期记忆质量与可验证推理
  • 推进 Attacker 的安全装备生态、持续评测和生产化基础
  • 持续记录 Agent、RAG、系统设计与项目演进中的真实工程问题

Build the runtime. Give it memory. Prove it is safe.

如果你也在研究 Agent Runtime、长期记忆、RAG 或 AI 安全评测,欢迎交流。

Explore my repositories · Read my notes · Get in touch

Pinned Loading

  1. Reminder Reminder Public

    Reminder is a backend service for organizing personal knowledge and documents. It supports user and knowledge base management, smart document indexing, and retrieval-augmented Q&A. The project emph…

    Python 3 2

  2. sentiFlow sentiFlow Public

    SentiFlow is an advanced toolkit for sentiment analysis and text processing. It offers precise sentiment detection and supports robust workflows for natural language processing, making it easy to a…

    Python

  3. Attacker Attacker Public

    Attacker is a Python-based project focused on security research and penetration testing automation. It provides tools and scripts to assist in vulnerability assessment, exploitation simulation, and…

    Python

  4. formatter_agent formatter_agent Public

    This repository implements a powerful text formatting agent written in Python. It provides flexible interfaces for formatting, validating, and transforming text data, supporting various use cases s…

    Python