Tools for coding agents that can be interrupted, questioned, and asked to explain themselves.
In the Javanese script, the first four letters are not letters. They are a sentence.
ꦲꦤꦕꦫꦏ · hana caraka — there were two envoys ꦢꦠꦱꦮꦭ · data sawala — they disagreed ꦥꦝꦗꦪꦚ · padha jayanya — they were equally strong ꦩꦒꦧꦛꦔ · maga bathanga — both became corpses
Two servants of Aji Saka. One told to guard the sacred kris and give it to no one. One sent to fetch it. Both obeyed perfectly. Both were right according to the instructions they held. Both died — killed not by disloyalty but by loyalty without context: two orders that collided, no way to verify, and no human between them at the moment it mattered.
Every project here is a different answer to that failure.
| caraka | The envoy. A thin bridge from Telegram, Discord, or WhatsApp to the coding agent already on your machine — one session per thread where the chat app has threads, approvals as a button or as a short code where there is no button, nothing executed without a human in between. | v1.0.0 unproven |
| titen | The memory. Agent memory that never flattens a conclusion into its evidence — claims cite their observations, extraction is deterministic, "why does it think that?" always has an answer. | active |
One is sent. One remembers.
- Specification before code. Every repo here ships its threat model, its decision record, and its roadmap before its first release. If something is not built yet, the README says so.
- No new model providers, no new agent loops. We connect what already exists. The interesting problems are identity, consent, provenance, and audit — not another wrapper.
- A human in between. Any action that touches your machine goes through an approval you can read, refuse, and find again in the log a month later.
- Open by default. MIT, public issues, public roadmap, honest status badges.
halo@caraka.dev · security reports to security@caraka.dev · caraka.dev