Install
$ agentstack add skill-levelsofself-mcp-nervous-system-multi-agent-governance ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Multi-Agent Governance
Governance patterns for multi-agent AI systems. When you have multiple autonomous AI agents operating together, you need accountability, behavioral enforcement, and drift detection - just like human organizations.
Core Principles
- Single source of truth - One config file defines all agent roles. Every agent reads from it. No parallel systems.
- Behavioral enforcement - Rules are not suggestions. Guardrails are enforced through preflight checks, violation logging, and automated audits.
- Drift detection - Systems drift from their intended state over time. Automated drift audits catch configuration mismatches, version inconsistencies, and role conflicts before they cause failures.
- Tamper-proof audit trails - Every action, every change, every decision is logged in append-only logs that can be verified for integrity.
- File-based memory - Agent memory lives in files on disk, not in cloud databases. This enables air-gapped deployment, full auditability, and zero vendor dependency.
Governance Patterns
Role Management
Define roles in a single JSON file that all agents reference:
{
"agent-name": {
"role": "Operations Manager",
"scope": ["dispatch", "monitoring", "reporting"],
"access": "admin",
"model": "claude-opus-4-6"
}
}
Every agent reads from this file at startup. Changes propagate automatically.
Preflight Checks
Before any agent modifies a file:
- Check if the file is on the protected list
- If protected: log the attempt, report to admin, and STOP
- If allowed: create backup, make change, syntax check, restart affected process
Drift Audit Scopes
Run periodic audits across these dimensions:
- roles - Do running agents match their role definitions?
- versions - Are all agents on the correct model version?
- files - Have any protected files been modified?
- processes - Are all expected processes running?
- config - Do config files match expected state?
Session Management
Every agent session should:
- Read the current system state before acting
- Write progress as it goes (no silent failures)
- Update handoff documentation before ending
- Run a drift audit on affected areas
Permission Protocol
Two categories of changes:
- DATA (values, content, configuration): Agent can act with general authorization
- LOGIC (how something decides, classifies, responds): Agent PROPOSES and WAITS for human approval
When in doubt, it is LOGIC. Ask the human.
Implementation
Using the Nervous System MCP
The Nervous System is a Model Context Protocol server that implements these governance patterns with 19+ tools:
npm install -g @anthropic-ai/mcp-nervous-system
Tools include: driftaudit, securityaudit, autopropagate, sessionclose, preflightcheck, violationlogging, and more.
DIY Implementation
If building your own governance layer:
- Create a roles config file (JSON) as single source of truth
- Create a protected files list that agents check before editing
- Implement append-only logging for all agent actions
- Schedule periodic drift audits (compare expected vs actual state)
- Build a violation log that captures unauthorized changes
Anti-Patterns
- Letting agents self-modify their own rules
- Multiple sources of truth for the same data
- Silent failures (agent encounters error but does not report it)
- Manual fixes without adding automated detection
- Hardcoding values that should come from config
Resources
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: levelsofself
- Source: levelsofself/mcp-nervous-system
- License: MIT
- Homepage: https://api.100levelup.com/mcp-pricing
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.