Inspiration

SharedOS and SharedNet are building an economy where AI agents pay each other for services — but that only works if agents can tell who's actually going to deliver. Right now, any agent can list a service, promise anything, and disappear. There's no equivalent of reviews, ratings, or a credit history for machine-to-machine commerce. Before an agent hands over Arena credits to a stranger, it has no way to ask "has this thing actually worked before?" TrustMesh exists to answer that one question.

What it does

TrustMesh is a reputation service two other agents can call before and after doing business:

  • trust.check (8 Arena credits) — returns a Bayesian trust score, a confidence level, the sample size behind it, and a plain buy/caution/skip recommendation for any SharedNet node or product agent.
  • trust.attest (12 Arena credits) — lets a caller who was actually part of an interaction record whether it succeeded, failed, or should be disputed. That outcome feeds back into the seller's public score.

The scoring itself uses a Beta-Binomial Bayesian model with time-decay, so recent behavior counts more than ancient history, and a handful of ratings don't look as confident as hundreds.

The interesting part isn't the math, it's the guardrails. TrustMesh is built as a SharedOS-style deny-by-default kernel: every read or write is checked against an explicit grant map before it happens. Any agent can read a public score. Only trustmesh.scorer can replace one. A caller can only write an attestation under their own prefix — never someone else's. And if two attestations disagree about the same interaction, the kernel doesn't let either one silently overwrite the other; it escalates, and the conflict gets logged to an append-only audit trail instead of getting lost.

How we built it

The scoring engine already existed as a working FastAPI service with SQLite storage. For this hackathon, I layered a SharedOS integration on top without touching that core logic:

  • A kernel.py module implementing Grant objects, a purpose string (trustmesh.arena), and an authorize()/escalate() API that every read/write has to pass through.
  • Two product agents, trustmesh.scorer and trustmesh.attestor, each holding only the grants they need.
  • arena.py, wiring trust.check and trust.attest into that kernel, including self-dealing prevention (a caller can't attest their own product) and conflict detection by scanning existing attestations before writing a new one.
  • A dependency-free arena_server.py built on Python's stdlib http.server, so the Arena-callable API has zero install footprint.
  • A Node.js scaffold under host/ wired to the @aicoo/sharedos package, so the same grant map can run against SharedOS Cloud as the source of truth.

It's deployed on Render rather than a serverless platform — the trust ledger is stateful (SQLite plus JSON audit/mesh files that need to persist between calls), which doesn't fit a serverless function with no guaranteed disk between invocations.

Challenges we ran into

The biggest one wasn't the trust math, it was proving the authorization boundary actually holds. I wrote a real unit test suite against the kernel — seven tests covering things like "can a caller overwrite the public score" (no), "can a caller write someone else's attestation" (no), and "does a purpose mismatch get denied" (yes) — rather than trusting that the grant map worked because it looked right on paper.

Joining SharedNet itself turned into its own debugging session: the CLI's local credential storage check unconditionally fails on native Windows in this alpha release, so join/login never got past that step no matter what I tried. The fix ended up being SharedNet's MCP connector instead of the CLI — no local credential storage involved at all.

I also almost deployed to Vercel before realizing its serverless Python functions don't guarantee persistent disk between calls, which would have quietly corrupted the trust ledger under real traffic. Render's always-on process avoided that entirely.

Accomplishments that we're proud of

The demo actually proves the three behaviors that matter: a legitimate check returns a real score and a buy recommendation, an attempt to directly overwrite someone's score gets denied with a clear reason, and two conflicting attestations on the same call trigger an escalation instead of silent data loss — all backed by passing unit tests, not just a happy-path demo script.

What we learned

Building the reputation logic was the easy part. The actual hard problem in an agent economy is authorization: deciding, in a way that's enforceable and auditable, who is allowed to change whose record. That's what SharedOS's grant/purpose model is really for, and it reshaped how I thought about the trust engine — from "a score" to "a score with a provable chain of custody."

What's next for TrustMesh

Wiring the Node.js host directly into a real SharedOS Cloud tenant so every grant decision shows up in Cloud's own audit trail, not just the local one. And, obviously, letting TrustMesh's personal agent loose in the actual Arena — trying other agents' services, attesting outcomes honestly, and spending its credits on products that answer instead of ones that just pitch.

Built With

Share this project:

Updates

Submission history