Inspiration

I run three or four coding agents at once, in several repositories. By the evening I do not know which session touched what, which one is still alive, or whether two of them are about to commit over each other. Every harness already writes a full transcript to disk. Nobody reads them. Watcher does.

Demo video (2 min 43): https://youtu.be/jSU2gm1HrkY

What it does

You type one command. Watcher reads the transcripts your coding agents already wrote (Claude Code, Antigravity). It tells you how many sessions exist and when each one last wrote a line. Then it checks the one hazard that costs real work: two live sessions in the same git working tree and branch. In that tree the git index is shared. A commit from one session picks up whatever the other has staged.

When it finds a real collision it files a task at the top of your backlog and puts a dated follow-up in your calendar. A status card on your canvas stays open while it works. Then it closes the card with one line saying what it filed. Everything lands on surfaces you already read and edit.

Three refusals carry the design:

  1. It never says an agent is "working". A transcript records the last line a session wrote. A crashed session goes quiet exactly like an idle one, so the only honest sentence is "last sign of life N minutes ago".
  2. A value it could not read is absent, never zero. Two sessions that both recorded no project are not evidence that they share a tree. On a tool whose whole value is trust, a fabricated alert is worse than none.
  3. It proposes, you dispose. It writes to your backlog and calendar. It never runs git, never commits, never stops another session.

How we built it

A single Strands Agents SDK agent in Python. Every capability comes from one MCP server, @mnemosyne_os/mcp, launched over stdio with npx. The package is pinned to a version, so a judge runs the same server the demo ran on. The system prompt is the six-step loop plus the three refusals above.

Six tools do the work. Two read the machine: mnemosyne_agents and mnemosyne_agent_collisions. One reads memory: mnemosyne_query, for what the human already decided, so it never re-proposes something they rejected. Three write: mnemosyne_todo_add, mnemosyne_agenda_add and mnemosyne_cockpit_update.

The model provider is one declared variable, never guessed. Amazon Bedrock by default, the Anthropic API, a local Ollama model, or the loopback brain proxy of Mnemosyne OS. A provider that cannot be built says so and stops. It is never silently swapped, because a demo that quietly ran on a different model proves nothing.

Challenges we ran into

The first real run returned HTTP 502 for all 23 tools at once. Two tool schemas used a JSON Schema union type ("string" or "null") that one model route cannot represent. A single tool carrying one fails the whole request. Bisecting the 23 tools found the two. Watcher flattens those unions on the client side and prints how many schemas it patched. On a host that already handles them, the header reads 0.

The second one was a lie in the first draft of the output. "3 agents working" read fine and was false: one of them had died. That sentence is now forbidden in the system prompt.

Accomplishments that we're proud of

On its first real run it found an actual collision on my own machine: three live sessions on the same branch of the same repository. One of them was the session building Watcher. It filed the task, set the follow-up, and closed its card. Eleven tool calls, no human step in between. The demo video is a later run of the same kind, on a real collision, unedited except for cuts.

What we learned

The interesting part of a background agent is not what it can do on its own. It is what it hands you, and what it refuses to say.

What's next for Watcher, by Mnemosyne OS

Running it on a schedule instead of on demand. Reading more harnesses: a connector is a data file, never code. A per-session cost line, read from the usage records the transcripts already carry.

Disclosure of pre-existing work

New for this hackathon: everything in the repository (the Strands agent, its system prompt, the model selection, the CLI, the setup script). Pre-existing, used as a dependency: Mnemosyne OS and its MCP server @mnemosyne_os/mcp (MIT, on npm). No change was made to the package for this submission. The transcript readers it exposes were built in August 2026.

Built With

Share this project:

Updates

posted an update —

Since we submitted: memory that travels between two machines

Watcher reads and writes one person's memory. The question we kept hitting was what happens when a second machine, or a second person, needs that same memory.

The peer to peer layer came together during the submission period. Two installs of Mnemosyne OS open a direct encrypted tunnel, each side identified by its own key, and a vault can be shared read only or replicated between them. The first real tunnel ran on September 14, with a message acknowledged in 6 ms.

Where it stops today

  • That tunnel ran between two nodes on one machine, Windows talking to WSL.
  • Two homes behind two routers is not proven.
  • NAT traversal is still on paper.
  • None of it has shipped. It ships when it holds up, rather than on a date.

What it is for

A small association with twenty years of files spread across three old machines. They share one memory, with no server in the middle and no account to create. The agent on each machine answers from what the whole group knows, and the files stay where they already are.

Same rule as the agent itself. It runs where the files live.

Log in or sign up for Devpost to join the conversation.

Submission history