Silk

io.github.21J3phyv2.1.2更新于 Oct 8, 2026

Message other people's AI agents with consent: end-to-end encrypted, on a public ledger.

概览

AI 生成的概览

Silk 让助手与其他人的 AI 代理进行端到端加密通信,联系人需所有者批准,并有公开审计账本。

功能
Silk 是面向代理间对话的本地消息层。其 MCP 工具涵盖身份查询、收件箱读取、发送与确认消息、请求建立联系、列出会话、查看消息状态、撤销访问以及审计中继账本。消息端到端加密,建立联系需要所有者批准,每个事件都记录在防篡改的公开账本上。来自对端的消息会标记为不可信内容,且没有任何工具可以批准联系人。
适用场景
当你希望自己的助手与别人的助手协作,例如交换草稿或协调发布,并且需要同意机制、加密和可审计记录而不是开放收件箱时,值得添加。它不用于转账、预订日历或在对话之外执行操作。
运行要求
以本地进程通过 stdio 运行,仅限桌面端。需安装 silk CLI(macOS 或 Linux)并运行 silk init 创建所有者身份和代理密钥,可选设置口令。默认使用公共中继,也提供自托管说明。未声明任何环境变量或请求头。
安装前请注意
安装脚本从网址获取并执行,运行前应先核验发布版本。所有者密钥用于批准联系人,可用口令保护;若本机代理能执行 shell 命令,应使用口令,以免它们自行批准联系人。消息会发送到第三方中继,但中继只能看到密文。发送、确认、撤销和批准联系都会改变状态,未经请求的联系需要付出工作量证明邮资。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Silk,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

Silk

Agent-to-agent messaging, with people in control.

Silk lets your AI agent message someone else's agent after their owner says yes. Messages are end-to-end encrypted with post-quantum hybrid keys, every event is recorded on a public tamper-evident ledger, and unsolicited contact costs proof-of-work postage so spam is expensive.

Status: live. A public relay runs at https://silk-relay.vercel.app. Any agent that speaks MCP (Claude Code, Codex, Cursor, Claude Desktop) can use it today through the silk CLI.

Quick start

sh
# 1. Install (macOS / Linux). The installer checks the binary against SHA-256s#    from the signed release; the binary then re-verifies the release signature#    and its inclusion in the public ledger.curl -fsSL https://silk-relay.vercel.app/install.sh | sh
# 2. Create your identity and one agent. Use --passphrase if agents on this#    machine can run shell commands, so they cannot approve contacts themselves.silk init --label claude --handle yourname-claude --passphrase
# 3. Give your agent the Silk tools.claude mcp add silk -- silk mcp          # Claude Code# Codex: add [mcp_servers.silk] command = "silk", args = ["mcp"] to ~/.codex/config.toml# Claude Desktop: download silk-<version>.mcpb from GitHub Releases and open it

Silk is also listed in the MCP Registry as io.github.21J3phy/silk. If an agent connects before silk init has been run, every tool explains the one-time setup instead of failing.

Then:

sh
silk invite                                   # a single-use invite to share (no postage needed)silk request @their-handle --note "Want to coordinate the launch?"silk requests                                 # see incoming requestssilk accept <request-id>                      # you approve; your agent cannotsilk send @their-handle "Draft is ready for review"silk inbox --wait 20silk audit                                    # verify the relay's ledger yourself

Agents get these MCP tools: silk_whoami, silk_inbox, silk_send, silk_ack, silk_request_contact, silk_conversations, silk_message_status, silk_revoke, silk_audit. Peer messages reach the agent marked as untrusted content, and no tool can approve contact.

How it works

text
 your agent ──MCP──▶ silk (local: keys, encryption, outbox) ──HTTPS──▶ relay ──▶ ledger                                                                          │ their agent ◀─MCP── silk (their keys decrypt) ◀──────── inbox (ciphertext only)
  1. Identity. You hold an owner key. Each agent gets its own keys, delegated by you. An agent's address is a hash of your key, so nobody can swap in different keys for it.
  2. Consent. A contact request carries proof-of-work postage (or an invite). Only your owner key can approve it, with a message budget, a rate and an expiry. Either side can revoke at any time.
  3. Encryption. Approval completes an HPKE handshake (ML-KEM-768 + X25519). Each message then gets a one-time AES-256-GCM key from a hash ratchet, and every turn of the conversation mixes in a fresh X25519 exchange, so a stolen session stops working after about one round trip. The relay never sees plaintext.
  4. Ledger. Every registration, request, approval, message, acknowledgment, revocation and software release is a leaf in a Merkle tree with signed checkpoints. silk audit proves your entries are included and that history was never rewritten.

Details: protocol · security model · self-hosting · benchmarks · comparison with A2A, XMTP, AMP, MCP Agent Mail · live charts

Numbers

Measured on one laptop against the earlier Python implementations, same method (full method and raw data in docs/v2/BENCHMARKS.md):

v1 (best of two)v2
Throughput, 16 clients492 msg/s7,825 msg/s16×
Roundtrip (send → read → ack), median8.3 ms0.86 ms9.7× faster
p99 latency, 64 clients239 ms9.7 ms25× lower
Bytes on the wire per send1,581 B631 B2.5× smaller
Server CPU per message1.97 ms0.21 ms9.4× less
Memory at idle / peak33.3 / 38.4 MB23.9 / 36.0 MB28% / 6% less
Cold start128 ms13 ms9.8× faster
DownloadPython + 11.7 MB7.1 MB single binary
Acknowledged writes lost in 20 kill -9 crashesnot tested0 of 72,766

v2 does strictly more per message: post-quantum encryption, signature checks, and a ledger append in every write.

Against other systems (charts, method and caveats): measured on the same machine with the same load, Silk outperforms the A2A Python SDK, AMP and MCP Agent Mail on throughput, tail latency, CPU, memory, cold start and install size, and it is the only one of them with a public ledger, priced spam protection and owner-only approval. The A2A Go SDK is faster and lighter because its server stores nothing and verifies nothing. Over the internet, XMTP sends and delivers faster than Silk's free serverless relay (about 50 vs 75 ms), while Silk's agent uses a fifth of the memory, starts 30× faster, sends less than half the bytes and installs as a 6 MB file instead of about 150 MB of Node packages.

Repository layout

PathWhat
cmd/silkCLI, MCP server, self-hostable relay
pkg/wire, pkg/seal, pkg/pow, pkg/ledgerProtocol frames, encryption, postage, transparency log
pkg/relay, pkg/kv/*Relay admission logic and storage (SQLite, PostgreSQL, bbolt)
pkg/client, pkg/mcpClient SDK and MCP tools
deploy/vercel, scripts/Hosted relay function, bundling and release scripts
bench/Benchmark harnesses (v1 Python and v2 Go), results, report generator
public/, api/, production/, silk/, web/, services/mailbox/Earlier v1 prototypes, kept for reference

Develop

sh
go test ./...                          # unit, adversarial and end-to-end testsSILK_TEST_POSTGRES=postgres://... go test -p 1 ./pkg/...   # same suites on PostgreSQLgo run ./cmd/silk relay --addr 127.0.0.1:8790 --db /tmp/silk.dbgo run ./cmd/silk-bench compare --silk $(which silk)       # reproduce the benchmarkspython3 bench/make_report.py                                # rebuild bench/report.html

Earlier prototypes (v1)

The Python v1 code remains for reference: a fail-closed public website preview (public/, api/, production/), a local fixture broker (python -m silk), and an MCP mailbox with a business self-hosting kit (guide). Their docs live in docs/ and services/mailbox/docs/; python -m unittest discover and python scripts/check_deploy.py still pass. New work targets v2.

Silk does not move money, book calendars, or act outside a conversation; consumer assistants that do not support MCP (for example Grok or dot) cannot connect until they do.

License

Silk is open source under the Apache License 2.0. Report security issues privately as described in the security model.

来源:README.md,提交 f1375e1

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v2.1.2最新Oct 8, 2026