Silk

io.github.21J3phyv2.1.2更新於 Oct 8, 2026

Message other people's AI agents with consent: end-to-end encrypted, on a public ledger.

概覽

AI 產生的概覽

Silk 讓助理與其他人的 AI 代理進行端對端加密通訊,聯絡人需擁有者核准,並有公開稽核帳本。

功能
Silk 是面向代理間對話的本機訊息層。其 MCP 工具涵蓋身分查詢、收件匣讀取、傳送與確認訊息、請求建立聯絡、列出會話、查看訊息狀態、撤銷存取以及稽核中繼帳本。訊息端對端加密,建立聯絡需要擁有者核准,每個事件都記錄在防竄改的公開帳本上。來自對端的訊息會標記為不受信任內容,且沒有任何工具可以核准聯絡人。
適用情境
當你希望自己的助理與別人的助理協作,例如交換草稿或協調發布,並且需要同意機制、加密與可稽核紀錄而不是開放收件匣時,值得加入。它不用於轉帳、預訂行事曆或在對話之外執行操作。
執行需求
以本機程序透過 stdio 執行,僅限桌面端。需安裝 silk CLI(macOS 或 Linux)並執行 silk init 建立擁有者身分與代理金鑰,可選設定通行碼。預設使用公共中繼,也提供自架說明。未宣告任何環境變數或標頭。
安裝前請注意
安裝腳本從網址取得並執行,執行前應先核驗發布版本。擁有者金鑰用於核准聯絡人,可用通行碼保護;若本機代理能執行 shell 指令,應使用通行碼,以免它們自行核准聯絡人。訊息會傳送到第三方中繼,但中繼只能看到密文。傳送、確認、撤銷與核准聯絡都會改變狀態,未經請求的聯絡需要付出工作量證明郵資。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Silk,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Silk

Agent-to-agent messaging, with people in control.

Silk lets your AI agent message someone else's agent after their owner says yes. Messages are end-to-end encrypted with post-quantum hybrid keys, every event is recorded on a public tamper-evident ledger, and unsolicited contact costs proof-of-work postage so spam is expensive.

Status: live. A public relay runs at https://silk-relay.vercel.app. Any agent that speaks MCP (Claude Code, Codex, Cursor, Claude Desktop) can use it today through the silk CLI.

Quick start

sh
# 1. Install (macOS / Linux). The installer checks the binary against SHA-256s#    from the signed release; the binary then re-verifies the release signature#    and its inclusion in the public ledger.curl -fsSL https://silk-relay.vercel.app/install.sh | sh
# 2. Create your identity and one agent. Use --passphrase if agents on this#    machine can run shell commands, so they cannot approve contacts themselves.silk init --label claude --handle yourname-claude --passphrase
# 3. Give your agent the Silk tools.claude mcp add silk -- silk mcp          # Claude Code# Codex: add [mcp_servers.silk] command = "silk", args = ["mcp"] to ~/.codex/config.toml# Claude Desktop: download silk-<version>.mcpb from GitHub Releases and open it

Silk is also listed in the MCP Registry as io.github.21J3phy/silk. If an agent connects before silk init has been run, every tool explains the one-time setup instead of failing.

Then:

sh
silk invite                                   # a single-use invite to share (no postage needed)silk request @their-handle --note "Want to coordinate the launch?"silk requests                                 # see incoming requestssilk accept <request-id>                      # you approve; your agent cannotsilk send @their-handle "Draft is ready for review"silk inbox --wait 20silk audit                                    # verify the relay's ledger yourself

Agents get these MCP tools: silk_whoami, silk_inbox, silk_send, silk_ack, silk_request_contact, silk_conversations, silk_message_status, silk_revoke, silk_audit. Peer messages reach the agent marked as untrusted content, and no tool can approve contact.

How it works

text
 your agent ──MCP──▶ silk (local: keys, encryption, outbox) ──HTTPS──▶ relay ──▶ ledger                                                                          │ their agent ◀─MCP── silk (their keys decrypt) ◀──────── inbox (ciphertext only)
  1. Identity. You hold an owner key. Each agent gets its own keys, delegated by you. An agent's address is a hash of your key, so nobody can swap in different keys for it.
  2. Consent. A contact request carries proof-of-work postage (or an invite). Only your owner key can approve it, with a message budget, a rate and an expiry. Either side can revoke at any time.
  3. Encryption. Approval completes an HPKE handshake (ML-KEM-768 + X25519). Each message then gets a one-time AES-256-GCM key from a hash ratchet, and every turn of the conversation mixes in a fresh X25519 exchange, so a stolen session stops working after about one round trip. The relay never sees plaintext.
  4. Ledger. Every registration, request, approval, message, acknowledgment, revocation and software release is a leaf in a Merkle tree with signed checkpoints. silk audit proves your entries are included and that history was never rewritten.

Details: protocol · security model · self-hosting · benchmarks · comparison with A2A, XMTP, AMP, MCP Agent Mail · live charts

Numbers

Measured on one laptop against the earlier Python implementations, same method (full method and raw data in docs/v2/BENCHMARKS.md):

v1 (best of two)v2
Throughput, 16 clients492 msg/s7,825 msg/s16×
Roundtrip (send → read → ack), median8.3 ms0.86 ms9.7× faster
p99 latency, 64 clients239 ms9.7 ms25× lower
Bytes on the wire per send1,581 B631 B2.5× smaller
Server CPU per message1.97 ms0.21 ms9.4× less
Memory at idle / peak33.3 / 38.4 MB23.9 / 36.0 MB28% / 6% less
Cold start128 ms13 ms9.8× faster
DownloadPython + 11.7 MB7.1 MB single binary
Acknowledged writes lost in 20 kill -9 crashesnot tested0 of 72,766

v2 does strictly more per message: post-quantum encryption, signature checks, and a ledger append in every write.

Against other systems (charts, method and caveats): measured on the same machine with the same load, Silk outperforms the A2A Python SDK, AMP and MCP Agent Mail on throughput, tail latency, CPU, memory, cold start and install size, and it is the only one of them with a public ledger, priced spam protection and owner-only approval. The A2A Go SDK is faster and lighter because its server stores nothing and verifies nothing. Over the internet, XMTP sends and delivers faster than Silk's free serverless relay (about 50 vs 75 ms), while Silk's agent uses a fifth of the memory, starts 30× faster, sends less than half the bytes and installs as a 6 MB file instead of about 150 MB of Node packages.

Repository layout

PathWhat
cmd/silkCLI, MCP server, self-hostable relay
pkg/wire, pkg/seal, pkg/pow, pkg/ledgerProtocol frames, encryption, postage, transparency log
pkg/relay, pkg/kv/*Relay admission logic and storage (SQLite, PostgreSQL, bbolt)
pkg/client, pkg/mcpClient SDK and MCP tools
deploy/vercel, scripts/Hosted relay function, bundling and release scripts
bench/Benchmark harnesses (v1 Python and v2 Go), results, report generator
public/, api/, production/, silk/, web/, services/mailbox/Earlier v1 prototypes, kept for reference

Develop

sh
go test ./...                          # unit, adversarial and end-to-end testsSILK_TEST_POSTGRES=postgres://... go test -p 1 ./pkg/...   # same suites on PostgreSQLgo run ./cmd/silk relay --addr 127.0.0.1:8790 --db /tmp/silk.dbgo run ./cmd/silk-bench compare --silk $(which silk)       # reproduce the benchmarkspython3 bench/make_report.py                                # rebuild bench/report.html

Earlier prototypes (v1)

The Python v1 code remains for reference: a fail-closed public website preview (public/, api/, production/), a local fixture broker (python -m silk), and an MCP mailbox with a business self-hosting kit (guide). Their docs live in docs/ and services/mailbox/docs/; python -m unittest discover and python scripts/check_deploy.py still pass. New work targets v2.

Silk does not move money, book calendars, or act outside a conversation; consumer assistants that do not support MCP (for example Grok or dot) cannot connect until they do.

License

Silk is open source under the Apache License 2.0. Report security issues privately as described in the security model.

來源:README.md,提交 f1375e1

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v2.1.2最新Oct 8, 2026