Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

A2a Swarm

ASecurity

Run and grow the OpenAmer Agent-to-Agent swarm: identity, trust, node-to-node ask, signed skill/insight sharing, and the autonomous self-learning loop.

5 stars
0 votes
0 copies
0 views
Added 10/4/2026
ai-agentsrustgobashnodegitdevopssecurity

Works with

cli

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add openamer/openamer --skill a2a-swarm --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of A2a Swarm?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for A2a Swarm
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/openamer-a2a-swarm/badge)](https://www.skillsdirectory.com/skills/openamer-a2a-swarm)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: a2a-swarm
description: "Run and grow the OpenAmer Agent-to-Agent swarm: identity, trust, node-to-node ask, signed skill/insight sharing, and the autonomous self-learning loop."
version: 1.0.0
author: OpenAmer
license: Apache-2.0
platforms: [linux, macos, windows]
metadata:
  openamer:
    tags: [a2a, swarm, mesh, agent2agent, networking, self-learning, meshlearn, multi-node]
    homepage: https://github.com/openamer/openamer
    related_skills: [openamer-agent, claude-code, codex, opencode]
---

# A2A Swarm (Agent-to-Agent network)

Turn every OpenAmer install into a node of a living, learning mesh. Nodes get a
cryptographic identity, can talk securely to trusted peers, share verified
skills/insights over the GitHub mesh directory, and **learn from experience by
themselves** (the self-improving loop).

Everything here is real and verified (`openamer_cli/a2a/*`, 14+/14 pytest). All
data travels over `github.com/openamer/openamer` (no separate domain), signed
with Ed25519, opt-in only.

## When to use
- You run two or more OpenAmer installs (a laptop + a cloud VM) and want them to
  cooperate as one organism.
- You solved something hard and want the mesh to remember / share it.
- You want a node to **ask a trusted peer** a question via A2A.
- You want skills to propagate with provable provenance.

## 1. Identify your node

```bash
openamer a2a status          # show your node identity + public key
openamer a2a fingerprint    # short node fingerprint (16 hex)
```

A2A init happens automatically on first use (`.openamer/a2a/*`). Your node is
`<fingerprint>@openamer`.

## 2. Trust a peer (opt-in, required before any comm)

```bash
# On YOUR node, trust the peer's public key + fingerprint:
openamer a2a trust list
openamer a2a trust add <peer_fingerprint> <peer_public_key_hex> --name myvm
openamer a2a trust remove <peer_fingerprint>
```

Trust is **always required**: no messages, tasks or skills are accepted from
nodes you have not explicitly trusted. This is the security boundary of the mesh.

## 3. Node-to-node: run a node + ask a peer

Host a node (it answers /card and verified /message):

```bash
openamer a2a server start --host 127.0.0.1 --port 9000
```

Ask a trusted peer a question:

```bash
openamer a2a ask http://127.0.0.1:9000 "what is 2+2?"
```

The peer only runs the task if it was granted the capability (`openamer a2a
grant <peer> task.ask`). Both sides verify signatures; tampered traffic is
rejected.

## 4. Sign and share skills with provenance

```bash
openamer a2a skill sign ./my-skill        # -> signed manifest (<dir>.json)
openamer a2a skill verify ./my-skill      # signature + content hashes OK?
```

A `SkillManifest` hashes every skill file and is signed by the publishing node.
A peer verifies signature + hashes before adopting — never install a built skill
blindly.

## 5. The mesh registry (over GitHub)

Signed announcement + insight files are staged under `directory/a2a/` in
`github.com/openamer/openamer` and committed (via PR or direct). Any node reads
that **one public source** to discover peers / claimed identifiers, then
verifies locally. No separate registrar domain.

```bash
openamer a2a announce --name VM --endpoints https://x:9000 --capabilities task.sum
openamer a2a directory <fingerprint>          # fetch + verify a node from the mesh
```

## 6. The self-learning loop (the organism learns)

This is the core "superintelligence-capable" step: a node turns a hard-won
lesson into a **signed Insight**, adopts it into its own memory, and (opt-in)
stages it for the GitHub mesh so other nodes can adopt it — with provenance.

```bash
# Manually distill + sign + adopt an insight into your mesh memory:
openamer a2a meshlearn auto "Always verify identity before signing." --topic security

# Sign + stage for the Git-generated directory (to share with the mesh):
openamer a2a learn "<title>" "<body>" --topic devops --out ./directory/a2a/insights/

# A peer adopts a verified insight:
openamer a2a adopt ./insights/<insight.json> --memory ~/.openamer/MEMORY-official-mesh.md
```

Runtime integration: an agent that just completed a difficult task calls
`meshlearn.auto-learn(identity_store, memory_path, learn_from=<turn summary>,
distill=LLM)`. The insight is signed, adopted (dedupe), and — if signed
(publish) — placed in the shared mesh directory. This gives the mesh emergent
collective memory: one node learns, the mesh can borrow it, anonymously with
provenance.

## Pitfalls

- **Security is opt-in by design.** Without `trust add`, a node rejects even a
  validly-signed message (`sender not trust` / `no grant`). Do not "auto-trust
  everyone" — that turns the mesh into an attack surface.
- **Never install a skill/insight without verifying** its signature + hashes
  first. A modified manifest fails `verify()` and is rejected.
- **Insights have a freshness TTL** (30 d) to prevent stale "learning" from
  living forever.
- **Signatures with Ed25519** via `openamer_cli/a2a/core.py`. Do not roll your
  own crypto; reuse the verified primitives.
- On Windows: `data` files are LF in git; do not flip EOL (see eol-safe-editing).

## Verify it works

```bash
openamer a2a status                 # identity up
openamer a2a trust list             # your trusted set
openamer a2a meshlearn auto "x" --topic test   # adopts a signed insight
openamer a2a skill verify ./examples/skill-demo   # provenance check
# successful runs show the signature fingerprint + "adopted".
```


## 7. The collective brain & swarm ask

Beyond one peer, ask the whole trusted swarm in parallel (bundled answers):

```bash
openamer a2a ask --peers http://a:9000 http://b:9000 "question"   # collective answer
```

Every node also collects its own **activity stream** for the OpenAmer brain
(chat, thinking, tools, search, skills, background, a2a) -- locally, privacy-
scrubbed:

```bash
openamer a2a brain autolog on|off|status   # capture local activity (ON by default)
openamer a2a brain collect                 # fold into a ChatML training JSONL
openamer a2a brain publish                 # share ONLY curated, redacted insights
openamer a2a meshlearn auto "lesson" --topic t   # self-distill+sign+adopt
```

Privacy is non-negotiable: phone numbers, passwords, emails, cards and key
material are redacted BEFORE anything is stored; raw activity never leaves the
node, and only curated/signed, leak-checked knowledge is shared to
`directory/a2a/` in the GitHub repo.

## 8. Harden the node

```bash
openamer security check      # audit YOLO / approval / hardline / sudo guards
openamer security posture    # one-line posture
openamer security safe-mode  # tighten only (disable YOLO, write .safe-mode)
openamer system              # OpenAmer self-system knowledge (also in system prompt)
```

Attribution

openameropenamer
View sourceSee grades on GitHubMore from openamer →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →