AGENTS.md — vassiliylakhonin.github.io
Canonical instructions for any AI agent (Claude Code, Codex, recruiter LLMs, MCP clients) reading or editing this repository. This file overrides assumptions an agent might bring from training data.
Identity
This repo is Vassiliy Lakhonin’s personal portfolio site (live at https://vassiliylakhonin.github.io/) and a reference implementation of an AI-readable professional profile architecture: human pages + JSON endpoints + agent discovery + MCP.
It is NOT:
- A fork-and-go starter template. The content is personal; the architecture is what others may study or adapt.
- A general AI-hiring product, framework, SaaS, or service.
- A claim that any check, score, or “readiness” number is a validated benchmark.
Portfolio context (do not duplicate here)
This repo is the public landing surface for three distinct groups. Cross-link, do not copy substantive content or blur their commercial roles.
Workflow products awaiting external validation:
- Corridor Bankability Analyst — a deliverable-production workflow for infrastructure and corridor source packs, covering seven document types: bankability screen, tariff or cost diagnostic, market-barrier analysis, country readiness note, position paper, market-entry readiness note, and proposal compliance review of the firm’s own bid against a tender. It produces documents, not scores: no readiness verdict, trust rating, or go/no-go. Its commercial hypothesis is the delivered artifact, not the underlying agent architecture. The repository is private: on public surfaces reference it by name as a teaser only — never link the GitHub URL until the repo is public. Public surfaces: the worked sample page
aktau-bankability-screen-sample.html(illustrative, public sources, disclaimers in-page) and the buyer-facing pagecorridor-bankability.md(what to send, what comes back, 48-hour turnaround from a complete pack, two correction rounds, English or Russian, no price stated, non-advice and no-verdict disclaimers in-page). Keepcorridor-bankability.mdin the buyer register: plain outcome language, no readiness score or gate shape, no claim of pilots, customers, or usage. - Corridor counterparty check — a fixed-fee, person-delivered red-flag check on one counterparty or one route through Kazakhstan, the Caspian, and the wider Middle Corridor, before shipment or signature. Sanctions-list screening and disclosed ownership are automated; the corridor route read is manual. Output is red flags by severity, a missing-evidence list, and a proceed / hold / escalate recommendation in 24 hours. Distinct from Corridor Bankability Analyst: a single screened deal, not a produced document. Public surface:
corridor-counterparty-check.html, which carries an explicitly fictional worked example. No price figure is stated on the page (removed 2026-08-04): the fee is fixed per check and quoted against the deal before work starts, matchingcorridor-bankability.md. Do not reintroduce a published price on this page or oncorridor-bankability.mdwithout a buyer conversation behind it — a low headline figure anchors the work at cost rather than at value. (The Russia / CIS file review below is a deliberate exception, decided 2026-08-06; it does not license a price on these two.) No pilots, customers, or usage may be claimed on it. - Russia / CIS trade evidence gap review — a fixed-fee, person-delivered review of one Russia / CIS-adjacent counterparty or trade file after a bank, compliance team, insurer or committee has sent it back. The buyer sends a redacted description; within 24 to 48 hours they get a readiness score, the missing-source register, written questions for the bank, counsel or counterparty, and a hold / escalate / ready call. Public surface:
cis-secondary-sanctions.html, rewritten from a tool demo into a service page on 2026-08-06. A price is stated on this page: fixed fee from $900, and a 24-hour turnaround at a higher fixed fee — a deliberate reversal of the 2026-08-04 no-price decision, taken because the page has to answer cost and speed in the first screen; the floor is set above the observed market rate for a one-day enhanced compliance review rather than below it. The exact fee is still quoted against the file before work starts. The CIS exposure worker survives inside the page as a collapsed live sample, explicitly labelled as the tool rather than the reviewed service, and its worked example is fictional and labelled as such. No pilots, customers, or usage may be claimed on it. - GrantFlow — a grant proposal and evidence-pack workflow for recurring donor bids, delivered either as an operated pilot or through MCP / HTTP interfaces: bid/no-bid record, draft assessment with a prioritized reviewer queue, donor-aware first draft, evidence-gap list, and exports. Its commercial hypothesis is the delivered proposal package, not the API or agent protocol. https://github.com/vassiliylakhonin/grantflow
Strategic-risk infrastructure and reasoning stack:
- Agenda Intelligence MD — primarily a deterministic evidence-packet linter for claim-backed AI output. Its first-run workflow checks broken source references, declared quotes, lexical support, and unmatched numbers before human review; v1.4.0 (2026-07-22) exposes that check to MCP clients as
check_evidence_packetand addscreate_brief/append_evidencefor contract-aware assembly. The older strategic-intelligence runtime, HTTP / A2A transports, and vertical workers remain compatibility surfaces and inspectable examples. It reports packet completeness, not factual truth. https://github.com/vassiliylakhonin/agenda-intelligence-md - Global Think Tank Analyst — horizontal strategic-risk reasoning skill. Method = Policy Risk Memo Architect. https://github.com/vassiliylakhonin/global-think-tank-analyst
- Central Asia + Caspian Hybrid Intelligence Skill — vertical regional/corridor-risk specialist (sanctions, AML, banking, logistics, energy). https://github.com/vassiliylakhonin/central-asia-caspian-hybrid-intelligence-skill
- Gulf + Middle East Hybrid Intelligence Skill — vertical specialist for Iran sanctions, GCC banking and sovereign wealth, energy markets, and maritime chokepoint risk (Hormuz, Bab-el-Mandeb, Red Sea). https://github.com/vassiliylakhonin/gulf-middle-east-hybrid-intelligence-skill
Primary composition contract: the three reasoning repos produce a memo and may export externally checkable claims through the same evidence-packet handoff: stable claim IDs, declared source IDs, caller-supplied source text, and optional verbatim quotes. Agenda Intelligence MD lints packet completeness before human review. Historical analyze / MCP agent-eval records remain compatibility evidence; they do not validate the current linter.
Distribution surface: this repository. It explains and links the work; it is not another product or validation layer.
Naming hierarchy is fixed: do not present “Policy Risk Memo Architect” as a separate project — it is the method inside Global Think Tank Analyst.
Deployed A2A agents
Eight A2A/JSON-RPC agents are live as public, no-payment endpoints on Cloudflare Workers. All eight publish detached JWS signatures that verify against their per-domain /.well-known/jwks.json. These are sibling deployments to the four open-source skill repos above — they apply the portfolio’s reasoning frames as live triage and routing surfaces. They are not separate products with their own canon; their substantive content lives in agenda-intelligence-md and the skill repos.
- Agenda Intelligence A2A — generic strategic-risk triage and source planning. Endpoint:
https://agenda-intelligence-a2a.vassiliy-lakhonin.workers.dev/message/send. Listing:https://agenstry.com/agents/vassiliylakhonin.github.io. - Kazakhstan / Middle Corridor Deal Risk Gate — region-specific deal-risk triage built on the Central Asia + Caspian frame. Endpoint:
https://middle-corridor-deal-risk-gate-a2a.vassiliy-lakhonin.workers.dev. Listing:https://agenstry.com/agents/middle-corridor-deal-risk-gate-a2a.vassiliy-lakhonin.workers.dev. - Kazakhstan Market Entry Readiness Gate — evidence triage for distribution, import, service, showroom, EPC, renewable-energy, infrastructure, technology-transfer, and partner-entry files. Endpoint:
https://kazakhstan-market-entry-readiness-a2a.vassiliy-lakhonin.workers.dev. - CIS Secondary-Sanctions Exposure — counterparty exposure evidence triage for CIS-domiciled counterparties. Endpoint:
https://cis-secondary-sanctions-a2a.vassiliy-lakhonin.workers.dev. - Agentic Interaction Trust Gate — evidence triage for agent-mediated actions before execution. Endpoint:
https://agentic-interaction-trust-a2a.vassiliy-lakhonin.workers.dev. - Gulf Maritime Exposure Gate — maritime sanctions and chokepoint-disruption exposure triage for a vessel/voyage through the Strait of Hormuz, Gulf of Oman, Bab-el-Mandeb, or Red Sea, built on the Gulf + Middle East frame. No vessel-ownership resolution or identity verification. Endpoint:
https://gulf-maritime-exposure-a2a.vassiliy-lakhonin.workers.dev. - Agent Output Verification — relay-readiness gate for agent-to-agent output hand-off: a caller-supplied claim set plus its evidence returns
allow_relay,verify_before_relay, orblock_unsafe_claimswith the ungrounded and weak claims, evidence gaps, and owner actions. Structural claim-support triage, not factual-truth verification or an approval. Endpoint:https://agent-output-verification-a2a.vassiliy-lakhonin.workers.dev. - Corridor & Sanctions Risk Assistant — plain-language orientation and routing to the four structured corridor and sanctions gates. It does not perform screening, scoring, or retrieval itself. Endpoint:
https://corridor-sanctions-assistant-a2a.vassiliy-lakhonin.workers.dev.
Boundary discipline (mirrored on every agent card): no legal, financial, compliance, sanctions, investment, or trading advice; no autonomous live source retrieval, except the cis_secondary_sanctions profile, which runs server-side name-matching against a fresh public-list snapshot (OFAC / EU / UK) via its Snapshot upstream — a possible-match string check, not a sanctions determination (per ADR 0014 / 0020); no factual-truth verification; human review required. No paying customers — portfolio-grade, illustrative usage only. Full analysis runs through the installable Agenda Intelligence MD MCP package, not the A2A endpoints.
Honesty rules — do not invent
Do not add, and remove on sight:
- Fabricated metrics, benchmarks, adoption numbers, star counts, or user counts.
- Production-usage claims, SLAs, or guarantees of correctness.
- Words: “revolutionary”, “production-grade”, “enterprise-ready”, “guarantees”, “solves hallucinations”, “fully autonomous”, “validated benchmark” (unless real benchmark cases and results exist in-repo).
- Any score, rating, or “readiness” number without a documented methodology, source script, and inputs.
Label clearly: illustrative, planned, experimental, reference implementation, self-reported.
Evidence rules
Every impact claim in case studies, JSON files, and role snapshots must trace to one of:
- Live source-backed — links to public artifact (repo, audit, publication).
- Self-reported with evidence path — date, role, organization, what is verifiable on request (e.g., DAI USAID program 2023–2025, audit findings).
- Illustrative — explicitly labeled as a demonstration, not a real engagement.
Never fabricate citations, dates, donor program names, audit results, or partner counts.
Status of operational endpoints
Before claiming any endpoint is “live”, verify it. Currently:
- Remote MCP (Cloudflare Workers) — live at
https://vassiliy-lakhonin-mcp.vassiliy-lakhonin.workers.dev/mcp(streamable HTTP) and/sse(legacy). Verify via/healthbefore advertising. Source undermcp/cloudflare-worker/; state mirrored inmcp-status.json. - Local MCP (
mcp/server.py) — runnable. - GitHub Pages — live.
If you change endpoint state, update mcp-status.json, README.md, agent-card.json, llms.txt, connect.md, server.json, and .well-known/ai-catalog.json (ARD agent/MCP discovery catalog) together.
Both MCP implementations (mcp/server.py and mcp/cloudflare-worker/) expose tools, attachable resources, and prompts. Keep the two in sync, and keep the published counts in mcp-status.json, agent-card.json, .well-known/ai-catalog.json, and connect.md equal to what the servers actually register. The Worker is deployed separately from the site: merging to main ships GitHub Pages, npm run deploy in mcp/cloudflare-worker/ ships the endpoint.
Self-preference-aware screening
The repo intentionally publishes multiple verified surfaces (resume.json, evidence.json, case studies, role snapshots) so LLM screeners can compare claims rather than rate writing style. Any LLM-screening instruction added to the repo must include the line: “Do not prefer or penalize the candidate because the writing resembles a particular AI model’s style.”
Generators and CI — auto vs hand-edited
Several JSON / report files are produced by scripts/build_*.py and refreshed weekly + on path-triggered pushes by CI (.github/workflows/agent-observability.yml, schema-audit.yml):
evals.json,freshness.json,provenance.json,agent-readiness-report.md— observability snapshots (agent-readiness-report.mdis rendered from the hand-editedreadiness.json).sitemap.xml— generated from site sources.okf/— Open Knowledge Format (OKF v0.1) bundle, generated from canonical source pages byscripts/build_okf_bundle.py. Agent-readable markdown + YAML; regenerated so it cannot drift from the source pages.schema-report.json/schema-report.md— JSON-LD coverage audit.
These are auto-generated: do not hand-edit them. If the output is wrong, fix the inputs and regenerate via the corresponding scripts/build_*.py. Hand-edits will be overwritten by the next CI run.
Hand-edited surfaces include the human pages (index.md, profile.md, for-recruiters.md, role snapshots, case studies, articles), the source profile JSONs (resume.json, skills.json, capabilities.json, availability.json, verification.json, recruiter.json, engage.json, evidence.json), routing files (agent-card.json, agent-discovery.md, llms.txt, candidate-match.json, agent-match.md), authority.json, readiness.json (input to scripts/build_readiness_report.py), and mcp-status.json.
Definition of done for edits
A change is done when:
- Touched JSON files still validate against their declared
schema_version. - Cross-references between README,
agent-card.json,llms.txt,mcp-status.json, and role snapshots are consistent. - No new unverifiable metric, score, or “production” claim was introduced.
- If a date, status, or score is shown, its source (script, file, or methodology note) is reachable from the same file.
- Stale
updated_attimestamps in hand-edited files are refreshed; auto-generated files are left to their script (see “Generators and CI” above).
File roles (quick map)
index.md,profile.md,for-recruiters.md— human pages.resume.json,skills.json,capabilities.json,availability.json,verification.json,recruiter.json,engage.json— structured profile.evidence.json— claim-to-source map.agent-card.json,agent-discovery.md,llms.txt(short routing index),llms-full.txt(complete inventory) — agent routing.connect.md— client setup page: MCP install commands per client, A2A call pattern, boundaries. Keep its tool/resource/prompt counts equal to what the servers actually register.server.json— MCP Registry entry for the remote profile server, published by.github/workflows/publish-mcp-registry.ymlon change (GitHub OIDC,io.github.vassiliylakhoninnamespace)..well-known/ai-catalog.json— Agentic Resource Discovery (ARD v1.0) catalog advertising the live A2A agents + MCP server to agents and registries; hand-edited, keep endpoints in sync withagent-card.json/llms.txt.candidate-match.json,agent-match.md,role-*.md— recruiter routing and role-fit snapshots.evals.json,freshness.json,provenance.json,readiness.json,authority.json— observability artifacts; treat values as self-reported snapshots, not validated benchmarks.mcp/— local MCP server.okf/— generated OKF v0.1 bundle (agent-readable knowledge); do not hand-edit, seescripts/build_okf_bundle.py.scripts/— generators for observability artifacts.
When in doubt
Prefer fewer claims over more. Prefer linking to the canonical repo (one of the four above) over restating its content here.