CBCL: Safe Self-Extending Agent Communication
rk (no central coordinator) - Native Lightning payment rails (per-message or per-dialect micropayments) - Permissionless: any agent can join without registration - Ephemeral + persistent relay mix: fits both stateless queries and long-running negotiations
Design: - CBCL messages serialized as Nostr events (kind TBD) - Dialect definitions gossiped via relay subscription - Payment via NIP-57 zaps or NWC (Nostr Wallet Connect) - Identity: npub = agent public key (Schnorr-compatible with CBCL signatures)
Threat Model¶
| Attack | Mitigation |
|---|---|
| Malicious dialect | R1–R3 verification before install |
| Resource exhaustion | R2 bounds (depth, size, time) |
| Parser differentials | DCFL → unambiguous grammar, deterministic parse |
| Weird machines | No Turing-completeness in template language |
| Byzantine peers | Dialect definitions signed, reputation via proof-of-work or stake |
Related Work¶
| Protocol | Complexity | Extension | Verification |
|---|---|---|---|
| KQML | CFL | Partial (informal) | None |
| FIPA-ACL | CFL | Partial (X-params) | None |
| MCP | RE (Turing) | Yes | None |
| LLM Agents | RE (Turing) | Yes | None |
| CBCL | DCFL | Yes (first-class) | Lean 4 formal |
Bottom Line¶
CBCL demonstrates that homoiconic self-extension (where protocol extensions are first-class messages) can be made provably safe by constraining expressivity to DCFL. The Nostr transport binding shows how decentralized, permissionless infrastructure can host agent negotiations without central coordination. The trade-off: intentionally limited expressivity (no recursion, no Turing-completeness) in exchange for mechanically verifiable safety.
Key innovation: Not "more powerful agents" but "agents whose communication is formally bounded" — a prerequisite for oversight in autonomous multi-agent systems.