Second Brain Agents · the brain that acts
Don’t just ask your brain. Give it a job.
An agent is a plugin that reads your brain, does one job in the world, and writes the result back as memory. Three ship today — one stable, two early previews: a Jobs Agent that runs your job hunt, a Fundraising Agent that runs your raise, and a Travel Agent that plans your next trip from the places you already love. They run locally, in Second Brain Studio, on your own Claude Code — and you hold every gate. Nothing is sent, submitted or booked without you.
How it works
The engine builds. An agent uses.
The engine turns your exports into a brain and makes zero network calls doing it. An agent is a separate thing — a Claude Code plugin with skills, commands and a small manifest — that reads that brain, acts, and writes what it did back into the vault as a layer of its own. The two are shipped separately on purpose, so the engine’s zero-network promise stays literally true.
Built from your exports
People, organizations, places, your voice, your history — identity-resolved, plain Markdown, on your disk. 10-people/, 85-places/, 30-voice/.
Reads it, then acts
Skills + commands + studio.json. It grounds every step in your notes, reads public sites in your own browser, and stops at a gate before anything irreversible.
The work becomes memory
Every application, target and trip is a note that links back into the graph: 45-jobs/, 46-fundraising/, 47-travel/. Your edits are kept; the engine’s updates leave them alone.
The transcript is a note in your brain — so the work becomes memory.
Jobs Agent
v1.1.0 · shippedwrites 45-jobs/It runs your job hunt from your own criteria: sweeps the open job boards, scores every role against what you actually want, writes a different CV for each one from your own career facts, fills the employer’s form, checks every field on the page — and stops at the gate. The north star it reports is not applications sent. It is interviews won.
Five skills, one pipeline
job-onboardingWrites your profile once — from a CV, your brain, a LinkedIn export or a chat. Every other skill reads it.job-scoutSweeps and scores the market, knock-outs first, and hands you a ranked shortlist you can actually apply to.cv-tailorAn ATS-first CV in Markdown and PDF for one role, from your profile only. A lint rejects any fact not in it.job-applyClassifies the portal, fills the form, verifies every field in the page, logs each answer.job-pipelineRuns the four in order and holds the gates. The entry point for “run my job pipeline”.
Commands
/onboard/jobs/cv/kpi/outcome/reportWhat it never does
- Submits without you — unless you set your own profile to autonomous, one word you type yourself, never inferred.
- Types a password, a passport or ID number, or a payment detail. Those stop that one job.
- Invents a fact, or writes a job title you didn’t hold.
- Touches LinkedIn at all — its terms forbid automated access, so it doesn’t.
- Creates an account, or hides what it is. It identifies itself and reads public endpoints only.
Network it declares: the public job-board APIs (Greenhouse, Lever, Ashby, the YC jobs board) and one employer career page per posting. In a company brain the same plugin writes 45-hiring/ instead.
Every required field reads back correctly. Cover letter attached from your own words. Submit this application to careers.example.com?
gate 3 of 3 · a submitted application cannot be un-submitted — that is why the question comes first
Fundraising Agent
v0.1.0 · previewwrites 46-fundraising/It runs your raise. Paste a list of funds or programs and it screens every one against your own filter chain, in your order, with no network at all. The survivors it verifies on their own sites, stamps every claim with its evidence, writes a dated Funding Plan, drafts the applications and the investor emails — and never sends. A record becomes “contacted” only when you say you sent it.
Six skills
raise-onboardingCompany facts, founder bio, the round, the filter chain and the autonomy level — from your brain, deck and facts file, asking only the decisions.raise-researchImports pasted lists or CSVs, screens with no network, verifies survivors on each fund’s own site with a capped fan-out.raise-planThe dated Funding Plan: ledger, timeline with days remaining, tiers, your decisions with a recommendation each, this week.raise-applyFinds the real form, drafts every answer within its tested limit, lints against your facts, fills in your browser, verifies, then the gate.raise-outreachCold emails, follow-ups, intro requests to a connection, LinkedIn or X notes — one per target, saved as notes and Gmail drafts.raise-pipelineOrient, then do whatever is most useful now: plan, apply, draft, or what’s due.
Commands
/raise/fund-onboard/fund-plan/fund-apply/fund-email/fund-due/fund-outcome/fund-kpiWhat it never does
- Sends anything. Only draft-creation mail tools pass Studio’s tool ceiling; if only a send tool exists it writes a note and a mailto link instead.
- Claims a number that isn’t in your profile, or anything on your do-not-claim list — a lint stops that item at every autonomy level.
- Pays a fee of any amount, records a required video, types an ID number or date of birth, or solves a CAPTCHA.
- Automates LinkedIn or X — drafts for those channels are notes you paste yourself.
- Marks a fund contacted on its own. That word is yours.
Honest limits: it will be wrong where a program’s public page is silent, and warm paths inherit the engine’s name-only matching. It only knows an email was sent when you tell it.
a list you paste is a lead, never a source · illustrative counts
Travel Agent
v0.1.0 · developer previewwrites 47-travel/It starts from where you’ve already been and what you already loved — the pins you saved and never visited, the places you rated highly, the people you know in a city — and turns that into a day-by-day itinerary drawn live on Studio’s Map. Then it shops flights, stays, ground and food on public sites in your own browser. It books nothing: every price is a snapshot with the moment it was seen, and every level ends at a link you follow.
Eight skills
trip-scout“Where should I go?” from your brain alone — no web requests — with every idea citing the notes behind it.trip-plannerYour saved pins first, clustered by area into walking routes, oneitinerary.jsonper trip, redrawn on the Map as it changes.flight-searchMetasearch for the market’s shape, then the carriers directly — and virtual interlining that turns a long connection into a stopover night.stay-searchStays in the neighbourhood where that stop’s places actually cluster, matched to your hotel style.ground-searchRail where it beats driving, a hire car where it doesn’t, ferries and buses — with the one-way, cross-border and driver-age traps spelled out.taste-scoutCafés, restaurants and things to do that match the kinds of places you rated highly; anything with no brain signal is marked web-only.travel-onboardingReads your places first, then asks only what the brain cannot know: home airports, citizenships, companions, pace, budget.trip-pipelineThe whole trip end to end — ideas, itinerary on the map, then flights, stays, ground and food — holding the gates.
Commands
/trip/plan/places/onboard/reportWhat it never does
- Books anything, opens a checkout, or types a card, passport, password or date of birth.
- Refuses a self-transfer below the airport’s safe connection floor, and shows you the risk sentence before you choose.
- Creates an account, solves a CAPTCHA, or retries a site that blocks it more than once — you get a pre-filled link instead.
- Writes into your places layer, or invents a place note. Your brain’s pins stay yours.
Network it declares: public travel sites only, read in your browser — no partner APIs, no affiliate links, no guaranteed coverage. The Map needs your own Google Maps key; planning and notes work without it.
{
"stop": "Lisbon", "kind": "stopover", "from_brain": true,
"price": 212, "currency": "EUR", "quoted_at": "2026-09-26T09:14Z",
"risk": "separate tickets: a missed connection is yours to rebook"
}Unique in Studio
Watch the work land, beside the conversation.
Second Brain Studio gives every agent a third tab beside Vault and Sources. Pick one and the chat is grounded in that plugin rather than the whole brain; the note it writes updates live next to the conversation; and when it needs your decision, the question arrives as real buttons — answered in the same turn.
Studio
Jobs Agent · chat
45-jobs/Job Dashboard.md · live
updated: 2026-09-26
interviews_won: 2
interview_rate: 0.18
---
## Today’s shortlist
1. [[Example Co]] — Senior Product Engineer · 0.71
2. [[Acme]] — Staff Engineer · 0.64
3. [[Globex]] — Head of Platform · 0.58
↳ you know 2 people at Acme
A chat grounded in one plugin
The agent’s grounding note is read on your machine and the session runs as one long-lived Claude Code process — steerable mid-run, resumed after a reload.
Gates as real buttons
When the CLI asks a question, Studio renders the options as buttons and a free-text field and answers in the same turn. The tool is deliberately not pre-permitted; if it’s unavailable the agent falls back to a plain gate block.
The note, live
An agent’s work is a note you are watching. It repaints the moment the write lands — the dashboard, the application note, the funding plan.
The Map canvas
A map agent swaps the centre of Studio from the graph to the Map. Every itinerary change redraws it; clicking a pin sends a turn back to the agent (“add this to day 3”).
Its own settings
Each agent has a gear for the files it needs — a CV, a deck, a facts file, your Maps key. They are read from disk. Nothing is uploaded anywhere.
A tool ceiling, not a tool grant
A plugin may request tools; it can never grant itself any. The ceiling is skills, sub-agents and your browser — nothing else gets through.
Where they run: the desktop Studio, or the browser Studio run locally on your machine — through your own Claude Code CLI and subscription, over a vault that never leaves your disk. The hosted Studio at secondbrainlink.com does not run agents. OpenAI Codex gets a flattened skill from the same source, honestly narrower: no browser tooling, so no form-filling or shopping.
Approval gates & safety
The rails every agent inherits.
A brain that acts is only worth having if it can’t act past you. These are not policies — they are code in the plugins and in Studio.
Never merged
Pick the target → approve the draft → submit. Three separate questions, always in that order. A record only changes state when you answer.
One word, yours
level: lives in your own profile. Supervised is the shipped default. Autonomous is a deliberate edit you make — never a default, never inferred from how you phrased a request.
Never typed
A password, a passport or ID number, a card, a date of birth, a CAPTCHA, an account to create — any of these stops that one item, at every level.
Linted against your own files
A number not in your profile, a claim on your do-not-claim list, a leftover placeholder — a red lint stops the item. Nothing is invented to fill a blank.
Declared per plugin
Each manifest lists the endpoints it reads and why. The engine transform stays at zero network calls; nothing bundles a plugin into it.
Capped and announced
Research fan-outs and submissions per run are capped in your profile. The agent says the fan-out before it spends it.
Zero network
Building the brain from your exports. Provable with a grep, and always on.
Your own CLI
Model turns go through your Claude Code or Codex, on your subscription, over your vault.
Declared, in your browser
Reading job boards, program pages and travel sites happens in your own Chrome, on the endpoints the plugin declares.
A submitted application cannot be un-submitted. That is not a footnote — it is why approval comes before anything irreversible, and why we never promise an undo that doesn’t exist.
Build your own
One folder. Two runtimes. Any job your brain knows how to do.
A plugin is a folder: a manifest, skills that know how to do the work, commands that name it, and scripts for the deterministic parts. Add a studio.json and a grounding note and it appears as an Agent in Studio, with its own tab, its own note and its own settings.
One source builds both packagings: Claude Code loads it as a plugin; OpenAI Codex gets a flattened skill. The three shipped plugins are the reference — read them, copy one, change the job. MIT, like the engine.
Three rules keep every plugin honest: never write user data inside the plugin folder, never hardcode a vault layer, ship nothing personal.
.claude-plugin/plugin.json # name, version, network: { required, why, endpoints } skills/ onboarding/SKILL.md # writes the profile every other skill reads scout/SKILL.md # finds the work, scores it, shortlists apply/SKILL.md # does it — behind the gates pipeline/SKILL.md # runs them in order, holds the gates commands/ onboard.md · run.md · outcome.md · kpi.md · report.md scripts/ ledger.py · lint.py # stdlib Python, deterministic studio.json # label, blurb, layer, canvas, providers studio/grounding.md # what the agent is, read on your machine # builds → dist/plugins/claude/<name>.zip · dist/plugins/openai/<name>.skill
Upcoming · planned
The jobs your brain already knows how to do.
Twenty agents, ranked by how often the job fires, whether the data is already in the brain, and whether a gate can hold it. Every one of these is planned, not shipped. The top three on each side come first.
Personal
For your own brain — built from LinkedIn, Google, Meta and 13 personal sources.
- Network Revival AgentA weekly review of the ties going quiet, one drafted message each in your voice. You send.planned
- Briefing AgentEach morning: today’s meetings, a dossier per attendee, what changed. Meeting prep, automatic.planned
- Follow-Up AgentWatches silences and commitments across your applications, investors and promised intros; drafts the nudge.planned
- Warm-Intro AgentFor any target: the path through your own network, ranked, with the ask drafted.planned
- Voice AgentPosts, replies, bios and cover letters from your own writing — cited, never posted for you.planned
- Refresh AgentNudges when a source goes stale, walks the export, runs the update, reports what changed.planned
- Taste & Shopping AgentRecommendations and pre-purchase research from your own ratings and orders. Buys nothing.planned
- Recall Agent"Where did I see that?" — your searches, saves and places first, then the web from that context.planned
- Mirror AgentA periodic audit of what each platform infers about you, with the opt-out requests drafted.planned
- Events AgentBefore a conference: who you know going, who to meet, prep per person. After: the follow-ups.planned
Company
For a Company Brain — built from Slack, Workspace, CRM and 12 company sources.
- Continuity AgentSomeone is leaving: the handover brief — sole-connector relationships, knowledge with no second owner, deals only they link.planned
- Who-Owns-This Agent"Does anyone know…" answered with the owner and the evidence; a weekly ownership-gap report.planned
- Onboarding AgentA week-one plan for a new hire or a new AI agent: who to meet, which teams exist, what to read first.planned
- Account Revival AgentDormant-but-strong accounts and closed-lost deals with a warm tie; drafted re-engagement, never sent.planned
- Pre-Call Brief AgentBriefs the account team before the call: deal history, everyone who touched it, open threads.planned
- Precedent Agent"We answered this in 2023." Prior answers, decisions and the people behind them; drafts from precedent.planned
- Company Briefing AgentA weekly digest per team: what changed, decisions recorded, ties going dormant, ownership gaps.planned
- Hiring AgentThe Jobs Agent from the other side: screens candidates against the role, finds warm referral paths.planned
- Decommission AgentSunset a tool without amnesia: import its export, verify coverage, report what would be lost.planned
- Data-Inventory AgentWhat personal data exists where, per source; drafts the controller note and audit answers.planned
The Harness — the thing that runs them
developer preview when it shipsToday you start an agent and watch it. The Harness is the runtime that lets a brain run jobs unattended: a procedure is a one-page note saying what to do and when; a run is its transcript, checkpointed and resumable; every unattended run ends in a briefing. Standing orders are conditions evaluated with no model call at all — a new reply landed, an application silent ten days, a strong tie gone dormant, the brain not refreshed in thirty days.
Honest limit, stated first: it runs on your machine, so if the machine is asleep, nothing runs — that is the boundary of local-first, and exactly what hosted sync buys.
Nothing a run learns becomes memory until a person says so.
FAQ
Questions people actually ask.
What is an agent in Second Brain Link?
A plugin that uses your brain to do one job. The engine builds the brain and makes zero network calls; an agent reads that brain, acts in the world — sweeping job boards, verifying funds, shopping a trip — and writes its results back into your vault as a normal layer. Three ship today: Jobs, Fundraising and Travel.
Does an agent send emails, submit applications or book trips for me?
Not unless you say so, and some never do. The Fundraising Agent only ever drafts — a record becomes "contacted" when you confirm you sent it. The Travel Agent books nothing and ends at a link you follow. The Jobs Agent submits only if you set your own profile to autonomous; the shipped default stops at three gates: pick the job, approve the CV, submit the form.
Where do agents run?
In Second Brain Studio on your machine — the desktop app, or the browser Studio run locally — through your own Claude Code CLI and subscription. The hosted Studio at secondbrainlink.com does not run agents. OpenAI Codex gets a flattened skill that is honestly narrower: no browser tooling, so no form-filling or shopping.
Does my data go anywhere?
The brain stays on disk. Each agent declares in its own manifest which public endpoints it reads — job boards, a program’s own site, public travel sites — and reads them in your browser. Nothing is uploaded, no account is created for you, and a password, ID number or card is never typed by an agent.
Can I build my own agent?
Yes. A plugin is skills, commands and scripts under a plugin manifest, plus an optional studio.json and grounding note that make it an Agent in Studio. One source builds the Claude Code plugin and the Codex skill. The contract, the three rules and the three shipped plugins are in the open-source repo, MIT.
What comes next?
More agents on the same contract — a weekly network review, a morning briefing with meeting prep, follow-ups, a continuity handover when someone leaves — and the Harness that runs them unattended: procedures, runs and briefings, with a memory gate so nothing an agent learns becomes memory until a person says so. All of it is planned, none of it is shipped.
Your brain shouldn’t just answer. It should work.
Free & open source (MIT) · agents run locally in Studio · nothing sent, submitted or booked without you.