Karpathy's Full Agentic Engineering Lifecycle using Google's Agents-CLI
Current agent memory systems are limited by a retrieval-heavy design that requires users to know exactly what to ask for. A more proactive approach involves continuous pattern recognition by analyzing the structural relationships within stored data. By using graph topology instead of embedding-based similarity, systems can identify complex dependencies and bottlenecks that simple retrieval misses. This process is implemented through a pipeline that builds a knowledge graph and generates automated summaries called Observations. Google's Agents-CLI enables developers to manage the entire Agent Development Lifecycle (ADLC), including the governance stage, using natural language prompts within a coding agent's environment. By injecting specific skills into tools like Cursor or Claude Code, developers can configure security features such as least-privilege identities, prompt injection filters via Model Armor, and network egress controls through Agent Gateway. This approach integrates security and deployment directly into the engineering workflow, reducing the friction traditionally associated with manual console-based governance. The process ensures that agents remain resilient against prompt injection while maintaining deterministic logic for critical tasks.
閱讀原文 ↗目錄
Agent memory shouldn’t wait for queries
Current agent memory systems are limited by a retrieval-heavy design that requires users to know exactly what to ask for. A more proactive approach involves continuous pattern recognition by analyzing the structural relationships within stored data. By using graph topology instead of embedding-based similarity, systems can identify complex dependencies and bottlenecks that simple retrieval misses. This process is implemented through a pipeline that builds a knowledge graph and generates automated summaries called Observations.
- Traditional retrieval systems fail to identify structural patterns that emerge from combined data points.
- Pattern recognition should run as a background process on top of retrieval rather than relying on better search algorithms.
- The proposed pipeline uses four stages: Raw episodes, Signatures, Clusters, and Observations.
- Graph topology is used for clustering to avoid the noise associated with embedding-based similarity scoring.
- Observations are generated by a constrained LLM call that summarizes the patterns found within specific graph clusters.
- Zep implements this structural analysis feature, which is powered by the open-source graph engine Graphiti.
Karpathy’s Full Agentic Engineering Lifecycle using Google’s Agents-CLI
Google's Agents-CLI enables developers to manage the entire Agent Development Lifecycle (ADLC), including the governance stage, using natural language prompts within a coding agent's environment. By injecting specific skills into tools like Cursor or Claude Code, developers can configure security features such as least-privilege identities, prompt injection filters via Model Armor, and network egress controls through Agent Gateway. This approach integrates security and deployment directly into the engineering workflow, reducing the friction traditionally associated with manual console-based governance. The process ensures that agents remain resilient against prompt injection while maintaining deterministic logic for critical tasks.
- Google's Agents-CLI adds seven bundled skills to coding agents to handle scaffolding, evaluation, and deployment.
- The Govern stage of the Agent Development Lifecycle (ADLC) focuses on identity, network access, and input screening.
- Model Armor provides a layer of protection against prompt injection and jailbreak attempts by screening untrusted text before it reaches the model.
- Agent Gateway implements egress allow-listing to restrict an agent's network access to specific, authorized domains.
- Using deterministic code for reconciliation tools prevents prompt injection from influencing final verdicts or logic.
- Governance controls like least-privilege identity and network restrictions can now be managed via natural language prompts rather than manual cloud console configurations.