Angel Hermon Contact

A thread of blue light passing through a row of glass panes in the dark.

Agents that fail should leave a trace.

I make AI agent and MCP pipelines observable and reproducible.

Describe your pipeline
agent.run · 8 spans · 4.82s 8 spans, one timeout run 1 Strands drawn from an illustrative 8-span run, not a customer trace. Same seed, same frame.

The system already runs. Nobody can say why it did that.

  • warnit got slower
  • warnit cost more
  • errorit behaved differently

This is for engineering teams with an agent or MCP-based system in production and a problem of exactly that shape: it failed, got slow, cost more or changed behaviour, and the logs do not say which step, which tool call or which prompt.

Observe, pin down, guard.

A blue light thread running along a row of small metal tick marks, like a measuring instrument.

Observe

Instrument agent runs and MCP tool calls with OpenTelemetry, so every call has a name, a duration, an outcome and trace context, in the backend you already use.

OTLPJaegerTempoHoneycomb

Pin down

Separate what the model decides from what code should decide. Fixed logic moves out of prompts into testable steps, so a run can be replayed, diffed and reviewed.

ReplayDiffTests

Two blue light threads, one fainter, landing on the same point of a slate surface.

Guard

Design MCP servers and tool layers with explicit boundaries: read-only by construction, allowlisted calls, secrets kept out of the model's context.

AllowlistRead-onlySecrets

  1. POST /api/Orders/SendOrderrejected: not a GET
  2. GET /api/Orders/SendOrderrejected: path not in the set
  3. GET /api/Account/GetHoldingsSummaryrejected: the set holds the server's own spelling, Summery
  4. GET /api/Account/GetHoldingsSummeryexact match: passes
spark-ordernet-mcp: Session.request() raises unless the method is GET and the path is in one exact 15-entry allowlist. Paths shown are real; timing is illustrative.

Read the code before you talk to me.

Five public, open-source repositories, all my own. Limits are listed where the READMEs list them.

  • mcp-trace

    Transparent Go proxy for MCP servers: one OpenTelemetry span per tools/call, no client or server changes. Speaks stdio, Streamable HTTP and HTTP+SSE.

    Limit On HTTP+SSE, a server that advertises an absolute POST endpoint bypasses the proxy and you get zero tool-call spans. The README says so.

    Language
    Go
    Licence
    MIT
    Release
    v2.0.3
  • sealref

    Keeps API keys out of a coding agent's context. Secrets live in the macOS Keychain; the agent only sees sealref:// references, and injected values are scrubbed from command output.

    Limit macOS only: it is built on the Keychain.

    Language
    Python
    Licence
    MIT
    OS
    macOS
  • spark-ordernet-mcp

    Read-only MCP server over a brokerage API. The read-only guarantee is enforced at the session layer with an exact-GET allowlist, not by convention.

    Language
    Python
    Licence
    MIT
  • anvil

    Single-binary agent harness in Rust: pluggable LLM providers, sub-agents, a skill library, and episodic memory in SQLite.

    Language
    Rust
    Licence
    MIT / Apache-2.0
  • awesome-agent-observability

    Curated list of tracing, evaluation, guardrail, gateway and MCP tooling for agent observability. Every entry checked to resolve and be maintained as of the last audit.

    Licence
    CC0-1.0
    Stars
    33 · 1 Oct 2026

How we would work together.

I do not publish a price list; scope decides the shape, and I quote after the first call.

  1. You describe the system

    Using the form below: what runs, what goes wrong, what you already use for monitoring.

  2. A short intro call

    Or an email thread, to confirm whether this is something I can help with. If it is not, I will say so and, where I can, point you elsewhere.

  3. A scoped proposal

    In writing: a time-boxed review with findings, a defined implementation task, or part-time contract work. You see the scope and rate before anything starts.

Good fit

  • An existing agent or MCP system
  • A named problem
  • A technical owner on your side

Poor fit

  • Building a product from a slide
  • Work that needs a full-time on-site presence

Describe your pipeline.

The more specific, the more useful my reply. Submitting sends these details straight to me; if that fails, a pre-filled email opens in your mail app instead.

I reply to every genuine inquiry by email.

angel.hermon.mail@gmail.com Copies the email address to your clipboard

What is stored: only the fields above plus the time, in a private database (Cloudflare), used only to reply to you; I get a notification with the same text. No IP address, no tracking. Email me and I delete it. This page sets no cookies; anonymous page analytics (PostHog, EU) record visits, clicks and session replays with every input masked, never form contents.

Double opt-in: you are only added after clicking the link in a confirmation email. Stored: your email, which box you ticked, its exact wording and the time. Nothing else.