When you share a package — a report, a code deliverable, a research corpus, a video + docs bundle — the human gets a link. But their agent gets nothing: no summary it can trust, no file order it can follow, no way to know the tree it fetched is the tree you sent.
INGEST.md is the missing convention: a machine-readable manifest at the artifact root. The receiving agent reads one file and knows exactly what it holds, in what order to consume it, and whether the bytes are intact.
share card: title + BLUF + link. The share card unfurls as a designed card on X, Discord, Slack, LinkedIn.
INGEST.md manifest: BLUF, load order, file map, sha256 fingerprint. The one-liner hands it to the recipient's agent.
Read INGEST.md at the artifact root and execute its load order; it routes everything else.
INGEST.md is canonical; AGENT-INGEST.md is a registered alias validating against the same schema.share_sent / share_opened / agent_ingested) ship with the spec.| Event | Meaning |
|---|---|
share_sent | The artifact was sent by its sharer (carries artifact id, fingerprint, channel). |
share_opened | The share surface was opened by a recipient. |
agent_ingested | The receiving agent fetched the manifest and executed the load order — the machine analog of "received and read". |
Armed packages resolve at agnt.in — one URL, three readers: crawlers get the unfurl, humans get the card, agents get the manifest. Try the playground: agnt.in/try.
git clone https://github.com/MediaPlural/ingest
cd ingest
python3 ingest.py init ./my-package --bluf bluf.txt
python3 ingest.py verify ./my-package
python3 ingest.py card ./my-package
Spec text: CC-BY 4.0. Reference code: Apache 2.0. The convention is freely implementable; attribution rides every copy.
AGENTS.md owns repo-instruction conventions; llms.txt and Jina Reader (r.jina.ai) own hosted-URL → LLM-readable conversion; A2A owns the Agent Card. INGEST.md claims the unclaimed lane: the shareable-ingest manifest — what an agent reads when an artifact arrives, not when it's hosted.