AI Lab · Cologne · Open source

Build boldly.
Operate safely.

mona.expert builds and operates two ventures. llminone.com turns a sentence into a working app, running in the browser. remoteagent.online runs AI agents on real machines — under policy, with a record. Everything else on this page came out of the same lab.

Scroll — the interesting part is the record
2Ventures, built and operated in-house
232Commands an agent may run — in 9 categories
20Tools, each one switchable per agent
MITDevice client, public and self-hostable

Read from the running products, not from a slide. Every figure below is checkable.

The two ventures

One creates.
One operates.

Most AI products stop at the demo. These two were built as halves of one job: getting something made, then keeping it alive on a machine somebody actually owns.

Venture 01 Creation

Dream Machine

llminone.com

Type an idea. Watch it become an app, a game or a tool — running live in the browser before you finish reading this.

  • One sentence in; what comes back is a running app, game or tool — not a snippet
  • Change it by talking to it — the app rebuilds in place, versions kept per project
  • Share by link with owner, editor or viewer rights — no deployment step
  • Twelve example builds and a wish library across thirteen fields — finance, industry, health, education, games
llminone.com
llminone.com — the Dream Machine start screen: LLMinONE wordmark, the shimmering Dream Machine headline, its composer with the placeholder “Träum es. Tipp es. Schau beim Entstehen zu.”, the 12-example button and the quick-start chips.
llminone.com, captured — the live start screen: one line in, a working thing out.

Apps · Games · Tools · Dashboards · 3D scenes · Simulations · Connected views

Venture 02 Operation

Control plane

remoteagent.online

An AI agent that runs on your own computer and writes down exactly what it did — so “it worked” is something you can check, not something you hope.

  • Policy decided before every tool call: first match wins, deny by default
  • Shell is allow-list only — 232 commands in 9 categories, or *
  • Provider keys encrypted with AES-256-GCM, returned masked, never in full
  • Files never move: the cloud queues typed operations, your device executes them
Intenta sentence Buildllminone.com Runremoteagent.online Recordpolicy, cost, audit

How it runs

Three moves. One gate. A receipt.

A wish becomes a build; the build gets a machine with limits and a record. Nothing skips the gate in the middle — that is why we built both halves instead of buying one.

01 / WISH

You say what you want

One sentence, in your own words. No configuration, no model choice, no ticket.

02 / BUILD

Dream Machine makes it real

The build streams into the browser as it is written. Keep it, change it or throw it away — the code is yours.

03 / RUN

The control plane keeps it alive

Hand it to an agent with limits and a record. It works on real files, on a real machine, while you watch the steps and the cost.

Nothing is reachable by default

Folders, commands and network destinations are chosen, not assumed. Outbound requests resolve DNS first and refuse loopback, private, link-local, metadata and CGNAT ranges, then validate redirects again.

One gate, not twenty exceptions

Every tool call passes the same check. Adding a tool does not add a way around the rules — it adds another thing the rules apply to.

The receipt is the product

Each run keeps its steps, tokens and cost; files keep content hashes and versions. Export a finished run as JSONL and the record leaves with you.

The world is data, never instructions

Tool output, files and web pages are labelled untrusted in the agent's own prompt and never followed as commands. Prompt injection is a design constraint, not a filter bolted on.

Worked examples

One wish. Six moves.
A bill you can read.

Real material only. The asks come from the example library that ships in Dream Machine; the trace is a published, anonymized capture from the control plane — the same format the console shows you live. Both are on the public sites, so you can check them without asking us.

01The ask — Dream Machinellminone.com · example library
Build a live flight radar with moving planes23 categories · 120+ prompts
Build a quality dashboard that traces defects back to the delivery batchindustry · quality
Baue ein Smart-Home-Energie-Dashboard mit Live-Solar und BatterieGerman works too
one sentence ina live app comes back, not a snippet each project keeps its own versionsshare by link: owner · editor · viewer

These are prompts from the shipped library, verbatim — including one in German, because the product is bilingual and does not mind.

02The build — one prompt, one captureremoteagent.online/docs/examples
Open Safari and go to YouTube's most played songdeepseek-chat
think“The user wants me to open Safari and go to YouTube to find the most played song…”
tool.callapps — launch Safari
tool.result{"exitCode":0,"stdout":"","stderr":""} — Safari is up
think“Safari is open. Now I'll open YouTube and search for the most played song…”
tool.callbrowser — open https://www.youtube.com/
tool.result{"opened":true,"url":"https://www.youtube.com/"}
tool.callbrowser — search YouTube for the most played song
answer“Done! Safari is now open on YouTube showing the most-played song…”
verifychecked the tool results: Safari opened, YouTube opened, the search ran
9,947tokens measured
≈ $0.0028real cost of the run
12steps, all on the record
Read the full published traces ↗
03What three one-prompt builds actually costpublished · not estimates
MAPSGoogle Maps clone — one prompt → 24 steps · 76.5k tokens · ≈ $0.04
APP STOREApp Store clone — one prompt → 30 steps · 48.2k tokens · ≈ $0.02
CHESSChess game — one prompt → 9 steps · 24.2k tokens · ≈ $0.0079

Captured by the control plane and anonymized. The console shows the same three numbers per run, per model and per day — which is why the spending question has an answer here and a “not built yet” label for the cap.

Everything from the lab

Two ventures carry the company.
The rest keeps us honest.

Eleven more products, all reachable. Some are polished, some are experiments we keep because they teach us something the ventures need. We would rather show the whole shelf than curate a story.

Food

Daily health intelligence turned into a simple, motivating game — the lab's longest-running product experiment.

Health · daily habitOpen /food ↗

Control Center

The live, self-hostable console: agents, devices, runs, approvals, insights and keys on one screen. This is the surface enterprises actually sit in front of.

Operations · liveOpen /agent ↗

ScanEat

Barcode scanning that tells people what they are actually choosing, without a nutrition degree.

Health/scan ↗

Eat

A focused checklist that turns better nutrition into a daily practice instead of a diet.

Health · habit/eat ↗

Florapedia

Discover plants, capture what you see, and build a personal field guide — vision meets a walk outside.

Vision · field guide/plants ↗

Play

Browser worlds and small 3D experiments — where we try ideas that are too strange for a venture.

Experiments/play ↗

Analytics

Tasks, tokens and cost per day, model, provider and agent — the numbers that keep the claims honest.

Insight/analytics ↗

Dashboard

Device telemetry and run health in one operating picture: CPU, memory, disk, uptime, last seen.

Operations/dashboard ↗

Wrapper

The policy gateway itself — the layer that decides before an agent touches a file, a command or an API.

Security/wrapper ↗

Home

A quieter doorway into the products — the version for people who do not want a console first.

Product home/home ↗

Agent landing

The pitch page for the agent platform — what it is, what it refuses, and how to install it in one command.

Story/landing ↗

The lab

Where the value compounds.

A build tool can be copied in a quarter. What is hard to copy is the part that decides what an agent may do, proves what it did, and keeps working when the model underneath changes. That layer is ours, it is already running, and both ventures sit on it.

01 / THE GATE

Policy that model vendors cannot supply

Every tool call is checked against your rules before it happens, on the customer's own machine. A model provider can offer safety filters on its own traffic; it cannot govern what a file, a shell or a network call does on your hardware. That position is structural, not a feature.

first-match policydeny by defaultapproval queue
02 / THE RECORD

Evidence is a requirement, not a nicety

Hash-chained audit logs, content hashes on files, per-run cost, JSONL export. The moment an agent does real work in a company, someone has to answer "what changed and who allowed it" — and that answer is a product, not a PDF.

append-only chaincontent hashesrun export
03 / THE SHAPE

Two products that feed each other

Creation without operation is a demo; operation without creation has nothing to run. Together they cover the full path from an idea to an audited job — and every build made in the browser is a candidate for something that later needs governing.

one labshared foundationsopen core

Where things stand

Shipped. And not yet.

Anyone can be shown a roadmap. Here is the line between the two lists, taken from what is actually deployed today.

Shipped

  • ✓Dream Machine in public use — prompt to live build, version timeline, share roles
  • ✓Agent daemon on Windows, macOS, Linux and Raspberry Pi, with one-command install
  • ✓Console: agents, devices, workspaces, runs, approvals, insights, keys, 2FA
  • ✓Policy engine, allow-list shell, approval queue, network egress rules
  • ✓Hash-chained audit log, content hashes, JSONL run export
  • ✓Open-source device client (MIT) and self-hostable foundations

Bring the idea. Keep the record.

Start with the half you need today — a build in the browser, or an agent on your own machine. They meet in the middle, and the lab keeps both honest.