Skip to main content
Case Study

How CubiCube Uses Pegasus for Optimized Model Selection

CubiCube, the modular deployment platform, leverages the Pegasus Orchestrator and KnowYourModel registry to deliver intelligent, secure, and auditable AI operations to its users.

10
Specialized Sub-Agents
100%
Scoped Credentials
∞
Audit Trail Receipts

The Challenge

CubiCube enables creators to build and deploy web applications using modular "cubes"—pre-built components for databases, authentication, payments, and more. As the platform grew, the team faced a critical question:

"How do we give our AI assistant the power to help users across all these domains without creating a security nightmare?"

A monolithic AI assistant with access to everything—databases, payment keys, deployment credentials—would be a single point of failure. One compromised prompt could expose the entire system.

The Solution: Pegasus Orchestrator

Instead of one all-powerful agent, CubiCube adopted the Pegasus Orchestrator—a master coordinator that delegates tasks to 10 specialized sub-agents, each with its own scoped credentials.

VSSA
Vector Search — Vectorize & semantic queries
CDSA
Database — D1 schemas & migrations
RSSA
Storage — R2 buckets & presigned URLs
BDTSA
Deploy — Build & deployment pipelines
ASSA
Auth — Sentinel SDK & sessions
EISA
Email — Resend & Turnstile
PISA
Payments — Stripe Connect & webhooks
SEASA
SEO & Analytics — Meta tags & tracking
KSA
Real-time — Kraken WebSocket gateway
RICSA
API Gateway — RIC routing & transforms

Key Benefits

Least-Privilege Security

Each sub-agent only has access to the credentials it needs. The database agent can't touch payment keys. The email agent can't access storage buckets. A compromised sub-agent is contained to its domain.

Optimized Model Selection

Pegasus queries the KnowYourModel registry to select the best model for each task. Complex reasoning tasks get Claude Opus. Quick code generation uses Sonnet. The registry's usage-proof voting ensures recommendations are based on real-world performance.

Cryptographic Audit Trail

Every sub-agent invocation generates a usage receipt—cryptographically signed proof of what ran, when, and for how long. Agent definitions are Git-verified, linking each action back to its source code. CubiCube can answer "what did the AI do?" with verifiable evidence.

Standards-Based Interoperability

All agents follow the A2A Protocol—an open standard for agent-to-agent communication. This means CubiCube's orchestrator can discover and work with agents from other systems, and external tools can integrate with CubiCube's agents seamlessly.

Architecture Overview

A2A
Master
Pegasus Orchestrator
Analyzes intent, delegates tasks
delegates via Task tool
CDSA
RSSA
ASSA
PISA
BDTSA
EISA
SEASA
KSA
RICSA
VSSA
reports usage
A2A
Registry
KnowYourModel
Usage receipts, model rankings, Git-verified agents

Live Skill Registries

Each sub-agent capability is managed through its own registry. The orchestrator queries these registries at runtime to discover the top-ranked agent for each task. Explore the live registries:

The Master Orchestrator registry allows admins to swap orchestrators without code changes—the same pattern used for all sub-agents.

Deep Dive: Security White Paper

Coming Soon

Our upcoming white paper, "Transparency vs. Opacity: A Comparative Security Analysis of Agentic AI Architectures", explores the security implications of orchestrator-based systems in depth—including comparisons with other approaches and OWASP Agentic Top 10 compliance.

Ready to explore the KnowYourModel Trust Registry?