Private Agent Harness · v0.4.2

The crew

Six bounded agents behind the MCP Worker. Each one is a job with an objective, fixed domains and hard limits — not a chat window with credentials. Nothing writes without an approval, and every run leaves receipts.

06
Agents
08
Process skills
0 AI
Default lane
MIT
Open source

Who runs

Jack is the default office manager · 3 cards awaiting repo confirmation
01
01 0 AI
Lookout
Site health

Watches uptime, version and smoke tests across the listed domains. Deterministic HTTP checks — it can require an expected text marker so a 200 serving the wrong site still fails.

site_health Zero-AI lane Schedule friendly
02
02 AI
Sentinel
Security review

Reads a diff for auth bypass, missing ownership checks and privilege escalation, and reports each finding with a CWE id. Refute-first: it argues against its own finding before filing it.

security_review CWE ids Refute-first
03
03 0 AI
Harness
Test runner

Runs the suite on demand and on schedule and captures failures. Named in the console as a live job source.

test_harness On schedule
04
04 Placeholder
Quarry
Source research

Not confirmed from the repo — name and scope are a placeholder for review. Bounded fetching only: fixed url count, source-character ceiling and one auto-followup. Google-first, opens and traces primary sources instead of trusting snippets.

source_pull max_urls: 4 6000 chars
05
05 Placeholder
Ledger
Accounting

Not confirmed from the repo — name and scope are a placeholder for review. Tracks AI calls against the daily lane, logs every zero-AI job, and refuses work that would spend past the budget shown in the console.

Daily limits Zero-AI log Fail fast
06
06 Placeholder
Packer
Memory

Not confirmed from the repo — name and scope are a placeholder for review. Hashes each job packet, prunes stale memory on the 4/7/30-day retention, and keeps the Continuity Keeper briefing small enough to hand off cleanly.

memory_pack 4/7/30 retention Hashed packets

Process skills

Selected automatically · recorded in the packet

Eight folders under skills/ get attached to bounded work instead of spawning permanent agents. The coordinator picks them, the console shows them, and the job packet records which ones ran.

cfops-safe-deploy Tests, Wrangler dry-run, Git checkpoint, then an exact public version-marker gate. A successful upload alone is not accepted.
cfops-live-verify Checks the changed route, redirect policy, expected text and phone interaction. A 200 serving the wrong app fails.
cfops-email-loopback Sends a one-use challenge through the production sender, public MX, Email Routing and the inbound Worker; records confirmed, expired or failed.
cfops-context-handoff Keeps the release commit, deployment receipt, verified facts and next safe action. Stale chatter expires.
cfops-security-review Refute-first review that has to argue against its own finding before it files one.
cfops-private-mcp Access to the private MCP surface under the operator's own OAuth grant.
cfops-google-research Opens and traces primary sources rather than trusting search snippets.
cfops-claude-verifier Optional independent second opinion when the operator has configured that provider. The user's key never enters the repo.

The rule

Every agent, every job, every lane runs the same five steps. It does not change for a cheaper model or a faster deadline.

Mint down, never up

Agents never hold the bootstrap token. They ask for a task token scoped to one zone with preset permissions that expires in an hour. There is deliberately no account-wide preset.

01
Check

Read current state first — scan, resolve the zone, fetch what exists.

02
Diff

Show desired versus current as a before/after. Nothing has been written yet.

03
Approve

A human says yes. Mutating tools need apply: true; the CLI needs --apply.

04
Apply

Write only the approved change. An apply never deletes as a side effect.

05
Verify

Re-check the public result — status, redirect policy, expected marker — then record the hashes.