Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ on:
pull_request:
branches: [ main ]

permissions:
contents: read

jobs:
build:
runs-on: ubuntu-latest
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/hermes-evals.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,10 @@ jobs:
PYTHONPATH: src
steps:
- uses: actions/checkout@v4
with:
# SoT-cleared is local git ancestry of references/claude-sot-cleared.json
# (no live GitHub fetch in doctor). Default depth=1 hides the pin SHA.
fetch-depth: 0
- name: Setup Python
uses: actions/setup-python@v5
with:
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ build/
!data/backfill/**/*.json
!data/phylogeny/**/*.json
!.claude-plugin/plugin.json
!references/claude-sot-cleared.json

# Temp / build output
tmp/
Expand Down
11 changes: 11 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,17 @@

## Unreleased

- **P1 fail-closed hardening:** Claude `init` / `install.sh --claude` helpers
are transactional (symlink refuse, target-keyed backup, staged smoke /
UNVERIFIED). Unguarded `copy_claude_helpers` removed. Scored `settle()` /
`settle_and_log()` require token or TTY confirm, non-empty `authority.ref`,
and non-advisory kind; piped yes is refused. X API base allowlists
`api.twitter.com` / `api.x.com` (https only). Cloud vector writes require
`HYPERLEX_CLOUD_WRITE=1` or TTY `--i-understand-cloud-write`. `doctor`
emits `CLAUDE_SOT_CLEARED=` from local pin/provenance (Skill Validation
fetches full git history so the pin SHA is locally present). `receipt.integrity`
is full sha256; `emit_receipt(..., validate=True)` default; legacy 12-char
verify only with `HYPERLEX_RECEIPT_LEGACY_INTEGRITY=1`.
- **Claude Code host (additive):** `.claude-plugin/plugin.json`, project
`CLAUDE.md`, slash helpers (`.claude/skills/` + plugin `commands/`),
`install.sh --claude` / `--claude-plugin`, `scripts/claude_hlx.sh`,
Expand Down
2 changes: 1 addition & 1 deletion SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -183,7 +183,7 @@ $HLX pipeline "rizz" --route offline
$HLX ingest "locked in" # same as pipeline (use --raw-only for signal only)
$HLX pipeline "sigma rizz locked in" # expands to atoms automatically
$HLX pending # open forecasts
$HLX settle --forecast-id <id> --decision TRUE
$HLX settle --forecast-id <id> --decision TRUE --authority-ref <ref> --settle-token "$HYPERLEX_SETTLE_TOKEN"
$HLX score-series --mean-shift --verify-chain
$HLX scan --route offline --receipt --forecasts --append-log
$HLX risk-schedule --tier MODERATE --schedule-out /tmp/hlx-cron
Expand Down
2 changes: 1 addition & 1 deletion SPEC.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ Extended: `hyperlex.API_EXTENDED` (additive; includes Phase 5 simulation)
- `compute_lineage_confidence(hits, family_terms, corpus) -> (float, dict)`

### Receipts
- `emit_receipt(result, out_dir=None, validate=False, append_ledger=True, ledger_path=None) -> Path`
- `emit_receipt(result, out_dir=None, validate=True, append_ledger=True, ledger_path=None) -> Path`
- `verify_receipt(payload) -> (bool, str)`

### Calibration
Expand Down
2 changes: 1 addition & 1 deletion docs/api-v1.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ or an explicit deprecation window.
| `ingest_signal(query, source="mock")` | `str` signal |
| `fetch_ingest(query, source="mock", ...)` | structured ingest + `source_fingerprint` |
| `detect_memetic_patterns(...)` | result dict; `provenance.brier` is always `null` |
| `emit_receipt(result, ...)` | writes receipt JSON; optional ledger append |
| `emit_receipt(result, ...)` | writes receipt JSON with full sha256 `receipt.integrity`; `validate=True` default (`--no-validate` CLI escape) |
| `extract_forecasts(result)` | list of forecasts; **no** Brier field |
| `settle` / `score_pair` / `score_series` | Brier only after settlement; else `NOT_COMPUTABLE` |
| `relay_from_result(result)` | `RUNE.HLX.*` envelopes |
Expand Down
1 change: 1 addition & 0 deletions docs/brier-calibration.md
Original file line number Diff line number Diff line change
Expand Up @@ -233,6 +233,7 @@ python3 scripts/hyperlex.py extract-forecasts --input out/result.json --append-l

# Operator settles a forecast (TRUE/FALSE/VOID/CONFLICT)
python3 scripts/hyperlex.py settle --forecast-id <id> --decision TRUE \
--authority-ref operator@local --settle-token "$HYPERLEX_SETTLE_TOKEN" \
--authority-note "human review confirmed family" --export-ledger

# Recompute series + optional mean-shift diagnostic + chain verify
Expand Down
4 changes: 4 additions & 0 deletions docs/claude-runtime-contract.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,10 @@ Operator data is unchanged (outside the skill tree):
3. Never invent numeric Brier. Open analysis keeps `provenance.brier` null.
4. Never auto-settle. Ask for TRUE|FALSE|VOID|CONFLICT, then run `settle`.
5. `doctor` reports `CLAUDE_OK` or `CLAUDE_MISSING`. Missing does not fail Hermes.
`CLAUDE_SOT_CLEARED=true|false` comes from the local pin
`references/claude-sot-cleared.json` plus git/install provenance (not a
live GitHub fetch). A shallow clone that lacks the pin commit stays
uncleared. Claimed Claude packaging + uncleared fails doctor.

## Authority

Expand Down
5 changes: 4 additions & 1 deletion docs/claude-skill.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,7 +84,10 @@ step: `pending` → operator decision → `settle` → `score-series`.
| Contract | Same `SKILL.md` | Same `SKILL.md` + Claude section |

Fail-closed rules do not change: no invented Brier, no auto-settle, no
phenomenology claims.
phenomenology claims. `hyperlex doctor` emits `CLAUDE_SOT_CLEARED=true|false`
from the local pin `references/claude-sot-cleared.json` plus git/install
provenance (not a live GitHub fetch). When Claude packaging is installed or
claimed and the pin does not match, doctor fails.

## See also

Expand Down
2 changes: 1 addition & 1 deletion docs/spec.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ Extended: `hyperlex.API_EXTENDED` (additive; includes Phase 5 simulation)
- `compute_lineage_confidence(hits, family_terms, corpus) -> (float, dict)`

### Receipts
- `emit_receipt(result, out_dir=None, validate=False, append_ledger=True, ledger_path=None) -> Path`
- `emit_receipt(result, out_dir=None, validate=True, append_ledger=True, ledger_path=None) -> Path`
- `verify_receipt(payload) -> (bool, str)`

### Calibration
Expand Down
18 changes: 9 additions & 9 deletions examples/receipts/golden/MANIFEST.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"file": "betting-sharp.json",
"has_source_fingerprint": true,
"id": "betting-sharp",
"integrity": "13740d87af49",
"integrity": "13740d87af49d5ed6a7d8a8d1ec6a3aaa4a8e37e413b137a6907894b7af6e034",
"lineage_family": "betting-sharp",
"n_forecasts": 3,
"query": "sharp steam square revenge wiseguy hammer",
Expand All @@ -18,7 +18,7 @@
"file": "crypto-degen.json",
"has_source_fingerprint": true,
"id": "crypto-degen",
"integrity": "138a57d9b7d1",
"integrity": "138a57d9b7d142c72416177191b81674617728b6690e48352b93ac1c85d42c8e",
"lineage_family": "crypto-degen",
"n_forecasts": 3,
"query": "hodl diamond hands rekt degen moon",
Expand All @@ -30,7 +30,7 @@
"file": "brainrot-aura.json",
"has_source_fingerprint": true,
"id": "brainrot-aura",
"integrity": "e8e43b010371",
"integrity": "e8e43b0103716d19d015c238b0d9fb8aef843aa687ac56697223d38706629abc",
"lineage_family": "brainrot-aura",
"n_forecasts": 3,
"query": "brainrot aura farming mid cooked",
Expand All @@ -42,7 +42,7 @@
"file": "ai-native.json",
"has_source_fingerprint": true,
"id": "ai-native",
"integrity": "88573ce1608b",
"integrity": "88573ce1608b2f02b456a484080066f36a688dffc58fc6077e0cec3fcefe53f0",
"lineage_family": "ai-native",
"n_forecasts": 3,
"query": "agentic slop skill issue hallucinate",
Expand All @@ -54,7 +54,7 @@
"file": "kinship-address.json",
"has_source_fingerprint": true,
"id": "kinship-address",
"integrity": "885f482d77d8",
"integrity": "885f482d77d8d49eb60038b18c2d1f70f3a068f099b39df7d3c5077ca0981372",
"lineage_family": "kinship-address",
"n_forecasts": 3,
"query": "bro sis twin unc cuz family",
Expand All @@ -66,7 +66,7 @@
"file": "political-status.json",
"has_source_fingerprint": true,
"id": "political-status",
"integrity": "2a4fcf971e08",
"integrity": "2a4fcf971e08baebb53b648e8fac0fc7065aff6d35de12ca856b4c536a6a61f1",
"lineage_family": "political-status",
"n_forecasts": 3,
"query": "based redpilled cope seethe dilate",
Expand All @@ -78,7 +78,7 @@
"file": "gaming-meta.json",
"has_source_fingerprint": true,
"id": "gaming-meta",
"integrity": "74d35f2b5769",
"integrity": "74d35f2b57698ea9eb00f05f5723b6d618b8e69011a049438fdfe6fbbfb19354",
"lineage_family": "gaming-meta",
"n_forecasts": 3,
"query": "nerf buff meta sweaty smurf gg",
Expand All @@ -90,7 +90,7 @@
"file": "workplace-corp.json",
"has_source_fingerprint": true,
"id": "workplace-corp",
"integrity": "0fcc0f79803d",
"integrity": "0fcc0f79803dac8a62abd2d1883fc2fa7b8451f6a8ae7add9e0b3425643b6fcb",
"lineage_family": "workplace-corp",
"n_forecasts": 3,
"query": "quiet quitting rto bandwidth act your wage",
Expand All @@ -102,7 +102,7 @@
"file": "open-no-lineage.json",
"has_source_fingerprint": true,
"id": "open-no-lineage",
"integrity": "48d6b080d68f",
"integrity": "48d6b080d68fb9cdd71e5350b8c308f762a263379633590b44033168b13b037b",
"lineage_family": null,
"n_forecasts": 2,
"query": "the weather is mild with clouds",
Expand Down
4 changes: 2 additions & 2 deletions examples/receipts/golden/ai-native.json
Original file line number Diff line number Diff line change
Expand Up @@ -175,9 +175,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "88573ce1608b",
"integrity": "88573ce1608b2f02b456a484080066f36a688dffc58fc6077e0cec3fcefe53f0",
"path": "examples/receipts/golden/ai-native.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.587 \u0394=0.115. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/betting-sharp.json
Original file line number Diff line number Diff line change
Expand Up @@ -182,9 +182,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "13740d87af49",
"integrity": "13740d87af49d5ed6a7d8a8d1ec6a3aaa4a8e37e413b137a6907894b7af6e034",
"path": "examples/receipts/golden/betting-sharp.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "ACTUALIZING hyperstition risk. slang -> public pressure -> line movement -> confirmed. Virality prediction (SPECULATIVE): 0.906 \u0394=0.18. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/brainrot-aura.json
Original file line number Diff line number Diff line change
Expand Up @@ -177,9 +177,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "e8e43b010371",
"integrity": "e8e43b0103716d19d015c238b0d9fb8aef843aa687ac56697223d38706629abc",
"path": "examples/receipts/golden/brainrot-aura.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.587 \u0394=0.115. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/crypto-degen.json
Original file line number Diff line number Diff line change
Expand Up @@ -177,9 +177,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "138a57d9b7d1",
"integrity": "138a57d9b7d142c72416177191b81674617728b6690e48352b93ac1c85d42c8e",
"path": "examples/receipts/golden/crypto-degen.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.744 \u0394=0.105. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/gaming-meta.json
Original file line number Diff line number Diff line change
Expand Up @@ -182,9 +182,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "74d35f2b5769",
"integrity": "74d35f2b57698ea9eb00f05f5723b6d618b8e69011a049438fdfe6fbbfb19354",
"path": "examples/receipts/golden/gaming-meta.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.604 \u0394=0.079. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/kinship-address.json
Original file line number Diff line number Diff line change
Expand Up @@ -161,9 +161,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "885f482d77d8",
"integrity": "885f482d77d8d49eb60038b18c2d1f70f3a068f099b39df7d3c5077ca0981372",
"path": "examples/receipts/golden/kinship-address.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.519 \u0394=0.054. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/open-no-lineage.json
Original file line number Diff line number Diff line change
Expand Up @@ -115,9 +115,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "48d6b080d68f",
"integrity": "48d6b080d68fb9cdd71e5350b8c308f762a263379633590b44033168b13b037b",
"path": "examples/receipts/golden/open-no-lineage.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.37 \u0394=-0.073. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/political-status.json
Original file line number Diff line number Diff line change
Expand Up @@ -177,9 +177,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "2a4fcf971e08",
"integrity": "2a4fcf971e08baebb53b648e8fac0fc7065aff6d35de12ca856b4c536a6a61f1",
"path": "examples/receipts/golden/political-status.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.573 \u0394=0.116. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
4 changes: 2 additions & 2 deletions examples/receipts/golden/workplace-corp.json
Original file line number Diff line number Diff line change
Expand Up @@ -178,9 +178,9 @@
"version": "0.2.5"
},
"receipt": {
"integrity": "0fcc0f79803d",
"integrity": "0fcc0f79803dac8a62abd2d1883fc2fa7b8451f6a8ae7add9e0b3425643b6fcb",
"path": "examples/receipts/golden/workplace-corp.json"
},
"recommendation": "Bind RUNE.HLX.COMMUNICATION_RELAY via hyperlex.relay; extract_forecasts for calibration; cron LIVE_EMERGENCE_SCAN.",
"speculative": "EMERGENT hyperstition risk. narrative circulating but no market confirmation yet. Virality prediction (SPECULATIVE): 0.611 \u0394=0.041. Brier requires settlement via hyperlex.calibration \u2014 not claimed on open forecasts."
}
}
23 changes: 13 additions & 10 deletions install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -192,22 +192,23 @@ install_extra_host() {
TARGET="$_saved"
}

copy_claude_helpers() {
install_claude_helpers() {
local dest_root="${HOME}/.claude/skills"
local name src dest
local check_args=()
[[ $SKIP_SMOKE -eq 1 ]] && check_args+=(--skip-checks)
for name in "${CLAUDE_HELPERS[@]}"; do
src="${ROOT}/.claude/skills/${name}/SKILL.md"
dest="${dest_root}/${name}/SKILL.md"
if [[ ! -f "$src" ]]; then
warn "Claude helper missing in source: ${src}"
src="${ROOT}/.claude/skills/${name}"
dest="${dest_root}/${name}"
if [[ ! -f "${src}/SKILL.md" ]]; then
warn "Claude helper missing in source: ${src}/SKILL.md"
continue
fi
if [[ $DRY_RUN -eq 1 ]]; then
log "DRY RUN: would install Claude helper ${name} → ${dest}"
log "DRY RUN: would transactional-install Claude helper ${name} → ${dest}"
continue
fi
mkdir -p "$(dirname "$dest")"
cp -f "$src" "$dest"
python3 "${ROOT}/scripts/install_transaction.py" "$src" "$dest" hyperlex-helper "${check_args[@]}"
done
}

Expand Down Expand Up @@ -237,8 +238,9 @@ if [[ $DRY_RUN -eq 1 ]]; then
[[ -d "$TARGET" ]] && log "DRY RUN: would publish a target-keyed backup under ${HERMES_ROOT}/backups/hyperlex/"
[[ $INSTALL_OPENCLAW -eq 1 ]] && log "DRY RUN: would also install to ${OPENCLAW_TARGET}"
[[ $INSTALL_CLAUDE -eq 1 ]] && log "DRY RUN: would also install Claude personal skill to ${CLAUDE_SKILL_TARGET}"
[[ $INSTALL_CLAUDE -eq 1 ]] && copy_claude_helpers
[[ $INSTALL_CLAUDE -eq 1 ]] && install_claude_helpers
[[ $INSTALL_CLAUDE_PLUGIN -eq 1 ]] && log "DRY RUN: would also install Claude plugin dir to ${CLAUDE_PLUGIN_TARGET}"
[[ $INSTALL_CLAUDE_PLUGIN -eq 1 ]] && install_claude_helpers
exit 0
fi

Expand All @@ -250,11 +252,12 @@ fi

if [[ $INSTALL_CLAUDE -eq 1 ]]; then
install_extra_host "$CLAUDE_SKILL_TARGET" "Claude personal skill"
copy_claude_helpers
install_claude_helpers
fi

if [[ $INSTALL_CLAUDE_PLUGIN -eq 1 ]]; then
install_extra_host "$CLAUDE_PLUGIN_TARGET" "Claude plugin"
install_claude_helpers
fi

echo ""
Expand Down
Loading
Loading