docs(readme): state three claims precisely — judge independence, stop-gate cap, provider keys
deploy / test (push) Successful in 5m21s
deploy / build (push) Successful in 1m5s

- the judge is cross-provider only when one is configured; the self-host
  default judges with Claude and records it as not independent
- the stop gate blocks at most 3 times, not until the check passes
- mission containers DO carry model-provider keys in their environment
  (verified on prod: CLAUDE_CODE_OAUTH_TOKEN, ZAI_API_KEY, KIMI_API_KEY);
  the broker claim holds for platform credentials, not these

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
Omar Sobh
2026-09-23 11:24:01 -05:00
co-authored by Claude Opus 5.5
parent 1e293f2840
commit 4030347b56
+11 -6
View File
@@ -28,8 +28,10 @@ Live at **[clawmates.work](https://clawmates.work)**.
gateway, running Claude Code (`claude_cli`) with fallback to Kimi and GLM. *MicroVM tier*: phases run
in Firecracker microVMs on fleet nodes (`clawmates-node` + the `fcagent` guest), with per-backend
egress (Claude, GLM, Kimi, or a local model over vsock).
- **An independent judge.** Every conditioned phase is judged by a model from a *different* provider
family than the agents (GLM by default, Kimi as automatic fallback), which runs its own allow-listed
- **An independent judge.** Every conditioned phase is judged. When a cross-provider judge is configured
(prod: GLM, with Kimi as automatic fallback) it is a model from a *different* provider family than the
agents; without one (the self-host default) the phase is judged by Claude and recorded as **not**
independent. The judge runs its own allow-listed
checks — tests, `rg`, git — against a copy of the work, commits to a verification plan before reading
the evidence, and installs npm dependencies offline from the lockfile. A phase that fails is retried
with the judge's guidance, up to `max_iterations`. Measured with `scripts/judge-eval.sh` (15 known-answer
@@ -40,8 +42,8 @@ Live at **[clawmates.work](https://clawmates.work)**.
`continuous_research` auto-merges additive-only changes into the vault.
- **Tool gates on every agent call.** A `PreToolUse` gate (both tiers) refuses destructive and exfiltrating
commands, protects its own hook files, enforces per-role policy (e.g. a read-only verifier), and records
task-permission and argument-provenance ("taint") violations in shadow mode. A stop gate keeps a
microVM agent working until its `done_when_check` passes.
task-permission and argument-provenance ("taint") violations in shadow mode. A stop gate sends a
microVM agent back to work while its `done_when_check` fails, up to 3 times.
- **Skills.** A catalog of skills bound to team roles, delivered to mission agents through the MCP
skills door; per-mission skill triage and skill-use measurement.
- **Project memory.** Each repository keeps a `.brain` (ClawhDF5) of every judge verdict; missions recall
@@ -251,8 +253,11 @@ structures, never gives an agent more reach than its sandbox. What that means to
blocked); see [`docs/MISSION-EGRESS.md`](docs/MISSION-EGRESS.md) and
[`docs/TASK-PERMISSION-AND-TAINT.md`](docs/TASK-PERMISSION-AND-TAINT.md) for the measurements and the
controls being built on top.
- Credentials are held by the secret broker behind a private socket. A mission container gets only a
narrowly scoped skills token, never a full session. The server reaches Docker through an allow-listed
- Platform credentials are held by the secret broker behind a private socket, and a mission container
gets only a narrowly scoped skills token, never a ClawMates session. **Model-provider keys are the
exception:** Claude Code inside a mission needs its own credential, so container-tier missions carry
the provider keys (`CLAUDE_CODE_OAUTH_TOKEN`, and `ZAI_API_KEY` / `KIMI_API_KEY` for the fallback
chain) in their environment, readable by the agent. The server reaches Docker through an allow-listed
socket proxy.
- The gate is a guardrail against accidents and obvious exfiltration, not a boundary against a
determined agent (indirection defeats string matching). The boundaries are the VM, the network policy