You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Say one hundred and fifty everywhere, not only in the data
Commit 024c1fd regenerated docs/receipts-11155111.json to 150 rows and left the
README quoting 50 in four places: the liveness claim above the surface table, the
two "live" cells for execute/contract-call and analytics/runs, and the sentence
that says how many times value moved through KeeperHub. The direction of the error
was under-claiming, which is the harmless direction, but a judge who opens the
receipts file after reading "value moved through KeeperHub 50 times" watches this
README contradict its own committed data. That is the one thing this repo cannot
afford to do.
The "What is actually proven" heading was still dated 2026-09-02. It now reads
2026-09-09, and every claim under it was re-checked before the date moved:
12 safes in src/manifest.json, 5 on the Sepolia roster, 80 tests, the recycle
disclosure.
That re-check turned up a second thing worth stating plainly. The execution
detailed in that section - 0xf0b3b611, executionId qy3vfai4lux3yokk7ilea - is NOT
among the 150 rows; it predates the 2026-09-06T16:01Z window the audit regenerated.
The section used to read as though the table and the count described the same
thing. It now says which is which, and points at the receipts file for the 150.
Copy file name to clipboardExpand all lines: README.md
+12-8Lines changed: 12 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -145,20 +145,20 @@ no scheduler and no wallet of its own; every read, every gate and the broadcast
145
145
KeeperHub. Four API surfaces and the Safe plugin carry the whole flow:
146
146
147
147
Every surface below carries a **liveness claim**. "Live" means it ran in the path that produced
148
-
the 50 executions on record. "Authored" means it is committed and was verified during the spikes,
148
+
the 150 executions on record. "Authored" means it is committed and was verified during the spikes,
149
149
but the production path does not go through it β and saying so is more useful to you than a longer
150
150
list of yeses.
151
151
152
152
| Surface | Liveness | Where | What it does |
153
153
|---|---|---|---|
154
-
|**`POST /api/execute/contract-call`**| β **live β all 50 executions**|[`scripts/drain.mjs:164`](scripts/drain.mjs)| Direct Execution. Always `simulate: true` as a preflight, then the real call with an `Idempotency-Key` so a retry can never double-broadcast |
155
-
|**`GET /api/analytics/runs`**| β **live β 50 rows**|[`scripts/audit.mjs:53`](scripts/audit.mjs)| KeeperHub's own execution rows β `verified`, `receiptStatus`, `blockNumber`, `gasUsed` β are the audit ledger. We render them; we never compute them |
154
+
|**`POST /api/execute/contract-call`**| β **live β all 150 executions**|[`scripts/drain.mjs:164`](scripts/drain.mjs)| Direct Execution. Always `simulate: true` as a preflight, then the real call with an `Idempotency-Key` so a retry can never double-broadcast |
155
+
|**`GET /api/analytics/runs`**| β **live β 150 rows**|[`scripts/audit.mjs:53`](scripts/audit.mjs)| KeeperHub's own execution rows β `verified`, `receiptStatus`, `blockNumber`, `gasUsed` β are the audit ledger. We render them; we never compute them |
156
156
|**MCP server**| β live, design-time | spikes |`get_plugin`, `get_spending_limits`, `list_projects`, `list_integrations`, `GET /api/mcp/schemas`. Every platform claim here was checked against a live MCP call |
157
157
|**`POST /api/workflows/create`**| β οΈ **called, rejected**|[`scripts/sync.mjs:300`](scripts/sync.mjs)| Emits the `gavel-drain` graph β 11 nodes, 10 edges, committed at [`workflows/`](workflows/). The API returns `upgrade_required`: `code/run-code` and `HTTP Request` are plan-gated (**issue #2279**) |
158
158
|**Safe plugin reads** β `safe/get-pending-transactions`, `-threshold`, `-owners`, `-nonce`| β οΈ **authored, not in the production path**|`workflows/*.json` nodes `queue-1`, `threshold-1`, `owners-1`, `nonce-1`| They are the canonical design and were verified in the spikes, but the graph holding them was never created. `drain.mjs` instead reads the queue from `api.safe.global` and takes `nonce()`/`getThreshold()`/`getOwners()` with viem straight off the RPC |
159
159
|**`web3/read-contract`** Β· **`web3/write-contract`**| β οΈ **authored, not in the production path**|`workflows/*.json` nodes `read-*`, `exec-1`| Same gate. `exec-1` is why the graph exists β all **7** Safe plugin actions are reads, so there is no Safe-plugin write action to execute with |
160
160
161
-
**So be precise about what "through KeeperHub" means here.** Value moved through KeeperHub 50 times
161
+
**So be precise about what "through KeeperHub" means here.** Value moved through KeeperHub 150 times
162
162
and the ledger proving it is KeeperHub's own β that part is real. The *reads* feeding the decision
163
163
do not currently go through KeeperHub in the running path, because the workflow that would carry
164
164
them is plan-gated. The canvas version and `drain.mjs` reach the identical on-chain outcome; they
@@ -211,10 +211,14 @@ Predicted, then measured. The cryptographic surface stays at six lines.
211
211
212
212
---
213
213
214
-
## β What is actually proven, as of 2026-09-02
214
+
## β What is actually proven, as of 2026-09-09
215
215
216
-
**One real end-to-end execution through KeeperHub**, on Ethereum Sepolia (11155111) β the
217
-
**rehearsal** chain:
216
+
**150 end-to-end executions through KeeperHub**, on Ethereum Sepolia (11155111) β the
217
+
**rehearsal** chain. [`docs/receipts-11155111.json`](docs/receipts-11155111.json) holds all 150,
218
+
150 of 150 `success`, every one via the Direct Execution API, in the window
219
+
2026-09-06T16:01Z β 2026-09-07T10:11Z. The execution detailed below is an **earlier** one and is
220
+
deliberately not among those 150 β it is the first that ran end to end, and it is the one whose
221
+
every field was checked by hand:
218
222
219
223
|||
220
224
|---|---|
@@ -229,7 +233,7 @@ A threshold-met, deliberately unexecuted payout was drained by an address that o
229
233
Safe. Three gates ran first and all passed: `assemble.mjs` β a local read-only `eth_call` β
230
234
KeeperHub's own `simulate: true` preflight.
231
235
232
-
Also standing up today:
236
+
Also standing up:
233
237
234
238
-**12 Safes deployed and funded** on Ethereum Sepolia from one manifest, CREATE2-deterministic β
235
239
thresholds 1-of-2 through 3-of-5, five of them on the opt-in roster.
0 commit comments