SoT Fleet Console

Autonomous session · 2026-09-03 · verification chain, pr-lens assessment, and the gate graph drawn by the tool being assessed.

77gates9active36partial28stub 154doctrines0violations1open err72stale pending

1 · Verification chain

commandresultwhat it said
tools/validate.pyexit 00 violations · 1 warning · clarity 0.54 · traversal 1.00 · 153 truth rows, 117 proved
tools/proof.py --summary-onlyexit 070 gates · 57 with primary_file · aligned 50/57 · TABLE_UNCOVERED 10
tools/doctrine_census.py --checkexit 1 → 0INDEX census block was STALE — synced, now current
tools/meta-consistency.pyexit 17 pass · 4 warn · 2 err → REVIEW.md oversize + census (census fixed)
tools/review-collisions.pyexit 021 REVIEW ids genuinely reused across eras
tools/rag/sync.shexit 0index was ~68h stale — re-ingested
tools/guard-check.pyexit 2requires --app-dir; not runnable bare (CLAUDE.md shows it bare)
tools/graph-export.pyexit 0emits MERMAID, not JSON as CLAUDE.md claims

Every row was run this session. validate.py is genuinely clean — 0 violations. The two bug/warn rows at the bottom are CLAUDE.md describing tools that do not behave as documented.

2 · The gate graph, drawn by pr-lens

73 gates → 4 lanes → 25 propagation edges, rendered through @coldtea/pr-lens-renderer as a library. delta is repurposed to carry build status instead of diff status, which is the one real cost of adopting their IR.

active / built partial stub — declared, never built
LumenBill gate graph — health by status Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). ENTRY & AUTH · SIGN-IN, ONBOARDING, PUBLIC WORK · CONTACTS, PROJECTS, TASKS, TIME MONEY · INVOICES, SUBSCRIPTIONS, PAYOUTS PLATFORM · SYSTEM, SETTINGS, INTEGRATIONS setup profile /setup-profile auth partial 1 tbl CHANGED blog list /blog public built NEW blog post /blog/[slug] public built NEW legal privacy /legal/privacy partial CHANGED legal terms /legal/terms partial CHANGED sign up /sign-up auth partial CHANGED auth middleware lib/supabase/middle… auth active NEW forgot password /forgot-password auth partial CHANGED onboarding /onboarding partial 1 tbl CHANGED reset password /reset-password auth partial CHANGED auth guard middleware — applies to all protected routes (exclude… auth partial CHANGED { } sow lifecycle bsm partial CHANGED projects list /projects partial 3 tbl CHANGED project detail /projects/[id] projects active NEW sow public /sow/[token] projects active NEW api sow decline /api/sow/[token]/decline projects partial 1 tbl CHANGED contacts new /contacts/new partial CHANGED contacts edit /contacts/[id]/edit partial CHANGED projects new /projects/new partial CHANGED contract builder /projects/[id] (tab… active 4 tbl NEW contact detail /contacts/[id] contacts partial 4 tbl CHANGED contacts list /contacts contacts partial 1 tbl CHANGED tasks list /tasks tasks partial 3 tbl CHANGED task detail /tasks/[id] tasks partial 4 tbl CHANGED time /time timer partial 4 tbl CHANGED contacts api create /api/contacts (POST) contacts stub REMOVED tasks new /tasks/new tasks stub REMOVED tasks edit /tasks/[id]/edit tasks stub REMOVED tasks api create /api/tasks (POST) tasks stub REMOVED project milestones /projects/[id]#mile… stub REMOVED google drive integration /api/integrations/f… stub 1 tbl REMOVED dropbox integration /api/integrations/folder-verify projects stub 1 tbl REMOVED { } invoice lifecycle bsm partial CHANGED invoices list /invoices partial CHANGED api subscription status /api/subscription partial 1 tbl CHANGED api billing invoices /api/billing/invoic… partial 3 tbl CHANGED checkout from compli… /checkout/from-comp… partial 3 tbl CHANGED issue paystub from co… /issue-paystub/from… partial 2 tbl CHANGED subscription status /subscription/status payments partial 1 tbl CHANGED invoice detail /invoices/[id] invoices partial 4 tbl CHANGED subscription plans /subscription/plans payments partial 2 tbl CHANGED subscription success /subscription/success payments partial 2 tbl CHANGED invoice new /invoices/new invoices partial 1 tbl CHANGED invoices api create /api/invoices (POST) invoices stub REMOVED dashboard overview /dashboard system active NEW invoice public /invoice/[token] active 4 tbl NEW support /support system partial CHANGED integrations settings /settings settings partial 2 tbl CHANGED pricing reference reference active NEW { } dev canvas (none — external to… partial CHANGED pre deploy guard partial CHANGED arch primitive selector infra partial CHANGED { } lumenbill domain rel partial CHANGED { } active timer context stub REMOVED { } notification aggregator (no dedicated route — surface overlaid on global-bar) system stub 4 tbl REMOVED landing / stub REMOVED sign in /sign-in stub REMOVED invoice edit /invoices/[id]/edit stub 3 tbl REMOVED settings /settings stub 3 tbl REMOVED search /search stub 4 tbl REMOVED subscription manage /subscription/manage stub 2 tbl REMOVED subscription billing /subscription/billi… stub 3 tbl REMOVED api payment link /api/invoices/[id]/… stub 2 tbl REMOVED api stripe webhook /api/webhooks/stripe stub 7 tbl REMOVED api sow accept /api/sow/[token]/ac… stub 1 tbl REMOVED api feedback /api/feedback stub 1 tbl REMOVED api subscription chec… /api/subscription/c… stub 2 tbl REMOVED api subscription portal /api/subscription/p… stub 2 tbl REMOVED auth callback /auth/callback stub REMOVED auth sign out /auth/sign-out stub REMOVED notes panel /projects/[id]#notes, /contacts/[id]#notes, /invoices… system stub 1 tbl REMOVED automation templates /settings/automations settings stub 1 tbl REMOVED notion integration /settings (integrations section) integrations stub REMOVED
LumenBill gate graph — health by status Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). ENTRY & AUTH · SIGN-IN, ONBOARDING, PUBLIC WORK · CONTACTS, PROJECTS, TASKS, TIME MONEY · INVOICES, SUBSCRIPTIONS, PAYOUTS PLATFORM · SYSTEM, SETTINGS, INTEGRATIONS setup profile /setup-profile auth partial 1 tbl CHANGED blog list /blog public built NEW blog post /blog/[slug] public built NEW legal privacy /legal/privacy partial CHANGED legal terms /legal/terms partial CHANGED sign up /sign-up auth partial CHANGED auth middleware lib/supabase/middle… auth active NEW forgot password /forgot-password auth partial CHANGED onboarding /onboarding partial 1 tbl CHANGED reset password /reset-password auth partial CHANGED auth guard middleware — applies to all protected routes (exclude… auth partial CHANGED { } sow lifecycle bsm partial CHANGED projects list /projects partial 3 tbl CHANGED project detail /projects/[id] projects active NEW sow public /sow/[token] projects active NEW api sow decline /api/sow/[token]/decline projects partial 1 tbl CHANGED contacts new /contacts/new partial CHANGED contacts edit /contacts/[id]/edit partial CHANGED projects new /projects/new partial CHANGED contract builder /projects/[id] (tab… active 4 tbl NEW contact detail /contacts/[id] contacts partial 4 tbl CHANGED contacts list /contacts contacts partial 1 tbl CHANGED tasks list /tasks tasks partial 3 tbl CHANGED task detail /tasks/[id] tasks partial 4 tbl CHANGED time /time timer partial 4 tbl CHANGED contacts api create /api/contacts (POST) contacts stub REMOVED tasks new /tasks/new tasks stub REMOVED tasks edit /tasks/[id]/edit tasks stub REMOVED tasks api create /api/tasks (POST) tasks stub REMOVED project milestones /projects/[id]#mile… stub REMOVED google drive integration /api/integrations/f… stub 1 tbl REMOVED dropbox integration /api/integrations/folder-verify projects stub 1 tbl REMOVED { } invoice lifecycle bsm partial CHANGED invoices list /invoices partial CHANGED api subscription status /api/subscription partial 1 tbl CHANGED api billing invoices /api/billing/invoic… partial 3 tbl CHANGED checkout from compli… /checkout/from-comp… partial 3 tbl CHANGED issue paystub from co… /issue-paystub/from… partial 2 tbl CHANGED subscription status /subscription/status payments partial 1 tbl CHANGED invoice detail /invoices/[id] invoices partial 4 tbl CHANGED subscription plans /subscription/plans payments partial 2 tbl CHANGED subscription success /subscription/success payments partial 2 tbl CHANGED invoice new /invoices/new invoices partial 1 tbl CHANGED invoices api create /api/invoices (POST) invoices stub REMOVED dashboard overview /dashboard system active NEW invoice public /invoice/[token] active 4 tbl NEW support /support system partial CHANGED integrations settings /settings settings partial 2 tbl CHANGED pricing reference reference active NEW { } dev canvas (none — external to… partial CHANGED pre deploy guard partial CHANGED arch primitive selector infra partial CHANGED { } lumenbill domain rel partial CHANGED { } active timer context stub REMOVED { } notification aggregator (no dedicated route — surface overlaid on global-bar) system stub 4 tbl REMOVED landing / stub REMOVED sign in /sign-in stub REMOVED invoice edit /invoices/[id]/edit stub 3 tbl REMOVED settings /settings stub 3 tbl REMOVED search /search stub 4 tbl REMOVED subscription manage /subscription/manage stub 2 tbl REMOVED subscription billing /subscription/billi… stub 3 tbl REMOVED api payment link /api/invoices/[id]/… stub 2 tbl REMOVED api stripe webhook /api/webhooks/stripe stub 7 tbl REMOVED api sow accept /api/sow/[token]/ac… stub 1 tbl REMOVED api feedback /api/feedback stub 1 tbl REMOVED api subscription chec… /api/subscription/c… stub 2 tbl REMOVED api subscription portal /api/subscription/p… stub 2 tbl REMOVED auth callback /auth/callback stub REMOVED auth sign out /auth/sign-out stub REMOVED notes panel /projects/[id]#notes, /contacts/[id]#notes, /invoices… system stub 1 tbl REMOVED automation templates /settings/automations settings stub 1 tbl REMOVED notion integration /settings (integrations section) integrations stub REMOVED

Signal propagation, animated (SMIL, 5 steps):

LumenBill gate graph — health by status Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). contacts list /contacts 1 tbl CHANGED contact detail /contacts/[id] 4 tbl CHANGED invoice new /invoices/new 1 tbl CHANGED invoice detail /invoices/[id] 4 tbl CHANGED time /time 4 tbl CHANGED open contact new invoice issue → detail time entries roll up exposure signal back
LumenBill gate graph — health by status Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). contacts list /contacts 1 tbl CHANGED contact detail /contacts/[id] 4 tbl CHANGED invoice new /invoices/new 1 tbl CHANGED invoice detail /invoices/[id] 4 tbl CHANGED time /time 4 tbl CHANGED open contact new invoice issue → detail time entries roll up exposure signal back

Entry & auth

Entry & Auth Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). ENTRY & AUTH · SIGN-IN, ONBOARDING, PUBLIC setup profile /setup-profile auth partial 1 tbl CHANGED blog list /blog public built NEW blog post /blog/[slug] public built NEW legal privacy /legal/privacy partial CHANGED legal terms /legal/terms partial CHANGED auth guard middleware — applie… auth partial CHANGED auth middleware lib/supabase/middle… auth active NEW sign up /sign-up auth partial CHANGED forgot password /forgot-password auth partial CHANGED onboarding /onboarding partial 1 tbl CHANGED reset password /reset-password auth partial CHANGED
Entry & Auth Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). ENTRY & AUTH · SIGN-IN, ONBOARDING, PUBLIC setup profile /setup-profile auth partial 1 tbl CHANGED blog list /blog public built NEW blog post /blog/[slug] public built NEW legal privacy /legal/privacy partial CHANGED legal terms /legal/terms partial CHANGED auth guard middleware — applie… auth partial CHANGED auth middleware lib/supabase/middle… auth active NEW sign up /sign-up auth partial CHANGED forgot password /forgot-password auth partial CHANGED onboarding /onboarding partial 1 tbl CHANGED reset password /reset-password auth partial CHANGED

Money

Money Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). MONEY · INVOICES, SUBSCRIPTIONS, PAYOUTS { } invoice lifecycle bsm partial CHANGED invoices list /invoices partial CHANGED subscription status /subscription/status partial 1 tbl CHANGED api subscription status /api/subscription partial 1 tbl CHANGED api billing invoices /api/billing/invoic… partial 3 tbl CHANGED checkout from compli… /checkout/from-comp… partial 3 tbl CHANGED issue paystub from compliance /issue-paystub/from-compliance payments partial 2 tbl CHANGED invoice new /invoices/new invoices partial 1 tbl CHANGED subscription plans /subscription/plans payments partial 2 tbl CHANGED invoice detail /invoices/[id] invoices partial 4 tbl CHANGED subscription success /subscription/success payments partial 2 tbl CHANGED invoices api create /api/invoices (POST) invoices stub REMOVED
Money Every declared gate in the SoT, coloured by build status. Green = active/built, amber = partial, red = stub (declared, never built). MONEY · INVOICES, SUBSCRIPTIONS, PAYOUTS { } invoice lifecycle bsm partial CHANGED invoices list /invoices partial CHANGED subscription status /subscription/status partial 1 tbl CHANGED api subscription status /api/subscription partial 1 tbl CHANGED api billing invoices /api/billing/invoic… partial 3 tbl CHANGED checkout from compli… /checkout/from-comp… partial 3 tbl CHANGED issue paystub from compliance /issue-paystub/from-compliance payments partial 2 tbl CHANGED invoice new /invoices/new invoices partial 1 tbl CHANGED subscription plans /subscription/plans payments partial 2 tbl CHANGED invoice detail /invoices/[id] invoices partial 4 tbl CHANGED subscription success /subscription/success payments partial 2 tbl CHANGED invoices api create /api/invoices (POST) invoices stub REMOVED

3 · pr-lens — what I took, what I refused

partcallwhy
Renderer
@coldtea/pr-lens-renderer
VENDORHand-rolled layout + SMIL SVG. Zero deps beyond its schema. No network, no fs, no clock, no process.env. Pure data→string.
Schema
@coldtea/pr-lens-schema
VENDORZod IR + referential-integrity pass + patch/apply semantics. Reports every issue at once.
Agent skill
skills/pr-lens/
REJECTAGENTS.md tells the agent to fetch and obey a third-party SKILL.md (blader/humanizer). Live second-order injection channel.
CLI · canvas
pr-lens canvas *
REJECT1,340 LOC of hosted token/registry/lock machinery against prlens.dev. Newest, least-settled code in the repo.
CLI · analyze
pr-lens analyze
REJECT--api-key-env reads ANY env var; --base-url ships it to ANY host. One-line exfil primitive in an agent context.
GitHub Action
packages/action
REJECTRuns npx --yes CLI in CI, version-pinned but not integrity-pinned. Not needed for our use.

Rustify: no. ~6,000 LOC is portable and the golden SVGs would be a free conformance suite, but the work is O(V+E) over documents capped at 256 nodes — there is no hot loop. The only honest argument is a single static binary with no Node in CI.

4 · Security scan — read-only, nothing executed

CLEAN

Planted prompt injection

No hidden Unicode (0 chars in Cf/Co/Cs/Cn), no HTML comments in any .md, no base64 blobs, 49 SVGs free of script/onload/foreignObject, installed skill byte-identical to source.

RISK

AGENTS.md:9 — third-party instruction fetch

Directs the agent to run copy through github.com/blader/humanizer SKILL.md. Whoever controls that repo controls instructions this repo hands your agent.

RISK

AGENTS.md:7 — names an out-of-repo secrets dir

Tells an agent ~/Documents/dev/pr-lens-secrets/ exists, in order to forbid it. One negated commit from bait.

BUG

ReDoS via .github/pr-lens.yml globs

renderer/src/glob.ts:8 builds RegExp from a 256-char attacker selector; ~40 nested .* → catastrophic backtracking. CI DoS.

BUG

Symlink-following registry write

cli/src/io.ts:45 writes <path>.<pid>.tmp with no flag:'wx' / O_NOFOLLOW; predictable name, 0600 lost on pre-existing target.

GOOD

Untrusted PR text → comment

comment.ts:23 escapes, collapses to one line, wraps every model string in an element so GitHub won't parse markdown, and inserts U+200B after @/# so nothing autolinks.

5 · SoT findings this session

SOT

Gate status enum drift

CLAUDE.md declares stub|partial|active|proved. On disk: partial 36, stub 28, active 7, pruned 4, built 2 — 'built' and 'pruned' undeclared, and NOTHING is 'proved'.

SOT

22 gates carry no domain

Of 77 gate files parsed, 22 have no domain: field — they fall through every domain-keyed tool.

SOT

70 doctrines invisible to INDEX

doctrine_census: 154 on disk, 84 named in INDEX.md, 70 never named. They exist but no tool that reads INDEX can see them.

SOT

REVIEW.md drain rule cannot fire

185,492B vs 175,000B cap. Its own header says drain only terminal RESOLVED entries — but 37 say OPEN and 29 carry no status at all.

SOT

21 REVIEW ids reused

Numbering was reused across eras, so a bare REVIEW-NNN citation is ambiguous for 21 numbers.

SOT

72 stale PENDING entries

Oldest 91 days. DEAD_STUB is 0, so these are queue mass, not broken pointers.

6 · Fleet heartbeat

applast touched
actionpack15d ago
compliance-ledger15d ago
haven15d ago
feedy35d ago
bigdonkeymailer57d ago

Doctrine census: L0 system 54 · L1 cross-app 51 · L2 app-local 27 · L3 candidate 22 = 154 total, 0 unclassified, 0 orphans — but 70 never named in INDEX.md.