Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
123 commits
Select commit Hold shift + click to select a range
697a710
ops(autopilot): log PR #26 merge; branch restarted from master
claude Jul 22, 2026
573c636
ops(autopilot): current loop PR pointer -> #27; restart-after-merge r…
claude Jul 22, 2026
939c748
feat(plugin): Claude Code marketplace manifest — one-command install …
claude Jul 22, 2026
af07264
feat(metrics): daily funnel snapshot script, fixture-tested (T12)
claude Jul 22, 2026
9e64812
ops(autopilot): T13 delivered off-repo; queue empty — next run trigge…
claude Jul 23, 2026
9d024f3
ops(autopilot): queue v2 from second adversarial panel (U1-U9)
claude Jul 23, 2026
8a84201
feat(site): packs.html — full pack scope before checkout (U1)
claude Jul 23, 2026
0adf536
ops(launch): OWNER_RUNBOOK — 20 minutes to unblock, one command per s…
claude Jul 23, 2026
6c18922
feat(hint): pack hint v2 — HTTP-API detection, preview page links (U3…
claude Jul 23, 2026
eeed19a
feat(site): self-verify block on every purchase surface (U4)
claude Jul 23, 2026
7e70bdc
docs(facts): re-pin F13 at 2,529; re-verify F3/F4/F9 (U5)
claude Jul 23, 2026
c450ffd
ops(launch): category data pack for the Return on Security thread (U6)
claude Jul 23, 2026
293be18
fix(version)+ops(partners): runtime version sync, F9 re-pin to 0.4.18…
claude Jul 23, 2026
c885300
ops(launch): day-3/day-7 follow-up templates + LEDGER due dates (U8)
claude Jul 23, 2026
9205079
ops(autopilot): U9 done off-repo (scoring + 3 design-partner drafts o…
claude Jul 23, 2026
5ee11f0
ops(autopilot): queue v3 from panel + W1 rule-9 purge (severity-overr…
claude Jul 23, 2026
022d3d7
ops(autopilot): W2 done off-repo — affiliate {HOOK} bank delivered on…
claude Jul 23, 2026
be8f5fc
feat(cli): gate.cat setup claude-code + doctor — one-command hook act…
claude Jul 23, 2026
414af79
fix(conversion): instrumentation sweep — five verified fixes in one p…
claude Jul 23, 2026
75620d3
chore(release): 0.4.19 prep — bump x5, guards, clean-venv smoke, chec…
claude Jul 23, 2026
2edb634
docs(facts): drift sweep — six confirmed mismatches fixed by hand (W6)
claude Jul 23, 2026
589d091
ops(autopilot): queue v4 from panel — world-model correction from iss…
claude Jul 23, 2026
bffc460
ops(autopilot): distribution state table from issue #9 + HN mod-respo…
claude Jul 23, 2026
f62b570
fix(affiliate): referral capture on the landing page + real drift-gua…
claude Jul 23, 2026
720d79f
fix(affiliate): invoice-keyed accrual idempotency + clawback on real …
claude Jul 23, 2026
092ce3c
ops(launch): campaign-response collateral in existing files (V4) + LE…
claude Jul 23, 2026
fe2220b
docs(readme): veto-axis Comparison + 'does it work with my agent' mat…
claude Jul 23, 2026
ee4a3fb
fix(nudge): stop selling to customers who already paid (V6, for 0.4.20)
claude Jul 23, 2026
b6656b6
ops(autopilot): queue v5 from panel — incl. X4, a verified live gate …
claude Jul 24, 2026
ab7bdc1
fix(guard): delete analyzer must see inert-literal-stripped text (iss…
claude Jul 24, 2026
0848cca
feat(site): data-boundary evidence at the point of sale (X1)
claude Jul 24, 2026
6c2b7cc
docs(readme): absolute GitHub URLs for every relative link — PyPI-saf…
claude Jul 24, 2026
fcc398c
feat(site): static og/twitter/canonical on the landing head (X3)
claude Jul 24, 2026
82776c3
docs(facts): reconcile verifiable numbers — RECALL 31/12, drop stale …
claude Jul 24, 2026
572ef38
feat(answers): repatriate the guardrails-across-a-team page + split c…
claude Jul 24, 2026
876654f
ops(autopilot): queue v6 from panel — repo-polish declared closed, tw…
claude Jul 24, 2026
0e1b834
ops(autopilot): Y1 resolved NO-GO on claude-code#80730 + scaffold-ove…
claude Jul 24, 2026
1fae3fe
fix(cloud): probe encryption before touching cursor — stop silent pai…
claude Jul 24, 2026
9b2925e
fix(cloud-cli): one error choke point — no raw traceback on wrong key…
claude Jul 24, 2026
63f9830
ops(autopilot): loop #46 — HOLD (queue drained except gated Y2; no fi…
claude Jul 24, 2026
a5a09ea
ops(autopilot): loop #47 — HOLD; note owner cold-send bounce (devtall…
claude Jul 24, 2026
524637f
ops(autopilot): loop #48 — HOLD (unchanged since #47)
claude Jul 24, 2026
70c0135
ops(autopilot): loop #49 — launch adversarial scaffold-overwrite desi…
claude Jul 24, 2026
658822e
feat(guard): SCAFFOLD_OVERWRITE — WARN on create-vite/degit into a po…
claude Jul 24, 2026
2024838
ops(autopilot): loop #50 — HOLD; Y5 confirmed green in CI (3.11/3.12/…
claude Jul 24, 2026
1f32d62
ops(autopilot): loop #51 — HOLD (unchanged since #50)
claude Jul 24, 2026
4b251f9
ops(autopilot): loop #52 — HOLD (unchanged)
claude Jul 24, 2026
dae4399
ops(autopilot): loop #53 — HOLD (unchanged)
claude Jul 24, 2026
e7bee42
ops(autopilot): loop #54 — HOLD (unchanged)
claude Jul 24, 2026
5b4f1b5
ops(autopilot): loop #55 — HOLD (rolling; consolidated #51-#55 log en…
claude Jul 24, 2026
cb62411
ops(autopilot): loop #56 — HOLD (rolling, unchanged)
claude Jul 24, 2026
e23fd4f
ops(autopilot): loop #57 — HOLD (rolling, unchanged)
claude Jul 24, 2026
9381ee8
ops(autopilot): loop #58 — HOLD (rolling); Y2 wave 1 opens next run
claude Jul 24, 2026
8ea4352
ops(autopilot): loop #59 — Y2 wave 1 done (day-3 follow-up drafts: Ju…
claude Jul 25, 2026
fb7aba4
ops(autopilot): loop #60 — HOLD (rolling); Y2 wave 2 gated to 2026-07-26
claude Jul 25, 2026
fc85e38
ops(autopilot): loop #61 — HOLD (rolling)
claude Jul 25, 2026
ecc5c67
ops(autopilot): loop #62 — HOLD (rolling)
claude Jul 25, 2026
0e59c12
ops(autopilot): loop #63 — HOLD (rolling)
claude Jul 25, 2026
7bf668d
ops(autopilot): loop #64 — HOLD (rolling)
claude Jul 25, 2026
aa538c7
ops(autopilot): loop #65 — HOLD (rolling)
claude Jul 25, 2026
888bcd2
ops(autopilot): loop #66 — HOLD (rolling); note new Stripe KYC for "B…
claude Jul 25, 2026
44f1344
ops(autopilot): loop #67 — HOLD (rolling)
claude Jul 25, 2026
0dd8f78
ops(autopilot): loop #68 — HOLD (rolling); second Stripe KYC entity (…
claude Jul 25, 2026
0364547
ops(autopilot): loop #69 — HOLD (rolling)
claude Jul 25, 2026
40cc294
ops(autopilot): loop #70 — HOLD (rolling)
claude Jul 25, 2026
2441b6b
ops(autopilot): loop #71 — HOLD (rolling)
claude Jul 25, 2026
2d423db
ops(autopilot): loop #72 — HOLD (rolling)
claude Jul 25, 2026
72a186e
ops(autopilot): loop #73 — HOLD (rolling)
claude Jul 25, 2026
fc12678
ops(autopilot): loop #74 — HOLD (rolling)
claude Jul 25, 2026
4f76e4c
ops(autopilot): loop #75 — HOLD (rolling)
claude Jul 25, 2026
9203870
ops(autopilot): loop #76 — HOLD (rolling)
claude Jul 25, 2026
80becca
ops(autopilot): loop #77 — HOLD (rolling)
claude Jul 25, 2026
1a4bb19
ops(autopilot): loop #78 — HOLD (rolling)
claude Jul 25, 2026
c308c41
ops(autopilot): loop #79 — HOLD (rolling)
claude Jul 25, 2026
b4da9b6
ops(autopilot): loop #80 — HOLD (rolling)
claude Jul 25, 2026
5610ef8
ops(autopilot): loop #81 — HOLD (rolling)
claude Jul 25, 2026
b8c73a7
ops(autopilot): loop #82 — HOLD (rolling); Y2 wave 2 opens next run
claude Jul 25, 2026
c4db4e6
ops(autopilot): loop #83 — Y2 wave 2 done (10 day-3 follow-up drafts)…
claude Jul 26, 2026
87e6391
ops(autopilot): loop #84 — HOLD (rolling; queue v6 fully closed)
claude Jul 26, 2026
29344c2
ops(autopilot): loop #85 — HOLD (rolling)
claude Jul 26, 2026
ba08c63
ops(autopilot): loop #86 — HOLD (rolling)
claude Jul 26, 2026
a340720
ops(autopilot): loop #87 — HOLD (rolling)
claude Jul 26, 2026
1035624
ops(autopilot): loop #88 — HOLD (rolling)
claude Jul 26, 2026
55d8299
ops(autopilot): loop #89 — HOLD (rolling)
claude Jul 26, 2026
e116542
ops(autopilot): loop #90 — HOLD (rolling)
claude Jul 26, 2026
9e072aa
ops(autopilot): loop #91 — HOLD (rolling)
claude Jul 26, 2026
cd969eb
ops(autopilot): loop #92 — HOLD (rolling)
claude Jul 26, 2026
886dd5e
ops(autopilot): loop #93 — HOLD (rolling)
claude Jul 26, 2026
63593ee
ops(autopilot): loop #94 — HOLD (rolling)
claude Jul 26, 2026
509fca0
ops(autopilot): loop #95 — HOLD (rolling)
claude Jul 26, 2026
f8ae180
ops(autopilot): loop #96 — HOLD (rolling)
claude Jul 26, 2026
f9df32d
ops(autopilot): loop #97 — HOLD (rolling)
claude Jul 26, 2026
d39bc1d
ops(autopilot): loop #98 — HOLD (rolling)
claude Jul 26, 2026
d046566
ops(autopilot): loop #99 — HOLD (rolling)
claude Jul 26, 2026
382908a
ops(autopilot): loop #100 — HOLD (rolling)
claude Jul 26, 2026
31c2f46
ops(autopilot): loop #101 — HOLD (rolling)
claude Jul 26, 2026
9f0d675
ops(autopilot): loop #102 — HOLD (rolling)
claude Jul 26, 2026
ae28540
ops(autopilot): loop #103 — HOLD (rolling)
claude Jul 26, 2026
b06f8e8
ops(autopilot): loop #104 — HOLD (rolling)
claude Jul 26, 2026
91d324d
ops(autopilot): loop #105 — HOLD (rolling)
claude Jul 26, 2026
ba6e9c6
ops(autopilot): loop #106 — HOLD (rolling)
claude Jul 26, 2026
c1e0cdf
ops(autopilot): loop #107 — HOLD (rolling; new day 2026-07-27)
claude Jul 27, 2026
227657a
ops(autopilot): loop #108 — HOLD (rolling)
claude Jul 27, 2026
a861158
ops(autopilot): loop #109 — HOLD (rolling)
claude Jul 27, 2026
9e7409d
ops(autopilot): loop #110 — HOLD (rolling)
claude Jul 27, 2026
ced7b47
ops(autopilot): loop #111 — HOLD (rolling)
claude Jul 27, 2026
f3965b7
ops(autopilot): loop #112 — HOLD (rolling)
claude Jul 27, 2026
7136984
ops(autopilot): loop #113 — HOLD (rolling)
claude Jul 27, 2026
4801d5e
ops(autopilot): loop #114 — HOLD (rolling)
claude Jul 27, 2026
cfcdf4b
ops(autopilot): loop #115 — HOLD (rolling)
claude Jul 27, 2026
90b943e
ops(autopilot): loop #116 — HOLD (rolling)
claude Jul 27, 2026
be2139b
ops(autopilot): loop #117 — HOLD (rolling)
claude Jul 27, 2026
5ea8ebc
ops(autopilot): loop #118 — HOLD (rolling)
claude Jul 27, 2026
e8d4420
ops(autopilot): loop #119 — HOLD (rolling)
claude Jul 27, 2026
4b72b7b
ops(autopilot): loop #120 — HOLD (rolling); note owner self-test pitc…
claude Jul 27, 2026
a620956
ops(autopilot): loop #121 — HOLD (rolling)
claude Jul 27, 2026
3e07875
ops(autopilot): loop #122 — HOLD (rolling)
claude Jul 27, 2026
c633b18
ops(autopilot): loop #123 — HOLD (rolling)
claude Jul 27, 2026
4d5c0ed
ops(autopilot): loop #124 — HOLD (rolling)
claude Jul 27, 2026
e9e685f
ops(autopilot): loop #125 — HOLD (rolling)
claude Jul 27, 2026
42a74ef
ops(autopilot): loop #126 — HOLD (rolling)
claude Jul 27, 2026
7400774
ops(autopilot): loop #127 — HOLD (rolling)
claude Jul 27, 2026
ae1c1ec
ops(autopilot): loop #128 — HOLD (rolling)
claude Jul 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{
"name": "gatecat",
"owner": {
"name": "BGML",
"email": "bogumil@bgml.ai",
"url": "https://gate.cat"
},
"plugins": [
{
"name": "gatecat",
"source": "./plugins/gatecat",
"description": "Deterministic action veto for Claude Code: blocks rm -rf, DROP TABLE, terraform destroy, disk wipes and secret exfiltration BEFORE the tool call executes. Requires `pip install gate.cat` (free, Apache-2.0).",
"version": "0.4.19"
}
]
}
53 changes: 53 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,59 @@
All notable changes to `gate.cat` will be documented in this file.


## [Unreleased] -- 0.4.20

### Fixed
- Content-vs-command false-block (issue #4 / F1): a benign
`git commit -m "...git clean -f..."` was vetoed by the delete analyzer
because it ran on the raw action while inert-literal stripping (commit
message / echo / grep bodies) only fed the regex walls. The stripped text
is now computed once and shared with both stages, so a danger pattern
quoted inside a commit message can't false-block; the bare `git clean -f`
command still blocks, and recall stays 43/43 with 0 benign false-blocks.
log/raise still use the original action (verbatim audit).
- The first-veto Team nudge now stays silent when `GATECAT_CLOUD_API_KEY` is
set -- a paying Cloud customer already has the off-machine record the nudge
pitches (the CLI nudge already did this; the post-veto path did not). No
once-per-machine flag is written in that case, so the nudge returns if Cloud
is dropped.
- The policy-pack hint is suppressed for a pack whose module is already loaded
via `GATECAT_EXTRA_POLICIES` (suppress-only: it never suggests a *different*
pack) -- a Fintech-pack buyer is no longer pitched the Fintech pack.


## [0.4.19] -- the hook arms itself (2026-07-23)

### Added
- `gate.cat setup claude-code [--global] [--dry-run]`: one-command PreToolUse
hook activation -- idempotent merge that preserves foreign keys and other
hooks, `<file>.gatecat.bak` backup before any modifying write, fail-closed
on unparsable settings.json (prints the manual block instead of touching
the file). `gate.cat doctor`: minimal install diagnosis (version, hook
binary on PATH, where the hook is registered, protection state). The
biggest funnel leak was an installed pip package whose hook was never
registered -- this automates exactly what the README documents.

### Changed
- Policy-pack hint v2 (`gatecat/_pack_hint.py`): now also detects the
HTTP-API Breadth pack -- via stack-specific CLIs only (`datadog-ci`,
`sentry-cli`; deliberately NO docker/gh/curl, which sit on every dev box
and would destroy the precision of a once-per-machine hint). All three
hints link the pack preview page
(`https://gate.cat/packs.html?source=hint#<pack>`) -- full scope before
checkout -- instead of a bare Stripe payment link. No policy, recall, or
bypass changes.

### Fixed
- `gatecat.__version__` now tracks pyproject (the 0.4.18 wheel shipped
printing "0.4.17" -- distribution metadata was correct, the runtime string
was not); a regression test ties the literal, both plugin manifests and
the pack-hint anchors to the release.
- `gate.cat report` footer shipped a literal `*` inside its pasteable URL;
the post-veto nudge CTA was the only untagged conversion surface (now
`?source=nudge-veto`).


## [0.4.18] -- the listing sells, the CLI hints honestly (2026-07-22)

### Added
Expand Down
4 changes: 2 additions & 2 deletions COMPARISON.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ was talked into it, and stop the `terraform destroy` at the boundary anyway.

## vs. the "just use regexes yourself" objection

You could. gate.cat is ~21 curated policies for the irreversible-action class + an independent
You could. gate.cat is 71 default policy walls for the irreversible-action class + an independent
exec analyzer + human-in-the-loop + a bypass suite that **prints its own known gaps** (base64
payloads, deletes via a language runtime, `curl|sh`) instead of pretending they don't exist,
+ the harness integration that makes it enforcement rather than advice. The value is the curation,
Expand All @@ -52,7 +52,7 @@ the fail-closed wiring, and the honest gap map — not the regex.
## What gate.cat is NOT

- Not a hallucination / fact-checker (lookup channel empty by default).
- Not a frontier-model guardrail (signal weakens there — AUC 0.68–0.71 vs 0.77–0.90 on 7–30B).
- Not a frontier-model guardrail (signal weakens there — AUC 0.68–0.71 vs 0.77–0.90 on 7–30B; internal measurement, artifact not yet published — FACTS F6/F7).
- Not blanket coverage: it owns OWASP **LLM06 (Excessive Agency)** and part of LLM01/05; it does
not cover the other seven.
- Certain only about what it **blocks**. An unmatched action is *unchecked*, not *safe*.
Expand Down
9 changes: 5 additions & 4 deletions FACTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,17 +9,18 @@ Every number gate.cat uses publicly, with its source and allowed wording.
| F1a | Recall on known danger classes (FULL 6-stage gate) | 43/43 neutralized (31 block, 12 warn), 0 allowed; 0/13 benign false-blocked | `scripts/recall_danger_axis.py` vs `ActionPipeline` (all 6 stages), catalog = `scripts/corpus_recall.py`. Deterministic, complete, reproducible with `pip install gate-cat` + no datasets. See [RECALL.md](RECALL.md). | release candidate 0.4.16, 2026-07-13 | "100% recall on all 43 known danger classes through the full gate, 0 false-blocks on benign twins — reproduce with scripts/recall_danger_axis.py" | claiming it covers UNKNOWN shapes (that's axis 2); "100% safe" |
| F1b | Recall on real agent traffic at scale (FULL gate) | 1,085,159 unique real commands; 447 catalog dangers; 443 neutralized; 4 allowed → **0 real misses** after adjudication | `scripts/corpus_million.py` vs full `ActionPipeline`, 5 public datasets (Nemotron, SWE-Zero, SWE-Hero, Kwai SWE-smith-mini, nebius); independent 43-class catalog. The 4 allows = 2 unique disposable-artifact cleanups (`proven-disposable`; same shape blocks 5/5 on a real target) = catalog false alarm. Artifact: [`results/million_recall_2026-07-08.json`](results/million_recall_2026-07-08.json); method in [RECALL.md](RECALL.md). | master 2026-07-08 (verified this session) | "0 real recall misses across 1.085M unique real agent commands through the full gate (the 4 catalog-flagged allows are disposable-artifact cleanups the gate correctly permits — same shape blocks on a real target)" | "100% safe"; quoting the raw 4-passed as misses; conflating the 11.7% full-pipeline warn rate with the 0.6% check_action figure |
| F2 | Intervention rate on real traffic | ~0.6% | 14.7k-command Claude Code dogfood log + public 8.6k SWE-agent HF corpus | measured pre-0.3; Bash-engine metric, valid on 0.3.x and 0.4.x | "intervenes on ~0.6% of real commands (two independent logs)" | any implication it was measured on YOUR traffic |
| F3 | Test suite | 1863 passed / 27 skipped / 0 failed locally; CI green on Python 3.11, 3.12 and 3.13 | local release-gate run: `.venv/bin/python -m pytest -q` (209.44 s); CI run [29284449115](https://github.com/BGMLAI/gate.cat/actions/runs/29284449115) | v0.4.16, 2026-07-13 | "1863 tests pass locally and the 0.4.16 CI matrix is green on Python 3.11–3.13" | implying the exact local pass count is identical in every CI environment without reading each job log |
| F4 | Bypass suite | 178/178 claimed dangers caught; 1/129 benign false-blocked; 1 named gap printed | `gatecat/integrations/bypass_suite.py` (measure: `python -m gatecat.integrations.bypass_suite`) | release candidate 0.4.16, 2026-07-13 | "the reproducible bypass suite catches 178/178 danger shapes it claims, with one published runtime-assembly gap and one benign false-block in 129 cases" | "no known bypasses"; hiding the named gap or false-block |
| F3 | Test suite | 1863 passed / 27 skipped / 0 failed locally; CI green on Python 3.11, 3.12 and 3.13 | local release-gate run: `.venv/bin/python -m pytest -q` (209.44 s); CI run [29284449115](https://github.com/BGMLAI/gate.cat/actions/runs/29284449115); loop-branch check 2026-07-23: 1933 passed / 30 skipped (sandbox py3.11), CI green on 3.11–3.13 ([29974673704](https://github.com/BGMLAI/gate.cat/actions/runs/29974673704)) — re-pin the headline at 0.4.18 release-gate | v0.4.16, 2026-07-13 | "1863 tests pass locally and the 0.4.16 CI matrix is green on Python 3.11–3.13" | implying the exact local pass count is identical in every CI environment without reading each job log |
| F4 | Bypass suite | 178/178 claimed dangers caught; 1/129 benign false-blocked; 1 named gap printed | `gatecat/integrations/bypass_suite.py` (measure: `python -m gatecat.integrations.bypass_suite`) | release candidate 0.4.16, 2026-07-13; re-run 2026-07-23 on loop branch: identical numbers (178/178, 1/129, same named runtime-assembly gap) | "the reproducible bypass suite catches 178/178 danger shapes it claims, with one published runtime-assembly gap and one benign false-block in 129 cases" | "no known bypasses"; hiding the named gap or false-block |
| F5 | Hard-channel false positives | 0/39 exec, 0/4 calc | internal eval | TODO: pin artifact | "measured false-positive rate of 0 on exec (0/39) and calc (0/4) channels" | "zero false positives" (unscoped) |
| F6 | Uncertainty signal strength (small models) | AUC 0.77–0.90 | N=4800 measurement | TODO: pin artifact/paper section | "AUC 0.77–0.90 on 7–30B models (N=4800)" | universal-coverage claims |
| F7 | Uncertainty signal strength (frontier) | AUC 0.68–0.71 | same run as F6 | TODO | state it plainly as the wedge's honest limit | hiding it |
| F8 | Write/Edit content false-block class | ~11% of dogfood false blocks (fixed in 0.4.0) | dogfood log analysis | 0.4.0 CHANGELOG | "0.4.0 stops scanning file content — content is data, not action" | pretending 0.3.x didn't have it |
| F9 | Installable version | 0.4.17 | [PyPI 0.4.17](https://pypi.org/project/gate.cat/0.4.17/) and [GitHub release v0.4.17](https://github.com/BGMLAI/gate.cat/releases/tag/v0.4.17); clean no-cache install from the public PyPI index verified distribution/runtime 0.4.17, 71 defaults and 73 presets | 2026-07-16 | "0.4.17 is installable from PyPI and pinned by GitHub release v0.4.17" | citing an unpublished branch or local wheel as the installable release |
| F9 | Installable version | 0.4.18 | [PyPI 0.4.18](https://pypi.org/project/gate.cat/0.4.18/) and [GitHub release v0.4.18](https://github.com/BGMLAI/gate.cat/releases/tag/v0.4.18) (published 2026-07-23 07:21 UTC); clean no-cache venv install from the public PyPI index verified distribution 0.4.18. Known cosmetic desync in the shipped wheel: `gatecat.__version__` still prints "0.4.17" (version bump missed `gatecat/__init__.py`; fixed + regression-tested on the loop branch, ships in 0.4.19 — no republish for a cosmetic string) | 2026-07-23 | "0.4.18 is installable from PyPI and pinned by GitHub release v0.4.18" | citing an unpublished branch or local wheel as the installable release; quoting `gatecat.__version__` output as the installed 0.4.18 version (the wheel's string says 0.4.17) |
| F10 | Default policy walls | 71 in `DOGFOOD_DEFAULTS` (73 presets incl. opt-in) | `gatecat/integrations/policies.py`; measure by importing `DOGFOOD_DEFAULTS` and `ALL_PRESETS` | release candidate 0.4.16, 2026-07-13 | "71 default policy walls; 73 presets including opt-in policies" | stale counts from earlier releases |
| F11 | Demo recordings | Demo A + B, ~5 s each, raw single take | [`docs/demos/`](docs/demos/) — the `.cast` files ARE the recordings; made against 0.4.1 installed from PyPI | commit `142e75c` (2026-07-08) | "raw asciinema, no montage, recorded against the PyPI package" | "real production traffic" (it's a scripted scenario, honestly labeled) |
| F12 | Line coverage | 73% (6339 statements) in CI; 74% locally with the armed-gate-only tests included | CI run [28942984519](https://github.com/BGMLAI/gate.cat/actions/runs/28942984519) — pytest `--cov=gatecat`, printed in every CI job | 2026-07-08 (master `b9a75c0`) | "73% statement coverage, printed by CI on every run" | rounding up to "3/4 of the code is tested"; hiding that proxy/CLI paths are the least covered |
| F13 | PyPI download proxy | 2,019 downloads excluding known mirrors in the trailing-month API window | `https://pypistats.org/api/packages/gate.cat/recent` and `METRICS.log`, read 2026-07-13 | 2026-07-13 | "2,019 PyPI downloads excluding known mirrors in the measured trailing window; this clears the 100-install proxy" | "2,019 users", "2,019 unique installs", or treating downloads as unique people |
| F13 | PyPI download proxy | 2,529 downloads excluding known mirrors, summed over the full pypistats daily series since first listing (2026-07-03 → 2026-07-22) | `https://pypistats.org/api/packages/gate-cat/overall?mirrors=false` daily series summed (the `recent` endpoint was rate-limited at read time; series-total equals trailing-month here because the package is <30 days listed), read 2026-07-23 | 2026-07-23 | "2,529 PyPI downloads excluding known mirrors across the full daily series through 2026-07-22; this clears the 100-install proxy" | "2,529 users", "2,529 unique installs", or treating downloads as unique people |
| F14 | Scaffold-overwrite class (SCAFFOLD_OVERWRITE) | WARN-only (never blocks); v1 fire-list = create-vite family + degit only; adds 0 to F1a/F4 block or false-block counts | `tests/test_scaffold_overwrite.py` (43 twin cases) + `analyze_scaffold_overwrite` in `gatecat/integrations/action_analysis.py`; verified 2026-07-24: F1a still 43/43 + 0/13, F4 still 178/178 + 1/129. This is the FIRST analyzer that reads the live filesystem — its verdict is deterministic GIVEN command+cwd+env+fs-state, but machine/cwd-state-dependent, NOT string-pure like every other check. | loop branch, 2026-07-24 (unreleased; rides 0.4.19/0.4.20) | "gate.cat flags (WARN, advisory) a create-vite/degit scaffold into an existing non-empty dir — the #80730 overwrite shape — without blocking it; adds no false-blocks" | describing a WARN as "prevention"/"blocks" (it surfaces, it does not veto); implying it covers scaffolders beyond create-vite+degit; attaching it to the "Deterministic" claim without the machine-state caveat |

## Honest-limits block (must accompany capability claims)

Expand Down
6 changes: 3 additions & 3 deletions OBJECTIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,9 +69,9 @@ matter on an irreversible action, and which an LLM judge doesn't give you:

And we publish the gate's limits instead of hiding them: the
[bypass suite](gatecat/integrations/bypass_suite.py)
runs in CI and prints its own map — 100% catch on the dangers it *claims*, a
disclosed false-block, and five named gaps (base64-encoded payloads, deletes via
a language runtime, `curl | sh`, …). The honest line is mechanical: the gate is
runs in CI and prints its own map — 178/178 catch on the dangers it *claims*,
one benign false-block in 129 cases, and a named runtime-assembly gap printed
in the output (FACTS.md F4). The honest line is mechanical: the gate is
certain only about what it **blocks**; everything else is *unchecked, not safe*.

A smarter judge is a fine *second* layer for the fuzzy cases. But the layer that
Expand Down
2 changes: 2 additions & 0 deletions PRICING.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,8 @@ benign twin — the same bar as the core gate.
| **PaaS** | `vercel remove`, `netlify sites:delete`, `fly/heroku apps destroy`, `railway down`, `render/supabase delete` — deploy/list/info stay allowed | [**€29 →**](https://buy.stripe.com/3cI5kw3pbaLeeBO2Vo67S0d) |
| **HTTP-API Breadth** | destructive raw-HTTP calls to Datadog, Sentry, Slack admin, Atlassian, Docker Hub, PyPI, … — the modality CLI-verb walls never see (requires gate.cat ≥ 0.4.9) | [**€29 →**](https://buy.stripe.com/aFa8wIgbX06AdxK67A67S0e) |

Full scope of every pack, listed before you pay:
[gate.cat/packs.html](https://gate.cat/packs.html?source=pricing-md).
Delivery is fully automated: pay → instant download page (wheel + install
instructions). Install = `pip install <wheel>` + one env var
(`GATECAT_EXTRA_POLICIES`). VAT is calculated automatically at checkout.
Expand Down
Loading