An agent’s day
Give one agent one morning. It needs the --glob flag’s definition from ripgrep, so it reads that one function and not
the 7,700-line file it lives in. It writes a summary with three quotations: two from the function, one of the kind a model
writes when it stops reading. It refuses to ship the summary unasserted, and assert finds the quote that is not in the
source and signs the verdict. It certifies the screenshot it is about to send a vision model. Then it verifies every record
it was handed, shows a tampered copy failing, and reads the issuer’s signed day. Six calls; every receipt and record on
this page re-derived by the generator before it was written.
Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 6 calls · 5,691 ms · list price $0.02 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written
1. Read the function, not the file
One symbol out of 1,088; the whole file would have cost the tokens of a small book.
curl -s -X POST 'https://api.s2ar.dev/v1/sym/read' \
-H "Authorization: Bearer $S2AR_KEY" \
-H 'content-type: application/json' \
-d '{"repo": "BurntSushi/ripgrep", "ref": "14.1.1", "file": "crates/core/flags/defs.rs", "symbol": "Glob as Flag"}'
| tokens_est | 565 |
|---|---|
| receipt.evidence_hash | sha256:598d5e19ec2bace6… |
the answer, as JSON
{
"tokens_est": 565,
"receipt.evidence_hash": "sha256:598d5e19ec2bace68778add369e74f054ca7dc43c2583e0e1e0c4cbefa58a832"
}
The text field:
impl Glob as Flag (crates/core/flags/defs.rs, lines 2459-2512)
2459 impl Flag for Glob {
2460 fn is_switch(&self) -> bool {
2461 false
2462 }
2463 fn name_short(&self) -> Option<u8> {
2464 Some(b'g')
2465 }
2466 fn name_long(&self) -> &'static str {
2467 "glob"
2468 }
2469 fn doc_variable(&self) -> Option<&'static str> {
… 43 more lines
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:598d5e19ec2bace6… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | the whole file is 230911 bytes, about 57,728 tokens; this answer is about 565 tokens: 57,163 tokens kept out of context |
2. Refuse to ship the summary unasserted
The summary carries three quotations. quotes_in_source looks for each of them, verbatim, in the text the agent just read; required_terms and length are the shape. Two quotes are there. The third is the sentence a model writes when it stops reading — the record names it.
curl -s -X POST 'https://api.s2ar.dev/v1/assert' \
-H "Authorization: Bearer $S2AR_KEY" \
-H 'content-type: application/json' \
-d '{"text": "ripgrep's --glob flag is the `impl Flag for Glob` block in crates/core/flags/defs.rs: short name g, long name glob. Its doc says \"Include or exclude file paths.\" and \"This always overrides any other ignore logic.\" On precedence it says \"the first matching glob wins and later ones are ignored\".", "source": "impl Glob as Flag (crates/core/flags/defs.rs, lines 2459-2512)\n 2459\timpl Flag for Glob {\n 2460\t fn is_switch(&self) -> bool {\n 2461\t false\n 2462\t }\n 2463\t fn name_short(&self) -> Option<u8> {\n 2464\t Some(b'g')\n 2465\t }\n 2466\t fn name_long(&self) -> &'static str {\n 2467\t \"glob\"\n 2468\t }\n 2469\t fn doc_variable(&self) -> Option<&'static str> {\n 2470\t Some(\"GLOB\")\n 2471\t }\n 2472\t fn doc_category(&self) -> Category {\n 2473\t Category::Filter\n 2474\t }\n 2475\t fn doc_short(&self) -> &'static str {\n 2476\t r\"Include or exclude file paths.\"\n 2477\t }\n 2478\t fn doc_long(&self) -> &'static str {\n 2479\t r#\"\n 2480\tInclude or exclude files and directories for searching that match the given\n 2481\tglob. This always overrides any other ignore logic. Multiple glob flags may\n 2482\tbe used. Globbing rules match \\fB.gitignore\\fP globs. Precede a glob with a\n 2483\t\\fB!\\fP to exclude it. If multiple globs match a file or directory, the glob\n 2484\tgiven later in the command line takes precedence.\n 2485\t.sp\n 2486\tAs an extension, globs support specifying alternatives:\n 2487\t.BI \"\\-g '\" ab{c,d}* '\n 2488\tis equivalent to\n 2489\t.BI \"\\-g \" \"abc \" \"\\-g \" abd.\n 2490\tEmpty alternatives like\n 2491\t.BI \"\\-g '\" ab{,c} '\n 2492\tare not currently supported. Note that this syntax extension is also currently\n 2493\tenabled in \\fBgitignore\\fP files, even though this syntax isn't supported by\n 2494\tgit itself. ripgrep may disable this syntax extension in gitignore files, but\n 2495\tit will always remain available via the \\flag{glob} flag.\n 2496\t.sp\n 2497\tWhen this flag is set, every file and directory is applied to it to test for\n 2498\ta match. For example, if you only want to search in a particular directory\n 2499\t\\fIfoo\\fP, then\n 2500\t.BI \"\\-g \" foo\n 2501\tis incorrect because \\fIfoo/bar\\fP does not match\n 2502\tthe glob \\fIfoo\\fP. Instead, you should use\n 2503\t.BI \"\\-g '\" foo/** '.\n 2504\t\"#\n 2505\t }\n 2506\t\n 2507\t fn update(&self, v: FlagValue, args: &mut LowArgs) -> anyhow::Result<()> {\n 2508\t let glob = convert::string(v.unwrap_value())?;\n 2509\t args.globs.push(glob);\n 2510\t Ok(())\n 2511\t }\n 2512\t}\n", "checks": [{"check": "quotes_in_source", "min_words": 4}, {"check": "required_terms", "terms": ["defs.rs", "--glob"]}, {"check": "length", "unit": "words", "max": 120}]}'
PARTIAL
| verdict | partial |
|---|---|
| passed | 2 |
| checks | 3 |
| results.0.check | quotes_in_source |
| results.0.ok | false |
| results.0.evidence | {"quotes": 3, "missing": ["the first matching glob wins and later ones are ignored"]} |
| results.1.ok | true |
| results.2.ok | true |
| record_sha256 | 3754515b7150255b… |
the answer, as JSON
{
"verdict": "partial",
"passed": 2,
"checks": 3,
"results.0.check": "quotes_in_source",
"results.0.ok": false,
"results.0.evidence": {
"quotes": 3,
"missing": [
"the first matching glob wins and later ones are ignored"
]
},
"results.1.ok": true,
"results.2.ok": true,
"record_sha256": "3754515b7150255bc42ac96cf7df751f5c37a522f26ced50442abe734673ba9e"
}
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:0680dc3297299d83… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | record 3754515b7150255b… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json) |
| ✓ | as the prose says: verdict = "partial" · passed = 2 · checks = 3 · results.0.evidence.quotes = 3 · results.0.evidence.missing.0 = "the first matching glob wins and later ones are ignored" |
3. Certify the screenshot before sending it
By URL, as a GET: the record names the image by hash (the API returns the record, never pixels), the witness is OCR because the image is text, and the tokens table says what each provider would have billed.
curl -s -X GET 'https://api.s2ar.dev/v1/certify?image_url=https%3A%2F%2Fs2ar.dev%2Fexamples%2Fmedia%2Finvoice.png&probe=ocr' \
-H "Authorization: Bearer $S2AR_KEY"
PASS
| outcome | pass |
|---|---|
| verdict | isomorphic |
| witnesses.0.name | ocr |
| subject.0.w | 1000 |
| subject.0.h | 600 |
| subject.1.w | 524 |
| subject.1.h | 314 |
| subject.1.bytes | 5966 |
| payload.tokens.anthropic | {"provider": "anthropic", "before": 800, "after": 220, "saved": 580, "ratio": 0.725} |
| payload.fidelity | {"drift": 0.0, "tolerance": 0.05, "acuity": 1568} |
| record_sha256 | 924aed0a44f0e675… |
the answer, as JSON
{
"outcome": "pass",
"verdict": "isomorphic",
"witnesses.0.name": "ocr",
"subject.0.w": 1000,
"subject.0.h": 600,
"subject.1.w": 524,
"subject.1.h": 314,
"subject.1.bytes": 5966,
"payload.tokens.anthropic": {
"provider": "anthropic",
"before": 800,
"after": 220,
"saved": 580,
"ratio": 0.725
},
"payload.fidelity": {
"drift": 0.0,
"tolerance": 0.05,
"acuity": 1568
},
"record_sha256": "924aed0a44f0e6754350a2cb7e02c8d640dbfd01057843172ea77259aa31df00"
}
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:a81e30b8ab8145c9… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | record 924aed0a44f0e675… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json) |
| ✓ | as the prose says: outcome = "pass" · verdict = "isomorphic" |
| ✓ | the record names the image by hash: aea08f226ec7ac2a… equals sha256 of media/invoice.png |
4. Verify the assertion record, free
No key, no account: the record is fetched back by hash, its seal recomputed, its signature checked against the issuer’s published key.
curl -s -X GET 'https://api.s2ar.dev/v1/verify/3754515b7150255bc42ac96cf7df751f5c37a522f26ced50442abe734673ba9e'
PARTIAL
| found | true |
|---|---|
| seal_ok | true |
| signature_ok | true |
| key_pinned | true |
| certificate.kind | assertion |
| certificate.verdict | partial |
the answer, as JSON
{
"found": true,
"seal_ok": true,
"signature_ok": true,
"key_pinned": true,
"certificate.kind": "assertion",
"certificate.verdict": "partial"
}
| re-derived by the generator | |
|---|---|
| ✓ | seal recomputed ✓ · signature ✓ · key pinned to assay-1 ✓ |
5. Change one field; watch the seal fail
The one field a cheat would change.
curl -s -X POST 'https://api.s2ar.dev/v1/verify' \
-H 'content-type: application/json' --data-binary @record.json # the record above, with verdict="pass"
PARTIAL
| seal_ok | false |
|---|---|
| signature_ok | null |
the answer, as JSON
{
"seal_ok": false,
"signature_ok": null
}
| re-derived by the generator | |
|---|---|
| ✓ | one changed field and the seal fails: seal_ok: false, the signature is not even consulted |
6. Read the issuer’s signed day
Calls paid, delivered and credited, the rails, the refusals by kind, the charter’s hash, the previous edition’s hash: the issuer’s own account of itself, signed.
curl -s -X GET 'https://api.s2ar.dev/.well-known/proceedings.json'
| period | 2026-10-11 |
|---|---|
| final | false |
| calls | 100 |
| calls_paid | 0 |
| calls_delivered | 100 |
| credited_not_delivered | 0 |
| distinct_payers | 0 |
| charter_sha256 | 5e12a7530c120a82… |
| record_sha256 | f1a8a66f4eb43f10… |
the answer, as JSON
{
"period": "2026-10-11",
"final": false,
"calls": 100,
"calls_paid": 0,
"calls_delivered": 100,
"credited_not_delivered": 0,
"distinct_payers": 0,
"charter_sha256": "5e12a7530c120a823a28ed1e525e9c397328873bc407ca04dd9eb19ced5b5cb8",
"record_sha256": "f1a8a66f4eb43f107067576d4af862f4676e6210475e753911c424f829131b5e"
}
| re-derived by the generator | |
|---|---|
| ✓ | seal re-derived ✓ · signed by assay-1 ✓ |
| ✓ | chain ✓: prior_sha256 equals the 2026-10-10 edition's record_sha256 |
| ✓ | charter ✓: /charter hashes to the charter_sha256 the edition sealed (5e12a7530c12…) |
What varies between runs: the latency, the edition of the proceedings, the record hashes. What cannot vary: the
verdict (partial: two of three checks passing, so nothing ships), the quotation named as missing, the image named by hash, the seal
breaking on one changed field. That is the difference between a tool that answers and a tool that answers with evidence.
What this cannot buy
From the signed proceedings (/.well-known/proceedings.json), verbatim:
- placement or routing position
- a different verdict or grade
- buyer data
- amendment access
- a revocation
Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.