Dev.to AI 🤖 Ai 👁 0 📖 8 min read

Ship Only If the Digest Matches

A ninety-minute spike ships only on local evidence. A remote draft never decides the ship bit. Mismatch the redacted digest, and the spike dies. This note records one hypothesis and one clock. The artifact is a small lo

A ninety-minute spike ships only on local evidence. A remote draft never decides the ship bit. Mismatch the redacted digest, and the spike dies.

This note records one hypothesis and one clock. The artifact is a small local contract gate. You can rerun it without a network call.

The hypothesis

The hypothesis is narrow and easy to falsify. A free host is usable for drafting only after three local checks pass. Those checks are a secret scan, a digest match, and a timeout cap.

Fail one check and the process exits before any socket opens. The time box is ninety minutes from the note's start line. A pass after that minute still counts as a kill.

Late evidence is not evidence for this spike. One contract file is the only allowed input. One ship-or-kill bit closes the spike cleanly here.

Why the clock is the point

Public threads this week argue about retries and model mistakes. Treat those titles as untrusted topic signals only. They do not prove a gate for your repository.

This spike does not rank models against each other. It does not measure tokens, latency, or uptime. It answers whether your prompt contract is stable.

Split the ninety minutes into three fixed blocks. Use twenty minutes to redact and hash the fixture. Use forty minutes to run the harness and read the report.

Use the last thirty minutes to decide and stop. Do not borrow time from the decision block. A longer draft session means the spike already failed.

Stop writing notes when the clock says kill. A second edit after that minute is out of scope. Start a new note if the question changed.

Ship-or-kill rules

Five rules sit in the spike log before any call. A missing rule is a failed spike, not a partial pass. Print the list, then run the local command.

  • A secret scan must return zero pattern hits.
  • The prompt SHA-256 must equal the fixture hash.
  • The declared timeout must be fifteen seconds or less.
  • The report JSON must contain decision and digest.
  • Model text must not overwrite the decision field.

Rule one blocks obvious credentials before a hash. Rule two blocks silent prompt edits after review. Rule three blocks an unbounded wait inside the spike.

Rule four blocks a report you cannot parse later. Rule five blocks a draft that pretends to be authority. All five must pass, or the decision word is kill.

Fixture contract

Keep the checked-in fixture to four fields only. Extra fields would silently become a second hypothesis. Hash the redacted string, not the raw log.

{
  "hypothesis_id": "digest-gate-001",
  "timeout_seconds": 15,
  "redacted_prompt": "Classify this redacted log line: <HOST> returned <CODE>.",
  "expected_sha256": "replace-with-local-hash"
}

Replace live host names with stable placeholders first. Replace customer text before you compute the hash. Leave expected_sha256 empty until the command below runs.

Proposed harness

The harness below is a proposed, unexecuted example. It is not a benchmark and not a production client. Run it on a machine you already control.

#!/usr/bin/env python3
"""Local ship-or-kill gate. Network stays closed until this exits 0."""

import hashlib
import json
import re
import sys
from pathlib import Path

PATTERNS = [
    re.compile(r"(?i)api[_-]?key\s*[:=]\s*\S+"),
    re.compile(r"(?i)bearer\s+[a-z0-9\-._~+/]+=*"),
    re.compile(r"(?i)password\s*[:=]\s*\S+"),
    re.compile(r"sk-[a-zA-Z0-9]{16,}"),
]

def digest(text: str) -> str:
    return hashlib.sha256(text.encode("utf-8")).hexdigest()

def main() -> int:
    fixture = json.loads(Path(sys.argv[1]).read_text(encoding="utf-8"))
    prompt = fixture["redacted_prompt"]
    timeout = int(fixture["timeout_seconds"])
    hits = [p.pattern for p in PATTERNS if p.search(prompt)]
    actual = digest(prompt)
    ok = (
        not hits
        and timeout <= 15
        and actual == fixture["expected_sha256"]
    )
    report = {
        "decision": "ship" if ok else "kill",
        "digest": actual,
        "secret_hits": hits,
        "timeout_seconds": timeout,
        "network_opened": False,
    }
    Path("spike-report.json").write_text(
        json.dumps(report, indent=2) + "\n", encoding="utf-8"
    )
    print(report["decision"], actual)
    return 0 if ok else 2

if __name__ == "__main__":
    raise SystemExit(main())

Exit code zero means the local contract passed. Exit code two means you stop the spike. Do not catch that code and continue outward.

The report schema is part of the contract. The decision field may be only ship or kill. The network_opened flag must stay false in this file.

Commands to record

Compute the digest before you fill the fixture. Paste that hash into expected_sha256 by hand only. Then run the gate and record the exit.

python3 - <<'PY'
import hashlib
text = "Classify this redacted log line: <HOST> returned <CODE>."
print(hashlib.sha256(text.encode("utf-8")).hexdigest())
PY

python3 spike_gate.py contract.json
echo "exit=$?"
test -s spike-report.json
python3 -m json.tool spike-report.json >/dev/null

Write four lines into the spike note immediately. Record the start time in UTC on line one. Record the process exit code on line two.

Record the digest and the decision word next. If ninety minutes have elapsed, write kill anyway. Do not extend the clock for a cleaner draft.

The time box is part of the hypothesis. A helper who finishes at minute ninety-one still failed. Archive that note as a kill and stop.

Where a free host fits

Disclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode enters only after the local gate exits zero. The operator describes it as an open-source project.

Operator notes also cite free model access today. The same notes cite a free server option. Those are availability claims, not a sizing sheet.

This draft states no model name and no token quota. This draft states no hardware size and no permanence. Confirm current terms in the official docs first.

Unread terms are a kill, even when the digest matches. Availability language is not a capacity plan here. Use the free server as a draft surface only.

Send the redacted prompt, never the raw log. Store the draft beside the report, not inside it. As of 12 October 2026, re-read the live terms before you rely on them.

A cached screenshot from an older week is not current evidence. Write the terms date beside the four-line clock log. A missing date is the same as unread terms.

After the gate exits zero

Follow the same five steps on every clean run. Skip none of them when the clock is still open. A skipped step turns a ship into a kill.

  1. The local gate writes spike-report.json with network_opened false.
  2. Open a free server session only after exit code zero.
  3. Paste the redacted prompt from the contract file.
  4. Save any draft text as draft-notes.md and nothing else.
  5. Re-run the gate to prove the fixture stayed fixed.

If step two is down, keep the local report. The spike still answered the original hypothesis cleanly. A missing host is data, not a skipped gate.

Failure cases

Three failure cases belong in the design of this gate. Each one maps to a single kill reason. None of them require a remote call to detect.

  • A placeholder was left in the expected hash field.
  • A raw log was pasted where the redacted prompt belongs.
  • A decision word was copied from a model draft.

Failure one means you hashed the wrong string. Failure two means the secret scan should have fired. Failure three means the report schema was ignored.

Fix the fixture, then start a new ninety-minute note. Do not patch the report by hand and call it a ship. Hand-edited decisions are kills in this method too.

Acceptance checks

Run these checks in order on a clean directory. They are the acceptance tests for the harness. They do not require any remote host at all.

  1. A clean placeholder prompt must exit with code zero.
  2. A planted password string must exit with code two.
  3. A timeout of thirty seconds must exit with code two.
  4. A wrong expected hash must exit with code two.
  5. The report file must exist after every single run.

Mark any skipped test as an incomplete spike. Incomplete spikes do not ship, even with a finished draft. Archive the report and stop at the time box.

Compare secret_hits with the planted line you used. An empty hit list on a planted password is a harness bug. Fix the pattern, then restart the ninety-minute clock.

Limits

The scanner is a short deny-list, not a product. A novel token shape can still slip through. Read the prompt by eye before you hash it.

The hash binds bytes, not the sentence meaning. A harmless paraphrase still fails the digest check. That failure is correct for this particular spike.

The timeout field is only a local declaration. It does not prove the remote side will obey. Enforce the same number in any client you add later.

This example never opens a socket on purpose. Add a client only after the report says ship. Until that later point, network_opened must stay false.

Python 3.11 or newer is enough for this file. No third-party package is required to run it. If your image lacks python3, the spike is blocked.

Who should skip this

Skip this spike if you cannot redact the source. Skip it if a named model build must be attested. Skip it if legal review needs a signed benchmark.

Skip it if fixture review needs more than ninety minutes. Skip it when today's free-server terms are unclear. Read the live limit yourself, outside this clock.

Also skip it for live production incident traffic. A live outage is the wrong place to test a digest gate. Use an already redacted sample from a closed ticket.

Evidence to keep

Keep four artifacts next to the hypothesis note. Keep contract.json with the expected hash filled in. Keep spike-report.json produced only by this local harness.

Keep draft-notes.md only if the gate already shipped. Keep a four-line clock log with the decision. None of those files should contain a live credential.

If a secret lands in a file, kill the spike. Delete the file and rotate that secret next. Do not commit the report until the scan is clean.

Close

The conclusion of this spike stays narrow on purpose. A free draft host is optional for the method. A matching digest is mandatory before any paste.

Kill the spike when the contract check fails. Kill it when the ninety-minute clock runs out. Kill it when the current terms were not read.

After a clean gate, a draft surface is optional. Check MonkeyCode's current free-access and free-server notes first. Rerun this harness before you paste any prompt.

📰 Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.