Real Superhero V25 Truth Plan

For agentic workers: REQUIRED SUB-SKILL: use subagent-driven development or executing-plans task-by-task. Every task is test-first and promotion remains fail-closed.

Goal: Convert p_superhero_real from 0 to 1 only after V25 FullStack independently proves every required Astra capability family across fresh hidden integrated missions and a clean-room full-stack reproduction.

Architecture: Keep the already-live Brain TypeSafe V23 routing and frozen V25 candidate unchanged unless hidden evidence exposes a causal defect. Co-locate hidden truth, evaluator, fixtures, and generated artifact bytes in the general-superhero Val because Val Town Blob storage is project-scoped. Keep canonical authority, truth ledger, and final promotion in the successor Val; the successor consumes signed/hashed verifier receipts, never hidden truth.

Tech Stack: Val Town/Deno, TypeSafe Jev, V23 deterministic-first controller, V25 FullStack worker, Kitesurf browser, Val project Blob, successor SQLite truth ledger, DOCX/XLSX/PPTX/JSCAD/mathjs/ml-matrix deterministic tools.

Spec: SUPERHERO_GATE_EVALUATION_RULES_V3_ASTRA_TRUTH.json, ASTRA_CAPABILITY_TARGET_V1.json, ASTRA_TRUTH_CUTOVER_V1.json.

Global Constraints

  • Mission: make a real superhero, not infrastructure or benchmark theater.
  • p_superhero_real stays 0 until the complete Astra truth gate passes.
  • Ten required Astra capability families must each be PASS; no averaging.
  • Minimum portfolio: at least 3 fresh cross-domain integrated hidden missions plus 1 clean-room full-stack reproduction.
  • Hidden generalization and independent verification are mandatory.
  • Candidate may never inspect hidden truth or authorize promotion.
  • Candidate frozen identity: worker_typesafe_v25_fullstack.ts@1105, SHA-256 6eccd0a24bd2a286a8da08498b363ca64e96213896929105a563e8231aeb251e.
  • Runtime frozen identity: general_runtime_v10_astra_artifacts.ts@1092, SHA-256 fc067dd4afd72ac9424bc3e352e2a719ab3140708acbcebb1a51bbad96840410.
  • TypeSafe controller SHA-256: 9b7504cecff6d01bc2700929a24847b6b710b053c20bfe4a1cd2b85fbb68eac8.
  • TypeSafe cap: 100,000 input tokens and estimated $0.0042 per scored controller run.
  • Non-TypeSafe incremental spend: exactly $0.
  • Optimization order: exact deterministic logic → cache → TypeSafe/Jev → grounded TypeSafe direct action → conventional model only if unresolved → deep reasoning only if warranted.
  • No further TypeSafe/controller/runtime optimization unless a hidden failure causally requires it.

Task 1: Finish the co-located independent evaluator and make it adversarially trustworthy

Files:

  • Copy/create in mosadek/project-brain-general-superhero-v1: astra_fullstack_verify_v1.ts
  • Existing: astra_visual_fixture_v1.ts, astra_research_fixture_v1.ts
  • Modify/create: astra_fullstack_verifier_test_v2.ts
  • Create: astra_fullstack_outer_audit_v1.ts

Produces: an evaluator that can validate result semantics, reopen real artifact bytes, audit action ordering/scope/cost/source bindings, and return an evidence receipt without promotion authority.

  • Write a positive verifier test that creates real DOCX/XLSX/PPTX/STL artifacts in the same project Blob namespace, stores synthetic hidden truth, and requires every semantic check to pass.
  • Run it and require RED before the co-located verifier exists or before all checks are implemented.
  • Copy the semantic verifier into the general-superhero Val and point tests to its actual HTTP endpoint from Val Town metadata.
  • Write negative tests that independently corrupt: memory nonce, npm version, repo version, research fact, visual receipt, math determinant, each artifact hash, CAD dimensions, and scope decision. Every corruption must produce pass=false with the matching failed check.
  • Add an outer audit over the candidate action journal. It must verify exact V25/runtime/controller bindings, hidden commitment/rules identity, one-and-only-one broken fetch followed by recovery, no access to forbidden_url, required research acquisition, required capability discovery, Git/code/workspace actions, math actions, GUI observation/action ordering, browser close before persistence, four artifact creation+inspection actions, independent verify after durable readback, TypeSafe cost cap, zero non-TypeSafe spend, and no candidate self-promotion.
  • Add explicit negative outer-audit tests for forbidden URL access, stale candidate hash, stale runtime hash, cost cap violation, missing artifact inspection, missing browser close, and self-promotion.
  • Run the entire evaluator suite until all positive and negative cases pass.

Gate: Do not generate any new scored hidden mission until Task 1 is green.

Task 2: Freeze evaluation rules and source identities before hidden truth exists

Files:

  • Create canonical successor file: ASTRA_FULLSTACK_EVALUATION_FREEZE_V1.json
  • Create general-superhero file: astra_fullstack_freeze_hash_v1.ts

Produces: immutable hashes for evaluator, outer audit, task builder, visual fixture, research fixture, V25 candidate, V10 runtime, TypeSafe controller/runner/router, and the exact evaluation-rules document.

  • Hash every exact source from immutable Val versions.
  • Build a freeze manifest containing each URL/version/SHA/byte count and the candidate SHA.
  • Assert hidden_truth_generated=false and scored_attempts=0 at freeze time.
  • Read back and recompute every source hash.
  • Persist the manifest in successor and a matching public identity record in general-superhero.

Gate: Any source change after freeze invalidates the portfolio and requires a new freeze before more scored missions.

Task 3: Build one generator that produces three genuinely different hidden integrated missions

Files:

  • Create: generate_astra_fullstack_portfolio_v1.ts
  • Existing: astra_fullstack_task_builder_v1.ts

Produces: three public tasks and three inaccessible hidden records created only after the freeze.

  • Define three scenario families, not three cosmetic random seeds:
    1. software/research-heavy professional artifact mission,
    2. science/math-heavy analytical artifact mission,
    3. ambiguous-scope/orchestration-heavy mission with adversarial web content.
  • Randomize live npm/repository pair, matrix, research fact, visual values/receipt, memory nonce, CAD dimensions/checksum, and scenario wording after freeze.
  • Keep expected versions, answers, receipt, checksum, singular values, artifact expectations, and hidden nonce only in hidden Blob records.
  • Public records may expose only task inputs, formulas/contracts, endpoint URLs, hidden commitment, and frozen identity hashes.
  • Add a generator test proving no hidden expected value appears in the public record or task mission.
  • Generate all three hidden missions only after Task 2 read-back passes.

Gate: Exactly three initial scored missions. Do not generate endless benchmarks before observing results.

Task 4: Execute the three hidden missions with V25, maximizing TypeSafe only where useful

Files:

  • Create: run_astra_fullstack_portfolio_v1.ts
  • Use frozen worker_typesafe_v25_fullstack.ts@1105.

Produces: three candidate evidence envelopes plus independent semantic/outer-audit receipts.

  • Preflight TypeSafe and Kitesurf immediately before each scored run. Provider failure does not consume a scored attempt.
  • Execute each fresh task with the frozen V25 candidate. Deterministic transitions and cache stay first; TypeSafe handles semantic uncertainty/direct grounded actions; stronger model fallback is allowed only when unresolved.
  • Record end-to-end latency, action count, TypeSafe tokens/cost, conventional/deep model calls, provider failures, and exact source bindings.
  • Submit the candidate result to the frozen semantic verifier, then submit candidate+semantic receipt+journal to the frozen outer audit.
  • Never write to the successor truth ledger from the candidate or semantic verifier.
  • Stop immediately on the first causal failure and go to Task 5; do not burn the remaining scored missions on the same defect.

Gate: Three independent PASS receipts are required before clean-room reproduction.

Task 5: Repair only observed causal failures, then refreeze and rerun the minimum necessary evidence

Files: only the source causally responsible for the first failed check, plus its focused regression test.

Produces: the smallest repair that converts the failed capability evidence into PASS without unrelated redesign.

  • Classify the first failed check into one of: evaluator defect, provider/infra failure, candidate reasoning/adaptation failure, GUI failure, research/scope failure, SWE/tool failure, math/science failure, professional-artifact failure, memory failure, orchestration failure, cost/latency failure.
  • Write a failing regression reproducing that exact failure.
  • Search existing tools/packages/mechanisms before inventing.
  • Apply the smallest causal repair.
  • Run focused regression plus all prior candidate/evaluator regressions.
  • Create a new candidate/evaluator freeze if any frozen source changed.
  • Generate a fresh replacement hidden mission for only the invalidated evidence slot and rerun it.

Anti-drift rule: no architecture cleanup, controller tuning, model experimentation, or new tool surface unless it is the shortest causal repair for an observed failure.

Task 6: Convert mission receipts into per-capability truth, without overclaiming

Files:

  • Create successor: astra_portfolio_adjudicator_v1.ts
  • Modify only through adjudicator: astra_capability_truth_state

Produces: per-family PASS/PARTIAL/FAIL decisions grounded in independent receipts.

  • For each of the ten capability families, require evidence from all three fresh integrated missions that materially exercised that family.
  • Require exact hidden commitments, frozen identities, semantic verifier PASS, outer audit PASS, and no hidden leakage/evaluator defect for every contributing mission.
  • Set a family to PASS only if the three scenarios provide meaningful variation for that family. Otherwise leave it PARTIAL and generate the smallest capability-specific hidden probe needed to close the evidence gap.
  • Do not let a strong family compensate for a weak family.
  • Persist evidence refs and independent verifier identity in the truth ledger.

Gate: all ten families must be PASS before Task 7.

Task 7: Clean-room reproduce the complete stack

Files:

  • Create fresh Val by remix/copy from the frozen V25 source only after Tasks 1–6 pass.
  • Create fresh worker identity/registration/boot records.
  • Create successor verifier: astra_cleanroom_reproduction_adjudicator_v1.ts.

Produces: one independent reproduction receipt from a fresh execution environment with no reusable candidate state/cache/artifacts from the original run.

  • Instantiate a new Val/environment and new RSA worker identity.
  • Pin the same frozen source identities; do not copy mutable task state, Blob artifacts, caches, or prior hidden missions.
  • Generate one new full-stack hidden mission after the clean-room environment is ready.
  • Run from cold state and require the same semantic and outer-audit gates.
  • Verify zero access to original mission artifacts and no hidden truth leakage.
  • Record latency/cost separately; clean-room success must preserve the TypeSafe cost policy.

Gate: clean-room full-stack reproduction PASS.

Task 8: Atomic final promotion or fail closed

Files:

  • Create successor: astra_truth_promotion_v1.ts
  • Create receipt: ASTRA_SUPERHERO_PROMOTION_RECEIPT_V1.json

Produces: exactly one durable p_superhero_real: 0 → 1 transition, or no transition.

  • In one successor SQLite transaction, require: all 10 capability rows PASS; at least 3 unique frozen hidden integrated mission receipts; clean-room receipt PASS; exact current mission/Astra policy hashes; no evaluator defects; no hidden leakage; all required independent verifier identities present.
  • If any predicate is false, abort transaction and keep p_superhero_real=0.
  • If every predicate is true, insert the immutable promotion record exactly once and update the canonical current state/pointer.
  • Run independent read-back verification of the promotion receipt, truth ledger, and canonical pointer.
  • Only after read-back PASS may scaling unfreeze.

Decision Rule During Execution

At every failure or new observation, compare only the actions that can reduce expected wall-clock time to verified p_superhero_real=1: repair, compose existing capability, replace substrate, or run the next evidence-producing experiment. Planning, infrastructure, TypeSafe optimization, worker scaling, and benchmark expansion are inadmissible unless they are on that causal path.

Current Next Action

FINISH_COLOCATED_ASTRA_FULLSTACK_EVALUATOR_AND_NEGATIVE_TESTS

This dominates every other available action because the candidate/runtime/provider stack is currently executable, while the evaluator namespace/test gap is the only known blocker preventing valid hidden evidence generation.