Why this exists
Agentic coding sessions start cold: hundreds of skills and agents, multi-project memory, optional MCP backends, and no deterministic opening move. Teams invent counts, miss dark plugins, trust docs that never shipped, and declare “done” while undecidable gaps hide under green.
intrikata-stack is a portable set of four agent skills: orient a session from verified local files, audit that orientation, measure drift from the last validated envelope toward the Tarski limit, and install the same workflow across supported tools. The public evidence is inspectable, and old evidence is labeled historical.
Four surfaces, one Intrikata system
- Intrikata Stack — this documentation, installer, package, and audit evidence.
- Intrikata Console — per-user provisioning, bootstrap, recovery, and operant control.
- Intrikata Topology — the graph workspace for browsing, editing, analyzing, and exporting connected knowledge.
- AWITS public-proxy — live v3.2 scorer. Published 7/30/90 envelopes and operational occurrence not-occurred under hysteresis 65/70. 37/37 rdgap probes and M/G/S/MGS ASEC materializers are public-proxy implementations, not frontier completion. ASI-TOPOLOGY-OPS score 0.6→1.0 on topology operation. Definitional occurrence remains UNDECIDABLE. Zero necessity weight on attention and direct readiness.
The public names above are canonical. Historical backend namespaces may remain only where compatibility requires them; they are not product labels.
1.7.1 ops surface · 53 traps · megametapraxis loop
Inventory is 53 operational traps. #29–#32 are the route/auth/CSP family; #34–#39 deploy-safety; #40/#42/#47/#48/#50 concurrency; #43/#45/#51 secrets; #52–#53 ASEC dispatch. Snapshot #8 still rolled 35 rows.
Historical 1.6.0 convergence certificate · Candidate-necessary R&D guide · machine receipt · target d7d96f62…d887 · Recovery service · product page
What you get
megapraxis
Session bootstrap: 7 modes, dark-plugin detection, truth-on-disk briefing. Filesystem-fallback is first-class.
metamegapraxis
Meta-auditor: 53 trap probes, compositional phases, bridge integrity, propose/apply, optional multi-lens SwarmInvocation.
megametapraxis
Loop closer: measures drift from the last validated envelope. Distance to the Tarski limit is UNDECIDABLE. Hooks fire every prompt and subagent run.
Tarski honesty
Residuals named (decidable / semi-decidable / undecidable). Never silently absorbed into “complete”.
Bridge flywheel
Recurring reasoning compiles to short-circuits. Novel work still pays full price — residual load-bearing.
Multi-harness
Claude Code, OpenAI Codex, Grok Build, plus AGENTS.md / Cursor / Gemini adapters.
Local realize
Self-realizing cross-OS deploy of the white-paper architecture — skill + realize.py + optional Tier-1 stub.
Live transparency
Public D1 snapshots API + Proven Cycle demo with browser-side PASS/FAIL checks.
Self-realize locally (cross-agent · cross-OS)
Materialize megapraxis + metamegapraxis on this machine for Claude, Codex, and Grok — Windows, macOS, or Linux — without inventing success:
# Windows iwr https://docs.intrikata.com/scripts/realize.py -OutFile realize.py py -3 realize.py --harness all --tier 0 --force # macOS / Linux curl -sL https://docs.intrikata.com/scripts/realize.py -o realize.py python3 realize.py --harness all --tier 0 --force
Skill: praxis-local-realize · optional Tier 1: --tier 1 --backend-dir ./praxis-backend · package 1.7.1 · traces: /trace
Get started in 60 seconds
Pick your harness. Proof of install is the running registry / a real briefing — not “files exist on disk.”
codex plugin marketplace add https://docs.intrikata.com/git/intrikata-stack.git codex plugin add praxis@intrikata-stack
Relaunch Codex once, start a new task, invoke $praxis:megapraxis. Plugin = two instruction skills only (no MCP/hooks/auth).
curl -sL https://docs.intrikata.com/pkg/intrikata-stack-skills.zip -o praxis.zip unzip -q praxis.zip -d intrikata-stack cd intrikata-stack python3 install.py --harness claude
Skills hot-reload next turn. Marketplace/plugin installs still need app restart (trap #2).
# Windows iwr https://docs.intrikata.com/pkg/intrikata-stack-skills.zip -OutFile praxis.zip Expand-Archive -LiteralPath praxis.zip -DestinationPath intrikata-stack -Force Set-Location intrikata-stack py -3 install.py --target "$env:USERPROFILE\.grok\skills"
Verdict: converged-modulo-harness. Missing intrikata-topology MCP is expected. Do not auto-run a 150K-token self-audit swarm on onboard.
git clone https://docs.intrikata.com/git/intrikata-stack.git cd intrikata-stack python3 install.py --harness codex # or claude | grok | all
Documentation map
Technical white paper
Intrikata Stack architecture, 53 traps, three production surfaces, SwarmInvocation, bridges, M/G/S/MGS, security, API, and residuals.
Install guide
Per-OS commands, backend optional path, uninstall notes.
Harness map
How to run the skills outside Claude Code.
Backend contract
Optional graph HTTP contract — stub to full KG server.
Candidate-necessary R&D
Four takeoff pathways, nine ranked gaps, 37 workstreams with live public-proxy probes (37/37 pass). Direct readiness remains unmeasured. Not frontier completion.
AWITS v3.2 — published forecast
7/30/90 public-proxy envelopes are published. Operational occurrence is not-occurred. 37/37 rdgap probes pass as implementations, not frontier AGI. Definitional singularity remains UNDECIDABLE.
llms.txt
Agent-optimized discovery index for this site.
Proven cycle JSON
One real self-audit loop with evidence tiers.
Open source & community
Community kit
- MIT License — free to use, modify, distribute
- CONTRIBUTING.md — MetaMethodology loop, norms, checklist
- Code of Conduct — Contributor Covenant–based
- Security policy — private reporting, safe harbor, residuals
- community.json — machine-readable OSS surface cert
How to contribute
- Clone or unpack the package; install skills locally
- Run
/megapraxisthen/metamegapraxisthen/megametapraxis snapshot - Propose patches as artifacts / PRs with content-anchored evidence
- Never invent counts; name Tarski residuals on “complete” claims
- Rebuild package + validate before publishing distribution surfaces
Canonical distribution is this site (zip + dumb-HTTP git). Keep package version + SwarmInvocation provenance in forks.
Project principles
| Principle | Meaning |
|---|---|
| Truth-on-disk | Unverified claims are dropped, never emitted |
| Content anchors | Evidence by symbol / grep-stable phrase — not line pins |
| Trap roll-call | 53 silent-failure classes with disk/runtime probes |
| Tarski honesty | Undecidables named every audit; no silent defaults |
| Apply is explicit | Meta-audit is read-only until operator says apply |
| Short-circuit ≠ skip residual | Novelty still pays full price |
Who is this for?
- Operators of multi-project agent harnesses who want a warm, honest session open
- Teams shipping agent skills who need silent-failure taxonomy and self-audit
- Researchers and builders studying MetaMethodology / SwarmInvocation provenance
- Anyone who refuses “all green” when the classifier was blind
Named residual (distribution)
There may not be a single public GitHub “stars” upstream for every fork. The zip + site-served git tree are the canonical portable surfaces. Community discovery residual is mitigated by llms.txt, onboard certs, and this homepage — not claimed solved forever.
What this is
Claude Code (and peer harness) sessions start cold: hundreds of installed skills, agents, and MCP servers; memory spanning every project on a machine; no deterministic opening move. The intrikata stack is a skill stack that orients, audits, then measures drift from that audit toward the Tarski limit.
megapraxis — the session bootstrap
megapraxis runs at session start. It detects one of seven modes from the working directory's shape and history, inventories skills/agents/MCP servers, flags silently-broken ("dark") plugins, reads project memory and git state, and emits a short dashboard briefing. Its contract: every line corresponds to a truth on disk — unverified claims are dropped, never emitted; counts that weren't computed render as count-skipped, never as guesses.
| Mode | Fires when |
|---|---|
| hook-auto | SessionStart hook; 3-line kernel briefing, no questions |
| active-project | cwd is a real project (git repo / manifest / memory) |
| container | cwd holds multiple project subdirs |
| picker | 2+ sub-projects recently active — asks which one |
| machine-dashboard | "show all projects" — machine-wide scan |
| cold | no prior context; minimal catalog |
| resume | "pick up where we left off" — replays the last unresolved thread |
metamegapraxis — the meta-auditor
Where megapraxis briefs the session, metamegapraxis briefs megapraxis. It rolls through 53 documented operational traps (each with a disk-verifiable probe), checks the bridge manifest's referential integrity, computes coverage deltas, and — when single-lens auditing isn't enough — dispatches a four-agent audit swarm whose verdicts persist to a knowledge graph. Focus and phase selectors compose in the fixed order audit → diff → swarm → propose → apply; applying changes never implicitly authorizes an expensive swarm dispatch.
megametapraxis — the observational loop
An audit is not closed until a validated envelope exists. megametapraxis diffs live megapraxis/metamegapraxis skill hashes against that envelope on every user prompt, spawn, and agent/subagent stop. Distance to the Tarski undecidability limit is UNDECIDABLE (never a number). Standing core-5 residuals (unknown-unknowns, true-lens-independence, fixed-point-vs-plateau, state-validity-horizon, converged-vs-correct) are named every report. Stop gates fire once on silent converged claims that omit those names (TARSKI-ABSORPTION).
The 53 operational traps
Silent-failure classes learned in production. Live roll-call is on the Live State tab. Full probe semantics: white paper §7.
| # | Trap | One-line signal |
|---|---|---|
| 1 | plugin-manifest-misplaced | manifest at plugin root instead of .claude-plugin/ — plugin silently absent while settings say ON |
| 2 | session-vs-app-restart | new session ≠ new process; plugin configs load only at app launch |
| 3 | user-belief-vs-harness | "it should be registered now" is a hypothesis until the harness confirms it |
| 4 | stdio-works-cc-never-launched | server responds when run manually, but the host never spawned it |
| 5 | http-up-not-stdio-up | HTTP health check green while the stdio MCP sibling is down — separate processes |
| 6 | windows-python-store-stub | bare python resolves to a Store alias that prints an install nag and exits 1 |
| 7 | stale-pyc-shadowing | bytecode mtime ties can shadow a fresh source edit |
| 8 | fabricated-count | a number derived from a truncated listing instead of a real count |
| 9 | heuristic-classification | client-side guesswork silently replacing an auditable server-side contract |
| 10 | fix-violates-feedback | a proposed action contradicting a saved user correction |
| 11 | ghost-warm-slug | directory looks recently active because a memory file was touched, not a session |
| 12 | stale-graph-cache | graph snapshot lagging fresh disk state |
| 13 | new-agent-needs-restart | agent files written mid-session are invisible until app relaunch |
| 14 | marketplace-root-claude-plugin | a marketplace manifest dir misread as a stray plugin — deleting it darkens everything it publishes |
| 15 | mcp-disconnect-mid-session | tool roster shrinks mid-session while the HTTP backend stays up |
| 16 | tmp-on-windows | /tmp/ writes that the next shell can't read back |
| 17 | shell-escape-json-winpath | backslash paths mangled across shell/curl escape layers |
| 18 | claude-md-aspirational-route | docs describe an endpoint the code never shipped — the handler is the truth |
| 19 | bulk-finalize-no-contribution-check | blanket-failing pending work destroys provenance of runs that succeeded |
| 20 | userpromptsubmit-empty-payloads | audit rows persisted before their fields were populated leak forever-pending |
| 21 | settings-dark-harness-resolves | settings say a plugin is off; the runtime dispatches it anyway — the harness wins |
| 22 | malformed-settings-json | one trailing comma silently disables every plugin and hook |
| 23 | while-read-subshell-hang | per-iteration subshells on MSYS stretch a 300ms scan to minutes |
| 24 | stale-head-clean-worktree-deploy | a remembered commit is deployed after another session advanced HEAD |
| 25 | intrikata-local-bridge-session-mismatch | the browser and local bridge use different session ids while both appear healthy |
| 26 | seed-simg-non-converge-without-op-contribution | a non-converged seed emits advice but no persisted assistant contribution |
| 27 | chat-paste-linewrap | a wrapped user-run command executes a secret or flag fragment as a second command |
| 28 | localhost-ipv6-first | Windows resolves localhost over an unbound IPv6 path before the healthy IPv4 listener |
| 29 | cf-pages-browser-only-403 | host/profile-specific 403 with Worker/edge marker present — fail-open to OTP on a clean host; cookieless 200 alone does not close the browser path |
| 30 | pre-worker-custom-host-403 | 403/challenge before Worker (no edge marker) — correlate browser CF-Ray with Security Events; never infer a bot product from the symptom alone |
| 31 | shared-auth-script-cross-subdomain-csp | a shared auth or remediation script works on one subdomain but is absent or blocked by another subdomain's CSP |
| 32 | metareasoning-skips-auth-csp-discriminators | a 403, CSP, or auth verdict is reached before route, marker, script-origin, and subdomain-copy discriminators run |
| 33 | enabled-plugin-skills-absent-from-harness-listing | an enabled skill-bearing plugin is on disk but none of its skills appears in the live harness registry |
| 34 | deploy-pinned-to-non-production-branch | a Pages deploy branch differs from the project's resolved production branch or the canonical hostname does not roll forward |
| 35 | per-project-branch-map-is-non-uniform | sibling projects disagree on which branch is production, so an omitted --branch infers correctly for some and wrongly for others; a deploy that lands right by inference is unverified, not passing |
| 36 | dirty-tree-directory-upload-deploy | directory-upload deploy runs while git status shows files you did not author |
| 37 | migration-ordering-fail-closed | fail-closed guard is live while its remote schema/migration is unapplied |
| 38 | edge-cached-404-mimics-routing-bug | identical sibling routes disagree or flip because of a stale edge 404 |
| 39 | crlf-vs-git-show-false-diff | git status is clean but git show vs the working copy differs on CRLF |
| 40 | concurrent-agent-same-tree | a second agent is editing or committing the same working tree |
| 41 | blocked-cli-probe-as-negative-evidence | a blocked CLI 403/empty body is treated as proof a feature is unsupported |
| 42 | concurrent-agent-deploy-deadlock | #36 and #40 compose: cannot deploy without shipping a peer dirty tree |
| 43 | credential-in-transcript-is-burned | a secret pasted into chat is already compromised; using it is the error |
| 44 | handed-off-command-wrong-shell | agent emits a POSIX one-liner for a PowerShell user, or the reverse |
| 45 | secret-file-trailing-newline | trailing CR/LF is stored in the secret and compares unequal at runtime |
| 46 | new-project-secrets-do-not-carry | new host project returns 200; config bindings travel, dashboard secrets do not |
| 47 | migration-number-collision-manifest-not-renumber | two agents share a migration prefix; renumbering is the wrong fix |
| 48 | duplicate-domain-concept-resolve-by-layer-asymmetry | two implementations of the same concept; resolve by derivability, not authorship |
| 49 | transient-control-plane-failure-and-correct-refusal | empty-bodied API fail then a correct dependent refusal look like two bugs |
| 50 | subagent-fanout-without-disjoint-ownership | N agents on one repo without exclusive file and number assignments |
| 51 | cli-sibling-subcommand-input-assumption | piped input works on a sibling CLI subcommand but this one is interactive-only |
| 52 | discoverable-skill-bypasses-ASEC-MGS-dispatch | skill listing treated as a menu; ASEC M/G/S/MGS dispatch is skipped |
| 53 | continuation-no-blocking-undecidables | resume with decidable work waits instead of firing a SwarmInvocation |
Session recovery (optional Intrikata console)
When a real browser profile gets bare HTTP ERROR 403 on intrikata.com / docs.intrikata.com while probes still return 200, recover on a different host so the OTP token can land:
- Algoblocker Enterprise Recovery (working recovery host)
- Safe console after OTP: intrikata-console-edge.workers.dev
- In-app entry from topology: topology.intrikata.com/recover.html
Never send #intrikata_auth back to a custom host that is already 403ing the profile. Traps #29/#30 name the post-admission vs pre-Worker split; #31 prevents passing probes and repeated shared-policy changes from hiding an asymmetric route.
Verdicts and Tarski honesty
Audit cycles terminate with an explicit verdict — converged, converged-modulo-restart, extend, extend-stable, degrade, cycle-complete-extend-deferred, or INCOMPLETE (with reason). What can't be decided is named, never absorbed: five canonical undecidables (unknown-unknowns, true-lens-independence, fixed-point-vs-plateau, state-validity-horizon, converged-vs-correct) plus observation-class buckets appear in every audit rather than being quietly folded into "all done".
Swarms and the bridge flywheel
When one lens isn't enough — self-audit above all — the stack composes an agent swarm: four reviewers in a pipeline, a coordinator synthesizing a verdict, every contribution persisted to a graph. Recurring reasoning compiles into bridges. The 1.6.0 fingerprint covers canonical skill membership, enabled state, layer assignments, orphan state, and completeness; an unchanged re-audit re-asserts the prior verdict without creating a new invocation. Novelty still pays full price.
Assistant runtime boundary
The optional graph backend can route work through ClaudeCode, CodexCode, or GrokBuild. CodexCode keeps codex exec on the Codex installation's subscription authentication. Only its unavailable-CLI fallback uses the official OpenAI CLI with a child-scoped API key; that fallback does not reconfigure the desktop app, and no secret is included in this package or site.
Onboarding short-circuits
- Codex · cert
- Grok Build · cert — Tier 0 filesystem-fallback; traps #4/#5 N/A unless graph requested
- Technical white paper — full specification
One real cycle, end to end — with receipts
This is not a mock-up. On 2026-07-17 the stack ran its full loop against itself — /megapraxis boot → /metamegapraxis audit → four-agent self-audit swarm → coordinator verdict → fixes applied → this site republished — and every stage left records. This tab replays that cycle and labels each claim by how far you can verify it from here:
- live — your browser re-checks it against this site's own artifacts, right now, below;
- graph — read from the audit knowledge graph at build time, scrubbed (ids become short hashes);
- origin — attested by grepping the origin machine's code at build time; honestly marked as not client-checkable.
The punchline is the loop eating its own cooking: the swarm's CRITICAL finding this cycle was that a fix recorded as "done, pending restart" by the previous cycle had landed in dead code — found because the dispatch tooling failed live during this very cycle's dispatch.