logicsrc/docs
Anthony Ettinger dde596b276
OpenErrand reference runner: @logicsrc/openerrand and logicsrc errand (#228)
* OpenErrand 0.1: an errand on a website with no API, with the human steps kept human

docs/openerrand.md mints OpenErrand: one JSON file per errand (register an
account, download a transcript) naming the site, the inputs with a
sensitivity class and ordered sources (document, vault, prompt, generate,
derive, candidate, literal), field rules matched by id then label, page and
wait steps, five human gates a runner never performs (declare,
identity-proofing, code, mail, captcha), outcomes, the never-retried shared
secret, vault and download outputs, hand-off cards that may name only public
inputs, the publisher index at /.well-known/openerrand.json, and thirteen
runner rules. The worked example is the MyFTB business registration that
cli-tools `ftb` performs (profullstack/cli-tools#125), with no personal data.

- @logicsrc/schemas: openerrand + openerrand-index schemas and fixtures
- @logicsrc/validators: semantic checks (references, templates, no personal
  or secret input on a card) and tests that validate the spec's own examples
- logicsrc-web: registry entry (process family), /openerrand landing page,
  the example and the index served as static files, contract tests

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* OpenErrand: hand-off cards stay on the surface that owns the data

Anthony's ruling: tax and finance data never touches a social or promotion
tool, and nothing is sent to a CPA or preparer.

- Hand-off cards are delivered only on the surface that owns the errand's
  data (for a tax or finance errand, the principal's finance app through its
  CLI, PWA, MCP server or API, such as CoinPay, or the runner's terminal),
  never a social, promotion or third-party posting service, and never to
  anyone but the principal. A card for an errand with personal or secret
  inputs does not leave that surface. Runner rule 9 says the same.
- The run record and the sample run name the card by an opaque id
  (pin-letter/7f3k2q) instead of a mynaposter.com URL; the myna mention is gone.
- `principal: represented` no longer cites a preparer with a power of attorney.
- The FTB card's last step no longer suggests sending the PIN to someone else.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* OpenErrand: user-agent rule, captcha solver policy, reference runner note

Anthony's answers on #227 ("go with your recommendations"):

- Rule 11: a runner may run headless with a normal desktop browser user agent
  (dropping HeadlessChrome) and nothing more: no fingerprint spoofing beyond
  the UA string, no stealth plugins, no solving or evading a bot challenge.
  A challenge the browser completes itself is a wait step; any other is a
  captcha gate.
- Captcha solvers: new site.sector and captcha step `solver`
  (forbidden by default | allowed). Never allowed on government, tax,
  financial, healthcare or identity-provider sites, nor on any errand with a
  declare or identity-proofing step or a secret input; elsewhere only when the
  file says so, with every use logged. The validator rejects `allowed` in the
  forbidden set or without a stated sector; six new tests. The FTB example
  states sector "tax".
- Reference runner: @logicsrc/openerrand / `logicsrc errand run`, marked in
  progress; ftb stays the runner the example was taken from.
- Name stays OpenErrand; family stays Agents and process.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* OpenErrand reference runner: @logicsrc/openerrand and logicsrc errand

Ship the runner docs/openerrand.md promised. `logicsrc errand run <file>`
reads an OpenErrand 0.1 file, validates it with @logicsrc/validators, and
drives headless Chrome through it under the spec's thirteen rules;
`errand validate` shows what a file will ask of you and `errand status`
shows the last run of each errand, its card and any lockout.

The engine is generalised from cli-tools `ftb` (PR #125) with no dependency
on cli-tools: the CDP client and Chrome finder from wcag.ts, the page reader,
native-setter fill and forward-button picker from ftb-run.ts, and the rule
matcher, throttle and outcome logic from ftb.ts, all now driven by the file.

- Inputs: document (an extractor hook; the one shipped runs a local command
  that reads JSON requests and prints records), vault (teams or OpenCreds),
  prompt (no echo for secrets), generate, derive, candidate, literal.
  `--input name=value` wins. Shared-secret candidates are ranked as the spec
  says, one is submitted, and a rejection lists the others for --candidate.
- Rules: id before label, step rules first, choices before text, an id match
  final, an unmatched required field stops the run naming it.
- Gates: declare only with --declare after the values are shown; identity
  proofing never touched (URL only) and handed over or stopped on; code from
  the terminal or a code file, used once, a wrong code waits for the next;
  mail ends the run waiting with the card; captcha is the person's, and a
  CaptchaSolver interface is called only where the spec permits (no solver is
  bundled); wait steps are polled, never solved.
- Throttle: 2 runs per errand and account in 30 minutes, 4 a day, 2 minutes
  between runs on a site, lockouts from metadata.lockout or a default, held
  per site and account, never lifted by --force.
- Outputs: credentials written before success to a teams vault by pull,
  merge, push (metadata.vault or --vault), else a 0600 file said aloud;
  downloads type-checked and never overwritten with different bytes; cards
  only in the local run record.
- The user agent is Chrome's own with HeadlessChrome replaced, given at
  launch: a CDP override did not reach a navigation the page's own script
  started, which is exactly the proof-of-work interstitial case.

Tests: 85 in the package (rule engine, inputs, gates, throttle, outcomes,
captcha gating, vaults, outputs, commands) including an integration test
that runs the published FTB example unchanged in real headless Chrome
against a local HTTPS fake site (Chrome maps webapp.ftb.ca.gov to it and
every other host to NOTFOUND; all data fictional), and 2 in the CLI.

CLI 0.6.0 -> 0.7.0; @logicsrc/schemas and @logicsrc/validators 0.3.0 ->
0.4.0 (the OpenErrand schemas, and the vocabularies now exported for
runners); PRD 0009; the spec's Reference runner section and the landing
page say it ships.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 09:17:06 -07:00
..
opencontext Add the LogicSRC OpenContext specification (#132) 2026-08-09 11:46:11 -07:00
opencreds vault + teams: filter secrets by category, export to CSV, simpler help (#195) 2026-09-23 21:08:08 -07:00
openprd Add Tech Stack and Monetization sections to OpenPRD (0.3) (#144) 2026-09-06 16:50:11 -07:00
openskill Add OpenSkill descriptions for human capabilities and OpenProfile discovery 2026-09-13 15:47:58 +00:00
openstream/reports docs: OpenStream benchmark report for nixamp 0.24.2 (#184) 2026-09-13 05:16:24 -07:00
openswarm OpenServer 0.2: the provider says how to install its CLI (#171) 2026-09-12 21:46:01 -07:00
agent-screening.md
agentad-marketplace.md feat(agentad): AgentAd Marketplace PRD + reference exchange (M5) 2026-07-01 10:29:36 +00:00
agentad.md feat(agentad): AgentAd Marketplace PRD + reference exchange (M5) 2026-07-01 10:29:36 +00:00
agentgit.md Add AgentGit M1: agent-native git layer over a Forgejo backend 2026-06-14 15:15:06 +00:00
agentstack.md feat(agentstack): add @logicsrc/agentstack coordination module (#5) 2026-06-10 16:39:32 -07:00
ans-sdk.md docs(ans): spec the @logicsrc/ans TypeScript SDK 2026-06-24 14:41:00 +00:00
arcade.md
asdlc.md Add ASDLC, the Agentic Software Development Lifecycle 2026-09-06 15:02:31 +00:00
cli.md OpenErrand reference runner: @logicsrc/openerrand and logicsrc errand (#228) 2026-10-04 09:17:06 -07:00
communication-accounts.md Ship OpenFleet contracts and the OpenWall draft proposal (#177) 2026-09-13 00:57:45 -07:00
config.md fix(credentials): one vault per user, in the config dir (#119) 2026-07-31 22:53:17 -07:00
credential-sharing.md vault + teams: filter secrets by category, export to CSV, simpler help (#195) 2026-09-23 21:08:08 -07:00
data-model.md Merge master; OpenFleet keeps its name, PR 177's rental descriptor becomes OpenRental 2026-09-13 08:45:33 +00:00
openabtest.md Add OpenABTest draft experiment and accounting contracts (#180) 2026-09-13 02:17:35 -07:00
openaccess.md OpenAccess 0.1: OAuth 2.1 with a grant you can carry (#158) 2026-09-12 12:26:15 -07:00
openaffiliate.md OpenAffiliate 0.1: one file a merchant serves about the commission it pays (#166) 2026-09-12 19:36:59 -07:00
openagent.md Publish OpenAgent profile specification and discovery (#188) 2026-09-13 05:37:59 -07:00
openapi.yaml
openbandwidth.md docs: OpenCPU, OpenMemory, OpenGPU and OpenBandwidth, the resources of a server purchase (#163) 2026-09-12 18:59:05 -07:00
openbroadcast.md docs: OpenBroadcast and OpenGuest, the broadcaster-and-guest framework as OpenProfile.md sections (#168) 2026-09-12 20:30:42 -07:00
opencar.md OpenVehicle is now OpenCar, and scoped to match the name (#214) 2026-09-25 03:22:36 -07:00
openconnection.md OpenConnection: a setup token you paste, a bridge that honours it (#174) 2026-09-12 22:22:39 -07:00
opencontext.md Add the LogicSRC OpenContext specification (#132) 2026-08-09 11:46:11 -07:00
opencoupon.md docs: OpenCoupon and OpenRecipe.md, the first two niche specs (#165) 2026-09-12 19:16:34 -07:00
opencpu.md docs: OpenCPU, OpenMemory, OpenGPU and OpenBandwidth, the resources of a server purchase (#163) 2026-09-12 18:59:05 -07:00
opencreds.md Add the LogicSRC OpenCreds specification (#140) 2026-08-29 04:11:38 -07:00
opendisk.md OpenFile and OpenDisk carry OpenServer 0.2's developer block, and OpenFile names fi1zes.com (#173) 2026-09-12 22:05:06 -07:00
openemoji.md OpenEmoji catalog: every emoji in the reference set, with search and filters (#197) 2026-09-23 21:27:40 -07:00
openerrand.md OpenErrand reference runner: @logicsrc/openerrand and logicsrc errand (#228) 2026-10-04 09:17:06 -07:00
openfile.md OpenFile and OpenDisk carry OpenServer 0.2's developer block, and OpenFile names fi1zes.com (#173) 2026-09-12 22:05:06 -07:00
openfleet.md Publish OpenAgent profile specification and discovery (#188) 2026-09-13 05:37:59 -07:00
opengpu.md docs: OpenCPU, OpenMemory, OpenGPU and OpenBandwidth, the resources of a server purchase (#163) 2026-09-12 18:59:05 -07:00
openguest.md docs: OpenBroadcast and OpenGuest, the broadcaster-and-guest framework as OpenProfile.md sections (#168) 2026-09-12 20:30:42 -07:00
openi18n.md docs: OpenL10n and OpenI18n, the words half and the languages half of OpenFile (#187) 2026-09-13 04:39:59 -07:00
openicon.md OpenIcon: the agentic styles re-render brand marks, and a style says which ground it needs (#211) 2026-09-24 07:24:08 -07:00
openinstall.md OpenInstall 0.1: one idempotent bin/install.sh that puts an app into service (#221) 2026-10-01 03:08:14 -07:00
openjob.md docs: OpenJob and OpenResume.md (#148) 2026-09-08 16:16:05 -07:00
openl10n.md docs: OpenL10n and OpenI18n, the words half and the languages half of OpenFile (#187) 2026-09-13 04:39:59 -07:00
openlisting.md OpenVehicle is now OpenCar, and scoped to match the name (#214) 2026-09-25 03:22:36 -07:00
openmcp.md logicsrc CLI 0.2.0: every LogicSRC tool is a word after logicsrc (#157) 2026-09-12 11:16:40 -07:00
openmemory.md docs: OpenCPU, OpenMemory, OpenGPU and OpenBandwidth, the resources of a server purchase (#163) 2026-09-12 18:59:05 -07:00
openmodel.md OpenModel 0.1: what a model costs, from the provider that bills you (#212) 2026-09-24 11:21:10 -07:00
openobject.md feat(specs): OpenObject and OpenSlice 0.1 (#192) 2026-09-21 03:05:38 -07:00
openontology-governance.md feat(openontology): implement OpenOntology Phase 0 + local engine and CLI (#99) 2026-07-26 02:10:13 -07:00
openontology-interoperability.md feat(openontology): Phase 2 + Phase 3 — storage, REST/SSE, MCP, RDF/SHACL, adapters, TUI, explorer (#101) 2026-07-28 05:10:33 -07:00
openontology.md feat(openontology): Phase 2 + Phase 3 — storage, REST/SSE, MCP, RDF/SHACL, adapters, TUI, explorer (#101) 2026-07-28 05:10:33 -07:00
openprd.md Add Tech Stack and Monetization sections to OpenPRD (0.3) (#144) 2026-09-06 16:50:11 -07:00
openprofile.md Add OpenSkill descriptions for human capabilities and OpenProfile discovery 2026-09-13 15:47:58 +00:00
openproperty.md OpenListing 0.1: one file a seller serves about a thing on offer (#213) 2026-09-25 03:14:19 -07:00
openrecipe.md docs: OpenCoupon and OpenRecipe.md, the first two niche specs (#165) 2026-09-12 19:16:34 -07:00
openrental.md Publish OpenAgent profile specification and discovery (#188) 2026-09-13 05:37:59 -07:00
openresume.md docs: OpenJob and OpenResume.md (#148) 2026-09-08 16:16:05 -07:00
opensaas.md OpenSaaS 0.1: one file a subscription service serves about the way in and the way out (#176) 2026-09-12 22:29:24 -07:00
openserver.md OpenServer 0.2: the provider says how to install its CLI (#171) 2026-09-12 21:46:01 -07:00
opensite.md OpenSite: one record about a page or a site, the card a reader would draw (#175) 2026-09-12 22:30:41 -07:00
openskill.md Add OpenSkill descriptions for human capabilities and OpenProfile discovery 2026-09-13 15:47:58 +00:00
openslice.md feat(specs): OpenObject and OpenSlice 0.1 (#192) 2026-09-21 03:05:38 -07:00
opensong.md Add OpenSong spec: a song as plain-text blocks a generator takes (#194) 2026-09-23 17:33:18 -07:00
openspec-comparison.md feat(agentstack): add @logicsrc/agentstack coordination module (#5) 2026-06-10 16:39:32 -07:00
openstack.md docs: OpenStack.md 0.1, one Markdown file for what a project is built on (#191) 2026-09-21 02:21:12 -07:00
openstream.md docs: OpenStream benchmark reports, published per release (#150) 2026-09-12 06:23:46 -07:00
openswarm.md feat(specs): OpenObject and OpenSlice 0.1 (#192) 2026-09-21 03:05:38 -07:00
openthreat.md docs: OpenThreat, one file a security tool serves about what it found in the open (#167) 2026-09-12 20:30:22 -07:00
opentld.md OpenTLD 0.1: what a domain costs at a registrar, and the TLD record from IANA (#219) 2026-09-25 09:42:12 -07:00
openwall.md Ship OpenFleet contracts and the OpenWall draft proposal (#177) 2026-09-13 00:57:45 -07:00
openwebring.md OpenWebring and OpenWiki carry the whole AI Content Disclosure vocabulary (#190) 2026-09-13 13:14:05 +00:00
openwiki.md OpenWebring and OpenWiki carry the whole AI Content Disclosure vocabulary (#190) 2026-09-13 13:14:05 +00:00
permissions.md
plugins.md Add AgentGit M1: agent-native git layer over a Forgejo backend 2026-06-14 15:15:06 +00:00
positioning.md
roadmap.md
tui.md