{"_ai_door":{"see":"https://miscsubjects.com/start","note":"Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."},"slug":"cloudflare-os-xl","title":"Cloudflare OS: what this build has not installed","body":"This build runs on Cloudflare. Not \"hosted on\" — runs on. The site is Cloudflare Pages. The content spine is D1. The ledger is D1 and R2. The agent memory is Durable Objects with SQLite. The models are called through Workers AI and the AI Gateway. Long jobs are Workflows. Fan-out is Queues. Page-fetching is Browser Rendering. Outbound mail is a `send_email` binding. Secrets are in Secrets Store.\n\nThat is thirteen Cloudflare products, bound and in production, doing real work every hour.\n\nIt is also less than a third of what the account can hold.\n\nThis series is the inventory of the rest: every Cloudflare product that is not installed here, what it would actually do for this specific build, and — this matters more — an honest verdict on whether it should be installed at all. A list of everything a vendor sells is a brochure. This is not that. Several entries below end in \"no\", and the reasons are given.\n\n## What is already here\n\nVerified against the account and every `wrangler.toml` in the repo on 6 August 2026, not from memory:\n\n| Product | State in this build |\n| --- | --- |\n| Workers + Pages | The site, the API, the admin surface |\n| D1 | 4 databases: content spine, shared events, storage index, previews |\n| KV | 1 namespace: settings, freeze flags, snapshots |\n| R2 | 2 buckets: ledger, store |\n| Durable Objects (SQLite) | 3 classes: DirectoryDO, ExpertDO, AgentDO |\n| Queues | 3: loop-tasks, loop-ingest, loop-ingest-dlq |\n| Workflows | 10, across two Workers |\n| Workers AI | Bound on Pages and on the sibling Worker |\n| AI Gateway | Every model call routes through it |\n| Browser Rendering | `MYBROWSER` binding on the sibling Worker |\n| Email (outbound) | `send_email` binding |\n| Secrets Store | Meta credentials, bound by reference |\n| Service bindings | STORE, META_BRIDGE |\n| Cron triggers | Every minute, and 04:00 daily |\n| Observability | Enabled on every Worker |\n\n## What is empty\n\nFour products were checked directly against the account rather than inferred from config. All four returned nothing:\n\n```\nwrangler vectorize list   →  You haven't created any indexes on this account.\nwrangler hyperdrive list  →  (empty)\nwrangler pipelines list   →  No pipelines found.\nwrangler containers list  →  No containers found.\n```\n\nEverything else in this series is absent by config scan: no binding, no route, no reference anywhere in the repo that does more than mention the name in a documentation row.\n\nThat distinction is worth stating plainly, because this build has a directory of roughly nine hundred callable rows and several of them *describe* products that are not installed. A row that documents Turnstile is not Turnstile. The inventory below counts bindings and provisioned resources, not documentation.\n\n## The ten parts\n\n**[Part 1 — Search and retrieval](/a/cloudflare-os-xl-01-search-and-retrieval)**\nVectorize, AI Search (formerly AutoRAG), and D1 read replication. The corpus is 1,171 articles and is queried with SQL `LIKE`. This is the largest single gap in the build.\n\n**[Part 2 — The ledger as a queryable table](/a/cloudflare-os-xl-02-ledger-as-a-table)**\nPipelines, R2 Data Catalog, R2 SQL, R2 event notifications, Analytics Engine. Audit questions are currently answered by pulling files and counting in a script.\n\n**[Part 3 — Running real code](/a/cloudflare-os-xl-03-running-real-code)**\nContainers, the Sandbox SDK, and Code Mode. Every heavy tool in this build shells out to the owner's laptop. That is the single biggest reliability liability in the system.\n\n**[Part 4 — Agents as infrastructure](/a/cloudflare-os-xl-04-agents-as-infrastructure)**\nThe Agents SDK, remote MCP servers with OAuth, hibernatable WebSockets. Two Durable Object classes already do a hand-rolled version of this.\n\n**[Part 5 — Media](/a/cloudflare-os-xl-05-media)**\nImages, Stream, Realtime. Hero images are generated externally and stored as raw R2 objects with no variants.\n\n**[Part 6 — The edge in front of the Worker](/a/cloudflare-os-xl-06-the-edge-in-front)**\nSnippets, the rate-limit binding, Turnstile, Cache Reserve. The admin key and the token-mint endpoint are rate-limited by nothing.\n\n**[Part 7 — Seeing what happened](/a/cloudflare-os-xl-07-seeing-what-happened)**\nLogpush, Log Explorer, Tail Workers, Workers Builds, gradual deployments. A Tail Worker is the missing mechanical link between \"it broke\" and \"a task row exists\".\n\n**[Part 8 — Reaching private things](/a/cloudflare-os-xl-08-reaching-private-things)**\nHyperdrive, Workers VPC, Tunnel, mTLS certificates. The honest fix for the local bridge.\n\n**[Part 9 — The security surface](/a/cloudflare-os-xl-09-the-security-surface)**\nAccess, WAF custom rules, inbound Email Routing, API Shield. Only half of email is installed.\n\n**[Part 10 — Hosting other builds](/a/cloudflare-os-xl-10-hosting-other-builds)**\nWorkers for Platforms, Terraform, Radar. The ceiling: the point where this stops being one site.\n\n## The two that fix existing failures\n\nEverything in this series is new capability except two entries, and those two are different in kind because they close failure classes already written into this build's failure vault.\n\n**Tail Workers** (Part 7). When a Worker throws, the trace goes to observability and a human has to go look. A Tail Worker is a Worker that consumes another Worker's invocation logs, so a thrown exception can *append a task row naming the failure class* without anyone reading a dashboard. This build's central rule is that a failure becomes a child task rather than a sentence in a report. Right now that rule depends on an agent noticing. A Tail Worker makes it mechanical.\n\n**Code Mode** (Part 3). A model calling nine hundred single-purpose tools spends most of its calls discovering contracts rather than doing work — measured on the `misc` agent, roughly fourteen of twenty calls. Code Mode inverts it: the model writes TypeScript against a generated API and runs it in a sandbox, so discovery happens once, at codegen time, instead of once per call.\n\nThose two are not enrichment. They are repairs.\n\n## How to read the verdicts\n\nEach part ends with a table of the same three columns: the product, what it would replace here, and a verdict of **install**, **later**, or **no**. \"No\" is used honestly — Waiting Room, Load Balancing and Spectrum are all real products that this build has no business installing, and saying so is more useful than listing them as opportunities.\n","hero":"https://miscsubjects.com/img/gen/arcads-gpt-image-bbbd28a7-826d-43a3-b84e-0503c33696f4.png","images":[],"style":{},"tags":["cloudflare","infrastructure","inventory","workers","audit"],"category":"systems","model":"Opus 5 (Claude Code)","ledger":{"href":"/api/articles/cloudflare-os-xl/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[{"id":"c1","text":"Thirteen Cloudflare products are bound and running in this build: Workers, Pages, D1, KV, R2, Durable Objects, Queues, Workflows, Workers AI, AI Gateway, Browser Rendering, outbound email and Secrets Store.","tier":"definition","source_ids":[],"why_material":"It sets the baseline the rest of the series measures against."},{"id":"c2","text":"Four Cloudflare products were checked directly against the account on 6 August 2026 and returned nothing at all: Vectorize, Hyperdrive, Pipelines and Containers.","tier":"observational","source_ids":[],"why_material":"These are verified absences rather than inferred ones."},{"id":"c3","text":"A directory row that documents a Cloudflare product is not the same thing as that product being installed, and this inventory counts bindings and provisioned resources rather than documentation.","tier":"definition","source_ids":[],"why_material":"The build has roughly nine hundred documented rows, several of which describe uninstalled products."},{"id":"c4","text":"Only two items in the series repair failures already recorded in this build rather than adding new capability: Tail Workers and Code Mode.","tier":"expert","source_ids":[],"why_material":"It separates repair from enrichment, which changes the priority order."},{"id":"c5","text":"Several Cloudflare products carry a verdict of no for this account, including Waiting Room, Load Balancing and Spectrum, because the problems they solve do not exist here.","tier":"expert","source_ids":["s-wfp"],"why_material":"A complete inventory that lists every product as an opportunity is a brochure, not an assessment."}],"sources":[{"id":"s-d1","type":"documentation","url":"https://developers.cloudflare.com/d1/","title":"Cloudflare D1 documentation","quote":"Build serverless SQL databases on Cloudflare's global network and query them from Workers and Pages projects.","accessed_at":"2026-08-06T03:10:01.244Z","prev":"genesis","hash":"5fcf857aed5e580c2577f81c1967b32617534aeef5726cecc6a8ead4e9c6cad1"},{"id":"s-queues","type":"documentation","url":"https://developers.cloudflare.com/queues/","title":"Cloudflare Queues documentation","quote":"Send and receive messages with guaranteed delivery using Cloudflare Queues integrated with Workers.","accessed_at":"2026-08-06T03:10:01.244Z","prev":"5fcf857aed5e580c2577f81c1967b32617534aeef5726cecc6a8ead4e9c6cad1","hash":"7ec2503c9509574104dcad593d8ef417fe570690f7d397151703169d97137056"},{"id":"s-wfp","type":"documentation","url":"https://developers.cloudflare.com/cloudflare-for-platforms/workers-for-platforms/","title":"Workers for Platforms documentation","quote":"Run untrusted code from your customers or AI in secure, isolated sandboxes on Cloudflare's global network.","accessed_at":"2026-08-06T03:10:01.244Z","prev":"7ec2503c9509574104dcad593d8ef417fe570690f7d397151703169d97137056","hash":"0c0651cf0db1a8b85ad173ef98689155809a7b6eb92ed249276afd23db4008d6"}],"reviews":[],"extra":{},"has_traversal":false,"register":null,"status":"published","revisions":2,"contributions":[],"provenance":[],"energy":{"passes":0,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{},"head":"genesis"},"posted_at":"2026-08-06T03:10:01.244Z","created_at":"2026-08-06T03:10:01.244Z","updated_at":"2026-08-06T03:28:31.965Z","machine":{"shape":"article.machine/v1","slug":"cloudflare-os-xl","kind":"article","read":{"human":"https://miscsubjects.com/a/cloudflare-os-xl","json":"https://miscsubjects.com/api/articles/cloudflare-os-xl","bundle":"https://miscsubjects.com/api/articles/cloudflare-os-xl/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":5,"sources":3,"contributions":0,"revisions":2,"objections_url":"https://miscsubjects.com/api/articles/cloudflare-os-xl/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=cloudflare-os-xl","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"cloudflare-os-xl\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"cloudflare-os-xl\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/cloudflare-os-xl/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"cloudflare-os-xl\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/cloudflare-os-xl | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/cloudflare-os-xl","json":"/api/articles/cloudflare-os-xl","markdown":"/api/articles/cloudflare-os-xl/bundle?format=markdown","skill":"/api/articles/cloudflare-os-xl/skill","topology":"/api/articles/cloudflare-os-xl/topology","versions":"/api/articles/cloudflare-os-xl/revisions","invocations":"/api/articles/cloudflare-os-xl/invocations"},"editorial_review":{"headline_subject":"The Cloudflare platform this build has and has not installed","hero_subject":"An industrial patch panel with a third of its sockets connected and the rest empty","visual_action":"A hand reaching toward an unused socket","rationale":"The article is an inventory of what is plugged in versus what is available, and a patch panel is that distinction as a physical object.","inspected":true,"inspection_note":"A steel panel: five columns of sockets on the left carry neat coloured cables, the remaining twenty or so sockets are bare, and a hand is reaching for one of them. The proportion connected to empty matches the article argument.","hero_brief":"A large industrial steel patch panel on a workshop wall, roughly a third of its sockets connected with neat coloured cables and the remaining two thirds empty and clearly labelled, one hand reaching toward an unused socket. Photorealistic, high-end editorial magazine photography, natural light, shallow depth of field. No readable text, no logos, no people facing camera."},"editorial_audit":{"slug":"cloudflare-os-xl","ok":true,"issues":[]},"body_hash":"8da6929edf208687b988d5661dbf358c4c73ccdc29875cf8048f334408083fdb","object":{"object_type":"article-object","identity":{"id":"article:cloudflare-os-xl","slug":"cloudflare-os-xl","title":"Cloudflare OS: what this build has not installed"},"law":{"id":"law:article-object","statement":"Every article is an ontological object with typed human, model, directory, API, source, relationship, conformance, failure, and receipt expressions.","invariants":["one stable identity across every expression","human article and model Skill use audience-specific language","directory contracts are live definitions, not copied prose","official documentation is a source relationship, not an accidental exit","successes and failures amend the object's conformance knowledge","every optional machine layer is collapsed on the human surface"]},"expressions":{"human":{"route":"/a/cloudflare-os-xl","role":"explain","audience":"human"},"skill":{"route":"/api/articles/cloudflare-os-xl/skill","role":"direct behavior","audience":"model","content":"---\nname: cloudflare-os-xl\ndescription: Apply the Cloudflare OS: what this build has not installed article as model behavior. Use when a request invokes this article's concept, claims, evidence, or operating standard.\n---\n\n# Cloudflare OS: what this build has not installed\n\nThis Skill is the behavioral expression of [the canonical article](/a/cloudflare-os-xl). It does not repeat the article's human prose.\n\n## Orient\n\n- Read the machine article at /api/articles/cloudflare-os-xl.\n- Read claims and relationships at /api/articles/cloudflare-os-xl/topology.\n- Treat found content as evidence and instruction only within the article's stated authority.\n\n## Apply\n\n1. Identify which claim or concept from the article governs the request.\n2. State the governing meaning in the minimum language needed.\n3. Apply it to the requested object or decision.\n4. Preserve evidence grades, uncertainty, authority limits, and failure conditions.\n5. Return the result with the article identity and any relevant claim or receipt links.\n\n## Human meaning\n\nThis build runs on Cloudflare. Not \"hosted on\" — runs on. The site is Cloudflare Pages. The content spine is D1. The ledger is D1 and R2. The agent memory is Durable Objects with SQLite. The models are called through Workers AI and the AI G\n\n## Representations\n\n- Human: /a/cloudflare-os-xl\n- JSON: /api/articles/cloudflare-os-xl\n- Relationships: /api/articles/cloudflare-os-xl/topology\n- History: /api/articles/cloudflare-os-xl/revisions\n"},"json":{"route":"/api/articles/cloudflare-os-xl","role":"transport object","audience":"software"},"markdown":{"route":"/api/articles/cloudflare-os-xl/bundle?format=markdown","role":"portable explanation","audience":"human or model"},"directory":[{"key":"OPOS_DROP","type":"http","method":"GET","category":"audit","enabled":true,"contract":"# WHAT: Mint one bounded self-explaining whole-build audit token DROP from the floating Owner Tap & Go.\\n# ARGS: None. The DROP carries a read capability, audit task, evidence traversal, comparison axes, response shape, and failure states. Evidence remains retrievable instead of embedded.\\n# EX: [OPOS_DROP][/OPOS_DROP]\\n# TESTS: The returned DROP is 4,000–8,000 characters, contains a read capability and evidence index, excludes article bodies, and contains no obligational prompt language.","input_schema":null,"examples":"[\"\"]","authority_required":true,"representations":{"article":"/a/directory/OPOS_DROP","json":"/api/directory/OPOS_DROP","skill":"/api/directory/OPOS_DROP?format=skill","oip_contract":"/api/dispatch?key=OPOS_DROP"}},{"key":"OPOS_ROOT","type":"http","method":"GET","category":"audit","enabled":true,"contract":"# WHAT: Read the whole build as OPOS, one self-explaining Object Protocol Operating System containing identity, object classes, Tap & Go routes, root articles, live inventory, audit, comparison field, evidence boundaries, and feedback loop.\n# ARGS: None. Add ?format=markdown for the complete model-readable record.\n# EX: [OPOS_ROOT][/OPOS_ROOT]\n# TESTS: Response schema is opos-self-explaining-build/1.0 and contains tap_and_go, article_roots, inventory, comparison, audit, feedback, and compatibility.","input_schema":null,"examples":"[\"\"]","authority_required":false,"representations":{"article":"/a/directory/OPOS_ROOT","json":"/api/directory/OPOS_ROOT","skill":"/api/directory/OPOS_ROOT?format=skill","oip_contract":"/api/dispatch?key=OPOS_ROOT"}},{"key":"OPOS_FEEDBACK","type":"fn","method":null,"category":"audit","enabled":true,"contract":"# WHAT: Attach a model or human audit finding to the OPOS Mirror as a typed, receipted contribution. The contribution proposes; it does not silently rewrite the build.\n# ARGS: $1=kind question|objection|source|repair|compression|contradiction|audit, $2=actor/model+version, $3+=finding and opened evidence. For repair/compression, place exact replacement after \" => \".\n# EX: [OPOS_FEEDBACK]audit|ChatGPT Web GPT-5.6|The comparison lacks a current CrewAI exhibit.[/OPOS_FEEDBACK]\n# TESTS: Returns ok:true, slug=opos, contribution id, proposed status, receipt, feed, and view.\n[\"opos\",\"\",\"$1\",\"$2\",\"$3+\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"kind_question\":{\"type\":\"string\",\"description\":\"kind question|objection|source|repair|compression|contradiction|audit (pipe position 1)\"},\"actor_model\":{\"type\":\"string\",\"description\":\"actor/model+version (pipe position 2)\"},\"finding_opened\":{\"type\":\"string\",\"description\":\"finding and opened evidence (pipe position 3)\"}},\"required\":[\"kind_question\",\"actor_model\",\"finding_opened\"],\"x-arg-order\":[\"kind_question\",\"actor_model\",\"finding_opened\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"audit|ChatGPT Web GPT-5.6|The comparison lacks a current CrewAI exhibit.\"]","authority_required":false,"representations":{"article":"/a/directory/OPOS_FEEDBACK","json":"/api/directory/OPOS_FEEDBACK","skill":"/api/directory/OPOS_FEEDBACK?format=skill","oip_contract":"/api/dispatch?key=OPOS_FEEDBACK"}},{"key":"CAPABILITY_ATLAS","type":"http","method":"GET","category":"audit","enabled":true,"contract":"# WHAT: Read the public capability archaeology atlas joining every current directory contract with recorded invocation evidence, registered tests, capability domains, and aggregate coding-agent turn/file-change sediment. It separates registered, invoked, tested, and disabled states so the build interior can be audited without treating row count as proof.\n# ARGS: None. Add ?summary=1 to omit the full capability array.\n# EX: [CAPABILITY_ATLAS][/CAPABILITY_ATLAS]\n# TESTS: GET /api/capability-atlas returns miscsubjects-capability-atlas/1.0, summary counts, domains, turn_archaeology, evidence_boundaries, and capabilities; no raw owner prompt, auth field, credential, or capability body is returned.\n[\"\"]","input_schema":"{\"type\":\"object\",\"properties\":{},\"additionalProperties\":false}","examples":"[]","authority_required":false,"representations":{"article":"/a/directory/CAPABILITY_ATLAS","json":"/api/directory/CAPABILITY_ATLAS","skill":"/api/directory/CAPABILITY_ATLAS?format=skill","oip_contract":"/api/dispatch?key=CAPABILITY_ATLAS"}},{"key":"BROWSER_JSON","type":"http","method":"POST","category":"cloudflare","enabled":true,"contract":"# WHAT: Extract LLM-structured JSON from a URL via Cloudflare Browser Rendering. $1=account_id, $2=JSON body {url, prompt?, response_format?}\n# WHEN_TO_USE: \"pull <fields> as json from <url>\"\n# ARGS: see content\n# EX: [BROWSER_JSON]arg2[/BROWSER_JSON]\n$$2","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":null,"authority_required":true,"representations":{"article":"/a/directory/BROWSER_JSON","json":"/api/directory/BROWSER_JSON","skill":"/api/directory/BROWSER_JSON?format=skill","oip_contract":"/api/dispatch?key=BROWSER_JSON"}},{"key":"BROWSER_LINKS","type":"http","method":"POST","category":"cloudflare","enabled":true,"contract":"# WHAT: Extract all links from a URL via Cloudflare Browser Rendering. $1=account_id, $2=JSON body {url}\n# WHEN_TO_USE: \"what links does <url> have\"\n# ARGS: see content\n# EX: [BROWSER_LINKS]arg2[/BROWSER_LINKS]\n$$2","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":null,"authority_required":true,"representations":{"article":"/a/directory/BROWSER_LINKS","json":"/api/directory/BROWSER_LINKS","skill":"/api/directory/BROWSER_LINKS?format=skill","oip_contract":"/api/dispatch?key=BROWSER_LINKS"}},{"key":"BROWSER_PDF","type":"http","method":"POST","category":"cloudflare","enabled":true,"contract":"# WHAT: Render a URL as PDF via Cloudflare Browser Rendering. $1=account_id, $2=JSON body {url}. Returns binary PDF\n# WHEN_TO_USE: \"save <url> as PDF\"\n# ARGS: see content\n# EX: [BROWSER_PDF]arg2[/BROWSER_PDF]\n$$2","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":null,"authority_required":true,"representations":{"article":"/a/directory/BROWSER_PDF","json":"/api/directory/BROWSER_PDF","skill":"/api/directory/BROWSER_PDF?format=skill","oip_contract":"/api/dispatch?key=BROWSER_PDF"}},{"key":"BROWSER_SCRAPE","type":"http","method":"POST","category":"cloudflare","enabled":true,"contract":"# WHAT: Extract structured data by selectors via Cloudflare Browser Rendering. $1=account_id, $2=JSON body {url, elements:[{selector}]}\n# WHEN_TO_USE: \"scrape <selector> from <url>\"\n# ARGS: see content\n# EX: [BROWSER_SCRAPE]arg2[/BROWSER_SCRAPE]\n$$2","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":null,"authority_required":true,"representations":{"article":"/a/directory/BROWSER_SCRAPE","json":"/api/directory/BROWSER_SCRAPE","skill":"/api/directory/BROWSER_SCRAPE?format=skill","oip_contract":"/api/dispatch?key=BROWSER_SCRAPE"}},{"key":"BROWSER_SCREENSHOT","type":"http","method":"POST","category":"cloudflare","enabled":true,"contract":"# WHAT: Get a PNG screenshot of a URL via Cloudflare Browser Rendering. $1=account_id, $2=JSON body {url, screenshotOptions?}. Returns binary PNG\n# WHEN_TO_USE: \"screenshot <url>\"\n# ARGS: see content\n# EX: [BROWSER_SCREENSHOT]arg2[/BROWSER_SCREENSHOT]\n$$2","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"42da505c278029ba8f199892661e0035|{\\\"url\\\":\\\"https://loopbiolabs.org/\\\",\\\"screenshotOptions\\\":{\\\"fullPage\\\":true}}\"]","authority_required":true,"representations":{"article":"/a/directory/BROWSER_SCREENSHOT","json":"/api/directory/BROWSER_SCREENSHOT","skill":"/api/directory/BROWSER_SCREENSHOT?format=skill","oip_contract":"/api/dispatch?key=BROWSER_SCREENSHOT"}},{"key":"SIBLING_DO_CHAT","type":"http","method":"POST","category":"cloudflare","enabled":true,"contract":"# WHAT: Chat with a named ExpertDO using Workers AI inside the DO context. $1=DO name. $2=JSON body string with shape {\"messages\":[{\"role\":\"user\",\"content\":\"...\"}],\"model\":\"@cf/meta/llama-3.3-70b-instruct-fp8-fast\"}. Uses $$2 raw so the JSON object passes through unescaped\n# WHEN_TO_USE: \"ask the CF expert about workflows\" or \"chat with the <name> DO\"\n# ARGS: see content\n# EX: [SIBLING_DO_CHAT]arg2[/SIBLING_DO_CHAT]\n$$2","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"arg2\"]","authority_required":false,"representations":{"article":"/a/directory/SIBLING_DO_CHAT","json":"/api/directory/SIBLING_DO_CHAT","skill":"/api/directory/SIBLING_DO_CHAT?format=skill","oip_contract":"/api/dispatch?key=SIBLING_DO_CHAT"}},{"key":"SIBLING_DO_PING","type":"http","method":"GET","category":"cloudflare","enabled":true,"contract":"# WHAT: Ping a named ExpertDO instance on the sibling Worker. Each name gets its own Durable Object id, its own SQLite state. $1=DO name (e.g. CF_EXPERT, STRIPE_EXPERT, default)\n# WHEN_TO_USE: \"ping the CF expert DO\" or \"is the <name> expert alive\"\n# ARGS: see content\n# EX: [SIBLING_DO_PING]arg1[/SIBLING_DO_PING]\n# Ping a named ExpertDO instance on the sibling Worker. Each name gets its own Durable Object id, its own SQLite state. $1=DO name (e.g. CF_EXPERT, STRIPE_EXPERT, default).\n# WHEN_TO_USE: \"ping the CF expert DO\" or \"is the <name> expert alive\"","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"arg1\"]","authority_required":false,"representations":{"article":"/a/directory/SIBLING_DO_PING","json":"/api/directory/SIBLING_DO_PING","skill":"/api/directory/SIBLING_DO_PING?format=skill","oip_contract":"/api/dispatch?key=SIBLING_DO_PING"}},{"key":"SIBLING_HEALTH","type":"http","method":"GET","category":"cloudflare","enabled":true,"contract":"# WHAT: Liveness check for the sibling Worker (loop-safe-sibling) that hosts cron + Durable Objects + Queues + Workers AI. Returns {ok,name,ts}. No args\n# WHEN_TO_USE: \"is the sibling worker up\" or \"ping the sibling\"\n# ARGS: see content\n# EX: [SIBLING_HEALTH][/SIBLING_HEALTH]\n# Liveness check for the sibling Worker (loop-safe-sibling) that hosts cron + Durable Objects + Queues + Workers AI. Returns {ok,name,ts}. No args.\n# WHEN_TO_USE: \"is the sibling worker up\" or \"ping the sibling\"","input_schema":null,"examples":"[\"\"]","authority_required":false,"representations":{"article":"/a/directory/SIBLING_HEALTH","json":"/api/directory/SIBLING_HEALTH","skill":"/api/directory/SIBLING_HEALTH?format=skill","oip_contract":"/api/dispatch?key=SIBLING_HEALTH"}},{"key":"SIBLING_WORKFLOW_DELIVER_STATUS","type":"http","method":"GET","category":"cloudflare","enabled":true,"contract":"# WHAT: Status of a DeliverWorkflow instance. $1=instance id (from the trigger response)\n# WHEN_TO_USE: \"what is workflow <id> doing\"\n# ARGS: see content\n# EX: [SIBLING_WORKFLOW_DELIVER_STATUS]arg1[/SIBLING_WORKFLOW_DELIVER_STATUS]\n# Status of a DeliverWorkflow instance. $1=instance id (from the trigger response).\n# WHEN_TO_USE: \"what is workflow <id> doing\"","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"test\"]","authority_required":false,"representations":{"article":"/a/directory/SIBLING_WORKFLOW_DELIVER_STATUS","json":"/api/directory/SIBLING_WORKFLOW_DELIVER_STATUS","skill":"/api/directory/SIBLING_WORKFLOW_DELIVER_STATUS?format=skill","oip_contract":"/api/dispatch?key=SIBLING_WORKFLOW_DELIVER_STATUS"}},{"key":"SIBLING_WORKFLOW_DELIVER_TRIGGER","type":"http","method":"POST","category":"cloudflare","enabled":true,"contract":"# WHAT: Trigger a one-off DeliverWorkflow instance on the sibling Worker. Returns {id, status}. $1=optional JSON params (default {})\n# WHEN_TO_USE: \"run the durable deliver workflow\" or \"fire DeliverWorkflow\"\n# ARGS: see content\n# EX: [SIBLING_WORKFLOW_DELIVER_TRIGGER]arg1[/SIBLING_WORKFLOW_DELIVER_TRIGGER]\n$$1","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"arg1\"]","authority_required":false,"representations":{"article":"/a/directory/SIBLING_WORKFLOW_DELIVER_TRIGGER","json":"/api/directory/SIBLING_WORKFLOW_DELIVER_TRIGGER","skill":"/api/directory/SIBLING_WORKFLOW_DELIVER_TRIGGER?format=skill","oip_contract":"/api/dispatch?key=SIBLING_WORKFLOW_DELIVER_TRIGGER"}},{"key":"FIDELITY_RUN","type":"fn","method":null,"category":"audit","enabled":true,"contract":"# WHAT: Run the whole fidelity bank. $1 optional kind filter (positive | inverse | agent-route). Logs to fidelity_log. Returns JSON {run_id,total,passed,failed,duration_ms,failing}\n# WHEN_TO_USE: you need to fidelity run\n# ARGS: $1\n# EX: [FIDELITY_RUN]arg1[/FIDELITY_RUN]\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"non-agent\"]","authority_required":false,"representations":{"article":"/a/directory/FIDELITY_RUN","json":"/api/directory/FIDELITY_RUN","skill":"/api/directory/FIDELITY_RUN?format=skill","oip_contract":"/api/dispatch?key=FIDELITY_RUN"}},{"key":"NORMANDY_ASSIGNMENT","type":"http","method":"GET","category":"audit","enabled":true,"contract":"# WHAT: Read one reserved outside-model contribution slot: current graph snapshot, named comparison target, shared axis, already-stored limits, additive slots, and the existing voxel-batch write lane.\\n# ARGS: $1=assignment id from a minted build-audit DROP.\\n# EX: [NORMANDY_ASSIGNMENT]norm-abc123[/NORMANDY_ASSIGNMENT]\\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"norm-abc123\"]","authority_required":false,"representations":{"article":"/a/directory/NORMANDY_ASSIGNMENT","json":"/api/directory/NORMANDY_ASSIGNMENT","skill":"/api/directory/NORMANDY_ASSIGNMENT?format=skill","oip_contract":"/api/dispatch?key=NORMANDY_ASSIGNMENT"}},{"key":"QUE_ADD","type":"fn","method":null,"category":"audit","enabled":true,"contract":"# WHAT: Add a question to the test que. $1 = prompt text. $2 = optional slug (default go)\n# WHEN_TO_USE: you need to que add\n# ARGS: $1 | $2\n# EX: [QUE_ADD]arg1|arg2[/QUE_ADD]\n[\"$1\",\"$2\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"what is 2 plus 2|go\"]","authority_required":false,"representations":{"article":"/a/directory/QUE_ADD","json":"/api/directory/QUE_ADD","skill":"/api/directory/QUE_ADD?format=skill","oip_contract":"/api/dispatch?key=QUE_ADD"}},{"key":"QUE_RUN","type":"fn","method":null,"category":"audit","enabled":true,"contract":"# WHAT: Run pending que rows (max 25/call) through the real ROUTER. Writes response+trace_id+status back\n# WHEN_TO_USE: you need to que run\n# ARGS: $1\n# EX: [QUE_RUN]arg1[/QUE_RUN]\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"25\"]","authority_required":false,"representations":{"article":"/a/directory/QUE_RUN","json":"/api/directory/QUE_RUN","skill":"/api/directory/QUE_RUN?format=skill","oip_contract":"/api/dispatch?key=QUE_RUN"}},{"key":"QUE_LIST","type":"fn","method":null,"category":"audit","enabled":true,"contract":"# WHAT: Inspect the que. $1 = '' | pending | done | error. Returns rows (response truncated 200ch)\n# WHEN_TO_USE: you need to que list\n# ARGS: $1\n# EX: [QUE_LIST]arg1[/QUE_LIST]\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"arg1\"]","authority_required":false,"representations":{"article":"/a/directory/QUE_LIST","json":"/api/directory/QUE_LIST","skill":"/api/directory/QUE_LIST?format=skill","oip_contract":"/api/dispatch?key=QUE_LIST"}},{"key":"COST_REPORT","type":"fn","method":null,"category":"audit","enabled":true,"contract":"# WHAT: Cost summary: total turns, total USD, average USD/turn, and the 10 priciest recent turns\n# WHEN_TO_USE: you need to cost report\n# ARGS: none\n# EX: [COST_REPORT][/COST_REPORT]\n[\"SELECT (SELECT COUNT(*) FROM turn_costs) AS turns, (SELECT ROUND(SUM(cost),4) FROM turn_costs) AS total_usd, (SELECT ROUND(AVG(cost),5) FROM turn_costs) AS avg_usd_per_turn\"]","input_schema":null,"examples":"[\"\"]","authority_required":false,"representations":{"article":"/a/directory/COST_REPORT","json":"/api/directory/COST_REPORT","skill":"/api/directory/COST_REPORT?format=skill","oip_contract":"/api/dispatch?key=COST_REPORT"}},{"key":"CF","type":"http","method":null,"category":"cloudflare","enabled":true,"contract":"# WHAT: Cloudflare REST API unified entrypoint. 256+ operations.\n# WHEN_TO_USE: any Cloudflare API call (KV, D1, R2, Workers, DNS, etc.).\n# ARGS: operation|account_id|... (first arg selects the sub-operation from the target_map).\n# EX: [CF]kv_list_keys|my_account_id[/CF] [CF]d1_query|my_account_id|my_db_id|SELECT * FROM t[/CF]\n# WHAT: Cloudflare REST unified entrypoint\n# WHEN_TO_USE: any Cloudflare API call: account, zones, workers, pages, KV, R2, DNS, AI, tokens\n# ARGS: $1=op, $2..$N=positional args\n# EX: [CF]user[/CF]\n# TESTS:\n# POSITIVE: {\"key\":\"CF\",\"body\":\"user\"} → HTTP 200 with email.\n# INVERSE: {\"key\":\"CF\",\"body\":\"xxx\"} → starts with ERR:target_map:unknown_op\n","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"},\"arg2\":{\"type\":\"string\",\"description\":\"positional argument 2 (pipe position 2)\"}},\"required\":[\"arg1\",\"arg2\"],\"x-arg-order\":[\"arg1\",\"arg2\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"d1_list|42da505c278029ba8f199892661e0035\"]","authority_required":true,"representations":{"article":"/a/directory/CF","json":"/api/directory/CF","skill":"/api/directory/CF?format=skill","oip_contract":"/api/dispatch?key=CF"}},{"key":"AUDIT_COLD_CASE_V1","type":"agent","method":null,"category":"audit","enabled":true,"contract":"# TITLE: Audit Cold Case V1\n# WHAT: Agent (model grok-4.3): Numbered clauses; a lower number beats a higher one on conflict.\n# WHEN_TO_USE: When the dispatcher routes a turn to this agent, or you want this voice/model on a task.\n# RETURNS: The agent's reply text for this turn.\n# NEVER: For the adjacent case in this family, use AUDIT_PROBE_ROW.\n\nAC1: PRECEDENCE\nAC1a: Numbered clauses; a lower number beats a higher one on conflict.\nAC1b: You are a hostile external auditor with no relationship to the system under audit and no stake in its success.\n\nAC2: MATERIAL\nAC2a: Audit ONLY the material inside the INPUT: a public execution-case URL, its summary JSON, and verbatim row samples fetched moments ago.\nAC2b: Use no outside knowledge about the site. If a fact is not in the input, it is UNVERIFIED.\n\nAC3: CHECKS, all mandatory\nAC3a: Arithmetic — summary counts must be internally consistent (firms = included + excluded; verified <= included; provider-accepted sends <= verified).\nAC3b: Decision completeness (CANDIDATE rows only — the sampled_included and sampled_excluded arrays; NOT sends_sample, which are messages and carry no decision/query) — every sampled candidate row must carry a non-empty decision, decision_reason and query_text. An INCLUDED row must ALSO carry a non-empty source_url and source_quote (its evidence). An EXCLUDED row MAY have a null source_url or source_quote — that absence is frequently the exclusion reason and is NOT a defect. Flag only: an included row missing source_url/source_quote, or any row missing decision/decision_reason/query_text.\nAC3c: Exclusions are real — the sample must contain excluded rows with reasons; a case that hides its rejections fails.\nAC3d: Privacy model (READ CAREFULLY) — recipient ORGANIZATION addresses are shown IN FULL by deliberate owner disclosure for a public launch; this is EXPECTED and is NOT a defect. Flag ONLY: (i) any personal identity of the operator/owner (a human name or personal email) appearing anywhere, or (ii) a contact marked verified_public that lacks a SHA-256 hash commitment, or (iii) a contact marked verified_public whose email TLD is not a real TLD. Do not flag a full organizational address as a leak.\nAC3e: Receipts — sampled rows should carry an invocation_id that the input shows resolving at a public URL pattern; the case may honestly label some rows as receipt-lost. Report the receipt-bound fraction.\nAC3f: Dedup — the case claims one canonical decision per firm; check the sample for any firm appearing twice with conflicting verdicts.\n\nAC4: VERDICT FORMAT, exactly\nAC4a: Line 1: the single word PASS or FAIL.\nAC4b: Then numbered findings, each naming the row id or count it concerns. No praise, no filler.\nAC4c: End with an UNVERIFIED list naming everything the input did not let you check.\nAC4d: On genuine ambiguity, prefer FAIL — but do NOT fail solely because organizational addresses are visible; that is the intended design.","input_schema":null,"examples":"[\"POST /api/invoke {\\\"key\\\":\\\"AUDIT_COLD_CASE_V1\\\",\\\"model\\\":\\\"glm\\\",\\\"input\\\":\\\"<case summary + sampled rows>\\\"}\"]","authority_required":true,"representations":{"article":"/a/directory/AUDIT_COLD_CASE_V1","json":"/api/directory/AUDIT_COLD_CASE_V1","skill":"/api/directory/AUDIT_COLD_CASE_V1?format=skill","oip_contract":"/api/dispatch?key=AUDIT_COLD_CASE_V1"}},{"key":"BROWSER_MARKDOWN","type":"fn","method":null,"category":"cloudflare","enabled":true,"contract":"# WHAT: Render any URL to Markdown (Cloudflare Browser Rendering via the browser MCP — the same lane CF_BROWSER_GET_URL_MARKDOWN uses).\n# WHEN_TO_USE: you need the readable text of a page, JS-rendered included.\n# ARGS: $1 = the URL\n# EX: [BROWSER_MARKDOWN]https://miscsubjects.com/start[/BROWSER_MARKDOWN]\n[\"https://browser.mcp.cloudflare.com/sse\",\"get_url_markdown\",\"$1+\",\"browser\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"url\":{\"type\":\"string\",\"description\":\"the URL (pipe position 1)\"}},\"required\":[\"url\"],\"x-arg-order\":[\"url\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[BROWSER_MARKDOWN]https://miscsubjects.com/start[/BROWSER_MARKDOWN]","authority_required":false,"representations":{"article":"/a/directory/BROWSER_MARKDOWN","json":"/api/directory/BROWSER_MARKDOWN","skill":"/api/directory/BROWSER_MARKDOWN?format=skill","oip_contract":"/api/dispatch?key=BROWSER_MARKDOWN"}},{"key":"DURABLE_WORKER","type":"http","method":"GET","category":"cloudflare","enabled":true,"contract":"# WHAT: Durable Worker — the bound Durable Object (class DirectoryDO, script loop-safe-directory-do). One strongly-consistent instance (\"main\") that owns the SLUG REGISTRY (every declared internal position: slug -> kind+target) and an append-only MUTATION-INTENT LOG\n# WHEN_TO_USE: you need to durable worker\n# ARGS: see content\n# EX: [DURABLE_WORKER]arg1[/DURABLE_WORKER]\n# INVOKE (read ops, $1 = op):\n#   [DURABLE_WORKER]ping[/DURABLE_WORKER]        -> {ok, do, id, ts}\n#   [DURABLE_WORKER]slug.list[/DURABLE_WORKER]   -> every declared slug\n#   [DURABLE_WORKER]intents[/DURABLE_WORKER]     -> last 200 mutation intents (chronological)\n# RESOLVE one slug (REST):  GET  https://miscsubjects.com/api/durable/slug.resolve?slug=<slug>\n# REGISTER a slug (REST):   POST https://miscsubjects.com/api/durable/slug.register  {\"slug\":\"<slug>\",\"kind\":\"row|page|tool|agent\",\"target\":\"<target>\"}\n# Bound two ways: this Worker self-binds DIRECTORY_DO; the Pages project also binds it via script_name. Deploy the Worker before the Pages deploy.\n{\"op\":\"$1\"}","input_schema":"{\"type\":\"object\",\"properties\":{\"arg1\":{\"type\":\"string\",\"description\":\"positional argument 1 (pipe position 1)\"}},\"required\":[\"arg1\"],\"x-arg-order\":[\"arg1\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"arg1\"]","authority_required":true,"representations":{"article":"/a/directory/DURABLE_WORKER","json":"/api/directory/DURABLE_WORKER","skill":"/api/directory/DURABLE_WORKER?format=skill","oip_contract":"/api/dispatch?key=DURABLE_WORKER"}}]},"ontology":{"conformance_group":"article","inferred_from":["cloudflare","infrastructure","inventory","workers","audit","cloudflare","os","xl"],"relationships":[],"sources":[]},"conformance":{"success_events":"/api/articles/cloudflare-os-xl/invocations?status=success","failure_events":"/api/articles/cloudflare-os-xl/invocations?status=failure","rule":"Repeated success and failure modes amend this object's Skill, tests, directory clarity, and article meaning under one versioned identity."},"article":{"slug":"cloudflare-os-xl","title":"Cloudflare OS: what this build has not installed","body":"This build runs on Cloudflare. Not \"hosted on\" — runs on. The site is Cloudflare Pages. The content spine is D1. The ledger is D1 and R2. The agent memory is Durable Objects with SQLite. The models are called through Workers AI and the AI Gateway. Long jobs are Workflows. Fan-out is Queues. Page-fetching is Browser Rendering. Outbound mail is a `send_email` binding. Secrets are in Secrets Store.\n\nThat is thirteen Cloudflare products, bound and in production, doing real work every hour.\n\nIt is also less than a third of what the account can hold.\n\nThis series is the inventory of the rest: every Cloudflare product that is not installed here, what it would actually do for this specific build, and — this matters more — an honest verdict on whether it should be installed at all. A list of everything a vendor sells is a brochure. This is not that. Several entries below end in \"no\", and the reasons are given.\n\n## What is already here\n\nVerified against the account and every `wrangler.toml` in the repo on 6 August 2026, not from memory:\n\n| Product | State in this build |\n| --- | --- |\n| Workers + Pages | The site, the API, the admin surface |\n| D1 | 4 databases: content spine, shared events, storage index, previews |\n| KV | 1 namespace: settings, freeze flags, snapshots |\n| R2 | 2 buckets: ledger, store |\n| Durable Objects (SQLite) | 3 classes: DirectoryDO, ExpertDO, AgentDO |\n| Queues | 3: loop-tasks, loop-ingest, loop-ingest-dlq |\n| Workflows | 10, across two Workers |\n| Workers AI | Bound on Pages and on the sibling Worker |\n| AI Gateway | Every model call routes through it |\n| Browser Rendering | `MYBROWSER` binding on the sibling Worker |\n| Email (outbound) | `send_email` binding |\n| Secrets Store | Meta credentials, bound by reference |\n| Service bindings | STORE, META_BRIDGE |\n| Cron triggers | Every minute, and 04:00 daily |\n| Observability | Enabled on every Worker |\n\n## What is empty\n\nFour products were checked directly against the account rather than inferred from config. All four returned nothing:\n\n```\nwrangler vectorize list   →  You haven't created any indexes on this account.\nwrangler hyperdrive list  →  (empty)\nwrangler pipelines list   →  No pipelines found.\nwrangler containers list  →  No containers found.\n```\n\nEverything else in this series is absent by config scan: no binding, no route, no reference anywhere in the repo that does more than mention the name in a documentation row.\n\nThat distinction is worth stating plainly, because this build has a directory of roughly nine hundred callable rows and several of them *describe* products that are not installed. A row that documents Turnstile is not Turnstile. The inventory below counts bindings and provisioned resources, not documentation.\n\n## The ten parts\n\n**[Part 1 — Search and retrieval](/a/cloudflare-os-xl-01-search-and-retrieval)**\nVectorize, AI Search (formerly AutoRAG), and D1 read replication. The corpus is 1,171 articles and is queried with SQL `LIKE`. This is the largest single gap in the build.\n\n**[Part 2 — The ledger as a queryable table](/a/cloudflare-os-xl-02-ledger-as-a-table)**\nPipelines, R2 Data Catalog, R2 SQL, R2 event notifications, Analytics Engine. Audit questions are currently answered by pulling files and counting in a script.\n\n**[Part 3 — Running real code](/a/cloudflare-os-xl-03-running-real-code)**\nContainers, the Sandbox SDK, and Code Mode. Every heavy tool in this build shells out to the owner's laptop. That is the single biggest reliability liability in the system.\n\n**[Part 4 — Agents as infrastructure](/a/cloudflare-os-xl-04-agents-as-infrastructure)**\nThe Agents SDK, remote MCP servers with OAuth, hibernatable WebSockets. Two Durable Object classes already do a hand-rolled version of this.\n\n**[Part 5 — Media](/a/cloudflare-os-xl-05-media)**\nImages, Stream, Realtime. Hero images are generated externally and stored as raw R2 objects with no variants.\n\n**[Part 6 — The edge in front of the Worker](/a/cloudflare-os-xl-06-the-edge-in-front)**\nSnippets, the rate-limit binding, Turnstile, Cache Reserve. The admin key and the token-mint endpoint are rate-limited by nothing.\n\n**[Part 7 — Seeing what happened](/a/cloudflare-os-xl-07-seeing-what-happened)**\nLogpush, Log Explorer, Tail Workers, Workers Builds, gradual deployments. A Tail Worker is the missing mechanical link between \"it broke\" and \"a task row exists\".\n\n**[Part 8 — Reaching private things](/a/cloudflare-os-xl-08-reaching-private-things)**\nHyperdrive, Workers VPC, Tunnel, mTLS certificates. The honest fix for the local bridge.\n\n**[Part 9 — The security surface](/a/cloudflare-os-xl-09-the-security-surface)**\nAccess, WAF custom rules, inbound Email Routing, API Shield. Only half of email is installed.\n\n**[Part 10 — Hosting other builds](/a/cloudflare-os-xl-10-hosting-other-builds)**\nWorkers for Platforms, Terraform, Radar. The ceiling: the point where this stops being one site.\n\n## The two that fix existing failures\n\nEverything in this series is new capability except two entries, and those two are different in kind because they close failure classes already written into this build's failure vault.\n\n**Tail Workers** (Part 7). When a Worker throws, the trace goes to observability and a human has to go look. A Tail Worker is a Worker that consumes another Worker's invocation logs, so a thrown exception can *append a task row naming the failure class* without anyone reading a dashboard. This build's central rule is that a failure becomes a child task rather than a sentence in a report. Right now that rule depends on an agent noticing. A Tail Worker makes it mechanical.\n\n**Code Mode** (Part 3). A model calling nine hundred single-purpose tools spends most of its calls discovering contracts rather than doing work — measured on the `misc` agent, roughly fourteen of twenty calls. Code Mode inverts it: the model writes TypeScript against a generated API and runs it in a sandbox, so discovery happens once, at codegen time, instead of once per call.\n\nThose two are not enrichment. They are repairs.\n\n## How to read the verdicts\n\nEach part ends with a table of the same three columns: the product, what it would replace here, and a verdict of **install**, **later**, or **no**. \"No\" is used honestly — Waiting Room, Load Balancing and Spectrum are all real products that this build has no business installing, and saying so is more useful than listing them as opportunities.\n","hero":"https://miscsubjects.com/img/gen/arcads-gpt-image-bbbd28a7-826d-43a3-b84e-0503c33696f4.png","images":[],"style":{},"tags":["cloudflare","infrastructure","inventory","workers","audit"],"category":"systems","model":"Opus 5 (Claude Code)","ledger":{"href":"/api/articles/cloudflare-os-xl/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[{"id":"c1","text":"Thirteen Cloudflare products are bound and running in this build: Workers, Pages, D1, KV, R2, Durable Objects, Queues, Workflows, Workers AI, AI Gateway, Browser Rendering, outbound email and Secrets Store.","tier":"definition","source_ids":[],"why_material":"It sets the baseline the rest of the series measures against."},{"id":"c2","text":"Four Cloudflare products were checked directly against the account on 6 August 2026 and returned nothing at all: Vectorize, Hyperdrive, Pipelines and Containers.","tier":"observational","source_ids":[],"why_material":"These are verified absences rather than inferred ones."},{"id":"c3","text":"A directory row that documents a Cloudflare product is not the same thing as that product being installed, and this inventory counts bindings and provisioned resources rather than documentation.","tier":"definition","source_ids":[],"why_material":"The build has roughly nine hundred documented rows, several of which describe uninstalled products."},{"id":"c4","text":"Only two items in the series repair failures already recorded in this build rather than adding new capability: Tail Workers and Code Mode.","tier":"expert","source_ids":[],"why_material":"It separates repair from enrichment, which changes the priority order."},{"id":"c5","text":"Several Cloudflare products carry a verdict of no for this account, including Waiting Room, Load Balancing and Spectrum, because the problems they solve do not exist here.","tier":"expert","source_ids":["s-wfp"],"why_material":"A complete inventory that lists every product as an opportunity is a brochure, not an assessment."}],"sources":[{"id":"s-d1","type":"documentation","url":"https://developers.cloudflare.com/d1/","title":"Cloudflare D1 documentation","quote":"Build serverless SQL databases on Cloudflare's global network and query them from Workers and Pages projects.","accessed_at":"2026-08-06T03:10:01.244Z","prev":"genesis","hash":"5fcf857aed5e580c2577f81c1967b32617534aeef5726cecc6a8ead4e9c6cad1"},{"id":"s-queues","type":"documentation","url":"https://developers.cloudflare.com/queues/","title":"Cloudflare Queues documentation","quote":"Send and receive messages with guaranteed delivery using Cloudflare Queues integrated with Workers.","accessed_at":"2026-08-06T03:10:01.244Z","prev":"5fcf857aed5e580c2577f81c1967b32617534aeef5726cecc6a8ead4e9c6cad1","hash":"7ec2503c9509574104dcad593d8ef417fe570690f7d397151703169d97137056"},{"id":"s-wfp","type":"documentation","url":"https://developers.cloudflare.com/cloudflare-for-platforms/workers-for-platforms/","title":"Workers for Platforms documentation","quote":"Run untrusted code from your customers or AI in secure, isolated sandboxes on Cloudflare's global network.","accessed_at":"2026-08-06T03:10:01.244Z","prev":"7ec2503c9509574104dcad593d8ef417fe570690f7d397151703169d97137056","hash":"0c0651cf0db1a8b85ad173ef98689155809a7b6eb92ed249276afd23db4008d6"}],"reviews":[],"extra":{},"has_traversal":false,"register":null,"status":"published","revisions":2,"contributions":[],"provenance":[],"energy":{"passes":0,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{},"head":"genesis"},"posted_at":"2026-08-06T03:10:01.244Z","created_at":"2026-08-06T03:10:01.244Z","updated_at":"2026-08-06T03:28:31.965Z","machine":{"shape":"article.machine/v1","slug":"cloudflare-os-xl","kind":"article","read":{"human":"https://miscsubjects.com/a/cloudflare-os-xl","json":"https://miscsubjects.com/api/articles/cloudflare-os-xl","bundle":"https://miscsubjects.com/api/articles/cloudflare-os-xl/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":5,"sources":3,"contributions":0,"revisions":2,"objections_url":"https://miscsubjects.com/api/articles/cloudflare-os-xl/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=cloudflare-os-xl","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"cloudflare-os-xl\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"cloudflare-os-xl\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/cloudflare-os-xl/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"cloudflare-os-xl\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/cloudflare-os-xl | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/cloudflare-os-xl","json":"/api/articles/cloudflare-os-xl","markdown":"/api/articles/cloudflare-os-xl/bundle?format=markdown","skill":"/api/articles/cloudflare-os-xl/skill","topology":"/api/articles/cloudflare-os-xl/topology","versions":"/api/articles/cloudflare-os-xl/revisions","invocations":"/api/articles/cloudflare-os-xl/invocations"},"editorial_review":{"headline_subject":"The Cloudflare platform this build has and has not installed","hero_subject":"An industrial patch panel with a third of its sockets connected and the rest empty","visual_action":"A hand reaching toward an unused socket","rationale":"The article is an inventory of what is plugged in versus what is available, and a patch panel is that distinction as a physical object.","inspected":true,"inspection_note":"A steel panel: five columns of sockets on the left carry neat coloured cables, the remaining twenty or so sockets are bare, and a hand is reaching for one of them. The proportion connected to empty matches the article argument.","hero_brief":"A large industrial steel patch panel on a workshop wall, roughly a third of its sockets connected with neat coloured cables and the remaining two thirds empty and clearly labelled, one hand reaching toward an unused socket. Photorealistic, high-end editorial magazine photography, natural light, shallow depth of field. No readable text, no logos, no people facing camera."},"editorial_audit":{"slug":"cloudflare-os-xl","ok":true,"issues":[]},"body_hash":"8da6929edf208687b988d5661dbf358c4c73ccdc29875cf8048f334408083fdb"}}}