Skip to content

Commit f27e91c

Browse files
james tooleclaude
authored andcommitted
add manifesto essay to docs/
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 3be1650 commit f27e91c

3 files changed

Lines changed: 138 additions & 1 deletion

File tree

AGENTGATE_PROJECT_CONTEXT.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -305,6 +305,9 @@ All 56 tests should pass.
305305
50. ✅ v0.2.0 tagged and pushed — Security & Adversarial Hardening release, 48 tests across 5 red team phases, 3 bugs fixed, 1 SSRF vulnerability closed
306306
51. ✅ Identity governance: status field on identities (active/banned), admin ban/unban endpoints (POST /admin/ban-identity, POST /admin/unban-identity) protected by API key, auto-ban after 3 malicious resolutions with security event logging, banned identities rejected at lockBond and executeAction with 403 IDENTITY_BANNED, dashboard shows status column and [BANNED] tag on reputation scores, 5 new tests (53 total)
307307
52. ✅ Prediction market demo: markets table, MarketRecord type, createMarket/resolveMarket service methods, Zod schemas, two REST endpoints (POST /markets, POST /markets/:marketId/resolve), two new MCP tools (7 total), two adapter methods, dashboard shows markets with summary stat and table, 3 market tests (happy path, double-resolution rejection, cross-market isolation), fix: occupied bonds now correctly accept concurrent actions (56 total tests)
308+
53. ✅ MIT License: added LICENSE file (MIT, 2025, James Toole) — repo is now legally open source
309+
54. ✅ GitHub Actions CI: .github/workflows/ci.yml runs npm ci and npm test on every push and PR to main, green checkmark on repo
310+
55. ✅ SSH authentication for GitHub: Ed25519 SSH key linked to GitHub account, remote switched from HTTPS to SSH, resolves workflow scope permission issue with PAT
308311

309312
---
310313

@@ -351,7 +354,7 @@ If one AI tool is unavailable, development should continue using another without
351354
- The project folder is at ~/Desktop/agentgate
352355
- Claude Code is the primary coding tool — James pastes instructions into Claude Code
353356
- Claude Code edits files locally — James must run git push separately to update GitHub
354-
- The GitHub repo name is "agentgate" under the "selfradiance" account
357+
- The GitHub repo name is "agentgate" under the "selfradiance" account — remote uses SSH: git@github.com:selfradiance/agentgate.git
355358
- agent-identity*.json files contain private keys — the wildcard .gitignore pattern covers all of them; never commit any of these files
356359
- Use npm run restart (not just npm run dev) to avoid ghost server processes on port 3000
357360
- James also keeps ChatGPT updated with the latest markdown file as a backup collaborator

README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ AgentGate sits as a deterministic choke point between autonomous agents and exte
1414

1515
> **[Threat Model →](docs/threat-model.md)** — What AgentGate defends against, what it doesn't, and why.
1616
17+
Read the full story: [How I Built AgentGate](docs/manifesto.md)
18+
1719
---
1820

1921
## Quick Integration

docs/manifesto.md

Lines changed: 132 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,132 @@
1+
# I Can't Code. I Built a Security-Critical System Anyway.
2+
3+
I'm 60 years old. I have zero coding experience. Not "I took a class once" zero — I mean I have never written a line of code in my life.
4+
5+
Over the past few weeks, I built AgentGate: a collateralized execution engine for AI agents. It has Ed25519 cryptographic signing. Replay protection with nonce stores. An auto-slash sweeper that punishes expired bonds. A prediction market that settles positions economically. Five phases of red-team adversarial testing. A live deployment with TLS, firewall rules, and process management. Fifty-six tests, all passing. CI on GitHub Actions.
6+
7+
I didn't write any of it. And I architected all of it.
8+
9+
---
10+
11+
## What AgentGate Actually Is
12+
13+
Before I tell you how I built it, let me tell you what it does — because the problem it solves is real.
14+
15+
As AI agents get better, they're going to start doing things in the world: placing trades, making API calls, sending money, negotiating contracts. The systems they interact with were designed for humans, and humans are slow. Humans have friction. That friction was a feature — it kept bad behavior expensive.
16+
17+
AI agents remove that friction. An agent can send a thousand bids in the time it takes a person to type one. Rate limits can cap volume, but they don't make bad actions *costly*. Auth tokens can verify identity, but they don't require skin in the game.
18+
19+
AgentGate fixes this. Before an agent can execute a high-impact action, it has to post a bond — real economic collateral. If the action succeeds, the bond is released. If the agent behaves maliciously, the bond is slashed. It makes bad behavior economically irrational.
20+
21+
That's the thesis. Now here's the part that surprised me.
22+
23+
---
24+
25+
## I'm Not a Coder. I'm an Investor.
26+
27+
I've spent my career analyzing systems. Figuring out where the risk is, where the leverage is, where the misalignment between incentives and outcomes creates opportunity. That's what investors do.
28+
29+
When I looked at the AI agent landscape, I saw a gap: there was no economic accountability layer. Agents could act, but they couldn't be held financially responsible for acting badly. That's a structural problem, and I understood it the way I understand any structural problem — not through code, but through incentives.
30+
31+
The problem was, I couldn't build anything. I could see the architecture in my head — the bond model, the exposure lifecycle, the settlement logic — but I had no way to turn that into software.
32+
33+
Then I started using AI coding agents.
34+
35+
---
36+
37+
## How It Actually Worked
38+
39+
I'm going to be honest about what this looked like, because I think people have a distorted picture of what "building with AI" means.
40+
41+
It was not: "Hey Claude, build me a security system." It was not a weekend project. It was not easy.
42+
43+
It was twelve sessions of patient, methodical work. One baby step at a time. Every step, I'd describe what I wanted in plain English. The AI would make the changes. I'd verify them. If something broke, we'd fix it before moving on. We never skipped ahead. We never took two steps at once.
44+
45+
I started with the simplest possible thing — a single endpoint that accepted a request and returned a response. Then I added identity. Then bonds. Then actions. Then resolution logic. Then the exposure model. Then replay protection. Then the sweeper. Then the dashboard. Then deployment. Then authentication. Then TLS. Then adversarial testing.
46+
47+
Each layer was small enough that I could understand what changed and verify it worked. That constraint was everything. It meant I was never confused about what the system was doing. It meant bugs got caught immediately, not three features later when they'd be impossible to trace.
48+
49+
The AI wrote the code. I decided what to build, in what order, and when something was good enough to move on.
50+
51+
---
52+
53+
## The Multi-AI Thing
54+
55+
Here's something that worked better than I expected: I used multiple AI models as auditors.
56+
57+
My primary coding tool was Claude Code — it made the actual changes to files, ran tests, committed and pushed code. But after every major phase, I'd take a snapshot of the entire project and hand it to a different AI (ChatGPT, in my case) and say: "Audit this. What's wrong? What's missing? What should I do next?"
58+
59+
Then I'd take that audit back to my primary tool and say: "Here's what the other AI found. Do you agree? What should we actually do?"
60+
61+
This created a kind of adversarial collaboration. Neither AI was checking its own work. Neither was invested in defending its earlier decisions. One would build, the other would critique, and I'd make the final call on what to prioritize.
62+
63+
I'm not going to pretend this was some genius innovation. It was common sense. If you're a beginner building something security-sensitive, you want more than one set of eyes on it. The fact that those eyes belong to AI models instead of human engineers is just the reality of my situation.
64+
65+
But it worked. The ChatGPT audits caught real issues — exposed ports, missing auth on endpoints, the need for adversarial test phases that I wouldn't have thought of on my own.
66+
67+
---
68+
69+
## The Red Team Phase
70+
71+
This is the part I'm most proud of, and it's also the part that best illustrates what I mean by "I architected it but didn't code it."
72+
73+
After the core system was working and deployed, I directed a five-phase red team exercise. Twenty attack scenarios across five categories: bond math attacks, sweeper edge cases, replay attacks, SQLite concurrency exploits, and outbound HTTP abuse.
74+
75+
I didn't write the attack code. But I understood what each attack was trying to do, because the attacks map directly to the economic model I designed. Can you over-commit exposure beyond what a bond can cover? Can you double-resolve an action to get your bond back twice? Can you replay a signed request to execute the same action again? Can you redirect an outbound HTTP call to hit an internal service?
76+
77+
Three real bugs got found and fixed. One was a genuine SSRF vulnerability — if an attacker crafted a redirect, they could bypass the outbound HTTP allowlist and hit internal services. That's a serious security hole, and it was found because I insisted on testing for it.
78+
79+
I didn't know the term "SSRF" before this project. But I understood the concept: "what if the system follows a redirect to somewhere it shouldn't go?" That's not a coding question. That's a systems thinking question.
80+
81+
---
82+
83+
## What I Learned About AI-Assisted Building
84+
85+
There are a few things I now believe that I didn't believe before I started.
86+
87+
**The constraint is the product.** The reason AgentGate works isn't that AI is powerful. It's that I imposed brutal constraints on the process: one step at a time, verify before moving on, never skip ahead, always test, always audit. Without those constraints, I'd have had a mess of code that sort of worked and was riddled with bugs I couldn't find. The discipline came from me. The execution came from AI.
88+
89+
**Architecture is not code.** I can't write a for loop. But I can look at a bond model and tell you whether the exposure accounting is sound. I can tell you whether the settlement logic handles edge cases. I can tell you whether the nonce store properly prevents replay attacks. Those are design decisions, and they're separable from implementation. Most software discourse conflates the two. They shouldn't.
90+
91+
**Multiple models are better than one.** Not because any single model is bad, but because a single model checking its own work has the same blindness as a human checking their own work. An external audit — even from another AI — catches things that the builder missed. This is just good practice, whether you're working with humans or machines.
92+
93+
**Beginners have an advantage in one specific way.** Because I don't know how things are "supposed" to be done, I ask very basic questions: "What happens if this fails?" "What if someone tries to do this twice?" "What if the bond expires while an action is still running?" Those questions turned out to be more valuable than technical sophistication. They led directly to the sweeper, the nonce store, and the identity governance system.
94+
95+
---
96+
97+
## What AgentGate Is Now
98+
99+
The technical arc is complete. AgentGate is a working, tested, adversarially hardened prototype that demonstrates economic accountability for AI agents. It has:
100+
101+
- Cryptographic identity with Ed25519 signing
102+
- A reusable bond model with exposure tracking
103+
- Automatic slashing of expired bonds
104+
- Replay protection via nonce stores
105+
- Identity governance with auto-ban logic
106+
- A prediction market that demonstrates multi-party economic settlement
107+
- Outbound HTTP safety rails (allowlist, timeout, size limits, redirect protection)
108+
- Five phases of red-team testing (20 attack scenarios, 3 bugs found and fixed)
109+
- A live dashboard, TLS, CI, and 56 passing tests
110+
111+
It's open source under the MIT license. You can read the code, run it, fork it, extend it. The repo is at [github.com/selfradiance/agentgate](https://github.com/selfradiance/agentgate).
112+
113+
I'm not building a company around it. I'm 60 and I don't want the grind. What I wanted was to prove — to myself, mostly — that the gap between understanding a system and building a system has fundamentally changed. It has.
114+
115+
---
116+
117+
## The Real Point
118+
119+
I said at the top that I can't code. That's still true. If you sat me down in front of an empty file and told me to write a function, I'd stare at it.
120+
121+
But I can tell you what a function should do, verify that it does it, and catch when it doesn't. I can decompose a complex system into layers and decide the order in which they should be built. I can think adversarially about what could go wrong. I can impose discipline on a process that would otherwise produce garbage.
122+
123+
It turns out, those skills have a name. They're called architecture.
124+
125+
I spent decades thinking I was on the wrong side of a wall — that the people who could code were the ones who could build things, and the rest of us could only talk about building things. AI didn't tear down that wall. But it gave me a door.
126+
127+
I walked through it. AgentGate is what's on the other side.
128+
129+
---
130+
131+
*James Toole, March 2026*
132+
*[github.com/selfradiance/agentgate](https://github.com/selfradiance/agentgate)*

0 commit comments

Comments
 (0)