01
01
Private Agent Harness
Jack-friendly reusable profiles plus eight automatic process skill folders for safe deploys, live checks, mail loopback, lean handoffs, security review, private MCP access, Google source research, and optional Claude second opinions.
02
02
SafeTry controls
Read-only defaults, explicit approvals, narrow adapters instead of a generic shell, tenant isolation, retention limits, and a tamper-evident audit chain.
03
03
Verified deploy gate
Checks the public target for an explicit 2xx status, rejects redirects, and optionally requires an expected release marker before reporting success.
04
04
Deterministic site health
Zero-AI HTTP checks remain useful for small valid pages and can require an expected text marker to catch a 200 response serving the wrong site.
05
05
Self-catching email loopback
Exercises the configured sending/routing path and records delivery evidence; it does not claim to prove placement in a provider's inbox tab.
06
06
Cloudflare-native connections
Optional OAuth connectors for the official Cloudflare API, Workers Builds, Bindings, Observability, and Docs MCP services, plus Wrangler-based Worker deployment and secrets.
07
07
Guarded operations
Turnstile, DNS, SPF/DMARC/BIMI, Email Routing, Pages cutovers, cache purge, scoped tokens, and account diagnostics stay dry-run or approval-gated where they write.