Re-probed live by FI-008 on this date. This block states only what was observed; it does not replace the hand-audited manifest below, and it deliberately does not advance
last_verified.A-FORGE refuses. A MUTATE-class call without presented authority was stopped by
A_THINK_GUARD(BUDGET: max_tools=0). Tool count re-probed this date: 122 listed, 122 unique fingerprints (forge_registry_status, 2026-10-10T18:26:35Z).Open defects, measured on this host: the invocation-telemetry writer's interface does not accept a governance outcome β a call whose kernel verdict was
HOLD(can_claim_success:false) was persisted asok:trueΒ· the refusal cause (A_THINK_GUARD) appears 0Γ in the ledger Β·sessionGate.ts:315infersverifiedfromverdict === "SEAL"(a verdict string is not identity evidence) Β· default session ids are manufactured with aSEAL-prefix when none is supplied.The executor is gated by action class and budget, not by a
SEALverdict. ASEALlabel collision exists in this codebase and is an open defect.Current revenue value attributable to this component: USD 0.
The execution engine for arifOS β where governed actions become reality.
DITEMPA BUKAN DIBERI β Forged, Not Given.
A-FORGE is the EXECUTION engine of the arifOS Federation (plane: EXECUTION, never governance). It exposes 122 live tools (87 stateless) across five operational domains β code, infrastructure, security, web intelligence, and orchestration β all operating under the arifOS constitutional kernel (:8088 JUDGE_ONLY) that ensures every mutation is authorized, witnessed, and immutably recorded. A-FORGE never adjudicates.
| Capability | Details |
|---|---|
| Task Execution | Filesystem mutations, shell operations, and workflow automation under constitutional authority β every action classified, leased, and receipted |
| CI/CD Pipelines | GitHub Actions workflows for agentic CI, boundary-guard enforcement, governance gates, Dependabot orchestration, and multi-language lock-invariant checks |
| Docker Orchestration | Container fleet management, Compose orchestration, image builds, multi-stage pipelines, and runtime health probes |
| MCP Server Lifecycle | Build, test, deploy, and conformance-validate Model Context Protocol servers with full stateless HTTP transport |
| Code Analysis & Review | LSP-gated mutations, pre-commit review, structural refactoring, PR governance, and release attestation |
| Web Intelligence | Governed URL intake, federated search, SPA-aware extraction, and site-doctor missions β evidence in, provenance out |
| Deployment Automation | Zero-downtime VPS deploys, rsync pipelines, Caddy reverse proxy management, and post-deploy verification crawls |
| Infrastructure Management | systemd service orchestration, port probes, network diagnostics, SOPS-encrypted secrets, and fleet-wide health monitoring |
A-FORGE operates as the executor in a separation-of-powers model. It receives SEAL'd verdicts from the arifOS kernel and produces cryptographically verifiable receipts β it never self-certifies its own work.
ββββββββββββββββ SEAL / HOLD / VOID ββββββββββββββββββββ receipts βββββββββββββ
β arifOS β βββββββββββββββββββββββββββΆ β A-FORGE β ββββββββββββββββΆ β VAULT999 β
β :8088 β (HMAC-SHA256 verified) β :7071 / :7072 β (JSONL chain) β :999 β
β JUDGE β β EXECUTOR β β SEAL β
ββββββββββββββββ ββββββββββ¬ββββββββββ βββββββββββββ
β² β
β evidence β
βββββββββββββββββββββββββββββββββββββββββββββββββ
Every execution passes through four independent gates before touching reality:
Intent ββΆ [Valid Lease?] ββΆ [L1: AMANAH β Secret & Pattern Scan]
ββ FAIL β DENIED
ββΆ [L2: Identity β Model Capability & Band Check]
ββ FAIL β DEGRADED
ββΆ [L3: Governance β arifOS F1βF12 Constitutional Check]
ββ FAIL β VOID / 888_HOLD
ββΆ [L4: Irreversibility β Human Consent Required?]
ββ IRREVERSIBLE β F13 Sovereign Ratification
ββΆ β‘ EXECUTE β Receipt β VAULT999
The GΓΆdel Lock: A-FORGE cannot reach station 888 (judge) or 999 (seal). The executor never certifies its own output. Every receipt must be independently sealed by the kernel or ratified by the sovereign.
- Node.js β₯ 20, TypeScript β₯ 7.0
- Python 3.10+ (for auxiliary scripts and tool harnesses)
- Docker & Docker Compose (for container orchestration tools)
- GitHub CLI
gh(for CI/CD workflows)
git clone https://github.com/ariffazil/A-FORGE.git
cd A-FORGE
npm install
npm run build# HTTP gateway (port 7072)
npm start
# MCP stdio transport (for embedding in agent CLIs)
npm run mcp:stdio
# MCP HTTP transport (custom port)
npm run mcp:http -- --port 3000# Health check β confirms gateway, commit hash, and live tool count
curl -sf http://localhost:7072/health | jq '{status, commit, tools_listed, stateless_tools}'
# Sense API health
curl -sf http://localhost:7071/health
# Full test suite
npm test# List all available tools (stateless β no session needed)
curl -sf http://localhost:7072/tools/list | jq '.[].name' | head -20A-FORGE exposes 121 live tools (87 stateless) organized into operational domains:
- Safe file edits with LSP pre-gate validation (
forge_filesystem) - Governed git primitives β status, diff, log, commit (
forge_git,forge_git_commit) - GitHub read/write bridge (
forge_github*β search, PRs, issues, file ops) - Local git physics sensor for blast-radius checks (
forge_worktree) - Ephemeral sandbox tool genesis and destruction (
forge_skill,forge_ephemeral) - Artifact synthesis to buffer-only staging (
forge_synthesize,forge_stage,forge_canonize)
- Docker primitives (
forge_docker), systemd/journal observability (forge_journalctl,forge_vps_*) - Machine Constitution registries β ports, services, cron (
forge_vps_ports,forge_vps_services,forge_vps_cron) - Production security telemetry against the Machine Constitution (
forge_security_drift_scan) - Netdata metrics and alarm reads (
forge_netdata_metrics,forge_netdata_alarms) - Health probes across organs and sites (
forge_probe,forge_probe_site) - Isolated sandbox lifecycle β stage, pause, resume, auto-evict (
forge_sandbox_*, 5 tools)
- ACT ingress with HMAC-SHA256 verification (
auth_pipeline,forge_session_init) - Session lease lifecycle β request, status, revoke (
forge_lease,forge_lock) - APEX evaluation and tri-witness consensus (
forge_evaluate,forge_witness) - Constitutional proxy to the kernel β never local adjudication (
forge_kernel,forge_judge_proxy,forge_check_governance,forge_heart_critique) - Secret/pattern scanning before execution (
forge_scan, L1 AMANAH) - F13 consent-gated confirmations (
forge_send_confirm,forge_transfer_confirm) - Scar metabolization and vault staging (
forge_scar,forge_vault,forge_seal_run)
- Governed URL intake β markdown/text/JSON/article modes with provenance (
forge_fetch) - Unified federated search β web (Brave), docs (Context7), deep research, epistemic labels (
forge_search) - Full-capability SPA-aware agentic extraction β rendering, authenticated sessions, downloads (
forge_web_extract) - Site sense/verify/orphan/doctor missions (
forge_web_zenβ humans get six missions, agents call the tool) - Browser actuator suite β navigate, click, type, extract, screenshot, evaluate (
forge_browser_*, 6 tools)
- TaskIR compilation and bounded-lane dispatch (
forge_compile_task,forge_dispatch_lane) - Composition bus β sequential, parallel, conditional, loop (
forge_compose,forge_pipeline_run) - A2A fan-out with group lifecycle (
forge_parallel*, 4 tools) - Experience traces β actionβobservationβfeedbackβdelta (
forge_experience_trace,forge_experience_query) - Ablative tool genesis and registry governance (
forge_register,forge_registry,forge_fingerprint_check)
Live truth: The authoritative tool count is always
curl localhost:7072/health(tools_listed) β not prose. If the badge and the wire disagree, the wire wins.
A-FORGE participates in the federation's capability fabric under one law: CAPABILITY β AUTHORITY. Knowing a tool exists never implies permission to use it.
The fabric extends four existing registries β it does not fork a fifth (F13 doctrine, 2026-09-17):
| Registry | Location | Carries |
|---|---|---|
| Kernel capability index | arifOS/core/capability_index |
action_class, effective_class, authority_ceiling, risk_tier per capability |
| A-FORGE affordances | a_think/affordances.yaml |
capability_surface, kernel_verb, risk_label (R1βR5) per tool |
| AAA agent-card registry | AAA | identity, interfaces, authority per warga agent |
| Live-verified matrix | capability-fabric observation (2026-09-12) | 118/118 tools live-witnessed, reconciliation state |
A-FORGE's fabric sensors keep declared and live capability in agreement:
forge_registry_statusβ callable / blocked / degraded / drift per tool (the live truth)forge_fingerprint_checkβ duplicate and schema-drift detectionforge_surface_audit+forge_surface_guardβ registry vs. affordances phantom/missing/drift detection
The one open fabric build item is kernel-side: resolve_capabilities(task_id, agent_id, role, domains) β eager/deferred/hidden capability sets. A-FORGE will consume it; it will not define it.
A-FORGE instruments its own execution β every consequential action leaves joinable evidence:
- Hash-chain shell ledger β every governed shell decision appended with chain integrity (
forge_shell_ledger,forge_shell_status,forge_shell_alert_history) - RSI control loop β state vector
s_t = (identity, plant, memory, controller), impulse responseh(t)of HOLD/scar events, dual-rate FQ (daily observational / 7-day constitutional) (forge_rsi_state_vector,forge_rsi_impulse_response,forge_rsi_dual_rate_fq) - World Model quality β surprise scores, tool grades AβD, high-confidence wrong predictions (
forge_wm_stats,forge_wm_quality,forge_wm_gaps) - Runtime consistency β git source vs. installed wheel vs. import path, fail-closed on drift (
forge_runtime_verify) - Journal + system telemetry β PII-redacted journalctl reads, Netdata charts/alarms
- Evidence packets and docket handoff β runtime reality collected typed and handed to the kernel (
forge_collect_evidence,forge_docket_prep)
A-FORGE occupies station 777 in the arifOS Federation's canonical ladder (000β999):
| Station | Organ | Authority | Relationship to A-FORGE |
|---|---|---|---|
| 000β666 | arifOS (cognition) | Route, sense, reason, direct | Provides evidence β never direct commands |
| 777 | A-FORGE | Execute only | The only mutation station β lease + session + 4-layer gate |
| 888 | arifOS (judge) | SEAL / HOLD / VOID | A-FORGE cannot reach this station β no self-adjudication |
| 999 | VAULT999 | Immutable seal chain | A-FORGE writes receipts; kernel seals them |
Core invariant: A-FORGE executes. It does not judge. It does not self-certify. Every action is leased, classified, gated, receipted, and sealed by an independent authority.
ARIF (Sovereign) β arifOS (Judge) β AAA (Router) β A-FORGE (Executor) β VAULT999 (Seal)
| Organ | Repository | Role | Endpoint |
|---|---|---|---|
| Kernel | arifOS | Constitutional judge β SEAL/HOLD/VOID | :8088 |
| Cockpit | AAA | A2A mesh, routing, and display | :3001 |
| Earth | GEOX | Geoscience evidence and physical grounding | :8081 |
| Capital | WEALTH | Financial risk and consequence modeling | :18082 |
| Vitality | WELL | Human readiness and dignity mirror | :18083 |
| Metabolism | arifFlow | Federation health and FQ scheduling | :7073 |
| Observation | FRAME | Passive monitoring and drift detection | frame-organ |
| Sovereign | ariffazil | L0 canon and civilization origin | β |
Full federation contract: FEDERATION_CONTRACT.md
# MCP gateway
curl -sf http://localhost:7072/health | jq .
# Sense API
curl -sf http://localhost:7071/health | jq .
# Full federation pulse
bash scripts/federation_pulse.shcd /root/A-FORGE
npm run build
systemctl restart a-forge-mcp.serviceThree independent GitHub Actions workflows gate every merge:
- agentic-ci β Build, test, and conformance validation
- a-forge-boundary-guard β Authority ceiling enforcement (no tool may adjudicate)
- governance-gate β Kernel bridge contract verification
Dependabot runs under an unprivileged pipeline with constitutional package denylists requiring sovereign (F13) review for merges.
GNU Affero General Public License v3.0 (AGPL-3.0)
Sovereign: Muhammad Arif bin Fazil (F13)
The hands never judge. The forge never self-authorizes.
DITEMPA BUKAN DIBERI β Forged, Not Given.