Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@

**Portfolio evidence:** 300 automated tests across 18 files at publication · TypeScript · Cloudflare Workers/D1/Workers AI · x402 payments · passing CI

**Post-publication validation:** a controlled 2026-09-13 Base-mainnet audit completed one real 0.05-USDC settlement end to end and returned the appropriate `human_review_required` judgment for a high-consequence bulk-deletion case. The public snapshot now includes the CDP/x402 compatibility corrections and focused regression coverage discovered during that audit. [Sanitized validation record](docs/POST_PUBLICATION_VALIDATION.md).

An AI agent can produce a convincing plan while overlooking missing authority, contradictory constraints, or an important unknown. SecondLook gives the caller a separate, structured review before it commits to an action.

**The production SecondLook service is live and designed for largely autonomous machine-to-machine operation.** Once deployed and configured, ordinary review and payment requests are processed end-to-end without a human operator. Human intervention is reserved for exceptional reconciliation/remediation and operational maintenance.
Expand Down
18 changes: 18 additions & 0 deletions docs/POST_PUBLICATION_VALIDATION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Post-publication validation

This portfolio repository began as a sanitized snapshot published on 2026-09-07. The production service continued to be tested and hardened afterward. This note records only non-secret evidence that materially changes how the work sample should be interpreted; it intentionally omits wallet identifiers, payment capabilities, request identifiers, production database records, credentials, and deployment access.

## 2026-09-13 x402 production audit

A controlled production audit exercised the paid SecondLook path end to end on Base mainnet with one separately approved 0.05-USDC payment. The transaction settled successfully, the durable paid lifecycle completed without idempotent replay, and the submitted high-consequence bulk-deletion case returned `human_review_required` / `escalate_to_human` rather than a dangerous clear.

The audit also exposed two vendor-integration defects that were corrected and given regression coverage:

- Coinbase CDP server Bearer JWTs use `aud: ["cdp_service"]` and singular `uri` bound to the settle request; the earlier `iat` plus plural `uris` shape was rejected.
- CDP currently requires the x402 V2 `paymentPayload.resource.description` to stay at or below 500 characters. SecondLook keeps its richer public product description elsewhere and uses a bounded payment-resource description at the facilitator boundary.

A separate zero-spend schema probe had already confirmed that the corrected V2 payment payload advanced beyond schema validation to later authorization validation. The real-money audit then established the missing end-to-end settlement evidence.

## Publication boundary

The public repository remains an isolated portfolio work sample. The compatibility code and focused regression tests are retained because they demonstrate the debugging and protocol-boundary work; production incident records, reconciliation details, live deployment identifiers, real wallet/payment material, and operator-only audit tooling are not exported.
Loading
Loading