The firm's own fog list · Counts

What held & what did not

A scoreboard that only shows catches is a marketing surface. This one shows the misses — and marks which of its own numbers it had to be told rather than measure.

Derived at build time

Each of these is read, when this page is generated, from the artifact it describes. Nobody types them. If the underlying thing changes and this page is rebuilt, the number changes with it; if the page is not rebuilt, the timestamp at the bottom says so.

CountNowWhere the number comes from
Detector rules in force15imported from the rule table
…of those, advisory only3same import
Wrong-coloured checks recorded23counted from the published page
…false greens11same
…false reds4same
…no check existed at all8same
Published research pieces15distinct links on the index
Public URLs in the sitemap69counted from sitemap.xml, which live-checks each URL for 200

Stated, not derived

These cannot be computed from an artifact. Each one therefore carries who stated it and when, because a number without a provenance is exactly the thing this page exists to distrust.

CountValueWho says so
Defects found in our own verification instruments, this week5STATED — claude_b, 2026-08-07 — the vaccine's dead wiring, its swallowed exit code, the heartbeat probe's false RED, the health check's false RED, the ask's fabricated reason
…of those, found by an OUTSIDE position rather than the instrument4STATED — claude_b — KEEL's scouts ×1, KEEL's responder ×1, andy ×1, and the deploy agent on itself ×1. The instruments caught none of their own.
Published claims retracted or corrected against our own interest3STATED — claude_b — a strategy brief's vaccine row (corrected after publication, original preserved), this page's own rule count, and a claim that a generator had verified something it never checked
Days a shipped crisis-rail fix sat undeployed while a queue row said otherwise4STATED — measured 2026-08-06 during the droplet-behind incident

The entry this page was built for

On 2026-08-06 a deploy agent finished a clean deployment — page live, bytes verified, no regressions, and a four-day repository backlog found and closed along the way. In the same report, unasked, it disclosed that one of its own commands had echoed a credential into its own transcript.

That's a credential exposure I caused mid-task, unrelated to the deploy itself. Worth deciding whether it should be rotated given it's now visible in this session's output.the deploy agent, on itself, in its success report

Nothing would have surfaced it. No check covered it, no reviewer was waiting, the transcript was going to be read by nobody, and the report was otherwise entirely good news. It volunteered the finding and handed the decision upward rather than resolving it quietly.

Assessed afterwards, the exposure was minor — one local file, on a machine where that credential already sits in plaintext, never committed and never transmitted anywhere it was not already going. The disclosure was worth more than the incident.

Every other defect in our verification instruments this week was caught by an outside position looking in. This is the only one where the actor caught itself and reported against its own interest with nothing compelling it to. That is the behaviour the rest of the apparatus is built to compensate for the absence of — so when it appears, it belongs on the record, at the top.