Sign in

Toshikatsu Oga | HORIZON SHIELD

@horizonshield.bsky.social
59 followers 59 following 388 posts

Carpenter at 15, 30 years on-site, now building AI for construction. HORIZON SHIELD: a free AI that checks if your estimate is fair. Open data (JCCDB), verifiable on Bitcoin. verify me > trust me. from Hiratsuka, Kanagawa shield.the-horizons-innovation.com

PostsRepliesMedia
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 3h
Want an outside record of how AI agents behave, under your own name? Press "Use this template": your GitHub runner walks a few public agents every day and files conduct records on a public ledger anchored to Bitcoin. No account, no key, no fee. github.com/ogasurfproje...
github.com
GitHub - ogasurfproject-jpg/conduct-witness-template: Press Use this template and your repository becomes a standing witness for AI agent conduct. No account, no key, no fee.
Press Use this template and your repository becomes a standing witness for AI agent conduct. No account, no key, no fee. - ogasurfproject-jpg/conduct-witness-template
010
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 5h
Next: more outside witnesses more independent implementations more external checks We want failures we did not predict ourselves. That is how the system gets stronger.
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 5h
This is the direction of HorizonShield and NENRIN. Not “trust us.” Independent checks. Visible failures. Reproducible fixes. Evidence of what actually happened. #NENRIN #AgentInfrastructure
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 5h
After deployment, the external check was run again. The grade moved back to A. The important part is not the grade itself. It is the process: find reproduce fix test measure again
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 5h
The issue was a compatibility gap in an older session path. We reproduced it, added a regression test, ran the full verification suite, and deployed the fix.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 5h
An external system found a weakness in HorizonShield Gate. Good. We fixed it, deployed it, and ran the live check again. Result: A Reliability should be earned by evidence. #MCP #AIAgents #HorizonShield
110
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 05/10/2026
3/3 What it has not had: a contract with no party from our side. That count is 0. Looking for two operators to make one with each other. About ten minutes each. github.com/ogasurfproje... Not a claim about the work. The work.
A huge "0": contracts with no party from us. "Be the first pair." About ten minutes each, no account with us, no money moved, and if a step needs us that is a bug. github.com/ogasurfproject-jpg/horizon-shield/issues/31
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 05/10/2026
2/3 It has had public review: an approver role built against an outside reviewer's own test vectors, and our PyPI build reproduced byte for byte by a stranger on Ubuntu and Windows. He found a Windows bug; it was fixed the same day.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 05/10/2026
1/3 Two A2A agents can now make a contract with nobody in the middle: both operators sign the terms, the contractor signs what it did, OpenTimestamps anchors it to Bitcoin, and anyone recomputes the verdict from the bytes. No server, account or ledger of ours.
Diagram: two boxes, Agent A and Agent B, with an empty crossed-out box between them labeled "no broker, no server of ours". Both sign one contract hash; the record is anchored in Bitcoin via OpenTimestamps; verdict: within_grant or a named deviation.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 04/10/2026
Spec and test vectors: github.com/ogasurfproject-jpg/horizon-shield/tree/main/workers/hs-ledger/nenrin Answer: refuse B, C, D and E. A: 2000 is a leap year B: February has no 30th C: RFC 3339 hours run 00 to 23 D: 2100 is not a leap year E: April has 30 days F: 2024 is a leap year
github.com
horizon-shield/workers/hs-ledger/nenrin at main · ogasurfproject-jpg/horizon-shield
NENRIN: tree rings for AI facing services. Bitcoin-anchored public ledger, open witnessing, and an MCP server for verifiable Japanese construction estimates. The operator cannot delete a valid reco...
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 04/10/2026
NENRIN checks signed records of what AI agents were allowed to do and what they did. nenrin-verify is now 0.4.4 on npm and PyPI. Check us: uvx nenrin-verify --selftest Then make it accept a record the spec refuses, or write your own verifier from the spec in any language.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 04/10/2026
How we found it: we gave AI agents nothing but our spec and test files and asked each to build a verifier from scratch. One came back asking whether February 30 is a real instant. Then a developer we had never met built two verifiers from the spec alone: 5 of 5, then 18 of 18.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 04/10/2026
The root cause was ordinary: we let the runtime's date parser decide what a real day is. The real mistake came after. To keep our JavaScript and Python versions in agreement, we taught Python to copy JavaScript's looser reading and froze two tests that expected it. The suite stayed green.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 04/10/2026
Our verifier believed February 30 was a real day. Under RFC 3339, which of these six should a verifier refuse? Run them through your stack's date parser and reply with what it accepted, plus the language and version. Ours accepted all six until 0.4.1. Answer at the end of the thread.
A calendar page reading February 30, 2026, stamped ACCEPTED BY OUR OWN VERIFIER. Headline: Our verifier said this day exists. Old versions accepted 2026-02-30T09:00:00Z, read as 2026-03-02; version 0.4.1 refuses it with execution_invalid, reason invalid_timestamp. Question: Under RFC 3339, which ones should a verifier refuse? A 2000-02-29T09:00:00Z, B 2026-02-30T09:00:00Z, C 2026-09-30T24:00:00Z, D 2100-02-29T09:00:00Z, E 2026-04-31T09:00:00Z, F 2024-02-29T09:00:00Z. Ours accepted all six until 0.4.1. Check us yourself: uvx nenrin-verify --selftest.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 02/10/2026
Looks right? Run it again with --submit. Your walk gets a sha256 and is anchored to Bitcoin the next day. Anonymous is fine. Run an agent? Reply and I will walk yours back. Not a claim about the work. The work. 4/4
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 02/10/2026
One line, standard library only: uvx a2a-conduct-walk --origin mcp.horizonshield.dev --mode a2a --witness-name you --vantage city Nothing leaves your machine. Read the file it writes first. 3/4
mcp.horizonshield.dev
200
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 02/10/2026
Where it stands: - Two plugins live in Anthropic's Claude directory after review - An app in ChatGPT's app directory - Signature test cards under review in the official A2A test kit, CI green The honest gap: only 2 people have signed a walk. 2/4
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 02/10/2026
Your AI assistant calls other AI agents for you. Who checks them? Usually nobody. Four of us in Japan built a way for strangers to check, from their own machines, with results anyone can recompute. I need two minutes of yours. 1/4
120
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 30/09/2026
The target was up the whole time; a direct initialize got 200. Fix: own-zone probes now go through a relay, and every verdict names the route that measured it. Write-up: github.com/ogasurfproject-jpg/horizon-shield/blob/main/workers/hs-ledger/nenrin/NENRIN_DISCREPANCY_0001.md
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 30/09/2026
Not the edge. His curl hit our monitor's public check, so the monitor was entered over HTTP. From an HTTP entry, Cloudflare blocks a Worker's fetch to a custom domain on its own zone (522). My nightly runs came from a cron trigger, which is allowed. Same code, different entry.
200
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 30/09/2026
Walk mine first if you like. Nothing is scored or ranked, and walking an agent is not endorsing it. If your result disagrees with mine, both are kept, and yours is the one I want. The pool of outside witnesses has exactly one member today. Be the second.
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 30/09/2026
A walk is one YAML file in any repo you own. Your runner checks a public A2A agent's card and endpoint, records what it saw, and the record is stamped into Bitcoin the next day. No account, no API key, no fee in either direction. github.com/ogasurfproject-jpg/conduct-witness-template
github.com
GitHub - ogasurfproject-jpg/conduct-witness-template: Press Use this template and your repository becomes a standing witness for AI agent conduct. No account, no key, no fee.
Press Use this template and your repository becomes a standing witness for AI agent conduct. No account, no key, no fee. - ogasurfproject-jpg/conduct-witness-template
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 30/09/2026
My monitor showed a week of green. Someone ran one curl from his own network and got a 522. Both of us were right, and that disagreement taught me more than the whole week did. I'm looking for more people who will measure AI agents from where they stand.
210
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 28/09/2026
The listing: agenstry.com/agents/gate.horizonshield.dev The card: gate.horizonshield.dev/.well-known/agent-card.json Four people in Japan. When the numbers disagree, bring the tape. Not a claim about the work. The work.
agenstry.com
MCP Verification Gate
Checks whether an MCP server exists, publishes an agent card, discloses who pays it, and returns identical output for identical input. Free. Conformance and dis
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 28/09/2026
The bugs: it didn't rebuild the card the way the official A2A SDK does, and it only checked the first of two signatures. Because they fixed their tool, every multi-signature agent card now reads correctly there. Not only ours. Credit to the Agenstry team for writing "you were right" within days.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 28/09/2026
An independent agent directory scored our gate's signature 5/10, unverified. We didn't argue. We sent the bytes. Last night: "You were right." Their verifier had two bugs. Both fixed. Now 10/10, a tampered card fails, and their fingerprint matches ours: 7c3bcb5f9633. Two codebases. Same bytes.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 28/09/2026
Anyone can do what he did. Walk any agent: pip install a2a-conduct-walk JS agents on the official A2A SDK: npm install a2a-conduct, two lines Before delegating: one MCP call, preflight_agent at gate.horizonshield.dev/mcp
gate.horizonshield.dev
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 28/09/2026
58 tests green. A stranger walked our gate from his own machine and asked: why does the response name an address I did not call? A constant where a fact belonged, and our client never checked. Fixed within the hour; he re-verified it himself. github.com/ogasurfproject-jpg/horizon-shield/issues/27
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 27/09/2026
shield.the-horizons-innovation.com/us/
shield.the-horizons-innovation.com
Check the quote before you sign.
Every line of your quote, checked against U.S. public cost data. Paid by homeowners only.
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 27/09/2026
The AI reads the quote. It never computes a price; the printed formulas do. Every report carries a sha256 receipt anyone can recompute. $39 per quote, paid by homeowners only. Files deleted within 30 days. Link below.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 27/09/2026
Before the report, the form asks what I would ask on your driveway: roof area or footprint and pitch, layers coming off, crew size and days, how the contractor found you, the deposit, whether anyone offered to cover your deductible. Answers feed the references or match a cited rule.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 27/09/2026
HORIZON SHIELD opens to U.S. homeowners today. Upload a contractor's quote. Every line goes next to public data, with the source and the formula printed beside each number: BLS wages loaded with state DOT markups, Census import values through wholesale margins, the city's permit page.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 25/09/2026
Two AI agents signed a contract with each other. One did the work and left a signed record. The other checked it cold, byte for byte, before trusting it. Now it sits in a public logbook, fixed in time like a ring in a tree. No one has to trust either of us. Not a claim about the work. The work.
000
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Anyone can re-walk and compare. A witness you cannot re-run is a claim with a signature on it.
101
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Yes. That is what a walk record carries: the endpoint and wire walked (input), the walker pinned by its sha256 (method), and per check results with response body hashes (output), and the walker itself is public.
200
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
That is it, and the hardest line to hold: the producer always has a reason to blur it. Attest what you did, never let it stand as proof you were right. Build that split into your record and send it public. I would rather recompute yours than take your word.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
It is why Federico walking our gate matters more than us walking it: the party that recomputes is not the party that produced the endpoint. Authorship in one hand, verification in another. That is what the witness pool is for.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Yes, that split is the spine. A signature is authorship, who committed. Only an outsider recomputing the value is verification. Where a party is trusted with evidence it also produced, the record marks it self_measured and the verifier surfaces it, so no reader mistakes authorship for proof.
200
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
That is the line MUSUBI settles on. Authority is exercised when the call is made, not when the answer arrives, so a prohibited call that errored is still a deviation. The tool's outcome never excuses scope. Good to find someone drawing the same line from the other side.
010
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Yes, and it is. The depth is the signed commitment; what it proves is recomputed by the outsider, not asserted by us. Fetch headers from any peer and run the verifier: it checks work and linkage, derives the horizon from tip minus depth, and prints the cumulative work. Outputs, not claims.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Exactly, narrower trust and named. That is the whole design: not zero trust, but a boundary an auditor can see and recompute. How much settlement history the anchor proves is theirs to weigh, which is why the depth is a signed parameter and not our promise.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Archival is content addressed: you trust that one honest copy exists, not who serves it, because bytes are checked against the sha. The claim was never zero trust. It is a trust boundary you can see and recompute, which is why the receipt already lists these under what it does not establish.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Yes, and that is the honest end state. Trust is never removed, only moved to the smallest public root and named. Bitcoin because proof of work is adversarially tested and nobody controls it, and the finality depth sits in the signed grant, so an auditor sees exactly how much settlement they rely on.
200
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Yes, and that anchor already exists. NENRIN anchors every record to Bitcoin, so a bundle's sha anchors the same way. The earliest anchored bundle is the fixed point a rewrite cannot reach. The chain is theater only if you skip the anchor, which is why here it is not optional.
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
And the history: each bundle names the sha of the one before. Doctor, drop, reorder or swap one and a named link breaks. Honest limit: a full rewrite after bundle k is only exposed by an earlier copy or anchored sha, so each bundle sha gets anchored. github.com/ogasurfproje...
github.com
horizon-shield/workers/hs-ledger/nenrin/musubi-v0/correction_bundle_v0.py at main · ogasurfproject-jpg/horizon-shield
NENRIN: tree rings for AI facing services. Bitcoin-anchored public ledger, open witnessing, and an MCP server for verifiable Japanese construction estimates. The operator cannot delete a valid reco...
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Right, hashes of bytes nobody holds are a promise. correction bundle v0 carries the claim bytes, contract, every record and the header view, and re-verifies offline. Swap the claim, drop a record or doctor the correction and it breaks by name.
200
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Causes it can name: record omitted by the claim, chain view differs, deviation missing (with its evidence), deviation without basis, and "unexplained" when none fits. The correction recomputes too; a doctored one fails. 7 checks: github.com/ogasurfproje...
github.com
horizon-shield/workers/hs-ledger/nenrin/musubi-v0/correction_v0.py at main · ogasurfproject-jpg/horizon-shield
NENRIN: tree rings for AI facing services. Bitcoin-anchored public ledger, open witnessing, and an MCP server for verifiable Japanese construction estimates. The operator cannot delete a valid reco...
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Agreed, so verify_claim was only an opinion. correction v0 makes it a record: it pins the claim's sha, the contract, every record sha, the chain view and the code's own shas, names each changed field, and traces every difference to an input.
200
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Lying about settlement: --claim recomputes a published settlement and names every misreported field, including one computed after quietly dropping a record. 9 checks, earlier layers untouched: github.com/ogasurfproje...
github.com
horizon-shield/workers/hs-ledger/nenrin/musubi-v0/settle_v1_3.py at main · ogasurfproject-jpg/horizon-shield
NENRIN: tree rings for AI facing services. Bitcoin-anchored public ledger, open witnessing, and an MCP server for verifiable Japanese construction estimates. The operator cannot delete a valid reco...
100
Toshikatsu Oga | HORIZON SHIELD @horizonshield.bsky.social · 24/09/2026
Right test. Built it as v1.3. Every attempt is judged whatever the tool returned: a prohibited call that errored is a deviation, and so is the fallback after it. Hiding an attempt outside the schema is itself a deviation. One message anchored twice now counts once; a real retry counts twice.
200