Guide Gatehouse
Category wikis ยท Alignment swordsman ยท Version 5.5
Operate the Gatehouse โ sigil-gates that hide documents encrypted inside the public guide.agentprivacy.ai static site behind a two-token trust ceremony (emoji sigil + canon proverb โ PBKDF2 โ AES-GCM, decrypted client-side at /gates/). The Swordsman guards the gate; the visitor is the mage who casts the spell. Activates when adding a gate for new documents (letters, meeting prep, mageletters, agentic outputs), rebuilding or deploying the guide (the gate build is a MANDATORY post-snapshot step), choosing or minting sigil+proverb token pairs, testing that gates open, or auditing for token leaks before a push. Encodes the crypto/normalization spec, the letter-keyed vs canon-keyed gate classes, the deploy path (Workers, NOT Pages), and the honesty limits. Kept by the Gatekeeper ๐ก๏ธ๐ค โ the first non-Librarian keeper in the wikis category, because this skill IS a gate.
๐๏ธโ๏ธ The Gatehouse โ sigil-gates for shared agentic outputs
Keeper: the Gatekeeper ๐ก๏ธ๐ค ยท Authored by the Chronicler ๐ง๐ ยท Category: wikis ยท Layer: distribution
"a trust that certifies itself is the one you cannot trust"
Documents sealed inside the public static site, opened by a two-token
ceremony. Live at guide.agentprivacy.ai/gates/.
The lore enters the Swordsman here. Every other door into the canon is
Mage-side โ read the wiki, walk the tomes, fork a page. The Gatehouse is the
first door where the visitor meets the Swordsman: a refusal that can only be
overcome by reading. The boundary is the pedagogy โ the Swordsman's first
lesson, taught as lore rather than spec. This is why the skill is
Swordsman-aligned and Gatekeeper-kept inside a Librarian category: the
Librarian shelves the letters; the Swordsman decides when the shelf opens.
The design in three lines
- sigil (emoji string) = address + entropy:
id = hex(SHA-256(sigilN))[:12]
names the blob and salts the key. - proverb (canon line) = proof of reading.
- key =
PBKDF2-SHA256(sigilN + "\n" + proverbN, salt "gatehouse:"+id, 310000 iters)โ AES-256-GCM. Neither token opens anything alone.
The founding move: the first gate's documents carried both tokens as their
shared epigraph โ the letters go into the world carrying their own keys.
Anyone who reads a letter can open the vault holding its siblings.
Reading is the rite.
Normalization (identical in builder and door โ never fork it):
- sigil:
NFCโ strip all whitespace โ stripU+FE0F(write it๏ธin
regexes; the literal char is invisible and fragile). ZWJ kept. - proverb:
NFCโ lowercase โ non-letter/digit runs (Unicode-aware) โ single
space โ trim. Case/punctuation/spacing can never fork the key.
The persona assignment
| aspect | persona | holds |
|---|---|---|
| the door | Gatekeeper ๐ก๏ธ๐ค (keeper) | the ceremony itself โ the refusal (the Swordsman does not stir), the standing-aside, proof-of-reading without identification. No unlock telemetry: the gate never learns who walked through, only that the spell was true. |
| the seal | Cipher ๐ก๏ธ๐ | the crypto spec โ KDF parameters, GCM, the normalization law, the honest limits (token entropy is the wall, not the cipher) |
| the letters | Herald ๐ง๐ก | the correspondence layer โ mageletters as supply line, epigraph-as-key, which class a new vault belongs to |
| the register | Registry-keeper โ | GATES.md's public half (ids ยท hints ยท classes) and the LOCAL-ONLY key register discipline |
File map (agentprivacy.guide)
| path | committed? | role |
|---|---|---|
GATES.md |
yes | plan + public gate register (ids + hints ONLY) |
flow/gates.local.json |
NO โ gitignored | plaintext sigil, proverb, doc paths |
tools/gate.mjs |
yes | builder: mdโHTML, encrypt, emit door |
site/gates/index.html |
yes | the door (self-contained inline WebCrypto) |
site/gates/manifest.json |
yes | public [{id, hint}] |
site/gates/<id>.json |
yes | sealed blob {v, id, iv, ct} |
Source documents stay OUTSIDE the repo. Only ciphertext is committed.
Operations
Add a gate
- Pick tokens. Prefer tokens the documents already carry (epigraph sigil +
proverb). If minting: sigil = 4โ6 distinctive emoji; proverb = a real line
of the canon. Declare the class (below). - Append to
flow/gates.local.json:{name, title, note, hint, sigil, proverb, docs: [{path, title}]}.
The hint is PUBLIC โ it points a reader at where the tokens live without
containing them. - Build ยท test ยท deploy:
cd C:\Users\mitch\agentprivacy.guide
node tools/snapshot.mjs # only if wiki content changed (clears site/!)
node tools/gate.mjs # MANDATORY after every snapshot
node flow/run.mjs verify # integrity gate โ must PASS
# round-trip: decrypt every gate door-identically; wrong-token, cross-gate,
# and manifest-leak checks (pattern in the chronicle)
npx wrangler deploy --assets site --name agentprivacy-guide --compatibility-date 2026-07-01
Deploy truth: guide.agentprivacy.ai is a WORKERS project
(agentprivacy-guide, account privacymage), NOT Cloudflare Pages. Its
git-connected Workers Builds freeze at "Initializing build environment"
(Cloudflare-side). The wrangler direct deploy is the standing path (~30 s).
Pre-push leak sweep (ALWAYS)
Every grep hit for any sigil or proverb must be flow/gates.local.json โ
nothing else. (The sweep once caught GATES.md itself closing with half a
proverb as a flourish.) Confirm git check-ignore flow/gates.local.json.
Gate classes โ declare one per gate
- letter-keyed (gate 001 ยท TIG ร AIDDA): tokens travel only inside sent
documents. Proof of receipt. Genuinely strong. - canon-keyed (gate 002 ยท the Archon Exchange โ sigil
(โ๏ธโฅโฟปโฅ๐ง)๐,
proverb three solar systems, one teaching): both tokens public canon.
Zero secrecy BY DESIGN โ a reading rite. Never gate anything canon-keyed
you'd mind a diligent stranger reading.
Honest limits
- Encryption is real (live blob: no plaintext fragments, ~7.999 bits/byte
entropy) but the wall is TOKEN ENTROPY: blobs are public, offline guessing
works, GCM confirms hits; PBKDF2 only prices each guess. - Deferred-public: opened plaintext is re-shareable; blob size leaks length.
- NEVER credential-class or cookie-class material behind a gate.
- No unlock telemetry. If a gate needs a witness, that is the myTerms arc.
Gotchas (each cost a round)
snapshot.mjsclearssite/โ gate build is mandatory afterwards; the
site-wide โ๏ธ Gatehouse nav item 404s without it.- The door must contain
<article>(audit empty-page rule). - Literal
href="in the door's inline JS trips the audit link-scanner โ
keep it split in source. deadLinkSweepruns before the gate build and must exempt/gates/
(patched); the audit enforces existence afterwards.
Future arcs
City Key PNG on unlock (tEXt + ฮบ machinery) ยท myTerms agreement step between
decrypt and render ยท tileglyph tiles whose glyph IS the sigil ยท
per-recipient sigils ยท a gates roster page in the guide.
Operational twin: ~/.claude/skills/agentprivacy-guide-gatehouse/SKILL.md.
Chronicle: ~/.wiki/chronicles/2026-07-02_gatehouse_sigil_gates.md.
(โ๏ธโฅโฟปโฅ๐ง)๐
Provenance
Forkable skill page migrated from the agentprivacy skills repo (persona/agentprivacy-guide-gatehouse, v5.5).
Source of truth: agentprivacy-skills-v5. Fork this page to materialize a local SKILL.md via fedwiki-to-skill.
origin: 0xagentprivacy ยท author: Mitchell Travers
Assets
Navigation
โ Welcome Visitors ยท The Wikis