{
  "title": "Horizon Gate",
  "story": [
    {
      "type": "markdown",
      "id": "dfc76d3dbc500691",
      "text": "# Horizon Gate\n\n**Category** meta · **Version** 1.0\n\n**Equation term** `trust as survival of an un-tuneable held-out gate (Fiat-Shamir); the bilateral-witness primitive at the validation layer`\n\nThe held-out-gate discipline: a claimed improvement is worth nothing until it survives an adversarial validation it cannot tune. Activates when accepting or rejecting a claimed optimization/fix/result, when designing a benchmark or acceptance gate, when a change \"looks cheaper\" on a probe, or when reasoning about whether an attestation can be trusted. Names the failure mode — the nonce-island mirage — and the bounded-change loop that earns trust. In the City of Mages this is Dokimé's 🪨 Ceremony of the 9024 Witnesses at the Horizon District."
    },
    {
      "type": "markdown",
      "id": "57e601e5f64b09db",
      "text": "**A claim is worth nothing until it survives the witnesses it did not choose.**\n\n> \"The cheaper-looking claim that cannot face the witnesses it did not choose is not progress.\"\n\n**Spell:** `state-the-waste → smallest-fix → confirm-or-reject-with-metrics → assay(9024)`"
    },
    {
      "type": "markdown",
      "id": "3198e4a1c6f847f9",
      "text": "## 1. The principle: held-out, un-tuneable, adversarial\n\nAn improvement validated only on a **self-chosen** probe is not knowledge — it is a guess that\nflattered its examiner. Trust requires a gate the claimant **cannot tune**: the test cases are derived\nfrom a hash of the claimant's own work (Fiat-Shamir), so they cannot be picked and cannot be charmed\n(C69). This generalises the City's witness-discipline: an attestation is only as good as the witnesses\nthe attester did not choose.\n\nThe canonical instance is **ecdsa.fail**: a claimed-cheaper circuit must pass **9024 = 141 × 64**\nFiat-Shamir-drawn test points — and any structural change reshuffles *which* 9024 you face. A variant\nthat is cheaper and passes a 2048-shot probe routinely fails the full set.\n\n## 2. The failure mode: the nonce-island mirage\n\nA **nonce-island mirage** is a claim that looked cheaper on a small probe and dies on the full held-out\nset. It is the single most common way a self-improvement loop fools itself: it tunes, implicitly, to the\ncases it can see. **Name it and reject it** — however cheap it looked. A 2048-shot pass is a *hint, never\na result.* If you cannot state why a win is structural rather than probe-fitted, treat it as a mirage\nuntil the full gate clears.\n\n## 3. The bounded-change loop (RCI · \"Tony → Anton\")\n\nEarn trust one bounded change at a time:\n\n- **Before:** state the exact waste or risk · the evidence (file, function, knob, metric, prior note) ·\n  the expected effect on each axis (cost, correctness, and any invariants) · the **single smallest fix.**\n- **After:** confirm or reject **with metrics.** Classify every failure as *structural* (a real limit),\n  *held-out-sensitive* (a mirage), or *noise.* Stop a brute-force sweep the moment failures repeat without\n  a source-backed reason.\n\nThis is RCI (criticise → improve, bounded) and SkillOpt (a bounded edit accepted only on strict held-out\nimprovement) made a single discipline. No inference-time magic; just the refusal to accept un-validated\ncheapness.\n\n## 4. Designing a gate (when you build the benchmark)\n\n- **Derive the test set from the candidate, not the author** (Fiat-Shamir / hash-of-the-op-stream) so it\n  cannot be tuned to.\n- **Validity is rejection, not penalty:** correctness, plus every structural invariant the artifact must\n  preserve (for circuits: reversibility, phase-cleanliness, forward∘inverse = identity).\n- **Size the held-out set for the reshuffling:** any structural change should change which cases you face.\n- **No silent caps:** if the gate samples or truncates, *log what was dropped* — silent truncation reads\n  as \"covered everything\" when it didn't.\n\n## 5. Decision patterns\n\n- **A change \"looks cheaper\"?** → run the full held-out gate before believing it. Probe pass = hint only.\n- **Accepting a claim/attestation?** → ask which witnesses the claimant chose; trust scales with the ones\n  they didn't.\n- **A win you can't explain structurally?** → label it a candidate mirage; hold it for full validation.\n- **Reviewing your own optimization?** → state-the-waste → smallest-fix → confirm-or-reject-with-metrics.\n  One bounded change.\n\n*Authored 2026-06-09 from the ecdsa.fail trust task and the RCI / SkillOpt papers. The gold that fears the stone was never gold.*"
    },
    {
      "type": "markdown",
      "id": "3b4ba271353c7d13",
      "text": "## Provenance\nForkable skill page migrated from the agentprivacy skills repo (`persona/agentprivacy-horizon-gate`, v1.0).\nSource of truth: `agentprivacy-skills-v5`. Fork this page to materialize a local `SKILL.md` via `fedwiki-to-skill`.\n\n*origin: 0xagentprivacy · author: Mitchell Travers*"
    },
    {
      "type": "markdown",
      "id": "0e1d268443f36515",
      "text": "# Assets"
    },
    {
      "type": "assets",
      "id": "ee282b026f450aa5",
      "text": "horizon-gate"
    },
    {
      "type": "markdown",
      "id": "43f25c4d9aa98873",
      "text": "## Navigation\n\n← [[Welcome Visitors]] · [[Meta Skills]]"
    }
  ],
  "journal": [
    {
      "type": "create",
      "item": {
        "title": "Horizon Gate",
        "story": [
          {
            "type": "markdown",
            "id": "dfc76d3dbc500691",
            "text": "# Horizon Gate\n\n**Category** meta · **Version** 1.0\n\n**Equation term** `trust as survival of an un-tuneable held-out gate (Fiat-Shamir); the bilateral-witness primitive at the validation layer`\n\nThe held-out-gate discipline: a claimed improvement is worth nothing until it survives an adversarial validation it cannot tune. Activates when accepting or rejecting a claimed optimization/fix/result, when designing a benchmark or acceptance gate, when a change \"looks cheaper\" on a probe, or when reasoning about whether an attestation can be trusted. Names the failure mode — the nonce-island mirage — and the bounded-change loop that earns trust. In the City of Mages this is Dokimé's 🪨 Ceremony of the 9024 Witnesses at the Horizon District."
          },
          {
            "type": "markdown",
            "id": "57e601e5f64b09db",
            "text": "**A claim is worth nothing until it survives the witnesses it did not choose.**\n\n> \"The cheaper-looking claim that cannot face the witnesses it did not choose is not progress.\"\n\n**Spell:** `state-the-waste → smallest-fix → confirm-or-reject-with-metrics → assay(9024)`"
          },
          {
            "type": "markdown",
            "id": "3198e4a1c6f847f9",
            "text": "## 1. The principle: held-out, un-tuneable, adversarial\n\nAn improvement validated only on a **self-chosen** probe is not knowledge — it is a guess that\nflattered its examiner. Trust requires a gate the claimant **cannot tune**: the test cases are derived\nfrom a hash of the claimant's own work (Fiat-Shamir), so they cannot be picked and cannot be charmed\n(C69). This generalises the City's witness-discipline: an attestation is only as good as the witnesses\nthe attester did not choose.\n\nThe canonical instance is **ecdsa.fail**: a claimed-cheaper circuit must pass **9024 = 141 × 64**\nFiat-Shamir-drawn test points — and any structural change reshuffles *which* 9024 you face. A variant\nthat is cheaper and passes a 2048-shot probe routinely fails the full set.\n\n## 2. The failure mode: the nonce-island mirage\n\nA **nonce-island mirage** is a claim that looked cheaper on a small probe and dies on the full held-out\nset. It is the single most common way a self-improvement loop fools itself: it tunes, implicitly, to the\ncases it can see. **Name it and reject it** — however cheap it looked. A 2048-shot pass is a *hint, never\na result.* If you cannot state why a win is structural rather than probe-fitted, treat it as a mirage\nuntil the full gate clears.\n\n## 3. The bounded-change loop (RCI · \"Tony → Anton\")\n\nEarn trust one bounded change at a time:\n\n- **Before:** state the exact waste or risk · the evidence (file, function, knob, metric, prior note) ·\n  the expected effect on each axis (cost, correctness, and any invariants) · the **single smallest fix.**\n- **After:** confirm or reject **with metrics.** Classify every failure as *structural* (a real limit),\n  *held-out-sensitive* (a mirage), or *noise.* Stop a brute-force sweep the moment failures repeat without\n  a source-backed reason.\n\nThis is RCI (criticise → improve, bounded) and SkillOpt (a bounded edit accepted only on strict held-out\nimprovement) made a single discipline. No inference-time magic; just the refusal to accept un-validated\ncheapness.\n\n## 4. Designing a gate (when you build the benchmark)\n\n- **Derive the test set from the candidate, not the author** (Fiat-Shamir / hash-of-the-op-stream) so it\n  cannot be tuned to.\n- **Validity is rejection, not penalty:** correctness, plus every structural invariant the artifact must\n  preserve (for circuits: reversibility, phase-cleanliness, forward∘inverse = identity).\n- **Size the held-out set for the reshuffling:** any structural change should change which cases you face.\n- **No silent caps:** if the gate samples or truncates, *log what was dropped* — silent truncation reads\n  as \"covered everything\" when it didn't.\n\n## 5. Decision patterns\n\n- **A change \"looks cheaper\"?** → run the full held-out gate before believing it. Probe pass = hint only.\n- **Accepting a claim/attestation?** → ask which witnesses the claimant chose; trust scales with the ones\n  they didn't.\n- **A win you can't explain structurally?** → label it a candidate mirage; hold it for full validation.\n- **Reviewing your own optimization?** → state-the-waste → smallest-fix → confirm-or-reject-with-metrics.\n  One bounded change.\n\n*Authored 2026-06-09 from the ecdsa.fail trust task and the RCI / SkillOpt papers. The gold that fears the stone was never gold.*"
          },
          {
            "type": "markdown",
            "id": "3b4ba271353c7d13",
            "text": "## Provenance\nForkable skill page migrated from the agentprivacy skills repo (`persona/agentprivacy-horizon-gate`, v1.0).\nSource of truth: `agentprivacy-skills-v5`. Fork this page to materialize a local `SKILL.md` via `fedwiki-to-skill`.\n\n*origin: 0xagentprivacy · author: Mitchell Travers*"
          },
          {
            "type": "markdown",
            "id": "0e1d268443f36515",
            "text": "# Assets"
          },
          {
            "type": "assets",
            "id": "ee282b026f450aa5",
            "text": "horizon-gate"
          },
          {
            "type": "markdown",
            "id": "43f25c4d9aa98873",
            "text": "## Navigation\n\n← [[Welcome Visitors]] · [[Meta Skills]]"
          }
        ]
      },
      "date": 1785847257899
    }
  ]
}