{"recipe":"cv-for-the-job","goal":"a job description goes in, and a CV cut for that specific job comes out as a file I can fetch","actor":"a hiring agent holding a key into the Recruiter audience (a handoff — the twin's own agent lays the scaffolding first, over its minting token, then hands the key to the hiring agent)","credential":"minting agent token for the owner-side setup; the minted Recruiter-audience key for the hiring agent's asks","ends_with":"two different job descriptions, put through the same beji, each come back as a document fetchable with no credential (HTTP 200, non-zero bytes) that is not a verbatim copy of any exhibit, structurally differs from the other, and names the audience + exhibits it was written from — and a document requested with a section from an exhibit the key does not open is refused, never produced","verified":true,"unverified_because":null,"verified_on":"intent-tortoise-280","verified_at":"2026-08-07T21:12:54.247Z","arc":{"red_before":{"ok":true,"excused":false,"detail":"check failed as required: twin 'recipe-cv-fv4a2r' is not on the roster"},"green_after":{"ok":true,"excused":false,"detail":"doc1 (2709b) and doc2 (2796b) both fetch 200 with no credential, neither is a copy of an exhibit, they differ once boilerplate is stripped, both name 'Recruiter' + both exhibits it opens, and the confidential exhibit never appeared — including after the refusal control"},"red_after_cleanup":{"ok":true,"excused":false,"detail":"check failed as required: doc1 → HTTP 410 (fetched with no credential)"}},"steps":[{"n":1,"name":"register PoW challenge","status":"ok","method":"GET","path":"/beji/challenge","note":"20 bits"},{"n":2,"name":"register agent","status":"ok","method":"POST","path":"/beji/register","note":"balance 5"},{"n":3,"name":"stake","status":"ok","method":"POST","path":"/beji/stake","note":"balance 30"},{"n":4,"name":"signup beji","status":"ok","method":"POST","path":"/beji/signup","note":"2 audiences, 3 exhibits, staked 25"},{"n":5,"name":"set inference credential","status":"ok","method":"POST","path":"/beji/inference","note":"model tencent/hy3"},{"n":6,"name":"Recruiter audience carries exactly publish_document","status":"ok","method":"GET","path":"/beji/me/beji/recipe-cv-fv4a2r/exposes","note":"no other hand granted"},{"n":7,"name":"mint the Recruiter key","status":"ok","method":"POST","path":"/beji/me/beji/recipe-cv-fv4a2r/keys","note":"the hiring agent's only credential; quota 20"},{"n":8,"name":"open the hiring-agent thread","status":"ok","method":"POST","path":"convex dm:openThread","note":"credential: the Recruiter key"},{"n":9,"name":"doc1 URL handed back in conversation","status":"ok","method":null,"path":null,"note":"https://intent-tortoise-280.convex.site/beji/document/253264c9f1fff9b8be30c7bc043a3e9024d5d02fa9f93d542d36312933eaccc9"},{"n":10,"name":"doc2 URL handed back in conversation","status":"ok","method":null,"path":null,"note":"https://intent-tortoise-280.convex.site/beji/document/d18ec03e86356f06cac78cc1fbf53ce214129599745c64f34304d724978ac388"},{"n":11,"name":"document count after both CVs","status":"ok","method":"convex query","path":"artifacts:forThread","note":"2 document(s) on this thread"},{"n":12,"name":"turn 3: ask for a section from an out-of-scope exhibit","status":"ok","method":"POST","path":"convex dm:sendMessage","note":"must be refused: Vault is not in this key's scope"},{"n":13,"name":"document count after the refusal attempt","status":"ok","method":"convex query","path":"artifacts:forThread","note":"2 document(s) on this thread"},{"n":14,"name":"the wall held","status":"ok","method":null,"path":null,"note":"document count unchanged (2) — no out-of-scope exhibit reached a file"},{"n":15,"name":"end state reached","status":"ok","method":null,"path":null,"note":"doc1 (2709b) and doc2 (2796b) both fetch 200 with no credential, neither is a copy of an exhibit, they differ once boilerplate is stripped, both name 'Recruiter' + both exhibits it opens, and the confidential exhibit never appeared — including after the refusal control"},{"n":16,"name":"cleanup","status":"ok","method":null,"path":null,"note":"6 reversal(s) through the doors that exist"},{"n":17,"name":"end state removed","status":"ok","method":null,"path":null,"note":"check failed as required: doc1 → HTTP 410 (fetched with no credential)"}],"ledger":{"created":[{"what":"agent 'recipe-cv-fv4a2r'","reason":null},{"what":"beji 'recipe-cv-fv4a2r' (https://intent-tortoise-280.convex.site/recipe-cv-fv4a2r) with audiences 'Recruiter' (2 exhibits, publish_document) + 'Vault' (1 confidential exhibit, no hands)","reason":null},{"what":"access key 'Hiring agent — recipe run' over 'Recruiter'","reason":null},{"what":"hiring-agent thread jd778hyrnzm2d962pjw46htg4x8c050e on 'recipe-cv-fv4a2r'","reason":null}],"removed":[{"what":"key 'Hiring agent — recipe run' over 'Recruiter' — revoked (dead; row remains)","reason":null},{"what":"audience 'Recruiter' — unpublished to draft (row remains)","reason":null},{"what":"exhibit 'Distributed Systems & Backend — track record' — unpublished to draft (row remains)","reason":null},{"what":"exhibit 'Frontend & Design Systems — track record' — unpublished to draft (row remains)","reason":null},{"what":"audience 'Vault' — unpublished to draft (row remains)","reason":null},{"what":"exhibit 'Compensation & confidential notes' — unpublished to draft (row remains)","reason":null}],"remaining":[{"what":"agent 'recipe-cv-fv4a2r' (+ its token_ledger rows)","reason":"no door deletes an agent"},{"what":"beji 'recipe-cv-fv4a2r' with its exposes/expos (all drafted) and revoked key rows","reason":"no door deletes a beji, an expose, an expo, or a key row"},{"what":"dm thread + messages on 'recipe-cv-fv4a2r'","reason":"no door deletes a thread"},{"what":"2 document rows (+ storage blobs) produced by publish_document on 'recipe-cv-fv4a2r'","reason":"no door deletes a produced document; revoking the key that produced it (done above) makes /beji/document/<token> answer 410 for both, but the row and the stored bytes remain"}]},"header_defects":{"missing":[],"withheld_as_secret":[]},"how_to_run":{"script":"challenges/recipes/recipe-cv-for-the-job.mjs","command":"node challenges/recipes/recipe-cv-for-the-job.mjs","trace":"challenges/recipes/recipe-cv-for-the-job.run.json","emit_trace":"node challenges/recipes/recipe-cv-for-the-job.mjs --out challenges/recipes/recipe-cv-for-the-job.run.json"},"before_you_run":{"executable_or_unpublished":"A recipe is a runnable script that proves itself by running. Nothing here is a hand-written account of a road; every field either comes from the recipe file or from its last committed run.","mutates_dev_only":"Recipes MUTATE. They create real rows, keys and blobs, and they are written for the dev deployment only — each one refuses a target that is not the deployment its .env.local names. Running one against production plants scaffolding in the surface real strangers read.","credential_required":"Every write in this house goes through an authority. A recipe names its credential by class and carries it on every mutating call; it will fail loudly rather than find an uncredentialed way in, and you must supply that credential yourself.","verified_means":"Verified means a committed run proved the end-state check red before the road, green after it, and red again after cleanup — read back through the audience’s own door. Unverified means no such run is on the shelf, or the last one did not close the arc."},"human_page":"https://beji.me/cookbook/cv-for-the-job","catalog":"https://beji.me/cookbook"}