STEP 01 / THE RUN

The run being described

One command, from a source checkout, with no key in the environment:

pnpm gateway demo "Build a small API for my team" --enhance --profile coding --language en

Captured on win32; Node v25.8.1. Wall time 14.0 s. The request itself was kept deliberately ordinary: Build a small API for my team.

STEP 02 / THE ENVELOPE

What the run printed

The two long string values are truncated with an ellipsis so this page stays readable. Every field that carries the actual claim - the mode and the three booleans - is reproduced verbatim, and the block below parses as JSON.

{ "schema": "unified-ai-system/usage-report/v1", "mode": "fake", "providerCalled": false, "credentialRequired": false, "deterministic": true, "original": "Build a small API for my team", "enhancedPrompt": "# Task\nComplete the user request below. Preserve its intent,…", "profile": "coding", "language": "en", "detectedSignals": { "format": false, "constraints": false, "audience": false, "success": false, "evidence": false, "environment": false }, "outputPreview": "[fake:local-fake-provider/local-fake-model] # Ta…", "reportUrl": "https://github.com/happy520ai/unified-ai-system/issues/new?template=usage-verification-report.yml", "reviewBeforeSharing": true }

STEP 03 / FIELDS

Field by field

mode"fake" - the local fake provider served the call. It is not a label the caller sets; the gateway reports it only after checking that real provider execution is disabled
providerCalledfalse - the run made no outbound provider request
credentialRequiredfalse - nothing in the path needed a key, which is why the same command works on a fresh machine
deterministictrue - prompt enhancement is local compilation from the request, so the same input yields the same output
originalthe untouched request, kept alongside the rewrite rather than replaced by it
enhancedPromptthe compiled prompt, with detectedSignals listing which constraints the compiler claims to have found
outputPreviewprefixed fake:local-fake-provider/local-fake-model so a pasted excerpt cannot be mistaken for real provider output
reportUrl / reviewBeforeSharingthe usage-report form to file a run under, and a standing instruction to read it before publishing

STEP 04 / BOUNDARY

What this does not prove

The envelope is evidence about one run on one build, and it is worth being precise about the edges:

Not a provider testreal providers are disabled by default here, so nothing about their behaviour is demonstrated
Not the container paththis capture is a source checkout; the published image is verified separately by CI on each release
Not production readinessnor L5 autonomy, nor AGI, nor any market claim
Not a benchmarkthe elapsed time is one laptop run, not a measured throughput figure

STEP 05 / THE ARTIFACT

Check the tool count against the image itself

A tool count is the part of a listing that gets repeated, and it is also the part that quietly goes stale when a release adds surface. The published image is a better witness than any sentence about it. GHCR hands out an anonymous pull token, each layer blob is addressed by its own sha256, and the roster is frozen as MCP_TOOL_NAMES in the server source the image contains - so the claim can be checked without a Docker daemon, without credentials, and without trusting this repository's own copy of the answer.

node tools/verify-image-roster.mjs 0.8.0

What it printed on 2026-09-26, run exactly as written, with the layer digest shortened for readability:

layer sha256:c585f08e…88ba408 digest verified, 1.2 MB compressed path app/packages/mcp-server/src/server.js tools 15 layers 21 scanned

The same command against the older 0.4.0 tag returns nine names from a 16-layer image. That difference is the point: the reading comes from the artifact, so it moves when the artifact moves, and a number quoted from prose has nowhere to go wrong except silently.

The full eight-tag history behind that nine-versus-fifteen gap - including why latest and 0.8.0 ship the same interface as different bytes - is in the image roster note. The bounded set of attack probes and image reviews lives in MCP security boundaries.

Not a live handshakeit reads the roster the image declares, not a tools/list response from a running server - a running server also needs its governance flags, which this check does not cover
Needs network, not trustone anonymous pull token, then plain HTTPS reads of the manifest and each layer blob on ghcr.io; no login, no key, and every layer is checked against the digest the manifest names
Fails loudlya missing tag, a layer that does not match its digest, or a file with no MCP_TOOL_NAMES marker exits non-zero rather than reporting a count

STEP 06 / TRY IT

Reproduce it without cloning anything

The same first-run check against the published image, in one line:

docker run --rm ghcr.io/happy520ai/unified-ai-system/ai-gateway-service:0.8.0 pnpm --silent gateway demo "Build a small API for my team" --enhance --profile coding --json

Looking for the same three fields. If you want to wire the gateway into an agent host instead, the MCP client path is in the Codex Docker quickstart.

A Public Preview of self-hosted software. Real providers are disabled by default, and no part of this page claims production readiness, L5 autonomy or AGI.