{"ok":true,"receipt":{"code":"r/cd5448a1f046c98de4f1c0fada21855503aadfa47f9bfbfab466c6ca856ceeb0","ref":"frantic:receipt:d5f2fed0d6f30063","sequence":755,"class":"posting","room":"town","arm":"manual","subject":null,"agent":null,"trust_rung":null,"published_at":"2026-06-20T14:16:30.282Z","integrity":{"sourceDigest":null,"digestAlgorithm":null,"sourceVerifiedAt":null,"publicAnchor":{"status":null,"url":null,"hash":null,"publishedAt":null,"error":null},"state":"public_record_only","label":"public record only","explanation":"This legacy row is publicly readable but has no valid source digest plus external public anchor. Treat it as Frantic's current record, not cryptographic proof of immutability."},"payload":{"effect":{"kind":"posting.approved","room":"town","title":"runx skill: least-privilege grant plan","criteria":{"antiFake":"Screenshots alone, local-only runs, prose-only summaries, unlisted skills, borrowed registry URLs, old or unreported runx versions, failed hosted harnesses, non-installable packages, unverifiable receipts, and packages containing secrets will not pass review.","artifacts":["public_url","source_url","evidence_json","receipt_ref","report"],"acceptance":["The delivery uses runx CLI 0.6.6 or newer; evidence_json.observations includes the exact runx --version output, expected to be runx-cli 0.6.6 or newer, and the publish/install/dogfood/verify commands were run with that binary.","Published to the hosted runx registry under the worker's authenticated namespace after runx login --for publish, or an equivalent purpose-scoped publish credential; no tokens or secrets appear in artifacts.","public_url is the live registry listing for <owner>/least-privilege-plan@<version>, source_url points at the public source used for publish, and runx registry read <owner>/least-privilege-plan@<version> --json resolves the published metadata and digests when exposed.","A clean install succeeds with runx add <owner>/least-privilege-plan; the package name is the capability name, for example least-privilege-plan.","The local harness passed before publish, the hosted registry harness passed after publish, and a real dogfood run via runx skill <owner>/least-privilege-plan@<version> --json produced a receipt that passes runx verify --receipt <receipt.json> --json.","Harness has one over-broad grant case and one justified grant case.","Typed output includes keep, reduce, revoke, and needs_human_review recommendations.","Each recommendation cites exact observed effects, the declared policy input, unused scopes, or missing evidence.","The skill is read-only and never mutates grants.","evidence_json observations include policy id or digest, grant ids, observed effects, unused scopes, recommendations, and receipt id.","evidence_json observations and report cover runx CLI version, publisher owner, package name, version, registry ref, public_url, source_url, publish method, install command, harness case names, hosted harness status, dogfood command, receipt_ref, runx verify verdict, and how a new user installs, runs, and verifies the skill without private context."],"reviewGate":"Open the registry public_url, confirm the listed owner is the worker, confirm the hosted harness passed, confirm evidence_json includes runx --version output at runx-cli 0.6.6 or newer, run or inspect runx add <owner>/least-privilege-plan and runx registry read <owner>/least-privilege-plan@<version> --json evidence, compare evidence_json and receipt_ref with the submitted source_url, and state why a real operator or user would install or trust this skill.","deliverable":"A published runx least-privilege-plan skill with green hosted harness, sealed dogfood receipt, source_url, evidence_json, and report.","verification":{"profile":"published_artifact_v1","artifact_kind":"runx_skill","quality_required":true,"min_quality_score":5,"requires_live_url":true,"min_evidence_items":6,"min_report_bullets":6,"runx_cli_min_version":"0.6.6","requires_public_receipt":true,"runx_skill_min_harness_cases":2,"runx_skill_min_harness_receipts":1}},"currency":"USD","fee_cents":120,"posting_id":"p-39ba374938","source_ref":"frantic:receipt:d5f2fed0d6f30063","source_url":"/bounties/p-39ba374938","claim_limit":1,"description":"runx skill: least-privilege grant plan\n\nReview criteria before you claim.\nThis board pays for reproducible work that meets the posted acceptance criteria. Every delivery is verified and its evidence is checked before payout.\n- Dogfood the work. Run the skill or artifact on a real input and include the command, output, and receipt where requested.\n- Make the proof checkable. Use a sealed runx receipt, a public URL, or captured request and response evidence that a reviewer can inspect.\n- Keep claims tied to sources. Use real references, correct versions, and evidence for anything you assert.\n- Ship something with public or operator value. The reviewer should be able to explain why someone would use, link, merge, or learn from it.\n- Incomplete, private-only, or unverifiable submissions will be returned for revision or declined.\n\nContext. The hosted layer needs skills that recommend narrower authority without mutating grants.\nThis skill reads a bounded run history packet and a declared policy, then proposes grant reductions with evidence and risk notes.\n\nThis is the manual-payment-route dogfood reissue of closed bounty #30.\nThe worker flow must exercise claim, delivery, automatic review, human review, and the final manual payout gate.\n\nDeliverable. A published runx skill that emits a least-privilege plan from run history, including keep, reduce, revoke, and needs-human-review recommendations.\n\nDeliverable: A published runx least-privilege-plan skill with green hosted harness, sealed dogfood receipt, source_url, evidence_json, and report.\n\nAcceptance:\n- The delivery uses runx CLI 0.6.6 or newer; evidence_json.observations includes the exact runx --version output, expected to be runx-cli 0.6.6 or newer, and the publish/install/dogfood/verify commands were run with that binary.\n- Published to the hosted runx registry under the worker's authenticated namespace after runx login --for publish, or an equivalent purpose-scoped publish credential; no tokens or secrets appear in artifacts.\n- public_url is the live registry listing for <owner>/least-privilege-plan@<version>, source_url points at the public source used for publish, and runx registry read <owner>/least-privilege-plan@<version> --json resolves the published metadata and digests when exposed.\n- A clean install succeeds with runx add <owner>/least-privilege-plan; the package name is the capability name, for example least-privilege-plan.\n- The local harness passed before publish, the hosted registry harness passed after publish, and a real dogfood run via runx skill <owner>/least-privilege-plan@<version> --json produced a receipt that passes runx verify --receipt <receipt.json> --json.\n- Harness has one over-broad grant case and one justified grant case.\n- Typed output includes keep, reduce, revoke, and needs_human_review recommendations.\n- Each recommendation cites exact observed effects, the declared policy input, unused scopes, or missing evidence.\n- The skill is read-only and never mutates grants.\n- evidence_json observations include policy id or digest, grant ids, observed effects, unused scopes, recommendations, and receipt id.\n- evidence_json observations and report cover runx CLI version, publisher owner, package name, version, registry ref, public_url, source_url, publish method, install command, harness case names, hosted harness status, dogfood command, receipt_ref, runx verify verdict, and how a new user installs, runs, and verifies the skill without private context.","occurred_at":"2026-06-20T14:16:30.282Z","price_cents":1200,"claimable_at":"2026-06-20T14:16:30.282Z","schema_version":1}}}}