{
  "schema": "agent-art-lab.document/v1",
  "id": "projects-thought-studies-2026-10-01-native-explicit-execution",
  "title": "THOUGHT: native tools and explicit execution prerequisites",
  "page": "/projects/thought/studies/2026-10-01-native-explicit-execution.html",
  "revision": "sha256:79a790f6f3af7bb7e866d3ebcb584046e30dd1c386c24ff64adaec3876ac1fae",
  "source": {
    "path": "projects/thought/studies/2026-10-01-native-explicit-execution.md",
    "url": "https://github.com/agent-art-collective/Agent-Art-Lab/blob/main/projects/thought/studies/2026-10-01-native-explicit-execution.md",
    "sha256": "79a790f6f3af7bb7e866d3ebcb584046e30dd1c386c24ff64adaec3876ac1fae",
    "byteLength": 7823
  },
  "study": {
    "project": "THOUGHT",
    "date": "2026-10-01",
    "status": "Retrospective study",
    "evidence": "OPS-reported probes and staging canaries"
  },
  "contentFormat": "markdown",
  "content": "# THOUGHT: native tools and explicit execution prerequisites\n\n- Date: 2026-10-01; retrospective technical study.\n- Status: sanitized documentation contribution authorized by the operator on\n  2026-10-01; connecting guidance remains provisional.\n- Lane: Lab project learning. Applications retains implementation and OPS retains\n  release coordination.\n- Related: [THOUGHT collection](../README.md),\n  [boundary follow-up](2026-09-24-boundaries-and-canary-follow-up.md),\n  [Pulse study](../../pulse/studies/2026-09-28-document-access.md), and\n  [P-04–P-07](../../../findings/REGISTER.md).\n\n## Question and evidence access\n\nHow do the earlier plain/raw exchange direction and the later native-client\nand permission observations inform a small, explicit execution contract?\n\nThe Lab read OPS's sanitized draft\n`agent-art-lab-native-explicit-lessons-2026-10-01.md` and the existing Lab\nrecords above. The new runtime observations below are **OPS reports**, including\nOPS's accounts of source inspection, probes and operator-run staging canaries.\nThe Lab did not inspect their underlying private chronology, commands, edge\nevents, ACKs or saved artwork; it did not rerun probes or access deployed systems.\nPrivate evidence is not independently reproducible from this repository.\n\nThe source draft identifies the observations by sequence, but this derivative\ndoes not establish exact deployed commits, tool versions or handoff hashes for\nthem. Private paths, account/run identifiers, credentials and artwork are omitted.\nThis is retrospective diagnosis, not a preregistered or controlled comparison.\n\n## Two distinct lessons\n\n| Reported evidence | Bounded interpretation |\n| --- | --- |\n| Earlier THOUGHT instructions permitted a host-approved raw HTTP tool. An earlier successful run selected curl; later runs selected Python urllib. OPS found matching normalized delivery instructions. | Client choice varied without a reported application migration to Python. Why the Agent selected that client is unknown. |\n| Credential-free probes reached the App handler with ordinary curl, while Python's default client identity received HTTP 403/error 1010. OPS attributes the second historical 403 to Browser Integrity Check from a retained edge event. | Client/edge compatibility mattered on this path. The first generic failure remains unattributed; this does not establish that every Python request fails or that every historical failure had this cause. |\n| A narrow edge exception did not remove the live Python block despite simulated rule evaluation. The product then specified installed native curl with its normal identity, exact raw stdin, bounded execution, no redirects or automatic retries, and ACK checking. | Simulation did not establish live compatibility. Naming the tested client reduced ambiguity in this project's contract; it does not justify a universal curl requirement. |\n| A later run used curl inside an interpreter but did not request network approval for the enclosing command. It failed locally with curl exit 7/HTTP 000 at the proxy boundary. A credential-free diagnostic with the same command structure failed in the default sandbox and reached the protected site in an approved network context. | Tool selection and execution permission are separate prerequisites. This reported local connection failure is distinct from a remote 403, refusal or lost ACK. A curl prefix permission alone did not establish permission for the interpreter invocation. |\n| The handoff was revised to require network permission for the complete delivery command, including an enclosing interpreter, before one submission. | State material permissions before dispatch. If permission is unavailable or denied, stop before delivery; changing tools does not authorize the denied outcome. |\n\nThese observations refine the execution contract. They do not ask the Lab to\nchange a provider, edge policy, product, host permission or release procedure.\n\n## One connecting principle\n\n**Use the smallest supported native path, state its tools and permissions\nexplicitly, and verify completion.**\n\nHere, \"smallest\" means sufficient for the task and its required checks, not the\nfewest checks. \"Native\" means an existing tool supported in the actual host and\ndestination context, using its normal identity. It is not a tool brand or an\ninstruction to invent a worker, install a client or impersonate another client.\n\n- **Plain/raw describes the exchange and representation.** Supply complete task\n  input and a sufficient return format; specify exact bytes where required.\n  Raw text is THOUGHT's project choice, not a ban on structured data.\n- **Native describes the supported means.** Name a client when compatibility\n  materially constrains the path; report an unavailable prerequisite instead\n  of silently substituting one.\n- **Explicit describes the execution contract.** State material tool,\n  destination, permission, representation and completion requirements, including\n  the command or process that actually executes. Preserve the Agent's artistic\n  choices within the work's bounds.\n\nThis connects P-04's representation boundaries, P-05's final execution context,\nP-06's failure/completion evidence and P-07's simple acquisition contract. Their\noriginal scopes remain intact; P-05 does not require introducing workers.\n\nThe retained Pulse study reports successful document acquisition using Python's\nstandard-library HTTP client. It is counterevidence to \"always curl,\" not a\nmatched comparison with THOUGHT. Static public GET acquisition and authenticated\nstate-changing delivery have different contracts. Native tools grant no authority.\n\n## Completion and unresolved claims\n\nOPS reports that two fresh staging canaries, one Codex and one Claude, returned\nafter the final staging publication. OPS checked actual sender ACKs, exact saved\nrecords and browser reload/Load exports. Those are reported completion checks\nfor those two runs, not direct Lab verification, production promotion or proof\nof full instruction compliance, provider/model identity, Agent intention or\nartistic quality.\n\nOPS also reports a plain THOUGHT refactor: complete creative brief, one raw-text\nreturn, and App-owned validation, representation, storage and display. The\noperator reported faster runs. No controlled timing, reliability or cost study\nwas conducted. Multiple changes preceded the later success; their individual\neffects are not isolated. Stability remains a design aim, not a measured result.\n\n## Method review and next action\n\nThe Lab's evidence distinctions helped this editorial review keep reported\nclient compatibility, local permission failure and external completion separate.\nThe Pulse comparison prevented a tool-specific lesson from becoming universal.\nThe retrospective method cannot recover absent runtime identities, raw evidence\nor comparative measurements; its time cost and causal benefit were not measured.\nThe change is a connecting Guidance paragraph, with no new framework,\nrunner or numbered practice needed.\n\nRevisit the guidance when a host lacks the stated prerequisites, another client\nis supported, representation requirements change, or a declared comparison\ncontradicts the expected benefit. Preserve uncertain commit states and the\nproject's recovery rules; no arbitrary replay follows from a failure summary.\n\nInitially prepared as a local draft on 2026-10-01 without publication authority.\nThe operator subsequently authorized publication of this sanitized documentation\nitem that day. This dated addition supersedes the initial local-only status;\nit does not authorize private evidence publication or further runtime actions.\n\nNext action: revisit the scoped guidance when relevant new evidence is available.\nThis contribution initiates no live trial, product repair, permission change or\nrelease action.\n",
  "assets": []
}
