Refine — the code healer

The code healer on the KAT network — mechanical fixes, compile-gated, seven rule domains. Runs as cargo heal today.

--mine (opt-in)

leased back

the KAT fleet

auto-sync

mining batch

proof queue

KAT payout

corpus grows

your crate

verified outcomes

scan

retrieve

draft

validate

fix

record

learn

The self-evolve flywheel: every local fix is recorded, verified fixes teach the healer, and opt-in mining feeds the fleet — the corpus comes back to every machine. How it works

What is KAT?

KAT is metered service credit: no cash value and no redemption right. Healing burns 1 KAT per million code word tokens, locally metered, and every KAT burn funds the next epoch's mining pool. New accounts draw the free trial credit (TUNA) first where the deployment funds it — refine, rethink, everything on the network bills it before KAT. TUNA counters are public.

What is TUNA?

TUNA is the network's free trial credit. The signup grant is TUNA now (not KAT): it pays exactly like KAT — same meter — across the whole network (refine for healing, rethink for decisions, everything that burns), is drawn before your KAT, and the blue squares in the pulse card above track it (yellow = KAT, green = a day that burned both).

The strings: one grant per account, 30 days from claim, spent on the network's services only, non-transferable, no cash value. Trial burns do not fund the mining pool — KAT burns do. When TUNA runs out (or expires), the network bills KAT as before.

Check your position with cargo heal --info; the network's two-door counters — spent on heals vs swept at expiry — are the public /tuna/stats. Trial credit is funded per environment: a deployment whose reservoir is not funded answers unconfigured and healing bills KAT directly.

Healer corpus — pattern classes per domain
How to read this

The pattern classes the heal network carries: the healer's shipped catalog, migrated on-chain as the baseline bucket, plus what mining has observed arriving since. One square per arrival bucket (a mining epoch), two channels: hue = which domain led that bucket, shade = the bucket's volume in four steps — quartiles of the active buckets, so one bulk arrival cannot flatten every other. Rule names the mapping does not know count under other — honest, never mislabeled. Live: aggregated from the network's own records by each maintenance pass.

OctNovDecJanFebMarAprMayJunJulAugSep
MonWedFri
kernel_optrust_perfclippydockersecdistother
kernel_opt607
rust_perf126
clippy52
docker31
sec15
dist5
other1
Self-evolve

rules shipped — cumulative, per domain

2026-08-132026-08-292026-09-17
kernel_optrust_perfclippysecdockerdistother

bars = rules shipped per domain, cumulative — a rule's removal never lowers the stack (coverage, not a live count); step line = hardest benchmark generation admitted; line = gen-1 heal rate, gaps = days with no gen-1 run. Bounded self-refinement — fixed evaluator, convergent and evaluable (arXiv:2607.07663).

Network pulse
How to read this

The ledger's own daily snapshot, recorded on its maintenance schedule. One square per day — shade = the day's total burn demand bucketed by quartile against the year's other active days, color = which plane paid it: yellow = KAT, blue = TUNA trial credit, green = both. Rings mark the mining pipeline (orange) and minted payouts (purple) — pink when a day did both; hover a square for the day's per-plane totals. Click a chip to hide a layer.

OctNovDecJanFebMarAprMayJunJulAugSep
MonWedFri
KAT burnTUNA (trial) burnboth planes

1 accounts · 0 KAT burned to date · 0 KAT minted to miners · epoch 2,959 · 0 KAT burned today · 0 KAT paid today · 0 KAT burned 7d

1 mint receipts · 0 KAT credit locked under vest · 0 KAT released

Network adoption
Who counts here

Who runs the healer, and what the miners contribute. Free = claimed the grant, never contributed (cargo heal); mining = pushed a redacted batch (cargo heal --mine). The tiers are the machines' own signed declarations (--mine / --unmine); an opted-out machine stops contributing but its last declaration stays on record. The table below lists the most recent machines that actually pushed rows — a signed note with nothing behind it is not a contribution, so it is counted in the totals above and left off the table.

1 accounts · 0 free · 1 mining · 327 batches · 19 rows contributed · consent: 0 in / 0 out

19 mining · settles at the epoch settle, pays after the 7d vest · pool backing them: 0 KAT

100%50%0
Feb 26Jun 11Oct 1
mining users / epochearned records / epoch
machinetieraccountlast notesuccess% (pushed/earned/dup/queued)
unsetc79c…5345—100% (19/19/0/0)
node tiers — what you can run
How to read this

Rows are roles (what you do with the healer); columns are tiers (the machine and account posture you run it at). A tier earns only what settles on the network today — this table never promises a future reward class. Every row on the leaderboard is the pro tier (miner); lite is anonymous by design and stays off the board.

Source of truth: the install-tier spec lives in ONE place — node_tiers.md (the consumer install-tier spec, riir-clippy Proposal 013). This table is its MIRROR; when they disagree, the spec wins (the one-place rule, Plan 042 T2).

role ↓ · tier → liteany desktop · free forever · no account proany desktop · login + miner maxCPU box ~2–4 vCPU ultraGPU rig / container VPS
coderheal your own code yes — anonymous dry-run + fix yes — optional login, the grant covers burns ——
minercontribute batches, earn KAT — anonymous earns nothing yes — the earn tier today ——
fixerverify & fix the network's queue —— designed (P015) · the operator lane is live today —
trainerhost the daily training window ——— ours only at launch

One install covers lite + pro (coder and miner below). Max and ultra are node lanes, not downloads — they open to third parties when their reward classes settle, and the leaderboard stays honest about that.

Get started

Pick your role — the tiers table above says what each can run.

Heal your own code — the lite tier: free forever, anonymous, earns nothing. The miner tab's join step upgrades the same install to pro.

install cargo-heal

cargo heal — dry run
private · nothing sent

cargo heal --fix
compile-gated writes

GET — healed code
warnings · errors · perf · sec
docker · compile errors

COST — the burn meter
1 KAT-equiv / 1M code-word tokens
TUNA trial credit pays first

no login = lite tier
free forever · anonymous
earns nothing

login — optional

100 TUNA trial grant
30 days from claim

The coder loop: install once, dry-run first, then the compile-gated fix — the burn meter draws your TUNA trial credit before KAT.

1install — pick your operating system:
brew tap gist-rs/tap && brew trust gist-rs/tap && brew install cargo-heal

or

curl -fsSL https://raw.githubusercontent.com/gist-rs/cargo-heal/main/install.sh | sh
About this command

Prebuilt formula via Homebrew — nothing compiles; updates with brew upgrade cargo-heal. The middle step is the one-time tap trust — Homebrew 6+ refuses to load formulas from an untrusted tap. Apple Silicon (M-series) and Intel binaries both ship.

2cargo heal — dry run: see the fixes it would make (private until you join).
3cargo heal --fix — fix; burns 1 KAT-equivalent per million code-word tokens — your free TUNA trial credit pays first (refine, rethink, everything on the network).
Why login?

--mine logs you in automatically — zero config, local key ops only. Logging in creates (or claims) your account and its free trial grant — 100 TUNA, 30 days from claim — once per account. The explicit command is the repair path: re-run cargo heal login to repair, or import an existing key on a new machine with cargo heal login --import-key.

Is it on crates.io?

No — the healer ships as checksum-verified prebuilt binaries only, landing in ~/.cargo/bin. It runs as cargo heal inside any Rust crate: a Rust toolchain is needed to use it, not to install it.

Give your coding agent a code healer.

One file teaches your coding agent to drive cargo heal properly — the dry run before the fix, the compile-gated write, verification at the real feature set, the divergence classes that stay manual, and the contribution loop. Curl-installable, plain instructions, exact commands.

Claude Code

mkdir -p .claude/skills/cargo-heal && curl -fsSL https://ai.gist.rs/skills/cargo-heal/SKILL.md -o .claude/skills/cargo-heal/SKILL.md

Zed / any agent

mkdir -p .agents/skills/cargo-heal && curl -fsSL https://ai.gist.rs/skills/cargo-heal/SKILL.md -o .agents/skills/cargo-heal/SKILL.md
Which agents does it work with?

Claude Code reads .claude/skills/ natively; Zed reads .agents/skills/. And any agent that accepts a markdown instruction file works — the skill is plain instructions plus exact commands your agent already knows how to run.

What does it change?

Without it, an agent fixing lint warnings hand-rolls edits and re-runs clippy hoping. With it, it dry-runs first, applies compile-gated fixes, verifies cfg-gated code at its real feature set, leaves the documented divergence classes manual, respects bench files, and reads the balance + contribution loop correctly — measured fixes instead of churn.

Links