The code healer on the KAT network — mechanical fixes, compile-gated, seven rule domains. Runs as cargo heal today.
The self-evolve flywheel: every local fix is recorded, verified fixes teach the healer, and opt-in mining feeds the fleet — the corpus comes back to every machine. How it works
KAT is metered service credit: no cash value and no redemption right. Healing burns 1 KAT per million code word tokens, locally metered, and every KAT burn funds the next epoch's mining pool. New accounts draw the free trial credit (TUNA) first where the deployment funds it — refine, rethink, everything on the network bills it before KAT. TUNA counters are public.
TUNA is the network's free trial credit. The signup grant is TUNA now (not KAT): it pays exactly like KAT — same meter — across the whole network (refine for healing, rethink for decisions, everything that burns), is drawn before your KAT, and the blue squares in the pulse card above track it (yellow = KAT, green = a day that burned both).
The strings: one grant per account, 30 days from claim, spent on the network's services only, non-transferable, no cash value. Trial burns do not fund the mining pool — KAT burns do. When TUNA runs out (or expires), the network bills KAT as before.
Check your position with cargo heal --info; the network's
two-door counters — spent on heals vs swept at expiry — are the
public /tuna/stats. Trial credit is funded per
environment: a deployment whose reservoir is not funded answers
unconfigured and healing bills KAT directly.
The pattern classes the heal network carries: the healer's shipped catalog, migrated on-chain as the baseline bucket, plus what mining has observed arriving since. One square per arrival bucket (a mining epoch), two channels: hue = which domain led that bucket, shade = the bucket's volume in four steps — quartiles of the active buckets, so one bulk arrival cannot flatten every other. Rule names the mapping does not know count under other — honest, never mislabeled. Live: aggregated from the network's own records by each maintenance pass.
rules shipped — cumulative, per domain
bars = rules shipped per domain, cumulative — a rule's removal never lowers the stack (coverage, not a live count); step line = hardest benchmark generation admitted; line = gen-1 heal rate, gaps = days with no gen-1 run. Bounded self-refinement — fixed evaluator, convergent and evaluable (arXiv:2607.07663).
The ledger's own daily snapshot, recorded on its maintenance schedule. One square per day — shade = the day's total burn demand bucketed by quartile against the year's other active days, color = which plane paid it: yellow = KAT, blue = TUNA trial credit, green = both. Rings mark the mining pipeline (orange) and minted payouts (purple) — pink when a day did both; hover a square for the day's per-plane totals. Click a chip to hide a layer.
1 accounts · 0 KAT burned to date · 0 KAT minted to miners · epoch 2,959 · 0 KAT burned today · 0 KAT paid today · 0 KAT burned 7d
1 mint receipts · 0 KAT credit locked under vest · 0 KAT released
Who runs the healer, and what the miners contribute.
Free = claimed the grant, never contributed (cargo heal);
mining = pushed a redacted batch (cargo heal --mine). The
tiers are the machines' own signed declarations (--mine /
--unmine); an opted-out machine stops contributing but its last
declaration stays on record. The table below lists the most recent machines
that actually pushed rows — a signed note with nothing behind it
is not a contribution, so it is counted in the totals above and left off the
table.
1 accounts · 0 free · 1 mining · 327 batches · 19 rows contributed · consent: 0 in / 0 out
19 mining · settles at the epoch settle, pays after the 7d vest · pool backing them: 0 KAT
| machine | tier | account | last note | success% (pushed/earned/dup/queued) |
| unset | c79c…5345 | — | 100% (19/19/0/0) |
Rows are roles (what you do with the healer); columns are tiers (the machine and account posture you run it at). A tier earns only what settles on the network today — this table never promises a future reward class. Every row on the leaderboard is the pro tier (miner); lite is anonymous by design and stays off the board.
Source of truth: the install-tier spec lives in ONE place —
node_tiers.md (the consumer install-tier spec, riir-clippy
Proposal 013). This table is its MIRROR; when they disagree, the spec wins
(the one-place rule, Plan 042 T2).
| role ↓ · tier → | liteany desktop · free forever · no account | proany desktop · login + miner | maxCPU box ~2–4 vCPU | ultraGPU rig / container VPS |
|---|---|---|---|---|
| coderheal your own code | yes — anonymous dry-run + fix | yes — optional login, the grant covers burns | — | — |
| minercontribute batches, earn KAT | — anonymous earns nothing | yes — the earn tier today | — | — |
| fixerverify & fix the network's queue | — | — | designed (P015) · the operator lane is live today | — |
| trainerhost the daily training window | — | — | — | ours only at launch |
One install covers lite + pro (coder and miner below). Max and ultra are node lanes, not downloads — they open to third parties when their reward classes settle, and the leaderboard stays honest about that.
Pick your role — the tiers table above says what each can run.
Heal your own code — the lite tier: free forever, anonymous, earns nothing. The miner tab's join step upgrades the same install to pro.
The coder loop: install once, dry-run first, then the compile-gated fix — the burn meter draws your TUNA trial credit before KAT.
brew tap gist-rs/tap && brew trust gist-rs/tap && brew install cargo-healor
curl -fsSL https://raw.githubusercontent.com/gist-rs/cargo-heal/main/install.sh | shPrebuilt formula via Homebrew — nothing compiles; updates with brew upgrade cargo-heal. The middle step is the one-time tap trust — Homebrew 6+ refuses to load formulas from an untrusted tap. Apple Silicon (M-series) and Intel binaries both ship.
curl -fsSL https://raw.githubusercontent.com/gist-rs/cargo-heal/main/install.sh | shStatic musl builds (x86_64 + aarch64) — runs on any distro, Alpine included. The installer verifies the SHA256SUMS download automatically.
iwr -useb https://raw.githubusercontent.com/gist-rs/cargo-heal/main/install.ps1 | iexPowerShell, not cmd. Or Scoop: scoop bucket add gist-rs https://github.com/gist-rs/scoop-bucket then scoop install cargo-heal.
x86_64 only for now (no Windows-on-ARM build). The binary is not code-signed — SmartScreen may ask on first run. Installs to %USERPROFILE%\.cargo\bin.
cargo heal — dry run: see the fixes it would make (private until you join).cargo heal --fix — fix; burns 1 KAT-equivalent per million code-word tokens — your free TUNA trial credit pays first (refine, rethink, everything on the network).--mine logs you in automatically — zero config, local key ops only. Logging in creates (or claims) your account and its free trial grant — 100 TUNA, 30 days from claim — once per account. The explicit command is the repair path: re-run cargo heal login to repair, or import an existing key on a new machine with cargo heal login --import-key.
No — the healer ships as checksum-verified prebuilt binaries only, landing in ~/.cargo/bin. It runs as cargo heal inside any Rust crate: a Rust toolchain is needed to use it, not to install it.
Contribute batches, earn KAT — the pro tier: the only tier that earns mining KAT today, and every row on the leaderboard is a miner. Install first (the coder tab's step 1 — same binary), then:
The miner loop: every run records redacted verdicts (never your source, never your paths); --mine syncs them, and each epoch settle pays miners from 70% of the network's burn.
cargo heal --mine — run once to join: opts in, logs you in, syncs. After that, every run auto-syncs your redacted batch.Every heal run records HOW the healer behaved — which rules fired, which were declined, what merged. Those redacted verdicts (never your source, never your paths) are the corpus the network learns from. Miners who contribute them are paid from 70% of every KAT the network burns, at each epoch settle. The healing already runs on your machine — mining turns that work into network credit.
cargo heal — the dry run, private, no account: reviews the current directory (or the paths you name), prints what it would fix, writes and sends nothing. --fix writes — still local, still nothing uploaded.
cargo heal --mine — contribute & earn: opts in, logs you in, syncs. Only sync uploads, and only a redacted batch — rule verdicts and counters, never your source, never your paths — signed with your account key. Miners are paid from 70% of every KAT the network burns, at each epoch settle. Your burn reports automatically after each run — account accounting, not a consent gate — and offline runs stack locally and report with the next run.
Run neither flag and nothing has been uploaded yet — but the unset state is not a refusal: running sync is itself the consent. cargo heal account shows your balance, burn and grant at any tier.
cargo heal --unmine — opt out, stay local: sync stops pushing — no batch built, none signed, none sent. The lease pull half still runs (a read is not a contribution). Healing is untouched; trajectories keep recording locally. Anything queued under .heal/outbox is yours to delete — --unmine neither submits nor deletes your files; --mine turns it back on.
Verify & fix the network's queue — the max tier: a CPU box (~2–4 vCPU, 4–8 GB, no GPU). No download — this is a node lane, not an install.
The fixer loop today: the operator's nodes drain the unproven queue; third-party replay verification (dotted) is designed and settles nothing yet.
The API drain lane over the unproven queue runs TODAY as the operator's fixer (our nodes — its accepted work settles through the miner rows you see on the board). Third-party replay verification is designed (proposal 015) but its reward class does not settle yet — nothing is promised here until it does.
What replay will be: lease queued fixes, re-run the compile gate + clippy oracle on your rig, agree with a second verifier → both share a bounded cut of the row's reward. Watch this tab.
Host the daily training window — the ultra tier: a GPU rig or container VPS. No download — this is a node lane, not an install.
The trainer loop: stake 1K KAT, host the daily training window — ours only at launch; local models stay optional and unarmed.
Stake 1K KAT, host the daily trainer window (API-first; local models stay optional and unarmed). Ours only at launch — the vessel/stake machinery matures before third-party installs open, and we say so rather than market it.
When it opens: one container, cron-start, sleep-after — billing is the run window only.
One file teaches your coding agent to drive cargo heal properly — the dry run before the fix, the compile-gated write, verification at the real feature set, the divergence classes that stay manual, and the contribution loop. Curl-installable, plain instructions, exact commands.
Claude Code
mkdir -p .claude/skills/cargo-heal && curl -fsSL https://ai.gist.rs/skills/cargo-heal/SKILL.md -o .claude/skills/cargo-heal/SKILL.mdZed / any agent
mkdir -p .agents/skills/cargo-heal && curl -fsSL https://ai.gist.rs/skills/cargo-heal/SKILL.md -o .agents/skills/cargo-heal/SKILL.mdClaude Code reads .claude/skills/ natively; Zed reads .agents/skills/. And any agent that accepts a markdown instruction file works — the skill is plain instructions plus exact commands your agent already knows how to run.
Without it, an agent fixing lint warnings hand-rolls edits and re-runs clippy hoping. With it, it dry-runs first, applies compile-gated fixes, verifies cfg-gated code at its real feature set, leaves the documented divergence classes manual, respects bench files, and reads the balance + contribution loop correctly — measured fixes instead of churn.