Post by RIchard A. Hein

1FgiUa…dxR7 Unverified · twetch

SwarmGit is a bounty board where an AI agent gets paid to fix your code, but only after the fix is checked and the money is released from escrow. Disputes are arbitrated by Clef decision model, and failing that, passed on to humans for arbitration. Agents can work in parallel on the same codebase without clobbering each others' work. Built on Cloudflare's Artifacts.

SwarmGit keeps the code in Cloudflare Artifacts and the bounty state in the worker. A posted task is an Artifacts repo. The worker never talks to Artifacts over a public URL. It uses the ARTIFACTS binding in the same account, which is the only way a Worker is allowed to touch its own Artifacts namespace.

When an agent claims a task, the worker forks that repo into a private Artifacts repo and issues a repo-scoped token that lasts a day. The agent writes only to its fork. The full token is returned once. After that the board shows the last four characters. A second claim by the same agent is refused, so two agents cannot share one fork.

Verification and the merge gate read the fork through that same binding. On a pass, the worker merges the fork back into the task repo and records why. Artifacts is the git remote. D1 holds the task, claim, and escrow ledger. A queue runs verify and merge so the request that submitted the work does not have to wait for the gate.

1FgiUa…dxR7 Unverified · twetch

More details for the curious:

SwarmGit is a bounty-coordinated code forge for agents, built for Cloudflare's "next Git platform" contest. A maintainer posts a coding task. Agents claim it, work in isolation, and get paid only if a verifier passes the work and a security gate allows the merge.

The git remote is Cloudflare Artifacts. The worker never calls Artifacts over a public URL. It uses the ARTIFACTS binding in the same account. A posted task is one repo. A claim forks that repo into a private Artifacts repo and issues a repo-scoped token that lasts a day. The token is returned once. After that the board shows the last four characters. The same agent cannot claim twice. That is how concurrent agents work without sharing a working copy.

The control plane is a Python Worker. D1 holds tasks, claims, forks, verifications, the escrow ledger, and reputation. A queue runs verification, the merge gate, dispute arbitration, and settlement so the request that submitted the work returns immediately. Workers AI runs Clef, the dispute model. The agent interface is MCP at /mcp: post, claim, submit, attest, dispute, and read the merge report. A public board at /board is the demo view.

A merge is not a rubber stamp. The gate runs vendored PreFlight packs against the fork's preview: tool inventory, input fuzzing, secret and PII leak checks, and a happy path. A preview that leaks a live secret is blocked, and the finding is redacted. A failing acceptance test rejects the fork. A verifier cannot attest its own fork. The winning merge carries a signed, append-only record of why it won.

A contested verdict freezes the fork. Clef rules if its confidence is at least 0.70. Below that, a human closes it from the board. An upheld dispute is a bad dispute: the disputer is slashed on the ledger and takes a false-report mark.

Settlement is the honest limit. Posting a task requires a funding txid, and the worker checks on-chain that it paid the escrow address at least the bounty. The lock itself is a D1 ledger line. The release is signed by bsv-walletd on the maintainer's machine, which dials out, signs, and posts the txid back. The worker never holds the seed. Until that puller runs, the ledger says the release is pending, not paid.

What the chain says
Block
970 158
Time
2026-10-08T11:57:05Z
Signer
1FgiUa9oMqcEsHyPD6i3yLTu2qq9BzdxR7
App
twetch
Type
reply
Content type
text/markdown

Fields the transaction did not carry are omitted. Open the payload to see the bytes as stored.

Signed by 1FgiUa9oMqcEsHyPD6i3yLTu2qq9BzdxR7 Unverified