
coldHat
io.github.vince-gonzalezv0.1.0更新于 Oct 11, 2026
Put on anyone's AI rules by GitHub username: fetches their hat.md and its hat code.
概览
让助手按 GitHub 用户名获取某人的公开 hat.md 规则,并在该对话中按这些规则工作。
- 功能
- coldHat 提供 hat(帽子):一份保存在名为 coldhat 的公开 GitHub 仓库中的 hat.md 文件,由本人拥有。该 MCP 连接器提供名为 wear_hat 的工具和名为 open_sesame 的提示;助手读取该 hat,用其 hat code 作答以证明已读取,然后在本次对话余下时间遵循这些规则。额外的 hat 放在 hats/ .md,以 /u/ / 访问。Status 标题下带日期的条目会与当天日期核对,过期的条目助手会主动询问。
- 适用场景
- 当你希望对话助手采用某个人的工作规则、语气或评审风格,而不想手动粘贴时使用。适合能访问该连接器的对话;无法浏览的对话也可以复制粘贴 hat 内容。
- 运行要求
- 远程 MCP 端点;未声明任何软件包、运行时、账号、密钥或请求头。hat 拥有者需要一个名为 coldhat 的公开 GitHub 仓库并包含 hat.md。用于编写、锁定和评估 hat 的独立 Python 工具链通过 pip 安装,模型运行时使用 ANTHROPIC_API_KEY 或 OPENAI_API_KEY。
安装
在 SourceWeft 中
- 打开 控制台中的 coldHat,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"coldhat": {
"type": "http",
"url": "https://coldhat.f-keys.com/mcp"
}
}
}README
coldHat puts your working rules on any AI chat in one line. Type this into Claude, ChatGPT or Grok:
The assistant reads the hat, answers with its hat code to prove it read it, and works by those rules for the rest of the chat. Live at coldhat.f-keys.com.
[Claude and Grok each put on the frontier hat from one typed line and answer with its hat code]
Recorded 2026-10-11 in Claude (incognito) and Grok (private). Both quote 33963b16, the frontier
hat's live code, which they can only know by reading the page. Models keep their own copy of a
page for a while, so after an edit the code they quote can trail the live one. A playful
version, with the main hat's joke opener, is in docs/demo.gif.
Try one now. Starter hats anyone can wear:
A hat is a hat.md in a public GitHub repository named coldhat, so only its owner can
change it. Extra hats go in hats/<name>.md at /u/<user>/<name>. Dated facts under
## Status (- label: value · as of YYYY-MM-DD · check after N days) are checked by the
server against today's date, and the assistant asks about any that have gone stale.
Which chat boxes work was measured, not assumed.
Edit your hat in your own editor
publish checks the file, commits only that file, pushes, and waits until the live hat code
matches your local one.
Under the hood
worker/: the Cloudflare Worker behind coldhat.f-keys.com: hat pages, the editor,llms.txt, the MCP server. Edge-cached, rate-limited, every name checked before GitHub is asked. 37 tests run in workerd.src/coldhat/: the Python toolchain for authoring hats as cards, locking them, and measuring them with evals across models.
A hat (as cards)
A card:
load: always cards sit in the instructions. load: retrieve cards are fetched
when a task calls for them, so the hat can grow without filling the context.
Activation. open sesame puts on head, body and footer. open sesame head
puts on the voice alone. hat off removes it.
Integrity. coldhat lock records a sha256 for every file. A hat whose files
differ from the lock refuses to load. The fingerprint is a hash over all of
them, and every eval run records it, so a score always names the exact hat
that earned it.
Authority. A hat describes how to work. It grants no tools, permissions or access; the host's own rules and the user's live instructions outrank it.
Delivery modes
Retrieval is BM25 over card titles, tags and bodies; standard library only and deterministic.
Commands
run and grade exit 0 when every case passed, 1 when any failed, and 2 when
none failed but some could not be fully graded.
Credentials come from each SDK's own environment variables
(ANTHROPIC_API_KEY, OPENAI_API_KEY). Name the OpenAI model with --model
or COLDHAT_OPENAI_MODEL. Claude defaults to claude-opus-5-5, with the API's
refusal fallback enabled.
Evals
A suite is a JSON list of cases. Each case is a prompt, usually a bait question built to tempt the model into breaking one rule, and a list of checks:
voice_bans run on every reply: announced honesty, filler words, a closing
"want me to...?" menu.
A judge check with no judge model is not_run. A judge that errors is error.
Either one makes the case incomplete, which is never counted as a pass. An
empty reply fails outright, since it would otherwise pass every "must not
contain" check.
Tuning
- Run the suite on a model.
- Read the failures. Each one points at a card, the head, or a missing card.
- Edit,
coldhat lock, run again. coldhat report OLD NEWshows which cases flipped and confirms the hat changed.
Once a hat scores well, coldhat export turns the head's example answers, the
suite's reference answers and the replies from judged, passing runs into
training data. It only takes replies from runs of the current fingerprint, so
behavior from an older hat cannot leak in.
Chat-window run
coldhat build hats/vinceand copydist/vince/MASTER.mdinto the chat.coldhat sheet evals/vince.json --out claude.json, send each question in that chat, paste each reply into the file.- Repeat in a second model's chat with
--out gpt.json. coldhat grade hats/vince evals/vince.json claude.json --label claude, same forgpt.json.coldhat reporton both runs, andcoldhat agreeto see whether they took the same positions.
Security
A hat is instructions, not a credential, and open sesame is not a password. Commits pass a secret and private-term scrubber before they exist, CI runs it again with gitleaks over the full history, hats refuse to read outside their own folder, and the only tool a hat exposes is a read-only search over its own cards. Details and limits are in SECURITY.md.
To install the commit hook in a clone:
python tools/scrub.py --hash WORD prints the line to add for a term.
Tests
No network and no keys. Each gate is tested on input built to pass it and input built to fail it, and both provider adapters are driven through their tool loops with fake clients.
Part of F-Keys — independent hardware, software and internet products. See the working log and live status.
来源:README.md,提交 78c3bfd
工具
0版本历史
1- v0.1.0最新Oct 11, 2026


