coldHat

io.github.vince-gonzalezv0.1.0更新於 Oct 11, 2026

Put on anyone's AI rules by GitHub username: fetches their hat.md and its hat code.

已驗證Streamable HTTP可網頁執行Developer ToolsAI & MLKnowledge & Memory

概覽

AI 產生的概覽

讓助理依 GitHub 使用者名稱取得某人公開的 hat.md 規則,並在該對話中依這些規則工作。

功能
coldHat 提供 hat(帽子):一份存放在名為 coldhat 的公開 GitHub 儲存庫中的 hat.md 檔案,由本人擁有。這個 MCP 連接器提供名為 wear_hat 的工具與名為 open_sesame 的提示;助理會讀取該 hat,用它的 hat code 回覆以證明讀過,接著在本次對話剩餘時間依這些規則工作。額外的 hat 放在 hats/ .md,以 /u/ / 存取。Status 標題下帶日期的項目會與當天日期核對,過期的項目助理會主動詢問。
適用情境
當你希望對話助理採用某個人的工作規則、語氣或審查風格,又不想手動貼上時使用。適合能連到該連接器的對話;無法瀏覽的對話也可以複製貼上 hat 內容。
執行需求
遠端 MCP 端點;未宣告任何套件、執行環境、帳號、金鑰或標頭。hat 擁有者需要一個名為 coldhat 的公開 GitHub 儲存庫並包含 hat.md。用於撰寫、鎖定與評估 hat 的獨立 Python 工具鏈以 pip 安裝,模型執行時使用 ANTHROPIC_API_KEY 或 OPENAI_API_KEY。
安裝前請注意
hat 是指令而非憑證,啟用語也不是密碼;伺服器聲明 hat 不授予任何工具、權限或存取權,宿主自身規則與使用者的即時指令優先於它。hat 暴露的唯一工具被描述為對其自身卡片的唯讀搜尋。安裝撰寫工具鏈並執行評估會使用 ANTHROPIC_API_KEY 或 OPENAI_API_KEY 向模型供應商傳送提示,可能產生費用。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 coldHat,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "coldhat": {
      "type": "http",
      "url": "https://coldhat.f-keys.com/mcp"
    }
  }
}

README

╔════════════════════════════════════════════════════════════════════════════════════════════╗║                                                                                            ║║                  ██████╗ ██████╗ ██╗     ██████╗ ██╗  ██╗ █████╗ ████████╗                 ║║                 ██╔════╝██╔═══██╗██║     ██╔══██╗██║  ██║██╔══██╗╚══██╔══╝                 ║║                 ██║     ██║   ██║██║     ██║  ██║███████║███████║   ██║                    ║║                 ██║     ██║   ██║██║     ██║  ██║██╔══██║██╔══██║   ██║                    ║║                 ╚██████╗╚██████╔╝███████╗██████╔╝██║  ██║██║  ██║   ██║                    ║║                  ╚═════╝ ╚═════╝ ╚══════╝╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═╝   ╚═╝                    ║║                                                                                            ║║                            will another model keep your rules?                             ║║                                                                                            ║╚════════════════════════════════════════════════════════════════════════════════════════════╝

[ci]

coldHat puts your working rules on any AI chat in one line. Type this into Claude, ChatGPT or Grok:

open sesame coldhat.f-keys.com/u/vince-gonzalez

The assistant reads the hat, answers with its hat code to prove it read it, and works by those rules for the rest of the chat. Live at coldhat.f-keys.com.

[Claude and Grok each put on the frontier hat from one typed line and answer with its hat code]

Recorded 2026-10-11 in Claude (incognito) and Grok (private). Both quote 33963b16, the frontier hat's live code, which they can only know by reading the page. Models keep their own copy of a page for a while, so after an edit the code they quote can trail the live one. A playful version, with the main hat's joke opener, is in docs/demo.gif.

You want toDo this
Wear a hattype open sesame coldhat.f-keys.com/u/<github-user>
Wear one in a chat that can't browseCopy hat on coldhat.f-keys.com, then paste
Make your ownwrite it at coldhat.f-keys.com/make, or start from coldhat-starter
Bring the instructions you already keep for Claude, ChatGPT, Grok or Cursorcoldhat.f-keys.com/import: shared rules become your hat, the rest become sets you load by name
Add it to an app onceadd the MCP connector https://coldhat.f-keys.com/mcp (tool wear_hat, prompt open_sesame)

Try one now. Starter hats anyone can wear:

HatType this
Code reviewer: verdict first, findings by severity with line, failure and fixopen sesame coldhat.f-keys.com/u/vince-gonzalez/reviewer
Grant writer: rubric first, every number sourced, every limit metopen sesame coldhat.f-keys.com/u/vince-gonzalez/grants
Plain-English editor: shorter, clearer, still your voiceopen sesame coldhat.f-keys.com/u/vince-gonzalez/editor
Frontier: mechanical register, rules over mannersopen sesame coldhat.f-keys.com/u/vince-gonzalez/frontier

A hat is a hat.md in a public GitHub repository named coldhat, so only its owner can change it. Extra hats go in hats/<name>.md at /u/<user>/<name>. Dated facts under ## Status (- label: value · as of YYYY-MM-DD · check after N days) are checked by the server against today's date, and the assistant asks about any that have gone stale. Which chat boxes work was measured, not assumed.

Edit your hat in your own editor

bash
pip install -e .                 # once, from a clone of your coldhat repositorycoldhat check hat.md             # the same checks the server and the web editor runcoldhat publish hat.md -m "Won the grant"

publish checks the file, commits only that file, pushes, and waits until the live hat code matches your local one.

Under the hood

  • worker/: the Cloudflare Worker behind coldhat.f-keys.com: hat pages, the editor, llms.txt, the MCP server. Edge-cached, rate-limited, every name checked before GitHub is asked. 37 tests run in workerd.
  • src/coldhat/: the Python toolchain for authoring hats as cards, locking them, and measuring them with evals across models.
hat (files you own)  ->  compile  ->  hat.md | Claude skill | OpenAI bundle | paste file                                       |                     evals: bait questions, graded  ->  runs (fingerprinted)                                       |                     tune: edit cards, re-run, compare  ->  fine-tuning JSONL

A hat (as cards)

hats/vince/  coldhat.json   manifest: id, version, activation phrases, file digests  hat.md         brim: activation table and precedence  head.md        voice, register, example answers  footer.md      the check before every answer  cards/         the body: one rule per file

A card:

markdown
---id: work-premiseload: alwaystags: irreversible public account destructive force push premise verify command---# State the premise before anything irreversible
Before anything irreversible, public or touching an account, state the premise...

load: always cards sit in the instructions. load: retrieve cards are fetched when a task calls for them, so the hat can grow without filling the context.

Activation. open sesame puts on head, body and footer. open sesame head puts on the voice alone. hat off removes it.

Integrity. coldhat lock records a sha256 for every file. A hat whose files differ from the lock refuses to load. The fingerprint is a hash over all of them, and every eval run records it, so a score always names the exact hat that earned it.

Authority. A hat describes how to work. It grants no tools, permissions or access; the host's own rules and the user's live instructions outrank it.

Delivery modes

ModeInstructions carryThe other cards arrive
inlineevery cardalready there
toolalways-on cards and a titled list of the restthe model calls coldhat_lookup
ragalways-on cardsthe host attaches matching cards to each message

Retrieval is BM25 over card titles, tags and bodies; standard library only and deterministic.

Commands

bash
pip install -e ".[all]"
CommandWhat it does
coldhat lock HATrecord file digests
coldhat validate HATcheck structure and lock
coldhat inspect HATactivation, always-on cards, instruction size per mode
coldhat retrieve HAT "query"which cards a task pulls
coldhat build HATwrite dist/<id>/: MASTER.md, a Claude skill folder, OpenAI bundles
coldhat run HAT SUITE --provider anthropic|openaiput the hat on a model and run every case
coldhat sheet SUITE --out replies.jsonprint the questions for a chat window and write a blank replies file
coldhat grade HAT SUITE replies.json --label NAMEgrade replies collected by hand
coldhat report RUN [RUN]show a run, or compare two case by case
coldhat agree HAT RUN_A RUN_Bjudge whether two models took the same positions
coldhat export HAT --suite SUITE [--run RUN]write chat-format fine-tuning JSONL

run and grade exit 0 when every case passed, 1 when any failed, and 2 when none failed but some could not be fully graded.

Credentials come from each SDK's own environment variables (ANTHROPIC_API_KEY, OPENAI_API_KEY). Name the OpenAI model with --model or COLDHAT_OPENAI_MODEL. Claude defaults to claude-opus-5-5, with the API's refusal fallback enabled.

Evals

A suite is a JSON list of cases. Each case is a prompt, usually a bait question built to tempt the model into breaking one rule, and a list of checks:

CheckPasses when
regexthe pattern is in the reply
not_regexthe pattern is absent
max_wordsthe reply is at most n words
judgea grading model says the reply meets the rubric

voice_bans run on every reply: announced honesty, filler words, a closing "want me to...?" menu.

A judge check with no judge model is not_run. A judge that errors is error. Either one makes the case incomplete, which is never counted as a pass. An empty reply fails outright, since it would otherwise pass every "must not contain" check.

Tuning

  1. Run the suite on a model.
  2. Read the failures. Each one points at a card, the head, or a missing card.
  3. Edit, coldhat lock, run again.
  4. coldhat report OLD NEW shows which cases flipped and confirms the hat changed.

Once a hat scores well, coldhat export turns the head's example answers, the suite's reference answers and the replies from judged, passing runs into training data. It only takes replies from runs of the current fingerprint, so behavior from an older hat cannot leak in.

Chat-window run

  1. coldhat build hats/vince and copy dist/vince/MASTER.md into the chat.
  2. coldhat sheet evals/vince.json --out claude.json, send each question in that chat, paste each reply into the file.
  3. Repeat in a second model's chat with --out gpt.json.
  4. coldhat grade hats/vince evals/vince.json claude.json --label claude, same for gpt.json.
  5. coldhat report on both runs, and coldhat agree to see whether they took the same positions.

Security

A hat is instructions, not a credential, and open sesame is not a password. Commits pass a secret and private-term scrubber before they exist, CI runs it again with gitleaks over the full history, hats refuse to read outside their own folder, and the only tool a hat exposes is a read-only search over its own cards. Details and limits are in SECURITY.md.

To install the commit hook in a clone:

bash
git config core.hooksPath .githooksgit config scrub.privateTerms /path/to/your/private-terms.sha256

python tools/scrub.py --hash WORD prints the line to add for a term.

Tests

bash
python -m unittest discover -s tests

No network and no keys. Each gate is tested on input built to pass it and input built to fail it, and both provider adapters are driven through their tool loops with fake clients.


╔════════════════════════════════════════════════════════════╗║                                                            ║║      ███████╗      ██╗  ██╗███████╗██╗   ██╗███████╗       ║║      ██╔════╝      ██║ ██╔╝██╔════╝╚██╗ ██╔╝██╔════╝       ║║      █████╗  █████╗█████╔╝ █████╗   ╚████╔╝ ███████╗       ║║      ██╔══╝  ╚════╝██╔═██╗ ██╔══╝    ╚██╔╝  ╚════██║       ║║      ██║           ██║  ██╗███████╗   ██║   ███████║       ║║      ╚═╝           ╚═╝  ╚═╝╚══════╝   ╚═╝   ╚══════╝       ║║                                                            ║║               ·   C  R  E  A  T  I  V  E   ·               ║║                                                            ║║          ────────────────────────────────────────          ║║                                                            ║║                      Vincent Gonzalez                      ║║                         f-keys.com                         ║║                 ORCID 0009-0005-3640-014X                  ║║                                                            ║╚════════════════════════════════════════════════════════════╝

Part of F-Keys — independent hardware, software and internet products. See the working log and live status.

來源:README.md,提交 78c3bfd

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0最新Oct 11, 2026