PTENES
Skip to content
MODULE 4.4

🧪 Lab and final project

First, the right place for reverse engineering: the lab, with a date and a label. Then, the final project: one of your own systems without an API becomes a bridge, a team of three roles works on it, and the verifier proves it's ready.

6
Topics
~35
Minutes
runtime/
Deliverable
Project
Type
0 of 60%
1

Go back to the ladder before the lab

The urge to "open up the program from the inside" comes up when something seems impossible. Before that, there’s a rule in the LEIA-ME.md and of the AGENTS.md: climb the ladder and test each level with a command.

The lab is step 7. You get there only after the six steps above answer “no,” with evidence. Often, the route exists; it just wasn’t documented.

1 · API 2 · MCP 3 · CLI 4 · SDK 5 · computer 6 · local bridge 7 · reverse engineering lab each step: one test command stop at the first path that works

How to read the diagram: the ladder goes from most stable (amber) to most fragile. The dashed red line separates the six production steps from step 7, which is for the lab only.

🎯 Objective: have evidence for each step before considering a lab

Open claude (or codex) in the kit folder and paste, replacing the system name:

Leia runtime/LEIA-ME.md e suba a escada das vias para o <meu sistema>. Para cada nível, de API até ponte local, diga qual comando ou menu testa esse nível e o que você encontrou. Não conclua "não dá" sem mostrar o teste de cada nível.
How to verify: the answer has six levels, each with a test and a result. If any level comes without a test, ask again for just that one.
🪜
Ladder

the highest available

🧾
Evidence

one test per level

📤
Export

almost always exists

🧪
Step 7

only after six

2

Treat reverse engineering as a lab

A POLITICA.md says in one line: reverse engineering is a lab: write it down in LIMITES.md and don't use it in production. A lab means a test machine, test data, and an expiration date.

The lab’s goal is to answer one question: “where does this program communicate?” Once you find the answer, go back to the ladder and look for the official route that does the same thing.

🆕 New here? Test machine and the "fragile" label

Test machine is a computer (or virtual machine) without your real data or logged-in accounts. If something goes wrong, nothing valuable is lost. "Fragile" label it’s writing next to the finding that it may break in the next update and the date it was tested.

1

Separate the machine

Don’t test on Clara’s clinic computer or on Sônia’s client’s production ERP.

2

Take notes before you start

One line in runtime/LIMITES.md: date, what you tried, what blocked it, workaround, and status.

3

Label the finding

"Fragile, tested on <date>". Without a date, no one knows if it’s still valid.

4

Back to the ladder

The finding becomes a question: "is there an export option, CLI, or MCP that does this?" The answer goes into the CAPACIDADES.md; not the trick.

📄 Example of a row in the runtime/LIMITES.md (what Sônia would write)
| data | o que tentei | o que barrou | contorno | status |
|---|---|---|---|---|
| <data> | achar por onde o ERP grava as vendas (máquina de teste, frágil) | sem API nem CLI | exportação CSV de vendas, ponte local (nível 6) | aceito |
What to look for: the "workaround" column points to a route on the ladder, not to the lab trick.

⚠️ Never in production

Anything built through reverse engineering breaks with the next program update, without notice, and only the person who built it knows how to fix it. If the lab didn’t find an official route, the discovery stays in the lab.

3

Respect terms of use and credentials

Even in the lab, the three integration rules of the POLITICA.md. They protect your account, your data, and your agreement with the tool provider.

The most sensitive point is credential. The Claude Code login is for Claude Code. The Codex login is for Codex. Copying one token into the other, or into a script, is exactly what the rule prohibits.

📄 runtime/POLITICA.md, Integration section (kit text)
- Só ferramentas oficiais pela assinatura (Claude Code, Codex CLI).
- Nunca passe credencial de uma ferramenta para outra.
- Engenharia reversa é laboratório: anote em LIMITES.md e não use em produção.

🆕 New here? Credential and token

Credential is anything that proves who you are: a password, key, or session cookie. Token it’s the credential a program stores after you log in, so it doesn’t ask for your password again. Anyone with the token can act as you.

✓ Can

  • ✓ Claude calls Codex through the bridge codex-exec.sh: each with its own login
  • ✓ Use the codex login and the login for claude through the subscription
  • ✓ You log in to the site; the agent only reads the page
  • ✓ Read the terms of service before automating a website

✗ Not allowed

  • ✗ Copy a tool’s token to another tool
  • ✗ Use the subscription through an unofficial client
  • ✗ Ask the agent to store a password
  • ✗ Put into production what came from the lab

💡 The right bridge doesn’t carry passwords

Notice the kit's bridges: the codex-exec.sh calls Codex’s official command, which uses its login. The mcp-modelo reads an exported file. Neither one stores, copies, or forwards credentials. Use this as a test for any new bridge.

🏷️
Official

through the subscription

🔐
Credential

stays where it was created

📜
Terms

read beforehand

🙋
Login

it’s up to you

4

Choose your system and fill in the map

Starts the final project. Choose a system from your work that has no API: a spreadsheet, an old ERP, a supplier’s website. Any system where an agent would save you time will do.

Sônia chose the client’s ERP. Clara chose the clinic’s schedule. You’ll go through the same six steps they did, from the map to the approved lesson.

1 · systemno API 2 · mapCAPACIDADES 3 · viathe highest 4 · bridgeR3 or R5 5 · teamR2 · N2 6 · deliveryverify OK+ 1 lesson deliverable: your populated runtime/ folder

How to read the diagram: the five blue boxes are the work; the amber box is proof that the work is done. No step skips the previous one: without a line on the map, there's no bridge; without a bridge, the team has nothing to use.

🎯 Objective: one tested line in CAPACIDADES.md for your system

Open claude in the kit folder and paste (the README prompt):

Read runtime/LEIA-ME.md and help me fill out CAPACIDADES.md for my work.

Example from the kit itself (Sônia’s line before the test):

| ERP sem API | Exportação CSV diária | 6 | ler ~/erp/export/*.csv | ler (N4) | pendente |
How to verify: your row has all six columns. The last one only replaces "pending" with the date when the bridge test (topic 5) passes.

💡 Choose small

One system, one question. "Total sales by customer" is a good final project. "Automate the entire office" is not. Once the first one passes, the second takes half the time.

🎯
One system

no API

🗺️
One line

in CAPACIDADES.md

⏳
Pending

up to the test

📁
runtime/

the deliverable

5

Build the bridge and run the team

The route you choose determines the recipe. A system that exports a file goes through the R3 (MCP bridge). A system that exists only as a website goes through the R5 (browser with policy).

With the bridge in place, the three-role team from R2 do the work. Here's one difference: N2 policy. The team asks before creating or changing any file.

Your systemRecipeBridge testModule
Exports CSV or spreadsheetR3 · MCP bridgenode runtime/pontes/mcp-modelo/server.mjs --selftest2.2 · 2.3
Only exists as a websiteR5 · browseragent-browser open + agent-browser get title2.4
🎯 Goal: the bridge responds and is connected to Claude (R3 path)

In the terminal, in the kit folder, after pointing PONTE_DADOS and swap the columns (module 2.3):

node runtime/pontes/mcp-modelo/server.mjs --selftest
claude mcp list

Real output (10/05/2026, with the kit's example files):

tools: 2 (listar_horarios_livres, resumo_vendas)
2026-10-06 09:00 · Dra. Ana
2026-10-06 10:00 · Dra. Ana
2026-10-06 15:00 · Dr. Bruno
TOTAL: R$ 856.00

ponte-modelo: node runtime/pontes/mcp-modelo/server.mjs - ✔ Connected
How to verify: with your data, the numbers change, but the format stays the same, and the bridge line ends with ✔ Connected. Now replace “pending” with the date in CAPACIDADES.md.
🎯 Objective: the three-role team works on your bridge, asking first (N2)

Open claude in the kit folder and paste (Sônia’s example; replace the task with yours):

Use the team: the planner plans, the executor does the work, and the reviewer checks it. Task: use the resumo_vendas tool from ponte-modelo and save the total for each customer and the TOTAL in resumo-vendas.md. N2 policy: before creating or changing any file, show me what you're going to do and wait for my OK. Finish with the reviewer's response.

Manual account of erp-vendas.csv, so you can check the summary:

Mercado Sol  10×18,50 + 40×5,20 = 185 + 208 = R$ 393,00
Padaria Lua  25×5,20 + 12×18,50 = 130 + 222 = R$ 352,00
Empório Mar  6×18,50             =             R$ 111,00
TOTAL                                          R$ 856,00
How to verify: Claude stopped and asked for your OK before writing the file; the totals match the hand calculation; the response ends with APROVADO.
🔌
R3

file becomes a tool

🌐
R5

site with a policy

👥
R2

plans, does, checks

🚦
N2

asks beforehand

6

Deliver with the verifier and an approved lesson

"Done" doesn’t mean the agent says it’s finished. It means the verificar.mjs run your criteria and show all OK. Write a goal in the format of the goal-exemplo.md, one criterion per line.

And the project only wraps up with the full cycle: something that happened becomes one row in the Learning table of the POLITICA.md, and you approve.

📋 Goal template to copy (save as meu-goal.md in the kit root)
# Goal — ponte do <meu sistema>

## Resultado
O agente lê o <meu sistema> pela ponte, o time grava o resumo e o kit continua saudável.

## Critérios de pronto
- [ ] `node runtime/scripts/doctor.mjs` → `PRONTO`
- [ ] `node runtime/pontes/mcp-modelo/server.mjs --selftest` → `tools: 2`
- [ ] `node runtime/pontes/mcp-modelo/server.mjs --selftest` → `TOTAL: R$ <total conferido à mão>`
- [ ] `claude mcp list` → `✔ Connected`
- [ ] `cat <arquivo que o time gravou>` → `<texto que tem de aparecer>`

## Portões humanos
Enviar, apagar, gastar ou publicar: pare e me pergunte.
What to look for: each criterion passes only if the command finishes without an error and the output contains the text between backticks after the arrow. Replace everything between < >.
🎯 Objective: see verify report "all OK"

In the kit folder, start by running it on the example goal. Then replace the path with your own meu-goal.md:

node runtime/scripts/verificar.mjs runtime/exemplos/goal-exemplo.md

Real output (10/05/2026, output 0):

OK     node runtime/pontes/mcp-modelo/server.mjs --selftest
OK     node runtime/pontes/mcp-modelo/server.mjs --selftest
OK     node runtime/pontes/mcp-modelo/server.mjs --selftest
OK     node runtime/scripts/doctor.mjs

4/4 critérios OK
How to verify: the last line says N/N critérios OK with both numbers matching. If one is missing, ask the agent using the R6 prompt: /goal Cumpra o goal em meu-goal.md. Depois de cada etapa rode node runtime/scripts/verificar.mjs meu-goal.md. Só pare com todos OK ou num portão humano do goal.
📄 Example of an approved row in the Learning table (runtime/POLITICA.md)
| data | o que aconteceu (com evidência) | proposta (1 linha) | status: proposto / aprovado / recusado |
|---|---|---|---|
| <data> | o resumo do time somou um cliente duas vezes; o revisor pegou (FALTA:) | o revisor sempre compara o TOTAL com a soma por cliente | aprovado |
After: approved becomes a line in the section Lessons of the AGENTS.md (module 4.2).

✅ Delivery checklist (your folder runtime/)

  • ☐ CAPACIDADES.md with your system line, method, level, policy, and test date
  • ☐ Bridge working: selftest and ✔ Connected (R3) or agent-browser reading the site (R5)
  • ☐ Three-role team run with N2 policy, ending in APROVADO
  • ☐ meu-goal.md in the format - [ ] `comando` → `esperado`, with human checkpoints
  • ☐ Output from verificar.mjs with all criteria marked OK
  • ☐ One line with status aprovado in the Learning table and the rule in the Lessons
  • ☐ If there was a lab: the line in LIMITES.md with a date and the "fragile" label

Quick test (optional): what proves that your final project is ready?

🎓 Module summary

✓
Ladder first — one test per level before saying “it can’t be done.”
✓
Reverse engineering is a lab — test machine, LIMITES.md, fragile, and date.
✓
Credentials stay where they originated — official tools through the subscription only.
✓
A system without an API becomes a bridge — R3 or R5, and the team works at R2 in N2.
✓
Done means proof — verify everything is OK and one lesson is approved.

End of the course:

You have a bridge, a team, a verified goal, and the first learned rule. Repeat the cycle with the next system.