Go back to the ladder before the lab
The urge to "open up the program from the inside" comes up when something seems impossible. Before that, there’s a rule in the LEIA-ME.md and of the AGENTS.md: climb the ladder and test each level with a command.
The lab is step 7. You get there only after the six steps above answer “no,” with evidence. Often, the route exists; it just wasn’t documented.
How to read the diagram: the ladder goes from most stable (amber) to most fragile. The dashed red line separates the six production steps from step 7, which is for the lab only.
Open claude (or codex) in the kit folder and paste, replacing the system name:
Leia runtime/LEIA-ME.md e suba a escada das vias para o <meu sistema>. Para cada nível, de API até ponte local, diga qual comando ou menu testa esse nível e o que você encontrou. Não conclua "não dá" sem mostrar o teste de cada nível.
the highest available
one test per level
almost always exists
only after six
Treat reverse engineering as a lab
A POLITICA.md says in one line: reverse engineering is a lab: write it down in LIMITES.md and don't use it in production. A lab means a test machine, test data, and an expiration date.
The lab’s goal is to answer one question: “where does this program communicate?” Once you find the answer, go back to the ladder and look for the official route that does the same thing.
🆕 New here? Test machine and the "fragile" label
Test machine is a computer (or virtual machine) without your real data or logged-in accounts. If something goes wrong, nothing valuable is lost. "Fragile" label it’s writing next to the finding that it may break in the next update and the date it was tested.
Separate the machine
Don’t test on Clara’s clinic computer or on Sônia’s client’s production ERP.
Take notes before you start
One line in runtime/LIMITES.md: date, what you tried, what blocked it, workaround, and status.
Label the finding
"Fragile, tested on <date>". Without a date, no one knows if it’s still valid.
Back to the ladder
The finding becomes a question: "is there an export option, CLI, or MCP that does this?" The answer goes into the CAPACIDADES.md; not the trick.
runtime/LIMITES.md (what Sônia would write)| data | o que tentei | o que barrou | contorno | status | |---|---|---|---|---| | <data> | achar por onde o ERP grava as vendas (máquina de teste, frágil) | sem API nem CLI | exportação CSV de vendas, ponte local (nível 6) | aceito |
⚠️ Never in production
Anything built through reverse engineering breaks with the next program update, without notice, and only the person who built it knows how to fix it. If the lab didn’t find an official route, the discovery stays in the lab.
Respect terms of use and credentials
Even in the lab, the three integration rules of the POLITICA.md. They protect your account, your data, and your agreement with the tool provider.
The most sensitive point is credential. The Claude Code login is for Claude Code. The Codex login is for Codex. Copying one token into the other, or into a script, is exactly what the rule prohibits.
runtime/POLITICA.md, Integration section (kit text)- Só ferramentas oficiais pela assinatura (Claude Code, Codex CLI). - Nunca passe credencial de uma ferramenta para outra. - Engenharia reversa é laboratório: anote em LIMITES.md e não use em produção.
🆕 New here? Credential and token
Credential is anything that proves who you are: a password, key, or session cookie. Token it’s the credential a program stores after you log in, so it doesn’t ask for your password again. Anyone with the token can act as you.
✓ Can
- ✓ Claude calls Codex through the bridge
codex-exec.sh: each with its own login - ✓ Use the
codex loginand the login forclaudethrough the subscription - ✓ You log in to the site; the agent only reads the page
- ✓ Read the terms of service before automating a website
✗ Not allowed
- ✗ Copy a tool’s token to another tool
- ✗ Use the subscription through an unofficial client
- ✗ Ask the agent to store a password
- ✗ Put into production what came from the lab
💡 The right bridge doesn’t carry passwords
Notice the kit's bridges: the codex-exec.sh calls Codex’s official command, which uses its login. The mcp-modelo reads an exported file. Neither one stores, copies, or forwards credentials. Use this as a test for any new bridge.
through the subscription
stays where it was created
read beforehand
it’s up to you
Choose your system and fill in the map
Starts the final project. Choose a system from your work that has no API: a spreadsheet, an old ERP, a supplier’s website. Any system where an agent would save you time will do.
Sônia chose the client’s ERP. Clara chose the clinic’s schedule. You’ll go through the same six steps they did, from the map to the approved lesson.
How to read the diagram: the five blue boxes are the work; the amber box is proof that the work is done. No step skips the previous one: without a line on the map, there's no bridge; without a bridge, the team has nothing to use.
CAPACIDADES.md for your systemOpen claude in the kit folder and paste (the README prompt):
Read runtime/LEIA-ME.md and help me fill out CAPACIDADES.md for my work.
Example from the kit itself (Sônia’s line before the test):
| ERP sem API | Exportação CSV diária | 6 | ler ~/erp/export/*.csv | ler (N4) | pendente |
💡 Choose small
One system, one question. "Total sales by customer" is a good final project. "Automate the entire office" is not. Once the first one passes, the second takes half the time.
no API
in CAPACIDADES.md
up to the test
the deliverable
Build the bridge and run the team
The route you choose determines the recipe. A system that exports a file goes through the R3 (MCP bridge). A system that exists only as a website goes through the R5 (browser with policy).
With the bridge in place, the three-role team from R2 do the work. Here's one difference: N2 policy. The team asks before creating or changing any file.
| Your system | Recipe | Bridge test | Module |
|---|---|---|---|
| Exports CSV or spreadsheet | R3 · MCP bridge | node runtime/pontes/mcp-modelo/server.mjs --selftest | 2.2 · 2.3 |
| Only exists as a website | R5 · browser | agent-browser open + agent-browser get title | 2.4 |
In the terminal, in the kit folder, after pointing PONTE_DADOS and swap the columns (module 2.3):
node runtime/pontes/mcp-modelo/server.mjs --selftest claude mcp list
Real output (10/05/2026, with the kit's example files):
tools: 2 (listar_horarios_livres, resumo_vendas) 2026-10-06 09:00 · Dra. Ana 2026-10-06 10:00 · Dra. Ana 2026-10-06 15:00 · Dr. Bruno TOTAL: R$ 856.00 ponte-modelo: node runtime/pontes/mcp-modelo/server.mjs - ✔ Connected
✔ Connected. Now replace “pending” with the date in CAPACIDADES.md.Open claude in the kit folder and paste (Sônia’s example; replace the task with yours):
Use the team: the planner plans, the executor does the work, and the reviewer checks it. Task: use the resumo_vendas tool from ponte-modelo and save the total for each customer and the TOTAL in resumo-vendas.md. N2 policy: before creating or changing any file, show me what you're going to do and wait for my OK. Finish with the reviewer's response.
Manual account of erp-vendas.csv, so you can check the summary:
Mercado Sol 10×18,50 + 40×5,20 = 185 + 208 = R$ 393,00 Padaria Lua 25×5,20 + 12×18,50 = 130 + 222 = R$ 352,00 Empório Mar 6×18,50 = R$ 111,00 TOTAL R$ 856,00
APROVADO.file becomes a tool
site with a policy
plans, does, checks
asks beforehand
Deliver with the verifier and an approved lesson
"Done" doesn’t mean the agent says it’s finished. It means the verificar.mjs run your criteria and show all OK. Write a goal in the format of the goal-exemplo.md, one criterion per line.
And the project only wraps up with the full cycle: something that happened becomes one row in the Learning table of the POLITICA.md, and you approve.
meu-goal.md in the kit root)# Goal — ponte do <meu sistema> ## Resultado O agente lê o <meu sistema> pela ponte, o time grava o resumo e o kit continua saudável. ## Critérios de pronto - [ ] `node runtime/scripts/doctor.mjs` → `PRONTO` - [ ] `node runtime/pontes/mcp-modelo/server.mjs --selftest` → `tools: 2` - [ ] `node runtime/pontes/mcp-modelo/server.mjs --selftest` → `TOTAL: R$ <total conferido à mão>` - [ ] `claude mcp list` → `✔ Connected` - [ ] `cat <arquivo que o time gravou>` → `<texto que tem de aparecer>` ## Portões humanos Enviar, apagar, gastar ou publicar: pare e me pergunte.
In the kit folder, start by running it on the example goal. Then replace the path with your own meu-goal.md:
node runtime/scripts/verificar.mjs runtime/exemplos/goal-exemplo.md
Real output (10/05/2026, output 0):
OK node runtime/pontes/mcp-modelo/server.mjs --selftest OK node runtime/pontes/mcp-modelo/server.mjs --selftest OK node runtime/pontes/mcp-modelo/server.mjs --selftest OK node runtime/scripts/doctor.mjs 4/4 critérios OK
N/N critérios OK with both numbers matching. If one is missing, ask the agent using the R6 prompt: /goal Cumpra o goal em meu-goal.md. Depois de cada etapa rode node runtime/scripts/verificar.mjs meu-goal.md. Só pare com todos OK ou num portão humano do goal.runtime/POLITICA.md)| data | o que aconteceu (com evidência) | proposta (1 linha) | status: proposto / aprovado / recusado | |---|---|---|---| | <data> | o resumo do time somou um cliente duas vezes; o revisor pegou (FALTA:) | o revisor sempre compara o TOTAL com a soma por cliente | aprovado |
Lessons of the AGENTS.md (module 4.2).✅ Delivery checklist (your folder runtime/)
- ☐
CAPACIDADES.mdwith your system line, method, level, policy, and test date - ☐ Bridge working: selftest and
✔ Connected(R3) oragent-browserreading the site (R5) - ☐ Three-role team run with N2 policy, ending in
APROVADO - ☐
meu-goal.mdin the format- [ ] `comando` → `esperado`, with human checkpoints - ☐ Output from
verificar.mjswith all criteria marked OK - ☐ One line with status
aprovadoin the Learning table and the rule in theLessons - ☐ If there was a lab: the line in
LIMITES.mdwith a date and the "fragile" label
Quick test (optional): what proves that your final project is ready?
🎓 Module summary
End of the course:
You have a bridge, a team, a verified goal, and the first learned rule. Repeat the cycle with the next system.