From Contributor Repositories to Evidence-First Interoperability: What We Built in One Night
During one long engineering session, we moved MyZubster from “we have several independent contributors” to something much more concrete:
independently reproducible contributor checkpoints connected through a shared, evidence-first interoperability layer.
The goal was not to pretend that every contributor runs the same software.
It was the opposite.
We wanted independent projects to remain independent while giving MyZubster a common way to answer four questions:
- What exactly did this contributor build?
- Which exact commit or evidence package are we talking about?
- Can MyZubster reproduce or retrieve it independently?
- What can we safely claim after that test?
That distinction ended up being the most important part of the work.
The interoperability pattern
The architecture we converged on looks like this:
INDEPENDENT CONTRIBUTOR WORK
↓
PUBLIC REPOSITORY / PR / EVIDENCE PACKAGE
↓
CANONICAL CONTRIBUTOR RECORD
↓
RUNTIME / EVIDENCE / VERIFIER BRIDGE
↓
HARMLESS REPRODUCIBLE TEST
↓
PUBLIC TEST EVIDENCE
↓
BOUNDED STATUS: TESTED / SUPPORTED / VERIFIED
Different contributors need different bridges.
A Docker application should be reproduced as software.
A research package should be ingested with provenance.
A security contribution should be exercised as a regression or verifier checkpoint.
A fork by itself proves almost nothing.
The common denominator is reproducible evidence.
1. Reproducing N4K48 independently
The first reference implementation was Nicola's N4K48 work.
We reproduced commit:
87a1021
on an independent MyZubster VPS.
The environment included:
- Docker
- the N4K48 API
- Qdrant
- Open WebUI
- Ollama
nomic-embed-text- the local
zorgax:latestmodel
The services were bound locally rather than exposed unnecessarily to the public network.
We verified:
- Docker build
- API health
- observations endpoint
- Nicola Comics catalog
- read-only Zorgax flow
That gave us a useful definition of TESTED:
MyZubster independently reproduced a specific technical checkpoint and observed the expected behavior.
It did not mean production certification, scientific validation, or direct peer-to-peer communication with Nicola's physical machine.
That scope boundary matters.
2. Adding H4X0R to the semantic evidence path
Once N4K48 was running independently, we inserted a MyZubster evidence observation for H4X0R.
The observation described the exact technical checkpoint and retained metadata such as:
actorRef: H4X0R
evidenceState: TESTED
project: MyZubster
sourceCommit: 87a1021
sourceIssue: MyZubster-Ecosystem/myzubster#1505
The resulting observation ID was:
d654a6bcde1ce181
We then tested semantic retrieval.
A supported question such as:
Who is H4X0R and which technical test was completed with N4K48?
returned the expected evidence.
More importantly, we tested an unsupported personal-data question.
Zorgax returned:
Informazione non disponibile nelle fonti MyZubster.
That negative test was as important as the positive one.
An evidence system should not only retrieve correct facts.
It should also know when not to invent one.
3. Connecting Open Period Care
The next contributor required a completely different bridge.
Open Period Care, contributed by khongten124, is primarily a research and knowledge package rather than a standalone runtime node.
Its canonical checkpoint was pinned to:
repo: khongten124/myzubster
branch: feat/open-period-care-research-1450
commit: 17cf7ca0a941d10e184771e574683785c1dbc8bf
The bridge fetched three public artifacts:
README.md
evidence-matrix.md
knowledge-cards.md
For each artifact, MyZubster retained:
- contributor
- repository
- branch
- commit
- source path
- SHA-256
- evidence states
- original content
- bridge status
The live VPS check succeeded.
That gave us:
Open Period Care public evidence fetch + normalization: TESTED
But an important rule remained:
the bridge being TESTED does not upgrade the underlying research claims.
If a Knowledge Card is SUPPORTED, connecting it successfully to MyZubster does not magically make it TESTED, VERIFIED, clinical, or regulatory evidence.
4. Our RAG failed — and that was useful
The most interesting part came next.
We ingested the Open Period Care material into the same N4K48/Qdrant/Zorgax evidence path.
The first semantic check failed.
Zorgax confused:
REQ-MAT-01
REQ-ABS-02
REQ-BAR-03
with Knowledge Card IDs.
Then it interpreted GOTS references in the research material as if they were a personal certification belonging to the contributor.
That was wrong.
The sources were retrieved, but the semantic interpretation was unsafe.
So the checkpoint stayed:
FAILED
instead of being promoted prematurely.
This failure exposed two separate architecture problems.
Problem 1: structured facts should not depend on free-form generation
IDs, titles, status values and credential boundaries are structured facts.
They should not rely on an LLM paraphrasing them correctly every time.
We created retrieval-friendly semantic anchors for canonical facts such as:
KC-OPC-001
Multi-Layer Biomaterial Architecture for Reusable Textile Absorbents
SUPPORTED
and:
KC-OPC-002
Contributor Privacy, Data Minimization & Clinical Boundaries
SUPPORTED
We also made the contributor credential boundary explicit:
professionalCredential: NOT_ESTABLISHED
medicalCredential: NOT_ESTABLISHED
This reduced ambiguity, but one more problem remained.
5. Shared vector search created cross-contributor contamination
N4K48 used one shared Qdrant collection:
myzubster
The default semantic search had no contributor filter.
That meant a query about Open Period Care could retrieve the H4X0R observation as the top result.
And N4K48's authoritative description path correctly returned the first result.
The problem was not the authoritative mechanism.
The wrong record had won the ranking.
That led to the architecture we now use:
Semantic search for discovery
Vector similarity is useful when asking broad questions.
Deterministic metadata lookup for structured facts
For identifiers, provenance, states and contributor-specific records, we now query metadata such as:
bridge = open-period-care
knowledgeCardId = KC-OPC-001
or:
sourcePath = docs/contributions/khongten124-project-registry.json
This produced the final scoped source set:
6133cdc69da3ae31
b29f3d1f6b99f5e1
48f5cbbaa4581906
Every returned source belonged to Open Period Care.
The final Zorgax answer correctly returned:
KC-OPC-001
Multi-Layer Biomaterial Architecture for Reusable Textile Absorbents
SUPPORTED
and:
KC-OPC-002
Contributor Privacy, Data Minimization & Clinical Boundaries
SUPPORTED
while correctly stating that the available sources do not establish a personal medical certification for khongten124.
Final result:
Contributor-scoped Open Period Care
→ Qdrant
→ Zorgax interoperability
TESTED
This became one of the most important lessons of the night:
Vector search is excellent for discovery.
Metadata filtering should be authoritative for structured identity and provenance.
6. Building an independent verifier for Shweta
The next contributor required another bridge type.
Shweta-singh24 had a concrete MyZubsterGateway contribution:
PR: MyZubster-Ecosystem/MyZubsterGateway#1385
commit: 82461433e0c5bfee9aa369b4a71e9331261cf803
The PR was closed and not merged.
That does not prevent us from independently testing the exact commit.
It simply changes what we are allowed to claim.
We created a verifier that cloned the contributor repository at the exact SHA and checked five JavaScript files.
The policy tests covered:
GLOBAL → known capabilities allowed
HK → known capabilities allowed
CN_MAINLAND → restricted capabilities denied
unknown jurisdiction → deny
unknown capability → deny
Four capabilities were exercised across the known jurisdictions:
wallet_transfer
exchange_flow
external_settlement
provider_crypto
We also verified route wiring for:
- Tari wallet transfer
- Tari external settlement
- XMR wallet transfer
- XMR external settlement
and checked that denied operations use:
HTTP 403
JURISDICTION_POLICY_DENIED
Every policy, syntax and wiring check passed.
Result:
Shweta jurisdiction capability verifier checkpoint: TESTED
Again, the boundary is explicit.
This does not mean:
- the upstream PR was merged
- it is deployed in production
- legal compliance was certified
- a security certification was issued
It means one thing:
MyZubster independently reproduced the technical behavior of that exact commit.
7. The CI pipeline then blocked us for the right reason
When the contributor bridges were ready, two repository-wide checks were still red:
Security Audit
Continuous Evidence Gate
The contributor code was not the cause.
The shared npm dependency tree contained:
compression 1.8.1
affected by a high-severity issue, and:
proxy-addr 2.0.7
affected by a critical issue.
Instead of bypassing the security gate, we opened a separate security-only PR.
We updated:
compression → 1.8.2
proxy-addr → 2.0.8
with a coherent lockfile.
The result:
Security Audit: PASS
Continuous Evidence Gate: PASS
CI / Test / Lint: PASS
Seller Free policy: PASS
Vercel: PASS
That security PR became:
#1510
merge commit:
aa5aa8883a993c99b50e233bea29c5da2f3497f0
The useful engineering lesson here was simple:
Do not silence a red security gate just because the feature PR did not introduce the vulnerability.
Fix the shared baseline.
8. Final merges
Once the shared dependency baseline was clean, we reran the contributor PRs against it.
The Shweta verifier was merged as:
PR #1509
aa54fd380e487c11ba39fb40a092212f412cf364
The original Open Period Care PR had become non-mergeable after the main branch evolved.
Instead of forcing it, we recreated its exact six bridge files from the current main.
The clean replacement was:
PR #1511
All required workflows passed:
Security Audit
Continuous Evidence Gate
CI – Test e Lint
MYZ-164 Seller Free policy
Vercel
and the final merge became:
6061140f4ade01ab10211b2a6698cac03f326e55
What we actually built
By the end of the session, MyZubster had several distinct interoperability patterns running under one evidence model.
Runtime reproduction
Nicola / N4K48
→ Docker
→ API
→ Qdrant
→ Zorgax
Semantic contributor bridge
khongten124 / Open Period Care
→ public evidence
→ normalized provenance
→ Qdrant
→ deterministic contributor filtering
→ Zorgax
Independent verifier
Shweta
→ exact contributor commit
→ independent clone
→ executable policy tests
→ bounded TESTED evidence
These systems do not pretend to be identical.
They share an evidence contract.
The most important design decisions
1. Pin evidence to exact commits
A branch can move.
A commit SHA cannot.
2. Preserve provenance through every layer
A generated answer is far less useful if you cannot identify the repository, commit and source record behind it.
3. Keep evidence states separate
SUPPORTED ≠ TESTED
TESTED ≠ VERIFIED
TESTED ≠ certified
4. Test unsupported questions
A RAG system that answers known facts correctly but invents unknown facts is not evidence-first.
5. Do not use semantic similarity as an identity system
Vector similarity answers:
“What looks relevant?”
Metadata answers:
“Which exact contributor / card / commit is this?”
We need both.
6. Failed tests are evidence too
Several of the most useful architectural decisions came from tests that returned:
FAILED
We did not hide those failures.
We used them to tighten the system until the claimed scope actually passed.
Where this goes next
The next step is to apply the same interoperability contract to more independent contributors.
The implementation can vary:
- deterministic accounting bridge
- security regression bridge
- sensor integration bridge
- validation/bot-testing bridge
- independent evidence review bridge
But every contributor should eventually have:
public source
+ exact provenance
+ bounded reproducible checkpoint
+ machine-readable evidence
+ explicit limitations
The goal is not a network where everybody runs identical code.
The goal is a network where independently produced work can be connected, reproduced, queried and evaluated without destroying its provenance or overstating what the evidence proves.
That is a much more useful foundation for an open contributor ecosystem.
Repositories and checkpoints
Core repository:
https://github.com/MyZubster-Ecosystem/myzubster
Key PRs from this session:
#1509 — Shweta independent verifier bridge
#1510 — npm security baseline repair
#1511 — Open Period Care contributor bridge
Pilot tracking:
#1505 — Pilot Node Network
The infrastructure is still evolving.
But the contributor interoperability model is no longer just an idea.
We have reproducible checkpoints showing how it can work.
Top comments (0)