This morning I moved the key that signs "Craig approved this" onto a hardware key on my desk. By afternoon it was working, and the follow-up did not end where I expected.

Signing had turned into a chore — getting one blog post published took four trips back and forth. So I told my ranch agent to fix that, with one requirement: my go, the PIN, and the touch. Nothing else.

It came back with exactly that. A window opens on the Mac mini, asks for my PIN, waits for me to touch the key.

I sent the design to Grok for review. The problem was obvious once somebody named it: that window asks for a PIN and shows me nothing at all. I would approve that a window opened, not what it said.

The key can prove I was at my desk and knew my PIN. It can't prove I agreed to anything in particular. That is what I bought it for, and the design had quietly taken it away.

The fix cost nothing. Print the task above the prompt. I still just read, type the PIN, touch the key.

So I asked for that lesson to go into the free kit I give away, as a rule plus a check: anything waiting on a human carries a hash of exactly what's being approved. It shipped.

An hour later I asked for an eval on it. One question did it: could the thing we're worried about rewrite the hash too? It could. The hash sat inside the very file it was protecting.

We moved the hash. Review broke that too. We fixed it and I pushed — and there is my mistake. I never sent the last version back.

When I finally did, one allowed command took the whole thing apart — not a break-in, just an ordinary call my own rules permit: rewrite the file, replace the log, and my checker still reported the thing unchanged.

So I pulled it. That layer came out of the public kit tonight; the reason is in the manifest. The principle stays. The principle was never the problem.

Knowing how a thing fails feels like being safe from it. It isn't — true of me, and of the agent I had walked through the same hole an hour before.

It cost me an afternoon and I have shipped less than I started with.