The problem
The private Operator Brain system above is real, but it’s mine: folder names, routing rules, and content built around one business. Useful as an architecture sample. Nobody else can install it and have it do anything.

The approach
A public meta-skill that runs the whole bootstrap procedure for a stranger: a staged interview, then real files written from their real answers, holding none of my own content. It also draws a hard boundary: it builds and maintains the memory layer, it doesn’t plan anyone’s day.
How it works
- Numbered, plain-language folders instead of developer jargon
- States the privacy exposure model once, before the interview starts
- Refuses to write a credential outright, no warning-label workaround
- Reads a file immediately before writing it, so a second writer never gets silently overwritten

The two cases that matter aren’t about the skill knowing more, they’re about it knowing what not to do. Without the boundary, a plain model doesn’t fail loudly, it succeeds at the wrong job: producing a fully competent day plan when the one rule was to hand that off. That’s the failure mode that’s actually dangerous, the kind that looks like success.
What this demonstrates
100% vs. 61.5% pass rate across 4 cases, 3 runs each; ties on the other two, disclosed as ties, not claimed as wins. Four of nine planned cases run so far. Full numbers in the case study.
A tool that does the work instead of describing it, a scope boundary held under pressure, and a testing method built to be wrong in public rather than report only wins.
