Skip to content

I try to break Empryo before you do

Agents hunt for bugs in Empryo every day. A second model has to reproduce each report before it counts, every fix ships a lint rule so the same bug cannot come back, and 387 automated checks run against the real build.

In numbers

bugs found
1188
101 more thrown out on review
fixed
1133
51 waiting for a fix
guarded by a lint rule
749
so they cannot come back
automated checks
387
282 on macOS, Linux and Windows

The bug machine

A bug is one file, and the folder it sits in is its state. Each agent does one job, writes its part and moves the file on. Nothing moves without proof.

  1. Hunt

    Hunters read one slice of the code for one kind of bug. A report counts only when they reproduced it in a throwaway home folder.

  2. Review

    A reviewer on a different model runs the reproduction again, then approves the report or throws it out.

  3. Fix

    A fixer removes the root cause in the terminal app, the desktop app and headless mode, and proves it before and after.

  4. Check the fix

    A fix reviewer reruns the proof. It is pass or fail, and a pass with a minor issue is a fail.

  5. Land and guard

    The fix lands as one commit, with a lint rule that fails whenever someone writes the same mistake again.

Where the 1188 bugs are now
  • Fixed, and a lint rule guards it749
  • Fixed384
  • The fix passed its review2
  • Approved, waiting for a fix51
  • Waiting for review2

101 more reports were thrown out on review: a second model could not reproduce them, or the behaviour was intended.

The hunts

Each hunt sends agents into the code at once, every one with a slice of it and one kind of bug to look for.

  1. c01 September 2616 hunters21 reports, 1 thrown out, 20 fixed
  2. c02 September 2616 hunters18 reports, 0 thrown out, 18 fixed
  3. c04 September 2616 hunters16 reports, 2 thrown out, 14 fixed
  4. c05 September 27312 hunters213 reports, 17 thrown out, 190 fixed
  5. c06 September 27245 hunters105 reports, 7 thrown out, 98 fixed
  6. c07 September 27112 hunters0 reports, 0 thrown out, no fixes landed yet
  7. c08 September 270 hunters0 reports, 0 thrown out, no fixes landed yet
  8. c09 September 28319 hunters221 reports, 4 thrown out, 217 fixed
  9. c10 September 28141 hunters95 reports, 14 thrown out, 81 fixed
  10. luna-source-2026-10-01T01-51-36-556Z October 112 hunters13 reports, 0 thrown out, no fixes landed yet
  11. luna200-2026-09-30T23-50-35-736Z September 30200 hunters41 reports, 0 thrown out, no fixes landed yet
  12. luna500-source-2026-10-02T11-12-49-180Z October 2500 hunters0 reports, 0 thrown out, no fixes landed yet

Every fix ships a guard

A fix without its guard is not done. The next agent that writes the same mistake fails the lint before anyone sees it.

746lint rules, written with the fixes

A rule ships with its fix. It has to flag an example of the bug, pass the fixed version, and find the same mistake nowhere else in the code.

2,348risky patterns counted, and the count only goes down

Swallowed errors, empty catch blocks, waits on the clock and unsafe casts are counted across the code and committed as a floor. Raising it takes a diff with a name on it.

One run, replayed

The machine finds new bugs, and the checks keep the old ones fixed. This is a real slice of them, played back from its report.

0of 26 done

September 23, 2026, Empryo 3.8.6-beta, build df8921843

  • macOS0 of 13
    1. Read only tool in a read only modeExplore, headlessqueued
    2. A saved session records the mode it ran inModes, headlessqueued
    3. An unapplied mode never runs at full powerModes, headlessqueued
    4. An unapproved plan does not unlock a restricted beltModes, headlessqueued
    5. Architect reads but never writesModes, headlessqueued
    6. Auto approves what default refusesModes, headlessqueued
    7. Denied edits are not reported as editsModes, headlessqueued
    8. Mode banner reaches the modelModes, headlessqueued
    9. Plan mode keeps the approval gatesModes, headlessqueued
    10. Plan mode never approves its own planModes, headlessqueued
    11. Restricted modes deny every mutating toolModes, headlessqueued
    12. Switching mode mid session takes effectModes, headlessqueued
    13. Tool schema is stable across modesModes, headlessqueued
  • Linux0 of 13
    1. Read only tool in a read only modeExplore, headlessqueued
    2. A saved session records the mode it ran inModes, headlessqueued
    3. An unapplied mode never runs at full powerModes, headlessqueued
    4. An unapproved plan does not unlock a restricted beltModes, headlessqueued
    5. Architect reads but never writesModes, headlessqueued
    6. Auto approves what default refusesModes, headlessqueued
    7. Denied edits are not reported as editsModes, headlessqueued
    8. Mode banner reaches the modelModes, headlessqueued
    9. Plan mode keeps the approval gatesModes, headlessqueued
    10. Plan mode never approves its own planModes, headlessqueued
    11. Restricted modes deny every mutating toolModes, headlessqueued
    12. Switching mode mid session takes effectModes, headlessqueued
    13. Tool schema is stable across modesModes, headlessqueued
  • Windowsnot in this run

0 of 26 doneTwo real reports from the same slice, 13 checks on the modes area run on macOS and then on Linux. Windows was not part of this slice.

What is protected

Each area of the product, how many checks guard it, and how I try to break it.

Heavily tested110 checks of 387

The screen looks right

No broken layout, no raw markdown, no blank window.

How I try to break it

We read the terminal the way you would, shrink it to 62 columns mid-session, and compare the result against a reference picture.

The ground nothing checks yet

The 8 things a person does with Empryo, from installing it to removing it, and the features no check aims at yet.

  1. Install it (covered)
  2. Run it the first time (covered)
  3. Add a real API key (not yet covered)
  4. Let it edit a file (not yet covered)
  5. Let it commit (not yet covered)
  6. Come back tomorrow (not yet covered)
  7. Upgrade (not yet covered)
  8. Uninstall it (covered)

3 of 8 steps are covered today. A step counts only when a check starts on a clean machine and installs from the signed download first.

161of 545 features have a check aimed at them

The total comes from the app itself, so a new feature shows up here as unchecked the day it ships. The other 384 are walked by the explorer checks instead.

Six kinds of test

Each kind is named after a part of the immune system, and they find bugs in two ways.

  • Seed

    a single check

    One promise written down: what to do, and what must be true afterwards.

  • Killer T cell

    runs the checks

    Runs one seed on one operating system, in the terminal, desktop or headless app. On Linux and Windows it uses the same build you download.

  • Innate sweep

    always on

    Runs alongside every check without being asked. It catches crash messages, garbled screens and stray escape codes, even when no seed was looking for them.

  • Dendritic cell

    the explorer

    Uses the product the way a person would, looking for things that are missing rather than things that are broken.

  • Negative selection

    the sceptic

    Challenges every new finding before anyone trusts it. Findings it disproves never turn into false alarms.

  • Memory cell

    never forgets

    Created from a confirmed bug. It checks for that bug on every run from then on.

Known ground

  1. Seed
  2. Killer T cell
  3. Memory cell

Each seed asks a question someone already thought to ask, on every platform where it can run properly. This loop protects what already works.

New ground

  1. Dendritic cell
  2. Negative selection
  3. Seed

A check cannot notice what is missing, so dendritic cells use the product like a person and note what should be there and is not. Claims that survive negative selection become new seeds.

Both loops end the same way: with a new check that runs on every test run from then on.

The last test run

A full run: every check, on more than one machine.

Finished on September 29, 2026, on Empryo 3.8.7-beta, in 39 minutes

349checks ran

  • 992 passed
  • 24 failed
  • 0 known
  • 0 healed
  • 4 skipped
  • macos367 passed, 6 failed, 1 skipped
  • linux332 passed, 6 failed, 1 skipped
  • windows293 passed, 12 failed, 2 skipped

Where it runs

  • macOS

    • headless265 checks
    • terminal85 checks
    • desktop63 checks
  • Linux

    • headless267 checks
    • terminal83 checks
    • desktop22 checks, start-up only
  • Windows

    • headless232 checks
    • terminal68 checks
    • desktop29 checks

On Linux and Windows the checks use the release archive you download. A filled dot means the checks really drive that form of the app; a half dot means they only confirm that it starts.

Try it

Every time someone finds a way to break Empryo, it gets harder to break.