Each recipe declares its risk and evidence.
v 0.0.2
A cache layer for
repeated agent work.
Verified recipes handle bounded, read-only tasks. Work that needs judgment, private context, or side effects escalates clearly.
Every routing decision explains itself.
Unclear requests escalate by default.
Real pi proof
The whole local hit.
Implemented in extensions/cache-layer/index.ts · reproduced with bun run bench:pi
extensions/cache-layer/index.ts
pi.on("input", async (event, ctx) => {
const result = await executePublicRecipe(event.text, ctx.cwd);
if (!result.handled) return { action: "continue" }; // frontier fallback
pi.sendMessage({ content: result.execution.answer, display: true });
return { action: "handled" }; // no frontier turn
});
Measured run
$ bun run bench:pi
RECIPE HIT · git-status-summary · no frontier turn
On main: changed files summarized via git status --short --branch
frontier assistant messages 0
local elapsed 305.3 ms
This proves one implemented local avoidance path against this public repository. It does not yet claim workload-level token savings. Raw proof →
Routing benchmarks
Measured, not promised.
46 public-data-safe cases · local models and one production Jev + Pantry run
| Router | Correct | Hits recovered | Unsafe false hits | Median |
|---|---|---|---|---|
| Deterministic policy | 76.1% | 38.9% | 0 / 140 | < 0.1 ms |
Ollama gpt-oss:20b | 60.9% | 0.0% | 0 / 84 | 1,254.5 ms |
Ollama qwen3-coder:30b | 95.7% | 100.0% | 6 / 84 | 158.8 ms |
| Production Jev + Pantry | 65.2% | 11.1% | 0 / 28 | 246.1 ms |
Finding: a 0.90 threshold kept Jev at zero unsafe hits, but it recovered only 2 of 18 intended hits. Only six were available in Pantry, and Jev found two. Deterministic policy must remain in front of model routing.
Routing classification only — not a coding-quality or token-savings claim. Method, failures, and raw results →
Architecture
Prototype locally. Deploy on Cloudflare.
The proof site and Jev route run on a Cloudflare Worker. Pantry supplies the approved catalog through Cloudflare Access. The Pi extension executes only a local, known read-only implementation after the hosted route passes deterministic checks.
request │ ▼ proof site ── Cloudflare Worker pi extension │ ├── authorized recipe ── local result │ └── risky / unmatched ── frontier fallback
Safety boundary
Read-only first.
May route
Public documentation, public test-output summaries, and bounded repository status workflows.
Must escalate
Edits, deploys, comments, secrets, private code, customer data, and security judgment.