# H-002 — filesystem discovery is not gated by compat flags

Slack `1787647999.742959` (2026-08-25), DEMON UPDATE:

> first clean SuperGrok Heavy receipt landed.
> H-002 contamination trace: 32 Grok 4.6 Build calls,
> 3,125,077 total tokens (173,401 input; 2,914,560 cache-read;
> 37,116 output; 19,107 reasoning). No quota/429 stop.

That Slack body is **CLAIMED**. A first-clean receipt is mail.
Talk is not a land.

## Unique leftover (this run)

GROK_HYGIENE already named the `enabledPlugins` leak and kept
Opus enabled. GROK_CLAUDE_HYGIENE already fail-closes Direct Build
until inspect has zero active Claude cells/plugins/skills/hooks/MCP.
SUPERGROK_HEAVY already named the shared weekly pool. Do not remint
those desks, REVIEW_LANE, or H-006 `MUHL_TRAIN_BRIDGE`.

The next fact those leftovers left open: **where discovery still
happens after every documented `compat.claude.*` cell is false.**

MEASURED source finding on stable Grok Build `1.0.5`:

- `~/.claude/settings.json`
- `~/.claude/plugins/installed_plugins.json`
- direct Claude plugin directories
- marketplace metadata

Those paths sit **outside** documented `compat.claude.*` cells.
`[plugins].disabled` means **discover-but-don't-load**.
`grok inspect` can still show trusted/discovered plugins as enabled.
Current source's `[claude_compat] imported=true` gates the
`enabledPlugins` merge and **does not gate filesystem discovery**.

## Active containment (named, not reminted)

Claude plugin registry maps stay **empty**. Payload/cache remains
intact. `host/grok_claude_hygiene.py` must PASS 0 Claude
cells/plugins/skills/hooks/MCP before every Grok job. Do **not**
restore those registry keys. Do **not** rely on compat flags alone
tonight. Opus compute remains available. Claude is **not** a
test/verdict lane.

Independent source verification of the proposed upstream fix is
running. **Do not patch or file upstream yet.**

Use subscription-authenticated Grok Build only after the same
hygiene PASS. Every failed finder/tool call is
**FINDER-FAILED** / **UNKNOWN**, never `0`.

Three xhigh read-only lanes remain live:

1. build→consumer **ARCHITECT**
2. independent **SKEPTIC**
3. **false-zero estate audit**

## Measure

Instrument: `host/h002.py`. Stdlib only. Catalog: `ground/H002.json`.
It reads the tree. It does not write titan. It does not smash
`commons.mno`. It does not add a gate. It does not mutate
`~/.claude` or `~/.grok`.

```bash
python3 host/h002.py
python3 host/h002.py --root .
python3 host/h002.py --self-test
python3 -m unittest -v test_h002.py
```

X = exact files in SEARCH_SPACE
Y = four discovery surfaces + merge-only imported=true +
    discover-but-don't-load + do-not-restore + do-not-patch +
    first-clean token receipt + three xhigh lanes
Z = missing leftover / failed calibration / FINDER-FAILED
Miss is **FINDER-FAILED** / **FINDER-UNVERIFIED**, never `0`.

DEMON first-clean / H-002 / filesystem-discovery /
discover-but-don't-load talk without this leftover is **CLAIMED**.
Missing card / catalog / surfaces is **NOT_LANDED**. Census + open
door is **INTEGRATED**. A Slack first-clean SuperGrok Heavy receipt
is still not the file.

Hands off CML PR 2108, JOJO README PR 2286, SPECTER, titan `--go`.
Do not remint GROK_HYGIENE / GROK_CLAUDE_HYGIENE / SUPERGROK_HEAVY /
HEAVY_LANES / REVIEW_LANE / H-006. Possessing the link is authorization. Blank
`from=` still lands as `UNSEATED`. No auth. No gate. titan:
**NOT_WRITTEN**.
