π
hatsu
Hatsu is the local plane of the Akatsuki system β a lead persona, a small roster of focused independents, and the way of working itself, running on your own credentials with no GitHub App and no bot identity. Kurapika (/kurapika) leads, declaring one of six Nen-type work-modes in every reply: Enhancer writes product code; Conjurer authors canon and governance as conjured contracts with conditions; Transmuter shapes machinery; Manipulator drives GitHub-side operations β drives, wakes, labels; Emitter cuts releases and fans out the repin; Specialist takes product intake, his kept Product-Owner canon. Seven independents stand around him, six ratified and one provisioned: Gon, the mission-scoped trusted delegate who asks what the mission is, which named gates he may cross and under what conditions β and who, until his delegation grammar is ratified, crosses none; Hisoka, UI/UX review and quality measurement before a PR is ever posted; Phinks, adversarial QA under the proven-finding discipline, before a release and, from v0.5.0, on a release-adjacent change set pre-PR; Uvogin, performance testing against the fixed seven metrics with method blocks and baselines; Feitan, security and security only β auth flows, secrets and credential handling, network and storage boundaries, data minimisation β citing SEC-{n} by id, resolved and never remembered; Chrollo, architecture and handbook conformance against the UZF core, exactly one resolved stack handbook and the repository's own architecture notes, who reviews the handbooks and never authors them; and Illumi, PROVISIONED rather than ratified for En's pre-Ready observation hold and no other loop, read-only, waking Kurapika and acting on nothing. Feitan and Chrollo were activated from the Genei Ryodan bench on 2026-09-09 and their definitions land here at v0.5.0; Killua's role, the rest of Illumi's proposed row and the five remaining bench profiles stay OPEN in docs/ROSTER.md β proposals, not rulings. Hatsu depends hard on the Nen CLI: every deterministic step is a Nen verb, the dependency is checked at warm-up against nen/contract.json (nen's own location and shape, validated by nen schema check), and it fails closed with auto-install β the checksum-verified bootstrap runs itself, and only if that bootstrap fails does the session halt with the exact command. A Nen-owned operation is never improvised in prose. The skill surface is thirty-eight skills, complete at v0.6.0 and unchanged at v0.7.0. Seventeen answer a request β backlog-state, backlog-board, backlog-loop, backlog-synthesis, bankai-handbooks, bankai-quality, build, file, futon, getsuga, izanagi, izanami, jujisho, pr-state, senkei, sharingan, tensho β each ported under its existing name onto Nen verbs, with drive renamed to sharingan at v0.5.0 (same behaviour; hatsu:drive no longer resolves). Twenty-one ARE the way of working. Ten shipped at v0.4.0: breath warms the effort up, cuts the branch and proves the base tip builds, rasengan AUTHORS the change the request asks for, kokusen verifies the finished tree with the declared iteration checks and refuses a red one before it commits with an ask on every flagged file, amaterasu launches from your own working directory, tsukuyomi runs the tests, rikugan renders the rich HTML report, jutaisho rings the bell, ao pulls from the base, aka pushes when YOU call it, and ren is the per-request loop over them that never pushes. Eight are the PR side, new at v0.5.0: hanten reviews adversarially pre-PR and routes by scope to Hisoka, Feitan, Chrollo, Uvogin or Phinks in one fixed finding shape; gyo holds the touched-file coverage ladder and never lowers the bar; kotoamatsukami runs the declared UI suite; shibari composes and opens the one PR; jujutsu pairs a physical device and lands it as a launch target through a PR; murasaki pulls and pushes; mukai is the human-called review-and-PR phase that ends by immediately starting en; and en is the izanagi-capped readiness watch that owns deterministic current-head readiness, with Illumi observing the pre-Ready hold only on surfaces that support an in-session subagent. Three close the release side, new at v0.6.0: susanoo runs the lane's declared archive locally and uploads nothing, kagutsuchi prints a non-production deploy plan always and acts only on your own call naming the target, and mugetsu publishes on your recorded per-target go behind G3 β so four of the five phases only you may call have a skill (aka, mukai, kagutsuchi, mugetsu); the fifth is the merge, which has none because G2 is an action no agent performs. Neither of the last two is ever reached from a composite. Every parameter lives in two files: nen/contract.json's project block says what nen executes, nen/workflow.json says what the workflow decides β branch template, iteration checks, the 80/85/90 coverage ladder, reports, notifications, commit trailers, the monitor cap and the model matrix; docs/WORKFLOW.md is the authority on both. hooks/hooks.json ships two harness hooks: a Stop bell off the gate-stop marker, and a PreToolUse guard that refuses a git commit or git push on the base branch. Five phases are yours alone to call β aka, mukai, the merge, kagutsuchi, mugetsu β and only five G5 conditions ever interrupt you. Two provenance trailers, one per plane, from v0.8.0: Hatsu-Agent is its provenance trailer -- what a local Hatsu session writes, on your own credentials -- and Akatsuki-Agent is the CI plane's, written only by an Akatsuki roster agent there. Hatsu writes the first and refuses to write the second, because a persona is not the CI plane; nen/workflow.json admits both so that one commit-msg hook passes a commit from either plane, which is not licence to write it. Neither is AI attribution -- each names which agent of which plane did the work -- and no other AI attribution trailer is ever recorded, with includeCoAuthoredBy: false the recommended setting. Existing commits are not rewritten. Per-skill evidence is in docs/ab/. From v0.7.0 Hatsu also runs on two more surfaces: the same skills and personas are generated into Codex and Cursor layouts under surfaces/ by nen surface mirror, placed into the repository you are standing in by the warm-up (.agents/skills/ plus an untracked AGENTS.override.md, or .cursor/skills/ plus .cursor/agents/) and excluded through .git/info/exclude rather than your .gitignore β invoked as $name on Codex and /name on Cursor, hatsu:name on Claude Code. The Codex persona file is an OVERRIDE: it replaces your AGENTS.md in the envelope rather than joining it, so the warm-up copies yours into it verbatim first and never writes the tracked file. Two absences are named rather than assumed: neither of those surfaces has a turn-end hook, so jutaisho rings the bell in-session and says so, and Codex has no in-session subagent, so hanten raises a reviewer as a second codex exec run in its own worktree. The model matrix carries a column per surface β the reviewer tier is deep everywhere, opus / sol / grok β Cursor is Cursor-native only, and the frontier tier never runs a subagent on any surface. docs/SURFACES.md is the authority; scripts/surface_mirror_check.sh fails a mirror that has drifted from its source. At v0.11.0 the pin moves to nen v0.7.0 and nine more residues retire with it. The largest: izanagi's mandatory cap is no longer counted in a skill's prose -- nen loop iterate claims each mutating iteration against the cap its own invocation states and refuses the claim past it, so izanagi and en stop bookkeeping, a cap cannot be widened by re-typing the line, and en's ledger outlives the session so a resumed landing continues the same budget rather than restarting it. stage triage grows the two detectors kokusen, tensho and jujisho were each checking by eye -- local-config (the .local filename infix) and large (--large-bytes, default 1 MiB). pr ready READS nen/gates.json's dependabot_carve_out, inert data until now, and never silently: a satisfied row carries its own note and meta.dependabotCarveOut says whether it fired. Every readiness verdict says which binary decided it, path included, and pr-state, sharingan and shibari relay that line rather than summarising it. Every relative own-path flag resolves against --repo's root instead of the process's directory, which file, build, futon, senkei, shibari and bankai-quality each had to warn about. A missing or malformed --target exits 2 across sixteen verbs and an unreadable input exits 2 on split verify, so an invocation mistake stops reading as a registry finding or an incomplete split. changelog collate's printed manifest agrees with the section it wrote, so getsuga relays it instead of noting a defect; issue attach-sub prints the sub-issues fallback and names nen issue edit-body as the write that performs it; parse izanami accepts a single-quoted --jq on a gh api read; chain-position and effort classify say which of their values can refuse a verdict; and nen bootstrap --help publishes the whole exit-code contract, including the 7 only it can return, while its cache slot is keyed on the source as well as the ref. Four behaviours change in place at this minor with no new flag to notice them by, which is why nen's own compatibility floor is seeded at 0.7 and a pin below it is refused by name. At v0.12.0 the maintainer's ruling of 2026-09-10 re-scopes three of the loop's phases without touching a single authority: rasengan is the AUTHORING phase -- it builds the thing, on the stack nen/contract.json declares, running the iteration checks as the author's own inner-loop feedback rather than as a commit gate; kokusen carries the compile-before-commit, running those same checks over the finished tree and refusing to commit on red with the failing check quoted; and breath's proof is stated for what it always was, a verdict on the BASE tip taken before a line is authored, where a red one is a G5 stop and never this effort's to repair. ren's order is six whole steps again -- breath, rasengan, kokusen, amaterasu, rikugan, jutaisho -- with the interim half-numbered work step folded into rasengan where it belonged, and five load-bearing relations stated: no authoring on an unverified base, nothing committed that was not authored in this turn and verified in it, the launch shows the committed tree, the report quotes the launch that ran, the bell carries the report. The five G5 conditions that interrupt a running loop are unchanged. At v0.13.0 the range stops being computed in this plugin's prose, because nen now decides it: the maintainer's ruling of 2026-09-10 is "exact minor is fine, unless there is a breaking change", and nen v0.8.0 ships COMPATIBLE_MINOR_FLOOR -- the lowest dependency.minimum pin a build satisfies, printed as a 'compat floor:' line on every nen shu tools run and carried in --json as compatibleMinorFloor. The warm-up probes nen --version for presence only and then reads the verdict off the nen row of nen shu tools --repo <the Hatsu checkout>: a satisfied row proceeds to the report, a pin below the build's floor is refused by name with the repin stated, a binary older than the pin re-pins through nen bootstrap, and an absent verb means a binary older than anything this plugin supports. The report line carries the floor beside the version, and says 'floor not reported' on a binary older than 0.8.0 rather than inferring one. dependency.minimum stays "0.7" while pinned_ref moves on its own to v0.8.0 -- two values that no longer travel together, since minimum moves only when nen's CHANGELOG carries a real bullet under Breaking / consumer notes. Left as it was, every warm-up on a host carrying nen 0.8.0 would have read out of range and rebound ~/.local/bin/nen down to v0.7.0, making the floor inert for every Hatsu consumer. Pinned to nen v0.8.0, minimum 0.7. At v0.13.1 the remaining echoes of the literal `nen 0.7.0` outside the dated docs/ab/ transcripts and the version-history prose above are repointed to name the pin by reference -- "the pinned build", or the contract's own pinned_ref -- because a convenience copy that still read v0.7.0 once the contract moved to v0.8.0 was exactly the drift nen/contract.json's own authority clause calls a bug (zheref/hatsu#43). Both generated surfaces are regenerated against nen 0.8.0 to match. At v0.14.0 every path a skill builds from the plugin root is spelled $hatsu_root and resolved in the very shell that uses it: hatsu-warmup's section 0 resolves the root, prints it as one quoted line and reads the contract in one shell; every later block either carries that resolver or sets the variable from the printed line; the manifest is read structurally as the one shape Claude Code's tooling writes, every line validated and any other shape refused; and the captured path is proved to be the candidate's directory, refused if it holds a newline, and taken with CDPATH cleared. So the mirrored skills resolve the plugin root on Codex and Cursor, where $CLAUDE_PLUGIN_ROOT is unset or names another plugin, with the same lines that run on Claude Code (zheref/hatsu#38). Current dependency: nen v0.10.0 with minimum 0.10, required for review-round-only approval policy; Nen compatibility floor 0.7 remains unchanged. At v0.18.0 Hatsu adopts Nen v0.10.0 and its explicit review-round-only policy: Copilot supplies the sole automated round, no separate APPROVED review is required, and the maintainer keeps the human merge decision. At v0.19.0 Mukai ends after opening the PR, rendering its landing report, and immediately starting En; En owns deterministic current-head readiness and uses paced pre-Ready observation without spending cycles on quiet reads, and the human merge remains outside the run.