Skip to content
[bmdpat]
All writing
5 min read

The Merge Trap Opened Without Me While Leads Hit Zero

On 2026-10-04, two PRs broke a strict merge trap without my hands. Meanwhile, 1,835 human visitors generated zero paid installs and one bot lead.

Share LinkedIn

On 2026-10-04, two pull requests cleared a strict branch trap without my intervention. The morning brief told me both were blocked. By 15:24 CT, both merged clean on main. A new check script unblocked the path.

Key decisions from The Merge Trap Opened Without Me While Leads Hit Zero

How did two blocked pull requests merge without me?

A strict branch gate held two pull requests until a helper script resolved the receipts. PR #1939 added scripts/check_file_matches_commit.py at commit e263c558. That check re-greened showwork-receipts right after PR #1937 merged at 1b122fde. The repository fixed its own gating rules without changing branch protections.

The strict branch trap had stayed stuck for two days. A check on showwork-receipts failed on main, blocking every push. At 07:25 CT, PR #1937 merged non-canonical blog archive URLs to canonical paths. At 15:24 CT, PR #1939 added the receipt script. The checks turned green. Meanwhile, bmd-desktop reached v3.47.42, with an installer of 209,234,936 bytes.

Why did 1,835 human visits produce zero installs?

Seven days of traffic brought 1,835 human sessions and nine button clicks, but zero paid installs. A customer-path audit at vault commit da60bfee4 confirmed those numbers across six separate database checks. Readers arrived to read technical posts, but the landing page never asked them for anything they actually wanted.

Two external signals arrived in the run up to 2026-10-04. Both were bots. One intake lead contained gibberish in the task field. On AgentGuard, PR #809 came from trustabl-kathrina, an account five weeks old that opened 199 PRs across GitHub. Five merged, and my repo was one.

The 1,835 human sessions were real. Understanding what an AI agent costs to build and run matters when readers visit but do not convert. I pushed draft PR #1947 to adjust the path, but held it. AgentGuard downloads sit at 1.57 per day net of cron on the AgentGuard tools page.

How can an empty security check report clean status?

An automated security scanner reported green status on 2026-10-04 because it silently skipped every target repository. The scanner inspected zero of five codebases for credential leaks and vulnerabilities. When tooling treats an unreachable path as a clean exit, passing checks provide false reassurance instead of real protection.

SecurityAnalyst returned green with zero P0 and P1 issues. Yet gitleaks and osv reached zero of five repositories. In the vault, health check GR-110 stayed red with 18 live tokens inside six runner logs for 28 days. A disconnected drive cable hit day 39, leaving checks blind.

Other jobs failed outright. The digest job skipped for a fourth day on Claude spend limits and Grok exit 1, leaving 80 links unprocessed. I use AI agent cost control with AgentGuard to halt runs before runaway token spend.

Check or SweepReported StatusActual State
SecurityAnalystGREENChecked 0 of 5 repositories
Canonical HealthRED611 to 614 of 615 failing
Daily Ship ReceiptREDPost stopped at publish stage
Queue Sweep1 Merged, 1 HeldPR #1942 merged, issue #1924 held
GitHub SweepClean zero35 issues scanned, 0 materialized

On the morning of 2026-10-04, my own brief told me that two finished pull requests were waiting on me, and that only I could unlock them. By 15:24 CT both had merged and nobody changed branch protection. PR #1939 carried the check that re-greens the showwork receipts, so the trap held its own fix and my fleet found the way out. I read that twice. The value report then put the day at minus 50 net minutes, with 850 minutes of open Requests and the attention-reduction loop still waiting on me.

So the work an agent can do for me got cheaper on 2026-10-04. The work only my hands can action lagged behind. An unplugged drive cable hit day 39, and because of it my security scanner printed GREEN after reading 0 of 5 repositories. Two credential Requests sit at 28 days and 8 days, and each one needs a sentence from me.

The other thing I keep turning over is that both outside contacts over seven days were machines. The one lead on record had gibberish in its task field. The first external pull request in six months came from an account that has opened 199 of them. Against that, 1,835 human sessions over seven days and zero install intents. The readers are arriving. I have not asked them for anything they want.

What should you do with this?

  1. Audit your CI checks so jobs fail if the count of scanned repositories equals zero.
  2. Put receipt validation scripts into your pull requests so branches unblock themselves when merged into main.
  3. Compare intake form submissions against web analytics to verify whether real visitors get what they need.

Accompanying prompt

What the prompt does: Audits a repository for empty security check passes and unverified branch merge receipts.

Copy/paste this prompt:

Copy-ready prompt

Paste the exact block into your coding agent.

No article chrome, no footnotes, no formatting drift.

Role: Codebase and CI Audit Assistant Context: Automated test suites and security scanners can report false green passes when target paths are unreachable or when merge receipt checks are missing. Inputs: - Repository path: __ - Scanner command: __ - Branch receipt script: __ - Minimum expected targets: __ Task: 1. Inspect the scanner command configured in Repository path to verify it does not exit with code 0 when zero targets are found. 2. Review Branch receipt script to ensure that merge receipts match the latest commit hash before branch protection gates evaluate. 3. Confirm that the total targets checked by Scanner command is at least Minimum expected targets. Output: - A list of silent pass vulnerabilities where empty scans exit clean. - Required script adjustments to enforce positive target counts. Constraints: - Do not assume missing files mean passing status. - Require non-zero target counts before returning success.
24 lines944 chars
Ready

This prompt and every other one we publish live in the free prompt library.

Copy the block above.

Weekly measured local runs: https://bmdpat.com/5090-reports

Get the Local AI Field Kit

Four copy-ready tools now, then one evidence-backed Local AI Lab Note on Friday when there is something worth sharing.

Try the free agent run check first

Get the requested artifact now, then at most one evidence-backed Local AI Lab Note on Friday when there is something worth sharing. One-click unsubscribe. No sponsored placements. Privacy.

PH

Patrick Hughes

I build BMD and publish measured AI runs, failure reports, and reusable checks. Nashville, Tennessee.

More writing