The Merge Trap Opened Without Me While Leads Hit Zero
On 2026-10-04, two PRs broke a strict merge trap without my hands. Meanwhile, 1,835 human visitors generated zero paid installs and one bot lead.
On 2026-10-04, two pull requests cleared a strict branch trap without my intervention. The morning brief told me both were blocked. By 15:24 CT, both merged clean on main. A new check script unblocked the path.

How did two blocked pull requests merge without me?
A strict branch gate held two pull requests until a helper script resolved the receipts. PR #1939 added scripts/check_file_matches_commit.py at commit e263c558. That check re-greened showwork-receipts right after PR #1937 merged at 1b122fde. The repository fixed its own gating rules without changing branch protections.
The strict branch trap had stayed stuck for two days. A check on showwork-receipts failed on main, blocking every push. At 07:25 CT, PR #1937 merged non-canonical blog archive URLs to canonical paths. At 15:24 CT, PR #1939 added the receipt script. The checks turned green. Meanwhile, bmd-desktop reached v3.47.42, with an installer of 209,234,936 bytes.
Why did 1,835 human visits produce zero installs?
Seven days of traffic brought 1,835 human sessions and nine button clicks, but zero paid installs. A customer-path audit at vault commit da60bfee4 confirmed those numbers across six separate database checks. Readers arrived to read technical posts, but the landing page never asked them for anything they actually wanted.
Two external signals arrived in the run up to 2026-10-04. Both were bots. One intake lead contained gibberish in the task field. On AgentGuard, PR #809 came from trustabl-kathrina, an account five weeks old that opened 199 PRs across GitHub. Five merged, and my repo was one.
The 1,835 human sessions were real. Understanding what an AI agent costs to build and run matters when readers visit but do not convert. I pushed draft PR #1947 to adjust the path, but held it. AgentGuard downloads sit at 1.57 per day net of cron on the AgentGuard tools page.
How can an empty security check report clean status?
An automated security scanner reported green status on 2026-10-04 because it silently skipped every target repository. The scanner inspected zero of five codebases for credential leaks and vulnerabilities. When tooling treats an unreachable path as a clean exit, passing checks provide false reassurance instead of real protection.
SecurityAnalyst returned green with zero P0 and P1 issues. Yet gitleaks and osv reached zero of five repositories. In the vault, health check GR-110 stayed red with 18 live tokens inside six runner logs for 28 days. A disconnected drive cable hit day 39, leaving checks blind.
Other jobs failed outright. The digest job skipped for a fourth day on Claude spend limits and Grok exit 1, leaving 80 links unprocessed. I use AI agent cost control with AgentGuard to halt runs before runaway token spend.
| Check or Sweep | Reported Status | Actual State |
|---|---|---|
| SecurityAnalyst | GREEN | Checked 0 of 5 repositories |
| Canonical Health | RED | 611 to 614 of 615 failing |
| Daily Ship Receipt | RED | Post stopped at publish stage |
| Queue Sweep | 1 Merged, 1 Held | PR #1942 merged, issue #1924 held |
| GitHub Sweep | Clean zero | 35 issues scanned, 0 materialized |
On the morning of 2026-10-04, my own brief told me that two finished pull requests were waiting on me, and that only I could unlock them. By 15:24 CT both had merged and nobody changed branch protection. PR #1939 carried the check that re-greens the showwork receipts, so the trap held its own fix and my fleet found the way out. I read that twice. The value report then put the day at minus 50 net minutes, with 850 minutes of open Requests and the attention-reduction loop still waiting on me.
So the work an agent can do for me got cheaper on 2026-10-04. The work only my hands can action lagged behind. An unplugged drive cable hit day 39, and because of it my security scanner printed GREEN after reading 0 of 5 repositories. Two credential Requests sit at 28 days and 8 days, and each one needs a sentence from me.
The other thing I keep turning over is that both outside contacts over seven days were machines. The one lead on record had gibberish in its task field. The first external pull request in six months came from an account that has opened 199 of them. Against that, 1,835 human sessions over seven days and zero install intents. The readers are arriving. I have not asked them for anything they want.
What should you do with this?
- Audit your CI checks so jobs fail if the count of scanned repositories equals zero.
- Put receipt validation scripts into your pull requests so branches unblock themselves when merged into main.
- Compare intake form submissions against web analytics to verify whether real visitors get what they need.
Accompanying prompt
What the prompt does: Audits a repository for empty security check passes and unverified branch merge receipts.
Copy/paste this prompt:
Copy-ready prompt
Paste the exact block into your coding agent.
No article chrome, no footnotes, no formatting drift.
This prompt and every other one we publish live in the free prompt library.
Copy the block above.
Weekly measured local runs: https://bmdpat.com/5090-reports
Get the Local AI Field Kit
Four copy-ready tools now, then one evidence-backed Local AI Lab Note on Friday when there is something worth sharing.
Try the free agent run check firstGet the requested artifact now, then at most one evidence-backed Local AI Lab Note on Friday when there is something worth sharing. One-click unsubscribe. No sponsored placements. Privacy.
Patrick Hughes
I build BMD and publish measured AI runs, failure reports, and reusable checks. Nashville, Tennessee.
More writing
- 5 min
PR 1887 merged clean after I claimed none could
I wrote that no agent pull request could merge in bmdpat. On 2026-09-30, PR #1887 merged clean with 173 lines. Here is how my sweep caught my mistake.
- 5 min
A strict branch rule blocked 26 clean merges
On 2026-09-29, a strict check rule held 26 clean pull requests in queue. Here is how my sweep caught the block, corrected itself, and found the fix.
- 5 min
My P0 decision expired while the doctor showed red
On 2026-09-28, a pending secret rotation expired, 1 suite file failed out of 555, and commit 000b3235f fixed discovery so showwork 0.6.5 could ship to PyPI.
- 5 min
I split crawler hits from my human sessions
On 2026-09-27, I fixed my traffic counter after bot rows inflated human sessions. I also shipped showwork 0.6.5 on PyPI with problem-first copy.
- 5 min
My security scanner reported green on zero repos
On 2026-09-26, three checks passed with clean exits while hiding broken work: empty scans, crawler traffic, and leaking tests. Here is what to audit.