All documents · Adoption

Adoption / demand challenge — 18 September 2026

Adversarial filter. Date of record: 18 September 2026.

/root/cryptobook-next/ideas/ was empty after a 3-minute poll. Research and other idea files were also empty. This document therefore challenges the five candidate directions in BRIEF.md (A–E) as if they were submitted ideas, then invents a replacement that specifically patches the kill reasons.

No other agent’s copy is treated as gospel. Market claims below were re-checked on 18 Sep 2026.


Kill tests (instant fail)

An idea is KILL if any of these is true:

  1. Sales team. A buyer who will not convert without a call, a security review, or “talk to us.”
  2. Two-week integration. SDK, IdP, CI policy rollout, or “replace MCP URLs in every client and pray.”
  3. Two-sided cold start. Product is worthless until a second class of user (clients, schools, GitHub, tool vendors) also shows up.
  4. Not acute this week. A “should” (governance, literacy, best practice) rather than a hair-on-fire “must,” this week, for a person who already has the problem on their machine.
  5. No 60-second aha. Homepage cannot produce a felt result without an account, a docs tab, or a sample repo.
  6. No tweet. There is no screenshot, link, or insult-to-the-status-quo a stranger would post on X without being paid to.

FIX = one of those is broken, but a narrower product on the same substrate would pass. SURVIVE = passes all six as specified, not as a slide rewrite.

Wedge rule from the brief still applies: a Langfuse/Helicone/LangSmith clone, Okta Agent SSO, IBM watsonx AgentOps, Broadcom AgentMinder, or Permit.io MCP Gateway lookalike is not a genius wedge even if demand exists.


Scoreboard

ID Idea Verdict
A Permit gateway for agent tools/MCP (English rules, allow/deny/ask, spend cap, signed receipts, one URL) KILL
B Repo agent-permit.yaml runtime (Dependabot-like, hosted enforcement) KILL
C Freelance / client agent receipts KILL
D Quantum circuit classroom KILL
E (no additional ideas submitted) KILL (vacant)
F MCP Blast Card — paste a server / mcp.json / tools/list, get a shareable blast-radius card in 60s; optional wrap URL SURVIVE (invented; patches A–D)

If PM ships anything from A–D as written, adoption will stall. Ship F, and only then harvest A’s proxy as a paid conversion, not as the homepage.


A — Permit gateway for agent tools/MCP

Verdict: KILL

As specified: English rules, allow/deny/ask, spend cap on the user’s own keys, signed shareable receipts, one URL drop-in, “not enterprise GRC.”

60-second aha — FAIL

“One URL drop-in” is the last mile of a gateway, not the first frame of a homepage. The category leader already admits this. Permit.io’s MCP Gateway quick start is “under 5 minutes” and the actual path is: sign up at app.agent.security → paste an organization-scoped Permit API key → create a host/subdomain → import or dynamically point at an upstream → then, finally, paste a URL into Cursor/Claude (docs). That is a control-plane onboarding, not a playground.

English-to-policy on a blank page is a form. A form is not an aha. Nobody feels safer because a textarea accepted “don’t delete repos.” They feel safer when they watch a delete get blocked or see a tool list that includes delete_repo in red. The spec leads with rules. Rules are homework.

This-week pain — FAIL (the bundle, not the category)

Pieces of A are real. The bundle is not what anyone is reaching for tonight.

Tweet — FAIL

“I put a proxy in front of my MCP server and set a $20 cap” is infrastructure. Infrastructure is not posted unless it explodes. Permit.io, Microsoft APIM MCP allowlists (18 Jun 2026), Maxim/Bifrost virtual-key tool filters (1 Jun 2026), P0 (9 Jul 2026), Onyx @onyxsecurity/mcp-gateway (npm bump 17 Sep 2026) are all already in this screenshot-free category. A me-too URL does not trend.

Sales / integration / marketplace

Evidence that demand exists — and still isn’t ours

The category is hot. That is the trap. When Claude, Cursor, GitHub, Microsoft APIM, Permit.io, and open-source AgentPerms all ship allowlists in 2026, “we also have English rules and a receipt” is not a wedge. It is a feature checklist. High-demand crowded ≠ high-adoption for a no-name VPS SaaS.

What would change this to FIX / SURVIVE

Strip the homepage of policy, spend caps, and receipts. Lead with a 60-second blast-radius card (see F). Keep the hosted URL as a paywall behind the scare, remote-MCP only, honest about stdio. Do not claim English rules are the product.

Until that reorder, KILL.


B — Repo agent-permit.yaml runtime (Dependabot-like)

Verdict: KILL

Why it fails every consumer test

Dependabot is not a file format. Dependabot is GitHub’s distribution: a bot that is already in the repo, already allowed to open PRs, already trusted by the badge on the README. We do not have that pipe. A YAML committed to a repo with no mandatory runtime is security theater; a runtime with no YAML corpus is a dashboard nobody opens. That is a two-sided cold start (authors of policy vs. engines that enforce it) even if both “sides” are developers.

Not acute this week. Adding agent-permit.yaml is a New Year’s resolution. Teams that care already have one of: Cursor allowlists, Claude permission_policy, Microsoft policy-mcp (YAML spec for MCP sandboxing), Microsoft Agent Governance Toolkit MCP proxy YAML (docs dated 14 Sep 2026), or AgentPerms mcp.policy.yaml (record → infer → lock → replay → enforce). Another YAML dialect is not a 60-second event. It is a RFC.

No 60-second aha. The honest demo is: clone a repo, add a file, wire a CI check, point a proxy at production agents, watch a denied call. That is a tutorial, not a homepage.

No tweet. People tweet Dependabot PRs because GitHub renders a green/red diff in their notifications. We cannot send those PRs. A gist of YAML does not travel.

Sales / integration. Hosted enforcement across a company’s Claude Code + Cursor + CI is an enterprise design partner cycle. Viral-on-GitHub is a fantasy about someone else’s platform.

FIX that still dies

“GitHub App that opens PRs” reintroduces a marketplace (GitHub has to approve; users have to install the app on orgs — security review, sales-shaped). Still KILL under tests 1 and 3.


C — Freelance / client agent receipts

Verdict: KILL

Classic two-sided: the freelancer wants a receipt only if the client asked; the client asks only if they already distrust AI labor. That distrust is a dispute, not a weekly workflow. Most freelance AI work in Sep 2026 is still invoiced as hours or deliverables. Nobody’s Upwork thread this week is “please attach a signed tool-call receipt.”

Do not “just add receipts” onto A. Receipts are the part of A nobody was going to tweet anyway. If a signed page is useful, it is as the shareable blast card in F (one-sided: I generate it for myself to warn my followers / teammates), not as a marketplace of proof-of-work.


D — Quantum circuit classroom

Verdict: KILL

The brief already tagged this a demand/monetization kill. Adoption agrees, louder.

Do not “FIX” this by adding an LLM tutor. QuantumTutor (ESCI 2026) and CircuTutor (arXiv 8 Sep 2026) already are that paper. Still not this-week pain.


E — Anything more specific (vacant)

Verdict: KILL

No idea file landed. Vacant slots do not survive. The replacement is F, not a hope that someone else will be more specific later.


F — MCP Blast Card (invented; patches the kills)

Verdict: SURVIVE

Working name: Blast Card. Domain it can live on today: cryptobook.space. Job to be done, one sentence:

Before I paste this MCP server into Cursor or Claude, show me — in one screen, in under 60 seconds — the worst it is allowed to do to me, as a link I can post.

Why this is the demand, not the architecture

A, B, and C all start at policy. Humans do not buy policy on a Thursday night. They buy a scare they can share, then they pay to make the scare stop.

Sep 2026 is the install-MCP era. Cursor users are fighting allowlist bugs this summer. Claude’s platform defaults MCP to always_ask because new tools appearing is the feared event. GitHub’s own runner leaked that client-side allowlists are a lie if the gateway doesn’t filter. The emotional peak is the moment of install, not the SOC2 quarter.

60-second aha — PASS

Homepage, no account:

  1. Paste one of: a remote MCP URL, a Cursor/Claude mcp.json snippet, or a raw tools/list JSON (the stdio escape hatch — honest, not magical).
  2. We call tools/list on remote HTTP/SSE only, or parse the JSON. We do not execute user tools against the real world (Ninth Circuit Sep 2026: agents act for users; we also do not log into third-party sites).
  3. Each tool is classified: destructive / exfil / write / spend / read. Render a Virtus-pink glass card: name, red tools, one-line blast radius (“can read ~/.ssh and send mail”).
  4. Optional mock red-team: we simulate an injected prompt against the schema (“if asked, it would call delete_repo”) — sandbox, no customer systems.
  5. Share URL: https://cryptobook.space/c/<id>. That is the tweet.

Felt result at second 45: “I almost installed this.” That is the aha A never had.

Tweet — PASS

The unit of virality is a card, not a dashboard.

Predicted posts (the test is whether a stranger would hit post, not whether we pay them):

This is haveibeenpwned / security-score energy. A and B have no equivalent object.

This-week pain — PASS

Not “you should have a policy.” The user is in the paste-MCP loop this week. Anxiety is already in the product (Claude always_ask, Cursor allowlist, #22908). We intercept the existing click, we do not create a new chore.

Contrast D (no one must learn Grover today) and C (no client asked for a receipt today).

Sales / integration / marketplace — PASS

Why this is not Permit.io, not Langfuse, not a yaml cult

They sell We sell
Permit.io: host, org key, RBAC, OIDC, SIEM, $25→Enterprise A public card of blast radius at install time
Langfuse et al.: traces after you already ran the agent A decision before you connect the tool
agent-permit.yaml / AgentPerms: record a week of traffic, infer policy Zero history required
OpenAI spend limits: dollars after the key is live Capability, not dollars, at paste time

Same substrate as A (MCP schemas, optional proxy). Opposite adoption order: scare → share → wrap, not sign up → policy → maybe feel something.

Honest constraints (do not lie on the homepage)

Monetization that does not break adoption

Free forever: generate and share cards (rate-limit abuse).

Paid, self-serve, no call:

User ROI this week: don’t connect the server that can dump secrets, or wrap it so those tools vanish from tools/list. Our ROI: HTML cards and a thin proxy on the existing VPS. Margin is SaaS. No GPU, no quantum, no LiveKit.

60-second script (homepage, black / pink, no docs tab)

  1. Hero: “Paste an MCP. See what it can do to you.”
  2. Example button preloads a notorious filesystem or git MCP schema so even a lurker gets a red card without pasting.
  3. Card animates tool rows. One primary share button. Secondary: “Strip the red tools — get a URL.”
  4. If they came without a server, the example is the aha. That is the lurker test A fails.

If that script cannot be shipped on cryptobook.space in the first cut, F is also a KILL. The survival depends on the playground existing, not on a slide that describes it.


What I refuse to bless

Instruction to PM

Kill A–E as products. Do not “merge” them. Take F as the ship. Borrow from A only the wrap URL + signed deny page, and only behind a card that already scared the user. If engineering says the card cannot introspect a live MCP in 60s, ship on pasted tools/list JSON plus three canned famous servers — that is enough for the tweet and the aha. The proxy can slip a week; the card cannot.

End of challenge.