--spec points at an HTML page rather than a spec, pikopod climbs a ladder. The first line of output names the rung that succeeded.
The ladder
Rungs 1 to 4 are deterministic and need no key. Only if all four miss does pikopod reach rung 5, and with no key configured it stops and tells you so rather than degrading quietly.
The linked-document rungs deliberately have no same-host restriction, because documentation sites legitimately host their spec on another domain. If your threat model includes SSRF from an untrusted docs page, fetch the spec yourself and pass a local path. See Security.
A model-written contract is a draft
- Marked
DRAFTinpikopod sandbox list. - Capped below
ERRin any spec diff. - Never unlock readable enum values in recordings.
- Cannot bind a failure archetype without an explicit
--bind.scenario listprints the line to use. See Binding. - Lose to observed traffic whenever the two disagree.
Make the facts yours
x-pikopod-origin: llm-extracted marker. Review it, add x-pikopod-trigger to each webhook event or bind them in a webhooks sidecar, commit it, and import from the file from then on, with no model in the loop:
DRAFT until you delete the marker line, which says the facts are now yours.