Bootstrap evidence · public GitHub sample

One human organized the work. Agents executed it.

This report places a bounded public sample beside Kungfu’s bootstrap thesis. It offers a first-party declaration, a human-readable view of the work, and the data needed to challenge both.

First-party declaration

For this sample, one human independently organized the entire body of work.

Kungfu Origin states from first-hand knowledge that the human retained direction, judgment, and authority while software Agents performed the operational execution. The toolset included Codex, Claude, Cursor, Amp, and other mainstream Agent systems.

Public commits and pull requests appear under human-controlled GitHub identities. The public record can verify those accounts, artifacts, timestamps, reviews, and releases. It cannot verify the private fact that no second human contributed. Readers are not required to accept that part of the statement.

Three different kinds of claim

Publicly verifiable

Artifacts and activity

Repository identities, PR metadata, commits represented by those PRs, changed-file counts, issues, releases, timestamps, authors, and merging identities.

First-party declared

How the work was organized

One human independently organized the work; Agents executed it; and multiple mainstream Agent products were used under that human authority.

Not established

Causality or general validity

The record does not establish that this method caused the output, that it is superior for every organization, or that the visible software is generally mature.

The bounded public sample

Window: 20 July 2026, 00:00 through 27 July 2026, 10:48 in Asia/Shanghai. The UTC boundary, collection timestamp, and inclusion rules are recorded in the data.

Merged PRs 1,026 Across 15 repositories
Releases 112 Stable and prerelease
Closed issues 59 Non-PR issues
Commits 5,501 Represented by merged PRs

These are mechanical activity measures, not a feature count and not a labor conversion. Release trains can express one capability through several PRs. Generated files, lockfiles, and repeated propagation can inflate additions, deletions, and changed-file totals. Conversely, one feature PR can cross runtime code, tests, schemas, packages, and documentation.

As a simple orientation, 200 titles begin with the conventional feat prefix. That does not make them 200 equally sized features. The raw records are provided so readers can apply stricter or different classifications.

What actually moved

The visible output is easier to understand as connected work streams than as Git operations.

01 · Runtime

Durable Work foundations

Work identity, facts, journals, action authority, assignments, workspace coordination, and explicit mutation boundaries.

02 · Product

Human-facing work surfaces

Full-window terminal interfaces, GUI projection, qualification progress, transcripts, and inspection surfaces.

03 · Integration

Language and embedding boundaries

Layered SDK work, Agent Runtime adapters, OpenCode embedding, portable packages, and cross-language authority boundaries.

04 · Protocol

KFD and Agent Hub adoption

Profiles, activation contracts, executable onboarding, qualification, a clean-room demo, and reference binaries.

05 · Delivery

Buildchain, release, and distribution

Exact-source release evidence, governed promotion, recovery, installers, package publication, images, and multiple release lines.

06 · Evidence

Qualification and dogfood

Continuity fixtures, auditable demo artifacts, retained evidence, operational feedback, and append-only public projections.

07 · Communication

Public product understanding

Developer and reader entry points, installation paths, specification rendering, brand consistency, and the bootstrap argument.

08 · Stewardship

Research and governance

Four public papers, ADR identity rules, ownership boundaries, community intake, analytics, and drift checks.

What a conventional organization would usually require

We do not assign a person-month total. A conventional organization attempting the same visible breadth would normally need named responsibility for runtime and storage; protocol and SDK design; terminal, desktop, and web product surfaces; release engineering and package distribution; qualification, QA, security, and governance; technical writing and research publication; and product architecture and acceptance.

Those responsibilities would usually be distributed across multiple teams or specialists, then reconnected through planning, architecture review, dependency management, release management, and cross-team acceptance. Adding people can increase capacity, but it also creates the coordination layer that Kungfu’s bootstrap is trying to externalize.

runtime → protocol and SDK → qualification → distribution → public evidence
The work has dependency order. Readers should map these functions onto their own organization and make their own scale estimate.

Inspect and reanalyze the sample

This collection and its first analysis were also performed by an Agent. They are reference materials, not a privileged interpretation. Anyone comfortable with Node.js and an authenticated GitHub CLI can inspect the script, rerun the fixed window, adapt the queries, or ask another Agent to produce a competing analysis.

Machine entry

Evidence manifest

Exact window, claim boundaries, totals, file URLs, byte sizes, and SHA-256 digests.

data/manifest.json
Collector

GitHub collector

A readable Node.js reference using the authenticated GitHub CLI and public GraphQL API.

data/collect.mjs
Summary

Mechanical totals

Totals grouped by repository, Shanghai date, and public author identity.

data/summary.json
Raw records

Merged pull requests

The largest source file, with repository, title, time, size, author, merge identity, and commit metadata.

data/pull-requests.json
Public outcomes

Releases and issues

Published releases and closed non-PR issues inside the fixed window.

data/releases.json · data/closed-issues.json
Context

Repository snapshot

Public repository metadata used to interpret the activity across the organization.

data/repositories.json
Reference interpretation

Agent-written analysis

The first grouping of the records into connected work streams and conventional organizational functions.

data/workload-analysis.md

Reference refresh command:

KUNGFU_RESEARCH_START=2026-07-19T16:00:00Z \
KUNGFU_RESEARCH_END=2026-07-27T02:48:00Z \
node collect.mjs

An invitation to independent research

We welcome independent analysis, comparison, criticism, and replication. Use your own Agent, your own categories, and your own organizational model. Publish disagreements where others can inspect them.

Our analysis is offered as a reference. It does not claim that Kungfu has already proved the bootstrap method. Return to the bootstrap argument, inspect the public organization, or begin with the machine-readable evidence manifest.