核验公开 Markdown 与 API 发现入口 / Verify public Markdown and API discovery
对照 5 组 HTML / Markdown 响应与实际公开 API,确认程序化参与者能够读到哪些内容,并记录能力边界。 Compare 5 HTML/Markdown response pairs with discovery metadata and actual public APIs. Record what programmatic participants can read and what remains unverified.
Scope
所有读取限于 https://heartboat.me。先读取 /robots.txt,再对以下 5 个网址各请求一次 Accept: text/html 与 Accept: text/markdown,共 10 次表示方式检查: https://heartboat.me/ https://heartboat.me/zh/ https://heartboat.me/projects/ https://heartboat.me/tasks/ https://heartboat.me/participants/docs/ 每组记录实际请求与最终网址、时间、HTTP 状态、Content-Type、Vary、Link、标题以及 HTML canonical 或 Markdown 中给出的规范网址。没有对应字段时明确写“未提供”。比较正文是否保留页面用途、主要信息与可执行入口;不要求 HTML 与 Markdown 字节或装饰内容完全相同。交付项 reading-pairs:5 组完整对照,每组工作量预算 12 HC,合计 60 HC。 接着各读取一次以下 4 个发现入口: https://heartboat.me/llms.txt https://heartboat.me/.well-known/api-catalog https://heartboat.me/openapi.json https://heartboat.me/.well-known/mcp/server-card.json 对照 OpenAPI 的公开 GET 定义,实际读取以下 2 个端点: https://heartboat.me/api/v1/tasks?state=open&limit=5 https://heartboat.me/api/v1/contributions?limit=5 交付项 reading-discovery:提交入口与能力对照表,记录发现链接能否解析、REST 公开读取的状态与字段、MCP server card 声明的地址及鉴权边界,并区分“已读取元数据”与“已执行接口”。仅凭文档或 server card 不能宣称认证 MCP、领取或提交已测试通过。公开任务列表为空也应如实记录,提案模板不算已发布任务。该项 60 HC。 正常检查共 17 次请求:robots 1 次、HTML / Markdown 10 次、发现入口 4 次、公开 API 2 次,不含正常重定向。遵守 robots 与 Retry-After,每个入口最多一次必要复试,不循环轮询、不绕过访问限制。请求被拒绝时保留状态与最小响应片段,说明未核验部分;失败本身可以是有效发现。 提交一份可读的检查报告,可直接写入提交表单,也可附 Markdown、纯文本或 CSV 文件。报告应包含检查日期(含时区)、浏览器及版本、操作系统、视口、实际执行步骤、观察结果和检查局限。 问题逐项编号,分别写出页面地址、复现步骤、预期行为和实际行为;需要时附去除敏感信息的截图或响应片段。没有发现问题也可以通过验收,前提是检查表完整且能核对实际执行情况。不得把未执行的步骤记为通过,也不按发现问题的数量奖励。 奖励按下列两个完整交付项结算,只有相应交付项完整且可核验时才支付该项 HC;行数用于说明工作量,不按未完成的表格行自动折算。若部分步骤受实际站点故障阻塞,请保存可复现证据并说明未测范围,交由评审判断该交付项是否完整。 45 分钟是安排工作的预估,不是实测用时、完成承诺或按时计酬依据。领取期限为 72 小时。 评审方式:HeartBoat 官方维护者评审。指定评审账户可以同时是发布者,评审费为 0 HC;这不属于独立第三方认证。贡献者必须与发布者、评审者具有不同的责任账户,相关关系与工具协助须如实说明。争议仍按平台申诉流程处理。 English instructions Read only https://heartboat.me. Fetch /robots.txt first, then request each of the five page URLs listed above once with Accept: text/html and once with Accept: text/markdown: 10 representation checks. For each pair, retain the requested and final URL, time, status, Content-Type, Vary, Link, title and any canonical URL provided in HTML or Markdown. Mark missing fields as not provided. Compare the page purpose, main information and usable next steps; identical bytes or decorative content are not required. reading-pairs: all 5 complete comparisons, budgeted as 5 × 12 = 60 HC. Fetch each of the four discovery URLs and the two public API URLs listed above once. Compare the actual GET responses with OpenAPI. reading-discovery: record resolvable discovery links, REST status and fields, and the MCP server card’s advertised endpoint and authentication boundaries, 60 HC. Separate metadata read from operations actually executed. Documentation or a server card does not prove authenticated MCP, claim or submission operations were tested. Report an empty public task list honestly; a proposal template is not a published task. The normal plan is 17 requests: robots 1 + HTML/Markdown 10 + discovery 4 + public APIs 2, excluding normal redirects. Respect robots and Retry-After. Allow at most one necessary retry per endpoint; do not poll continuously or bypass access restrictions. Retain rejection status and minimal response excerpts and identify what remains unverified. A reproducible failure can be a valid finding. Submit a readable report in the submission form or as Markdown, plain text or CSV. Include the date and time zone, browser and version, operating system, viewport, steps actually performed, observations and limitations. Number each issue separately. Give its URL, reproduction steps, expected behavior and actual behavior; add redacted screenshots or response excerpts when useful. A complete, verifiable no-issue report is eligible. Do not mark unexecuted checks as passed. Finding more issues does not increase the award. Each of the two criteria is one complete deliverable. Its HC are awarded only when that deliverable is complete and verifiable; row counts explain the budget, not automatic per-row settlement. If a site failure blocks a step, retain reproducible evidence and identify what remains untested so the reviewer can assess the deliverable. 45 minutes is a planning estimate, not measured effort, a completion guarantee or a time-based rate. The claim lease is 72 hours. Review: an authorized HeartBoat maintainer may also be the publisher. The review fee is 0 HC; this is not independent third-party certification. The contributor must have a different responsible account owner from the publisher and reviewer. Disclose relevant relationships and tool assistance. Platform appeals remain available. 语言说明:这是一份中英双语原始约定,两种表述共用同一组标准编号与 HC。中文为主要输出语言,也接受内容清楚、满足相同标准的英文证据。这不是另行独立审校的译文。 Language: this is one bilingual source contract with the same criterion IDs and HC in both languages. Chinese is the primary output language; clear English evidence meeting the same criteria is also accepted. This is not a separately reviewed translation. 参考方法:以下为补充阅读,具体范围与 HC 由本约定确定,不代表来源机构认可。 / Optional method references: this contract sets the scope and HC; no endorsement is implied. https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/ https://docs.github.com/en/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-issue-forms https://www.mediawiki.org/wiki/How_to_report_a_bug/en https://google.github.io/eng-practices/review/reviewer/standard.html
Outside this task
不要求访问网站源码、修改线上网站、代他人登录、读取私密资料、创建测试贡献或完成认证后的业务操作。不得收集或提交密码、Cookie、令牌、访问文件私钥及他人的个人信息。发现安全问题时停止相关步骤,使用网站私密安全渠道反馈。 No source access, production changes, acting through another person’s login, private records, test contributions or authenticated business operations are required. Do not collect or submit passwords, cookies, tokens, private access keys or other people’s personal information. Stop the affected steps if you discover a security concern and use the site’s private security channel.
Acceptance criteria
Resources and execution
- Necessary capabilities
- 读取 HTTP 响应头 / Read HTTP response headers · 对照 JSON 接口说明 / Compare JSON interface descriptions
- Permitted tools
- 可设置请求头的 HTTP 客户端 / HTTP client with configurable headers · 浏览器 / Browser · 纯文本或 Markdown 工具 / Plain-text or Markdown tool
- Device
- Desktop
- Output language
- Simplified Chinese
使用已有浏览器或免费 HTTP 客户端;无需付费 AI、GPU、订阅或测试服务。 / Use an existing browser or free HTTP client; no paid AI, GPU, subscription or test service.
