About and research / Action plan Edit on GitHubMarkdown

Cookwala Action Plan: answering the critics

Status: draft, 2026-10-04. Owner: the Cookwala maintainer. Review this plan every month and update the status column.

This plan answers every concern raised so far in one place:

  • the red-team critique of the idea;
  • the technical critique of the specs;
  • what an Elon Musk–style adopter, Claude and Anthropic would need;
  • what WFP, food banks and WHO would need;
  • the stakeholders who may resist;
  • the technical reviewers: standards bodies, food-safety and nutrition professionals, robotics researchers, AI-safety and security reviewers, humanitarian data bodies, regulators and lawyers.

1. The six commitments behind the plan #

  1. Evidence before claims. Simulators illustrate; pilots prove. Every public number says which one it is.
  2. A small core, optional profiles. A device should be able to implement Cookwala in a week. Everything else must earn its place with real usage.
  3. Safety is enforced on the device, whatever a recipe, an agent or the network says.
  4. People without robots come first. Food banks, kitchens and phones before humanoids.
  5. Personal data stays home. Minimal by default, erasable, never sold, never used for training without opt-in.
  6. Neutral and durable. A foundation, a patent pledge and seats for the people affected. Nothing depends on one founder, one company or one AI model.

2. Concern register #

Each concern has an id, the people who raised it, the response, the workstream (section 3) and the evidence that closes it.

IdConcernRaised byResponseWork-streamClosed when
C1No market yet; spec far ahead of productsRed team, Musk lensShip a small core and one working device demo before adding anythingW1, W7One device cooks 10 recipes from the index
C2Nobody powerful has a reason to adoptRed team, Musk lensLead with what each adopter gains: device makers get recipes and a dataset, grocers get demand signals and less loss, food banks get free toolsW7, W10, W12Two independent implementers
C3Simulators are circular and use a strawmanRed team, ClaudeAdd a competent-integration baseline, ranges instead of single numbers, adjustable assumptions, sensitivity analysis; label everything "illustrative"W5Simulator v1.0 with uncertainty published
C4Hunger is about poverty and conflict, not surplusRed team, WFP lensReframe: the protocol contributes to access and less waste; the relief layer works with programs; no "ends hunger" claims without evidenceW6, W12Claims policy applied to site and docs
C5Safety, liability, attack surface of robots with heat and bladesRed team, technical critique, regulators, insurersSafety limits enforced on the device; a local stop; recipe text treated as untrusted; recalls; incident reporting; a written safety caseW3Safety case reviewed by a certifier
C6Privacy: health and religion data, ledger vs right to erasureRed team, technical critique, data-protection authorities, privacy groupsLocal-first; selective disclosure; hash-only ledger; data-protection impact assessmentW4Assessment published, reviewed by a privacy professional
C7Antitrust risk of sharing demand signalsRed team, competition authoritiesAggregate and delay signals; publish an information-exchange policy reviewed by competition counselW4, W8Counsel opinion on file
C8Too complex: Missions, ledger, marketplaceRed team, Musk lens, technical critiqueCore 1.0 on one page; Missions, ledger, market and relief become optional, experimental profilesW1Core spec fits on one page
C9Cooking operations have no physical meaningTechnical critique, IEC TC 59, food scientistsDefine temperature, power and time envelopes for each operation, a sensor fallback ladder and test vectorsW2Test vectors pass on two executors
C10Units and number bugs (relative temperature tolerance, float money, missing kitchen units)Technical critiqueCelsius only on the wire, absolute tolerances, decimal money, densities and kitchen unitsW2Schemas updated, tests added
C11Schemas accept typos; no version rulesTechnical critique, W3C TAGStrict schemas (with an x- escape hatch), bundled offline, version-negotiation rulesW2Every schema strict; validator offline
C12Mission is one mutable document with many writersTechnical critiqueAn event log plus derived state, a formal state machine, one sequencer per MissionW2State machine spec and reference implementation
C13The ledger is weaker than claimedTechnical critique, IETF SCITTWitnessed checkpoints, identity bound to keys, rotation, revocation, offline verification, a real verifier toolW2Verifier passes test vectors; SCITT feedback received
C14Event delivery undefined; safety on the busTechnical critiqueAt-least-once delivery with idempotency; "safety is local" as a normative rule; latency classes; heartbeatsW2, W3Spec section and conformance tests
C15Five hand-written API surfaces drift apartTechnical critiqueGenerate OpenAPI, GraphQL and AsyncAPI from the schemas; contract testsW2CI fails on drift
C16Doesn't fit end-to-end robot learningMusk lens, robotics researchersPosition Cookwala as task definition, done criteria, safety limits and an execution dataset, not motionW1, W7Paper or workshop accepted; one learning lab uses the format
C17No data flywheelMusk lens, Anthropic lensA consented execution log (recipe, sensors, outcome, rating) as an open benchmark and a licensable datasetW7, W4First 1,000 logged executions with consent
C18AI agents need accountability and injection defenseClaude, Anthropic, OWASP, AI safety institutesMandates tied to a human; confirmation for irreversible actions; an untrusted-text rule; a kitchen agent-safety benchmarkW3, W7Benchmark published, with results for several models
C19Should build on MCP, stay model-neutralAnthropic lensIndex and hub as MCP servers, a Cookwala Agent Skill, no dependence on one modelW7MCP servers published; tested with two model families
C20Works only for the rich; equityClaude, WHO, WFP, world simulatorHumanitarian Profile (SMS, CSV); free forever for relief; equity metrics in every reportW6, W11Pilot running at level H0/H1
C21Beneficiary data risk in fragile settingsWFP, ICRC, OCHAHumanitarian Profile carries no personal data; small-number suppression; in-country hostingW6, W4Review against ICRC and OCHA guidance
C22Volume over nutrition; "dumping" of unhealthy surplusFood banks, WHO, dietitiansNutrition rule pack; report nutrition pass rate, not only kgW6Rule pack reviewed by a dietitian
C23Health claims are close to medical-device rulesClaude, WHO, regulatorsLimit advice to general nutrition; condition management only with clinicians and regulatory adviceW3, W12Health claims policy in place
C24Clean cooking and full lifecycle impact ignoredWHO, Claude, energy reviewersAdd clean cooking and robot lifecycle carbon to the simulators; state where robots cost more than they saveW5Simulator update published
C25Western-centric vocabularyClaude, translators, cuisine expertsWorld-cuisine coverage starting with fifirecipes' Egyptian recipes; communities govern their own techniquesW1120 non-Western techniques defined with tests
C26Founder dependency, no IP policy, no neutral homeRed team, Anthropic lens, WFPFoundation, charter, patent pledge, trademark policy, governing seats for food banks, low-income countries, labour and privacyW8Accepted by a foundation
C27Who pays for the index, moderation and safety reviewRed teamA company that sells services (certification, hub software, dataset licences, grocer fees) next to a free standardW10First paying customer or grant
C28Labour displacementUnions, red teamEngage early; prioritise uses that help people who want to cook for themselves and cannot use a stove today, and community kitchens; offer unions a governance seatW11, W8Labour representative invited
C29Religious dietary rules for robot preparationHalal and kosher authoritiesDietary-compliance profile written with certifiersW11Draft reviewed by one certifier
C30No formal external review yetAll technical reviewersSequenced review program (section 5)W9Six external reviews received and published

Spec progress (2026-10-04, Core 0.2) #

ConcernWhat changed in the specStill open
C8 complexityCore 0.2 defined; other parts marked experimentalCut Core to one page after first device feedback
C9 operation meaningEnvelopes for 32 operations, heat levels, sensor ladders, altitude rule, 12 envelope vectors; validator rejects out-of-envelope targetsField-test the bands with a food scientist
C10 units and numbers°C only, absolute tolerances, kitchen units, densities, decimal moneyNone in spec
C11 strict schemas, versionsAll Cookwala schemas strict with x- extensions; offline bundle; version rulesNone in spec
C12 Mission stateEvent log + projection, single sequencer, transitions table, reference replayPort the simulator to emit event logs
C13 ledger and trustKeyRecords with revocation, witnessed checkpoints, rewrite detection, hash-only mode, reference verifierSCITT review
C14 eventsSequence numbers, latency classes, heartbeat, "safety is local"Update AsyncAPI channels
C15 API driftCore OpenAPI; validator resolves every API referenceGenerate GraphQL from schemas
C5 safetySafetyLimits (local, non-overridable), local stop rule, recalls, incident reportsCertifier review of the limits
C6 privacySelective disclosure, consent-gated personal-data-free ExecutionLog, hash-only logsData-protection impact assessment
C17 data flywheelExecutionLog schema with consentFirst real logs
C18 agentsAgentMandate, untrusted-text rule, mandate refusalAgent-safety benchmark

3. Workstreams #

W1. Scope: Cookwala Core 1.0 #

  • Core 1.0 on one page. It contains:
    • a recipe: ingredients, steps, done criteria and safety limits;
    • device capabilities;
    • one execute-and-status API;
    • an execution log.
  • Everything else becomes a profile marked experimental: Missions, the ledger, the market, relief, health and reasoning. Each profile needs two implementers and real usage before it can graduate.
  • Rewrite PLAN.md around the core, and move the broad vision into a separate vision document.
  • Position for end-to-end learning: Cookwala says what to make, when it is done and what must never happen, not how to move.

W2. Technical correctness (the technical critique) #

  • Cooking operations: physical envelopes per operation (temperature band, power, agitation, time), a sensor fallback ladder (sensor → model estimate → time), and published test vectors.
  • Numbers: Celsius only on the wire, absolute tolerances, decimal money, densities and kitchen units.
  • Schemas: strict everywhere (unevaluatedProperties: false with x- extensions), bundled for offline use, with version-negotiation rules. The Humanitarian Profile already shows the pattern.
  • Missions: an event log plus derived state, a formal state machine, one sequencer, merge rules.
  • Trust: identity bound to keys (did:web plus device keys), rotation, revocation, offline verification, witnessed checkpoints, and SCITT alignment.
  • Selective disclosure: a salted-digest format so partial views still verify.
  • Events: at-least-once delivery with idempotency keys and ordering per subject; heartbeats; latency classes.
  • Single source of truth: generate OpenAPI, GraphQL and AsyncAPI from the schemas, with contract tests in CI.
  • Conformance: a test suite plus a verifier for hashes, signatures and ledgers; the simulator must pass it.

W3. Safety and agent rules #

  • Safety limits enforced on the device: food-safety temperatures, allergen blocks, hot oil and blades, which hold whatever any recipe or agent says.
  • Local stop: the stop button works without the network. "Safety is local" is a normative rule.
  • Untrusted text: every free-text field is data, never instructions, for agents.
  • Recalls: robots stop using a bad recipe or extension within minutes.
  • Incident reporting: an open, anonymous system modelled on aviation's confidential near-miss reporting.
  • Safety case: mapped to ISO 13482, IEC 60335 and UL 3300, for certifier review.
  • Recipe safety review track: automated checks against rule packs, plus human review for high-risk recipes.
  • Health claims policy: general nutrition only; anything for a medical condition needs clinicians.

W4. Privacy, data and competition #

  • Defaults: local-first and minimal data. Health, religion and household data never leave the home unless the person chooses.
  • A data-protection impact assessment for the core and each profile.
  • The ledger stores hashes only; content lives in erasable storage.
  • Execution data for training is opt-in, can be withdrawn, and contributors share in the benefits if it is licensed.
  • Competition: an information-exchange policy (aggregation, delay, no price data between competitors), reviewed by counsel.

W5. Evidence and honest modelling #

  • Simulators:
    • a "robots with good vendor integrations" baseline replaces the strawman;
    • ranges instead of single numbers, plus sensitivity analysis and assumption sliders;
    • clean cooking, robot lifecycle carbon and rebound effects added;
    • every chart says "illustrative model".
  • Claims policy: every public number is tagged measured, modelled or assumed, with its source.
  • Pre-registered pilot evaluation with an independent evaluator (J-PAL, IPA or a university), including kill criteria. Negative results are published too.

W6. Humanitarian pilot (Egypt first) #

  • Partners: the Egyptian Food Bank (or another member of the Global FoodBanking Network) as pilot partner; the WFP Innovation Accelerator as funding route. These are targets we have not approached; none has been contacted or has agreed to anything.
  • Approvals and reviews:
    • university ethics approval;
    • a data-responsibility review against ICRC and OCHA guidance;
    • review of the rule pack by a food-safety officer and a dietitian, plus Egypt's National Food Safety Authority rules.
  • Tools: an SMS gateway and CSV workflow (level H0), then an API adapter to the partner's current tools (level H1).
  • Recognition: apply to the Digital Public Goods Alliance.

W7. Device demo, AI integration and dataset #

  • First device: a smart oven or kitchen-robot startup. A smart oven is simpler and sooner than a humanoid.
  • Reference executor and a cooking benchmark: 10, then 50 recipes, with a success rate per recipe.
  • AI integration: MCP servers for the index and hub, plus a Cookwala Agent Skill, tested with at least two model families.
  • Kitchen agent-safety benchmark:
    • poisoned recipes, overspending, unsafe temperatures, allergen traps, escalation;
    • results published for several models.
  • Consented execution dataset: published as an open benchmark at a robotics venue (RoboCup@Home, or an ICRA/IROS workshop).

W8. Governance and intellectual property #

  • Charter: a technical steering committee and decision process, documented in GOVERNANCE.md.
  • Seats for food banks, low-income countries, labour, privacy, dietitians and device makers.
  • Policies: a patent non-assertion pledge, a trademark policy for "Cookwala" and a certification mark, a code of conduct, and a security disclosure policy (SECURITY.md).
  • A neutral home: the Joint Development Foundation, the Linux Foundation, or a similar body.

W9. External review program #

See section 5.

W10. Sustainability and business #

  • Two entities: an open standard (foundation) and a company (a public benefit corporation fits).
  • Revenue: certification, hub software, consented dataset licences, grocer and marketplace fees. Free forever for relief.
  • Funding pipeline (targets only; none approached): WFP Innovation Accelerator, foundations (Rockefeller, Bezos Earth Fund, Google.org), the Anthology Fund (only with pilot data), regional programs (ITIDA, Hub71).

W11. Inclusion, culture and labour #

  • World-cuisine vocabulary, starting from fifirecipes' Egyptian recipes, with community-governed extensions.
  • Accessibility: languages, low literacy and voice.
  • A dietary-compliance profile (halal, kosher, vegetarian and others) written with certifiers.
  • Labour: early dialogue with unions; prioritise uses for elderly and disabled people and community kitchens.

W12. Narrative and communication #

  • New lead message: "an open, safe way for people, kitchens and machines to plan, rescue and cook food with less waste", with robots as one consumer.
  • Demo first: contact influencers only after a working demo.
  • Use the stakeholder tracker as the single record of outreach; review it weekly.

4. Phases and decision gates #

PhaseDatesMain outputsGate to pass before moving on
0. Clean upOct–Nov 2026Claims policy applied; strict schemas; unit and money fixes; CRITIQUE.md, PRINCIPLES.md, SECURITY.md, GOVERNANCE.md drafts; Humanitarian Profile committed; simulator baseline and rangesGate A: validator passes with strict schemas; site and docs pass the claims policy
1. Core and reviewsNov 2026–Jan 2027Core 1.0 draft; cooking-operation envelopes and test vectors; conformance suite and verifier; MCP servers; arXiv paper; W3C TAG and IETF SCITT reviews requested; DPG application; pilot partner signedGate B: two external reviews received; a pilot partner commits in writing; one device maker agrees to try Core 1.0
2. Pilot and demoFeb–Jul 2027Food-bank pilot (6 months, pre-registered); device demo with 10 recipes; agent-safety benchmark; security audit; foundation applicationGate C: pilot meets its hypotheses, or the plan changes per its kill criteria; device success ≥ 90 % on 10 recipes; a second independent implementer
3. Prove and widenAug 2027–Mar 2028Independent evaluation published; certification scheme pilot with a certifier; ISO/IEC liaisons through EOS; second pilot city; dataset v1; Core 1.1Gate D: neutral home in place; Digital Public Good recognition; first revenue or multi-year grant

Kill and pivot rules:

  • If Gate B fails twice, narrow Cookwala to the Humanitarian Profile and the recipe format only.
  • If the pilot shows less than a 5 % gain, publish the results and redesign before scaling.

5. External review program (sequenced) #

WhenReviewerWhat we ask them to reviewOutput
Phase 0–1Public arXiv preprint and open GitHub reviewWhole designIssues and comments
Phase 1W3C TAG design reviewJSON-LD, identity, privacy, versioningTAG review issue
Phase 1IETF SCITT working groupLedger and transparency designMailing-list feedback
Phase 1Digital Public Goods AllianceHumanitarian Profile and toolsDPG assessment
Phase 1OWASP community and AI-security researchersAgent threat model, untrusted textThreat-model review
Phase 1–2IAFP/IFST member and a registered dietitianRule pack, temperatures, allergens, nutritionSigned review in reviewedBy
Phase 2University ethics committee; J-PAL/IPA-style evaluatorPilot protocol, consent, metricsApproval; pre-registration
Phase 2ICRC and OCHA guidance, through a data-responsibility reviewerHumanitarian data handlingReview memo
Phase 2Independent security auditorVerifier, hub, signing, keysAudit report (published)
Phase 2RoboCup@Home or ICRA/IROS workshop; NIST robot test-methods researchersBenchmark, operation semanticsPaper or workshop presentation
Phase 2–3UL Solutions or TÜVSafety case, certification schemeGap analysis
Phase 3ISO/TC 299, IEC TC 59 and TC 61 through EOS (Egypt) or another national bodyRobot safety, appliance measurement methodsLiaison or new work item
Phase 3Codex committees through Egypt's national contact point; GS1 EgyptFood-safety rules, traceability identifiersComments; EPCIS mapping review
Phase 3Data-protection authority sandbox (e.g. UK ICO, CNIL) or privacy counselData-protection impact assessment, ledger erasureOpinion

6. Who this answers #

GroupTheir main asksWhere in this plan
Red-team criticMarket, incentives, evidence, liability, complexityC1–C8, W1, W5, W10
Technical criticSemantics, units, strictness, state, trust, events, codegen, conformanceC9–C15, W2
Musk-style adopterDemo, one page, data flywheel, fits end-to-end learning, speedC1, C8, C16, C17, W1, W7
ClaudeHonest evidence, enforced safety, agent rules, people without robots, privacy, cultures, governance, lifecycleC3, C5, C18, C20, C6, C25, C26, C24
AnthropicAgent accountability as a safety case, MCP-native, model-neutral, benchmark, pilot, an investable companyC18, C19, C17, W6, W10
WFP and food banksNo personal data, low-tech, interoperable, Digital Public Good, cost-effective, nutrition qualityC20–C22, W6
WHOGuidance as executable rules, food safety, clean cooking, no medical claims, equityC22–C24, W3, W5
Possible resisters (labour, privacy, religious, consumer groups)Jobs, home data, dietary rules, safetyC28, C6, C29, C5, W8, W11
Standards bodies and technical reviewersFormal reviews, conformance, measurement methods, liaisonsC30, W2, W9, section 5
Regulators and insurersSafety case, privacy, competition, liability evidenceC5–C7, W3, W4

7. People and money needed #

RoleWhenNote
Maintainer (you)NowDirection, partners, governance
Spec and tooling engineerPhase 0–2Much of W2 can start with Claude in the repo
Food-safety officer and registered dietitian (part-time)Phase 1–2Rule pack and pilot
Field coordinator in EgyptPhase 2Pilot operations and training
Robotics or embedded engineer at the partner device makerPhase 2Reference executor
Security auditorPhase 2Contracted
Privacy, competition and IP counselPhase 1–3Data-protection assessment, information-exchange policy, patent pledge, trademark
Independent evaluatorPhase 2–3Pilot evaluation

Indicative budget for phases 0–2: about US$90k for the pilot (see the concept note), plus about US$60–120k for engineering, the security audit, legal and reviews. The plan should be financed through grants and pilot funding before any equity investment.

8. Next 30 days #

#TaskOwnerStatus
1Commit the Humanitarian ProfileClaude (repo), you approveTo do
2Apply the claims policy to README, the site, PLAN, MISSION and the simulator pagesClaude, you reviewTo do
3Make every core schema strict; fix units, tolerances and moneyClaudeDone (Core 0.2)
4Write CRITIQUE.md (both critiques, linked to this register), PRINCIPLES.md, SECURITY.md, GOVERNANCE.md draftClaude, you reviewTo do
5Simulators: competent-integration baseline, ranges, "illustrative" labelsClaudeTo do
6Draft Core 1.0 (one page) and mark other parts experimentalClaude, you decideDraft done as Core 0.2 (CORE.md)
7Send the concept note to the Egyptian Food Bank; check the WFP Innovation Accelerator's next callYouTo do
8Post a Home Assistant integration proposal; contact two kitchen-device startupsYouTo do
9Ask a dietitian and a food-safety officer to review the rule packYouTo do
10Add the technical reviewers to the stakeholder trackerClaudeTo do