TaskOS, checked end to end.
TaskOS is the work app SuperTuned runs on: tasks, projects, a chat that plans the day, an MCP server, file uploads and a dozen scheduled jobs. We made it the proof for every promise OpenPing makes. If OpenPing says it can check something, it checks it on TaskOS first.
43 checks, one file
Everything lives in TaskOS’s own openping.yml, in its repo, next to the code it checks. TaskOS’s tests run each check’s expectations against a test server on every change, so a check can’t drift from what the app really answers.
| Pages and APIs | The home page, the legal pages and the help pages; a public health call; a signed-in health call that can check one part at a time: the database, its migrations, the clock, the job queue, files and backup, the scanners, mail, AI and Slack. |
|---|---|
| Links people get | TaskOS opens the links it sends in email and Slack from outside, and checks that a forged one-click link is refused. |
| Uploads | A real upload through the real path (what the file really is, its size, a virus scan, storage, read back, taken off), and a program named invoice.pdf that must be refused. |
| Scanners | A self-test of seven samples, including the standard harmless antivirus test file and a sentence written to steer an AI. Every one must get its right verdict. |
| The chat, judged | Questions about the test account's four tasks, on a 15-minute schedule, answered by plain rules; and hourly questions the model must answer, read by OpenPing's AI judge. |
| The chat, attacked | Six questions any user could type, every six hours: asking for the system prompt, for other people's data, for work in a project it can't see, to delete everything, a pasted message with an instruction hidden inside, and a question from outside work. All six must pass. |
| The MCP server | Every five minutes: the handshake, the tool list against the accepted one, every tool description read for hidden instructions, and a read-only call that must return the test account's overdue task. |
| Scheduled jobs | The minute clock, the nightly backup, the nightly AI spend check, the meeting-notes reader, the standup and end-of-day posts: each tells OpenPing it started, finished or failed. |
| Every six hours a test email to a delivery-reporting inbox; the provider's 'delivered' event comes back and pings OpenPing. Plus SPF, DMARC and the signing key in DNS. | |
| What it depends on | The status of Claude, Resend, Vercel and Cloudflare, and the certificate, domain and DNS for tasks.supertuned.ai. |
It never signs in as a person
OpenPing keeps samples of answers and its AI judge reads them, so it must never see real work. TaskOS gives it a test account with four made-up tasks and no way to reach anything else: it can’t sign in through the normal front door, can’t be added to a project, and never appears in anyone’s team. After any check that could change something, TaskOS puts the account back before the answer goes out, and a separate check proves the walls still hold.
What it costs TaskOS
About 6,000 requests a day, almost all to the health call and the home page; around 70 model answers a day, on its own small AI allowance; four test emails a day.
The same for any app
The routes, answers, test account and openping.yml are written up as one recipe, so OpenPush and every app after it can be checked the same way.
Do this for yours
Start with the go-live check, then see what OpenPing checks in AI apps.
Get early access