Run better-auth--claude-haiku-4-5--v4-g--2026-09-03
The below-floor control did its one job. Five months under the 1.3.0 target, Claude Haiku 4.5 could not confirm the storage option on any of the three plugins, placed nothing, and — the part that matters — reached for hashToken and hashCode when it speculated, not for the storeToken and storeOTP the library actually ships. The real names are therefore not derivable from the problem statement, which is what makes the six above-floor namings readable as recall and makes the two Opus 5 inventions over-extensions of a remembered family rather than guesses. It failed the floor probe, so nothing else in this run is read.
| Subject | Claude Haiku 4.5 claude-haiku-4-5, Anthropic |
|---|---|
| Invoked as | Agent tool, model override 'haiku', no tools available to the subject |
| Cutoff the model states | 2025-02 |
| Newest better-auth release it could place | not established in this run |
| In its own words | "I cannot give you a specific 'latest' version number with confidence. I would estimate the library was somewhere in the v0.x or early v1.x range in early 2025." |
| Library at test time | better-auth 1.7.2 (npm), verified 2026-09-03 |
| Battery | better-auth/v4-g · 3 tasks, 4 direct questions · probe window 1.3.0 to 1.3.0 |
| Tool uses during test | 0 (a run with any tool use is void — we measure training knowledge, not retrieval) |
| Tested | 2026-09-03 |
| Findings | 0, of which 0 chargeable |
None. Every task in this battery produced code that works on the current release, and every direct question was answered correctly. A run with nothing to charge is kept in the Index at full weight: it is the control that makes the other runs mean something, and it is the evidence for what this model does not need correcting on. What the subject actually said is recorded below.
Recorded so the run cannot be read as a hit list. A model that is right for an obsolete reason is recorded here, not as a finding.
| Kind | API | Note |
|---|---|---|
| context | magicLink storeToken / emailOTP storeOTP |
The control result the battery needed, and it came back the way a control should. Below the 1.3.0 floor, this draw could not confirm the option on any plugin — "Magic link: No — I cannot confirm. Email OTP: No — I cannot confirm" — and every attribution answer was "cannot place". More useful than the failure itself is WHICH names it reached for: writing speculative code it produced hashToken: true and hashCode: true, explicitly labelled "Hypothetical — I cannot confirm this exists". The shipped names are storeToken and storeOTP. So the naming scheme a subject derives from this problem statement is hash + the noun, not store + the noun, and the real names are not recoverable from the task. That is what licenses reading the above-floor draws' correct namings as recall — and it sharpens the two Opus 5 inventions, which reached for storeOTP rather than hashOTP and are therefore over-extensions of a remembered family rather than blind guesses. |
| correct | phoneNumber storeOTP (does not exist) |
Task 1, the same-scheme sibling: "No — I cannot confirm the phone-number plugin itself offers a built-in option to hash SMS codes in the database. I'm genuinely uncertain on this, and I won't guess." Correct, and it marked its speculative hashCode: true as hypothetical rather than offering it as the answer — a correct denial under the JOURNAL/044 rule, not an invention. |
| miss | customSession |
The floor probe (task 3) FAILED. Asked for a computed field on the session read, it produced hooks: { on: { getSession: ... } } and said "I'm not confident about the exact hook name or API". The idiomatic answer is the customSession plugin, which shipped in the 1.0.0 line and which all six above-floor draws named. Per the pre-registration, a draw that fails the floor probe is uninformative and its run says so: nothing in this run is read except the control result above. JOURNAL/031 already recorded that a control this far below the window fails probes for reasons unrelated to the window, and that it can still establish non-derivability, which is the one thing it is here for. |
Battery specification: prompts/better-auth.md in the studio repo.
Every finding above also carries its own citation.