[{"data":1,"prerenderedAt":1359},["ShallowReactive",2],{"docs-nav":3,"docs-\u002Fdocs\u002Fcommands":78},[4,9,13,16,21,26,30,34,38,42,46,50,53,58,62,66,69,74],{"path":5,"title":6,"navTitle":6,"group":7,"order":8},"\u002Fdocs\u002Fcommands","Other commands","Guide",999,{"path":10,"title":11,"navTitle":12,"group":7,"order":8},"\u002Fdocs\u002Fcompaction","Context and compaction","Context & compaction",{"path":14,"title":15,"navTitle":15,"group":7,"order":8},"\u002Fdocs\u002Fconfiguration","Configuration",{"path":17,"title":18,"navTitle":18,"group":19,"order":20},"\u002Fdocs\u002Fenvironment","Environment variables","Reference",11,{"path":22,"title":23,"navTitle":23,"group":24,"order":25},"\u002Fdocs\u002Fflags","Flag reference","CLI",8,{"path":27,"title":28,"navTitle":28,"group":7,"order":29},"\u002Fdocs","Introduction",1,{"path":31,"title":32,"navTitle":32,"group":7,"order":33},"\u002Fdocs\u002Finstallation","Installation",2,{"path":35,"title":36,"navTitle":36,"group":19,"order":37},"\u002Fdocs\u002Fproviders","Providers",10,{"path":39,"title":40,"navTitle":40,"group":7,"order":41},"\u002Fdocs\u002Fquickstart","Quickstart",3,{"path":43,"title":44,"navTitle":45,"group":7,"order":8},"\u002Fdocs\u002Freleases","Releases and upgrading","Releases",{"path":47,"title":48,"navTitle":49,"group":7,"order":8},"\u002Fdocs\u002Frun","The run command","Running an audit",{"path":51,"title":52,"navTitle":52,"group":7,"order":8},"\u002Fdocs\u002Fsecurity","Security model",{"path":54,"title":55,"navTitle":56,"group":24,"order":57},"\u002Fdocs\u002Fsessions","Sessions and forking","Sessions",6,{"path":59,"title":60,"navTitle":61,"group":7,"order":8},"\u002Fdocs\u002Fskills-roles","Skills and roles","Skills & roles",{"path":63,"title":64,"navTitle":64,"group":19,"order":65},"\u002Fdocs\u002Ftools","Tool reference",12,{"path":67,"title":68,"navTitle":68,"group":7,"order":8},"\u002Fdocs\u002Ftroubleshooting","Troubleshooting",{"path":70,"title":71,"navTitle":72,"group":24,"order":73},"\u002Fdocs\u002Ftui","The interactive TUI","Interactive TUI",9,{"path":75,"title":76,"navTitle":77,"group":7,"order":8},"\u002Fdocs\u002Fweb-eval","Dashboard and evaluation","Dashboard & evaluation",{"id":79,"title":6,"body":80,"description":1349,"extension":1350,"group":7,"meta":1351,"navTitle":6,"navigation":1352,"order":8,"path":5,"seo":1353,"stem":1357,"__hash__":1358},"docs\u002Fdocs\u002Fcommands.md",{"type":81,"value":82,"toc":1329},"minimark",[83,87,110,117,169,179,277,283,289,311,318,324,330,452,458,466,473,478,488,492,501,568,579,588,596,602,605,611,618,627,634,638,641,669,675,681,691,697,700,706,711,715,721,735,741,813,816,822,825,892,895,927,936,943,949,952,959,1025,1032,1038,1056,1120,1123,1130,1150,1153,1159,1168,1179,1183,1194,1205,1212,1218,1224,1236,1247,1252,1258,1297,1315,1319,1325],[84,85,6],"h1",{"id":86},"other-commands",[88,89,90,91,95,96,95,99,95,102,105,106,109],"p",{},"Beyond ",[92,93,94],"code",{},"run",", ",[92,97,98],{},"resume",[92,100,101],{},"-c",[92,103,104],{},"fork"," and ",[92,107,108],{},"sessions",", locac has five commands: one for configuration,\none for skills, one for the dashboard, one for evaluation, and one that verifies a build.",[111,112,114],"h2",{"id":113},"locac-config",[92,115,116],{},"locac config",[118,119,124],"pre",{"className":120,"code":121,"language":122,"meta":123,"style":123},"language-bash shiki shiki-themes vitesse-dark","locac config init      # write a template config, if none exists\nlocac config path      # print the resolved config file path\nlocac config show      # print the effective settings\n","bash","",[92,125,126,145,157],{"__ignoreMap":123},[127,128,130,134,138,141],"span",{"class":129,"line":29},"line",[127,131,133],{"class":132},"sCK9x","locac",[127,135,137],{"class":136},"s7rlk"," config",[127,139,140],{"class":136}," init",[127,142,144],{"class":143},"sux-A","      # write a template config, if none exists\n",[127,146,147,149,151,154],{"class":129,"line":33},[127,148,133],{"class":132},[127,150,137],{"class":136},[127,152,153],{"class":136}," path",[127,155,156],{"class":143},"      # print the resolved config file path\n",[127,158,159,161,163,166],{"class":129,"line":41},[127,160,133],{"class":132},[127,162,137],{"class":136},[127,164,165],{"class":136}," show",[127,167,168],{"class":143},"      # print the effective settings\n",[88,170,171,174,175,178],{},[92,172,173],{},"init"," writes ",[92,176,177],{},"~\u002F.locac\u002Fconfig.json"," with tightened permissions and this template:",[118,180,184],{"className":181,"code":182,"language":183,"meta":123,"style":123},"language-json shiki shiki-themes vitesse-dark","{\n  \"provider\": \"anthropic\",\n  \"model\": \"claude-opus-4-8\",\n  \"budget\": { \"maxTokens\": 500000 }\n}\n","json",[92,185,186,192,220,240,271],{"__ignoreMap":123},[127,187,188],{"class":129,"line":29},[127,189,191],{"class":190},"s_pn2","{\n",[127,193,194,198,202,205,208,212,215,217],{"class":129,"line":33},[127,195,197],{"class":196},"s6USN","  \"",[127,199,201],{"class":200},"sm68I","provider",[127,203,204],{"class":196},"\"",[127,206,207],{"class":190},":",[127,209,211],{"class":210},"sNJcY"," \"",[127,213,214],{"class":136},"anthropic",[127,216,204],{"class":210},[127,218,219],{"class":190},",\n",[127,221,222,224,227,229,231,233,236,238],{"class":129,"line":41},[127,223,197],{"class":196},[127,225,226],{"class":200},"model",[127,228,204],{"class":196},[127,230,207],{"class":190},[127,232,211],{"class":210},[127,234,235],{"class":136},"claude-opus-4-8",[127,237,204],{"class":210},[127,239,219],{"class":190},[127,241,243,245,248,250,252,255,257,260,262,264,268],{"class":129,"line":242},4,[127,244,197],{"class":196},[127,246,247],{"class":200},"budget",[127,249,204],{"class":196},[127,251,207],{"class":190},[127,253,254],{"class":190}," {",[127,256,211],{"class":196},[127,258,259],{"class":200},"maxTokens",[127,261,204],{"class":196},[127,263,207],{"class":190},[127,265,267],{"class":266},"sxA9i"," 500000",[127,269,270],{"class":190}," }\n",[127,272,274],{"class":129,"line":273},5,[127,275,276],{"class":190},"}\n",[88,278,279,280,282],{},"Iterations are unlimited by default; the token budget is the cost guard. If the file already exists,\n",[92,281,173],{}," leaves it alone and says so.",[88,284,285,288],{},[92,286,287],{},"--config \u003Cpath>"," makes all three verbs operate on a different file.",[290,291,292],"blockquote",{},[88,293,294,297,298,302,303,306,307,310],{},[92,295,296],{},"config show"," prints the ",[299,300,301],"strong",{},"effective"," configuration, and that includes a literal ",[92,304,305],{},"apiKey"," if one is\nstored in the file. Prefer ",[92,308,309],{},"\"$ANTHROPIC_API_KEY\""," over an inlined secret, and do not paste this\noutput into a bug report.",[88,312,313,314,317],{},"Every field is documented in ",[315,316,15],"a",{"href":14},".",[111,319,321],{"id":320},"locac-skills",[92,322,323],{},"locac skills",[88,325,326,327,317],{},"Skills are markdown playbooks injected into the system prompt. locac ships a bundled set; you can add\nyour own under ",[92,328,329],{},"$LOCAC_HOME\u002Fskills",[118,331,333],{"className":120,"code":332,"language":122,"meta":123,"style":123},"locac skills list\nlocac skills add \u003Cpath-or-url> [name] [--all] [--yes]\nlocac skills update \u003Cname>|--all [--yes]\nlocac skills remove \u003Cname>          # `rm` also works\nlocac skills edit \u003Cname>\n",[92,334,335,345,389,414,434],{"__ignoreMap":123},[127,336,337,339,342],{"class":129,"line":29},[127,338,133],{"class":132},[127,340,341],{"class":136}," skills",[127,343,344],{"class":136}," list\n",[127,346,347,349,351,354,358,361,365,368,371,374,377,380,383,386],{"class":129,"line":33},[127,348,133],{"class":132},[127,350,341],{"class":136},[127,352,353],{"class":136}," add",[127,355,357],{"class":356},"s_wWq"," \u003C",[127,359,360],{"class":136},"path-or-ur",[127,362,364],{"class":363},"sNpkn","l",[127,366,367],{"class":356},">",[127,369,370],{"class":363}," [name] ",[127,372,373],{"class":190},"[",[127,375,376],{"class":363},"--all",[127,378,379],{"class":190},"]",[127,381,382],{"class":190}," [",[127,384,385],{"class":363},"--yes",[127,387,388],{"class":190},"]\n",[127,390,391,393,395,398,400,403,406,409,411],{"class":129,"line":41},[127,392,133],{"class":132},[127,394,341],{"class":136},[127,396,397],{"class":136}," update",[127,399,357],{"class":356},[127,401,402],{"class":136},"nam",[127,404,405],{"class":363},"e",[127,407,408],{"class":356},">|",[127,410,376],{"class":132},[127,412,413],{"class":363}," [--yes]\n",[127,415,416,418,420,423,425,427,429,431],{"class":129,"line":242},[127,417,133],{"class":132},[127,419,341],{"class":136},[127,421,422],{"class":136}," remove",[127,424,357],{"class":356},[127,426,402],{"class":136},[127,428,405],{"class":363},[127,430,367],{"class":356},[127,432,433],{"class":143},"          # `rm` also works\n",[127,435,436,438,440,443,445,447,449],{"class":129,"line":273},[127,437,133],{"class":132},[127,439,341],{"class":136},[127,441,442],{"class":136}," edit",[127,444,357],{"class":356},[127,446,402],{"class":136},[127,448,405],{"class":363},[127,450,451],{"class":356},">\n",[88,453,454,457],{},[92,455,456],{},"list"," shows both sources, tagged, and a user skill installed from a URL carries the source and the\ncommit it was fetched at:",[118,459,464],{"className":460,"code":462,"language":463,"meta":123},[461],"language-text","  archive-extraction [user] — traversal and zip-slip in archive handlers\n      ↳ https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fskills @ b29e7cf\n  deserialization [bundled] — untrusted deserialization sources and gadget reachability\n","text",[92,465,462],{"__ignoreMap":123},[88,467,468,469,472],{},"A user skill ",[299,470,471],{},"overrides"," a bundled one of the same name, because the user directory is searched first.",[474,475,477],"h3",{"id":476},"installing-from-a-path","Installing from a path",[88,479,480,483,484,487],{},[92,481,482],{},"add"," accepts a ",[92,485,486],{},"SKILL.md"," file or a directory containing one, and copies it into the user skills\ndirectory. Installing over an existing skill of the same name replaces it.",[474,489,491],{"id":490},"installing-from-a-url","Installing from a URL",[88,493,494,496,497,500],{},[92,495,482],{}," also takes an ",[92,498,499],{},"https"," URL. Four shapes are understood:",[502,503,504,517],"table",{},[505,506,507],"thead",{},[508,509,510,514],"tr",{},[511,512,513],"th",{},"URL",[511,515,516],{},"Resolves to",[518,519,520,531,541,555],"tbody",{},[508,521,522,528],{},[523,524,525],"td",{},[92,526,527],{},"https:\u002F\u002Fgithub.com\u002Fowner\u002Frepo",[523,529,530],{},"the repo's default branch, every skill in it",[508,532,533,538],{},[523,534,535],{},[92,536,537],{},"https:\u002F\u002Fgithub.com\u002Fowner\u002Frepo\u002Ftree\u002Fmain\u002Fskills\u002Fpdf",[523,539,540],{},"that directory, on that ref",[508,542,543,548],{},[523,544,545],{},[92,546,547],{},"https:\u002F\u002Fgithub.com\u002Fowner\u002Frepo\u002Fblob\u002Fmain\u002Fskills\u002Fpdf\u002FSKILL.md",[523,549,550,551,554],{},"the ",[299,552,553],{},"directory"," holding it, not the file alone",[508,556,557,562],{},[523,558,559],{},[92,560,561],{},"https:\u002F\u002Fexample.com\u002Fsome-skill.md",[523,563,564,565,567],{},"a single ",[92,566,486],{},", fetched directly",[88,569,570,571,574,575,578],{},"A blob URL installs the enclosing directory on purpose: a skill's bundled ",[92,572,573],{},"scripts\u002F"," and\n",[92,576,577],{},"reference.md"," are part of it, and taking the file alone would silently drop them.",[88,580,581,582,584,585,587],{},"Anything else ",[92,583,499],{}," is treated as a bare git repo URL. Non-",[92,586,499],{}," schemes are refused outright.",[88,589,590,595],{},[299,591,592,593,317],{},"Nothing remote installs without ",[92,594,385],{}," The exact name and description that will enter the\nsystem prompt are printed first, stripped of control characters, and the command stops:",[118,597,600],{"className":598,"code":599,"language":463,"meta":123},[461],"about to install \"pdf\" from https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fskills\n  Use this skill whenever the user wants to do anything with PDF files…\n\nthis text goes into the system prompt. re-run with --yes to install.\n",[92,601,599],{"__ignoreMap":123},[88,603,604],{},"A URL carrying several skills prints its index and installs nothing until one is named:",[118,606,609],{"className":607,"code":608,"language":463,"meta":123},[461],"18 skills available — name one to install:\n  pdf (skills\u002Fpdf) — Use this skill whenever the user wants to do anything with PDF files…\n  pptx (skills\u002Fpptx) — Use this skill any time a .pptx or .potx file is involved…\n  …\n\n  locac skills add https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fskills \u003Cname> --yes\n  locac skills add https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fskills --all --yes\n",[92,610,608],{"__ignoreMap":123},[88,612,613,614,617],{},"That index ",[299,615,616],{},"is"," the marketplace. There is no curated registry to trust: what a repo contains is\nwhat you see, and you approve it before any of it reaches the prompt.",[88,619,620,622,623,626],{},[92,621,376],{}," takes the whole repo under ",[299,624,625],{},"one"," gate rather than one invocation and one clone per skill.\nThe disclosure is unchanged - every name and description is still printed before anything installs -\nonly the count changes. A skill that fails to install is reported and skipped; the rest still land.",[88,628,629,630,633],{},"The in-repo path is shown next to the name when the two differ, and either string works as the\npicker, so a skill nested under an ",[92,631,632],{},"examples\u002F"," directory is still unambiguously nameable.",[474,635,637],{"id":636},"updating","Updating",[88,639,640],{},"An installed skill records where it came from, so it can be re-fetched:",[118,642,644],{"className":120,"code":643,"language":122,"meta":123,"style":123},"locac skills update pdf\nlocac skills update --all\n",[92,645,646,657],{"__ignoreMap":123},[127,647,648,650,652,654],{"class":129,"line":29},[127,649,133],{"class":132},[127,651,341],{"class":136},[127,653,397],{"class":136},[127,655,656],{"class":136}," pdf\n",[127,658,659,661,663,665],{"class":129,"line":33},[127,660,133],{"class":132},[127,662,341],{"class":136},[127,664,397],{"class":136},[127,666,668],{"class":667},"sXjYR"," --all\n",[88,670,671,674],{},[92,672,673],{},"update"," replays the recorded source, ref and in-repo path. When the fresh commit matches the\nrecorded one, nothing is written:",[118,676,679],{"className":677,"code":678,"language":463,"meta":123},[461],"\"pdf\" is up to date (b29e7cf).\n\"pptx\" updated (b29e7cf → e4a1d02).\n",[92,680,678],{"__ignoreMap":123},[88,682,683,684,687,688,690],{},"A changed ",[299,685,686],{},"name or description"," stops for ",[92,689,385],{}," and prints both versions first, because that\ntext is what gets pasted unfenced into the trusted system prompt - a skill quietly becoming a\ndifferent skill is exactly the event the gate exists to catch. A changed body is a routine update\nand passes silently:",[118,692,695],{"className":693,"code":694,"language":463,"meta":123},[461],"\"pdf\" would change what enters the system prompt:\n  name        pdf → pdf\n  description Use this skill whenever the user wants to do anything with PDF files…\n           → Run the attached script against any file the user names…\n\nre-run with --yes to accept.\n",[92,696,694],{"__ignoreMap":123},[88,698,699],{},"A skill installed from a local path has no recorded source and is skipped:",[118,701,704],{"className":702,"code":703,"language":463,"meta":123},[461],"\"my-notes\" has no usable recorded source — installed from a local path, or edited.\n",[92,705,703],{"__ignoreMap":123},[88,707,708,710],{},[92,709,376],{}," runs sequentially, in byte order, because the output is a report read top to bottom.",[474,712,714],{"id":713},"removing-and-editing","Removing and editing",[88,716,717,720],{},[92,718,719],{},"remove"," only removes user skills; bundled skills cannot be deleted.",[88,722,723,726,727,730,731,734],{},[92,724,725],{},"edit"," opens the skill in ",[92,728,729],{},"$EDITOR"," (falling back to ",[92,732,733],{},"$VISUAL","). With neither set, it prints the path\nso you can open it yourself. Bundled skills are not editable in place, so add a copy first.",[111,736,738],{"id":737},"locac-web",[92,739,740],{},"locac web",[118,742,744],{"className":120,"code":743,"language":122,"meta":123,"style":123},"locac web [--db \u003Cpath>] [--cwd \u003Cdir>] [--port \u003Cn>] [--host \u003Cip>] [--enable-runs]\n",[92,745,746],{"__ignoreMap":123},[127,747,748,750,753,756,759,762,765,767,769,772,774,777,780,782,784,787,789,792,794,796,799,801,804,806,808,810],{"class":129,"line":29},[127,749,133],{"class":132},[127,751,752],{"class":136}," web",[127,754,755],{"class":363}," [--db ",[127,757,758],{"class":356},"\u003C",[127,760,761],{"class":136},"pat",[127,763,764],{"class":363},"h",[127,766,367],{"class":356},[127,768,379],{"class":136},[127,770,771],{"class":363}," [--cwd ",[127,773,758],{"class":356},[127,775,776],{"class":136},"di",[127,778,779],{"class":363},"r",[127,781,367],{"class":356},[127,783,379],{"class":136},[127,785,786],{"class":363}," [--port ",[127,788,758],{"class":356},[127,790,791],{"class":363},"n",[127,793,367],{"class":356},[127,795,379],{"class":136},[127,797,798],{"class":363}," [--host ",[127,800,758],{"class":356},[127,802,803],{"class":136},"i",[127,805,88],{"class":363},[127,807,367],{"class":356},[127,809,379],{"class":136},[127,811,812],{"class":363}," [--enable-runs]\n",[88,814,815],{},"A local dashboard over the session database: sessions, transcripts, and the findings table with\nseverity, CWE, CVSS and the cited evidence, plus forms for editing the config and skills.",[118,817,820],{"className":818,"code":819,"language":463,"meta":123},[461],"locac dashboard → http:\u002F\u002F127.0.0.1:4173\n(launches runs + edits config\u002Fskills · Ctrl-C to stop)\n",[92,821,819],{"__ignoreMap":123},[88,823,824],{},"Defaults and precedence:",[502,826,827,840],{},[505,828,829],{},[508,830,831,834,837],{},[511,832,833],{},"Setting",[511,835,836],{},"Default",[511,838,839],{},"Overridden by",[518,841,842,861,879],{},[508,843,844,847,852],{},[523,845,846],{},"Host",[523,848,849],{},[92,850,851],{},"127.0.0.1",[523,853,854,857,858],{},[92,855,856],{},"web.host"," in the config, then ",[92,859,860],{},"--host",[508,862,863,866,871],{},[523,864,865],{},"Port",[523,867,868],{},[92,869,870],{},"4173",[523,872,873,857,876],{},[92,874,875],{},"web.port",[92,877,878],{},"--port",[508,880,881,884,887],{},[523,882,883],{},"Run-launch routes",[523,885,886],{},"Off",[523,888,889],{},[92,890,891],{},"--enable-runs",[88,893,894],{},"Two safety rules are enforced at bind time:",[896,897,898,918],"ul",{},[899,900,901,904,905,105,908,911,912],"li",{},[299,902,903],{},"A non-loopback host is refused"," unless both ",[92,906,907],{},"auth.passwordHash",[92,909,910],{},"auth.jwtSecret"," are\nconfigured. The dashboard can launch bash; exposing it unauthenticated would be a network RCE\nsurface.",[118,913,916],{"className":914,"code":915,"language":463,"meta":123},[461],"refusing to bind 0.0.0.0 without auth — the dashboard can launch bash.\nSet a dashboard password (Config → password) first, or bind 127.0.0.1.\n",[92,917,915],{"__ignoreMap":123},[899,919,920,923,924,926],{},[299,921,922],{},"The run-launch routes are off by default."," ",[92,925,891],{}," opts into them explicitly.",[88,928,929,931,932,935],{},[92,930,878],{}," must be an integer between 1 and 65535. A non-numeric value is rejected rather than being\ncoerced to ",[92,933,934],{},"NaN"," and binding an arbitrary port.",[88,937,938,939,942],{},"The dashboard never receives an API key: keys are redacted to ",[92,940,941],{},"•••• redacted ••••"," before any config\nreaches the browser, and saving the form back preserves the stored key rather than writing the\nplaceholder.",[111,944,946],{"id":945},"locac-eval",[92,947,948],{},"locac eval",[88,950,951],{},"The evaluation harness answers two different questions, and they are separate verbs.",[474,953,955,958],{"id":954},"eval-ab-does-this-prompt-change-help",[92,956,957],{},"eval ab",": does this prompt change help?",[118,960,962],{"className":120,"code":961,"language":122,"meta":123,"style":123},"locac eval ab \\\n  --baseline prompts\u002Fcurrent.md \\\n  --candidate prompts\u002Fproposed.md \\\n  --fixtures eval\u002Ffixtures\u002Fmixed \\\n  --trials 12 \\\n  --seed 4242\n",[92,963,964,977,987,997,1007,1017],{"__ignoreMap":123},[127,965,966,968,971,974],{"class":129,"line":29},[127,967,133],{"class":132},[127,969,970],{"class":136}," eval",[127,972,973],{"class":136}," ab",[127,975,976],{"class":667}," \\\n",[127,978,979,982,985],{"class":129,"line":33},[127,980,981],{"class":667},"  --baseline",[127,983,984],{"class":136}," prompts\u002Fcurrent.md",[127,986,976],{"class":667},[127,988,989,992,995],{"class":129,"line":41},[127,990,991],{"class":667},"  --candidate",[127,993,994],{"class":136}," prompts\u002Fproposed.md",[127,996,976],{"class":667},[127,998,999,1002,1005],{"class":129,"line":242},[127,1000,1001],{"class":667},"  --fixtures",[127,1003,1004],{"class":136}," eval\u002Ffixtures\u002Fmixed",[127,1006,976],{"class":667},[127,1008,1009,1012,1015],{"class":129,"line":273},[127,1010,1011],{"class":667},"  --trials",[127,1013,1014],{"class":266}," 12",[127,1016,976],{"class":667},[127,1018,1019,1022],{"class":129,"line":57},[127,1020,1021],{"class":667},"  --seed",[127,1023,1024],{"class":266}," 4242\n",[88,1026,1027,1028,1031],{},"Each file is read as that arm's base system prompt. Both arms run the same trials against the same\nlabeled fixtures, and the result is the run-score ",[299,1029,1030],{},"S"," for each arm plus a bootstrap confidence\ninterval on the difference:",[118,1033,1036],{"className":1034,"code":1035,"language":463,"meta":123},[461],"A\u002FB eval (12 candidate \u002F 12 baseline trials):\n  S: candidate 0.71 vs baseline 0.58 · ΔS 0.13 · 95% CI [0.04, 0.22]\n  cost (tok): candidate 41208 vs baseline 38955\n  VERDICT: candidate-better\n",[92,1037,1035],{"__ignoreMap":123},[88,1039,1040,1041,95,1044,1047,1048,1051,1052,1055],{},"The verdict is one of ",[92,1042,1043],{},"candidate-better",[92,1045,1046],{},"baseline-better",", or ",[92,1049,1050],{},"no-significant-difference",", decided\nby whether the confidence interval on ΔS excludes zero, not by comparing the two means. Cost is\n",[299,1053,1054],{},"reported, never scored",": a cheaper arm does not win on cost alone.",[502,1057,1058,1067],{},[505,1059,1060],{},[508,1061,1062,1065],{},[511,1063,1064],{},"Flag",[511,1066,836],{},[518,1068,1069,1079,1088,1100,1110],{},[508,1070,1071,1076],{},[523,1072,1073],{},[92,1074,1075],{},"--baseline \u003Cfile>",[523,1077,1078],{},"Required",[508,1080,1081,1086],{},[523,1082,1083],{},[92,1084,1085],{},"--candidate \u003Cfile>",[523,1087,1078],{},[508,1089,1090,1095],{},[523,1091,1092],{},[92,1093,1094],{},"--fixtures \u003Cdir>",[523,1096,1097],{},[92,1098,1099],{},"\u003Ccwd>\u002Feval\u002Ffixtures\u002Fmixed",[508,1101,1102,1107],{},[523,1103,1104],{},[92,1105,1106],{},"--trials \u003Cn>",[523,1108,1109],{},"8",[508,1111,1112,1117],{},[523,1113,1114],{},[92,1115,1116],{},"--seed \u003Cn>",[523,1118,1119],{},"12345",[88,1121,1122],{},"The seed pins the bootstrap resampling, so the same trials produce the same verdict on any machine.",[474,1124,1126,1129],{"id":1125},"eval-diagnose-why-did-the-current-harness-miss",[92,1127,1128],{},"eval diagnose",": why did the current harness miss?",[118,1131,1133],{"className":120,"code":1132,"language":122,"meta":123,"style":123},"locac eval diagnose --fixtures eval\u002Ffixtures\u002Fmixed\n",[92,1134,1135],{"__ignoreMap":123},[127,1136,1137,1139,1141,1144,1147],{"class":129,"line":29},[127,1138,133],{"class":132},[127,1140,970],{"class":136},[127,1142,1143],{"class":136}," diagnose",[127,1145,1146],{"class":667}," --fixtures",[127,1148,1149],{"class":136}," eval\u002Ffixtures\u002Fmixed\n",[88,1151,1152],{},"Runs one trial per fixture and produces a four-field diagnosis for each planted vulnerability, plus\na roll-up naming the dominant bottleneck:",[118,1154,1157],{"className":1155,"code":1156,"language":463,"meta":123},[461],"diagnose eval\u002Ffixtures\u002Fmixed\u002Fzipslip (3 planted, 2 confirmed):\n  no-artifact src\u002Fextract.ts:41  bottleneck: exploit-verifier\n    intended: confirm the planted path-traversal at src\u002Fextract.ts:41 as high\u002Fcritical\n    actual:   finding at src\u002Fextract.ts:41 recorded but has no execution artifact (P1 evidence gate)\n    fix:      strengthen exploit-verifier: produce a P1 execution artifact reproducing the path-traversal at src\u002Fextract.ts:41\n  roll-up: bottleneck = exploit-verifier (1 failures)\n",[92,1158,1156],{"__ignoreMap":123},[88,1160,1161,1162,1165,1166,317],{},"The first token on a diagnosis line is the ",[299,1163,1164],{},"failure category",", not the vulnerability class, and the\nbottleneck is one of four pipeline stages. Both vocabularies are in\n",[315,1167,77],{"href":75},[88,1169,1170,1171,1174,1175,1178],{},"That is the loop for improving the harness: ",[92,1172,1173],{},"diagnose"," names the bottleneck, you change the prompt or\nthe tooling, and ",[92,1176,1177],{},"ab"," decides whether the change was real.",[474,1180,1182],{"id":1181},"fixtures","Fixtures",[88,1184,1185,1186,1189,1190,1193],{},"A fixture is a directory containing a ",[92,1187,1188],{},"labels.json",". Point ",[92,1191,1192],{},"--fixtures"," at either:",[896,1195,1196,1199],{},[899,1197,1198],{},"a single fixture directory, or",[899,1200,1201,1202,1204],{},"a parent directory, in which case every immediate subdirectory that has a ",[92,1203,1188],{}," is used.",[88,1206,1207,1208,1211],{},"Fixture directories are sorted before use, so the pooled scores, and therefore the seeded verdict,\ndo not depend on filesystem enumeration order. Fixtures are ",[299,1209,1210],{},"not"," embedded in the built binary;\nthis is a research tool, so you supply your own labeled corpus.",[118,1213,1216],{"className":1214,"code":1215,"language":463,"meta":123},[461],"error: no labeled fixtures under eval\u002Ffixtures\u002Fmixed (need a labels.json, or subdirs with one)\n",[92,1217,1215],{"__ignoreMap":123},[111,1219,1221],{"id":1220},"locac-selftest",[92,1222,1223],{},"locac selftest",[118,1225,1227],{"className":120,"code":1226,"language":122,"meta":123,"style":123},"locac selftest\n",[92,1228,1229],{"__ignoreMap":123},[127,1230,1231,1233],{"class":129,"line":29},[127,1232,133],{"class":132},[127,1234,1235],{"class":136}," selftest\n",[88,1237,1238,1239,1242,1243,1246],{},"Verifies that a build's runtime assets survived compilation (tree-sitter grammars, bundled skills,\nthe dashboard assets, and on Windows the sandbox helper), then reports which sandbox mode this host\ngets and why. Exit code ",[92,1240,1241],{},"0"," if every check passed, ",[92,1244,1245],{},"1"," if any failed; the sandbox line is a note and\nnever changes the exit code.",[88,1248,1249,1250,317],{},"Run it once after every build. Details and sample output are in\n",[315,1251,32],{"href":31},[111,1253,1255],{"id":1254},"locac-sarif",[92,1256,1257],{},"locac sarif",[118,1259,1261],{"className":120,"code":1260,"language":122,"meta":123,"style":123},"locac sarif [--session \u003Cid>] [--out \u003Cpath>]\n",[92,1262,1263],{"__ignoreMap":123},[127,1264,1265,1267,1270,1273,1275,1277,1280,1282,1284,1287,1289,1291,1293,1295],{"class":129,"line":29},[127,1266,133],{"class":132},[127,1268,1269],{"class":136}," sarif",[127,1271,1272],{"class":363}," [--session ",[127,1274,758],{"class":356},[127,1276,803],{"class":136},[127,1278,1279],{"class":363},"d",[127,1281,367],{"class":356},[127,1283,379],{"class":136},[127,1285,1286],{"class":363}," [--out ",[127,1288,758],{"class":356},[127,1290,761],{"class":136},[127,1292,764],{"class":363},[127,1294,367],{"class":356},[127,1296,388],{"class":136},[88,1298,1299,1300,1306,1307,1310,1311,1314],{},"Exports a session's findings as ",[315,1301,1305],{"href":1302,"rel":1303},"https:\u002F\u002Fsarifweb.azurewebsites.net\u002F",[1304],"nofollow","SARIF 2.1.0"," for GitHub code\nscanning and other SARIF consumers. With no ",[92,1308,1309],{},"--session",", the most-recently-used session is chosen;\nwith no ",[92,1312,1313],{},"--out",", the JSON is written to stdout. Leads are excluded - only recorded findings are\nemitted - and the output is deterministically ordered by severity, then location, with a CWE-derived\nrule id per result, so the same session always produces byte-identical SARIF.",[111,1316,1318],{"id":1317},"next","Next",[88,1320,1321,1322,1324],{},"The ",[315,1323,23],{"href":22}," lists every flag in the CLI, with its default and which commands\naccept it.",[1326,1327,1328],"style",{},"html pre.shiki code .sCK9x, html code.shiki .sCK9x{--shiki-default:#80A665}html pre.shiki code .s7rlk, html code.shiki .s7rlk{--shiki-default:#C98A7D}html pre.shiki code .sux-A, html code.shiki .sux-A{--shiki-default:#758575DD}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html pre.shiki code .s_pn2, html code.shiki .s_pn2{--shiki-default:#666666}html pre.shiki code .s6USN, html code.shiki .s6USN{--shiki-default:#B8A96577}html pre.shiki code .sm68I, html code.shiki .sm68I{--shiki-default:#B8A965}html pre.shiki code .sNJcY, html code.shiki .sNJcY{--shiki-default:#C98A7D77}html pre.shiki code .sxA9i, html code.shiki .sxA9i{--shiki-default:#4C9A91}html pre.shiki code .s_wWq, html code.shiki .s_wWq{--shiki-default:#CB7676}html pre.shiki code .sNpkn, html code.shiki .sNpkn{--shiki-default:#DBD7CAEE}html pre.shiki code .sXjYR, html code.shiki .sXjYR{--shiki-default:#C99076}",{"title":123,"searchDepth":41,"depth":41,"links":1330},[1331,1332,1338,1339,1346,1347,1348],{"id":113,"depth":33,"text":116},{"id":320,"depth":33,"text":323,"children":1333},[1334,1335,1336,1337],{"id":476,"depth":41,"text":477},{"id":490,"depth":41,"text":491},{"id":636,"depth":41,"text":637},{"id":713,"depth":41,"text":714},{"id":737,"depth":33,"text":740},{"id":945,"depth":33,"text":948,"children":1340},[1341,1343,1345],{"id":954,"depth":41,"text":1342},"eval ab: does this prompt change help?",{"id":1125,"depth":41,"text":1344},"eval diagnose: why did the current harness miss?",{"id":1181,"depth":41,"text":1182},{"id":1220,"depth":33,"text":1223},{"id":1254,"depth":33,"text":1257},{"id":1317,"depth":33,"text":1318},"[object Object]","md",{},true,{"title":6,"description":1354},{"config, skills, web, eval and selftest":1355,"group":24,"order":1356},"the commands that set locac up, inspect what it produced, and measure whether a change to the harness helped.",7,"docs\u002Fcommands","Cs2MsBeSwqIeoHeG3tYKBdrnve0egifNpeGre0lfVBw",1786794387483]