Docs & API
Public-safe documentation and machine-readable surfaces.
OpenAPI
generatedRoute contract, auth boundary, and run APIs.
Generated from the current route contract at request time.
MCP
generatedJSON-RPC metadata and tool registry.
Generated from the current MCP registry at request time.
llms.txt
generatedConcise AI-reader summary of the product boundary.
Generated from the source-backed platform registry.
Surface Update Rules
Responsible-Use Baseline
- Authorized testing only.
- Only test systems you own or have explicit written permission to assess.
- The operator is responsible for target authorization and scope.
- No anonymous active testing against arbitrary targets.
- No denial-of-service testing unless explicitly scoped and separately enabled.
- No destructive testing.
Getting Started
source backedJean-Claude setup flow, execution modes, and first dry-run path.
Source-backed static docs; updates on deploy.
Open surfaceResponsible Use
source backedAuthorization and safety requirements before any real run.
Source-backed static docs; updates on deploy.
Open surfaceSafety
source backedNo remediation, no PRs, no branch pushes, no anonymous active scanning.
Source-backed static docs; updates on deploy.
Open surfaceModes
source backedapi-multi-model, local-client, local-model, and multi-mode behavior.
Source-backed static docs; updates on deploy.
Open surfacePipeline
source backedRECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD.
Source-backed static docs; updates on deploy.
Open surfaceIntegrations
source backedVercel, Sandbox, AI Gateway, Neon, Trace, Docs, Sheets, Files.
Source-backed static docs; updates on deploy.
Open surfaceJean-Claude boot and setup wizard
live surfaceSetup wizard and run planner for scoped dry runs and protected real runs.
Live UI; submitted plans persist to Neon when configured.
Open surfaceDry-run and real-run selection with dry-run default
live surfaceDry-run default, real-run gate, budget controls, and authorization confirmation.
Live UI; run state is persisted when a run is created.
Open surfaceExecution modes: api-multi-model, local-client, local-model, multi-mode
source backedDocumented execution modes from the original harness configuration.
Source-backed static docs; updates on deploy.
Open surfaceModel roster: fable5, opus48, gpt55
source backedConfigured model roster, provider selection, fallback models, pricing inputs, and stage role mapping.
Source-backed model registry; updates on deploy.
Open surfaceKey resolution status for env, runtime keys, key files, AWS SSM, and Vercel AI Gateway
live surfacePresence-only key status for server envs and browser-session runtime keys.
Live server/runtime credential status; raw values are never rendered.
Open surfaceTarget base URL, repositories, trust boundaries, and allowed-host validation
live surfaceTarget base URL, repositories, trusted hosts, and responsible-use scope controls.
Live UI validation; submitted run scope is persisted with the run.
Open surfaceRECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD pipeline timeline
live dataPipeline timeline and run history with persisted stage, log, finding, and scorecard evidence.
Live data-backed surface from Neon and local run storage.
Open surface44 attack-class taxonomy across 9 harness frameworks
source backedCanonical Jean-Claude attack-class matrix, framework mapping, and latest class-level execution evidence.
Source-backed taxonomy plus persisted coverage evidence; taxonomy updates on deploy.
Open surfaceFinding normalization, schema validation, run linkage, and evidence drilldown
live dataFinding explorer with run linkage, target context, validation rationale, remediation text, and evidence boundaries.
Live data-backed surface from persisted finding records.
Open surfacePriority scoring, persisted scorecards, and comparative-scorecard gap disclosure
live dataPriority scoring method, persisted scorecard rows, and explicit rubric boundary for evidence-backed findings.
Live data-backed rows from persisted scorecards; rubric notes update on deploy.
Open surfacePublic-safe report packages and report ledger
live dataReport packages generated from persisted runs, findings, scorecards, class evidence, and sanitized logs.
Live data-backed report packages; generated from current persisted evidence at request time.
Open surfacePrompt packages, class evidence grids, scorecards, findings summaries, and artifact inventory
live dataPublic-safe artifact inventory for run outputs, report package routes, class evidence, and downstream handoff artifacts.
Live data-backed artifact ledger; no artifact is claimed without persisted evidence.
Open surfaceEvent outbox, audit trail, and live run progress refresh
live dataDurable lifecycle event outbox, structured audit rows, canonical event catalog, and live refresh for in-flight runs.
Live data-backed surface from ph.events, ph.audit_log, and server-rendered run refresh.
Open surfaceResponsible-use audit and protected operator actions
source backedResponsible-use audit policy and protected operator action boundary.
Source-backed static docs; updates on deploy.
Open surfaceRuntime browser-session credential entry for protected setup and handoff operator auth
live surfaceBrowser-session runtime credential entry for explicit operator auth and missing runtime dependencies.
Live browser-session state; secrets stay in sessionStorage and are sent only on explicit actions.
Open surfacePlatPhorm Sandbox handoff preview and protected receive-handoff delivery
live surfaceSandbox handoff preview and protected receive-handoff delivery controls.
Live integration status; protected delivery only claims confirmed downstream receipt.
Open surfacePlatPhorm BrowserOps handoff preview and protected receive-handoff delivery
live surfaceBrowserOps handoff preview and protected receive-handoff delivery controls.
Live integration status; protected delivery only claims confirmed downstream receipt.
Open surfaceMCP, OpenAPI, llms, sitemap, RSS, robots, and well-known discovery
generatedDiscovery routes, API docs, MCP metadata, sitemap, RSS, robots, and well-known policy files.
Mixed generated/source-backed discovery surfaces; route smoke verifies public availability.
Open surface