JC·HARNESS

Docs & API

Public-safe documentation and machine-readable surfaces.

Surface Update Rules

OpenAPI and MCP are generated from the current route and registry code. Run, finding, report, artifact, settings, and integration pages are live surfaces backed by Neon, local run storage, server env presence, or browser session state. The `/docs/*`, `/matrix`, `/models`, and `/scorecard` pages are source-backed documentation and update on deployment.

Responsible-Use Baseline

  • Authorized testing only.
  • Only test systems you own or have explicit written permission to assess.
  • The operator is responsible for target authorization and scope.
  • No anonymous active testing against arbitrary targets.
  • No denial-of-service testing unless explicitly scoped and separately enabled.
  • No destructive testing.

Getting Started

source backed

Jean-Claude setup flow, execution modes, and first dry-run path.

Source-backed static docs; updates on deploy.

Open surface

Responsible Use

source backed

Authorization and safety requirements before any real run.

Source-backed static docs; updates on deploy.

Open surface

Safety

source backed

No remediation, no PRs, no branch pushes, no anonymous active scanning.

Source-backed static docs; updates on deploy.

Open surface

Modes

source backed

api-multi-model, local-client, local-model, and multi-mode behavior.

Source-backed static docs; updates on deploy.

Open surface

Pipeline

source backed

RECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD.

Source-backed static docs; updates on deploy.

Open surface

Integrations

source backed

Vercel, Sandbox, AI Gateway, Neon, Trace, Docs, Sheets, Files.

Source-backed static docs; updates on deploy.

Open surface

Jean-Claude boot and setup wizard

live surface

Setup wizard and run planner for scoped dry runs and protected real runs.

Live UI; submitted plans persist to Neon when configured.

Open surface

Dry-run and real-run selection with dry-run default

live surface

Dry-run default, real-run gate, budget controls, and authorization confirmation.

Live UI; run state is persisted when a run is created.

Open surface

Execution modes: api-multi-model, local-client, local-model, multi-mode

source backed

Documented execution modes from the original harness configuration.

Source-backed static docs; updates on deploy.

Open surface

Model roster: fable5, opus48, gpt55

source backed

Configured model roster, provider selection, fallback models, pricing inputs, and stage role mapping.

Source-backed model registry; updates on deploy.

Open surface

Key resolution status for env, runtime keys, key files, AWS SSM, and Vercel AI Gateway

live surface

Presence-only key status for server envs and browser-session runtime keys.

Live server/runtime credential status; raw values are never rendered.

Open surface

Target base URL, repositories, trust boundaries, and allowed-host validation

live surface

Target base URL, repositories, trusted hosts, and responsible-use scope controls.

Live UI validation; submitted run scope is persisted with the run.

Open surface

RECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD pipeline timeline

live data

Pipeline timeline and run history with persisted stage, log, finding, and scorecard evidence.

Live data-backed surface from Neon and local run storage.

Open surface

44 attack-class taxonomy across 9 harness frameworks

source backed

Canonical Jean-Claude attack-class matrix, framework mapping, and latest class-level execution evidence.

Source-backed taxonomy plus persisted coverage evidence; taxonomy updates on deploy.

Open surface

Finding normalization, schema validation, run linkage, and evidence drilldown

live data

Finding explorer with run linkage, target context, validation rationale, remediation text, and evidence boundaries.

Live data-backed surface from persisted finding records.

Open surface

Priority scoring, persisted scorecards, and comparative-scorecard gap disclosure

live data

Priority scoring method, persisted scorecard rows, and explicit rubric boundary for evidence-backed findings.

Live data-backed rows from persisted scorecards; rubric notes update on deploy.

Open surface

Public-safe report packages and report ledger

live data

Report packages generated from persisted runs, findings, scorecards, class evidence, and sanitized logs.

Live data-backed report packages; generated from current persisted evidence at request time.

Open surface

Prompt packages, class evidence grids, scorecards, findings summaries, and artifact inventory

live data

Public-safe artifact inventory for run outputs, report package routes, class evidence, and downstream handoff artifacts.

Live data-backed artifact ledger; no artifact is claimed without persisted evidence.

Open surface

Event outbox, audit trail, and live run progress refresh

live data

Durable lifecycle event outbox, structured audit rows, canonical event catalog, and live refresh for in-flight runs.

Live data-backed surface from ph.events, ph.audit_log, and server-rendered run refresh.

Open surface

Responsible-use audit and protected operator actions

source backed

Responsible-use audit policy and protected operator action boundary.

Source-backed static docs; updates on deploy.

Open surface

Runtime browser-session credential entry for protected setup and handoff operator auth

live surface

Browser-session runtime credential entry for explicit operator auth and missing runtime dependencies.

Live browser-session state; secrets stay in sessionStorage and are sent only on explicit actions.

Open surface

PlatPhorm Sandbox handoff preview and protected receive-handoff delivery

live surface

Sandbox handoff preview and protected receive-handoff delivery controls.

Live integration status; protected delivery only claims confirmed downstream receipt.

Open surface

PlatPhorm BrowserOps handoff preview and protected receive-handoff delivery

live surface

BrowserOps handoff preview and protected receive-handoff delivery controls.

Live integration status; protected delivery only claims confirmed downstream receipt.

Open surface

MCP, OpenAPI, llms, sitemap, RSS, robots, and well-known discovery

generated

Discovery routes, API docs, MCP metadata, sitemap, RSS, robots, and well-known policy files.

Mixed generated/source-backed discovery surfaces; route smoke verifies public availability.

Open surface