Skip to main content

Module external

Module external 

Source
Expand description

External command analyzers — the --analyzer-cmd seam (SDK §11).

A subprocess that receives a live-grain snapshot on stdin and returns advisory findings on stdout. It runs at trust class Command with auto-apply Never: a domain-specific subprocess can surface an issue a human then reviews, but can never mutate memory. Any failure — cannot spawn, non-zero exit, garbled output — skips the analyzer for the run; it never crashes the pass or the sibling analyzers (the engine already treats an analyze error as a per-analyzer skip).

§Protocol (one JSON object on stdin, one on stdout)

  • Probe (at construction): {"loop_analyzer":1,"op":"probe"} → {"id":"acme.pii/1","title":"PII scan","description":"…"} — every field optional; a missing/garbled probe just falls back to an id derived from the command name.
  • Analyze (per run): {"loop_analyzer":1,"op":"analyze","now_ms":…, "watermark_ms":…,"grains":[<grain>…]} → {"findings":[{"target": "entity:ns/subject","summary":"…","severity":"low","evidence":["<hash>"], "confidence":0.8}]}. Each <grain> is a {hash,grain_type,namespace, created_at_ms,fields} record; a finding must name a target and a summary (others are dropped).

Structs§

CommandAnalyzer
An Analyzer backed by an external command (--analyzer-cmd).