Expand description
External command analyzers — the --analyzer-cmd seam (SDK §11).
A subprocess that receives a live-grain snapshot on stdin and returns
advisory findings on stdout. It runs at trust class Command with
auto-apply Never: a domain-specific subprocess can surface an issue a
human then reviews, but can never mutate memory. Any failure — cannot spawn,
non-zero exit, garbled output — skips the analyzer for the run; it never
crashes the pass or the sibling analyzers (the engine already treats an
analyze error as a per-analyzer skip).
§Protocol (one JSON object on stdin, one on stdout)
- Probe (at construction):
{"loop_analyzer":1,"op":"probe"}→{"id":"acme.pii/1","title":"PII scan","description":"…"}— every field optional; a missing/garbled probe just falls back to an id derived from the command name. - Analyze (per run):
{"loop_analyzer":1,"op":"analyze","now_ms":…, "watermark_ms":…,"grains":[<grain>…]}→{"findings":[{"target": "entity:ns/subject","summary":"…","severity":"low","evidence":["<hash>"], "confidence":0.8}]}. Each<grain>is a{hash,grain_type,namespace, created_at_ms,fields}record; a finding must name atargetand asummary(others are dropped).
Structs§
- Command
Analyzer - An
Analyzerbacked by an external command (--analyzer-cmd).