Docs & API
Public-safe documentation and machine-readable surfaces.
OpenAPI
generatedRoute contract, auth boundary, and run APIs.
Generated from the current route contract at request time.
MCP
generatedJSON-RPC metadata and tool registry.
Generated from the current MCP registry at request time.
llms.txt
generatedConcise AI-reader summary of the product boundary.
Generated from the source-backed platform registry.
Surface Update Rules
Responsible-Use Baseline
- Authorized testing only.
- Only test systems you own or have explicit written permission to assess.
- The operator is responsible for target authorization and scope.
- No anonymous active testing against arbitrary targets.
- No denial-of-service testing unless explicitly scoped and separately enabled.
- No destructive testing.
Getting Started
source backedJean-Claude setup flow, execution modes, and first dry-run path.
Source-backed static docs; updates on deploy.
Open surfaceResponsible Use
source backedAuthorization and safety requirements before any real run.
Source-backed static docs; updates on deploy.
Open surfaceSafety
source backedNo remediation, no PRs, no branch pushes, no anonymous active scanning.
Source-backed static docs; updates on deploy.
Open surfaceModes
source backedapi-multi-model, local-client, local-model, and multi-mode behavior.
Source-backed static docs; updates on deploy.
Open surfacePipeline
source backedRECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD.
Source-backed static docs; updates on deploy.
Open surfaceIntegrations
source backedVercel, Sandbox, AI Gateway, Neon, Trace, Docs, Sheets, Files.
Source-backed static docs; updates on deploy.
Open surfaceJean-Claude boot and setup wizard
live surfaceSetup wizard and run planner for scoped dry runs and protected real runs.
Live UI; submitted plans persist to Neon when configured.
Open surfaceDry-run and real-run selection with dry-run default
live surfaceDry-run default, real-run gate, budget controls, and authorization confirmation.
Live UI; run state is persisted when a run is created.
Open surfaceExecution modes: api-multi-model, local-client, local-model, multi-mode
source backedDocumented execution modes from the original harness configuration.
Source-backed static docs; updates on deploy.
Open surfaceModel roster: fable5, opus48, gpt55
source backedConfigured model roster, provider selection, and role mapping.
Source-backed model registry; updates on deploy.
Open surfaceKey resolution status for env, AWS SSM, key file, and Vercel AI Gateway
live surfacePresence-only key status for server envs and browser-session runtime keys.
Live server/runtime credential status; raw values are never rendered.
Open surfaceTarget base URL, repositories, trust boundaries, and allowed-host validation
live surfaceTarget base URL, repositories, trusted hosts, and responsible-use scope controls.
Live UI validation; submitted run scope is persisted with the run.
Open surfaceRECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD pipeline timeline
live dataPipeline timeline and run history with persisted stage, log, finding, and scorecard evidence.
Live data-backed surface from Neon and local run storage.
Open surface44 attack-class taxonomy across the harness frameworks
source backedCanonical Jean-Claude attack-class matrix and framework mapping.
Source-backed taxonomy; updates on deploy.
Open surfaceFinding normalization and schema validation through finding-normalizer.js
live dataFinding explorer with run linkage, target context, validation, and remediation evidence.
Live data-backed surface from persisted finding records.
Open surfacePriority scoring through scoring.js with comparative-scorecard gap disclosure
source backedPriority scoring method and scorecard boundary for evidence-backed findings.
Source-backed scoring documentation; persisted scorecards are shown on run and report pages.
Open surfaceResponsible-use audit and protected operator actions
source backedResponsible-use audit policy and protected operator action boundary.
Source-backed static docs; updates on deploy.
Open surfaceRuntime browser-session credential entry for protected setup and handoff actions when server envs are absent
live surfaceBrowser-session runtime credential entry used only when server envs are absent.
Live browser-session state; secrets stay in sessionStorage.
Open surfacePlatPhorm Sandbox handoff preview and protected receive-handoff delivery
live surfaceSandbox handoff preview and protected receive-handoff delivery controls.
Live integration status; protected delivery only claims confirmed downstream receipt.
Open surfacePlatPhorm BrowserOps handoff preview and protected receive-handoff delivery
live surfaceBrowserOps handoff preview and protected receive-handoff delivery controls.
Live integration status; protected delivery only claims confirmed downstream receipt.
Open surfaceMCP, OpenAPI, llms, sitemap, RSS, robots, and well-known discovery
generatedDiscovery routes, API docs, MCP metadata, sitemap, RSS, robots, and well-known policy files.
Mixed generated/source-backed discovery surfaces; route smoke verifies public availability.
Open surface