STRΛTΛ19

Limits

Detailed docs that hide the edges are worse than no docs. This page states the boundaries plainly, not as a footnote.

TypeScript and JavaScript only

The free-local detectors and the deep code index cover .ts, .tsx, .js, .jsx, .mjs, and .cjs — nothing else. The indexer parses these via web-tree-sitter with three shipped grammars (JavaScript, TypeScript, TSX); no other language grammar ships. Point Strata19 at a Python, Go, Rust, or polyglot repository and a scanning tool returns an honest UNSUPPORTED verdict rather than a fabricated pass — never a confident answer about a language it cannot actually parse.

Four checks, and exactly what each one does and does not prove

strata19.verify_implementation runs four deterministic detectors, all local, none of them a model call:

DetectorWhat it checksIts own stated limit
GC-01 — unreachable-file candidateWhole-file graph reachability from the persisted symbol graphReports candidates, not deletion authority. Incomplete index or entrypoint evidence makes a candidate indeterminate, not confirmed.
GC-02 — duplicatesRegex-based; hashes function-shaped bodiesDetects textual/structural duplication, not full semantic equivalence — two functions that do the same thing differently will not match.
GC-08 — placeholdersFour regex sub-checksThe most precise of the four, tuned against a real corpus; a fifth sub-check (bare console.log/debug/info) was retired after measuring 0-of-40 correct outside that corpus — a reminder that even a "precise" pattern-based detector can be wrong outside the data it was tuned on.
GC-13 — missing/placeholder configLocal-only; looks for missing or placeholder configuration valuesDoes not detect stale configuration — a value that's present but wrong.

A fifth detector, GC-14 (dependency audit), exists in the codebase but is not one of the four behind the free-local verification gate, because it reaches the network (npm audit) — see Local Data and Privacy for why that distinction matters.

None of the four is a general security or correctness claim. A clean verify_implementation result means these four specific, narrow checks found nothing in their scope — it does not mean the code is correct, secure, or complete in any broader sense.

Nothing here is trained on your code

Nothing in Free Local trains across repositories, and no model weight changes based on what it sees. Every deterministic check runs fresh, per repository, from that repository's own current state — there is no shared model or shared index that accumulates knowledge from one project and applies it to another. A "spec_generate" run over your repository produces markdown proposals scoped to your repository; it does not become part of any dataset, shared or otherwise.

Specbook sections are proposals, not verified truth

Every Specbook section — whether from a first spec_generate run or a later spec_sync — is labelled origin: generated. That label means exactly what it says: a proposal about what the code appears to intend, derived from the code itself, not an independently verified or human-accepted fact. Treat it as a draft to review, the same way you'd review a teammate's first pass, not as documentation you can cite without reading.

Host control is architecturally out of this version

Strata19 cannot steer, interrupt, fork, or drive a session in your coding host from outside your own conversation with it. This is a resolved decision for this version (not a partially-built feature or a bug): the bridge that would do this only exists inside the separate web application, never inside the bundled plugin an installed user actually runs, and the plugin's internal host-control entry points return an honest, typed decline rather than a fabricated success or an unverified probe result.

Model-assisted text is a draft, not a checked answer

Anything produced with BYOK model assistance — a work-item enrichment, a remediation explanation, a recommendation, an interpreted query — is a language-model draft. It is generated from the same evidence the deterministic tools already surfaced, but the drafting step itself is not independently checked. Read it the way you would read a colleague's first-pass explanation: useful, and still yours to verify.

What this page deliberately does not cover

Extension authoring — a manifest format, a contribution model, and a worked example — is being built as of this writing and does not exist yet. Writing about it here would describe something a reader cannot go verify against running code, which is the one thing this page is trying not to do. It will get its own page once there is a shipped format to document.