Limits
Detailed docs that hide the edges are worse than no docs. This page states the boundaries plainly, not as a footnote.
TypeScript and JavaScript only
The free-local detectors and the deep code index cover .ts, .tsx, .js,
.jsx, .mjs, and .cjs — nothing else. The indexer parses these via
web-tree-sitter with three shipped grammars (JavaScript, TypeScript, TSX);
no other language grammar ships. Point Strata19 at a Python, Go, Rust, or
polyglot repository and a scanning tool returns an honest UNSUPPORTED
verdict rather than a fabricated pass — never a confident answer about a
language it cannot actually parse.
Four checks, and exactly what each one does and does not prove
strata19.verify_implementation runs four deterministic detectors, all
local, none of them a model call:
| Detector | What it checks | Its own stated limit |
|---|---|---|
| GC-01 — unreachable-file candidate | Whole-file graph reachability from the persisted symbol graph | Reports candidates, not deletion authority. Incomplete index or entrypoint evidence makes a candidate indeterminate, not confirmed. |
| GC-02 — duplicates | Regex-based; hashes function-shaped bodies | Detects textual/structural duplication, not full semantic equivalence — two functions that do the same thing differently will not match. |
| GC-08 — placeholders | Four regex sub-checks | The most precise of the four, tuned against a real corpus; a fifth sub-check (bare console.log/debug/info) was retired after measuring 0-of-40 correct outside that corpus — a reminder that even a "precise" pattern-based detector can be wrong outside the data it was tuned on. |
| GC-13 — missing/placeholder config | Local-only; looks for missing or placeholder configuration values | Does not detect stale configuration — a value that's present but wrong. |
A fifth detector, GC-14 (dependency audit), exists in the codebase but is
not one of the four behind the free-local verification gate, because it
reaches the network (npm audit) — see
Local Data and Privacy for why that distinction
matters.
None of the four is a general security or correctness claim. A clean
verify_implementation result means these four specific, narrow checks
found nothing in their scope — it does not mean the code is correct, secure,
or complete in any broader sense.
Nothing here is trained on your code
Nothing in Free Local trains across repositories, and no model weight changes based on what it sees. Every deterministic check runs fresh, per repository, from that repository's own current state — there is no shared model or shared index that accumulates knowledge from one project and applies it to another. A "spec_generate" run over your repository produces markdown proposals scoped to your repository; it does not become part of any dataset, shared or otherwise.
Specbook sections are proposals, not verified truth
Every Specbook section — whether from a first spec_generate run or a later
spec_sync — is labelled origin: generated. That label means exactly what
it says: a proposal about what the code appears to intend, derived from the
code itself, not an independently verified or human-accepted fact. Treat it
as a draft to review, the same way you'd review a teammate's first pass, not
as documentation you can cite without reading.
Host control is architecturally out of this version
Strata19 cannot steer, interrupt, fork, or drive a session in your coding host from outside your own conversation with it. This is a resolved decision for this version (not a partially-built feature or a bug): the bridge that would do this only exists inside the separate web application, never inside the bundled plugin an installed user actually runs, and the plugin's internal host-control entry points return an honest, typed decline rather than a fabricated success or an unverified probe result.
Model-assisted text is a draft, not a checked answer
Anything produced with BYOK model assistance — a work-item enrichment, a remediation explanation, a recommendation, an interpreted query — is a language-model draft. It is generated from the same evidence the deterministic tools already surfaced, but the drafting step itself is not independently checked. Read it the way you would read a colleague's first-pass explanation: useful, and still yours to verify.
What this page deliberately does not cover
Extension authoring — a manifest format, a contribution model, and a worked example — is being built as of this writing and does not exist yet. Writing about it here would describe something a reader cannot go verify against running code, which is the one thing this page is trying not to do. It will get its own page once there is a shipped format to document.