JC·HARNESS

Docs & API

Public-safe documentation and machine-readable surfaces.

Surface Update Rules

OpenAPI and MCP are generated from the current route and registry code. Run, finding, report, artifact, settings, and integration pages are live surfaces backed by Neon, local run storage, server env presence, or browser session state. The `/docs/*`, `/matrix`, `/models`, and `/scorecard` pages are source-backed documentation and update on deployment.

Responsible-Use Baseline

  • Authorized testing only.
  • Only test systems you own or have explicit written permission to assess.
  • The operator is responsible for target authorization and scope.
  • No anonymous active testing against arbitrary targets.
  • No denial-of-service testing unless explicitly scoped and separately enabled.
  • No destructive testing.

Getting Started

source backed

Jean-Claude setup flow, execution modes, and first dry-run path.

Source-backed static docs; updates on deploy.

Open surface

Responsible Use

source backed

Authorization and safety requirements before any real run.

Source-backed static docs; updates on deploy.

Open surface

Safety

source backed

No remediation, no PRs, no branch pushes, no anonymous active scanning.

Source-backed static docs; updates on deploy.

Open surface

Modes

source backed

api-multi-model, local-client, local-model, and multi-mode behavior.

Source-backed static docs; updates on deploy.

Open surface

Pipeline

source backed

RECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD.

Source-backed static docs; updates on deploy.

Open surface

Integrations

source backed

Vercel, Sandbox, AI Gateway, Neon, Trace, Docs, Sheets, Files.

Source-backed static docs; updates on deploy.

Open surface

Jean-Claude boot and setup wizard

live surface

Setup wizard and run planner for scoped dry runs and protected real runs.

Live UI; submitted plans persist to Neon when configured.

Open surface

Dry-run and real-run selection with dry-run default

live surface

Dry-run default, real-run gate, budget controls, and authorization confirmation.

Live UI; run state is persisted when a run is created.

Open surface

Execution modes: api-multi-model, local-client, local-model, multi-mode

source backed

Documented execution modes from the original harness configuration.

Source-backed static docs; updates on deploy.

Open surface

Model roster: fable5, opus48, gpt55

source backed

Configured model roster, provider selection, and role mapping.

Source-backed model registry; updates on deploy.

Open surface

Key resolution status for env, AWS SSM, key file, and Vercel AI Gateway

live surface

Presence-only key status for server envs and browser-session runtime keys.

Live server/runtime credential status; raw values are never rendered.

Open surface

Target base URL, repositories, trust boundaries, and allowed-host validation

live surface

Target base URL, repositories, trusted hosts, and responsible-use scope controls.

Live UI validation; submitted run scope is persisted with the run.

Open surface

RECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD pipeline timeline

live data

Pipeline timeline and run history with persisted stage, log, finding, and scorecard evidence.

Live data-backed surface from Neon and local run storage.

Open surface

44 attack-class taxonomy across the harness frameworks

source backed

Canonical Jean-Claude attack-class matrix and framework mapping.

Source-backed taxonomy; updates on deploy.

Open surface

Finding normalization and schema validation through finding-normalizer.js

live data

Finding explorer with run linkage, target context, validation, and remediation evidence.

Live data-backed surface from persisted finding records.

Open surface

Priority scoring through scoring.js with comparative-scorecard gap disclosure

source backed

Priority scoring method and scorecard boundary for evidence-backed findings.

Source-backed scoring documentation; persisted scorecards are shown on run and report pages.

Open surface

Responsible-use audit and protected operator actions

source backed

Responsible-use audit policy and protected operator action boundary.

Source-backed static docs; updates on deploy.

Open surface

Runtime browser-session credential entry for protected setup and handoff actions when server envs are absent

live surface

Browser-session runtime credential entry used only when server envs are absent.

Live browser-session state; secrets stay in sessionStorage.

Open surface

PlatPhorm Sandbox handoff preview and protected receive-handoff delivery

live surface

Sandbox handoff preview and protected receive-handoff delivery controls.

Live integration status; protected delivery only claims confirmed downstream receipt.

Open surface

PlatPhorm BrowserOps handoff preview and protected receive-handoff delivery

live surface

BrowserOps handoff preview and protected receive-handoff delivery controls.

Live integration status; protected delivery only claims confirmed downstream receipt.

Open surface

MCP, OpenAPI, llms, sitemap, RSS, robots, and well-known discovery

generated

Discovery routes, API docs, MCP metadata, sitemap, RSS, robots, and well-known policy files.

Mixed generated/source-backed discovery surfaces; route smoke verifies public availability.

Open surface