Illustration · planned interface
This screen is a mockup of a graphical interface that does not
exist yet. The shipped product is a command-line tool: one static binary that runs locally, with no account
and no server. The project and its findings below are a worked example, not a real scan.
1
Blockers
Fails the build at --fail-on BLOCK
2
Conditions
Shippable once acknowledged
1
Undetermined
Never counted as a pass
47
Dependencies
3 weight files · 2 upstream CLIs
Findings
sorted by severity, then id — never map order
Block
firecrawl@1.2.3
node_modules/firecrawl/LICENSE:1–9
High
AGPL-3.0-only
npm:firecrawl@1.2.3 Condition hey-gem (weights) models/hey-gem/LICENSE.md§3.2 Medium Community v2
weights · 1.4 GB Condition kokoro-82m models/kokoro/config.json:4 High Apache-2.0
weights · 326 MB Note p-limit@5.0.0 node_modules/p-limit/license:1–21 High MIT
npm:p-limit@5.0.0 Undetermined models/embed.bin models/embed.bin2.1 GB · SafeTensors Low not found
weights
npm:firecrawl@1.2.3 Condition hey-gem (weights) models/hey-gem/LICENSE.md§3.2 Medium Community v2
weights · 1.4 GB Condition kokoro-82m models/kokoro/config.json:4 High Apache-2.0
weights · 326 MB Note p-limit@5.0.0 node_modules/p-limit/license:1–21 High MIT
npm:p-limit@5.0.0 Undetermined models/embed.bin models/embed.bin2.1 GB · SafeTensors Low not found
weights
The undetermined entry is not a pass. models/embed.bin
is 2.1 GB of SafeTensors with no resolvable licence. Locate its terms or remove the file — until then the
verdict can never be SHIP, regardless of everything else.
Machine output
{ "schema_version": 1, "verdict": "DO_NOT_SHIP", "project": "my-saas", "summary": { "dependencies": 47, "weight_files": 3, "upstream_clis": 2, "blockers": 1, "conditions": 2, "undetermined": 1 }, "blockers": [ { "id": "f_8a3c1e", "dependency_id": "npm:firecrawl@1.2.3", "kind": "agpl-3.0.network-disclosure", "severity": "BLOCK", "confidence": "HIGH", "citation": { "url": "https://www.gnu.org/licenses/agpl-3.0.txt", "section": "§13" }, "evidence": [{ "path": "node_modules/firecrawl/LICENSE", "line_start": 1, "line_end": 9 }], "predicate": { "op": "and", "l": { "field": "use.modified", "op": "==", "value": true }, "r": { "field": "use.network_exposed", "op": "==", "value": true } } } ], "meta": { "tool_version": "0.1.0-rc.2", "corpus_version": "2026.09.2", "corpus_signed": true, "duration_ms": 412 } }
Two runs on identical (project, intent, corpus) produce byte-identical JSON once meta.scanned_at and meta.duration_ms are zeroed. Enforced by TestVerdictDeterminism.
Declared intentEdit
- commercial
- true
- licence_model
- closed-source
- modified
- true ← the §13 trigger
- network_exposed
- true ← with modified
- distributed
- false
- saas
- true
- territories
- EU, US, GB
- scale.mau
- 5,000
Every one of these six fields is required. An omitted field evaluates to UNKNOWN — never to a default. The tool does not guess your intent.
Provenance
Corpus2026.09.2 · 2026-09-20
SignatureEd25519 ✓
Toolv0.1.0-rc.2 · a1b2c3d
Intent hashsha256:9f2b…
Network calls0
Coverage
Classified46 / 47
High confidence44
Medium confidence2
Undetermined1
Coverage is reported, never implied. A scan that classified 46 of 47 files says so — it does not round up to "complete".
Ignored paths
vendor/legacy-internal-only/**
Reason: internal tooling, never distributed. An ignore without a reason is refused with E-CFG-005, and an ignore covering more than half the tree raises E-SCAN-020.
Informational findings based on the licence text as published on the date recorded in the corpus.
This is not legal advice. Ambiguous clauses are flagged as ambiguous and carry a confidence
level. Important decisions must be reviewed by a qualified professional.