{"_id":"@alizain/doublecheck","_rev":"8-251eec172359cb7d87a8f21c74ea4bdd","name":"@alizain/doublecheck","dist-tags":{"latest":"2.4.2"},"versions":{"1.0.0":{"name":"@alizain/doublecheck","version":"1.0.0","keywords":["claude","code-review","llm","agent","microvm","sandbox","checks"],"license":"MIT","_id":"@alizain/doublecheck@1.0.0","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"bin":{"doublecheck":"dist/cli.mjs"},"dist":{"shasum":"098358f8930022ba6422181120845a402ce81e76","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-1.0.0.tgz","fileCount":7,"integrity":"sha512-M87G2A5sFwGvythdUn6FKfyQq2bjiIItxdtSIXN8MWHST7bLoURdOvIqt7e1alNIz7qUBQHgt+5oTSPfgVgQ0w==","signatures":[{"sig":"MEUCIGXF0X70ali1HBfZhMZXq+krASzXNo53+5LQsfYxn2aLAiEArEXRK9eIm/jLMNT9C1cYntI1xxcQ6RT6V8Ycww0zzEE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":75219},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"06b49ef5268bc4602eabdcddb1999a81d4343af0","scripts":{"test":"vitest run","build":"tsdown","check":"biome check .","format":"biome format --write .","release":"semantic-release","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","typecheck":"tsc --noEmit","test:watch":"vitest","doublecheck":"tsx src/cli.ts"},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"repository":{"url":"git+https://github.com/alizain/doublecheck.git","type":"git"},"_npmVersion":"11.16.0","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","directories":{},"_nodeVersion":"24.18.0","dependencies":{"p-queue":"^9.0.0","commander":"^14.0.3","microsandbox":"^0.6.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"tsx":"^4.22.4","tsdown":"^0.22.3","vitest":"^2.1.0","typescript":"^5.6.0","@types/node":"^24.0.0","@biomejs/biome":"^2.0.0","semantic-release":"^25.0.5"},"_npmOperationalInternal":{"tmp":"tmp/doublecheck_1.0.0_1783289640024_0.394389905522478","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@alizain/doublecheck","version":"2.0.0","keywords":["claude","code-review","llm","agent","microvm","sandbox","checks"],"license":"MIT","_id":"@alizain/doublecheck@2.0.0","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"bin":{"doublecheck":"dist/cli.mjs"},"dist":{"shasum":"ea25514434e3bc94e42f4c4b39cd335980ecb02c","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-2.0.0.tgz","fileCount":7,"integrity":"sha512-1GngFpsOsbIEklLoDwF3T+ZcvcouGAFGuIiSJISg8vDgMVVah3hDbFAgwXPPpPiWFhXXaoqQgZFO7S1vPpaJpg==","signatures":[{"sig":"MEYCIQCaf9eShVNC6kKdLHVmojE+kFFFGDWjZBESwe2GE2yyGAIhANp3r6gPKmsd8eJ+qozBT6Th9pXzqSIFa8lOCgJewENQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":92082},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"0bd73040ee2eec632526528c79218b7bb653be1c","scripts":{"test":"vitest run","build":"tsdown","check":"biome check .","format":"biome format --write .","release":"semantic-release","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","typecheck":"tsc --noEmit","test:watch":"vitest","doublecheck":"tsx src/cli.ts"},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"repository":{"url":"git+https://github.com/alizain/doublecheck.git","type":"git"},"_npmVersion":"11.16.0","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","directories":{},"_nodeVersion":"24.18.0","dependencies":{"p-queue":"^9.0.0","commander":"^14.0.3","microsandbox":"^0.6.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"tsx":"^4.22.4","tsdown":"^0.22.3","vitest":"^2.1.0","typescript":"^5.6.0","@types/node":"^24.0.0","@biomejs/biome":"^2.0.0","semantic-release":"^25.0.5"},"_npmOperationalInternal":{"tmp":"tmp/doublecheck_2.0.0_1783304994668_0.857480105202818","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"name":"@alizain/doublecheck","version":"2.1.0","keywords":["claude","codex","openai","code-review","llm","agent","microvm","sandbox","checks"],"license":"MIT","_id":"@alizain/doublecheck@2.1.0","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"bin":{"doublecheck":"dist/cli.mjs"},"dist":{"shasum":"bc4e2f06ac1aac16c804d4d1619c8e0c293dd0df","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-2.1.0.tgz","fileCount":7,"integrity":"sha512-9YD9uTe20UZR1YCHmzyonVRDHVTYFOmuHa6rHGu7tjADmB2rivr9vxbeQpm4u3XrFMCH7MammhGPCAE4xYCPCQ==","signatures":[{"sig":"MEYCIQDhhWoQdyeT8LTiI6EZnVTATQu10BaBbDcoRVNO5kS4/gIhAOTN3WeLibvaGrmMD+pu0yVOUge/PPVV0AL637UIBLkd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113802},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"eb28501cff3dfc7e1be81315be90637ace066090","scripts":{"test":"vitest run","build":"tsdown","check":"biome check .","format":"biome format --write .","release":"semantic-release","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","typecheck":"tsc --noEmit","test:watch":"vitest","doublecheck":"tsx src/cli.ts"},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"repository":{"url":"git+https://github.com/alizain/doublecheck.git","type":"git"},"_npmVersion":"11.16.0","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","directories":{},"_nodeVersion":"24.18.0","dependencies":{"p-queue":"^9.0.0","commander":"^14.0.3","microsandbox":"^0.6.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"tsx":"^4.22.4","tsdown":"^0.22.3","vitest":"^2.1.0","typescript":"^5.6.0","@types/node":"^24.0.0","@biomejs/biome":"^2.0.0","semantic-release":"^25.0.5"},"_npmOperationalInternal":{"tmp":"tmp/doublecheck_2.1.0_1783338980382_0.6243041836370264","host":"s3://npm-registry-packages-npm-production"}},"2.2.0":{"name":"@alizain/doublecheck","version":"2.2.0","keywords":["claude","codex","openai","code-review","llm","agent","microvm","sandbox","checks"],"license":"MIT","_id":"@alizain/doublecheck@2.2.0","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"bin":{"doublecheck":"dist/cli.mjs"},"dist":{"shasum":"9bbf133adffc9efbe2765dedacab5b9ba377e8c8","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-2.2.0.tgz","fileCount":7,"integrity":"sha512-ne10LL6anmOa1G9jMQW1sow8r4Vyqnz2WcS2y7qgJ8CUM1Giwyp9fHJS6rNU9rQSluXgIcDUnjziQIZyeX9GlQ==","signatures":[{"sig":"MEUCIQD6YAGLqbtGFBrQM3awVTN8ZO/UXIGRlRdFYhwr9SoXbgIgZ2OqFXd2D2AJsFRINlWDC5m0tGdb9/uXmYwJgpJH0ww=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":118452},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"1ad77b4d4bc40c4201abd93a24a2a5482975801d","scripts":{"test":"vitest run","build":"tsdown","check":"biome check .","format":"biome format --write .","release":"semantic-release","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","typecheck":"tsc --noEmit","test:watch":"vitest","doublecheck":"tsx src/cli.ts"},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"repository":{"url":"git+https://github.com/alizain/doublecheck.git","type":"git"},"_npmVersion":"11.16.0","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","directories":{},"_nodeVersion":"24.18.0","dependencies":{"p-queue":"^9.0.0","commander":"^14.0.3","microsandbox":"^0.6.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"tsx":"^4.22.4","tsdown":"^0.22.3","vitest":"^2.1.0","typescript":"^5.6.0","@types/node":"^24.0.0","@biomejs/biome":"^2.0.0","semantic-release":"^25.0.5"},"_npmOperationalInternal":{"tmp":"tmp/doublecheck_2.2.0_1783339979643_0.6003090770824031","host":"s3://npm-registry-packages-npm-production"}},"2.3.0":{"name":"@alizain/doublecheck","version":"2.3.0","keywords":["claude","codex","openai","code-review","llm","agent","microvm","sandbox","checks"],"license":"MIT","_id":"@alizain/doublecheck@2.3.0","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"bin":{"doublecheck":"dist/cli.mjs"},"dist":{"shasum":"2023b37aefc1c4f754145adf3c8ae8a34491a7fa","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-2.3.0.tgz","fileCount":7,"integrity":"sha512-3pY0rmdpv4hvm7tD3Ihq3c7r2yIvgeGwNf+Eazxn963elRqQlivlF9rK1Fsu376NXyB95uPCKXYbF7vSZo00NQ==","signatures":[{"sig":"MEUCIBGVEWPCp4XbsaCRfxMqNK5cfsQ4KfAUGVzFZ9HMCqNWAiEA0924Rx+c5FyVj9hsicr98oneIqYufO8N+hexlhKJ5tQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":121516},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"3a8a7cfb244b95a58616b4a15ce0b500259698d6","scripts":{"test":"vitest run","build":"tsdown","check":"biome check .","format":"biome format --write .","release":"semantic-release","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","typecheck":"tsc --noEmit","test:watch":"vitest","doublecheck":"tsx src/cli.ts"},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"repository":{"url":"git+https://github.com/alizain/doublecheck.git","type":"git"},"_npmVersion":"11.16.0","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","directories":{},"_nodeVersion":"24.18.0","dependencies":{"p-queue":"^9.0.0","commander":"^14.0.3","microsandbox":"^0.6.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"tsx":"^4.22.4","tsdown":"^0.22.3","vitest":"^2.1.0","typescript":"^5.6.0","@types/node":"^24.0.0","@biomejs/biome":"^2.0.0","semantic-release":"^25.0.5"},"_npmOperationalInternal":{"tmp":"tmp/doublecheck_2.3.0_1783340923901_0.9069473506868773","host":"s3://npm-registry-packages-npm-production"}},"2.4.0":{"name":"@alizain/doublecheck","version":"2.4.0","keywords":["claude","codex","openai","code-review","llm","agent","microvm","sandbox","checks"],"license":"MIT","_id":"@alizain/doublecheck@2.4.0","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"bin":{"doublecheck":"dist/cli.mjs"},"dist":{"shasum":"7c8e6471b18293f256ccf7cfb3012c48f5cf2c37","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-2.4.0.tgz","fileCount":7,"integrity":"sha512-AsfQNGVJKV0cFNEijywfzjcSg4EmTvSXbPKU+Vw9ICYBjatxFx3W7Z46SyYXLWKTAdzoezyo/ZaMxDerHrkDkA==","signatures":[{"sig":"MEUCIEtmfQZWBD1S7YsENO+ivfvbjt17cQvrQWMmUsCM38CYAiEAqOUfmp6/PQ4yJDxPZjtJ2mI2XX4hEfzSdrzm4K4fYDw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":121564},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"053a44039881b0c8636d5d8a7a144d87881bfe9d","scripts":{"test":"vitest run","build":"tsdown","check":"biome check .","format":"biome format --write .","release":"semantic-release","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","typecheck":"tsc --noEmit","test:watch":"vitest","doublecheck":"tsx src/cli.ts"},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"repository":{"url":"git+https://github.com/alizain/doublecheck.git","type":"git"},"_npmVersion":"11.16.0","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","directories":{},"_nodeVersion":"24.18.0","dependencies":{"p-queue":"^9.0.0","commander":"^14.0.3","microsandbox":"^0.6.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"tsx":"^4.22.4","tsdown":"^0.22.3","vitest":"^2.1.0","typescript":"^5.6.0","@types/node":"^24.0.0","@biomejs/biome":"^2.0.0","semantic-release":"^25.0.5"},"_npmOperationalInternal":{"tmp":"tmp/doublecheck_2.4.0_1783684865859_0.6608833957597482","host":"s3://npm-registry-packages-npm-production"}},"2.4.1":{"name":"@alizain/doublecheck","version":"2.4.1","keywords":["claude","codex","openai","code-review","llm","agent","microvm","sandbox","checks"],"license":"MIT","_id":"@alizain/doublecheck@2.4.1","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"bin":{"doublecheck":"dist/cli.mjs"},"dist":{"shasum":"c9828b60737ab83959f91d303f3b03a528d92b66","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-2.4.1.tgz","fileCount":7,"integrity":"sha512-P8pdTq9poJlvgjmcsXNPB6IY9ScYKTNLKIfdPJbLJ0fc+E/duf63Q0nYWHS+DHOlLDJSeybVp4vAfltDgsr6lg==","signatures":[{"sig":"MEQCIDKlKo02QVeDFb3PhmyPPyzZKP8iAio6To+yl/jOEnmIAiAs/phWs32IcgV4u98OVfDFdJDrANNX/HW2E6uv6g7WFg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":120055},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"5ececb2b5b312ff6608c63dd915c2ab134894d36","scripts":{"test":"vitest run","build":"tsdown","check":"biome check .","format":"biome format --write .","release":"semantic-release","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","typecheck":"tsc --noEmit","test:watch":"vitest","doublecheck":"tsx src/cli.ts"},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"repository":{"url":"git+https://github.com/alizain/doublecheck.git","type":"git"},"_npmVersion":"11.16.0","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","directories":{},"_nodeVersion":"24.18.0","dependencies":{"p-queue":"^9.0.0","commander":"^14.0.3","microsandbox":"^0.6.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"tsx":"^4.22.4","tsdown":"^0.22.3","vitest":"^2.1.0","typescript":"^5.6.0","@types/node":"^24.0.0","@biomejs/biome":"^2.0.0","semantic-release":"^25.0.5"},"_npmOperationalInternal":{"tmp":"tmp/doublecheck_2.4.1_1783912659955_0.9105448948597892","host":"s3://npm-registry-packages-npm-production"}},"2.4.2":{"name":"@alizain/doublecheck","version":"2.4.2","description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","type":"module","packageManager":"pnpm@11.5.1","license":"MIT","repository":{"type":"git","url":"git+https://github.com/alizain/doublecheck.git"},"homepage":"https://github.com/alizain/doublecheck#readme","bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"keywords":["claude","codex","openai","code-review","llm","agent","microvm","sandbox","checks"],"engines":{"node":">=22.0.0"},"publishConfig":{"access":"public"},"bin":{"doublecheck":"dist/cli.mjs"},"scripts":{"doublecheck":"tsx src/cli.ts","build":"tsdown","test":"vitest run","test:unit":"vitest run --exclude \"**/*.integration.test.ts\"","test:watch":"vitest","check":"biome check .","format":"biome format --write .","typecheck":"tsc --noEmit","release":"semantic-release"},"dependencies":{"commander":"^14.0.3","microsandbox":"0.6.6","p-queue":"^9.0.0"},"devDependencies":{"@biomejs/biome":"^2.0.0","@types/node":"^24.0.0","semantic-release":"^25.0.5","tsdown":"^0.22.3","tsx":"^4.22.4","typescript":"^5.6.0","vitest":"^2.1.0"},"gitHead":"79df50635d9aa04558f15f7c8b2ab787051fc0cb","_id":"@alizain/doublecheck@2.4.2","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-VkgmJWBUWglSbT6GPpWvSjbvM1oDOgyjaOFN3mfGNCjM4XqDS02pHSnBGo1+uykx7zp2YjXv9EcRZrYWMa80Sw==","shasum":"06233e833313f2054127b5019bdc13220c46ee12","tarball":"https://registry.npmjs.org/@alizain/doublecheck/-/doublecheck-2.4.2.tgz","fileCount":7,"unpackedSize":120054,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHKM4ApCrY+n71DfrNMNGsERi+m4ptQ8ZfRW0A06ktc3AiEA746OVPw2MrVn+2pj3Ggi/joO3wRK6BRd+oIMIho/pYU="}]},"_npmUser":{"name":"alizain","email":"alizain.feerasta@gmail.com"},"directories":{},"maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/doublecheck_2.4.2_1785192067281_0.40451474423806855"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-05T22:13:59.840Z","modified":"2026-07-27T22:41:07.573Z","1.0.0":"2026-07-05T22:14:00.174Z","2.0.0":"2026-07-06T02:29:54.854Z","2.1.0":"2026-07-06T11:56:20.538Z","2.2.0":"2026-07-06T12:12:59.810Z","2.3.0":"2026-07-06T12:28:44.042Z","2.4.0":"2026-07-10T12:01:05.989Z","2.4.1":"2026-07-13T03:17:40.094Z","2.4.2":"2026-07-27T22:41:07.427Z"},"bugs":{"url":"https://github.com/alizain/doublecheck/issues"},"license":"MIT","homepage":"https://github.com/alizain/doublecheck#readme","keywords":["claude","codex","openai","code-review","llm","agent","microvm","sandbox","checks"],"repository":{"type":"git","url":"git+https://github.com/alizain/doublecheck.git"},"description":"Run self-authored LLM code-inspectors against a project — one sandboxed microVM agent per check, one markdown report each","maintainers":[{"name":"alizain","email":"alizain.feerasta@gmail.com"}],"readme":"# doublecheck\n\nRuns self-authored LLM code-inspectors (\"checks\") against a project — one\nsandboxed agent per check, in parallel — and writes one markdown report per\ncheck.\n\n**A check is a markdown file:** a timeless standard — no frontmatter, no\nschema; the body is the inspector's instructions. Checks come from one or\nmore `--checks-dir` directories (default: `$TARGET/.agents/checks`), so a\nshared check set can serve a whole folder of repos. Everything run-specific —\nthe intent of the work under review, known nuances, sanctioned exceptions,\nscope (\"these changed files vs main\") — arrives per run via `--context`; the\nharness computes no diffs and knows nothing about git. **A report is a\nmarkdown file:** whatever the agent writes, no imposed structure — and the\noperator's agent reads every line of it, which the prompt tells the inspector.\n\n## Why this exists\n\nLinters and type checkers catch what can be pattern-matched. The defects that\nsurvive them are judgment calls: a silent fallback that swallows a config\nerror, an abstraction at the wrong layer, a \"for now\" that will outlive its\nauthor. doublecheck encodes *your* judgment about those — each check is a\nstandard you actually hold, written as prose instructions to an inspector\nagent that can read the whole tree and reason about it.\n\nThe division of labor is deliberate: everything that requires judgment lives\nin the check body (what to flag, what to leave alone, where to look);\neverything mechanical lives in the harness (sandboxing, parallelism, report\ncollection). The harness knows nothing about git, diffs, or languages, so it\nnever needs to change when your standards do.\n\n## The loop\n\n1. **`doublecheck mine`** distills your Claude Code history into durable\n   preference observations (`~/.doublecheck/catalog`) — evidence of standards\n   you have actually enforced in past conversations.\n2. **A human and/or agent authors checks** from those observations. This step\n   is deliberately unproductized: going from \"observed preference\" to\n   \"runnable standard\" is judgment work.\n3. **`doublecheck check`** runs every check against a project, one sandboxed\n   agent per check, and writes one report per check. Read the reports, fix\n   what is real, tighten any check that cried wolf.\n\n## How it works\n\nPer check: a scratch workdir gets `prompt.txt` (environment preamble +\noperator run context, when given + check body + report contract). A [microsandbox](https://github.com/superradcompany/microsandbox)\nmicroVM boots from a locally built image with the project bind-mounted\n**read-only at its real host path** and the scratch dir mounted rw as the\nguest cwd. The selected agent CLI (`--agent`: headless `claude -p`, or\n`codex exec`) runs inside with its full toolkit and no permission gates —\nthe microVM is the safety boundary, the ro mount is the \"don't touch\nmy repo\" guarantee. The agent writes `report.md`; the host copies it to\n`$OUTPUT/<run-timestamp>/<check>.md` (with `--save-jsonl`, alongside\n`<check>.stream.jsonl` — the inspector's raw stream, kept so a run can be\naudited after the guest is gone).\n\nThe project is never copied — every guest shares the live host directory\n(dirty files included) through the ro mount, so per-check cost is one temp dir\nand ~2 GiB of guest memory.\n\nExit 0 only when every check produced a report. An agent failure (exit ≠ 0,\nno report) writes a failure-record report and flips the run's exit code;\nmissing token / checks / image abort loudly up front.\n\n## Setup\n\n```bash\nnpm install -g @alizain/doublecheck   # installs the `doublecheck` command; or, from a clone: pnpm install\n```\n\nGuests boot from an image with both agent CLIs baked in, and no install\nneeds an image step. An installed release resolves\n`ghcr.io/alizain/doublecheck-guest:<its own version>`; a clone resolves the\nnearest release tag reachable from its checkout (`git describe`), so `git\npull` bringing a new tag is also the image update. Either way the runner\npulls the image on first use (~1 GB, once per version — the release workflow\npublishes it for amd64+arm64 alongside the npm package).\n\nThe locally built image is only for iterating on `Dockerfile.guest` itself\n(needs a running Docker daemon), opted into explicitly:\n\n```bash\n./scripts/build-guest-image.sh\nDOUBLECHECK_GUEST_IMAGE=doublecheck-guest:latest pnpm doublecheck check …\n```\n\n`DOUBLECHECK_GUEST_IMAGE=<ref>` works for any install — the named ref must\nalready be in the microsandbox cache (it is never pulled); useful offline or\nfor custom guest images. A clone with no reachable release tag (e.g. a\nshallow clone) falls back to the locally built image.\n\n## Usage\n\n```bash\nCLAUDE_CODE_OAUTH_TOKEN=... doublecheck check \\\n  --target DIR       # tree under inspection, mounted read-only; default: cwd\n  --checks-dir DIR   # repeatable; default: $TARGET/.agents/checks\n  --context FILE     # run brief: intent, nuances, sanctioned exceptions, scope\n  --agent NAME       # claude (default) or codex\n  --model MODEL      # default per agent: claude haiku, codex gpt-5.6-sol\n  --parallel N       # default: 4 concurrent guests\n  --output DIR       # default: $TARGET/.doublecheck\n  --check NAME       # repeatable; default: every check in the checks dirs\n  --save-jsonl       # persist each inspector's raw stream beside its report\n```\n\nCredentials per agent, gathered on the host before any guest boots:\n\n- **claude**: `CLAUDE_CODE_OAUTH_TOKEN` is required in the environment and\n  injected into each guest; where it comes from is the operator's business.\n- **codex**: no env var — each guest gets a fresh copy of the host's\n  `~/.codex/auth.json` (run `codex login` once). No staleness guard\n  (removed 2026-07-13): accepted risk that a guest-side refresh of\n  near-expiry ChatGPT tokens rotates the single-use token family out from\n  under the host (codex self-refreshes at ~8 days; a mid-run 401 could do\n  the same regardless). Recovery is `codex login` on the host. Guests\n  never write auth state back.\n\n### Mining your Claude history into an observation catalog\n\n`doublecheck mine` walks every Claude Code transcript on the machine and runs\none sandboxed agent per real conversation (≥ `--min-turns` genuine human\nturns) to extract durable engineering preferences into\n`~/.doublecheck/catalog`, mirroring the transcript tree — one\n`<project>/<session>/observations.md` per conversation, frontmatter recording\nthe source hash so re-runs only mine new or grown sessions. Mining guests get\negress to the selected agent's own API domains only (`claude`:\n`*.anthropic.com`; `codex`: `*.chatgpt.com` + `*.openai.com`) — the one\nreachable destination is the service the agent already sends its context to.\nNote what that means for `--agent codex`: your Claude Code transcript\ncontent flows to OpenAI. Design: `docs/2026-07-05-mine-design.md`.\n\n```bash\nCLAUDE_CODE_OAUTH_TOKEN=... doublecheck mine \\\n  --projects DIR     # default: ~/.claude/projects\n  --catalog DIR      # default: ~/.doublecheck/catalog\n  --agent NAME       # claude (default) or codex\n  --model MODEL      # default per agent: claude opus, codex gpt-5.6-sol\n                     # (a bad-model mine pollutes a durable asset)\n  --parallel N       # default: 4\n  --min-turns N      # default: 2\n  --limit N          # mine at most N pending conversations\n  --dry-run          # list what would be mined, boot nothing\n```\n\n`fixtures/planted/` is a tiny target with two planted silent fallbacks (and\ntwo legitimate defaults that must not be flagged) for exercising the tool\nend-to-end:\n\n```bash\nCLAUDE_CODE_OAUTH_TOKEN=... doublecheck check --target fixtures/planted --model haiku\ndoublecheck check --target fixtures/planted --agent codex  # auth from ~/.codex/auth.json\n```\n\n## What the inspector sees\n\nThe facts of the agent's world, so you can decide how to author checks:\n\n- **The agent** is one headless CLI process per check, running inside its\n  own microVM with all approval/permission gates bypassed — the VM is the\n  boundary. Check agents have unrestricted internet egress.\n  - `--agent claude` (default): `claude -p` (model from `--model`, default\n    haiku) with the pinned toolkit Task (it can spawn subagents), Bash,\n    Read, Write, Edit, Glob, Grep, WebSearch, WebFetch.\n  - `--agent codex`: `codex exec` (default model gpt-5.6-sol, reasoning effort\n    pinned to xhigh in the staged guest config) with codex's own toolset:\n    shell, apply_patch, plan/todo, subagent spawning (multi_agent), and\n    server-side web search. The staged config disables codex's ambient\n    inputs — no AGENTS.md pickup, no plugin/marketplace fetch — so the\n    piped prompt is its only input, same as claude.\n- **Its only input is the prompt**: a short environment preamble (verbatim in\n  `src/contract.ts`) + the operator's run context, when `--context` was given\n  + the check body + the report contract. No session, no conversation history\n  — the check body is the standard; the run context is everything about this\n  particular run (intent, sanctioned exceptions, scope). The report contract\n  also tells the inspector that every line of its report is read in full,\n  findings must be verified, and \"no findings\" is a perfectly good report.\n- **The filesystem**: the project is bind-mounted read-only at its real host\n  path — the live working tree, dirty files and `.git` included, so `git\n  log`/`git diff`/`git blame` and `rg` work against the real repo; writes to\n  it fail. The guest image also has node 24, curl, and wget. The cwd is a\n  writable scratch dir private to the check; nothing in it survives except\n  `report.md`.\n- **The output**: the prompt tells the agent its chat reply is discarded and\n  only `./report.md` is read back. The harness imposes no structure on the\n  report — it contains whatever the check body asks for.\n\n```bash\npnpm doublecheck # run the CLI from source (tsx)\npnpm test        # vitest — pure logic, plus real-guest integration tests with a FAKE agent (never real claude)\npnpm typecheck   # tsc --noEmit\npnpm check       # biome\n```\n\nDesign records: `docs/2026-07-05-doublecheck-design.md`, `docs/2026-07-05-run-context-and-decomposed-flags-design.md`, `docs/2026-07-06-codex-agent-design.md`. For how a driving agent should use this tool — above all, what a good `--context` brief contains — see `SKILL.md`.\n\n## Releasing\n\nManual, via the `release` GitHub Actions workflow — semantic-release over\nConventional Commits, ported from pggit. Nothing releases as a side effect of\npushing to main.\n\n```bash\ngh workflow run release -f dry_run=true    # preview next version + notes, publish nothing\ngh workflow run release -f dry_run=false   # ship: npm publish + GitHub Release + tag + guest image\ngh workflow run release -f image_version=X.Y.Z  # no release: (re)build + push the guest image\n                                                # for an existing version (recovery, or refreshing\n                                                # the baked-in agent CLIs)\n```\n\nA real release also builds `Dockerfile.guest` for amd64+arm64 and pushes\n`ghcr.io/alizain/doublecheck-guest:<version>` (+ `:latest`) — the image\ninstalled CLIs pull at runtime. The ghcr package must be **public** for those\nunauthenticated pulls (one-time visibility flip in the package settings after\nthe very first push). `image_version` mutates an existing tag in place;\nmachines that already pulled it keep their cached copy (the runner pulls\nif-missing and never re-checks).\n\n- **Only `feat:` / `fix:` / `BREAKING CHANGE:` commits trigger a release** and\n  decide the bump (minor / patch / major). Other commit styles ride along\n  unreleased — use `docs:`/`chore:`/plain messages for work that shouldn't ship\n  a version.\n- `version` in package.json stays `0.0.0-development` forever — semantic-release\n  derives the real version from git tags. Never hand-bump it.\n- The pre-publish gate is biome + tsc + **unit tests only** (`test:unit`\n  excludes `*.integration.test.ts`, which boots real microsandbox guests CI\n  doesn't have) + tsdown build. Run the full `pnpm test` locally before\n  releasing.\n- Needs the `NPM_TOKEN` repo secret: a token that can publish\n  `@alizain/doublecheck` without an OTP prompt — classic \"Automation\" type, or\n  a granular token with read/write package access (and 2FA bypass if the\n  account requires 2FA for writes).\n\nLearned the hard way on the first release (2026-07-05):\n\n- **A failed `npm publish` leaves a stale tag.** semantic-release pushes\n  `vX.Y.Z` *before* publishing to npm. If the publish step fails, delete the\n  tag (`git push origin :refs/tags/vX.Y.Z`) before retrying — otherwise the\n  retry sees the tag as the last release, finds no new conventional commits,\n  and releases nothing.\n- **The package is scoped because npm forbids unscoped `doublecheck`.** The\n  name-similarity rule (`DoubleCheck` and `double-check` exist) rejects it with\n  a 403 at publish time only — registry lookups 404 as if the name were free.\n  The installed bin is still `doublecheck`; `publishConfig.access: public` is\n  what keeps a scoped package from defaulting to private.\n- **npm provenance/OIDC is off on purpose** — the presence of `id-token: write`\n  makes npm 11.x prefer trusted publishing and 404 when none is configured\n  (npm/cli#8976). Details in the comment block of\n  `.github/workflows/release.yml`.\n","readmeFilename":"README.md"}