{"_id":"@anthonysnider/alltest","_rev":"6-dfaa8d477e66992ae111a301cb1c7252","name":"@anthonysnider/alltest","dist-tags":{"latest":"0.5.1"},"versions":{"0.2.0":{"name":"@anthonysnider/alltest","version":"0.2.0","keywords":["testing","test-suite","static-analysis","security","vulnerability","code-quality","fuzzing","solidity","secrets-detection","sast","linter","ai-agents","code-review","0-day","zero-day"],"author":{"name":"lordbasilaiassistant"},"license":"MIT","_id":"@anthonysnider/alltest@0.2.0","maintainers":[{"name":"anthonysnider","email":"drlordbasil@gmail.com"}],"homepage":"https://github.com/lordbasilaiassistant-sudo/alltest#readme","bugs":{"url":"https://github.com/lordbasilaiassistant-sudo/alltest/issues"},"bin":{"alltest":"bin/alltest.js"},"dist":{"shasum":"28b95632d021dd511395a492d06089a2683c6b60","tarball":"https://registry.npmjs.org/@anthonysnider/alltest/-/alltest-0.2.0.tgz","fileCount":38,"integrity":"sha512-8jcn0IIuJMZWqpYEIXdnhMt0r6rYu/iAcAki7VCGhrX+ub8PMxLZ7ALgWqt96OLxLNM3sKCNZ0/jcndMv8opkg==","signatures":[{"sig":"MEYCIQClTP1CO2Y9YqIw0NfrfxJiE3WVDsphVMdj2meBXYTJIgIhAKZQaRfFRn6wLx62nd24JR8IwLIOoHoJgH7KBozh9UII","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":185337},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./probe":"./src/core/probe.js","./finding":"./src/core/finding.js"},"gitHead":"ec239f2cbc917a57717c40526f12184a460b540a","scripts":{"test":"node --test test/*.test.js","start":"node bin/alltest.js","sweep":"node bin/alltest.js sweep","selftest":"node bin/alltest.js scan . --format table","test:layers":"node scripts/run-layers.js"},"_npmUser":{"name":"anthonysnider","email":"drlordbasil@gmail.com"},"repository":{"url":"git+https://github.com/lordbasilaiassistant-sudo/alltest.git","type":"git"},"_npmVersion":"11.5.2","description":"The layered code-testing engine — run every kind of test/probe against any codebase, catch 0-day issues, file AI-fixable reports, and self-improve. Live → https://github.com/lordbasilaiassistant-sudo/alltest","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/alltest_0.2.0_1784742785032_0.7530272069812949","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@anthonysnider/alltest","version":"0.3.0","keywords":["testing","test-suite","static-analysis","security","vulnerability","code-quality","fuzzing","solidity","secrets-detection","sast","linter","ai-agents","code-review","0-day","zero-day"],"author":{"name":"lordbasilaiassistant"},"license":"MIT","_id":"@anthonysnider/alltest@0.3.0","maintainers":[{"name":"anthonysnider","email":"drlordbasil@gmail.com"}],"homepage":"https://github.com/lordbasilaiassistant-sudo/alltest#readme","bugs":{"url":"https://github.com/lordbasilaiassistant-sudo/alltest/issues"},"bin":{"alltest":"bin/alltest.js"},"dist":{"shasum":"c01474b729d6645361ff430a5ceb10f1c3f9ff1b","tarball":"https://registry.npmjs.org/@anthonysnider/alltest/-/alltest-0.3.0.tgz","fileCount":39,"integrity":"sha512-t6hOGHo7m0VQ8qSBpG4HcwCgNl5ASrNx7L0ZjCBWeJsr5Sg9LvBXfmZlhWerrjYa4hXPsAUA6ZA3YtFf7PT7+Q==","signatures":[{"sig":"MEUCIFQcgWGBWcZECTQi6OsqLMEtu9RlU7v1RkESBVS2fTVoAiEAnK5QwuiJfevd3MIAX28/yp/9FSQ/FbWlXnXOaYcYamo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":206194},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./probe":"./src/core/probe.js","./finding":"./src/core/finding.js"},"gitHead":"cdd65b8e6a0979ed4c056058bbf673ec34f68902","scripts":{"test":"node --test test/*.test.js","start":"node bin/alltest.js","sweep":"node bin/alltest.js sweep","selftest":"node bin/alltest.js scan . --format table","test:layers":"node scripts/run-layers.js"},"_npmUser":{"name":"anthonysnider","email":"drlordbasil@gmail.com"},"repository":{"url":"git+https://github.com/lordbasilaiassistant-sudo/alltest.git","type":"git"},"_npmVersion":"11.5.2","description":"The layered code-testing engine — run every kind of test/probe against any codebase, catch 0-day issues, file AI-fixable reports, and self-improve. Live → https://github.com/lordbasilaiassistant-sudo/alltest","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/alltest_0.3.0_1784745486933_0.8347284889837632","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@anthonysnider/alltest","version":"0.3.1","keywords":["testing","test-suite","static-analysis","security","vulnerability","code-quality","fuzzing","solidity","secrets-detection","sast","linter","ai-agents","code-review","0-day","zero-day"],"author":{"name":"lordbasilaiassistant"},"license":"MIT","_id":"@anthonysnider/alltest@0.3.1","maintainers":[{"name":"anthonysnider","email":"drlordbasil@gmail.com"}],"homepage":"https://github.com/lordbasilaiassistant-sudo/alltest#readme","bugs":{"url":"https://github.com/lordbasilaiassistant-sudo/alltest/issues"},"bin":{"alltest":"bin/alltest.js"},"dist":{"shasum":"c74865b1bcc22849839776d9f76e282e8cd9d720","tarball":"https://registry.npmjs.org/@anthonysnider/alltest/-/alltest-0.3.1.tgz","fileCount":39,"integrity":"sha512-Ln6bLK3lZQuoWnhCcyD2ZBbFbUmheg777Gj9l7eqYvktWnSNWp1KBEIn1HqXNTM8m/a3tjKN60hrDi9ekHKnZA==","signatures":[{"sig":"MEUCIQDGouhbm/DfKgAbObwqwH3CgURqgqBwZkvDNi4x+ag1fAIgMN9zDxBi3s46tVdaEwbV84eiFzrIg4eBFvrY6cWpd+c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":211215},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./probe":"./src/core/probe.js","./finding":"./src/core/finding.js"},"gitHead":"97681fb69807be3a4057bfe7f82ea6c1aff4b2a3","scripts":{"test":"node --test test/*.test.js","start":"node bin/alltest.js","sweep":"node bin/alltest.js sweep","selftest":"node bin/alltest.js scan . --format table","test:layers":"node scripts/run-layers.js"},"_npmUser":{"name":"anthonysnider","email":"drlordbasil@gmail.com"},"repository":{"url":"git+https://github.com/lordbasilaiassistant-sudo/alltest.git","type":"git"},"_npmVersion":"11.5.2","description":"The layered code-testing engine — run every kind of test/probe against any codebase, catch 0-day issues, file AI-fixable reports, and self-improve. Live → https://github.com/lordbasilaiassistant-sudo/alltest","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/alltest_0.3.1_1784745716380_0.8958359169330581","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@anthonysnider/alltest","version":"0.4.0","keywords":["testing","test-suite","static-analysis","security","vulnerability","code-quality","fuzzing","solidity","secrets-detection","sast","linter","ai-agents","code-review","0-day","zero-day"],"author":{"name":"lordbasilaiassistant"},"license":"MIT","_id":"@anthonysnider/alltest@0.4.0","maintainers":[{"name":"anthonysnider","email":"drlordbasil@gmail.com"}],"homepage":"https://github.com/lordbasilaiassistant-sudo/alltest#readme","bugs":{"url":"https://github.com/lordbasilaiassistant-sudo/alltest/issues"},"bin":{"alltest":"bin/alltest.js"},"dist":{"shasum":"2f71f174cdd6bef02e3c6a97bc446f723fb8084a","tarball":"https://registry.npmjs.org/@anthonysnider/alltest/-/alltest-0.4.0.tgz","fileCount":40,"integrity":"sha512-OO6TiWyll/7+b8oyfeB72uRi4EFbXWiqjVjLQsBugUkdrmB8J0gwGCddG1ym9iY8jYqV0xEz5Nf//LguRm3xRg==","signatures":[{"sig":"MEUCIB3Er7PAvJb6WhWZdD9yLUJQTO+dI6GG6YZQiSPccFn7AiEA5j1piHQPwsTinIegcj4vAUtAFfYoVoU6jgqzHDYDm+M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":222210},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./probe":"./src/core/probe.js","./finding":"./src/core/finding.js"},"gitHead":"1431338693b95ee661ffa6dee8286994accc4276","scripts":{"test":"node --test test/*.test.js","start":"node bin/alltest.js","sweep":"node bin/alltest.js sweep","selftest":"node bin/alltest.js scan . --format table","test:layers":"node scripts/run-layers.js"},"_npmUser":{"name":"anthonysnider","email":"drlordbasil@gmail.com"},"repository":{"url":"git+https://github.com/lordbasilaiassistant-sudo/alltest.git","type":"git"},"_npmVersion":"11.5.2","description":"The layered code-testing engine — run every kind of test/probe against any codebase, catch 0-day issues, file AI-fixable reports, and self-improve. Live → https://github.com/lordbasilaiassistant-sudo/alltest","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/alltest_0.4.0_1784746010843_0.5816670275610474","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@anthonysnider/alltest","version":"0.5.0","keywords":["testing","test-suite","static-analysis","security","vulnerability","code-quality","fuzzing","solidity","secrets-detection","sast","linter","ai-agents","code-review","0-day","zero-day"],"author":{"name":"lordbasilaiassistant"},"license":"MIT","_id":"@anthonysnider/alltest@0.5.0","maintainers":[{"name":"anthonysnider","email":"drlordbasil@gmail.com"}],"homepage":"https://github.com/lordbasilaiassistant-sudo/alltest#readme","bugs":{"url":"https://github.com/lordbasilaiassistant-sudo/alltest/issues"},"bin":{"alltest":"bin/alltest.js"},"dist":{"shasum":"87d7cfd95e7bf03892cceffa7a2890c22d50e828","tarball":"https://registry.npmjs.org/@anthonysnider/alltest/-/alltest-0.5.0.tgz","fileCount":41,"integrity":"sha512-YnrYK7L3I9cSHB9wHkVDctzMIOgLl4IPsvapCWc6XV1nqBNYh+JikQCewzMGZjqlZ8QHFE35OwrjBUcy17vO5A==","signatures":[{"sig":"MEUCIQCmsbkmhb6Pw+G7/kXcERp0nH0MYjZ70cxwFvJxqVrCFQIgb1LwpzCZW/jfNknaaupoJalkLwlb/tuced4b/7HBvcc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":228994},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./probe":"./src/core/probe.js","./finding":"./src/core/finding.js"},"gitHead":"7f18e68cb30adc14d6f49912766f8abb250d8b13","scripts":{"test":"node --test test/*.test.js","start":"node bin/alltest.js","sweep":"node bin/alltest.js sweep","selftest":"node bin/alltest.js scan . --format table","test:layers":"node scripts/run-layers.js"},"_npmUser":{"name":"anthonysnider","email":"drlordbasil@gmail.com"},"repository":{"url":"git+https://github.com/lordbasilaiassistant-sudo/alltest.git","type":"git"},"_npmVersion":"11.5.2","description":"The layered code-testing engine — run every kind of test/probe against any codebase, catch 0-day issues, file AI-fixable reports, and self-improve. Live → https://github.com/lordbasilaiassistant-sudo/alltest","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/alltest_0.5.0_1784746411403_0.6074227838685486","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@anthonysnider/alltest","version":"0.5.1","description":"The layered code-testing engine — run every kind of test/probe against any codebase, catch 0-day issues, file AI-fixable reports, and self-improve. Live → https://github.com/lordbasilaiassistant-sudo/alltest","type":"module","bin":{"alltest":"bin/alltest.js"},"publishConfig":{"access":"public"},"exports":{".":"./src/index.js","./probe":"./src/core/probe.js","./finding":"./src/core/finding.js"},"scripts":{"test":"node --test test/*.test.js","test:layers":"node scripts/run-layers.js","selftest":"node bin/alltest.js scan . --format table","sweep":"node bin/alltest.js sweep","start":"node bin/alltest.js"},"keywords":["testing","test-suite","static-analysis","security","vulnerability","code-quality","fuzzing","solidity","secrets-detection","sast","linter","ai-agents","code-review","0-day","zero-day"],"author":{"name":"lordbasilaiassistant"},"license":"MIT","engines":{"node":">=18"},"repository":{"type":"git","url":"git+https://github.com/lordbasilaiassistant-sudo/alltest.git"},"homepage":"https://github.com/lordbasilaiassistant-sudo/alltest#readme","_id":"@anthonysnider/alltest@0.5.1","gitHead":"1bc56b16ad1ff6c51aa66ccea1a3ff346b4d74d1","bugs":{"url":"https://github.com/lordbasilaiassistant-sudo/alltest/issues"},"_nodeVersion":"24.14.0","_npmVersion":"11.5.2","dist":{"integrity":"sha512-kiOvYKQCRjl1A5Q3Ax/UCtk6dw8j14xrny7nMv1AR9j43y151FSSNweUWs7xdD0VF0QeWf1L3y+AIs+bkrWrLw==","shasum":"50f9e81fa15149873cb3eef10372ade091238b03","tarball":"https://registry.npmjs.org/@anthonysnider/alltest/-/alltest-0.5.1.tgz","fileCount":41,"unpackedSize":231630,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIC/Knm0NbW8cEHcmNAe/1GJrCbpxKy5klzQEDQGq5ajNAiAvdPfSYvfVSyMQr8uxFIY4gPY35CTa5llNMOpPEBDE9g=="}]},"_npmUser":{"name":"anthonysnider","email":"drlordbasil@gmail.com"},"directories":{},"maintainers":[{"name":"anthonysnider","email":"drlordbasil@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/alltest_0.5.1_1784746574407_0.7746871375975863"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-22T17:53:04.914Z","modified":"2026-07-22T18:56:15.213Z","0.2.0":"2026-07-22T17:53:05.169Z","0.3.0":"2026-07-22T18:38:07.084Z","0.3.1":"2026-07-22T18:41:56.531Z","0.4.0":"2026-07-22T18:46:51.023Z","0.5.0":"2026-07-22T18:53:31.563Z","0.5.1":"2026-07-22T18:56:14.565Z"},"bugs":{"url":"https://github.com/lordbasilaiassistant-sudo/alltest/issues"},"author":{"name":"lordbasilaiassistant"},"license":"MIT","homepage":"https://github.com/lordbasilaiassistant-sudo/alltest#readme","keywords":["testing","test-suite","static-analysis","security","vulnerability","code-quality","fuzzing","solidity","secrets-detection","sast","linter","ai-agents","code-review","0-day","zero-day"],"repository":{"type":"git","url":"git+https://github.com/lordbasilaiassistant-sudo/alltest.git"},"description":"The layered code-testing engine — run every kind of test/probe against any codebase, catch 0-day issues, file AI-fixable reports, and self-improve. Live → https://github.com/lordbasilaiassistant-sudo/alltest","maintainers":[{"name":"anthonysnider","email":"drlordbasil@gmail.com"}],"readme":"# alltest\n\n[![npm](https://img.shields.io/npm/v/@anthonysnider/alltest?color=%23FFC24B&label=npm)](https://www.npmjs.com/package/@anthonysnider/alltest)\n[![ci](https://github.com/lordbasilaiassistant-sudo/alltest/actions/workflows/ci.yml/badge.svg)](https://github.com/lordbasilaiassistant-sudo/alltest/actions/workflows/ci.yml)\n[![license](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n[![site](https://img.shields.io/badge/live-site-FFC24B.svg)](https://lordbasilaiassistant-sudo.github.io/alltest/)\n\n**The layered code-testing engine.** Point it at *any* codebase and it runs layer upon\nlayer of probes — static analysis, dynamic build/test execution, fuzzing, and meta\nself-checks — to surface bugs, security holes, hardcoded secrets, smart-contract flaws,\nand quality issues. Then it files **AI-fixable** reports, **learns** new issue patterns as\nit goes (RSI), and streams a **labeled ML training corpus** for a future issue-detection model.\n\nBuilt for AI agents to test anyone's code, thoroughly, in one command.\n\n```bash\nnpx alltest scan .\n```\n\n```\n  alltest — /your/project\n  418 files · 6 languages · 13 probes · 210ms\n\n  server/db/users.js\n    ✗ HIGH     SQL built via string concatenation/interpolation:88\n        ↳ Possible SQL injection. Use parameterized queries instead of building the query string.\n  .env\n    ✗ HIGH     Environment file committed: .env:1\n        ↳ Remove the .env (git rm --cached), add it to .gitignore, and rotate anything it contained.\n  contracts/Vault.sol\n    ⛔ CRITICAL Authorization via tx.origin:42\n        ↳ tx.origin auth is phishable. Use msg.sender for authorization checks.\n\n  Summary: 1 critical · 2 high\n```\n\n---\n\n## Why alltest\n\nMost scanners do one thing. alltest is an **engine of layers**, designed so coverage grows\nover time instead of going stale:\n\n- **Layers upon layers.** `static → dynamic → fuzz → meta`. Each probe is a tiny pluggable\n  unit, so the catalog keeps expanding — and the RSI loop can propose new ones.\n- **It tests itself.** The suite runs *on itself*, a meta probe verifies its own integrity,\n  and a meta-**meta** test proves the self-test can actually go red on a regression.\n  Turtles all the way down (`npm run test:layers`).\n- **Findings are fixes-in-waiting.** Every finding carries an exact `file:line`, a redacted\n  snippet, why it matters, a concrete remediation, and acceptance criteria — ready for an\n  AI agent (or human) to act on, or to file as a GitHub issue.\n- **It gets smarter.** Novel finding signatures are learned into a knowledge base; recurring\n  ones get promoted to candidate detection rules. Every finding is also emitted as a labeled\n  training example — the seed corpus for a model that learns to find issues directly.\n- **Zero-friction.** Dependency-light, no build step, runs on Node ≥ 18, works on any repo\n  with no config.\n\n## Install\n\n```bash\n# one-off\nnpx alltest scan .\n\n# or install\nnpm i -g alltest        # global CLI\nnpm i -D alltest        # dev dependency + programmatic API\n```\n\n## Usage\n\n### Scan a codebase\n```bash\nalltest scan <path>                     # static probes (safe, no code execution)\nalltest scan . --exec                    # also build + run the test suite\nalltest scan . --format sarif --out report.sarif   # CI / GitHub code scanning\nalltest scan . --format json             # machine-readable (for agents)\nalltest scan . --min medium              # severity floor\nalltest scan . --fail-on high            # exit non-zero → CI gate\nalltest scan . --corpus data/findings.jsonl --learn   # feed ML corpus + RSI\n```\n\n### Adopt on a large repo — gate on *new* issues only\nA legacy codebase has existing debt you can't fix all at once. Accept it once, then fail CI\nonly on findings a change *introduces*:\n```bash\nalltest baseline .                                   # accept current findings → .alltest/baseline.json\nalltest scan . --baseline .alltest/baseline.json --fail-on high   # only NEW high+ findings fail\n```\nMatching is line-independent — moving accepted code never resurfaces it as \"new\", but a\ngenuinely new issue is caught. Output also reports how many baselined issues you've since fixed.\n\nFor the fastest possible PR gate, scan **only what changed**:\n```bash\nalltest scan . --since origin/main --fail-on high    # only files this PR touched\nalltest scan . --changed                             # working-set changes (staged/unstaged/untracked)\n```\n\n### Test every project under a directory\n```bash\nalltest sweep ~/code --corpus data/findings.jsonl --out sweep.json\n```\nFinds each project root and scans them all — \"check all my repos\" in one command.\n\n### Get the actual fix — not just advice\n```bash\nalltest fix .            # show the concrete before→after change for every fixable finding\nalltest fix . --apply    # write the safe, mechanical fixes to disk (shows what changed)\n```\nEach finding carries a real remediation, not a hint: the exact line rewrite, a unified-diff\npatch, and a plain-language note. Mechanical, behavior-safe fixes (`yaml.load`→`safe_load`,\nremove `rejectUnauthorized:false`, `tx.origin`→`msg.sender`, strip `debugger`, create\n`.gitignore`) are **auto-applicable**; risk-bearing ones (move a secret to `process.env`,\nparameterize a query) come as a reviewed suggestion. Add `--fix` to any `scan` to attach\nfixes to the JSON output for an agent to apply.\n\n```diff\n  ● auto  disable-tls-verify  server.js:44\n- const agent = new https.Agent({ rejectUnauthorized: false });\n+ const agent = new https.Agent({});\n  ○ review hardcoded-password  config.js:5   (set DB_PASSWORD, then rotate the old value)\n- const dbPassword = \"sup3r…\";\n+ const dbPassword = process.env.DB_PASSWORD;\n```\n\n### File AI-fixable GitHub issues\n```bash\nalltest report . --github owner/repo --min-severity high            # dry run\nalltest report . --github owner/repo --min-severity high --confirm  # create them\n```\nDeduped by signature so re-runs never spam. Requires the [`gh`](https://cli.github.com) CLI.\n\n### Use in CI (GitHub Actions)\n\nGate any repo on alltest in one step — findings appear in the **Security → Code scanning** tab:\n```yaml\n# .github/workflows/alltest.yml\nname: alltest\non: [push, pull_request]\npermissions: { contents: read, security-events: write }\njobs:\n  scan:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: lordbasilaiassistant-sudo/alltest@v1     # runs the scan → alltest.sarif\n        with: { fail-on: high }\n      - uses: github/codeql-action/upload-sarif@v3\n        with: { sarif_file: alltest.sarif }\n```\nOr just `run: npx @anthonysnider/alltest scan . --fail-on high` for a plain gate.\n\n## Programmatic API\n```js\nimport { scan, render } from 'alltest';\n\nconst result = await scan({ root: './my-app', allowExec: false });\nconsole.log(render(result, 'markdown'));\nfor (const f of result.findings) {\n  console.log(f.severity, f.ruleId, f.location, '→', f.fixHint);\n}\n```\n\n## What it catches — 15 probes across 4 layers\n\n| Layer | Probe | Examples |\n|---|---|---|\n| static | secrets | private keys (incl. EVM `Wallet()`), 40+ vendor patterns (AWS, GitHub, GitLab, OpenAI, Anthropic, Stripe, Slack, npm, Twilio, SendGrid, Google OAuth, Telegram…), DB/credential URLs, credential assignments |\n| static | **entropy-secrets** | **0-day secrets**: high-entropy tokens of *unknown* vendor/format that match no signature (found real hardcoded `ADMIN_KEY`s in testing) |\n| static | dangerous-js | eval (incl. indirect `(0,eval)`), `Function()`, string-arg `setTimeout`, command & SQL injection, DOM-XSS (`innerHTML +=`), disabled TLS, JWT `none`, weak randomness |\n| static | python-danger | eval/exec, pickle/yaml/torch/joblib deserialization (RCE), `shell=True`, `verify=False`, SSTI, Django secret, assert-auth |\n| static | solidity | tx.origin auth, unchecked/low-level calls, delegatecall, selfdestruct, block-var randomness, range pragma, unbounded loops, zero-address setters |\n| static | deps | wildcard/unbounded versions, missing lockfile, `curl\\|bash` in scripts, install hooks, optional/peer deps, invalid manifest |\n| static | config-hygiene | committed `.env`, **private-key files** (`.key`/`.pem`/`id_rsa`, content-aware vs public certs), `.env` not gitignored |\n| static | env-leak | error/stack leaks (Express/Koa/Fastify/render), `process.env` dumps, wildcard CORS |\n| static | ci-docker | `:latest` images, `curl \\| bash`, ADD-from-URL, root containers, unpinned Actions, `pull_request_target` |\n| static | complexity | high cyclomatic complexity, long functions, deep nesting, oversized files — where latent bugs hide |\n| fuzz | json-roundtrip | malformed JSON/config that crashes at load |\n| dynamic | build / tests | build failures, failing or absent test suites (`--exec`) |\n| meta | self-integrity | alltest's own registry + Finding-schema invariants |\n\nRun `alltest probes` for the live list.\n\n## Hard isolation for untrusted probes\n\nProbes run in-process by default (fast, like ESLint plugins). To scan with untrusted or\nRSI-generated probes — or to enforce a real wall-clock — use the worker **sandbox**, whose\nsupervisor can `terminate()` a probe stuck in a *synchronous* infinite loop (something no\nsame-thread timeout can do):\n\n```bash\nalltest scan . --sandbox --timeout 60          # hard 60s ceiling, killable\nalltest scan . --sandbox --probe-module ./my-probe.mjs\n```\n\n## Extend detection with your own rules — no code\n\nDrop a `.alltest/rules.json` in any repo to add detections (org-specific token formats,\nforbidden functions, deprecated APIs):\n```json\n[{\n  \"id\": \"no-internal-token\",\n  \"pattern\": \"INT-[A-Z0-9]{24}\",\n  \"severity\": \"high\",\n  \"title\": \"Internal service token committed\",\n  \"fixHint\": \"Load INT_TOKEN from the environment and rotate this one.\",\n  \"languages\": [\"*\"]\n}]\n```\n\nalltest also **proposes new rules from what it has learned**. As the RSI knowledge base\naccumulates repeated patterns, `alltest propose-rules --out .alltest/rules.json` drafts\ndetection rules for you to review and enable — the closed end of the self-improvement loop\n(it proposes; a human/agent vets before a learned regex can flag other code).\n\n## Suppressing false positives\n```js\nconst y = eval(trusted);   // alltest-ignore\nconst z = eval(trusted);   // alltest-disable-line eval-use\n```\n```\n# .alltestignore\nvendor/\n**/generated/*.js\n```\n\n## The layered self-test\n\n```\nLayer 0  Bootstrap — the engine loads, the registry builds\nLayer 1  Unit — the tests FOR the tester (probes vs ground-truth fixtures)\nLayer 2  Meta — the suite tests ITSELF (alltest scans alltest)\nLayer 3  Meta-meta — proves Layer 2 can go red on a real regression\nLayer 4  Mutation — deliberately breaks detection to prove the tests have teeth\nLayer 5  Robustness — hostile & degenerate inputs never crash the engine\nLayer 6  Sandbox — proves a synchronously-hanging probe is actually killed\nLayer 7  Regressions — every adversarial-review finding locked forever\nLayer 8  RSI + ML pipelines learn and emit correctly\nLayer 9  Probe coverage + reporter/ignore contracts (SARIF/JSONL/JSON)\n```\n```bash\nnpm test            # 100 tests, all layers\nnpm run test:layers # narrated, layer by layer\n```\n\nEvery detection rule was adversarially reviewed; each confirmed false-positive and\nfalse-negative is now a locked regression test (`test/regressions.test.js`).\n\n## Roadmap\n- More probes (Rust/Go/Java depth, taint-tracking, AST-level analysis).\n- A code-level fuzz engine (property generation against exported functions).\n- Rule synthesis: auto-generate probes from promoted RSI signatures.\n- Train the first issue-detection model on the collected corpus.\n\n## License\nMIT\n\n---\n\n<sub>alltest can use free GLM for optional AI-assisted triage. If you want a coding plan\nthat runs models like this, the **[z.ai Coding Plan](https://z.ai/subscribe?ic=BWTG6TRYYQ)**\nlink is a referral — it helps fund alltest's development. (Disclosed referral, not a discount.)</sub>\n","readmeFilename":"README.md"}