Browse documentation
Documentation / LintLang 0.8.0

Concepts and limitations #

A LintLang verdict describes the content actually inspected with the selected checks. It does not describe everything an agent may see or do.

Inspection coverage #

Read Inspected: in terminal/Markdown output or inspected and not_inspected in JSON. Unsupported dynamic prompts, omitted host layouts, excluded files, and unresolved localization text are coverage limits, not clean results. Supported inputs explains what extraction recognizes.

SKIPPED is not PASS #

SKIPPED means a readable file contained nothing recognized for inspection. A zero-inspection scan is an error by default. --allow-empty and --allow-uninspected deliberately relax particular empty/uninspected cases; consult the full exit contract before using either in CI.

PASS means no remaining MEDIUM-or-higher structural finding after selected filters and any baseline. LOW/INFO findings can remain. REVIEW means MEDIUM; FAIL means HIGH/CRITICAL. ERROR means inspection failed. The CLI reports verdicts without gating by default; exit policy is explicit.

HERM confidence is coverage #

HERM confidence is a heuristic coverage label, separate from PASS/REVIEW/FAIL. It is not a statistical probability, finding certainty, detector accuracy, or a safety score. Coverage bands in this release are high at 90% or above, medium at 75% or above, and low below 75%; the released CLI help is the source for these thresholds.

Static analysis boundary #

LintLang does not run models, observe tool selection, prove semantic truth or correctness, certify safety, or replace runtime evaluation, domain review, or security review. H1.6's finite lexicon cannot recognize every semantic equivalence; external labeled-corpus precision and recall have not been measured. Samples and regression tests are not an independent accuracy benchmark.

Determinism and network boundary #

The same inputs and selected rules produce the same findings and verdicts. Terminal elapsed time is not byte-stable. Scans make no model, network, or telemetry calls. Installers download dependencies; GitHub/GitLab uploads and agent hosts retain their own network behavior. Diagnostics can contain source-derived text: review reports before sharing them.