Skip to main content

matrx-mandate-scan

The ONE Mandate reference scanner. It finds every place code reaches for platform intelligence — through a Mandate carrier or around it — reports the result to the database in one frozen contract, and screams (never blocks) when something is unresolved, unmeasured, or bypassing the mandate system.

Built for the Mandate Declaration & Usage Reporting program (common-docs/projects/mandate-declaration-reporting/), lane L2.

Install / run

# from any repo, no checkout needed
uvx --from matrx-mandate-scan==0.1.0 matrx-mandate-scan check

# inside the aidream workspace (vendored via [tool.uv.sources])
uv run matrx-mandate-scan scan --root aidream --root packages/matrx-ai

Commands

Command What it does
scan Contract-v1 JSON on stdout, the red human report on stderr.
report scan, then submit through mandate.submit_scan_report(jsonb) and file every red finding into ops.system_error (source_app='mandate-scan').
check The release-path command: scan + report + reconcile.
explain <file:line> What the scanner sees at one location, and why.
--self-test The built-in RED→GREEN fixture suite. Runs from a uvx install.

Every command exits 0 unless --strict is passed. That is ruling D23: a mandate check is loud and non-blocking; --strict exists for humans and for the scheduled remediation task, never for a release script.

What counts as a reference

Classification is by carrier, never by the word or the path. A dotted string is a mandate key only where a carrier puts it — so consumerId = "extend.chat" is not a reference and never becomes one.

Python carriers:

  • declare_mandate / declare_generated_mandate / declare_mandated_agentdeclaration
  • declare_mandate_family(prefix, members=...)family_declaration, one constant per resolvable member, dynamic_family when the iterable is computed
  • resolve_mandateresolution; run_mandateexecution
  • run_mandated(Cls) / Cls.run()execution
  • a NamedAgent subclass mandate_key (including type(name, (NamedAgent,), {...})) → declaration
  • seed_agent_id=<uuid> inside a declare_*seed_holder
  • @mandate_passthrough / MandateKeyParampassthrough, with the caller attributed when it lives in the same module

Config carriers (JSON / YAML / TOML) — the property name is the carrier: mandate_key, mandateKey, defaultMandateKey, fallback_mandate_key. Anything else that merely looks key-shaped is unclassified and advisory.

Keys resolve through literals, module and function constants (UPPER or not), attribute constants, f-strings, + concatenations, ternaries (both branches become real references), tuple/list loop members, aliases, literal-container subscripts, and one level of analyzable module-local wrapper function.

An argument that resolves to none of those → finding UNRESOLVED_KEY, plus an unresolved-flagged reference: D21 says unreachable is a flag, never a filter, so nothing is ever dropped from the inventory.

Bypass detection and the ratchet

Importing a provider SDK (anthropic, openai, groq, google.genai, google.generativeai, litellm, xai, ollama, cohere, mistralai) or naming a provider host, anywhere outside packages/matrx-ai/matrx_ai/providers/** and the one D10-approved module (conversation_labeler.py), is a bypass reference. The exact standalone RAG default embedding adapter (packages/matrx-rag/matrx_rag/embeddings.py) is also an approved provider adapter: it is injected through EmbeddingProvider, does not select a Mandate holder, and is independently ratcheted by scripts/check_raw_llm_clients.py. No broader matrx-rag exemption exists.

  • in the --baseline file → CONVERSION_PENDING (flag conversion_pending)
  • not in it → NEW_BYPASS (D20: no new ones)
  • a dynamic import that hides its target → UNRESOLVED_IMPORT

--write-baseline regenerates the file and refuses to write a larger one. No entry in the baseline is an approved class; every one is a defect awaiting conversion.

Coverage is mandatory output

Every file is scanned or listed with a reason (generated, test_fixture, parse_error, unsupported_language). Any parse_error makes the package verification_status = incomplete and files an UNMEASURED finding.

Reference identity

sha256(repo_slug · package_path · file_path · symbol · occurrence_n · reference_type · mandate_key_or_prefix).

repo_slug is always the repo the scan ran in, resolved from git remote get-url origin through the platform.repo mirror in matrx_mandate_scan/repo.py. An unknown remote is UNMEASURED, never a guessed slug — a folder name is not a repo identity.

Boundaries

Per docs/packages/PACKAGE_DOCTRINE.md, this package imports neither aidream nor matrx-orm. It carries the AST walkers that used to live in scripts/audit_mandate_wiring.py and aidream/services/mandates/code_truth.py; those two modules now import them from here, so there is exactly one definition of "what a carrier looks like".

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

matrx_mandate_scan-0.1.0.tar.gz (81.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

matrx_mandate_scan-0.1.0-py3-none-any.whl (78.1 kB view details)

Uploaded Python 3

File details

Details for the file matrx_mandate_scan-0.1.0.tar.gz.

File metadata

  • Download URL: matrx_mandate_scan-0.1.0.tar.gz
  • Upload date:
  • Size: 81.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for matrx_mandate_scan-0.1.0.tar.gz
Algorithm Hash digest
SHA256 830a3e6af58870b1f61c4bffd20a2dc4b43b753b2335a2b9450fc42e58bb2614
MD5 bf204b23eb2536931bf67df12f25c130
BLAKE2b-256 a637922abfc7b2cbcf94298f049f3c2c4a7a129595c1f16ef54cbf31ec696f64

See more details on using hashes here.

Provenance

The following attestation bundles were made for matrx_mandate_scan-0.1.0.tar.gz:

Publisher: publish-package.yml on AI-Matrix-Engine/aidream

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file matrx_mandate_scan-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for matrx_mandate_scan-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a5c268f10aece835f41c08b9db93347a2eb4f74c39017179adf96b1d3e9f9a3f
MD5 d88ceb947169fb7df1330c8c277c23f4
BLAKE2b-256 d395962d35cd43dd78d6a010f7ae5f22c6b71b7b0005c1aa50933e632bfa7f18

See more details on using hashes here.

Provenance

The following attestation bundles were made for matrx_mandate_scan-0.1.0-py3-none-any.whl:

Publisher: publish-package.yml on AI-Matrix-Engine/aidream

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.11

2 files

0.1.10

2 files

0.1.9

2 files

0.1.8

2 files

0.1.7

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page