Skip to main content

reconkit (Judicium surface)

reconkit is a conservative, safe-by-default toolkit that exposes a Noir Stack / Hexarch / Judicium-flavored public API.

It is designed to produce audit-grade structured outputs that explicitly state:

  • what was observed (evidence)
  • how it was observed (provenance)
  • what is and is not being asserted (verification limits)

This project is intended for lawful use on systems/data you own or have permission to assess.

Noir Stack primitives

Public primitives:

  • EvidenceArtifact: immutable bytes + provenance
  • EvidenceBundle: a set of artifacts for joint assessment
  • ProvenanceRecord: acquisition/derivation metadata + trust boundary
  • VerificationResult: structured decision output

All structured outputs include:

  • decision_basis
  • verification_status
  • provenance_confidence

Because this is Judicium, not divination.

Guarantees

What the system will reliably do:

  • Preserve evidence payload bytes as acquired/derived, and compute stable SHA-256 for artifacts.
  • Emit structured, JSON-serializable outputs suitable for logging and later review.
  • Respect declared acquisition constraints (e.g., max_bytes) and treat them as policy boundaries.
  • Respect robots.txt by default for web acquisition.

Assumptions

What the system assumes unless you override it:

  • trust_boundary is declared explicitly for acquisitions. The tool will not invent one.
  • Web acquisition is transport-level observation, not identity/authenticity proof.
  • Public-internet boundary data (DNS/WHOIS/RDAP) is administrative metadata.

Non-goals

What the system explicitly does not do:

  • No anti-bot bypassing, fingerprint evasion, proxy-rotation orchestration, or credentialed scraping.
  • No claims of attribution, intent, or identity. (You can do that in your report; the tool will not do it for you.)
  • No “automatic truth.” The system is already busy being correct.

Install

python -m pip install -e ".[dev]"

CLI quickstart (Noir terminology)

All commands emit audit-grade JSON.

# Evidence acquisition / derivation
reconkit evidence acquire-web "https://example.com" --trust-boundary public-internet
reconkit evidence derive-links "https://example.com"
reconkit evidence derive-text "https://example.com"

# Boundary observations (OSINT-ish, but we say the quiet part out loud)
reconkit boundary dns example.com
reconkit boundary whois example.com
reconkit boundary ip 8.8.8.8

# Verification (informational)
reconkit verify file-hash .\somefile.bin --algo sha256
reconkit verify file-type .\somefile.bin
reconkit verify strings .\somefile.bin --min-len 6
reconkit verify exif .\photo.jpg

Notes

  • If acquisition is blocked by robots.txt, that is not a “bug.” It is a boundary condition.
  • If you need features that reduce accountability, you are in the wrong repository. Convenient.

Release files for reconkit 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for reconkit 0.1.0
File Size Uploaded
reconkit-0.1.0.tar.gz 12.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for reconkit 0.1.0
File Interpreter ABI Platform
reconkit-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 30.8 kB

Release files / reconkit-0.1.0.tar.gz

Download URL reconkit-0.1.0.tar.gz
Size 12.9 kB
Tags Source
SHA-256 checksum
How to use checksums
0f3d635c0622ecd2a29cdada1fc8eb28b744181f2c6138e05b378bf010782118
BLAKE2b-256 checksum
How to use checksums
3fb8b6e09f0e57e98615a3e6471b674e0907f48a741a64a404d242e9b6a36656
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.10

Release files / reconkit-0.1.0-py3-none-any.whl

Download URL reconkit-0.1.0-py3-none-any.whl
Size 17.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7f3b227fe9fd59c5621f6284b75e4b5baba050be17155dbca23a7e568d73bae2
BLAKE2b-256 checksum
How to use checksums
8d11ebc491d4d42776976e22deb73b423fa7df2eb0e1520414bfb13d0d486645
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.10

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page