Precision begins with measuring what is true.
Inspect a real public analysis sample, live engine test telemetry, and our Three-Universe validation methodology. AI-generated code needs independent evidence; generation alone cannot establish semantic equivalence.
145 test files with 16,413 assertions executing on Bun 1.4.2. 0 failed, 1 skipped (file symlink privilege).
Automated governance verification verdict PASS on engine HEAD commit 97ab7a9dcdd.
Stratified evaluation against representative benchmark fixtures from Express v4.21.2 and Fastify v5.3.3; does not claim full framework semantic coverage.
Five-file inspection slice at revision 42b90bd in legacyexodus-analysis-sample.
A small program.
An explicit model.
The source-visible sample demonstrates selected AST/CFG construction, reachability, invariant checks, serialization, a CLI, and a local browser demo. It is a limited slice of the private platform.
function classifyScore(score: number) {
if (score >= 70) {
return "pass";
}
return "review";
}
classifyScore(82);From the repository's actual sample.ts at revision 42b90bd.
Source line 2: score >= 70. The true edge leads to pass and the false edge to review.
Inspect reachability
Both return branches have a path from ENTRY. No statement is stranded after a return in this example. Reachability describes this graph; it does not prove all runtime behavior.
The public sample test suite verifies 92 tests across five files. Consult the capability matrix for exact supported constructs and uncertainty handling.
The Three-Universe fidelity model
To prevent self-confirming static analysis errors, LegacyExodus evaluates code understanding across three distinct universes of evidence:
Universe 1: Source Ground Truth
The literal source code as authored on disk—including syntactic structure, lexical scopes, and repository configuration manifests. VyrixScout establishes this baseline through deterministic file inventory and module resolution.
Universe 2: Synthesized Semantic Model
The compiler-grade intermediate representation constructed by NolaraStruct: normalized Babel ASTs, scoped symbol resolution tables, interprocedural call graphs, CFGs, DFGs, and conservative taint facts.
Universe 3: Behavioral Runtime Reality
The actual observed behavior under execution. While static analysis cannot mathematically prove all dynamic runtime behaviors, cross-referencing with test suites and differential execution exposes discrepancies between inferred paths and runtime reality.
Our 25-file stratified ground truth validates Universe 2 extraction accuracy against real-world production libraries (Express v4.21.2 and Fastify v5.3.3), ensuring real architectural patterns are handled correctly.
The broader foundation.
Documented scope.
JavaScript and TypeScript
The published foundation focuses on JavaScript and TypeScript repositories. Babel parsing and AST normalization provide the starting representation. Support for other languages (PHP, Ruby, Java) is on our active roadmap and should not be assumed from the long-term vision.
Semantic modeling
Scope and symbol analysis distinguish declarations from references and account for documented cases such as destructuring and hoisting. Module resolution and semantic call-graph reconstruction recover relationships beyond file inventory.
Program flow & taint analysis
Control-flow graphs describe inferred execution paths. Data-flow graphs describe inferred movement of values. Interprocedural taint-flow foundations extend this model across function boundaries, within the analyzer's supported static cases.
Evidence that survives the run
Structured output is a contract between analysis and its consumers. The private engineering engine implements streaming JSON serialization with bounded backpressure, in-memory and SQLite providers, snapshot restoration, and deterministic artifact reuse.
Reproducibility helps compare runs under the same inputs and detect unexpected changes. It cannot substitute for checking whether the reconstructed model represents the source faithfully.
Known limitations and boundaries
Static analysis operates under sound conservative assumptions. It is essential to document what is known versus what is not yet established:
- Intraprocedural vs. Interprocedural: Certain complex higher-order callbacks and dynamic closures remain bounded to intraprocedural scope.
- Dynamic Dispatch & Reflection: Dynamic property accesses,
eval(), runtimeimport(), and prototype modifications cannot be statically guaranteed without runtime tracing. - Conservative Taint Facts: Taint paths represent potential propagation routes and may over-approximate unreachable paths or miss highly dynamic reflection routes.
- Framework Semantics Boundary: Analysis covers generic deterministic JavaScript/TypeScript analysis plus narrow Express route and middleware recognition for proven patterns. Comprehensive Fastify, React, NestJS, Angular, Vue, or other framework runtime semantics are deferred; benchmark fixtures represent sample-based evaluation rather than exhaustive framework coverage.
Not yet established: complete migration safety, general runtime equivalence, and production readiness of the planned transformation pipeline.
Generation needs its own evidence
The intended AI gateway (ZelvoxForge) can help explain architecture, surface migration risks, and propose candidate transformations against versioned, source-traceable context. Typed outputs and limited tool access make proposals reviewable.
A compiling candidate can still change behavior. Planned verification (VymosGate) must assess transformation contracts, tests, compiler results, and relevant behavioral evidence independently of the proposer. Human approval remains a separate checkpoint.
Explore the governed AI boundaryQuestions worth asking
Start with understanding.
Follow the engineering, explore the approach, or get in touch.