Implement the approved toolkit 0.10.0 local scenario alongside OCR qualification #181. Local review must work without GitLab credentials or API calls, including with inherited CI variables; accept immutable commit/range input; require the built-in evidence MCP and completed summary; allow explicitly configured external MCP; return all admitted findings in a private Markdown artifact and shared console summary without posting, suppression or approval.
Local debug must execute the same validation and DLP path, retain bounded owner-only original and safe artifacts separately, and journal actual system decisions rather than rescan approximations. Raw rejected text stays in private files, not automatic console output. Cover early failures, permissions, hostile paths, limits, cleanup and installed wheel/sdist end-to-end boundaries. Preserve GitLab formatting and lifecycle semantics through shared pure reporting.
Delivery stops at a green Draft PR. Real-provider GitLab/local/debug qualification and owner confirmation precede merge and stable delivery. Keep this issue open until the protected release lifecycle proves delivery.
Implementation and current evidence are tracked in replacement Draft #184 (replacing #183). The configured external qualification checklist is in docs/local.md: install the exact Draft artifact and record GitLab/local/debug/progress outcomes plus unset, explicit none and intended nonempty reasoning effort for the actual provider/model/protocol. No-LLM wire qualification does not prove provider acceptance or application; HTTP 200 alone is insufficient.
Implement the approved toolkit 0.10.0 local scenario alongside OCR qualification #181. Local review must work without GitLab credentials or API calls, including with inherited CI variables; accept immutable commit/range input; require the built-in evidence MCP and completed summary; allow explicitly configured external MCP; return all admitted findings in a private Markdown artifact and shared console summary without posting, suppression or approval.
Local debug must execute the same validation and DLP path, retain bounded owner-only original and safe artifacts separately, and journal actual system decisions rather than rescan approximations. Raw rejected text stays in private files, not automatic console output. Cover early failures, permissions, hostile paths, limits, cleanup and installed wheel/sdist end-to-end boundaries. Preserve GitLab formatting and lifecycle semantics through shared pure reporting.
Delivery stops at a green Draft PR. Real-provider GitLab/local/debug qualification and owner confirmation precede merge and stable delivery. Keep this issue open until the protected release lifecycle proves delivery.
Implementation and current evidence are tracked in replacement Draft #184 (replacing #183). The configured external qualification checklist is in
docs/local.md: install the exact Draft artifact and record GitLab/local/debug/progress outcomes plus unset, explicit none and intended nonempty reasoning effort for the actual provider/model/protocol. No-LLM wire qualification does not prove provider acceptance or application; HTTP 200 alone is insufficient.