{
  "schema_version": "2.0",
  "slug": "lacs-project-sysknife",
  "name": "SysKnife",
  "agent_url": "https://lacs-project.github.io/sysknife/",
  "repo_url": "https://github.com/lacs-project/sysknife",
  "category": "Infrastructure",
  "run_id": "run-349042e4bb09dfd2-lacs-project-github-io",
  "run_at": "2026-08-18T08:06:25.333Z",
  "editor": "Hlido Editor",
  "editorial_method": "public-surface-tier-2+editorial-narrative-v2",
  "methodology_version": "2026.05",
  "methodology_url": "/methodology/public-surface-tier-1/",
  "score": 81,
  "tier": "STEADY",
  "laddoo_score": 81,
  "confidence": "low-medium",
  "hlido_opinion": {
    "headline": "A Linux sysadmin co-pilot built around the right safety primitive: the AI proposes typed actions, never shell strings, and a privileged daemon executes only what you approve.",
    "body": "SysKnife turns a plain-language request into a typed plan — named actions with formal risk levels (Low read-only, Medium reversible, High irreversible) — that you review and approve before a root daemon executes it step by step with live output and automatic rollback on failure. The architecture is the point and it is well-drawn: an unprivileged brain talks to the LLM and can only propose typed actions; an approval-gate shell shows you the plan and collects consent; a locked root daemon is the only thing that touches the system, and only after an approved plan. Every execution is Ed25519-signed and hash-chained into an immutable audit trail. This directly answers the failure mode of pasting an LLM's shell command and finding out what it did afterward. MCP is presented as the primary path (npx sysknife-setup wires up Claude Code, Cursor, Codex CLI), with a fully-supported CLI and a distant-third experimental GUI. The claimed evidence base is substantial and specific: 190 typed actions, 1,759 Rust tests plus 72 frontend tests, MIT-licensed, with committed live-VM story runs for Ubuntu 22.04/24.04/26.04 at 79/79 and honest gates flagged for Fedora Atomic and plain Fedora. SysKnife is also framed as the reference implementation of LACS, a CC0 protocol. Hlido reviewed the documentation site, not a running daemon, so the audit chain, rollback and story-run results are described-and-cited rather than reproduced here — but the trust-boundary design is exactly what system-level agent tooling should look like.",
    "voice": "Hlido Editor",
    "as_of": "2026-08-19",
    "editor_signature_pending": true
  },
  "tier_rationale": "STEADY (81) for a system-level agent co-pilot whose core design is a genuine safety architecture (typed actions not shell strings, privilege-separated brain/shell/daemon, mandatory human approval, Ed25519 hash-chained audit, automatic rollback), backed by a specific evidence base (190 actions, 1,759+ tests, committed multi-release VM story runs) and MIT-licensed — held at low-medium confidence because Hlido reviewed the docs surface, not a live daemon, so the audit chain and story runs are cited rather than reproduced. Not VITAL absent hands-on verification of the privileged execution path.",
  "what_it_does_well": [
    "Correct core safety primitive: the LLM emits typed actions with risk levels, never raw shell strings, and cannot itself touch the system",
    "Clean privilege separation — unprivileged brain (proposes) / user shell (approval gate) / locked root daemon (executes) — with human approval mandatory",
    "Immutable accountability: every execution is Ed25519-signed and hash-chained; automatic rollback on high-risk failure",
    "MCP-first (npx sysknife-setup for Claude Code / Cursor / Codex) with a first-class CLI; runs local models via auto-detected Ollama with no API key",
    "Specific, checkable evidence base — 190 typed actions, 1,759 Rust + 72 frontend tests, MIT, and committed 79/79 live-VM story runs across three Ubuntu LTS releases, with Fedora honestly marked experimental"
  ],
  "what_it_fails_at": [
    "Surface-only review — Hlido read the documentation, not a running daemon, so the audit chain, rollback and story-run pass rates are cited, not reproduced here",
    "Fedora support is partial by the project's own admission (Atomic gated on a Silverblue run; plain Fedora experimental until the dnf action family ships)",
    "A source build pulls ~400 crates and takes ~7–12 minutes; running it means a root daemon on your system",
    "The desktop GUI is explicitly the least-maintained surface — reach for MCP or CLI"
  ],
  "best_for": [
    "Engineers who want an AI Linux co-pilot with real guardrails — preview, approval, rollback and a signed audit trail",
    "Teams that need an accountable record of every system change an agent made",
    "Ubuntu/Debian users wanting MCP-driven administration from Claude Code / Cursor / Codex"
  ],
  "not_recommended_for": [
    "Plain-Fedora or non-Ubuntu users needing full action coverage today",
    "Anyone unwilling to run a privileged (root) daemon",
    "Users wanting a polished GUI-first experience"
  ],
  "red_flags": [],
  "compared_to": [],
  "evidence_urls": [
    {
      "claim": "Correct core safety primitive: the LLM emits typed actions with risk levels, never raw shell strings, and cannot itself touch the system",
      "source": "https://lacs-project.github.io/sysknife/",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Clean privilege separation — unprivileged brain (proposes) / user shell (approval gate) / locked root daemon (executes) — with human approval mandatory",
      "source": "https://lacs-project.github.io/sysknife/",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Immutable accountability: every execution is Ed25519-signed and hash-chained; automatic rollback on high-risk failure",
      "source": "https://lacs-project.github.io/sysknife/",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "MCP-first (npx sysknife-setup for Claude Code / Cursor / Codex) with a first-class CLI; runs local models via auto-detected Ollama with no API key",
      "source": "https://lacs-project.github.io/sysknife/",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Hands-on runtime behaviour (executing the tool / a live task)",
      "source": "https://lacs-project.github.io/sysknife/ (surface-only review; not hands-on tested)",
      "tested_at": "2026-08-19",
      "verified": false
    }
  ],
  "agent_relevance": {
    "has_api": false,
    "has_cli": true,
    "has_mcp": true,
    "has_webhook": false,
    "has_sdk": false,
    "behavioral_testable": true,
    "agent_integration_path": "`npx sysknife-setup` wires the MCP server into Claude Code / Cursor / Codex CLI; the agent proposes typed actions in chat, the user approves in a terminal, and a root daemon executes with a one-time receipt. A first-class CLI offers the same loop.",
    "agent_friendly_score": 9
  },
  "summary": "A Linux sysadmin co-pilot built around the right safety primitive: the AI proposes typed actions, never shell strings, and a privileged daemon executes only what you approve.",
  "_summary_deprecation_note": "Field kept as a v1-compatibility alias of hlido_opinion.headline. New consumers should read hlido_opinion.{headline,body,voice,as_of}.",
  "staleness_after": "2026-11-19",
  "review_age_days_at_publish": 0,
  "next_review_due_at": "2026-11-19",
  "attestation_url": "/data/attestations/lacs-project-sysknife.json",
  "signature_pending": true,
  "source": "hlido-editor-v2",
  "marking_signal": {
    "marking_statement": false,
    "detection_tool": false,
    "cop_signatory": null,
    "evidence_url": null,
    "checked_at": "2026-08-19",
    "source": "r-publish-editorial-enrich",
    "not_applicable": true,
    "note": "A system-administration agent tool, not a generator of synthetic media or deceptive content — Article-50(4) marking obligations do not apply."
  },
  "evidence_images": {
    "run_id": "run-349042e4bb09dfd2-lacs-project-github-io",
    "base": "https://images.hlido.eu/reviews/lacs-project-sysknife/run-349042e4bb09dfd2-lacs-project-github-io",
    "files": [
      "home.png",
      "pageintroduction_html.png",
      "pagequickstart_html.png",
      "pagemcp_html.png"
    ],
    "urls": [
      "https://images.hlido.eu/reviews/lacs-project-sysknife/run-349042e4bb09dfd2-lacs-project-github-io/home.png",
      "https://images.hlido.eu/reviews/lacs-project-sysknife/run-349042e4bb09dfd2-lacs-project-github-io/pageintroduction_html.png",
      "https://images.hlido.eu/reviews/lacs-project-sysknife/run-349042e4bb09dfd2-lacs-project-github-io/pagequickstart_html.png",
      "https://images.hlido.eu/reviews/lacs-project-sysknife/run-349042e4bb09dfd2-lacs-project-github-io/pagemcp_html.png"
    ]
  },
  "pricing_facts": {
    "schema": "pricing-facts/1",
    "model": [
      "open-source"
    ],
    "free_tier": true,
    "last_verified": "2026-08-18",
    "basis": "Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page.",
    "derived_at": "2026-08-21"
  }
}
