Skip to content

Diagnose scanner capabilities

prc doctor checks whether the local host can perform the scanner operations you intend to use. It does not execute project code, containers, Codex, or Claude Code. Requested executable capabilities are resolved, identity-checked, and hashed without being launched.

Check read-only scanning

prc setup /path/to/project
# or, for the full diagnostic record:
prc doctor --target /path/to/project

Published builds discover their bundled catalog automatically. Pass --catalog-root only when deliberately testing a source checkout or another catalog build. Target inventory and catalog validation are required. State storage, candidate workspaces, an OCI runtime, and agent providers are reported as optional warnings unless their corresponding flags are supplied.

Probe state and remediation filesystems

Create the state directory with private permissions before probing it:

mkdir -m 0700 /safe/path/prc-state

prc doctor \
  --target /path/to/project \
  --state-dir /safe/path/prc-state \
  --candidate-parent /safe/path/candidates

The state probe verifies private-directory enforcement and the hard-link publication primitive used for immutable evidence records. The candidate probe creates a private temporary sibling directory, verifies that it is disjoint from the target, and tests file creation and mode enforcement. Probe directories are removed before the command returns.

Do not place --candidate-parent inside the target. An ancestor such as a shared temporary root is allowed only when the actual private probe directory is a disjoint sibling of the target.

Inspect optional executables

prc doctor \
  --target /path/to/project \
  --oci-runtime docker \
  --provider codex \
  --provider claude

The command you request must be named docker or podman for OCI, or codex or claude for a provider. Normal package-manager command links are supported: Doctor checks the requested command name, follows the link, and hashes the real versioned executable. The report records both paths when they differ. A matching filename is not treated as trust; execution planning can bind the exact digest later. Doctor does not test authentication, make network requests, pull images, or prove that a daemon is running.

After the exact Gitleaks image in the adapter guide is present, prc verify /path/to/project runs the core scan plus that one bundled adapter. It never downloads the image and fails closed if the digest is unavailable.

Automation output

prc doctor --target . --format json > doctor.json
python scripts/validate_instance.py doctor.schema.json doctor.json

JSON conforms to prc.doctor/v0.1. Each check is pass, warn, or fail and states whether it is required. The command exits 0 when all requested required capabilities pass and 2 when at least one required capability fails. Warnings never silently claim that an untested optional capability is available.