Offline, read-only audit of an exported documentation-source inventory against an independently exported permission inventory. It checks declared audience, data class, and index destinations without changing access settings. Requires Node.js 22 or newer; no package dependencies.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
node bin/knowledge-source-permission-auditor.mjs --root . --input examples/passing.json
node bin/knowledge-source-permission-auditor.mjs --root . --input examples/failing.json
npm run checkRead the result
The passing example exits 0; the restricted source in a public index exits 1. Add --human for a short stderr summary. --out report.json additionally writes the same JSON report within --root; stdout remains JSON. The output parent must already exist. Input and output names are relative to --root, and input realpaths must remain within it. An output symlink, an output-parent escape, and any path or hard link alias of the input are refused; output refusal exits 2 with empty stdout. An ordinary existing output file may be replaced atomically. No output file is written without --out.
Where this check stops
At most 1,048,576 input bytes, 1,000 sources, 1,000 permissions, 20 targets per source, 20 evidence references per permission, JSON depth 16 (root depth 0), and 5,000 ms of evaluation. Each bound accepts exactly N and returns incomplete at N+1. This tool never fetches a live documentation system, verifies a referenced approval, changes an ACL, publishes an index, or repairs an export. It evaluates only the supplied snapshot; stale or fabricated exports remain outside its proof.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.