Your repository stays
under your control.
Know what stays local. Know what crosses a boundary. Know why.
Local-first, not mysteriously offline
Analyze the repository. Don't run it.
Repository intelligence is based on static evidence. Fuzit extracts normalized framework and language signals without requiring arbitrary project execution.
Secrets should not become context.
Network access should be explicit.
Ordinary local commands do not silently become network operations. Remote provider functionality is invoked exclusively through explicit provider workflows.
Explicit Workflows
- Direct GitHub URL processing (
fuzit context https://...) - PR review evidence (
fuzit review/fuzit pr) - Issue extraction (
fuzit issue) - Explicit provider targeting (
provider github)
fuzit reviewAuthentication & Offline Resilience
Surfaces & Isolation
Fuzit exposes intelligence through explicitly bounded service surfaces.
MCP Trust Surface
MCP exposes Fuzit's local context services to compatible clients. The server is strictly read-only, local, and stdio-based. It does not provide arbitrary repository execution or unrestricted filesystem tools.
Plugin Host
Fuzit runs extensions via a restricted, out-of-process plugin host. Filesystem, network, shell, and runtime access are denied by default.
Editor & Watcher
The VS Code extension consumes the same canonical local engine. It strictly respects Workspace Trust enforcement.
The local watcher operates purely for filesystem observation to maintain incremental freshness, with no hidden network behavior.
Context should have a trail.
| Evidence | Source | Decision | Reason |
|---|---|---|---|
| src/auth/session.ts | Local repo | Included | Task + symbol relationship |
| .env.local | Local repo | Excluded | Security policy |
Master Trust Ledger
A definitive breakdown of Fuzit's behavior and control boundaries.
| Concern | Fuzit Behavior | Control Boundary |
|---|---|---|
| Repository Privacy | Core intelligence runs locally. Does not require uploading the repository to a Fuzit cloud service. | Local Machine |
| Secrets | Tokens, keys, and sensitive paths are filtered before they can become context output. | Pre-output Policy |
| Network Access | Ordinary local commands do not silently contact remote endpoints. | Explicit Invocation |
| Repository Execution | Analysis is derived statically. Fuzit does not run build scripts or application code. | Static Evidence |
| MCP Server | Exposes intelligence over local stdio. Read-only by default. | Bounded Schema |
| Plugins | Extensions execute externally over a restricted interface, with capabilities denied by default. | Out-of-process |
| Telemetry | No background telemetry or analytics collection. | None |
- A Fuzit cloud account
- Repository upload
- Background telemetry
- Execution of your code
