PROJECTSKILLSCONNECTING…

SYS.10 / SOURCES

Giving it code

Three ways in, one ingestion path. What is read, what is discarded before anything counts, and what is never read at all.

Reading a project4 SECTIONS

Three ways in

They differ in how the archive is obtained and in nothing after that.

GitHub App
Read-only, per-repository access you grant and can revoke. The right choice for a private repository you will analyse more than once.
Public repository URL
No app, no installation, no token — the archive is downloaded exactly as a browser would. Paste the repository link, or a deep link to a branch; the branch is picked up from the URL.
Archive upload
A ZIP of the project. Nothing has to be on a git host, which is also the path the CLI uses for a directory you are working in.

A public URL is resolved twice: once to show you which repository and which ref will actually be read, and again on the server when the ingestion starts. The preview is a convenience for the reader, never an authorisation the browser hands back.

What is read, and what is thrown away

Dependencies and history are discarded before any ceiling is counted.

  • Installed dependency trees and version-control history are discarded at ingestion. A repository zipped with node_modules is judged on its source, not on its vendor directory.
  • Binary and generated output is classified and excluded from reasoning, while still being counted in the structural map.
  • Files identified as credential material are never read. Their path and classification are recorded; their bytes are not.

The uploaded archive itself is deleted once the snapshot is built, and only on success — a retry needs it to still be there. Extracted blobs exclude secrets, but the archive is your file verbatim, so it does not outlive the ingestion that needed it.

Ceilings, and what a ceiling does to a result

Truncation is carried forward rather than hidden.

Ingestion is bounded — by archive size and by file count — so one very large repository cannot consume the worker. The exact numbers for your account are on your plan page.

Secrets

Redaction runs before the reasoning layer sees any text.

Redaction happens during the scan, in a package that has no access to any model. By the time any text could reach a provider, credential material has already been removed. This is an ordering property of the pipeline, not an instruction in a prompt.

One consequence worth knowing: because a secret file contributes no content hash, two snapshots that differ only inside a secret file produce the same content root. That is why a no-change verdict needs a complete comparison as well as a matching root — see Snapshots and change.

DOCS23 CHAPTERS