# Project export: ClearToGo

This document was generated by HackStack to give an AI agent context about a hackathon project. Sections are labeled with their provenance; content marked as truncated was cut to keep this document small.

## Project metadata

- Hackathon: OpenAI Build Week
- Tagline: Before you erase your old iPhone, ClearToGo finds the app access and data risks your new iPhone may still be hiding.
- Devpost: https://devpost.com/software/cleartogo
- GitHub: https://github.com/wwdbsh/cleartogo
- Video: https://www.youtube.com/embed/6x57Kl-jXos?enablejsapi=1&hl=en_US&rel=0&start=&version=3&wmode=transparent
- Team: 1 GitHub contributor(s) — 이상헌 (125 commits)

## Devpost submission (written by the team)

### Inspiration

An iPhone transfer can look complete while the old phone is still the only place where a bank login, authenticator, work account, passkey, message history, or locally stored file actually works. The dangerous moment comes later, when the old iPhone is erased, sold, traded in, or returned and the missing access is discovered too late. ClearToGo is a macOS app for that final checkpoint. It helps a person compare the old and new iPhones, decide which apps matter, perform the smallest useful set of real checks on the new phone, and understand what still needs recovery. It never erases a device and never claims that erasure is safe.

### What it does

The user connects both iPhones and explicitly assigns the old and new roles. ClearToGo reads each installed-app inventory through a read-only Standard Scan that does not require Developer Mode. It uses deterministic guardrails and GPT-5.6 to narrow the source inventory to likely priorities while keeping the complete list searchable, so the user can recover anything AI missed. The user makes each importance decision before seeing the AI rationale. GPT-5.6 then converts the confirmed apps and iPhone features into a subject-bound risk ledger and a minimum set of plain-language checks: sign in, approve authentication, receive a message, open a recent photo, or verify an important local item. Private actions stay on the iPhone; ClearToGo records only the outcome and its provenance. Deterministic code—not the model—validates completeness, evidence compatibility, severity, and the final state. The only states are BLOCKED, CHECKS_COMPLETED_WITH_USER_CONFIRMATION, and CHECKS_PASSED. The product never exposes an erase action or says the old phone is safe to erase.

### How we built it

ClearToGo is a native macOS SwiftUI application. Its device bridge uses a read-only libimobiledevice inventory path, keeps physical-device handles ephemeral, and never sends device names or product types to GPT. File-backed checkpoints and audit events support recovery without persisting USB identity. GPT-5.6 runs through managed ChatGPT OAuth and a local Codex runtime. Every inference uses an ephemeral thread, strict structured output, an isolated working directory and CODEX_HOME, no executable tools, and no API-key fallback. Returned subjects and required risks must match the exact outbound session inventory. Invalid, incomplete, mutated, or uncovered output fails closed. The interface follows a provenance-first Continuity Atlas system. Live, Replay, Simulator, development-synthetic, and user-confirmed evidence remain structurally distinct. English is the production language; Korean localization is retained for development and accessibility review. How Codex was used Codex was part of the entire build, not an after-the-fact assistant. It helped turn a safety-focused product contract into Swift modules and requirement-linked tests; implement and harden the read-only device bridge; build strict GPT-5.6 and OAuth boundaries; generate adversarial validators; create the SwiftUI experience; diagnose real-device, restoration, structured-output, and timeout failures; and keep the README, acceptance evidence, and submission materials synchronized. The builder retained the consequential decisions: a Mac-first product, read-only scanning without Developer Mode, explicit old/new role selection, human judgment before AI rationale, full-inventory recovery, GPT-5.6 for semantic reasoning, deterministic code for final state, no erase control, and honest evidence provenance.

### Challenges we ran into

Real devices revealed problems that fixtures did not. Large inventories initially created too much manual review. Restored sessions could not reuse ephemeral USB handles. A valid-looking model plan failed strict subject/risk coverage. Internal schema vocabulary leaked into consumer guidance. A 90-second inference budget inherited from an earlier API assumption was too short for a larger plan. We addressed those issues with audited batching, conservative candidate recovery, explicit role re-selection and inventory matching, typed non-payload diagnostics, retry without rescanning, consumer-safe fallback guidance, and a measured 240-second per-attempt engineering budget. The historical two-iPhone run exposed two concrete product defects: an independent four-app check shared one result, and generic email/VPN names were interpreted as work access without explicit company context. The current revision deterministically splits independent multi-app checks into app-scoped checks, preserves genuinely inseparable cross-app actions, and neutralizes unsupported work-purpose inference. Automated mixed-outcome regressions pass. A separate corrected Live run completed 17 actions covering 18 risks without either defect recurring; the historical run remains a distinct BLOCKED record and is not reinterpreted.

### Accomplishments we're proud of

A historical normal-product run compared 117 apps on the old iPhone with 98 on the new iPhone and exposed the grouped-outcome and unsupported account-purpose defects. Its distinct packet remains BLOCKED and is not rewritten as post-fix evidence. A separate corrected Live run narrowed 117 source apps to 37 suggestions and 11 required apps, read 98 destination apps, generated 17 actions covering 18 risks, and reached CHECKS_COMPLETED_WITH_USER_CONFIRMATION with 18 user-confirmed results, 0 recovery results, and 0 unchecked results. The two historical defects did not recur. The default automated suite contains 420 tests: 412 pass, 0 fail, and 8 explicit opt-in tests are skipped by default. A failure-inclusive current-model benchmark retains three preregistered holdout failures and then passes a new zero-overlap 24-app KR public holdout in three frozen gpt-5.6-sol runs, each with TP 12, FP 0, FN 0, TN 12. The claim is limited to execution and repeatability on that holdout. The Release build contains no development-hybrid activation, fake identifiers, or demo provenance markers. A credential-free, Debug-only Judge Demo runs in under five minutes without an iPhone, ChatGPT login, API key, or network model call, while remaining permanently labeled as synthetic Replay evidence. More than 50 repository commits were created during the submission period, with no pre-period commit in this repository.

### What we learned

Installed does not mean working. A migration checker must distinguish inventory clues from account access, authentication, data visibility, and user confirmation. AI is useful for interpreting app meaning and minimizing the action plan, but safety improves when deterministic code owns completeness and final state. Provenance is not just an audit field; it has to be visible in the product language and interaction design.

### What's next

Future product work can extend physical VoiceOver across initial role/consent, active scan/planning retry, and Challenge outcomes; broaden the public holdout with a consented private human-labeled evaluation; and prepare signing, notarization, sandboxing, runtime packaging, and consumer distribution. None of those optional evidence or distribution modalities is an automatic current shortlist requirement. The complete physical Keyboard Navigation route, final-packet VoiceOver, and a partial completed-screen VoiceOver revisit are already proven; the corrected two-physical-iPhone Live rerun is complete with user-confirmed provenance.

## README (from the GitHub repository)

# ClearToGo

## English

ClearToGo is a macOS app for the moment after someone has set up a new iPhone but before they erase, sell, trade in, or return the old one. A successful phone transfer can still leave a banking login, authenticator, work account, passkey, or locally stored file unusable on the new phone. ClearToGo finds what deserves another look, turns those risks into concrete checks, and shows what remains unresolved.

It is a read-only checker. It never erases a device, never treats an installed app as proof that the app works, and never claims that erasure is safe.

### Current project status

The product implementation, `pre-final-product` mock-jury cycle, submission, and `final-submission` audit are complete. Two independent final-submission panels against the same icon-bearing frozen packet each recorded a 90/100 median, Stage One 5/5, shortlist `yes` 5/5, criterion medians 5/4/4/5, and zero functional failures, required gaps, deferred submission items, or contract violations. The score, quality, two-round stability, and automatic loop-exit gates all pass. This is an internal synthetic diagnostic, not an official judging prediction.

The approved 2:44 public demo is available on [YouTube](https://youtu.be/6x57Kl-jXos) with its force-aligned English caption track, and Devpost displays the project as submitted. Public signed-out access to the project and video was verified. The current product/evidence summary and document map are in [Current Project Status](docs/CURRENT_STATUS.md).

### The problem and the user

ClearToGo is for an everyday iPhone owner who does not want to remember and manually test every app before letting go of an old phone. The decisive question is simple: **“If I erase the old iPhone now, could I later lose access to something important?”**

Backup and transfer tools are good at moving large amounts of data. They do not prove that a bank recognizes the new device, an authenticator can approve a login, a work account still has access, or a local-only file actually arrived. ClearToGo focuses on that last-mile uncertainty.

### How ClearToGo works

1. The user may connect both iPhones at once. ClearToGo shows their local connection and trust status, and the user explicitly chooses the old iPhone to scan and the new iPhone to check.
2. ClearToGo reads the complete user-app inventory locally.
3. Deterministic rules and GPT-5.6 reduce the inventory to apps that deserve closer review, while keeping the full list searchable.
4. The user makes an independent decision and can recover anything the analysis missed.
5. ClearToGo compares destination evidence and asks GPT-5.6 for the smallest useful set of real checks, such as opening a bank account, approving MFA, or viewing a local file.
6. Deterministic policy—not the model—separates observed proof, user confirmation, and unresolved risk into an auditable decision packet.

### Why this is different

Apple's Quick Start, iCloud restore, App Store redownload, and trade-in guidance move or recover apps and data and prepare a device handoff. ClearToGo complements those workflows after setup: it preserves the old-iPhone inventory, finds the important last-mile checks, distinguishes installed presence from working account or data access, and keeps user-confirmed evidence separate from direct observation. The source-backed scope comparison is in [Alternatives and Differentiation](docs/ALTERNATIVES_AND_DIFFERENTIATION.md).

### What GPT-5.6 does

GPT-5.6 interprets app meaning and public metadata, proposes migration-risk categories, builds a subject-aware risk ledger, and designs minimum verification challenges. It helps answer **what might matter and what the user should test next**.

GPT-5.6 does not control either iPhone, assign the final state, upgrade weak evidence into proof, or recommend erasing a device. Strict schemas and deterministic validators preserve every subject and reject incomplete, mutated, or executable output.

### How Codex accelerated the build

Codex was used throughout the project—not only for initial scaffolding. It helped turn the product contract into traceable Swift modules, implement and harden the read-only C/Swift device bridge, build typed GPT-5.6 and OAuth protocol boundaries, generate adversarial contract and persistence tests, create the Continuity Atlas UI, diagnose live-device and timeout failures, and keep implementation evidence synchronized with the requirements.

Every commit in this repository was created after the hackathon Submission Period began. The work progressed from the product baseline to a runnable Mac app, physical iPhone acceptance, OAuth lifecycle acceptance, accessibility inspection, and a development-only end-to-end hybrid rehearsal.

### Inspectable mock-jury process

The repository includes the project-scoped [`build-week-mock-jury`](.agents/skills/build-week-mock-jury/SKILL.md) Codex skill used to stress-test the submission before human review. It maps the official viability gate and four equal-weight criteria, generates an allowlisted blind submission packet, applies five independent public-evidence research lenses, validates structured reports, and deterministically surfaces panel disagreement and improvement priority. Its committed finding taxonomy preserves the original report keys while normalizing explicitly reviewed aliases, with a regression test for consensus recovery. These lenses do not impersonate the published judges or predict their votes; the source notes, evidence boundaries, schemas, scripts, and checks are committed so the process can be audited and reproduced. The dependency-free [score dashboard](docs/mock-jury/dashboard/README.md) links every immutable round audit and charts both panel and individual-lens trends. Final-submission [Round 014](docs/mock-jury/round-014/README.md) and stability [Round 015](docs/mock-jury/round-015/README.md) independently reviewed the same submitted, icon-bearing frozen packet. Both record a 90/100 median, Stage One 5/5, shortlist `yes` 5/5, criterion medians 5/4/4/5 with zero range, and zero functional failures, required gaps, deferred submission items, or contract violations. The score, quality, stability, and automatic loop-exit gates pass with zero score movement and no new critical failure. Consumer notarization and clean-Mac acceptance, independent-user outcomes, and complete physical VoiceOver remain low-severity post-submission evidence opportunities rather than blockers.

### Reproducible value evidence

The [Deterministic Impact Benchmark](docs/DETERMINISTIC_IMPACT_BENCHMARK.md) makes three narrow product-value claims inspectable. On one complete privacy-preserving frozen derivative, ClearToGo reduced required relevance decisions from 139 to 33—76.3% fewer—while retaining all 30 labeled material apps and the complete searchable inventory. Eight synthetic policy stress cases verify subject-aware checks and fail-closed evidence behavior. On one matched privacy-safe synthetic case, a generous combination of three official Apple transfer, restore-troubleshooting, and handoff documents directly covered 3 of 9 readiness risks; ClearToGo's production ledger and deterministic policy covered all 9 with 8 risk-bound challenges, kept all 9 unresolved risks explicit, returned `BLOCKED`, and reported zero contract violations. This is a scope-and-policy comparison, not an independent-user outcome, competitor product execution, elapsed-time saving, or current-model/population claim.

The [Public Current-Model Candidate Benchmark](docs/PUBLIC_CURRENT_MODEL_CANDIDATE_BENCHMARK.md) preserves the full preregistered learning chain instead of showing only the successful run. Holdout v1 failed before its third model call because of a runner path defect; v2 failed at 75% recall in all three runs; and v3 failed both recall and recall-range thresholds. After those sets became development evidence and the production routing defects were corrected, a new zero-overlap 24-app KR-storefront

[README truncated for size]

## Detected evidence (automated analysis)

Indexed codebase: 198 recognized source files, 3279 KB.
- C (language) — detected in the code
- HTML (language) — detected in the code
- JavaScript (language) — detected in the code
- Python (language) — detected in the code
- Swift (language) — detected in the code
- OpenAI (technology) — claimed on Devpost, not found in the code
- AI coding agent: Codex — evidence: config files committed to the repository

## Codebase structure (from repository index)

### Files (120 of 272)

```
.agents/skills/build-week-mock-jury/agents/openai.yaml
.agents/skills/build-week-mock-jury/assets/cleartogo-packet-manifest.json
.agents/skills/build-week-mock-jury/assets/judge-report.schema.json
.agents/skills/build-week-mock-jury/assets/quality-evidence.schema.json
.agents/skills/build-week-mock-jury/references/blind-packet-contract.md
.agents/skills/build-week-mock-jury/references/finding-taxonomy.json
.agents/skills/build-week-mock-jury/references/judge-kath-korevec.md
.agents/skills/build-week-mock-jury/references/judge-leah-belsky.md
.agents/skills/build-week-mock-jury/references/judge-peter-steinberger.md
.agents/skills/build-week-mock-jury/references/judge-tara-seshan.md
.agents/skills/build-week-mock-jury/references/judge-thibault-sottiaux.md
.agents/skills/build-week-mock-jury/references/official-rubric.md
.agents/skills/build-week-mock-jury/references/research-method.md
.agents/skills/build-week-mock-jury/references/scoring-and-prioritization.md
.agents/skills/build-week-mock-jury/scripts/aggregate_scores.py
.agents/skills/build-week-mock-jury/scripts/build_blind_packet.py
.agents/skills/build-week-mock-jury/scripts/self_test.py
.agents/skills/build-week-mock-jury/SKILL.md
.github/workflows/ci.yml
.gitignore
AGENTS.md
CLEAR_TO_GO_PRODUCT_CONTRACT_V1.md
ClearToGo.xcodeproj/project.pbxproj
ClearToGo.xcodeproj/project.xcworkspace/contents.xcworkspacedata
ClearToGo.xcodeproj/xcshareddata/xcschemes/ClearToGo.xcscheme
ClearToGo.xcodeproj/xcshareddata/xcschemes/ClearToGoAccessibilityAcceptance.xcscheme
ClearToGo.xcodeproj/xcshareddata/xcschemes/ClearToGoDevelopmentHybridAcceptance.xcscheme
ClearToGo.xcodeproj/xcshareddata/xcschemes/ClearToGoLiveCandidateEvaluation.xcscheme
ClearToGo.xcodeproj/xcshareddata/xcschemes/ClearToGoLiveDeviceAcceptance.xcscheme
ClearToGo.xcodeproj/xcshareddata/xcschemes/ClearToGoPhysicalConnectionAcceptance.xcscheme
ClearToGo.xcodeproj/xcshareddata/xcschemes/ClearToGoTwoDeviceAcceptance.xcscheme
ClearToGo/App/AppDependencies.swift
ClearToGo/App/ClearToGoApp.swift
ClearToGo/App/CodexSubscriptionAccountView.swift
ClearToGo/App/DevelopmentHybridAcceptanceDeviceScanner.swift
ClearToGo/App/P0WorkflowCoordinator.swift
ClearToGo/App/ReplayPrecursorSummaryBuilder.swift
ClearToGo/App/RootView.swift
ClearToGo/Core/Audit/AuditEvent.swift
ClearToGo/Core/Candidate/CandidateEngine.swift
ClearToGo/Core/Candidate/CandidateEvaluationHarness.swift
ClearToGo/Core/Candidate/CandidateModels.swift
ClearToGo/Core/Candidate/CandidateReviewLedger.swift
ClearToGo/Core/Candidate/SubjectPseudonymizer.swift
ClearToGo/Core/Domain/DecisionState.swift
ClearToGo/Core/Domain/Evidence.swift
ClearToGo/Core/Domain/Identifiers.swift
ClearToGo/Core/Domain/MigrationSession.swift
ClearToGo/Core/Domain/RiskPolicyModels.swift
ClearToGo/Core/OpenAI/JSONValue.swift
ClearToGo/Core/OpenAI/OpenAIAuditMetadata.swift
ClearToGo/Core/OpenAI/OpenAIOutboundPrivacyValidator.swift
ClearToGo/Core/OpenAI/OpenAIResponseValidator.swift
ClearToGo/Core/OpenAI/OpenAISchemaCatalog.swift
ClearToGo/Core/OpenAI/OpenAITypedOutputs.swift
ClearToGo/Core/OpenAI/ResponsesAPIRequest.swift
ClearToGo/Core/Persistence/AuditCheckpointValidation.swift
ClearToGo/Core/Persistence/SessionCheckpoint.swift
ClearToGo/Core/Policy/DeterministicPolicyEngine.swift
ClearToGo/Core/Ports/AppMetadataProviding.swift
ClearToGo/Core/Ports/DeviceScanning.swift
ClearToGo/Core/Ports/OpenAIResponding.swift
ClearToGo/Core/Ports/ScreenCaptureProviding.swift
ClearToGo/Core/Ports/SessionPersisting.swift
ClearToGo/Core/Replay/P0RuntimeReplayFixture.swift
ClearToGo/Core/Replay/ReplayIsolation.swift
ClearToGo/Core/Replay/ReplayPrecursorSummary.swift
ClearToGo/Core/Vocabulary/ProductVocabulary.swift
ClearToGo/Core/Workflow/P0WorkflowPipeline.swift
ClearToGo/Features/CandidateReview/CandidateReviewPresentationMapper.swift
ClearToGo/Features/CandidateReview/CandidateReviewScaffoldView.swift
ClearToGo/Features/CandidateReview/CandidateReviewState.swift
ClearToGo/Features/Challenges/ChallengeEvidencePresentation.swift
ClearToGo/Features/Challenges/ChallengesScaffoldView.swift
ClearToGo/Features/DecisionPacket/DecisionPacketPresentation.swift
ClearToGo/Features/DecisionPacket/DecisionPacketScaffoldView.swift
ClearToGo/Features/DecisionPacket/EvidenceSealView.swift
ClearToGo/Features/DesignSystem/AtlasTokens.swift
ClearToGo/Features/DesignSystem/ContinuityAtlasLayout.swift
ClearToGo/Features/DesignSystem/UserFacingRiskPresentation.swift
ClearToGo/Features/Destination/DestinationScaffoldView.swift
ClearToGo/Features/DeviceScan/ConnectedDeviceRolePicker.swift
ClearToGo/Features/DeviceScan/SourceScanScaffoldView.swift
ClearToGo/Features/MissionShell/MissionShellView.swift
ClearToGo/Features/MissionShell/MissionStage.swift
ClearToGo/Features/Replay/ReplayPrecursorSummaryPanel.swift
ClearToGo/Features/Shared/StageScaffoldView.swift
ClearToGo/Integrations/Device/LiveDeviceScanner.swift
ClearToGo/Integrations/DeviceBridge/CTGReadOnlyDeviceBridge.c
ClearToGo/Integrations/DeviceBridge/Include/CTGReadOnlyDeviceBridge.h
ClearToGo/Integrations/DeviceBridge/Include/module.modulemap
ClearToGo/Integrations/Fakes/FakeAppMetadataProvider.swift
ClearToGo/Integrations/Fakes/FakeDeviceScanner.swift
ClearToGo/Integrations/Fakes/FakeOpenAIResponsesClient.swift
ClearToGo/Integrations/Fakes/FakeScreenCaptureProvider.swift
ClearToGo/Integrations/Fakes/InMemorySessionStore.swift
ClearToGo/Integrations/Metadata/ApplePublicAppMetadataProvider.swift
ClearToGo/Integrations/OpenAI/BoundedOpenAIHTTPTransport.swift
ClearToGo/Integrations/OpenAI/CodexManagedRuntime.swift
ClearToGo/Integrations/OpenAI/CodexSubscriptionAccountController.swift
ClearToGo/Integrations/OpenAI/CodexSubscriptionProvider.swift
ClearToGo/Integrations/OpenAI/OpenAIResponsesAdapter.swift
ClearToGo/Integrations/OpenAI/OpenAITypedResponsesClient.swift
ClearToGo/Integrations/Persistence/FileSessionStore.swift
ClearToGo/Resources/Assets.xcassets/AppIcon.appiconset/Contents.json
ClearToGo/Resources/Assets.xcassets/Contents.json
ClearToGo/Resources/Localizable.xcstrings
ClearToGo/Tests/AccessibilityUITests/DownstreamAccessibilityAcceptanceTests.swift
ClearToGo/Tests/AppTests/DevelopmentHybridAcceptanceTests.swift
ClearToGo/Tests/AppTests/OAuthAccountPresentationTests.swift
ClearToGo/Tests/AppTests/OpenAIAuditFailureAppTests.swift
ClearToGo/Tests/AppTests/P0AtomicTransitionRestartTests.swift
ClearToGo/Tests/AppTests/P0DeleteDuringFlightTests.swift
ClearToGo/Tests/AppTests/P0ExplicitReplanTests.swift
ClearToGo/Tests/AppTests/P0InitialLiveAtomicRecoveryTests.swift
ClearToGo/Tests/AppTests/P0ReplayPrecursorIntegrationTests.swift
ClearToGo/Tests/AppTests/P0WorkflowCoordinatorTests.swift
ClearToGo/Tests/AppTests/P0WorkflowTaskRegistryTests.swift
ClearToGo/Tests/AppTests/WindowStateIdentityTests.swift
ClearToGo/Tests/ContractTests/CandidateReviewFeatureTests.swift
[152 more files omitted for size]
```

### Dependencies

No dependency index available.

### Recent commits (newest first)

- docs: publish final submission jury audit
- feat: add ClearToGo macOS app icon
- test: freeze submitted jury media
- docs: record submitted Devpost state
- docs: record final submission readiness
- docs: finalize submission readiness evidence
- docs: sync final submission status
- feat: add managed Codex runtime onboarding
- docs: close mock jury loop after taste approval
- docs: record stable 90-point mock jury panels
- docs: remove unofficial model evidence gate
- docs: publish preregistered candidate holdout chain
- test: preregister KR candidate holdout
- fix: preserve routes across storefront lookup gaps
- fix: preserve inconclusive metadata routes for review
- fix: require full public metadata consideration
- test: preregister third candidate holdout
- fix: honor explicit workplace collaboration metadata
- fix: align workplace metadata routing contract
- fix: route ambiguous critical apps through metadata

## Key source files (fetched from GitHub, selected and truncated for size)

### THIRD_PARTY_NOTICES.md

```markdown
# Third-Party Dependencies and Distribution Notice / 제3자 의존성 및 배포 고지

Audit date: 2026-07-20

## English Original

### Distribution boundary

The hackathon judge path builds ClearToGo from source. This repository and the current app bundle do not redistribute Homebrew libraries. At runtime, the locally built app resolves `libimobiledevice` and `libplist` from the build machine's Homebrew installation under `/opt/homebrew`. The current artifact is therefore not a self-contained consumer distribution.

If ClearToGo later embeds, copies, statically links, packages, or redistributes any third-party library, its license obligations and notices must be reviewed again before release. Signing, notarization, App Sandbox support, and a self-contained runtime package remain separate release work.

`Scripts/stage-relocatable-app.sh` may create an unpublished local engineering copy to test Mach-O relocatability. Those temporary binaries are not committed or distributed, and this experiment does not authorize redistribution or replace the release-specific license review above.

### Direct build and runtime dependencies

| Dependency | Audit baseline | License | Current use and distribution mode |
|---|---:|---|---|
| [XcodeGen](https://github.com/yonaskolb/XcodeGen) | 2.46.0 | MIT | Build-time project generator installed by Homebrew; not linked or bundled. |
| [ripgrep](https://github.com/BurntSushi/ripgrep) | 15.2.0 | Unlicense | Build/test-time contract scanner installed by Homebrew; not linked or bundled. |
| [OpenAI Codex](https://github.com/openai/codex) | 0.144.6 | Apache-2.0 | Optional on-demand runtime downloaded directly from the pinned official OpenAI GitHub Release after explicit user action; SHA-256 and OpenAI Developer ID are verified; it is not committed to or bundled with this repository/app. |
| [libimobiledevice](https://github.com/libimobiledevice/libimobiledevice) | 1.4.0 | LGPL-2.1-or-later | Dynamically linked read-only device bridge dependency supplied by the local Homebrew installation; not bundled. |
| [libplist](https://github.com/libimobiledevice/libplist) | 2.7.0 | LGPL-2.1-or-later | Dynamically linked property-list dependency supplied by the local Homebrew installation; not bundled. |

The CI workflow checks these reference versions after installation and fails closed when the direct dependency versions drift. Homebrew formula resolution is still external build infrastructure rather than a reproducible consumer package.

### Homebrew-resolved transitive dependencies

The audited Homebrew dependency graph also includes the following formulae. ClearToGo does not copy or bundle them in this repository.

| Dependency | License reported by Homebrew |
|---|---|
| `libimobiledevice-glue` | LGPL-2.1-or-later |
| `libusbmuxd` | GPL-2.0-or-later AND LGPL-2.1-or-later |
| `libtasn1` | LGPL-2.1-or-later |
| `libtatsu` | LGPL-2.1-or-later |
| `openssl@3` | Apache-2.0 |
| `ca-certificates` | MPL-2.0 |

The upstream project pages and license file
[truncated — 2413 more characters]
```

### AGENTS.md

```markdown
# AGENTS.md

## English

### Communication

- Always address the user as `상헌 님`.

### Documentation

- Every human-readable document newly created or substantively revised from now on must include both the English original and a Korean translation.
- Place the English version first, followed by a Korean translation with equivalent meaning.
- Where practical, write titles and major section headings in both languages so that the correspondence is clear, with English before Korean.
- Apply this rule to READMEs, plans, specifications, guides, handoff documents, hackathon submission copy, and other human-readable deliverables.
- Source code, configuration files, generated files, and externally sourced documents are exempt unless explicitly requested otherwise.

### Codex Session Evidence

- Whenever `handoff.md` is created or updated, update the gitignored local file `CODEX_SESSION_LOG.local.md` in the same task.
- Each session entry must record the date, task/thread ID when observable, `/feedback` ID, work scope, related requirement IDs, changed files, key commits, verification performed, and remaining work.
- `/feedback` is an interactive UI command. The agent must not claim to run it or invent its returned ID. If the ID has not been supplied, record `PENDING_USER_FEEDBACK_ID` and explicitly ask the user to run `/feedback` in the current task and provide the returned value.
- Never copy `/feedback` IDs or task/thread IDs into public documents, Git commits, or command output. Store them only in `CODEX_SESSION_LOG.local.md`.
- Before `/clear`, `/new`, a new conversation, or a major milestone transition, bring the current session entry and `handoff.md` up to date. Within one milestone, prefer `/compact` when only context reduction is needed.
- After repeated compaction, reread `handoff.md` and the authoritative documents and verify that active requirement IDs, decisions, and incomplete work were not lost during summarization.

### ClearToGo Implementation Baseline

Before starting any ClearToGo implementation, modification, or review, read these documents in order:

1. `CLEAR_TO_GO_PRODUCT_CONTRACT_V1.md`
2. `PRD.md`
3. `FRD.md`
4. `SRS.md`
5. `UI_UX_DESIGN_SPEC_V1.md`

Earlier documents take precedence. Existing spike and benchmark code is validation evidence and reference implementation; the new documents govern when they conflict.

The following decisions are frozen and must not change without Sangheon's explicit approval and new validation evidence:

- Mac-app product
- Read-only Standard Scan without requiring Developer Mode
- No `cfgutil`, device erase, or destructive commands
- User confirmation and full-inventory recovery after candidate discovery
- GPT-5.6 owns classification, risk reasoning, minimum challenges, and optional evidence interpretation
- Deterministic code owns severity and final state
- States are `BLOCKED`, `CHECKS_COMPLETED_WITH_USER_CONFIRMATION`, and `CHECKS_PASSED`
- `READY`, `READY_TO_ERASE`, `SAFE_TO_ERASE`, and `can_erase
[truncated — 2533 more characters]
```

### project.yml

```yaml
name: ClearToGo

options:
  minimumXcodeGenVersion: 2.45.0
  createIntermediateGroups: true
  deploymentTarget:
    macOS: "15.0"

configs:
  Debug: debug
  Release: release

configFiles:
  Debug: Config/Debug.xcconfig
  Release: Config/Release.xcconfig

targets:
  ClearToGoDeviceBridge:
    type: library.static
    platform: macOS
    sources:
      - path: ClearToGo/Integrations/DeviceBridge/CTGReadOnlyDeviceBridge.c
    headers:
      - path: ClearToGo/Integrations/DeviceBridge/Include
        visibility: public
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.device-bridge
        PRODUCT_MODULE_NAME: ClearToGoDeviceBridge
        DEFINES_MODULE: YES
        MODULEMAP_FILE: $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include/module.modulemap
        HEADER_SEARCH_PATHS:
          - $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include
        SYSTEM_HEADER_SEARCH_PATHS:
          - $(CTG_HOMEBREW_PREFIX)/opt/libimobiledevice/include
          - $(CTG_HOMEBREW_PREFIX)/opt/libplist/include
        CLANG_WARN_DOCUMENTATION_COMMENTS: YES
        GCC_C_LANGUAGE_STANDARD: c11
        WARNING_CFLAGS:
          - -Wall
          - -Wextra
          - -Werror

  ClearToGoCore:
    type: framework
    platform: macOS
    sources:
      - path: ClearToGo/Core
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.core
        GENERATE_INFOPLIST_FILE: YES

  ClearToGoIntegrations:
    type: framework
    platform: macOS
    sources:
      - path: ClearToGo/Integrations
        excludes:
          - DeviceBridge
    dependencies:
      - target: ClearToGoCore
      - target: ClearToGoDeviceBridge
        link: true
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.integrations
        GENERATE_INFOPLIST_FILE: YES
        SWIFT_INCLUDE_PATHS:
          - $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include
        LIBRARY_SEARCH_PATHS:
          - $(CTG_HOMEBREW_PREFIX)/opt/libimobiledevice/lib
          - $(CTG_HOMEBREW_PREFIX)/opt/libplist/lib
        OTHER_LDFLAGS:
          - -limobiledevice-1.0
          - -lplist-2.0

  ClearToGoFeatures:
    type: framework
    platform: macOS
    sources:
      - path: ClearToGo/Features
    dependencies:
      - target: ClearToGoCore
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.features
        GENERATE_INFOPLIST_FILE: YES

  ClearToGo:
    type: application
    platform: macOS
    sources:
      - path: ClearToGo/App
      - path: ClearToGo/Resources
        buildPhase: resources
    dependencies:
      - target: ClearToGoCore
      - target: ClearToGoIntegrations
      - target: ClearToGoFeatures
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.app
        PRODUCT_NAME: ClearToGo
        GENERATE_INFOPLIST_FILE: YES
        SWIFT_INCLUDE_PATHS:
          - $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include
        INFOPLIST_KEY_CFBundleDisplayName: ClearToGo
        INFOPLIST_KEY_LSApplicationCategoryType: public.app-category.utilities
        INFOPLIST_KEY_NSHumanReadableCopyright: "Copyright © 2026 ClearToGo"

  ClearToGoCoreTests:
    type: bundle.unit-test
    platform: macOS
    sources:
      - path: ClearToGo/Tests/CoreTests
    dependencies:
      - target: ClearToGoCore
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.core-tests
        GENERATE_INFOPLIST_FILE: YES

  ClearToGoIntegrationsTests:
    type: bundle.unit-test
    platform: macOS
    sources:
      - path: ClearToGo/Tests/IntegrationsTests
      - path: ClearToGo/Tests/DeviceBridgeTests
        excludes:
          - DeviceBridgeSanitizerHarness.c
    dependencies:
      - target: ClearToGoCore
      - target: ClearToGoIntegrations
      - target: ClearToGoDeviceBridge
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.integrations-tests
        GENERATE_INFOPLIST_FILE: YES
        SWIFT_INCLUDE_PATHS:
          - $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include

  ClearToGoContractTests:
    type: bundle.unit-test
    platform: macOS
    sources:
      - path: ClearToGo/Tests/ContractTests
    dependencies:
      - target: ClearToGoCore
      - target: ClearToGoIntegrations
      - target: ClearToGoFeatures
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.contract-tests
        GENERATE_INFOPLIST_FILE: YES
        SWIFT_INCLUDE_PATHS:
          - $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include

  ClearToGoAppTests:
    type: bundle.unit-test
    platform: macOS
    sources:
      - path: ClearToGo/Tests/AppTests
    dependencies:
      - target: ClearToGo
      - target: ClearToGoCore
      - target: ClearToGoIntegrations
      - target: ClearToGoFeatures
      - target: ClearToGoDeviceBridge
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.app-tests
        GENERATE_INFOPLIST_FILE: YES
        SWIFT_INCLUDE_PATHS:
          - $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include

  ClearToGoLiveCandidateEvaluationTests:
    type: bundle.unit-test
    platform: macOS
    sources:
      - path: ClearToGo/Tests/LiveCandidateEvaluationTests
    dependencies:
      - target: ClearToGoCore
      - target: ClearToGoIntegrations
      - target: ClearToGoDeviceBridge
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.live-candidate-evaluation-tests
        GENERATE_INFOPLIST_FILE: YES
        SWIFT_INCLUDE_PATHS:
          - $(PROJECT_DIR)/ClearToGo/Integrations/DeviceBridge/Include

  ClearToGoAccessibilityUITests:
    type: bundle.ui-testing
    platform: macOS
    sources:
      - path: ClearToGo/Tests/AccessibilityUITests
    dependencies:
      - target: ClearToGo
    settings:
      base:
        PRODUCT_BUNDLE_IDENTIFIER: com.cleartogo.accessibility-ui-tests
        GENERATE_INFOPLIST_FILE: YES
        TEST_TARGET_NAME: ClearToGo

schemes:
  ClearToGo:
    build:
      targets:
      
[truncated — 2708 more characters]
```

### Scripts/verify-impact-benchmark.sh

```shell
#!/bin/bash
set -euo pipefail

REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
cd "$REPO_ROOT"

xcodegen generate
xcodebuild test \
  -project ClearToGo.xcodeproj \
  -scheme ClearToGo \
  -destination 'platform=macOS,arch=arm64' \
  -only-testing:ClearToGoCoreTests/ImpactBenchmarkTests

shasum -a 256 docs/evidence/impact-benchmark-v1.json
shasum -a 256 docs/evidence/matched-checklist-benchmark-v1.json

```

### Scripts/verify-device-bridge-sanitizers.sh

```shell
#!/bin/bash

set -euo pipefail

repository_root="$(cd "$(dirname "$0")/.." && pwd)"
temporary_directory="$(mktemp -d)"
trap 'rm -rf "$temporary_directory"' EXIT

homebrew_prefix="${CTG_HOMEBREW_PREFIX:-/opt/homebrew}"

clang \
  -std=c11 \
  -Wall \
  -Wextra \
  -Werror \
  -DDEBUG=1 \
  -fsanitize=address,undefined \
  -fno-omit-frame-pointer \
  -I "$repository_root/ClearToGo/Integrations/DeviceBridge/Include" \
  -isystem "$homebrew_prefix/opt/libimobiledevice/include" \
  -isystem "$homebrew_prefix/opt/libplist/include" \
  "$repository_root/ClearToGo/Integrations/DeviceBridge/CTGReadOnlyDeviceBridge.c" \
  "$repository_root/ClearToGo/Tests/DeviceBridgeTests/DeviceBridgeSanitizerHarness.c" \
  -L "$homebrew_prefix/opt/libimobiledevice/lib" \
  -L "$homebrew_prefix/opt/libplist/lib" \
  -limobiledevice-1.0 \
  -lplist-2.0 \
  -o "$temporary_directory/device-bridge-sanitizer-harness"

"$temporary_directory/device-bridge-sanitizer-harness"
echo "Device Bridge sanitizer harness passed."

```

### Scripts/verify-app-icon.sh

```shell
#!/bin/bash

set -euo pipefail

ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
ICON_SET="$ROOT_DIR/ClearToGo/Resources/Assets.xcassets/AppIcon.appiconset"
CONTENTS="$ICON_SET/Contents.json"
PROJECT_FILE="$ROOT_DIR/ClearToGo.xcodeproj/project.pbxproj"

# Packaging evidence for CTG-UX-001 §§2, 4, and 10. The icon must retain the
# Continuity Atlas visual grammar without adding a PRD-011 safety/erase claim.
jq empty "$CONTENTS"

expected_icons=(
  "AppIcon-16.png:16"
  "AppIcon-16@2x.png:32"
  "AppIcon-32.png:32"
  "AppIcon-32@2x.png:64"
  "AppIcon-128.png:128"
  "AppIcon-128@2x.png:256"
  "AppIcon-256.png:256"
  "AppIcon-256@2x.png:512"
  "AppIcon-512.png:512"
  "AppIcon-512@2x.png:1024"
)

for specification in "${expected_icons[@]}"; do
  filename="${specification%%:*}"
  expected_size="${specification##*:}"
  icon_path="$ICON_SET/$filename"

  test -f "$icon_path"
  rg -Fq "\"filename\" : \"$filename\"" "$CONTENTS"

  actual_width="$(sips -g pixelWidth "$icon_path" | awk '/pixelWidth/ { print $2 }')"
  actual_height="$(sips -g pixelHeight "$icon_path" | awk '/pixelHeight/ { print $2 }')"
  test "$actual_width" = "$expected_size"
  test "$actual_height" = "$expected_size"
done

rg -Fq "Assets.xcassets in Resources" "$PROJECT_FILE"
rg -Fq "ASSETCATALOG_COMPILER_APPICON_NAME = AppIcon;" "$PROJECT_FILE"

if [[ $# -gt 0 ]]; then
  app_bundle="$1"
  test -f "$app_bundle/Contents/Resources/AppIcon.icns"
  test -f "$app_bundle/Contents/Resources/Assets.car"
  test "$(plutil -extract CFBundleIconFile raw "$app_bundle/Contents/Info.plist")" = "AppIcon"
fi

echo "App icon verification passed (${#expected_icons[@]} slots)."

```

### Scripts/stage-relocatable-app.sh

```shell
#!/bin/bash

set -euo pipefail

usage() {
  echo "Usage: $0 <source ClearToGo.app> <new staged ClearToGo.app>"
}

if [[ $# -ne 2 ]]; then
  usage
  exit 64
fi

source_app=$1
staged_app=$2

if [[ ! -d "$source_app" || ! -x "$source_app/Contents/MacOS/ClearToGo" ]]; then
  echo "Source app is missing or invalid: $source_app" >&2
  exit 2
fi
if [[ -e "$staged_app" ]]; then
  echo "Refusing to overwrite existing output: $staged_app" >&2
  exit 2
fi
case "$staged_app" in
  /|"$HOME"|"$HOME"/)
    echo "Refusing unsafe output path: $staged_app" >&2
    exit 2
    ;;
esac

for tool in codesign ditto file install_name_tool otool realpath; do
  if ! command -v "$tool" >/dev/null 2>&1; then
    echo "Required tool is unavailable: $tool" >&2
    exit 2
  fi
done

ditto "$source_app" "$staged_app"
frameworks_dir="$staged_app/Contents/Frameworks"
mkdir -p "$frameworks_dir"

binaries=("$staged_app/Contents/MacOS/ClearToGo")
while IFS= read -r -d '' candidate; do
  if file "$candidate" | grep -q 'Mach-O'; then
    binaries+=("$candidate")
  fi
done < <(find "$frameworks_dir" -type f -print0)

copied_count=0
index=0
while (( index < ${#binaries[@]} )); do
  owner=${binaries[$index]}
  index=$((index + 1))
  chmod u+w "$owner"

  while IFS= read -r dependency; do
    [[ "$dependency" == /opt/homebrew/* ]] || continue
    if [[ ! -f "$dependency" ]]; then
      echo "Homebrew dependency is missing: $dependency" >&2
      exit 2
    fi

    dependency_name=$(basename "$dependency")
    staged_dependency="$frameworks_dir/$dependency_name"
    if [[ ! -e "$staged_dependency" ]]; then
      resolved_dependency=$(realpath "$dependency")
      ditto "$resolved_dependency" "$staged_dependency"
      chmod u+w "$staged_dependency"
      install_name_tool -id "@rpath/$dependency_name" "$staged_dependency"
      binaries+=("$staged_dependency")
      copied_count=$((copied_count + 1))
    fi
    install_name_tool -change "$dependency" "@rpath/$dependency_name" "$owner"
  done < <(otool -L "$owner" | tail -n +2 | awk '{print $1}')
done

unresolved=0
for binary in "${binaries[@]}"; do
  if otool -L "$binary" | tail -n +2 | awk '{print $1}' | grep -q '^/opt/homebrew/'; then
    echo "Unresolved Homebrew dependency in $binary" >&2
    unresolved=1
  fi
done
if [[ $unresolved -ne 0 ]]; then
  exit 2
fi

while IFS= read -r -d '' dylib; do
  codesign --force --sign - "$dylib"
done < <(find "$frameworks_dir" -maxdepth 1 -type f -name '*.dylib' -print0)
while IFS= read -r -d '' framework; do
  codesign --force --sign - "$framework"
done < <(find "$frameworks_dir" -maxdepth 1 -type d -name '*.framework' -print0)
codesign --force --sign - "$staged_app"
codesign --verify --deep --strict --verbose=2 "$staged_app"

echo "Staged local technical candidate: $staged_app"
echo "Copied Homebrew runtime libraries: $copied_count"
echo "All staged Mach-O references are free of /opt/homebrew paths."
echo "Signature is ad-hoc local execution only; Hardened Runtime and release signing remain unproven."

```

### Scripts/verify-document-language-order.sh

```shell
#!/bin/bash

set -euo pipefail

repository_root="$(cd "$(dirname "$0")/.." && pwd)"
cd "$repository_root"

ruby <<'RUBY'
checks = {
  "AGENTS.md" => ["## English", "## 한국어"],
  "CLEAR_TO_GO_PRODUCT_CONTRACT_V1.md" => [
    "# ClearToGo Core Product and GPT-5.6 Role Contract V1",
    "# ClearToGo 핵심 제품 및 GPT-5.6 역할 계약 V1"
  ],
  "PRD.md" => [
    "# ClearToGo Product Requirements Document (PRD) V1.0",
    "# ClearToGo 제품 요구사항 문서(PRD) V1.0"
  ],
  "FRD.md" => [
    "# ClearToGo Functional Requirements Document (FRD) V1.0",
    "# ClearToGo 기능 요구사항 문서(FRD) V1.0"
  ],
  "SRS.md" => [
    "# ClearToGo Software Requirements Specification (SRS) V1.0",
    "# ClearToGo 소프트웨어 요구사항 명세(SRS) V1.0"
  ],
  "UI_UX_DESIGN_SPEC_V1.md" => ["## English Original", "## 한국어 번역"],
  "README.md" => ["## English", "## 한국어"],
  "docs/CURRENT_STATUS.md" => ["## English Original", "## 한국어 번역"]
}

checks.each do |path, (english_marker, korean_marker)|
  content = File.read(path)
  english_index = content.index(english_marker)
  korean_index = content.index(korean_marker)

  if english_index.nil? || korean_index.nil? || english_index >= korean_index
    abort "Document language-order violation: #{path} must place English before Korean."
  end
end

agents = File.read("AGENTS.md")
unless agents.include?("Place the English version first") && agents.include?("문서는 영어를 먼저 작성하고")
  abort "Documentation-rule violation: AGENTS.md must require English-first bilingual documents."
end

handoff = File.read("handoff.md")
required_handoff_headings = [
  "## CURRENT STATE",
  "## DONE",
  "## IN PROGRESS",
  "## TODO",
  "## IMPORTANT DECISIONS",
  "## ISSUES / RISKS",
  "## LOG SUMMARY"
]

unless handoff.start_with?("# PROJECT HANDOFF\n")
  abort "Handoff structure violation: handoff.md must start with # PROJECT HANDOFF."
end

actual_handoff_headings = handoff.scan(/^## .+$/)
unless actual_handoff_headings == required_handoff_headings
  abort "Handoff structure violation: handoff.md must contain only the required ordered sections."
end

paired_sections = handoff.split(/(?=^## )/).select do |section|
  section.include?("### English") || section.include?("### 한국어")
end

if paired_sections.empty?
  abort "Document language-order violation: handoff.md has no bilingual section pairs."
end

paired_sections.each do |section|
  english_index = section.index("### English")
  korean_index = section.index("### 한국어")
  unless english_index && korean_index && english_index < korean_index
    abort "Document language-order violation: every bilingual handoff section must place English first."
  end
end

todo_section = handoff[/^## TODO\n(.*?)(?=^## IMPORTANT DECISIONS)/m, 1]
abort "Handoff structure violation: TODO section is missing." unless todo_section

english_todo, korean_todo = todo_section.split(/^### 한국어\n/m, 2)
abort "Handoff structure violation: TODO translations are incomplete." unless korean_todo

english_count = english_todo.scan(/^\d+\. /).length
korean_count = korean_todo.scan(/^\d+\. /).length
if english_count.zero? || english_count > 10 || english_count != korean_count
  abort "Handoff TODO violation: keep 1-10 equivalent executable tasks in each language."
end
RUBY

echo "English-first bilingual document order verified."

```

### Scripts/run-public-current-model-candidate-benchmark.sh

```shell
#!/bin/zsh

set -euo pipefail

script_directory="${0:A:h}"
repository_root="${script_directory:h}"
default_benchmark_input="${repository_root}/docs/evidence/public-current-model-candidate-benchmark-v1-input.json"
benchmark_input="${CLEARTOGO_CANDIDATE_EVALUATION_INPUT:-${default_benchmark_input}}"
benchmark_derived_data="${repository_root}/.derived-data/PublicCurrentModelCandidateBenchmark"
local_output_directory="${repository_root}/CandidateEvaluation.local"
default_local_output="${local_output_directory}/public-current-model-candidate-v1.local.json"
local_output="${CLEARTOGO_CANDIDATE_EVALUATION_OUTPUT:-${default_local_output}}"

# XCTest does not promise to inherit the repository as its working directory.
# Resolve caller-provided relative paths before serializing them into xctestrun.
if [[ "${benchmark_input}" != /* ]]; then
  benchmark_input="${repository_root}/${benchmark_input}"
fi
if [[ "${local_output}" != /* ]]; then
  local_output="${repository_root}/${local_output}"
fi
benchmark_input="${benchmark_input:A}"
local_output="${local_output:A}"

cd "${repository_root}"

for required_command in xcodebuild xcodegen jq /usr/libexec/PlistBuddy; do
  if ! command -v "${required_command}" >/dev/null 2>&1 && [[ ! -x "${required_command}" ]]; then
    print -u2 "Missing required command: ${required_command}"
    exit 3
  fi
done

codex_executable="${CLEARTOGO_CODEX_EXECUTABLE:-}"
if [[ -z "${codex_executable}" ]]; then
  for candidate in "${HOME}/.local/bin/codex" /opt/homebrew/bin/codex /usr/local/bin/codex; do
    if [[ -x "${candidate}" ]]; then
      codex_executable="${candidate}"
      break
    fi
  done
fi
if [[ -z "${codex_executable}" || ! -x "${codex_executable}" ]]; then
  print -u2 "A compatible standalone Codex executable is required. Set CLEARTOGO_CODEX_EXECUTABLE when using an approved session shim."
  exit 3
fi

"${codex_executable}" login status >/dev/null
if [[ ! -f "${benchmark_input}" ]]; then
  print -u2 "Candidate evaluation input does not exist: ${benchmark_input}"
  exit 4
fi
xcodegen generate
mkdir -p "${local_output_directory}"
mkdir -p "${local_output:h}"

xcodebuild build-for-testing \
  -project ClearToGo.xcodeproj \
  -scheme ClearToGoLiveCandidateEvaluation \
  -destination 'platform=macOS,arch=arm64' \
  -derivedDataPath "${benchmark_derived_data}" \
  CODE_SIGNING_ALLOWED=NO

products_directory="${benchmark_derived_data}/Build/Products"
base_xctestrun="$(find "${products_directory}" -maxdepth 1 -name 'ClearToGoLiveCandidateEvaluation_macosx*.xctestrun' -print -quit)"
if [[ -z "${base_xctestrun}" ]]; then
  print -u2 "The Live candidate evaluation xctestrun was not generated."
  exit 4
fi
benchmark_xctestrun="${products_directory}/ClearToGoLiveCandidateEvaluation_public-current-model.xctestrun"
cp "${base_xctestrun}" "${benchmark_xctestrun}"

/usr/libexec/PlistBuddy -c "Add :ClearToGoLiveCandidateEvaluationTests:EnvironmentVariables:CLEARTOGO_CODEX_EXECUTABLE string ${codex_executable}" "${benchmark_xctestrun}"
/usr/libexec/PlistBuddy -c "Add :ClearToGoLiveCandidateEvaluationTests:EnvironmentVariables:CLEARTOGO_CANDIDATE_EVALUATION_INPUT string ${benchmark_input}" "${benchmark_xctestrun}"
/usr/libexec/PlistBuddy -c "Add :ClearToGoLiveCandidateEvaluationTests:EnvironmentVariables:CLEARTOGO_CANDIDATE_EVALUATION_OUTPUT string ${local_output}" "${benchmark_xctestrun}"

xcodebuild test-without-building \
  -xctestrun "${benchmark_xctestrun}" \
  -destination 'platform=macOS,arch=arm64'

print "Detailed local report: ${local_output}"
jq '{datasetID, aggregate}' "${local_output}"
jq '[.items[] | select(.candidateTier != "tier_a_deterministic")] as $model | {
  model_eligible_count: ($model | length),
  true_positive: ([$model[] | select(.groundTruthRelevant and .predictedRelevant)] | length),
  false_positive: ([$model[] | select((.groundTruthRelevant | not) and .predictedRelevant)] | length),
  false_negative: ([$model[] | select(.groundTruthRelevant and (.predictedRelevant | not))] | length),
  true_negative: ([$model[] | select((.groundTruthRelevant | not) and (.predictedRelevant | not))] | length)
}' "${local_output}"

```

### Scripts/run-judge-demo.sh

```shell
#!/bin/zsh

set -euo pipefail

script_directory="${0:A:h}"
repository_root="${script_directory:h}"
judge_derived_data="${repository_root}/.derived-data/JudgeDemo"
judge_app="${judge_derived_data}/Build/Products/Debug/ClearToGo.app"
verify_only=0
allow_dirty=0
verification_output=""

while (( $# > 0 )); do
  case "$1" in
    --verify-only)
      verify_only=1
      shift
      ;;
    --allow-dirty)
      allow_dirty=1
      shift
      ;;
    --output)
      if (( $# < 2 )); then
        print -u2 "--output requires a directory path"
        exit 2
      fi
      verification_output="$2"
      shift 2
      ;;
    *)
      print -u2 "Unknown argument: $1"
      exit 2
      ;;
  esac
done

cd "${repository_root}"

for required_command in xcodebuild xcodegen brew git; do
  if ! command -v "${required_command}" >/dev/null 2>&1; then
    print -u2 "Missing required command: ${required_command}. See README.md#requirements."
    exit 3
  fi
done

if [[ "$(uname -m)" != "arm64" ]]; then
  print -u2 "Judge Demo requires an Apple Silicon Mac (arm64)."
  exit 3
fi

macos_version="$(sw_vers -productVersion)"
macos_major="${macos_version%%.*}"
if (( macos_major < 15 )); then
  print -u2 "Judge Demo requires macOS 15 or later; found ${macos_version}."
  exit 3
fi

xcode_version="$(xcodebuild -version | sed -n '1s/^Xcode //p')"
xcode_major="${xcode_version%%.*}"
if (( xcode_major < 16 )); then
  print -u2 "Judge Demo requires Xcode 16 or later; found ${xcode_version}."
  exit 3
fi

ctg_homebrew_prefix="$(brew --prefix)"
for required_formula in libimobiledevice libplist; do
  if [[ ! -d "${ctg_homebrew_prefix}/opt/${required_formula}" ]]; then
    print -u2 "Missing Homebrew dependency: ${required_formula}. Run: brew install ${required_formula}"
    exit 3
  fi
done

project_hash_before="$(shasum -a 256 ClearToGo.xcodeproj/project.pbxproj | awk '{print $1}')"
xcodegen generate
project_hash_after="$(shasum -a 256 ClearToGo.xcodeproj/project.pbxproj | awk '{print $1}')"
if [[ "${project_hash_before}" != "${project_hash_after}" ]]; then
  print -u2 "Generated Xcode project was stale. Commit the regenerated ClearToGo.xcodeproj before verification."
  exit 4
fi

if (( verify_only == 1 )); then
  worktree_clean=true
  if [[ -n "$(git status --porcelain --untracked-files=all)" ]]; then
    worktree_clean=false
    if (( allow_dirty == 0 )); then
      print -u2 "Verification requires a clean tracked worktree. Commit the frozen revision or use --allow-dirty only for development."
      exit 4
    fi
  fi

  if [[ -z "${verification_output}" ]]; then
    verification_output="$(mktemp -d "${TMPDIR:-/tmp}/cleartogo-judge-verification.XXXXXX")"
  elif [[ -e "${verification_output}" ]]; then
    if [[ ! -d "${verification_output}" || -n "$(ls -A "${verification_output}")" ]]; then
      print -u2 "Verification output must be a missing or empty directory: ${verification_output}"
      exit 4
    fi
  else
    mkdir -p "${verification_output}"
  fi

  verification_output="${verification_output:A}"
  result_bundle="${verification_output}/JudgeDemo.xcresult"
  receipt="${verification_output}/judge-demo-receipt.json"
  receipt_plist="${verification_output}/judge-demo-receipt.plist"
  verification_derived_data="${verification_output}/DerivedData"

  xcodebuild test \
    -project ClearToGo.xcodeproj \
    -scheme ClearToGo \
    -configuration Debug \
    -destination 'platform=macOS,arch=arm64' \
    -derivedDataPath "${verification_derived_data}" \
    -resultBundlePath "${result_bundle}" \
    -only-testing:ClearToGoAppTests/P0WorkflowCoordinatorTests/testJudgeDemoUsesSyntheticPreviewThenExistingIsolatedReplay \
    CTG_HOMEBREW_PREFIX="${ctg_homebrew_prefix}" \
    SWIFT_TREAT_WARNINGS_AS_ERRORS=YES \
    GCC_TREAT_WARNINGS_AS_ERRORS=YES

  /usr/bin/plutil -create xml1 "${receipt_plist}"
  /usr/bin/plutil -insert schema_version -string "1.0" "${receipt_plist}"
  /usr/bin/plutil -insert project -string "ClearToGo" "${receipt_plist}"
  /usr/bin/plutil -insert git_revision -string "$(git rev-parse HEAD)" "${receipt_plist}"
  /usr/bin/plutil -insert worktree_clean -bool "${worktree_clean}" "${receipt_plist}"
  /usr/bin/plutil -insert architecture -string "arm64" "${receipt_plist}"
  /usr/bin/plutil -insert macos_version -string "${macos_version}" "${receipt_plist}"
  /usr/bin/plutil -insert xcode_version -string "${xcode_version}" "${receipt_plist}"
  /usr/bin/plutil -insert xcodegen_version -string "$(xcodegen --version | awk '{print $2}')" "${receipt_plist}"
  /usr/bin/plutil -insert acceptance_test -string "P0WorkflowCoordinatorTests.testJudgeDemoUsesSyntheticPreviewThenExistingIsolatedReplay" "${receipt_plist}"
  /usr/bin/plutil -insert result -string "passed" "${receipt_plist}"
  /usr/bin/plutil -insert source_apps -integer 4 "${receipt_plist}"
  /usr/bin/plutil -insert review_candidates -integer 3 "${receipt_plist}"
  /usr/bin/plutil -insert replay_challenges -integer 9 "${receipt_plist}"
  /usr/bin/plutil -insert final_state -string "CHECKS_PASSED" "${receipt_plist}"
  /usr/bin/plutil -insert live_export_allowed -bool false "${receipt_plist}"
  /usr/bin/plutil -insert physical_device_access -bool false "${receipt_plist}"
  /usr/bin/plutil -insert network_model_calls -bool false "${receipt_plist}"
  /usr/bin/plutil -insert result_bundle -string "JudgeDemo.xcresult" "${receipt_plist}"
  /usr/bin/plutil -convert json -o "${receipt}" "${receipt_plist}"
  rm "${receipt_plist}"

  print "Judge Demo verification passed."
  print "Receipt: ${receipt}"
  print "Result bundle: ${result_bundle}"
  exit 0
fi

xcodebuild build \
  -project ClearToGo.xcodeproj \
  -scheme ClearToGo \
  -configuration Debug \
  -destination 'platform=macOS,arch=arm64' \
  -derivedDataPath "${judge_derived_data}" \
  CTG_HOMEBREW_PREFIX="${ctg_homebrew_prefix}" \
  SWIFT_TREAT_WARNINGS_AS_ERRORS=YES \
  GCC_TREAT_WARNINGS_AS_ERRORS=YES

exec env \
  CLEARTOGO_JUDGE_DEMO=1 \
  CLEARTOGO_JUDGE_DEMO_RESET=1 \
  "${judge_app}/Contents/MacOS/ClearToGo
[truncated — 42 more characters]
```

[158 more indexed source files omitted to keep this export small. The full file list is in the Codebase structure section above.]