Follow a finding until the evidence answers.

Uruma maps an existing claim to code paths, runs a selected path in an isolated sandbox, and records what the oracle observed.

$npx uruma
Watch the session

Illustrative Uruma session

Session session-7f3a, pinned repository 4f3a21c.

  1. Open a claimnpx urumasession session-7f3a / pinned repo 4f3a21c / phase IDLE / tool extract / path stored-XSS / map 0 bindings / xproof offstored-XSS claim entered and pinned to 4f3a21c.$ npx urumaURUMA session-7f3a IDLEentered claim stored-XSS in saved diagram title
  2. Explore bindings/exploresession session-7f3a / pinned repo 4f3a21c / phase IDLE / tool extract / path stored-XSS / map 2 bindings / xproof offcontinuing pinned stored-XSS claim.MAP 2 bindings attempts 0/12 stop openAND page_loaded + sink_activated + effect_observed -> VERIFIED /s/mermaid hypothesized diagram renderer /s/preview hypothesized preview renderer
  3. Select a path/mapsession session-7f3a / pinned repo 4f3a21c / phase PICK / tool map / path /s/mermaid / map 2 bindings / xproof offoperator chose a mermaid-reaching path.$ /map /s/mermaid hypothesized diagram renderer no oracle run yet. a hypothesis is not a verdict.
  4. Run the oracle/try /s/mermaidsession session-7f3a / pinned repo 4f3a21c / phase RUN / tool verify / path /s/mermaid / map 2 bindings / xproof offbaseline activation in progress.$ /try /s/mermaidverify /s/mermaid baseline declared payload[########--------] 3/6 ATTACKthe session run does not write an xproofDeclared boundary: attacker to target to victim browser, observed by the host witness on a closed network.
  5. Record the verdict/mapsession session-7f3a / pinned repo 4f3a21c / phase IDLE / tool verify / path /s/mermaid / map 2 bindings / xproof offbaseline VERIFIED activated_sink.oracle /s/mermaid [baseline]: VERIFIED (activated_sink)effect observed on this pathdeclared boundary attacker -> target -> victim browserliveness ok negative control cleanFAMILY 1/4 mutation-family variants executedexport remains an operator action
  6. Export a verdict snapshot/export /s/mermaid verdictsession session-7f3a / pinned repo 4f3a21c / phase IDLE / tool mint-verdict / path /s/mermaid / map 2 bindings / xproof offjudged oracle state copied to verdict.json.$ /export /s/mermaid verdictSELECT ok /s/mermaidCONVERT ok verdict.jsonthis verdict.json is not a signed .xproofsigned receipt handoff npx uruma verify proof.yml
DECISION
The model maps paths. Only the oracle writes a verdict.
HANDOFF
The session exports verdict.json. uruma verify writes signed .xproof.
LIMITS
NOT_REPRODUCED is not safe. INCONCLUSIVE stays explicit.

Start in the repository that holds the claim.

$npx uruma
Open the dashboard