Skip to content

LANCET Nano v0.2.0

Pre-release
Pre-release

Choose a tag to compare

@TannerMidd TannerMidd released this 26 Sep 04:19
· 8 commits to main since this release

LANCET Nano: a local classifier for Bash command risk. It has 35.3M parameters, ships as a 38 MB CPU INT8 ONNX model, takes about 3 ms per command and needs no network connection.

Model: Apache-2.0. Runtime: MIT. The datasets used for training are not included.

Results on 400 fresh commands (sealed diagnostic suite, one scoring pass)

LANCET Nano V5 (v0.1.0)
Risky caught 83.9% (177/211) 76.3%
Safe commands wrongly stopped 5.8% (11/189) 8.5%
AUROC 0.935 0.902

For comparison on the same suite:

Model Risky caught Safe commands wrongly stopped
Hosted Jev (about 200× larger by estimate) 97.6% 4.8%
Laya (421M parameters, GPU) 77.7% 42.9%

The suite's labels were written by the developer, an AI agent. These results are diagnostic, not independent acceptance.

What changed from V5

  • The new training labels come from documentation. The wording of the human-written example descriptions in tldr-pages (CC BY 4.0) sets each example's label, and so do the AWS operation verbs in the botocore service models (Apache-2.0).
  • No language model, hosted API or human labeler produced any label.
  • Nano now returns three bands: risky, review and not_flagged.

Install and verify

  1. Download lancet-v0.2.0-nano-cpu-int8.zip.
  2. Check it against SHA256SUMS.txt.
  3. Extract it and run python verify_bundle.py --strict.
  4. Follow README.md inside the ZIP.

Tested

  • The ZIP builds reproducibly.
  • Strict verification passes on all 30 files.
  • In a clean virtual environment with the pinned dependencies (numpy 2.5.3, tokenizers 0.23.2, onnxruntime 1.30.0), the release runtime exactly matched the research runtime on 5,262 development rows: identical scores, identical bands and identical input-contract handling.

Limits

  • Bash only.
  • not_flagged is not execution authorization or a safety guarantee.
  • Independent acceptance and human label adjudication remain unavailable.

Model ONNX SHA-256: 183ae5051fffe8578267c524efb78ef82c2f668f1e575690923ced8c5f1827f5