Skip to content

LANCET Nano v0.3.0

Pre-release
Pre-release

Choose a tag to compare

@TannerMidd TannerMidd released this 26 Sep 21:31
· 12 commits to main since this release

LANCET Nano v0.3.0 is a larger, more accurate local Bash command-risk classifier. It uses a CodeT5-base encoder, trained from the pinned upstream weights rather than an earlier LANCET checkpoint. It remains experimental.

Model: Apache-2.0. Runtime: MIT.

What's new

  • Larger model: 109.6M parameters, a 111 MB INT8 ONNX file, and about 22 ms per command on a CPU (median, measured on a busy Ryzen 9 3900X). v0.2.0 is 35.3M parameters and 36 MB.
  • More training data:
    • Azure CLI, GitHub CLI, kubectl and Docker CLI reference examples.
    • A documentation rule that labels commands which print or mint secrets as risky, using AWS's own sensitive output-field markings.
    • A project-authored secrets family.
    • LANCET's earlier agent-authored evaluation suites, retired into training with their original labels.
  • Labels: no language model, hosted API or human labeler produced any training label.

Results on the 793-command release benchmark (one pass each)

v0.3.0 v0.2.0 v0.1.0 Jev (hosted)
Risky caught 85.8% 73.6% 65.5% 96.8%
Safe wrongly stopped 5.5% 6.2% 5.5% 7.8%
Risky secrets caught 66% 24% 14% 98%
  • Benchmark caveat: the benchmark's labels were written by the developer, an AI agent. This is diagnostic evidence, not independent acceptance.
  • Upstream ShellRisk sets (not agent-authored, never trained on):
    • source-external: v0.3.0 caught 48.9% vs 48.3% for v0.2.0 and stopped 6.3% vs 9.7% of safe commands.
    • source-holdout: v0.3.0 caught 41.9% vs 45.9%.
  • Weaker areas: network/remote execution and infrastructure-as-code.

Release by owner exception

  • Failed check: one of four preregistered release checks. It required the 95% lower bound of the ShellRisk catch-rate difference to be at least −5 points. The observed difference was +0.6 points [−6.5, +7.8].
  • Why: with only 176 risky commands, even an equal model would usually fail that check. This design error is disclosed.
  • Decision: the owner approved the release as a documented exception, recorded in provenance/release-gate.json.

Verify and run

certutil -hashfile lancet-v0.3.0-nano-cpu-int8.zip SHA256   # compare with SHA256SUMS.txt
python verify_bundle.py --strict
python -m pip install -r requirements.txt
echo {"command": "kubectl delete namespace prod", "shell": "bash"} | python classify.py --model model

not_flagged is not execution authorization or a safety guarantee. v0.2.0 (smaller and faster) remains available unchanged.