Skip to main content
NikaCheckResult deliberately stays open:
Findings are report data. Configuration, engine resolution, transport and protocol failures throw typed errors. Keep application policy outside the SDK: inspect engine-owned fields your pinned engine documents, and preserve unknown fields when storing or forwarding the report.
The source SDK exposes no separate dry-run-plan method. Do not manufacture a TypeScript plan contract from engine output. Use check() for SDK admission and the engine CLI when an operator needs CLI-specific planning.
Remote checks intentionally reject the local-only model and nativeStrict overrides rather than silently ignoring them. For a contained served name, the remote result is the resident’s typed acknowledgement or workflow refusal, without local findings or an exit code. An explicit local path instead captures a local engine report and snapshot; successful capture requires the resident to acknowledge that exact snapshot. See remote checks for the two forms.

Run and cancel

Admit only after application policy accepts the check report.

Errors

Separate dirty reports from thrown boundary failures.