Deterministic command catalog — experimental preview
These registered commands preview review, diagnose, and validate surfaces. The analysis capability is experimental and requires opt-in; results need human review. Zero-model commands do not invoke a model, but some can still use configured remote integrations.
The full harness — 44 deterministic agents across five phases. — every verdict is word-plus-color, never color alone.
$ vectalon review#061PR Review Agent
Reviews the git diff against the project’s own derived coding standards — every added line probed line-level, with an optional LLM pass that degrades to the deterministic review when no model is configured.
$ vectalon arch#062Architecture Review Agent
One pass over the module graph — circular dependencies, layering violations, god modules, over-coupling, wide fan-in, orphans, and over-deep nesting — with per-module coupling metrics.
$ vectalon sec#063Security Review Agent
Scans for hardcoded secrets (every captured value redacted in reports), unsafe code patterns, and best-effort dependency advisories via npm audit.
$ vectalon build-fix#064Build Fix Agent
Diagnoses a failing Metro, Gradle, or Xcode build from its log — kind auto-detected, a pattern classifier returns the root cause, the standard fix, and corroborating symptoms as a fix plan.
$ vectalon test-repair#065Test Repair Agent
Diagnoses a failing Jest, Detox, or Maestro run from its output — pattern databases per runner return the root cause with the standard fix and corroborating symptoms.
$ vectalon refactor#066Refactoring Agent
Scans source for dead code (AST-backed), duplication, modernization opportunities, type smells, inline-style debt, console noise, and complexity — every finding line-pinned with a specific suggestion.
$ vectalon deps#067Dependency Upgrade Agent
Finds what to upgrade and the safe path — RN ecosystem pairing violations, duplicate versions across workspace members, and vulnerable dependencies via best-effort npm audit.
$ vectalon a11y#068Accessibility Agent
One deterministic pass over component files — unlabeled images, touchables without roles, unlabeled inputs, and undersized touch targets below the 44×44pt guideline.
$ vectalon release-ready#069Release Readiness Agent
Answers “can we ship?” — version past the last tag, CHANGELOG section, clean tree, CI present, lockfile, tests configured, secrets hygiene, TODO/FIXME triage — read-only git.
$ vectalon bug-fix#070Autonomous Bug Fix Agent
Proposes fixes for deterministic defects and executes the provably-safe ones — whole-line unused-import removal and var→const — with `--apply` refusing a dirty tree unless forced.
$ vectalon crash#071Crash Intelligence Agent
Classifies an iOS, Android, or JavaScript crash log into a root-cause bucket (null-reference, module-resolution, resource, network, state-mutation, concurrency) with the standard fix and investigation steps.
$ vectalon arch-score#072Mobile Architecture Scorecard
Scores the module graph 0–100 across circular dependencies, layer boundaries, coupling, module cohesion, testability, and nesting depth — with a letter grade and top improvements.
$ vectalon cicd#073CI/CD Intelligence Agent
Scans CI workflow files for anti-patterns — actions pinned to tags instead of SHAs, missing concurrency and timeouts, inline secrets, deploys without a test gate, missing triggers — with other CI systems detected and named.
$ vectalon app-store#074App Store Readiness Agent
Store-submission checks — version/version-code consistency across Info.plist, build.gradle, and package.json, app icons, the iOS privacy manifest, launch screen, ATS/cleartext posture, and permissions.
$ vectalon soc2#075SOC2 Readiness Agent
A repository-evidence checklist mapped to the five trust-service criteria plus operational hygiene — auth, secrets, lockfiles, CI, coverage, TLS, privacy policy, audit logs, backups, incident response — with a score.
$ vectalon tokens#076Design Token Sync Agent
Flattens a style-dictionary-style token JSON and checks source for drift — tokens never referenced, hardcoded colors that should be tokens, and token pairs with identical values.
$ vectalon team-stats#077Team Productivity Analytics
One read-only git log derives commit cadence, author distribution, bus factor, category mix, and change velocity — warning on single-owner risk and low cadence.
$ vectalon perms#078Agent Permissions Audit
Scans agent/MCP configuration for auto-approved shell and file-mutation tool grants, local-exec MCP servers, and credential-shaped values in config — errors redacted.
$ vectalon dashboard#079Engineering Dashboard
Aggregates every agent report under docs/vectalon/* into one executive view — per-agent health cards, an overall verdict, and a self-contained HTML dashboard with drill-down, filtering, and search.
$ vectalon figma#080Figma-to-code Sync Agent
Parses a Figma design export and checks design↔code drift — design colors with no matching token or hardcoded value, component names with no source component, text styles with no font usage.
$ vectalon sentry#081Sentry Intelligence Agent
Ingests Sentry/Crashlytics telemetry exports, groups crashes into classes by exception type, ranks them by volume and distinct-user impact, and flags release regressions.
$ vectalon observability#082Mobile Observability Agent
Audits instrumentation coverage in source — Sentry init, crash handlers, analytics SDK, network breadcrumbs, performance tracing — and flags slow traces and spans from telemetry.
$ vectalon governance#083Enterprise Governance Agent
A repository-evidence checklist — license, security policy, contributing guide, CODEOWNERS, PR template, lockfile/SBOM, Dependabot, CI — with pass/warn/fail statuses.
$ vectalon audit#084Org-wide Audit Trail Agent
Validates the .vectalon/audit/*.jsonl trail — required fields, sequence continuity, malformed lines, secret-shaped values — and summarizes activity by actor and action.
$ vectalon repos#085Multi-repository Memory Agent
Verifies the .vectalon/repos.json workspace manifest — each sibling repo reachable, a git checkout, with a memory store — and flags missing or non-git entries.
$ vectalon release-predict#086Release Prediction Agent
A deterministic 0–100 release-risk score from read-only git history — fix density, refactor density, staleness, breaking changes, author breadth in the release window — with a per-factor breakdown.
$ vectalon play-store#087Deep Play Store Readiness Agent
Play-specific checks beyond the shared store surface — manifest permissions and the data-safety form they imply, exported components, backup rules, SDK levels, signing, and measured listing assets.
$ vectalon dataset#088Fine-tuning Dataset Agent
Validates .vectalon/dataset/*.jsonl training data — schema consistency, duplicates, label balance, length outliers, and PII leakage (emails, phones, keys, SSNs).
$ vectalon lora#089LoRA Training Readiness Agent
Checks the .vectalon/lora config — dataset path, base model with a VRAM estimate, r/alpha hyperparams, quantization, output dir, wandb — and flags what’s missing before training starts.
$ vectalon gh-pr#090GitHub PR Triage Agent
Scores every open PR for merge-readiness in one deterministic pass — age, draft state, size, review decision, CI check rollup, and mergeability — from the gh CLI or an export; degrades to an explicit no-data verdict when neither exists.
$ vectalon gh-issue#091GitHub Issue Intelligence Agent
Turns the open-issue backlog into a triage queue — staleness ranking, unassigned gaps nobody owns, and label hygiene — so old issues stop being a background tax on every dev.
$ vectalon gh-ci#092GitHub Workflow Reliability Agent
Detects flaky and slow CI before it costs a release — per-workflow failure rates, workflows that both pass and fail across their runs, and 30-minute-plus duration outliers.
$ vectalon gh-sec#093GitHub Security Posture Agent
One security snapshot of the GitHub surface — open dependabot alerts, secret-scanning findings, and branch protection with review enforcement — plus remediation steps for every finding.
$ vectalon monitor#094Observability Dashboard Agent
Folds telemetry into one executive view — crash classes ranked by the Sentry agent, observability instrumentation findings, crash intelligence, the engineering-dashboard verdict, and raw telemetry event counts.
$ vectalon evals#095Model Evaluation Harness
Scores golden eval cases deterministically — exact, includes, or regex matching — and compares the pass rate against the previous run, flagging any regression bigger than five points.
$ vectalon search#096Semantic Code Search Agent
Sub-second, line-pinned search across the source tree — term matches ranked by density so files that are mostly about the topic surface first, with a no-results verdict that tells you to broaden the query.
$ vectalon incident#097Incident Commander Agent
From a crash log — or the latest crash report — to an incident brief: root-cause bucket via the shared analyzer, hot files with their recent commits, release risk from the prediction agent, and next steps.
$ vectalon train#098Release Train Automation
Dry-run release planning across every workspace repo — version versus the last tag, changelog section present, clean tree, and a suggested semver bump from recent commit types. Read-only: the plan is the deliverable.
$ vectalon cost#099Cost Governance Agent
Estimates cloud + model spend from project config — LoRA GPU-hours at the VRAM class, eval inference tokens, dataset bytes — with the rate assumptions printed so the estimate is auditable.
$ vectalon dx#100DX Scoring Agent
One 0–100 developer-experience score from local evidence — README, contributing guide, docs, CI, tests, lint, strict types, changelog, onboarding — across twelve weighted axes with the top gains ranked.
$ vectalon archive#101Build Archive Agent
Builds (or ingests a pre-built) IPA/APK/AAB, computes its SHA-256, and writes a typed BuildManifest with full provenance — git commit, flavor, environment, build number, platform — stored under .vectalon/builds/. Zero-config flavor detection from Gradle productFlavors, Xcode schemes, and eas.json profiles.
$ vectalon distribute#102Distribution Agent
Deploys an archived build to TestFlight, the Google Play Store, the SaaS portal, or a generated white-label portal. Credentials are never stored — Fastlane/EAS/Expo or direct API env vars are detected and delegated, or actionable instructions are printed. --dry-run plans without side effects.
$ vectalon share#103Local Share Agent
Serves an archived build on an ephemeral static install page — download link, optional tunnel (ngrok/localtunnel), optional QR code, and auto-shutdown after --expires. Free tier; nothing leaves your machine unless the tunnel is enabled.
$ vectalon portal#104White-label Portal Agent
Generates a self-contained static build portal (SSG) from the archive store — a listing page plus per-build detail pages with install instructions and an embedded builds.json. --deploy prints the vercel/netlify command; --deploy static exports the site for any host.