THE STRANGER TEST
Your repo.
One clean machine.
Zero tribal knowledge.
It works on your machine.
How much does your machine know?
Real fixture. Real execution. Every conclusion leaves a trace.
A build passing on your laptop
proves your laptop works.
Remove the laptop.
Cold Machine puts a repository in an isolated, clean environment. Then it attempts to discover, bootstrap, build, test, run, and verify it—using only what’s inside the repository.
No inherited services. No personal shell setup. No colleague who remembers the missing step.
It doesn’t predict whether your repo works.
It performs the
experiment.
The build passed.
The assumption didn’t.
This repository looks ready. Its README even tells you what to
run.
Watch what happens when nothing is already listening.
- 01Isolate✓
- 02Discover✓
- 03Bootstrap✓
- 04Build✓
- 05Test×
- 06Run—
- 07Verify—
ISOLATE → DISCOVER → BOOTSTRAP → BUILD → TEST FAILED
Curated real events. Playback timing is compressed.
Nothing listening on 5432.
The documented test command exited with code 1.
error: 'connect ECONNREFUSED 127.0.0.1:5432' code: 'ECONNREFUSED'
Execution proves the refused connection. The PostgreSQL attribution comes from the repository clue.
The missing prerequisite was outside the instructions.
database.test.js:3 references
localhost:5432. Cold Machine flagged a PostgreSQL
assumption; no prerequisite was found in README.md.
Then execution exposed the refused connection.
DECLARATION ANALYSIS
“This repository appears
to need PostgreSQL.”
A useful clue.
Still a statement about the code.
COLD MACHINE
“Bootstrap passed.
Build passed.
Tests hit a closed port.”
A command. An exit code. Captured output.
A result you can
inspect and repeat.
And CI?
CI usually runs a workflow someone already wrote. Cold Machine asks whether the repository contains enough information to discover and execute a path to working software from zero project-specific context.
Where did the
instructions come from?
Operational knowledge leaves a trail. Cold Machine records which actions came from the repository, which it inferred, and which needed recovery or user input.
Every recovery attempt counts as an intervention-equivalent. If the machine has to fill a gap, the repository didn’t explain itself.
- Repository-contained
- 4 actions
- Inferred
- 1 HTTP probe
- Recovered
- 0
- User supplied
- 0
The HTTP probe is inferred. The operating commands are documented. Zero recovery is meaningful; it doesn’t mean every action was written down.
It was obvious.
To someone.
01 A service that was always running −
PostgreSQL on localhost. Redis behind a test suite. Cold Machine can flag source references and classify captured connection failures. The demo above shows the difference between a clue and an observation.
02 A tool the README forgot +
A declared pnpm or Yarn manager can require Corepack activation. The current runner records that limited recovery. The demo fixture also exposes an undeclared jq reference as a static warning.
03 Instructions that stopped being true +
The stale-docs fixture says “npm run compile.” That script no longer exists. Cold Machine follows the instruction and records the failed command. Inspect that real run
04 A machine quietly doing the work +
Runtime constraints, developer-specific paths, undeclared environment variables, and system binaries. Findings carry evidence and confidence; a static reference alone is not proof that a dependency is required.
COLD START PASSED
Nothing remembered.
Everything needed.
Another repository. The same clean start.
Documented
commands. Passing tests.
An HTTP response from the launched
application.
- Bootstrap
- ✓ PASS
- Build
- ✓ PASS
- Tests
- ✓ PASS
- Run
- ✓ PASS
- Proof of life
- ✓ HTTP 200
REQUIRED0
Your next operator
may have no memory
of your last
machine.
A new engineer. An ephemeral CI worker. A coding agent. A disposable development environment.
The more often software changes hands, the more valuable it is for a repository to carry its own operating knowledge.
Self-sufficiency is something you can test.
FUTURE WORK / NOT SHIPPED
Regression mode
Could a pull request introduce a new environmental assumption? Compare runs to find out.
Agent Stranger Mode
Can an unfamiliar coding agent operate a repository using only what it tells the agent?
How much does
your machine know?
Start with the evidence. Then give your repository
the same clean start.
Cold Machine is currently in a private JP5 Labs repository. Source access is limited; there is no published npm package.
git clone --branch feature/cold-machine-site https://github.com/jp5labs/incubator.git cd incubator/cli/cold-machine npm ci npm run build npm run sandbox:build node dist/cli.js challenge ./fixtures/perfect-repo
Requires Node.js 22+ and a local Docker daemon. Optional: run
npm link, then use
coldmachine challenge . from your repository.
Dependency downloads require --network enabled.
What the current version supports
Local Node.js, Python, and Make repositories; deterministic discovery, bounded recovery, isolated execution, and offline reports. This is a repository experiment, not an unrestricted autonomous coding agent. Containers share the host kernel.