Automation Script Test Harness · For your security review
You can run this without anything leaving your network.
The CLI runs on your own machine today — no account, no upload, no call home. Everything here is how it works today, written to be forwarded to a security team without a covering explanation.
Runs on your machine, offline
mvn verify compiles and runs the script harness's JUnit profiles locally. maximo-stub runs as a local Node process, and its browser build runs the whole engine in the page. Neither engine makes an outbound network call to run. An air-gapped machine or a CI runner needs nothing but the source.
Nothing is installed in your Maximo
A run executes your script against a mock. Never against a live Maximo. No component is deployed into your system. No automation script from the harness runs in your production JVM. Nothing connects to your database.
What a run reads
Your script source. Dictionary data only where you provide it — captured read-only, metadata only, never business rows unless explicitly sampled and pseudonymised. No work orders, no assets, no people, no transactions.
If a future hosted run sends anything
The static evidence check at /connect is stateless, per call — your script text is not stored. A hosted service that executes your script and returns a real PASS/FAIL/BLOCKING verdict is roadmap, not built. When it exists, it carries the same commitments MXH's hosted option carries: processed in your own country of data residency, the input deleted once the result is returned, a named set of people per engagement able to see what you send.