Read-only diagnostics
Run python3 scripts/doctor.py --host mac on the Mac or --host shipyard on Shipyard. The command checks its actual platform and refuses a mismatched host profile. It does not SSH elsewhere, inspect private key contents, refresh tokens, install software, restart services or print raw logs.
Use --json for structured output. Each result includes a status, scope and a link to an applicable runbook. Exit code 0 means the implemented baseline checks passed; 1 means at least one warning/failure; 2 means the selected profile is inappropriate or arguments are invalid. Baseline success does not establish complete application readiness or matching tools and access.
Checks include required command availability, selected local repository paths, private-key file presence/mode (never contents), browser loopback endpoints, and drift between curated runtime sources and the active installation. The key check says only that a private file exists with the expected mode; it does not validate IAM or authenticate a user.
python3 scripts/runtime.py check is a focused read-only drift report on Shipyard. python3 scripts/runtime.py plan shows what the explicit installer would change. See tooling updates.
For a specific task, use its own status command and current health URL. Shared browser /json/version is probed without displaying tab URLs or titles. Use access recovery to investigate a denied application call without broadening permissions.