tighten joins the environment model (every server’s tools and filesystem roots) with aspex trace activity (which tools were called, which paths were read or written) and recommends the narrowest configuration that would have supported what actually happened.
Tool allowlists
--min-calls (default 20) the evidence is labelled weak and the list is a hint, not a recommendation.
Filesystem roots
~/.ssh) are ignored; only path-shaped arguments count. A server already scoped to a project gets no root recommendation.
The reduction is qualitative: SIGNIFICANT, MODERATE, or LIKELY SIGNIFICANT when the evidence is weak. Aspex does not print a percentage it cannot justify.
What it never does
- It never edits your configuration. Apply the change in your client, then run
aspex lockagain. - It never calls an unobserved server unused. Servers with no activity in the window are listed separately with the caveat that absence in traces is not proof of disuse.
- It needs real traces: with no events in the window it says so and recommends nothing.