TraceLens is an advanced, production-grade visual code tracer and runtime DSAI/ML auditor built for the IBM Bob 2.0 Hackathon (lablab.ai).
Static code analysis can only predict what might happen. TraceLens tells developers and data scientists what actually happened at runtime — recording every line execution, variable mutation, loop iteration, branch decision, tensor shape transition, and data-leakage flaw in real time, accompanied by contextual, zero-hallucination explanations powered by IBM Granite 3.8B.
https://tracelens-ivory.vercel.app)TraceLens features a dual-engine architecture:
Designed for algorithms, data structures, and general-purpose Python pipelines:
break/continue hooks.if/elif/else blocks, explicitly highlighting chosen vs. unvisited pathways.A specialized runtime auditor purpose-built for Data Science & Machine Learning pipelines:
scaler.fit_transform() across the entire dataset prior to train_test_split()).flowchart TD
subgraph Client["Frontend (React 19 + Vite + Tailwind CSS v4)"]
UI["Code Editor & Dataset Dropzone"]
Player["Time-Traveling Trace Player"]
Studio["LogicLens & ModelLens Studio"]
BobPanel["Bob AI Explainer & Diff Patcher"]
end
subgraph Server["TraceLens Backend (FastAPI on Railway)"]
Router["FastAPI Gateway (/api/trace, /api/explain)"]
ASTPass["AST Control-Flow Pre-Pass (ast_flow.py)"]
PkgMgr["Runtime Dependency Provisioner (package_installer.py)"]
Sandbox["Deterministic Execution Sandbox (sandbox.py)"]
Tracer["Deterministic Delta Engine (tracer.py)"]
MLAudit["ML Diagnostics & Taint Analyzer (ml_diagnostics.py)"]
BobClient["WatsonX Client (IBM Granite 3.8B)"]
end
subgraph Execution["Isolated Subprocess Boundary"]
Spawn["multiprocessing.get_context('spawn')"]
Guards["Restricted Builtins & sys.settrace Hook"]
DiskTransport["Atomic JSON Payload (result.json)"]
end
UI -->|POST /api/trace| Router
Router --> ASTPass
Router --> PkgMgr
Router --> Sandbox
Sandbox --> Spawn
Spawn --> Guards
Guards --> Tracer
Tracer --> DiskTransport
DiskTransport --> Sandbox
Router --> MLAudit
Router -->|Execution Steps & State Deltas| Studio
Studio --> Player
BobPanel -->|POST /api/explain| Router
Router --> BobClient
BobClient -->|WatsonX Granite Inference| BobPanel
sys.settrace)TraceLens uses a two-level trace architecture to minimize runtime overhead:
event == 'call'). Evaluates the frame's co_filename against the dedicated sandboxed user string <tracelens_user_code>. Library code, standard library modules, and third-party dependencies are skipped entirely.line, call, return, and exception events.x: 0 -> 1). For collections, it logs additions/deletions. For DataFrames and ndarrays, it tracks dimensions (shape: (1000, 8)), column names, memory footprints, and null-value distributions.ast_flow.py)Before code executes, an AST visitor traverses the Python syntax tree:
For, While, If, and Try blocks.sandbox.py)multiprocessing.get_context("spawn"). No memory, file descriptors, or global states are shared between runs.terminate(), followed by a non-catchable kill() (SIGKILL).result.json via os.replace.RLIMIT_AS) is deliberately omitted in favor of container cgroups, allowing data-science libraries (numpy, pandas, scikit-learn, scipy, imbalanced-learn) to safely map BLAS/LAPACK contiguous blocks without process termination.package_installer.py)sklearn -> scikit-learn, imblearn -> imbalanced-learn, cv2 -> opencv-python).dataset.py)uploaded_datasets/) and automatically exposed to user scripts via relative path injection (pd.read_csv("data.csv")).POST /api/traceExecutes user code in the deterministic sandbox and returns the complete trace structure.
Request Body:
{
"code": "x = 10\nfor i in range(3):\n x += i",
"filename": "pipeline.py",
"timeout": 30.0,
"max_steps": 1000
}
Response Contract:
{
"status": "ok",
"total_steps": 7,
"steps": [
{
"step_index": 0,
"line_number": 1,
"code_line": "x = 10",
"event_type": "line",
"variables": { "x": 10 },
"variable_deltas": { "x": { "old": null, "new": 10 } },
"stdout": ""
}
],
"flow_index": { ... },
"safe_insertion_points": [ ... ],
"ml_audit": {
"issues": [ ... ],
"proposed_fix": "..."
}
}
POST /api/explainGrounded natural language explanation powered by IBM Granite 3.8B.
Request Body:
{
"code": "code snippet",
"current_line": 14,
"current_step": 6,
"step_context": { ... },
"selected_lines": [12, 13, 14],
"block_type": "loop",
"force_regenerate": false
}
POST /api/upload-datasetMultipart form upload for tabular datasets (.csv, .tsv, .parquet).
GET /health & GET /Returns service availability status ({"status": "ok"}).
git clone https://github.com/Omar-astro/Tracelens.git
cd Tracelens
# Copy environment configuration
cp .env.example .env
Add your credentials inside .env:
IBM_CLOUD_API_KEY=your_ibm_watsonx_api_key_here
BOB_MODEL_ID=ibm/granite-3-8b-instruct
# Create virtual environment
python -m venv venv
# Activate virtual environment
# Windows:
.\venv\Scripts\Activate.ps1
# Linux/macOS:
source venv/bin/activate
# Install dependencies
pip install -r backend/requirements.txt
# Start backend server
python backend/run.py
Backend will be live at http://localhost:8000. API documentation is available at http://localhost:8000/docs.
cd frontend
# Install frontend dependencies
npm install
# Start development server
npm run dev
Frontend will be live at http://localhost:5173.
# Run backend test suite (32+ unit and integration tests)
pytest tests/
The backend includes a production-ready Dockerfile and backend/run.py runner:
backend (or leave as /).IBM_CLOUD_API_KEY.$PORT and routes public traffic with automated SSL.The frontend is deployed as a Vite Single Page Application:
frontend.Vite.VITE_API_BASE_URLhttps://your-railway-backend-url.up.railway.appConfigfrontend/vercel.json automatically routes all browser navigations through /index.html..bobignore and .gitignore prevent credential leaks in commits or AI session logs.os, sys, subprocess, socket) and deletes file-opening builtins (open).Developed with pride for the IBM Bob 2.0 Hackathon (lablab.ai).
TraceLens — Bridging the gap between static code and dynamic runtime truth.
JavaScript
60.0%
Python
39.1%
TraceLens is an advanced, production-grade visual code tracer and runtime DSAI/ML auditor built for the IBM Bob 2.0 Hackathon (lablab.ai).
Static code analysis can only predict what might happen. TraceLens tells developers and data scientists what actually happened at runtime — recording every line execution, variable mutation, loop iteration, branch decision, tensor shape transition, and data-leakage flaw in real time, accompanied by contextual, zero-hallucination explanations powered by IBM Granite 3.8B.
https://tracelens-ivory.vercel.app)TraceLens features a dual-engine architecture:
Designed for algorithms, data structures, and general-purpose Python pipelines:
break/continue hooks.if/elif/else blocks, explicitly highlighting chosen vs. unvisited pathways.A specialized runtime auditor purpose-built for Data Science & Machine Learning pipelines:
scaler.fit_transform() across the entire dataset prior to train_test_split()).flowchart TD
subgraph Client["Frontend (React 19 + Vite + Tailwind CSS v4)"]
UI["Code Editor & Dataset Dropzone"]
Player["Time-Traveling Trace Player"]
Studio["LogicLens & ModelLens Studio"]
BobPanel["Bob AI Explainer & Diff Patcher"]
end
subgraph Server["TraceLens Backend (FastAPI on Railway)"]
Router["FastAPI Gateway (/api/trace, /api/explain)"]
ASTPass["AST Control-Flow Pre-Pass (ast_flow.py)"]
PkgMgr["Runtime Dependency Provisioner (package_installer.py)"]
Sandbox["Deterministic Execution Sandbox (sandbox.py)"]
Tracer["Deterministic Delta Engine (tracer.py)"]
MLAudit["ML Diagnostics & Taint Analyzer (ml_diagnostics.py)"]
BobClient["WatsonX Client (IBM Granite 3.8B)"]
end
subgraph Execution["Isolated Subprocess Boundary"]
Spawn["multiprocessing.get_context('spawn')"]
Guards["Restricted Builtins & sys.settrace Hook"]
DiskTransport["Atomic JSON Payload (result.json)"]
end
UI -->|POST /api/trace| Router
Router --> ASTPass
Router --> PkgMgr
Router --> Sandbox
Sandbox --> Spawn
Spawn --> Guards
Guards --> Tracer
Tracer --> DiskTransport
DiskTransport --> Sandbox
Router --> MLAudit
Router -->|Execution Steps & State Deltas| Studio
Studio --> Player
BobPanel -->|POST /api/explain| Router
Router --> BobClient
BobClient -->|WatsonX Granite Inference| BobPanel
sys.settrace)TraceLens uses a two-level trace architecture to minimize runtime overhead:
event == 'call'). Evaluates the frame's co_filename against the dedicated sandboxed user string <tracelens_user_code>. Library code, standard library modules, and third-party dependencies are skipped entirely.line, call, return, and exception events.x: 0 -> 1). For collections, it logs additions/deletions. For DataFrames and ndarrays, it tracks dimensions (shape: (1000, 8)), column names, memory footprints, and null-value distributions.ast_flow.py)Before code executes, an AST visitor traverses the Python syntax tree:
For, While, If, and Try blocks.sandbox.py)multiprocessing.get_context("spawn"). No memory, file descriptors, or global states are shared between runs.terminate(), followed by a non-catchable kill() (SIGKILL).result.json via os.replace.RLIMIT_AS) is deliberately omitted in favor of container cgroups, allowing data-science libraries (numpy, pandas, scikit-learn, scipy, imbalanced-learn) to safely map BLAS/LAPACK contiguous blocks without process termination.package_installer.py)sklearn -> scikit-learn, imblearn -> imbalanced-learn, cv2 -> opencv-python).dataset.py)uploaded_datasets/) and automatically exposed to user scripts via relative path injection (pd.read_csv("data.csv")).POST /api/traceExecutes user code in the deterministic sandbox and returns the complete trace structure.
Request Body:
{
"code": "x = 10\nfor i in range(3):\n x += i",
"filename": "pipeline.py",
"timeout": 30.0,
"max_steps": 1000
}
Response Contract:
{
"status": "ok",
"total_steps": 7,
"steps": [
{
"step_index": 0,
"line_number": 1,
"code_line": "x = 10",
"event_type": "line",
"variables": { "x": 10 },
"variable_deltas": { "x": { "old": null, "new": 10 } },
"stdout": ""
}
],
"flow_index": { ... },
"safe_insertion_points": [ ... ],
"ml_audit": {
"issues": [ ... ],
"proposed_fix": "..."
}
}
POST /api/explainGrounded natural language explanation powered by IBM Granite 3.8B.
Request Body:
{
"code": "code snippet",
"current_line": 14,
"current_step": 6,
"step_context": { ... },
"selected_lines": [12, 13, 14],
"block_type": "loop",
"force_regenerate": false
}
POST /api/upload-datasetMultipart form upload for tabular datasets (.csv, .tsv, .parquet).
GET /health & GET /Returns service availability status ({"status": "ok"}).
git clone https://github.com/Omar-astro/Tracelens.git
cd Tracelens
# Copy environment configuration
cp .env.example .env
Add your credentials inside .env:
IBM_CLOUD_API_KEY=your_ibm_watsonx_api_key_here
BOB_MODEL_ID=ibm/granite-3-8b-instruct
# Create virtual environment
python -m venv venv
# Activate virtual environment
# Windows:
.\venv\Scripts\Activate.ps1
# Linux/macOS:
source venv/bin/activate
# Install dependencies
pip install -r backend/requirements.txt
# Start backend server
python backend/run.py
Backend will be live at http://localhost:8000. API documentation is available at http://localhost:8000/docs.
cd frontend
# Install frontend dependencies
npm install
# Start development server
npm run dev
Frontend will be live at http://localhost:5173.
# Run backend test suite (32+ unit and integration tests)
pytest tests/
The backend includes a production-ready Dockerfile and backend/run.py runner:
backend (or leave as /).IBM_CLOUD_API_KEY.$PORT and routes public traffic with automated SSL.The frontend is deployed as a Vite Single Page Application:
frontend.Vite.VITE_API_BASE_URLhttps://your-railway-backend-url.up.railway.appConfigfrontend/vercel.json automatically routes all browser navigations through /index.html..bobignore and .gitignore prevent credential leaks in commits or AI session logs.os, sys, subprocess, socket) and deletes file-opening builtins (open).Developed with pride for the IBM Bob 2.0 Hackathon (lablab.ai).
TraceLens — Bridging the gap between static code and dynamic runtime truth.
JavaScript
60.0%
Python
39.1%