Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-24 06:53 UTC

ArcadeAI / safeword

Personal AI agent guides, templates, and learnings

TypeScriptKeine Lizenz erkannt★ 8 Sterne⑂ 2 Forksseit Okt. 2025Auf GitHub ansehen ↗

ArcadeAI/safeword erreicht einen Gesundheitsindex von 62 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (88/100) ab, am schwächsten bei Community & Adoption (30/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

62
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

62
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Arcade.devOrganisation
290 Follower82 öffentliche Reposseit Dez. 2023

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
npmsafeword0.69.07.036158vor 5 Tagenclisafeworddeveloper-experiencelintingclaude-code

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

88Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
24.2/36Commit-Rhythmus — 35/52 Wochen mit Commits
18/18Commit-Volumen — 2.371 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year2.371
human_commit_share0,94
days_since_last_push0
active_weeks_last_year35
Wie die Bewertung erfolgt
16.2/27Liefert Releases aus — 48 Versions-Tags (keine GitHub-Releases)
36/36Release-Aktualität — letztes Release vor 5 Tagen
27/27Release-Rhythmus — ein Release etwa alle 2,6 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count48
latest_release_tagv0.69.0
releases_from_tagsja
days_since_latest_release5
mean_days_between_releases2,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

30Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
13.7/60Stars — 8 Stars
0/25Forks — 2 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks2
stars8
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
0/22.5Lizenz — keine Lizenzdatei erkannt
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licensenein
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
51.3/80Downloads pro Monat — 7.036 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagessafeword
dependents
ecosystemsnpm
total_downloads
monthly_downloads7.036
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

57Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
5.2/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 77 % der Commits
4.1/13.5Breite der Beitragenden — 3 Beitragende
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Verwendete Eingangsdaten
bus_factor1
contributors_sampled3
top_contributor_share0,767
Wie die Bewertung erfolgt
18.5/46.8Issue-Lösungsquote — 40 % der Issues geschlossen
34/38.3PR-Annahme — 469/527 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 1/27 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs469
open_issues518
closed_issues340
issue_closed_ratio0,396
closed_unmerged_prs58
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
17.7/25Reichweite des Inhabers — 290 Follower von ArcadeAI
18.2/25Kontohistorie — 82 öffentliche Repos, Kontoalter ca. 2 Jahre
Verwendete Eingangsdaten
followers290
owner_typeOrganization
is_verified
owner_loginArcadeAI
public_repos82
account_age_days957

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 5 Tagen
20/20Versionshistorie — 158 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagessafeword
ecosystemsnpm
any_deprecatednein
min_days_since_publish5

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

72Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 5 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — eslint.config.mjs, ruff.toml
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://arcadeai.github.io/safeword/
10/10Repository-Beschreibung
0/10Topics
0/10Wiki
Verwendete Eingangsdaten
topics
has_wikinein
homepagehttps://arcadeai.github.io/safeword/
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

59Mittel · 16 % des Gesamtindex

Sicherheitslage

49Gefährdet
Wie die Bewertung erfolgt
3/7.5Binary-Artifacts — binaries present in source code
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/27 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Lizenz — license file not detected
7.5/7.5Maintained — 30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4,8
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): signed_releases. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages292
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:safeword@0.69.0 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 292 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

74Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — .cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 94 von 94 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_files.cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md
agent_instruction_max_bytes11.149
Wie die Bewertung erfolgt
12.6/18Bootstrap mit einem Befehl — experiments/go-skill-directive/checker/go.mod (Toolchain-Konvention, kein Task-Runner)
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — eslint.config.mjs, ruff.toml
11/11Statische Typprüfung — packages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json
0/10Reproduzierbare Umgebung
10/10Belegte Agentenpraxis — 74 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
8/8Automatisierte Wartung — 6 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
1/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfiles
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_configja
typecheck_configspackages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json
agent_commit_share0,74
toolchain_manifestsexperiments/go-skill-directive/checker/go.mod
dependency_bot_commit_share0,06
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
54.7/55Handhabbare Dateigrößen — 4/855 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes74.384
source_files_sampled855
oversized_source_files4
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
20/20MCP-Server
0/40Lauffähige Beispiele
Verwendete Eingangsdaten
example_dirs
has_mcp_signalja
api_schema_files

Eckdaten

8GitHub-Sterne
3Mitwirkende
2.371Commits, letzte 12 Monate
0Tage seit letztem Push
48Releases
1Bus-Faktor
518offene Issues
npm, PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 2 ⇿
0Sterne
2Forks
9Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

111222212026-062026-062026-06
Major 0Minor 8Patch 1
OpenSSF Scorecard 4.8 / 10
4.8Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-24 06:53 UTC

4Binary-Artifactsbinaries present in source code
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/27 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
1Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
Direkte Abhängigkeiten 34
RegistryPaketVersionsvorgabeManifest
npm@cucumber/gherkin^41.0.0packages/cli/package.json
npm@cucumber/messages^34.0.1packages/cli/package.json
npm@eslint-community/eslint-plugin-eslint-comments^4.7.2packages/cli/package.json
npm@eslint-react/eslint-plugin5.14.6packages/cli/package.json
npm@eslint/js^10.0.1packages/cli/package.json
npm@next/eslint-plugin-next16.2.10packages/cli/package.json
npm@secretlint/core^13.0.2packages/cli/package.json
npm@secretlint/secretlint-rule-preset-recommend^13.0.2packages/cli/package.json
npm@tanstack/eslint-plugin-query5.101.2packages/cli/package.json
npm@vitest/eslint-plugin1.6.23packages/cli/package.json
npmcommander15.0.0packages/cli/package.json
npmeslint-config-prettier^10.1.8packages/cli/package.json
npmeslint-import-resolver-typescript^4.4.5packages/cli/package.json
npmeslint-plugin-astro~2.1.1packages/cli/package.json
npmeslint-plugin-better-tailwindcss4.6.1packages/cli/package.json
npmeslint-plugin-import-x^4.17.1packages/cli/package.json
npmeslint-plugin-jsdoc^63.0.13packages/cli/package.json
npmeslint-plugin-playwright2.10.5packages/cli/package.json
npmeslint-plugin-promise^7.3.0packages/cli/package.json
npmeslint-plugin-react-hooks^7.1.1packages/cli/package.json
npmeslint-plugin-regexp3.1.1packages/cli/package.json
npmeslint-plugin-security4.0.1packages/cli/package.json
npmeslint-plugin-simple-import-sort^14.0.0packages/cli/package.json
npmeslint-plugin-sonarjs4.1.0packages/cli/package.json
npmeslint-plugin-storybook10.5.0packages/cli/package.json
npmeslint-plugin-turbo2.10.4packages/cli/package.json
npmeslint-plugin-unicorn72.0.0packages/cli/package.json
npmsmol-toml1.7.0packages/cli/package.json
npmtypescript-eslint8.63.0packages/cli/package.json
npmyaml^2.9.0packages/cli/package.json
npm@astrojs/starlight^0.41.1packages/website/package.json
npmastro^7.0.7packages/website/package.json
npmastro-mermaid^2.1.0packages/website/package.json
npmmermaid^11.16.0packages/website/package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 0

Die Installation von npm:safeword@0.69.0 zieht 292 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 14739,
      "has_wiki": false,
      "homepage": "https://arcadeai.github.io/safeword/",
      "languages": {
        "Go": 710,
        "CSS": 14599,
        "MDX": 61935,
        "Shell": 35402,
        "Python": 12793,
        "Gherkin": 365477,
        "JavaScript": 42262,
        "TypeScript": 5860967,
        "Go Template": 605
      },
      "pushed_at": "2026-07-24T06:03:53Z",
      "created_at": "2025-10-27T03:36:25Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T05:43:07Z",
      "description": "Personal AI agent guides, templates, and learnings",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://docs.arcade.dev",
      "name": "Arcade.dev",
      "type": "Organization",
      "login": "ArcadeAI",
      "company": null,
      "location": "United States of America",
      "followers": 290,
      "avatar_url": "https://avatars.githubusercontent.com/u/153409375?v=4",
      "created_at": "2023-12-10T03:38:49Z",
      "is_verified": null,
      "public_repos": 82,
      "account_age_days": 957
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.69.0",
          "kind": "minor",
          "published_at": "2026-07-18T20:57:56Z"
        },
        {
          "tag": "v0.68.0",
          "kind": "minor",
          "published_at": "2026-07-07T21:47:32Z"
        },
        {
          "tag": "v0.67.0",
          "kind": "minor",
          "published_at": "2026-07-07T05:48:35Z"
        },
        {
          "tag": "v0.63.0",
          "kind": "minor",
          "published_at": "2026-07-04T06:17:29Z"
        },
        {
          "tag": "v0.62.0",
          "kind": "minor",
          "published_at": "2026-07-03T02:33:29Z"
        },
        {
          "tag": "v0.61.0",
          "kind": "minor",
          "published_at": "2026-07-02T19:18:23Z"
        },
        {
          "tag": "v0.60.0",
          "kind": "minor",
          "published_at": "2026-07-01T15:50:40Z"
        },
        {
          "tag": "v0.59.0",
          "kind": "minor",
          "published_at": "2026-07-01T01:09:06Z"
        },
        {
          "tag": "v0.58.0",
          "kind": "minor",
          "published_at": "2026-06-26T13:32:39Z"
        },
        {
          "tag": "v0.57.0",
          "kind": "minor",
          "published_at": "2026-06-25T00:51:17Z"
        },
        {
          "tag": "v0.56.0",
          "kind": "minor",
          "published_at": "2026-06-24T18:18:47Z"
        },
        {
          "tag": "v0.55.0",
          "kind": "minor",
          "published_at": "2026-06-23T00:46:41Z"
        },
        {
          "tag": "v0.54.0",
          "kind": "minor",
          "published_at": "2026-06-21T14:04:28Z"
        },
        {
          "tag": "v0.52.1",
          "kind": "patch",
          "published_at": "2026-06-18T19:31:24Z"
        },
        {
          "tag": "v0.52.0",
          "kind": "minor",
          "published_at": "2026-06-18T14:39:39Z"
        },
        {
          "tag": "v0.51.0",
          "kind": "minor",
          "published_at": "2026-06-18T01:51:32Z"
        },
        {
          "tag": "v0.49.0",
          "kind": "minor",
          "published_at": "2026-06-16T05:52:57Z"
        },
        {
          "tag": "v0.48.0",
          "kind": "minor",
          "published_at": "2026-06-15T23:53:12Z"
        },
        {
          "tag": "v0.47.0",
          "kind": "minor",
          "published_at": "2026-06-14T04:47:11Z"
        },
        {
          "tag": "v0.46.2",
          "kind": "patch",
          "published_at": "2026-06-13T17:27:28Z"
        },
        {
          "tag": "v0.46.1",
          "kind": "patch",
          "published_at": "2026-06-13T14:24:51Z"
        },
        {
          "tag": "v0.46.0",
          "kind": "minor",
          "published_at": "2026-06-13T01:24:00Z"
        },
        {
          "tag": "v0.45.0",
          "kind": "minor",
          "published_at": "2026-06-12T17:57:53Z"
        },
        {
          "tag": "v0.44.0",
          "kind": "minor",
          "published_at": "2026-06-12T13:31:44Z"
        },
        {
          "tag": "v0.43.0",
          "kind": "minor",
          "published_at": "2026-06-10T21:51:51Z"
        },
        {
          "tag": "v0.42.0",
          "kind": "minor",
          "published_at": "2026-06-05T18:24:38Z"
        },
        {
          "tag": "v0.41.0",
          "kind": "minor",
          "published_at": "2026-06-01T18:25:08Z"
        },
        {
          "tag": "v0.40.1",
          "kind": "patch",
          "published_at": "2026-06-01T16:56:13Z"
        },
        {
          "tag": "v0.40.0",
          "kind": "minor",
          "published_at": "2026-06-01T15:53:00Z"
        },
        {
          "tag": "v0.39.1",
          "kind": "patch",
          "published_at": "2026-05-28T04:44:41Z"
        },
        {
          "tag": "v0.39.0",
          "kind": "minor",
          "published_at": "2026-05-27T00:25:41Z"
        },
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2026-05-26T05:51:32Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2026-05-26T05:33:07Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2026-05-25T16:46:34Z"
        },
        {
          "tag": "v0.35.2",
          "kind": "patch",
          "published_at": "2026-05-24T15:01:15Z"
        },
        {
          "tag": "v0.35.1",
          "kind": "patch",
          "published_at": "2026-05-23T05:27:00Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2026-05-23T00:35:39Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2026-05-18T18:46:28Z"
        },
        {
          "tag": "v0.32.1",
          "kind": "patch",
          "published_at": "2026-05-18T01:50:06Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-05-18T01:18:52Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-05-15T19:17:55Z"
        },
        {
          "tag": "v0.30.3",
          "kind": "patch",
          "published_at": "2026-05-14T15:34:43Z"
        },
        {
          "tag": "v0.30.2",
          "kind": "patch",
          "published_at": "2026-05-13T19:51:03Z"
        },
        {
          "tag": "v0.30.1",
          "kind": "patch",
          "published_at": "2026-05-06T14:46:03Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2025-12-05T22:42:01Z"
        },
        {
          "tag": "v0.7.4",
          "kind": "patch",
          "published_at": "2025-12-05T22:07:08Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2025-12-05T21:41:21Z"
        },
        {
          "tag": "v0.0.1",
          "kind": "patch",
          "published_at": "2026-01-10T01:53:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "625c1d47ad5fa546cea7792ce976ec1208941a72",
          "body": "* chore(deps): bump eslint-plugin-unicorn from 71.1.0 to 72.0.0\n\nBumps [eslint-plugin-unicorn](https://github.com/sindresorhus/eslint-plugin-unicorn) from 71.1.0 to 72.0.0.\n- [Release notes](https://github.com/sindresorhus/eslint-plugin-unicorn/releases)\n- [Commits](https://github.com/sindresorhus/e\n[…]\nror opt-outs in base.ts.\n\n---------\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: T <t@t.com>",
          "is_bot": true,
          "headline": "chore(deps): bump eslint-plugin-unicorn from 71.1.0 to 72.0.0 (#1142)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T05:42:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58d966598b063efe4cc56d7af251fc02d9fd6cd2",
          "body": "* Record RED for invalid Codex marketplace scenario\n\n* GREEN classify invalid Codex marketplace installs\n\n* Record GREEN for invalid Codex marketplace scenario\n\n* Record refactor decision for invalid Codex marketplace scenario\n\n* RED expose Safe Word Codex plugin skills\n\n* Record RED for Codex plugi\n[…]\n: cover repeated plugin installs\n\n* chore: refresh audit tooling\n\n* docs: restore tracker integration reference\n\n* docs(architecture): refresh generated CLI map\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Let Codex users install Safe Word without a migration (#1368)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:48:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d158a836ff94cc8aaccb7388dec4f7d360237632",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore: close DDFA7X ticket (#1369)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:13:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9450465b8ad6123f0f5bb4e0e25e731571661a28",
          "body": "* feat(retro): dedupe cloud-spooled drafts canonically\n\n* test(retro): verify canonical spool dedupe\n\n* chore(retro): reconcile verification ledger\n\n* fix(retro): enforce canonical marker integrity\n\n* fix(retro): route Codex filer through packaged skill\n\n* chore(retro): record canonical dedupe evide\n[…]\n canonicalSignature is a hash of the normalized repro,\nnever raw finding text.\n\nFixes the sole failing test on this branch (360 files passed, 1 failed pre-fix).\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Keep cloud-spooled retro filing from bypassing duplicate checks (#1092)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:07:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c406c90b2490a31f362642e260c29ae1ade74557",
          "body": "* fix: recognize default BDD lanes\n\n* chore(8B4GVR): flip ticket to done — done-gate closure\n\nIndependent review confirmed all Done-When behaviors are covered by\npassing assertions and CI is green on node 22/24. Clears the\ndone-flip gate blocking PR #1365.\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Recognize default BDD lanes without configuration (#1365)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:00:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01e6553b4322ac93cdc55ab75f72b1daf322a59f",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "fix(cursor): record relative skill proof (#1343)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-23T23:40:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "659ed1cac9ab813af7982eec18a218f429fb36ce",
          "body": "* fix(audit): discover nested native manifests\n\n* fix(audit): honor workspace Knip configs\n\n* fix(audit): prune standard environment trees\n\n* refactor(audit): share file discovery traversal\n\n* fix(codex-plugin): refresh audit skill asset\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Fix native-stack discovery in audit skill (#1310)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-23T23:38:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25508117af8555e95559d3f4ab3087abfc01e663",
          "body": "* Fix E008 feature lane coverage\n\n* Harden E008 resolver fallback\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Scan all feature lanes for E008 drift (#1277)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T05:00:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1c4733287154801c39d83d44538786676e01ed3",
          "body": "… (KKNFZA) (#1086)\n\n* feat(DGH59K): tracker identity + join — off-board ticketing increment (KKNFZA)\n\nDeliver the done child DGH59K of epic KKNFZA (off-board local ticketing)\nonto current main as a focused, self-contained increment. Issue-first ticket\nidentity: with a GitHub/Linear tracker connected\n[…]\nerate after merging main (codex-plugin modules)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(DGH59K): tracker identity + join — off-board ticketing increment…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T04:36:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4e88ce7e58b178977dc31d565fcf76bbe99907ee",
          "body": "… (#1332)\n\nFollow-up to #1243. Two accuracy fixes in the Claude Code Cloud surface entry:\n\n- The `+ → Add from GitHub` repo picker belongs to the claude.ai\n  Projects/Chats GitHub knowledge-file integration, not claude.ai/code.\n  On Claude Code on the web, repos appear in a selector below the input\n\n[…]\n with' said 'reclaimed container' while this entry's own\n  Description says 'Anthropic-managed VM' — aligned to VM.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(surfaces): correct Claude Code Cloud repo-onboarding + VM wording…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T03:36:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "20a37f2eb45810c8dac5554311cf073be9558990",
          "body": "…ear E008 surface drift (#1243)\n\n* fix(surfaces): rename Claude Code on the Web to Claude Code Cloud\n\nThe cloud surface now covers both Anthropic-hosted cloud sessions and\nClaude Code GitHub Actions, so \"on the Web\" no longer describes it.\nRename the surface and retag its references.\n\nCorrect two wr\n[…]\nface-drift references in packages/cli/features.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(surfaces): rename Claude Code on the Web to Claude Code Cloud; cl…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T02:30:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a9f2d0ae27be3d3ab5e90f9f90fe66db45a61573",
          "body": "Follow-ups from the independent review of #1260, filed as #1284.\n\n**Coverage was attributed to every changed file, not the selecting ones**\n(#1284.1). A config ran if it covered *any* changed file, so a session\ntouching both `.safeword/hooks/` and `packages/cli/` let the root config\nride in on the p\n[…]\nten failing first), stop-typecheck-gate integration 3/3,\nlint clean, parity 190 pairs + 8 contracts, 22/22 release.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): judge each tsconfig by the files that selected it (#1289)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T01:58:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7bf1e827ed1037f2bed1ea8967624da493632137",
          "body": "* docs(WNMCH1): add §8 product-management + design role plugins\n\nFold Anthropic's knowledge-work role playbooks (product-management, design)\ninto the comparison: per-skill teardown, plus new borrow candidates G7\n(connector-agnostic ~~category pattern) and S6 (write-spec PM rigor →\nspec/self-review).\n[…]\nand PR #1290\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AkABNy1kurs3nAoX8PYCLL\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(WNMCH1): add product-management + design role plugins (§8) (#1290)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T01:57:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6426b6e82a5cfb603746d8d1640dcd02c70fabc4",
          "body": "…#1260)\n\n* fix(hooks): check the configs that actually cover the changed files\n\nThe implement-stop typecheck gate picked a tsconfig by proximity alone.\n`findTsconfigUp` returns the nearest `tsconfig.json` at or above a changed\nfile, and nothing asked whether that config covers the file it started\nfr\n[…]\n parity 190 pairs +\n8 contracts, 22/22 release.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): check the configs that actually cover the changed files (…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-21T13:50:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c72d8474f4199931ac8597c8231a4b0f42c95004",
          "body": "…ons (#1229)\n\nTwo follow-ups from the #1210 review.\n\n**The remedy command was wrong where it is read.** #1209 shipped\n`bun run --cwd packages/cli generate:codex-plugin`. That flag resolves\nagainst the caller's cwd, so it only works from the repo root — and fails\nwith `ENOENT: Could not change direct\n[…]\nrelease, lint clean, parity 190 pairs + 8 contracts in\nsync, corrected command confirmed working from packages/cli.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(codex-plugin): correct the drift remedy; pin out repo-only citati…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T18:47:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f40541401a9cffe0c343b2fc1cea3b2338c27ef",
          "body": "…needs (#1225)\n\n`tsc -p tsconfig.json` at the repo root reported 88 errors on a clean\ncheckout. Every one was a missing modern-lib member — `toSorted` /\n`toReversed` (ES2023), `Iterator.toArray` (ESNext.Iterator), and\n`Set.difference` (ESNext.Collection) — in files nobody had touched.\n\nThe root conf\n[…]\nrified: root `tsc -p tsconfig.json` 88 -> 0, root `eslint .` clean,\n`packages/cli` lint clean, 22/22 release tests.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tsconfig): give the root config the lib settings its own include …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T18:36:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b15ea0501e0f55af9d5afe6f5370442c2839e332",
          "body": "…rd's own churn against the user (#1228)\n\n* fix(hooks): stop the self-report Stop wake loop; exempt .agents/ + .codex/ from the LOC gate\n\nTwo compounding bugs observed live on 0.68.0 → 0.69.0: the LOC gate\nproduced a signal that the self-report Stop hook then looped on for\n~1h40m, the agent replying\n[…]\nan; 187 tests green across the affected suites.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): stop the self-report Stop wake loop; stop counting safewo…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T18:07:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03838402e16e6d5f549803b57d8e09365757a28c",
          "body": "All three catalogue assertions reported which asset was wrong but not what\nto do about it, so hitting one cost a full investigation to rediscover\n`generate:codex-plugin` — which is documented in README.md but not at the\npoint of failure.\n\nAppends a shared remedy line to the missing / unexpected / dr\n[…]\noper command is the right remedy to name.\n\nVerified: 22/22 release tests, 83 BDD scenarios / 986 steps, lint clean.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(codex-plugin): name the remedy in catalogue drift errors (#1209)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T17:08:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "42158544c7976ca4b7c1bda3cabd43443997883e",
          "body": "…s (#1210)\n\nPRINCIPLES.md lives only at the safeword repo root. It is not in\ntemplates/, has no entry in ConfiguredPathKey (personas | glossary |\nsurfaces | architecture), and is never installed into a customer project.\nSo `(PRINCIPLES.md §1)` in audit/ and verify/ pointed customers at a file\nthey d\n[…]\nrified: 170 tests across the 6 suites that read these files, 22/22\nrelease, parity 190 pairs + 8 contracts in sync.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(skills): drop dangling PRINCIPLES.md citations from shipped skill…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T17:07:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "498f49bbd067b57abf0fb7df5a33af96a0616ed9",
          "body": "Adds a fast, deterministic unit guard for the detection rule fixed in #993:\na fresh non-JS project whose only .sh files are vendored by safeword (its own\nscripts + an auto-installed language skill under .claude/.agents) must NOT be\ndetected as a shell project — otherwise the post-setup health check \n[…]\nd; this pins the detector contract\ndirectly (detectProjectType().shell) so a regression localizes fast and offline.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(setup): guard shell detection against vendored .sh files (#1123)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T05:43:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c84ba658b4ebf75b8ba047e2d9e8a5d630d04fba",
          "body": "* docs(quality-review): trim skill bloat (151→137 lines)\n\nRemove redundancy per Anthropic skill-authoring best-practices (concise-is-key).\nDedupe the hook-vs-skill explanation (3-4x -> 1), the fresh-reviewer\nindependence rule (4x -> 1), and the couple-of-passes cap (3x -> 1); tighten\ninvocation-log \n[…]\nn unrelated pre-existing #993 test-harness bug.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Trim skill bloat; generalize quality-review to any work-product (#1122)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T05:43:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bc822b0538eb135af4f151588e6f5dbd9aefd5e3",
          "body": "…NMCH1) (#1160)\n\n* docs(ticket): file Anthropic plugins vs safeword comparison (WNMCH1)\n\nCapture a thorough compare/contrast of Anthropic's 13 claude-code\nplugins against safeword's capability surface as ticket WNMCH1.\nResearch artifact only; no code changes.\n\nCo-Authored-By: Claude Opus 4.8 <norepl\n[…]\n candidates.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AkABNy1kurs3nAoX8PYCLL\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(ticket): Anthropic claude-code plugins vs safeword comparison (W…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-19T20:33:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f45e8c0a201fa84b14db6f764351c0189aba47ea",
          "body": "Bumps the github-actions group with 2 updates: [actions/setup-node](https://github.com/actions/setup-node) and [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-node` from 6 to 7\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://git\n[…]\nsion-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the github-actions group with 2 updates (#1139)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T11:47:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e423ef2bf7b20f27e06a99056140d7a3e0544d98",
          "body": "…0.0 (#1141)\n\nBumps [eslint-plugin-simple-import-sort](https://github.com/lydell/eslint-plugin-simple-import-sort) from 13.0.0 to 14.0.0.\n- [Changelog](https://github.com/lydell/eslint-plugin-simple-import-sort/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/lydell/eslint-plugin-simple-import\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump eslint-plugin-simple-import-sort from 13.0.0 to 14.…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T01:56:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ad671373ab0af668c88ef940cb4b027f9e8ad31",
          "body": "Bump to 0.69.0 across package.json, marketplace.json, codex plugin.json, and hooks.json. Ships #993 Codex packaged-plugin migration + #1128 hardening.",
          "is_bot": false,
          "headline": "chore(release): v0.69.0 (#1124)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-18T20:57:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a05b1433c8ea076352b6307b14b2b3517b57b20",
          "body": "…rministic BDD (#1128)\n\nVerify/audit/refactor hardening over the #993 Codex migration: document smol-toml dep, clean async-action error handling via parseAsync (fixes stack-trace errors + spurious self-reports), knip ignore hygiene, and a deterministic 'Bun is unavailable' BDD scenario (fixes a CI flake). CI green.",
          "is_bot": false,
          "headline": "chore: 0.69 release hardening — parseAsync errors, knip hygiene, dete…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-18T20:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a94d77846cb9eaabb42ee671394ba24d4c42cfc5",
          "body": "Migrates Codex Safe Word from repo-local skill/hook files to a packaged Codex plugin plus the `safeword hook codex` / `migrate codex-plugin` CLI entrypoints. Plugin hooks run pinned `bunx --bun safeword@<version>` commands; version-sync is guarded across manifests + hooks.json. Upgrade preserves legacy runtime files for an explicit, reviewed handoff (`--remove-legacy-hooks`). Reviewed across multiple passes; CI green (lint + test node 22/24).",
          "is_bot": false,
          "headline": "feat(codex): migrate Safe Word to packaged plugin hooks (#993)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-18T16:00:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "344667ebd04eef129977f11b41f6214cf6eee74a",
          "body": "Prevent duplicate upstream GitHub issues when a recurring retro finding's title\ndrifts across sessions.\n\n- Add a second hidden marker keyed only on the normalized repro\n  (`canonical:<hash>`) alongside the existing title-based signature marker.\n- triage dedupes legacy-signature-first, then falls bac\n[…]\nner (\"if it's good merge\"); review requirement\nbypassed at their explicit instruction. 1 behind main = the just-merged #1053\n(unrelated files).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(A8NNZV): dedupe recurring retro findings by canonical repro (#1065)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-16T20:23:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "954f37c0d72acbd714c10e9339a772ccac3e7723",
          "body": "…ity (#1053)\n\nDerive new persona codes as canonical 3-4 characters and carry them unchanged\nfrom personas.md through JTBD IDs and Gherkin Rule tags.\n\n- CLI policy (personas.ts): canonical derivation, bounded deterministic\n  collision suffixes, non-throwing `codeError` discriminator so `safeword\n  ch\n[…]\nw\nrequirement bypassed at their explicit instruction. All checks green on head\n631b4266 (lint, test node 22.22.3, test node 24); 0 behind main.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(FAJV19): canonical 3-4 char persona codes with legacy compatibil…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-15T14:10:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "589b262308d769447a96f663053cba77cff03678",
          "body": "* refactor(R4S85Y): rename DEV persona code to TB across the corpus\n\nEliminate the redundant DEV persona code (DEV and TB name the same technical-\ndeveloper persona; PR #1040 review). Mechanical, collision-free rename:\n- DEV<n> -> TB<n>: 828 occurrences (JTBD/rule ids, @slug feature tags, .ts test\n \n[…]\n (parity restored), test:bdd 407 / 0 undefined.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: rename DEV persona code to TB across the corpus (#1052)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T18:41:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7eb638f0e9c1ac7c3a57be7a3121398b95b3725d",
          "body": "…+ drift (#1038)\n\n* docs(N0W5KG): intake + scenarios + plan for audit domain-docs check\n\nFeature: /audit checks personas/surfaces/glossary for emptiness (W008),\nsurface drift (E008), persona drift (E009). Design via /figure-it-out\n(pure-prose bash block, no new CLI code). 15 scenarios, two rounds of\n[…]\nipped\nthe earlier verify — noted for the retro.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit: check personas/surfaces/glossary namespace docs for emptiness …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T18:29:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2139ad76be22159ee18fa25f1f2da8ca50a3c560",
          "body": "feature-surfaces-bdd.feature tags @surface.safeword-cli on 3 tag lines but\nsurfaces.md had no matching entry (E008 drift surfaced by the new audit check).\nThe safeword CLI is a distinct CLI-kind surface — its own setup/upgrade/check/\nreconcile behaviors, harness-agnostic — not an agent runtime. Slug resolves;\n121 surface/persona tests green.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(P9Z3P7): add Safeword CLI surface to surfaces.md (#1039)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T04:13:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9511dca4485588048882a1e75ef465c733acd630",
          "body": "…9S30R) (#1016)\n\n* test(retro): live-lane smoke for reconcile version-provenance path\n\nAdd a token-gated live test asserting createReconcileTransport(token)\n.resolveTagDate('v0.68.0') returns the tag's real commit date against the\nreal GitHub API. This is the one reconcile path that never runs in CI\n[…]\necorded in verify.md.\n\nRefs #791, ticket B9S30R\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(retro): live-lane smoke for reconcile version-provenance path (B…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T04:13:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0066461ad62b251394138662a99bde089f655b75",
          "body": "Bumps the bun-minor-patch group with 2 updates in the / directory: [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) and [@eslint-react/eslint-plugin](https://github.com/Rel1cx/eslint-react/tree/HEAD/plugins/eslint-plugin).\n\n\nUpdates `dependency-cruiser` from 18.0.0 to 18.1.0\n- [R\n[…]\nion-update:semver-patch\n  dependency-group: bun-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the bun-minor-patch group with 2 updates (#1010)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T04:28:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dcf735dee1764c3d928a2af713af65e370701d8",
          "body": "Claude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): close FG6V57 — session-token rule merged (#992) (#1011)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-13T04:28:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "11d868eb5edff63d609c42bd16146546ce57c4ea",
          "body": "* fix: repair Codex retro extraction\n\n* chore(ticket): mark codex retro runtime done\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Fix Codex retro extraction outside git worktrees (#960) (#994)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-13T04:21:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "198a8d35d6e78bf3062dc6f6aa7c7899bf6e96ae",
          "body": "Rebased #995 onto current main (which now carries #996 @cucumber/messages 34\nand #998 eslint-plugin-unicorn 71). The 12 minor/patch bumps apply cleanly;\nthe one dependencies-block conflict was resolved as the union — kept main's\neslint-plugin-unicorn 71.1.0, took the group's storybook/turbo/typescript-eslint\nbumps. bun.lock regenerated (--lockfile-only) from the merged manifests.\nReviewed SAFE (all 12 minor/patch, no hidden major, no Node-floor change).\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(deps): bump the bun-minor-patch group with 12 updates (#1009)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-13T02:12:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "446071eed24b5b11b71fb077b7572bb174d87aa1",
          "body": "Bumps [eslint-plugin-unicorn](https://github.com/sindresorhus/eslint-plugin-unicorn) from 70.0.0 to 71.1.0.\n- [Release notes](https://github.com/sindresorhus/eslint-plugin-unicorn/releases)\n- [Commits](https://github.com/sindresorhus/eslint-plugin-unicorn/compare/v70.0.0...v71.1.0)\n\n---\nupdated-depe\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump eslint-plugin-unicorn from 70.0.0 to 71.1.0 (#998)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T01:19:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d61b0b1c1a9c51a70ab80df7d4b9bfa5ca524de",
          "body": "Bumps [@cucumber/messages](https://github.com/cucumber/messages) from 33.0.4 to 34.0.1.\n- [Release notes](https://github.com/cucumber/messages/releases)\n- [Changelog](https://github.com/cucumber/messages/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/cucumber/messages/compare/v33.0.4...v34.0\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @cucumber/messages from 33.0.4 to 34.0.1 (#996)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T01:18:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b14e9e0c505c492095075057304a66dff8ba3dc4",
          "body": "* fix(retro): one session-token rule, pinned by parity contract (FG6V57)\n\nThree sanitizers had drifted (charset, strip-vs-substitute, missing cap).\nOne rule now: substitute non-[\\w.-] to _, cap 80, fallback 'unknown' —\ntriage's public ledger token and the spool filename gain the missing\nlength bound\n[…]\nee-stage pass\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro: one session-token rule, pinned by parity contract (FG6V57) (#992)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-12T23:55:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "876a4a290fc10c4f42e323f7a10c911ac1d1a60f",
          "body": "PR #990 merged; first workflow_dispatch run green in 49s with the done-when\nsummary line (89 issues swept, 0 failed). Daily cron armed on main.\n\n\nClaude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): close 4KP67A — reconcile sweep scheduled and live (#991)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T22:55:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "30cd3d6cdcaf02da7b4ce7d6fb97de71d34349a8",
          "body": "Documents the plan-implementation phase (#988/#480) across the flow docs:\nSAFEWORD.md + planning-guide (dogfood + template mirrors), the website\nworkflow flowchart/prose, and the config reference's review-gate section.\nRebuilt cleanly on main after #988's squash-merge; dogfood planning-guide\nsynced \n[…]\ny\nis prettier-ignored, so the table realign had to be copied over — the drift\nthe release-gate parity test caught).\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: seven-phase flow + four-gate inventory (#989)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T22:54:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8f11e9a935ff982b7b55b81d1e0ae56b6bced14b",
          "body": "…80) (#988)\n\n* ticket(TXRHMD): intake — spec for plan-implementation phase (#480)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* ticket(TXRHMD): intake — cold-start check gaps appended, goal + work log\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* ticket(TXRHMD): define-beha\n[…]\nprovenance+parity green; mirrors byte-identical.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add plan-implementation phase between scenario-gate and implement (#4…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T22:10:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90a0c7e04e93ce06e94a0faf33ce200f544440bb",
          "body": "* ci: schedule the retro-reconcile sweep daily (4KP67A, #791 follow-up)\n\nNew standalone workflow: daily 06:17 UTC cron + workflow_dispatch,\npermissions {issues:write, contents:read}, non-cancelling concurrency\ngroup, runs the CLI from source with the Actions token. Fails loudly on\nmissing/broken aut\n[…]\ner side textually conflicts. Regenerated via\ntree-source sync-tickets so the index reflects current ticket state.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "CI: schedule the retro-reconcile sweep daily (4KP67A) (#990)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T20:17:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8890cf51a7bb78b0331e556d4c5bd8118a6df002",
          "body": "… KQ3MRV, HRDN42) (#967)\n\n* ticket(EDDABK): behavioral diff + panel-verified unification decision\n\n45-command corpus diff (9 divergence classes), 3-lens adversarial panel:\nsingle superset tokenizer, zero pinned-test flips, two companion gate\nfixes required (kill-guard bareName backslash strip, class\n[…]\n-review APPROVE; branch-staleness basename added.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(hooks): unify shell tokenizers + harden Bash gates (EDDABK #948,…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:58:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9601aebc4f8b61c09760dc8ce2337f992794da3f",
          "body": "…t-SHA reachability (HGYGND) (#964)\n\n* docs(ticket): park artifact-content phase-anchor redesign at intake, blocked on #810\n\nDesign-session record for the phase-provenance primitive redesign\n(core cluster #813/#815/#814/#816, epic #808): audit table of the five\nforward transitions against their comm\n[…]\nrtifact pair.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01DvXuj3us862ZSZxqxfxJQs\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Artifact-content phase anchors: tree-verified evidence replaces commi…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:56:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "85f168334f2ab9b9c8637e6f4325c0562d56a438",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Close M8NNX0 ticket after #928 (#968)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:32:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69e5418b878ea7855e26f3a86e7ad7c265b0b479",
          "body": "* Single lint-staged config + deterministic shellcheck lane (#966)\n\nThe package.json lint-staged block was dead config — lint-staged resolves\nsame-directory configs alphabetically, so lint-staged.config.mjs always\nshadowed it — yet it alone carried the shellcheck guard. Deleted the dead\nblock; porte\n[…]\ng fix (#966).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01DvXuj3us862ZSZxqxfxJQs\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Single lint-staged config + deterministic shellcheck lane (#966) (#980)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:32:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6acf044d83b63ef2520dbebdbbdfb07947b797ab",
          "body": "…urfaces + drop reporting (#587) (#958)\n\n* Open intake for retro tickets PNZM3B (process surfaces) and G19QG7 (filing provenance)\n\nIntake briefs and JTBDs for upstream issues #587 and #791; both tickets\nat phase: intake pending the JTBD gate.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nC\n[…]\nnd\npremortem.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro: filing provenance + reconcile sweep (#791) and process-level s…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-08T05:41:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "647d34ecd1838467e7a0c6007ccc5c57179d5e6a",
          "body": "… (#957)\n\nJ555B9 tracked GHSA-mp2f-45pm-3cg9 (shellcheck -> decompress@4.2.1). #927\nremoved the shellcheck npm wrapper + its decompress dep (relies on system\nShellCheck), shipped in v0.68.0 — the chain is gone from bun.lock, so the\nDone-When (advisory clean) is met. Ticket.md flip only; the ticket INDEX is\nseparately stale (388→404) and left for a dedicated regen.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): close J555B9 — decompress advisory resolved by v0.68.0…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T23:46:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "969d6d89db5f4cd38441c5f6d45f955e535941cf",
          "body": "* Document uncommittable RED evidence path\n\n* refactor: structure uncommittable RED guidance\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Document uncommittable RED evidence path (#928)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T23:23:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5905a721003e03c86b9a67b641dc14820c7911a",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(release): v0.68.0 (#955)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T21:47:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b0f5ae5b4a5707a40e527408a6f0e64dd702ff0",
          "body": "* Restore Node 22 support\n\n* Fix Cucumber source import on Node 22 branch\n\n* Add Node 22 CI coverage\n\n* Restore Node 22 boundary error handling\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Restore Node 22 support (#927)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T21:06:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb6ad7ba04c4a2e7900f56295a43eab83024dddb",
          "body": "…tch cleanup) (#946)\n\n* refactor: extract boundaryShimCommand to single-source the boundary-gate shim\n\nThe armored '[ -x … ] && … boundary --at <tier> || true' invocation was\nhand-copied 5× across schema.ts (husky textPatch) and hook-nudge.ts\n(lefthook + pre-commit snippets). A change to the [ -x ] \n[…]\n/91 boundary + phase-provenance + parity green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: dedupe boundary-shim command + frontmatter helpers (post-ba…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:59:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7eeff13770dc006145967a0bde8b56a401597f5e",
          "body": "…W) (#949)\n\n* cleanup-zombies.sh kills only with explicit --yes (#773 rung 4, 2KG1JW)\n\nBare invocation now previews (today's --dry-run behavior); killing requires\n--yes/-y. The skill/command/guide \"run --dry-run first, then re-run\" ritual\nwas prose-only — an agent that skipped the guide went straigh\n[…]\nticket 2KG1JW\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cleanup-zombies.sh kills only with explicit --yes (#773 rung 4, 2KG1J…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:57:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9937df40c5a619aed5fe33247e430c2c0f284fcf",
          "body": "…import-linter) (#947)\n\n`safeword upgrade` hardcoded ['ruff', 'mypy'] for a Python project while\n`safeword setup` installs ruff + mypy + deadcode (+ import-linter when a\nconfig would be scaffolded). So a repo upgraded rather than freshly set up\nsilently missed deadcode and import-linter. Move getPyt\n[…]\nof truth; both setup and upgrade now call\nit. Unit test pins the set (incl. deadcode) so the two can't drift again.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(python): upgrade installs the same tool set as setup (deadcode + …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:55:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "17f5caeef1909199577a49085839c4a53bb83870",
          "body": "…e) (#948)\n\n* chore(ticket): EDDABK — consolidate divergent shell tokenizers across security gates (intake)\n\nCold-start intake for the item-5 finding deferred from the post-v0.67.0\nrefactor scout. dependency-readiness.ts carries a private\nsplitShellSegments/tokenizeShellWords/stripExecutionPrefixes \n[…]\nmentation constraint confirmed sound by review.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): EDDABK — consolidate divergent shell tokenizers (intak…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:52:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c1d0a00c510240311db9c1b91bcd0228713ce7e4",
          "body": "… (#773 rung 3, JDK0F0) (#933)\n\n* Seal retro draft bodies with a digest; filing refuses modified bodies (#773 rung 3, JDK0F0)\n\nbuildDraft seals the final body (signature marker included) with\nbodyDigest = shortHash(body). The spool round-trips the seal, and the\nfiling seam (fileSpooledDrafts) refuse\n[…]\nticket JDK0F0\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Seal retro draft bodies with a digest; filing refuses modified bodies…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:07:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "676c936bd03e601fa1197c23ba656dc1ca624768",
          "body": "Completes the spawn-plumbing dedup started in #878 — this was the third\nhand-rolled copy, deferred then as out of that PR's scope.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: switch ledger-gate integration suite to spawnHookScript (#925)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:07:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fa5f404d52a70dd8a65c013b7f50d798dd8b5268",
          "body": "…o the bun:test lane (#922)\n\n* fix(lint): harden the deferred-test marker + mirror integrity rules to the bun:test lane\n\nQuality-review hardening of the just-merged #906 (one verified critical, two\nsuggestions):\n\n- The custom deferred-marker selector missed chained modifiers —\n  it.concurrent.todo p\n[…]\nntegrity pins\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(lint): harden the deferred-test marker + mirror integrity rules t…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:06:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b773c0fd2642111843121f5e001ab3b10a33011",
          "body": "…all (#810 slices 1–2) (#938)\n\n* CDRJTW intake start: boundary-reconciliation-gate ticket scaffold (#810)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01P42UynqbDXvubkgtrYMVQx\n\n* CDRJTW intake: boundary reconciliation gate — engine + local ho\n[…]\nkin phrasings\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01P42UynqbDXvubkgtrYMVQx\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Boundary reconciliation gate: engine, local hooks, and host-repo inst…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:05:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "44963e54872c3f14239421f0ab6931bdda127536",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(release): v0.67.0 (#926)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T05:48:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cf4b3456b729fde506b3c02d8854cd969de3940",
          "body": "… (#891) (#908)\n\n* fix(coverage): honor @-tag lineage in ledger-only test-definitions.md (#891)\n\nThe test-definitions.md coverage fallback derived AC/Rule references solely\nfrom `### Scenario:` titles shaped `<jtbd>.AC#.<name>`. A ticket with no\n`.feature` file that instead carried lineage as an `@<\n[…]\nd and green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VD4JSsVzspnYxGrnSbSWRB\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(coverage): honor @-tag lineage in ledger-only test-definitions.md…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T04:36:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a93d315a7f14bb98668560f2cded846e2d91048",
          "body": "…g 2, VFD6X1) (#906)\n\n* feat(VFD6X1): graduate test-integrity + no-sleep rules from prose to lint (#773)\n\nSecond enforce-then-trim rung of #773. The vitest lane gains:\n\n- vitest/no-disabled-tests (error): unconditional skips (it.skip, xit,\n  xdescribe) now need an inline eslint-disable with a reason\n[…]\n the ready PR\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Graduate test-integrity + no-sleep rules from prose to lint (#773 run…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T04:26:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d0fbffb953245b680c57d3d675723ce51e436b7c",
          "body": "…heck runs out of the box (#895)\n\n* ticket(V4MATC): intake for Python import-linter scaffold feature (#847)\n\nFeature ticket + spec: JTBD, five Rules, engineering scope converged.\nScaffold a safeword-owned .importlinter (root package + acyclic-siblings)\nonly when the top-level package is unambiguous;\n[…]\ntract setUpAcyclicProject fixture in lint-imports teeth tests\n\n* refactor: complete fileContainsSection adoption in project-detector siblings\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(python): scaffold generic import-linter config — audit's cycle c…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:20:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bcf9d13f677ee0fa98c3897be42ef6879b0cf20a",
          "body": "* feat(K4STDR): deny broad killall/pkill runtime kills on the Bash channel (#773)\n\nGraduates the zombie-process-cleanup.md:34 prose invariant into code — the\nfirst enforce-then-trim rung of #773. New lib/process-kill-guard.ts predicate\n(shell-segments tokenization, same doctrine as bash-ledger-write\n[…]\nof PR\nscope).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bash process-kill denylist + real-time work-log stamps (#878)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:20:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d3535f9f2807380cbb79324026fd7f5319a2018",
          "body": "Independent post-merge review (both CLEAN, 0 must-fix) surfaced three\nworthwhile notes:\n\n- ARCHITECTURE.md retro/ one-liner misattributed transcript mining — the\n  LLM miner front-end lives in commands/retro.ts; src/retro/ is the\n  sanitize/draft/triage/transport pipeline.\n- ticket-sync/ line now us\n[…]\nommendedTypeScript rows can no longer be\n  satisfied by their longer siblings.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs+test: post-merge review notes for #886/#887 (#900)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:16:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "883d70231942c2a78eba6efcfdaf4b33091ac337",
          "body": "* fix(hooks): match ticket.md by exact basename, not suffix\n\nA file merely ending in ticket.md (e.g. sub-ticket.md) took the\ncanonical-ticket branch in pre/post-tool-quality, reading its own\nfrontmatter instead of the folder's ticket.md — silently skipping or\nstealing the session binding and misappl\n[…]\ntests green).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01S8gT3sN8HC5K4rMjCCsCGV\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro sweep: fix 9 issues from session retrospectives (#890)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:14:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9fe4953fb5ed5c6b01df1cc008a114980e9293e3",
          "body": "…#887)\n\n- golden-path graceful-handling tests assert the observable outcome (exit 0,\n  byte-identical unfixable content, surfaced error / silent no-op) instead of\n  bare not.toThrow — a hook that corrupted the file used to pass.\n- git.test no-op cases assert the index is unchanged against a seeded t\n[…]\nh contract table, with behavioral coverage explicitly routed\n  to golden-path.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: strengthen weak assertions flagged by the full audit (A7192X) (…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T14:23:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6a74f5dacaf2e4a3c1773375e147076dcb2b067e",
          "body": "… (25TJAR) (#886)\n\nFull-audit findings: the CLI Structure tree documented 5 of 13 real src/\nmodules — adds learning-sync, retro, skills, test-plan, ticket-sync,\ntracker-connect, tracker-sync, upstream-monitor with one-line purposes from\ntheir module docs. Runtime deps table gains @cucumber/gherkin +\n[…]\nude-plugin/plugin.json), not Cursor, and\ndeliberately not a workspace package.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(architecture): reconcile narrative with the generated module map…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T14:23:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d605a631311f11d6fc2e659ec4be1f083adce324",
          "body": "…nforcement is opted out (#868)\n\nFollow-up to #864. In `architecture --stage`, the drift advisory sat after the\n`architectureDocEnforcement: false` opt-out early-return, so an opted-out host\nmissed it there — inconsistent with --check and default mode, and with the\ncode's own 'coverage honesty is no\n[…]\ne, so it reads the doc as-is, matching\n--check). New integration test pins it.\n\n\nClaude-Session: https://claude.ai/code/session_01KmPeTtB72TjBWquzo8t3Eo\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(architecture): surface narrative-drift advisory in --stage when e…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T00:49:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e31b164c90b6ce758dafe74daf76350c4cc80b7",
          "body": "…+ surfaces pre-existing drift (#848) (#864)\n\n* ticket(BY7RNR): intake + scenarios for architecture narrative blind spots (#848)\n\nSpec, dimensions, feature source (20 scenarios / 7 rules), R/G/R ledger, and\nimpl plan for honoring paths.architecture in the reconcile nudge and surfacing\npre-existing n\n[…]\ndes (-8 LOC).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014cxsMsSmNgZ4MUgTcQ39M3\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: architecture narrative reconciliation honors paths.architecture …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T23:21:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "abd4abdfc14f74fffaa7e10da13cc057ac11d7fa",
          "body": "… (F9W3JP) (#865)\n\n* ticket(F9W3JP): intake — epic-child linker feature\n\nFeature: `ticket new --parent <epicId>` writes both ends of the epic↔child\nlink (child parent:, epic children[] append) and groups the child under its\nepic in INDEX. One JTBD (TB1), four ACs (link both ways / index grouping /\nf\n[…]\nicket closed\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NXdv6zZRRJdCGf7XkCqvkh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "`ticket new --parent`: link a child ticket to its epic in one command…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T22:46:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65516026a3bd5a593226bd434fd51c2037f20123",
          "body": "…chitecture check (#857)\n\n* Route verify's Gherkin + typecheck lanes through test-plan (polyglot)\n\nThe verify skill's Gherkin acceptance lane was hardcoded to package.json's\ntest:bdd script (cucumber-js only), and the typecheck lane was TS-only. Fold\nboth into `safeword test-plan` — the single polyg\n[…]\n in bd669ca.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_012X1PmAQ8j7tfAF12DzhXij\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Polyglot verify + audit: de-JS the Gherkin/typecheck lanes and the ar…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T21:46:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9cefee868e24e635e0e08dab1e06492e1f937c16",
          "body": "Behavior-preserving Tier-1 rename. #822 renamed the user-facing gate label\n\"AC gate\" → \"criteria gate\" (the gate accepts a numbered Rule or a legacy AC);\nthis brings the internal symbols in line with that concept:\n\n- evaluateAcGate    → evaluateCriteriaGate\n- parseAcsByJtbd    → parseCriteriaByJtbd\n\n[…]\nTypecheck + lint + parser-parity + cucumber (243) green; full suite verifying.\n\n\nClaude-Session: https://claude.ai/code/session_01AisW4aBoExfLcVDVkAWCKm\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: rename internal AC-gate symbols to Criteria (#850)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T21:07:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "159bd1599a91309b5b11177c381e4993c2747cde",
          "body": "…orkspace Go/Python/Rust services (#843, #844) (#858)\n\n* feat(architecture): recognize flat/lib JS layouts + orphan non-JS services (#843, #844)\n\n#843: broaden the JS/TS skeleton recognizer to match the Python/Rust\nextractors — a flat `src/` (files, no subdirs), a `lib/` root, and\ntop-level source f\n[…]\nxtracts once.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Nfb4uXwwx5hvuiAo9BUoQj\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "architecture generator: recognize flat/lib JS layouts + surface non-w…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T21:07:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65358e08894cab1ec91b9b2461a202b9a69ac023",
          "body": "…advisory (#809, #824, #825) (#839)\n\n* RM84M8 intake: evidence-anchored phase transitions (#809)\n\nSpec + engineering scope for the deliverable-boundary epic's substrate\nchild: a per-phase SHA anchor on feature ticket phase transitions,\nmirroring the R/G/R ledger's SHA-per-tick, with a shared detecti\n[…]\n index regen\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01P42UynqbDXvubkgtrYMVQx\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Evidence-anchored phase transitions: phase_anchors substrate + check …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:59:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4fd6a7b4d379cb013f9baa2a38fb886e94615164",
          "body": "…hantom (#838)\n\nWeb/remote sessions sign every commit via the env-runner\n(commit.gpgsign=true + gpg.ssh.program), but local `git log\n--show-signature` / `verify-commit` / `gpg --list-secret-keys` report\nan allowedSignersFile error and %G?=N because there's no local\nallowed-signers file. That is a lo\n[…]\n so agents stop\nmisdiagnosing signed commits as unverified / \"no signing key\".\n\n\nClaude-Session: https://claude.ai/code/session_01PHJHmk3eBjWd63Vo2hks5A\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agents): note that \"unverified commit\" is a local-verification p…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:38:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1be7f64ca56e0902e14756d500237ee0f131b54c",
          "body": "* Soft-deprecate Acceptance Criteria in favor of numbered Rules\n\nThe intake authoring layer now leads with numbered Rules (`.R<n>`) as the\ndefault criteria rung; Acceptance Criteria (`.AC<n>`) become the documented,\nstill-accepted legacy alternative. Parser and gate behavior are unchanged — the\ncrit\n[…]\narity green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AisW4aBoExfLcVDVkAWCKm\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Soft-deprecate Acceptance Criteria in favor of numbered Rules (#822)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:31:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3e53918c211b3aca7b0da9d5c45a8405c00a248d",
          "body": "…er-error-is-error (#806)\n\n* chore!: raise Node engine floor to 24 (drop Node 22)\n\nDrops the Node 22 term from packages/cli engines.node\n(`^22.22.3 || ^24.16.0 || >=26.3.0` → `^24.16.0 || >=26.3.0`) and\nupdates the astro engine-contract assertion to match.\n\nBREAKING CHANGE: Node 22/23 are no longer \n[…]\n floor to 24 (drops Node 22/23) and the shipped\nESLint preset now requires Node 24 (unicorn/prefer-error-is-error →\nError.isError). See #806.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release)!: v0.66.0 — raise Node floor to 24 + unicorn 70 + pref…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:30:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f793b0e249149a8321fe57292344d704b0c8a7ec",
          "body": "Co-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.65.0 (#846)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T19:24:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "adc73efc2c7c3feeb19ea0893122c749b7e5e785",
          "body": "… + cargo-deny gates (#823)\n\n* feat(rust): add strict workspace clippy gate to the typecheck plan\n\nThe per-file lint hook runs `clippy -p <pkg> --fix` — package-scoped, no\n`-D warnings`, no `--all-targets --all-features` — so feature-gated code\nand test/bench targets never see clippy until CI. Nothi\n[…]\ncheck/deps).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NzXf5iJmGodwv1P4kSHJNY\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rust): evolve the Rust langpack quality stack — workspace clippy…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T19:05:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "939d63400115c76e6f226cf48049fe08cbe4f095",
          "body": "…tions (#835)\n\n* refactor(ticket-new): extract fail() helper for the stderr+exit pattern\n\nDRYs the four identical `process.stderr.write(msg); process.exit(1)` sites\n(invalid --type, --why-on-feature, SlugError, TicketIdCollisionError) into a\nsingle `fail(message): never`. Byte-identical output and e\n[…]\n (3/3 pass).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KmPeTtB72TjBWquzo8t3Eo\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: post-48h cleanup — fail() helper + shared cucumber spawn op…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T18:27:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c1e2273cb4594153d51fabb696a81031a2c72f20",
          "body": "* fix: batch low-risk retro quick-wins (#793, #705, #634, #696)\n\n- #696: the AC intake gate no longer counts arbitrary level-4 headings;\n  only lineage headings (`<jtbd>.AC<n>` / `<jtbd>.R<n>`) satisfy the\n  \"≥1 AC per JTBD\" requirement, so `#### Notes` can't vacuously pass it.\n- #634: resolveGitHub\n[…]\ntests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NXdv6zZRRJdCGf7XkCqvkh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro backlog: low-risk quick-wins + `ticket new` epic/goal/why (#817)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T17:21:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25116a85b04f5bf059a6344247262b562fd06964",
          "body": "…s (#765 follow-up) (#804)\n\nFollow-up to the merged de-prescription pass (#803). verify/audit/quality-review/\nrefactor over the merged result surfaced three prose fixes, all in\ncontext-files-guide.md:\n\n- audit (dedup): the auto-load/brevity point was stated twice — the Reliability\n  note (:79) and a\n[…]\n); remaining clones are the pre-existing per-skill\ninvocation-log boilerplate.\n\n\nClaude-Session: https://claude.ai/code/session_01RTCTEqXfKZvmMEDY12FfMT\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Post-merge quality sweep: dedup + scope two context-files-guide claim…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T16:24:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "073452f842af9b33eefa3303ac1e3c4f0abec7eb",
          "body": "…st ergonomics (#786)\n\n* test: give the Cucumber wiring child its own timeout/kill (#488)\n\nspawnSync blocks the event loop, so Vitest's outer TIMEOUT_ACCEPTANCE_LANE\ncannot interrupt a hung `bunx cucumber-js`. Pass a child-process timeout\n(90s, inside the outer budget) and SIGKILL on expiry; the std\n[…]\nClaude Code.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01BCiX1gTvpS1sH6tG3CWJqM\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Test-harness reliability: Cucumber spawn/flake + vitest/build-lock/di…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T10:21:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0e9c6473051902ca7803f8f9a9defa62c9e9e40c",
          "body": "…els (#769–779) (#803)\n\n* De-prescribe pass (#765): retire decision-trees, downgrade emphasis, cut recaps\n\nPart of #765 (Goal 10 model portability / Goal 3 unambiguous instructions).\nCanonical edits in packages/cli/templates/**, propagated to dogfood mirrors via\nparity:fix (212 pairs + 3 contracts i\n[…]\nining scope.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RTCTEqXfKZvmMEDY12FfMT\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "De-prescribe pass (#765): retune the instruction layer for modern mod…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T10:21:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "46f7097c8afdf0411d7a863f909d720b68fcfdd2",
          "body": "Prior audit-follow-up commit (#763) bumped root dev deps and four of the\nfive cli-workspace deps, but left packages/cli's tsx at ^4.22.4. Align it\nto ^4.23.0 (lockfile already resolved 4.23.0) to close #717's lockstep\nrequirement.\n\nThe eslint devDep was already aligned to ^10.6.0 by #763. The eslint\n[…]\n #718 (5 unused exports) were already\nresolved by #763; knip is clean on both.\n\n\nClaude-Session: https://claude.ai/code/session_01GFFMurbDa1ZmzEBHjBSDA9\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): finish #717 cli tsx bump (closes #305, #717, #718) (#795)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T04:31:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "636720a3ce1f98a17513076658304cd262a84409",
          "body": "Co-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.64.0 (#785)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T00:38:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7c636ec2c2a709f3ba554aca9d4c05e7a9483fe9",
          "body": "…ency (#763)\n\n* chore(audit): un-export dead symbols, bump deps, fix markdown lint\n\nAudit follow-ups from /audit run:\n\n- Un-export 5 symbols knip flagged as unused (used only within their own\n  file): CODEX_SESSION_START_HOOK_PATCH, OWNED_LABEL_PREFIXES,\n  MONITOR_SOURCES, normalizeMarkdown, SYNCTIC\n[…]\n tests (comment, single-quote, virtual-manifest-no-edition), 2 updated.\nRegexes narrowed to [ \\t] to avoid sonarjs super-linear backtracking.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Audit follow-ups: dep hygiene, dead-export cleanup, Rust/Go pack curr…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T20:21:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5c08461a7f2908327c762e9a9499b4435fb2c9a",
          "body": "…(#756)\n\n* 7CK2KP: BDD-lane adoption — bdd.conventions pointer + deferral prose\n\nAdds readBddConventionsPath (bdd.conventions in .safeword/config.json) and a\nstderr pointer in safeword codify, and de-hardcodes lane paths + the\nrun-and-expect-failure verify story in the installed BDD prose (templates\n[…]\nENARIOS/TDD).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LCXJRr67NFJTiuJEi9D8KN\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "BDD lane adoption: bdd.conventions pointer + deferral prose (7CK2KP) …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T20:08:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f85c792747034d26d6105af8acefca50165c5da3",
          "body": "* test(cucumber): retry a CLI spawn once when killed with no output\n\nThe 'When I run' step spawns node dist/cli.js with a 30s timeout. A ~1s\ncommand starved past that timeout under concurrent test load (e.g. the vitest\nsuite co-running, or a contended CI runner) is SIGTERM-killed with empty\noutput —\n[…]\nlane 243/243.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01XaAFny6rSiwMbhbHTMqn3b\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retry a cucumber CLI spawn once when killed with no output (#764)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T20:08:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d7f8b48eee042a1d28f5a48d68112ec48f45994",
          "body": "…ce roots (#755)\n\n* refactor: name SAFEWORD_LANE_CONFIG_FILE in project-detector\n\nReplace the 'cucumber.mjs' literal at the three own-scaffold identity sites\n(config-discovery list, self-exclusion guard, own-lane probe) with a named\nconst so a scaffold rename stays in lockstep. Behavior-identical.\n\n\n[…]\ne the same list. Hoist one WORKSPACE_ROOTS into workspaces.ts\nso a new root can't be added to one scanner and silently missed by the others.\nBehavior-identical.\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "refactor: post-36h cleanup — name lane-config literal + dedup workspa…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T08:01:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "09a2545b538cc98d7c8eff3cb622218a8cf39320",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(release): v0.63.0 (#753)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T06:17:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87342d50810241ec71e519b3b6fd16d7025962a4",
          "body": "…n-zero exits (#720) (#729)\n\n* fix(self-report): capture only genuine CLI crashes, not deliberate exits (#720)\n\nrecordCliExit fired on process.on('exit') for ANY non-zero code, so the ~12\ncommands that use process.exit(1) as normal control flow (check,\narchitecture --check, codify arg errors, …) flo\n[…]\ny: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017A57mMA4Jo1rHDu1n5SKjd\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "fix(self-report): capture only genuine CLI crashes, not deliberate no…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T05:52:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b961bad13fb010c80482260a8ae5e9ec0c324f53",
          "body": "* test(W42G34): RED - bulk-tick sed against a ticket ledger must be denied (#644 G3)\n\nFailing integration test: pre-tool-quality's Bash branch currently allows\nthe literal #644 command (sed -i ticking every R/G/R checkbox). Includes\nthe ticket's BDD artifacts (spec, dimensions, feature source, ledge\n[…]\n tests green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01XaAFny6rSiwMbhbHTMqn3b\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Gate Bash-channel writes to the R/G/R ledger (#644 G3) (#721)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T05:17:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "49121345e8d49ccffae872daccb8d04ab03a37c1",
          "body": "…) (#719)\n\n* chore(tickets): file audit follow-ups JCC69C + J2R9HY (#644 G8 verify)\n\nTwo maintenance tasks surfaced by the audit during the G8 verify pass,\nboth out of scope for the merged docs-cleanup PR:\n\n- JCC69C: bump 6 outdated dev-tool deps (@types/node, eslint, knip,\n  prettier, tsx, markdown\n[…]\nlready exact.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_018PVMS5fJ5R3a11JVWQd5vh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(tickets): file audit follow-ups JCC69C + J2R9HY (#644 G8 verify…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T04:52:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3994451b11816d24424536a08ce6d1e8d68ee582",
          "body": "Adds numbered Rules (`<jtbd-id>.R<n>`) as an optional per-JTBD substitute for Acceptance Criteria — the coexistence bridge toward a single Rule tier (#716). Closes #649.\n\nRule ref grammar with AC-wins precedence, rule uncovered/stale/orphan coverage advisories, zero-@rejection advisory, rule-name-tag-mismatch lint, gate denial naming Rules, plain-language actionable messages, and zero behavior change for repos with no Rules. Full suite + Gherkin acceptance lane green.",
          "is_bot": false,
          "headline": "Add a numbered Rule tier between JTBD and scenarios (#713)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T00:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2d51768f7658d4bd8f0ce883f10a66a070986d9",
          "body": "…44 G8) (#714)\n\n* docs(tickets): label retrospective R/G/R ledgers as non-precedent (#644 G8)\n\nAnnotate 26 test-definitions.md ledgers whose RED/GREEN/REFACTOR boxes\nwere bulk-ticked after the fact — each file entered git history already\nfully ticked, with no per-step commit SHAs — starting with CDX\n[…]\nedger markers\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_018PVMS5fJ5R3a11JVWQd5vh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(tickets): label retrospective R/G/R ledgers as non-precedent (#6…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-03T23:00:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "efa6eaf5bb3367086b5848316402ec1b0b2d47d0",
          "body": "* 7PG694: ticket for verify/audit skill refactor\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QsRxD44HSbzHsrhXLm3XEW\n\n* 7PG694: refactor verify and audit skills per quality-review plan\n\nFresh-review verdict REQUEST CHANGES; all 7 APPLY item\n[…]\n with PR #701\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QsRxD44HSbzHsrhXLm3XEW\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Refactor the verify and audit skills (7PG694) (#701)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-03T22:59:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 48,
      "commits_last_year": 2371,
      "latest_release_at": "2026-07-18T20:57:56Z",
      "latest_release_tag": "v0.69.0",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 35,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 2.6
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 25,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "safeword",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "cli",
            "safeword",
            "developer-experience",
            "linting",
            "claude-code"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/safeword",
          "is_deprecated": false,
          "latest_version": "0.69.0",
          "repository_url": "https://github.com/ArcadeAI/safeword",
          "versions_count": 158,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 7036,
          "first_published_at": "2025-11-28T16:14:55.476000Z",
          "latest_published_at": "2026-07-18T20:59:14.958000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 8,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-27",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 527
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/cli/tsconfig.json",
        "packages/website/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "experiments/go-skill-directive/checker/go.mod"
      ],
      "largest_source_bytes": 74384,
      "source_files_sampled": 855,
      "oversized_source_files": 4,
      "agent_instruction_files": [
        ".cursor/rules/bdd-core.mdc",
        ".cursor/rules/bdd-discovery.mdc",
        ".cursor/rules/bdd-done.mdc",
        ".cursor/rules/bdd-plan-implementation.mdc",
        ".cursor/rules/bdd-scenarios.mdc",
        ".cursor/rules/bdd-splitting.mdc",
        ".cursor/rules/bdd-tdd.mdc",
        ".cursor/rules/bdd-verify.mdc",
        ".cursor/rules/safeword-brainstorming.mdc",
        ".cursor/rules/safeword-core.mdc",
        ".cursor/rules/safeword-debugging.mdc",
        ".cursor/rules/safeword-elicitation.mdc",
        ".cursor/rules/safeword-figure-it-out.mdc",
        ".cursor/rules/safeword-quality-reviewing.mdc",
        ".cursor/rules/safeword-refactoring.mdc",
        ".cursor/rules/safeword-retro-filer.mdc",
        ".cursor/rules/safeword-tdd-review.mdc",
        ".cursor/rules/safeword-testing.mdc",
        ".cursor/rules/safeword-ticket-system.mdc",
        ".safeword/AGENTS.md",
        "AGENTS.md",
        "CLAUDE.md",
        "packages/cli/templates/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 11149
    },
    "dependencies": {
      "manifests": [
        ".github/requirements-ci.txt",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 292,
        "malicious_count": 0,
        "assessed_package": "npm:safeword@0.69.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "@cucumber/gherkin",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^41.0.0"
        },
        {
          "name": "@cucumber/messages",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^34.0.1"
        },
        {
          "name": "@eslint-community/eslint-plugin-eslint-comments",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.7.2"
        },
        {
          "name": "@eslint-react/eslint-plugin",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "5.14.6"
        },
        {
          "name": "@eslint/js",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.0.1"
        },
        {
          "name": "@next/eslint-plugin-next",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "16.2.10"
        },
        {
          "name": "@secretlint/core",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.0.2"
        },
        {
          "name": "@secretlint/secretlint-rule-preset-recommend",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.0.2"
        },
        {
          "name": "@tanstack/eslint-plugin-query",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "5.101.2"
        },
        {
          "name": "@vitest/eslint-plugin",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.6.23"
        },
        {
          "name": "commander",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "15.0.0"
        },
        {
          "name": "eslint-config-prettier",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.1.8"
        },
        {
          "name": "eslint-import-resolver-typescript",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.5"
        },
        {
          "name": "eslint-plugin-astro",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "~2.1.1"
        },
        {
          "name": "eslint-plugin-better-tailwindcss",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.6.1"
        },
        {
          "name": "eslint-plugin-import-x",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.17.1"
        },
        {
          "name": "eslint-plugin-jsdoc",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^63.0.13"
        },
        {
          "name": "eslint-plugin-playwright",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.10.5"
        },
        {
          "name": "eslint-plugin-promise",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.3.0"
        },
        {
          "name": "eslint-plugin-react-hooks",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.1.1"
        },
        {
          "name": "eslint-plugin-regexp",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "3.1.1"
        },
        {
          "name": "eslint-plugin-security",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.0.1"
        },
        {
          "name": "eslint-plugin-simple-import-sort",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^14.0.0"
        },
        {
          "name": "eslint-plugin-sonarjs",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.1.0"
        },
        {
          "name": "eslint-plugin-storybook",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "10.5.0"
        },
        {
          "name": "eslint-plugin-turbo",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.10.4"
        },
        {
          "name": "eslint-plugin-unicorn",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "72.0.0"
        },
        {
          "name": "smol-toml",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.7.0"
        },
        {
          "name": "typescript-eslint",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "8.63.0"
        },
        {
          "name": "yaml",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.9.0"
        },
        {
          "name": "@astrojs/starlight",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.41.1"
        },
        {
          "name": "astro",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.7"
        },
        {
          "name": "astro-mermaid",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.0"
        },
        {
          "name": "mermaid",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.16.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 9,
        "merged_prs": 469,
        "open_issues": 518,
        "closed_ratio": 0.396,
        "closed_issues": 340,
        "closed_unmerged_prs": 58
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "TheMostlyGreat",
          "commits": 1800,
          "avatar_url": "https://avatars.githubusercontent.com/u/70783618?v=4"
        },
        {
          "type": "User",
          "login": "TESTPERSONAL",
          "commits": 538,
          "avatar_url": "https://avatars.githubusercontent.com/u/6664588?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.767
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "deploy-website.yml",
        "release.yml",
        "retro-reconcile.yml",
        "upstream-changelog-monitor.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs",
        "ruff.toml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 4,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/27 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 1,
            "reason": "dependency not pinned by hash detected -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "625c1d47ad5fa546cea7792ce976ec1208941a72",
        "ran_at": "2026-07-24T06:53:28Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T05:47:20Z",
      "oldest_open_prs": [
        {
          "number": 548,
          "created_at": "2026-06-29T00:16:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1143,
          "created_at": "2026-07-18T22:24:52Z",
          "last_comment_at": "2026-07-21T05:24:27Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 1382,
          "created_at": "2026-07-24T04:52:21Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1383,
          "created_at": "2026-07-24T04:57:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1384,
          "created_at": "2026-07-24T05:03:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1385,
          "created_at": "2026-07-24T05:17:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1386,
          "created_at": "2026-07-24T05:43:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1392,
          "created_at": "2026-07-24T05:53:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1394,
          "created_at": "2026-07-24T06:04:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T05:42:54Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 3,
          "created_at": "2025-11-27T19:40:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 5,
          "created_at": "2025-11-27T19:45:30Z",
          "last_comment_at": "2026-06-18T02:48:23Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 6,
          "created_at": "2025-11-27T20:24:41Z",
          "last_comment_at": "2026-06-20T07:20:58Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 11,
          "created_at": "2025-11-29T20:41:40Z",
          "last_comment_at": "2026-06-18T02:47:47Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 13,
          "created_at": "2025-12-02T05:58:09Z",
          "last_comment_at": "2026-06-18T02:47:41Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 16,
          "created_at": "2025-12-02T05:58:49Z",
          "last_comment_at": "2026-06-18T02:47:38Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 17,
          "created_at": "2025-12-02T05:58:52Z",
          "last_comment_at": "2026-06-18T02:47:51Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 18,
          "created_at": "2025-12-02T05:59:21Z",
          "last_comment_at": "2026-06-18T02:47:54Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 19,
          "created_at": "2025-12-02T05:59:24Z",
          "last_comment_at": "2026-06-18T02:47:56Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 21,
          "created_at": "2025-12-02T06:23:29Z",
          "last_comment_at": "2026-06-18T02:47:24Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 22,
          "created_at": "2025-12-03T17:59:35Z",
          "last_comment_at": "2026-06-18T02:47:31Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 23,
          "created_at": "2025-12-03T17:59:51Z",
          "last_comment_at": "2026-06-18T02:47:35Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 24,
          "created_at": "2025-12-03T18:16:25Z",
          "last_comment_at": "2026-06-18T02:48:06Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 29,
          "created_at": "2025-12-08T06:40:25Z",
          "last_comment_at": "2026-06-18T02:48:14Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 119,
          "created_at": "2026-05-20T08:46:55Z",
          "last_comment_at": "2026-06-26T00:03:58Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 129,
          "created_at": "2026-05-22T13:09:41Z",
          "last_comment_at": "2026-06-18T02:46:52Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 191,
          "created_at": "2026-06-05T13:21:03Z",
          "last_comment_at": "2026-06-26T00:04:02Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 292,
          "created_at": "2026-06-20T22:25:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 294,
          "created_at": "2026-06-20T22:32:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 307,
          "created_at": "2026-06-21T14:19:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ArcadeAI/safeword",
    "host": "github.com",
    "name": "safeword",
    "owner": "ArcadeAI"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 59,
        "vitality": 88,
        "community": 30,
        "governance": 57,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 88,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "commits_last_year": 2371,
              "human_commit_share": 0.94,
              "days_since_last_push": 0,
              "active_weeks_last_year": 35
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "35/52 weeks with commits",
                "points": 24.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 35
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "2371 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 2371
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 48,
              "latest_release_tag": "v0.69.0",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 2.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "48 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 48
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 30,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 14,
            "inputs": {
              "forks": 2,
              "stars": 8,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "8 stars",
                "points": 13.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "packages": [
                "safeword"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 7036
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "7,036 downloads/month across npm",
                "points": 51.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 7036,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 24,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.767
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 77% of commits",
                "points": 5.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 77
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "merged_prs": 469,
              "open_issues": 518,
              "closed_issues": 340,
              "issue_closed_ratio": 0.396,
              "closed_unmerged_prs": 58
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "40% of issues closed",
                "points": 18.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "469/527 decided PRs merged",
                "points": 34,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 469,
                      "decided": 527
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "followers": 290,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "ArcadeAI",
              "public_repos": 82,
              "account_age_days": 957
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "290 followers of ArcadeAI",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 290,
                      "login": "ArcadeAI"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "82 public repos, account ~2 yr old",
                "points": 18.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 82
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "safeword"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "158 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 158
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs, ruff.toml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs, ruff.toml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://arcadeai.github.io/safeword/",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://arcadeai.github.io/safeword/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 59,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 0.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:safeword@0.69.0 runtime dependency closure — what installing the published package pulls in — 292 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:safeword@0.69.0",
                  "assessed": 292
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 292,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 292,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                ".cursor/rules/bdd-core.mdc",
                ".cursor/rules/bdd-discovery.mdc",
                ".cursor/rules/bdd-done.mdc",
                ".cursor/rules/bdd-plan-implementation.mdc",
                ".cursor/rules/bdd-scenarios.mdc",
                ".cursor/rules/bdd-splitting.mdc",
                ".cursor/rules/bdd-tdd.mdc",
                ".cursor/rules/bdd-verify.mdc",
                ".cursor/rules/safeword-brainstorming.mdc",
                ".cursor/rules/safeword-core.mdc",
                ".cursor/rules/safeword-debugging.mdc",
                ".cursor/rules/safeword-elicitation.mdc",
                ".cursor/rules/safeword-figure-it-out.mdc",
                ".cursor/rules/safeword-quality-reviewing.mdc",
                ".cursor/rules/safeword-refactoring.mdc",
                ".cursor/rules/safeword-retro-filer.mdc",
                ".cursor/rules/safeword-tdd-review.mdc",
                ".cursor/rules/safeword-testing.mdc",
                ".cursor/rules/safeword-ticket-system.mdc",
                ".safeword/AGENTS.md",
                "AGENTS.md",
                "CLAUDE.md",
                "packages/cli/templates/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 11149
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "94 of 94 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 94,
                      "sampled": 94
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/cli/tsconfig.json",
                "packages/website/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.74,
              "toolchain_manifests": [
                "experiments/go-skill-directive/checker/go.mod"
              ],
              "dependency_bot_commit_share": 0.06
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "experiments/go-skill-directive/checker/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "experiments/go-skill-directive/checker/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs, ruff.toml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs, ruff.toml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "74 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 74,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "6 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 6,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 74384,
              "source_files_sampled": 855,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/855 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 855,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T06:53:49.239530Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/ArcadeAI/safeword.svg",
  "full_name": "ArcadeAI/safeword",
  "license_state": "absent",
  "license_spdx": null
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.