JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 372,
"has_wiki": true,
"homepage": null,
"languages": {
"JavaScript": 34327,
"TypeScript": 64896
},
"pushed_at": "2026-07-25T08:25:08Z",
"created_at": "2026-07-19T10:06:09Z",
"owner_type": "User",
"updated_at": "2026-07-19T19:46:29Z",
"description": "Universal security audit skill for AI agents. 52 pure Markdown files encoding 15 years of pentest expertise — web & mobile security, OWASP-aligned, CVSS scoring, compliance checks, zero dependencies.",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": null,
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript",
"JavaScript"
]
},
"owner": {
"blog": null,
"name": null,
"type": "User",
"login": "ArisRoman",
"company": null,
"location": null,
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/165471526?v=4",
"created_at": "2024-03-30T09:59:18Z",
"is_verified": null,
"public_repos": 4,
"account_age_days": 847
},
"license": {
"state": "absent",
"spdx_id": null,
"raw_spdx": null,
"file_present": false,
"scorecard_found": false,
"profile_has_license": false
},
"activity": {
"releases": [
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2026-07-19T19:57:16Z"
},
{
"tag": "v3.1.5",
"kind": "patch",
"published_at": "2026-07-19T18:07:34Z"
},
{
"tag": "v3.1.4",
"kind": "patch",
"published_at": "2026-07-19T18:02:19Z"
},
{
"tag": "v3.1.3",
"kind": "patch",
"published_at": "2026-07-19T18:00:44Z"
},
{
"tag": "v3.1.2",
"kind": "patch",
"published_at": "2026-07-19T17:51:51Z"
},
{
"tag": "v3.1.1",
"kind": "patch",
"published_at": "2026-07-19T17:45:16Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2026-07-19T17:41:55Z"
},
{
"tag": "v3.0.7",
"kind": "patch",
"published_at": "2026-07-19T17:16:58Z"
},
{
"tag": "v3.0.6",
"kind": "patch",
"published_at": "2026-07-19T12:58:17Z"
},
{
"tag": "v3.0.5",
"kind": "patch",
"published_at": "2026-07-19T12:31:06Z"
},
{
"tag": "v3.0.4",
"kind": "patch",
"published_at": "2026-07-19T12:29:42Z"
},
{
"tag": "v3.0.3",
"kind": "patch",
"published_at": "2026-07-19T12:28:43Z"
},
{
"tag": "v3.0.2",
"kind": "patch",
"published_at": "2026-07-19T12:27:45Z"
},
{
"tag": "v3.0.1",
"kind": "patch",
"published_at": "2026-07-19T12:09:41Z"
}
],
"recent_commits": [
{
"oid": "3ed2a0236a8d68424aff3dc98dd711107652bc62",
"body": "feat: 22 agents like ui-ux-pro, deterministic scanners, cloud module, safe install, 8 cmds on '/'",
"is_bot": false,
"headline": "Merge pull request #1 from ArisRoman/arena/019f7b92-cyberaudit-skill",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:46:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe7d17697c1054b25ee8efac2b909dfb855fea34",
"body": "…d '/' menu\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "docs: add --local/--global install modes like ui-ux-pro for guarantee…",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:40:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64b335096835cdf795757df6b658b786f10026f7",
"body": "…cmds on '/' guaranteed\n\n- Add --local flag: installs to ./.claude/skills/, ./.cursor/commands/, ./.windsurf/workflows/, ./.agent/workflows/ etc. in project cwd (like uipro init --ai all)\n- --global remains default for backward compat (~/)\n- toLocalPath() converts global paths to project-local via r\n[…]\nated cli.test.ts to check isSafeInsideHome and '/' menu\n- Enables 100% guarantee for '/' when using --local like ui-ux-pro\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(install): --local / --global modes like ui-ux-pro, 22 agents, 8 …",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:39:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1286ab94b4465fda7cda8a3d09e7e7bbc63bddab",
"body": "… + deterministic scanners\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "docs: update README to 22 agents like ui-ux-pro + 8 main '/' commands…",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:29:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b956ddb648a13780266039f0734e089508efe842",
"body": "…'/' menu\n\n- Expand from 7 to 22 agents: opencode, claude-code, cursor, windsurf, antigravity, copilot, kiro, codex, qoder, roocode, gemini, trae, continue, codebuddy, droid, kilocode, warp, augment, codewhale, cline, aider + antigravity-cli\n- AGENT_CONFIG: skillPaths, commandPaths, workflowPaths, m\n[…]\nFIG, installCommands), total 44 passing\n- Build verified: list shows 22 agents, dry-run for claude-code and windsurf works\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(agents): 22 agents like ui-ux-pro-max-skill, 8 main commands on …",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:28:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0572690f204dfa78b68db88942669ce5f82d5ee0",
"body": "- Add eslint with @typescript-eslint, 0 errors 0 warnings\n- Add prettier config, scripts lint, lint:fix, format, format:check\n- Fix 6 warnings: remove unused imports (relative, DEFAULT_EXTENSIONS, formatFindingsJson, mkdirSync etc), prefer-const, remove dead phaseForSeverity\n- Remove LUNAIRE EDITION branding from reports/templates (was v3.0 LUNAIRE -> v3.1.5)\n- All 40 tests passing, build clean\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(P2-B2): eslint + prettier + polish LUNAIRE removal",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:15:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e6b6bc7cba14727b95cc4e85d97a5d28d822242",
"body": "- src/report/generator.ts: score calc (100 -20*CRITICAL...), verdict, dashboard, OWASP compliance mapping from patternId keywords, bar visualization, business risks, immediate actions, detailed findings with CVSS, remediation plan phased\n- src/report/types.ts: UnifiedFinding, ReportInput/Output\n- CL\n[…]\nVerified: scan /tmp/reporttest -> findings.json -> report.md with 40/100 CRITICAL, dashboard, OWASP FAIL, remediation plan\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(P2-B3): deterministic report generator + CLI report command",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:10:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "14efb293889a68063196f698e63fc90335a6512d",
"body": "…ass assignment)\n\n- 12 patterns: WEB_SQLI_CONCAT, WEB_SQLI_RAW, WEB_XSS_DANGEROUS, WEB_XSS_INNERHTML, WEB_JWT_DECODE, WEB_CORS_WILDCARD, WEB_EXEC_INJECTION, WEB_EVAL, WEB_MASS_ASSIGNMENT, WEB_NOSQL_INJECTION, WEB_HELMET_MISSING, WEB_LARAVEL_DEBUG\n- src/scanners/web.ts: walk files, regex + fileRegex,\n[…]\n.test.ts, total 35 tests passing\n- Verified: 7 findings on synthetic vuln app (SQLi, eval, JWT, CORS, mass assign, helmet)\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(P2-A2): web deterministic scanner (SQLi, XSS, JWT, CORS, eval, m…",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T19:04:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb12d8b1ff2fc3c0a02cae7844cb26f115b02557",
"body": "- 15 patterns: AWS keys, GitHub PAT, Stripe SK, private keys, Slack tokens, JWT secrets, NEXT_PUBLIC secrets, DB URLs, OpenAI keys, NPM tokens, high-entropy\n- src/scanners/secrets.ts: walkDir with ignore node_modules/.git/dist, redaction, CVSS, OWASP/CWE, dedup, severity sort\n- CLI: cyberaudit-skill\n[…]\nts in secrets.test.ts, total 25 tests passing\n- Build verified, scan works on /tmp/testscan with redaction and JSON output\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(P2-A1): deterministic secrets scanner + CLI scan + MCP quick scan",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:56:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ffed56d702270c3feeea63086e1d8b3f41c6100",
"body": "…ts + security docs\n\n- Cloud module implemented (checklist, philosophy, remediation, report)\n- Unified MCP server SSOT, version from package.json\n- Safe installDir with isSafePath + backup mcp.json\n- 60 commands (was 8)\n- Tests (vitest) 14 passing, SECURITY.md, CONTRIBUTING.md, vitest.config.ts\n- Do\n[…]\np 3.0 -> 3.1.5, fix placeholders\n\nCI workflow excluded from this push due to GitHub App permission (needs workflows scope)\n\nCo-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(P0+P1): cloud module, unified MCP, safe install, 60 commands, tes…",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:44:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bf7212e0f5b1a8c7154851c2f1fd4c626fcdd358",
"body": null,
"is_bot": false,
"headline": "fix: v3.1.5 — wipe+recopy on install for clean updates",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:07:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f99ca0602f3196c5c282a5d97943fb88ba78a220",
"body": "All agents: rmSync + cpSync ensures renamed/deleted files\ndon't linger across updates. opencode commands dir handled\nsurgically (only audit* files removed) to preserve caveman\ncommands.",
"is_bot": false,
"headline": "fix: install wipes + re-copies to purge stale files on update",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:07:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c8c82f45c02ef45b6381f4ee4eeb9daffe3617a0",
"body": null,
"is_bot": false,
"headline": "fix: v3.1.4 — stale cmd cleanup",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:02:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a898da8a6debfeb5b2540c9a516fa284effade80",
"body": null,
"is_bot": false,
"headline": "fix: cleanup stale colon-named command files on install",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:02:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8641eda79c2270a8af56c2e142298082360ce7f0",
"body": null,
"is_bot": false,
"headline": "fix: v3.1.3 — colon→hyphen commands + opencode skill dir",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:00:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a05e0e81abe5ff8420b48e0492309025c9256223",
"body": "Colons in filenames likely broke opencode command parser.\nHyphens match caveman pattern (caveman-help.md).\nAlso installs to ~/.config/opencode/skills/cyberaudit/ for\nopencode skill context.",
"is_bot": false,
"headline": "fix: rename command files hyphen not colon + add opencode skill dir",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T18:00:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e45e55f0147870624abe11e625871f8ec0f67397",
"body": null,
"is_bot": false,
"headline": "fix: v3.1.2 — dynamic version from package.json",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:51:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e85a7c403e1c6c98d3ff90974343e1e52bb8bdd8",
"body": "Hardcoded version string fell behind npm version bumps.\nNow PKG.version via readFileSync — always in sync.",
"is_bot": false,
"headline": "fix: read version from package.json at runtime",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:51:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d42b7cd07eb6e2830766072f19ee331dd4fbd303",
"body": null,
"is_bot": false,
"headline": "chore: v3.1.1 — sync CLI version string",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:45:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4239fb98c11ceb537232dced44bf2faea400a53b",
"body": null,
"is_bot": false,
"headline": "chore: sync CLI version to 3.1.0",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:44:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0260762d2ea01e539ebf18829453e5b6a069924a",
"body": null,
"is_bot": false,
"headline": "feat: v3.1.0 — opencode command autocomplete [commands]",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:41:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a865a50f8a280644a509468ebead31d19b5b0dca",
"body": "7 command files (audit, audit:web, audit:mobile, audit:api,\naudit:quick, audit:report, audit:help) installed to\n~/.config/opencode/commands/ via CLI installer.\n\nRemoves 'already installed' guard so updates always apply.",
"is_bot": false,
"headline": "feat: add opencode slash-command files for autocomplete",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:41:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3294c5b0acebb4b42dde2999cd271ecb3f9a6fb",
"body": null,
"is_bot": false,
"headline": "chore: bump to 3.0.7 [API module]",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:16:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c6070e688c1d72b20ac901dfe2a088c9255fd38",
"body": "OWASP API Top 10 coverage: 11 skill files + 1 report template.\n- Philosophy + checklist + remediation library (3 base)\n- Type-specific: REST, GraphQL, WebSocket (3)\n- Vulnerability deep-dives: BOLA, BOPLA, rate limiting, inventory, third-party (5)\n- API report template (1)\n- Updated SKILL.md + COMMANDS.md with API commands and boot sequence",
"is_bot": false,
"headline": "feat: add API security audit module",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T17:16:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b60fc4631cb2b840c631a70a5e35c89caf292065",
"body": null,
"is_bot": false,
"headline": "3.0.6",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:58:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e460f33282f0b9fbeafa2aa7b9543541178d93c",
"body": "…mmands.md",
"is_bot": false,
"headline": "cli: add antigravity detection; skill: inline command tables; trim co…",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:58:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d439ac5d1cb1a15cff119dffa03a4def3d21c3cd",
"body": null,
"is_bot": false,
"headline": "3.0.5",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:31:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1c0eecb2e174c477b3420614a0a7af21e1cb6185",
"body": null,
"is_bot": false,
"headline": "cleanup: remove emojis/legacy from skills readme",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:31:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "135cced96d19a157ed2709b2b45ddbaa1ab91279",
"body": null,
"is_bot": false,
"headline": "3.0.4",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:29:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9aa211f7dadaf39796c18023828141c3260a48cf",
"body": null,
"is_bot": false,
"headline": "skil.md: add compatibility field for agent discovery",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:29:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1787416e95a3ddebaa2dbeadc041a213dc96ebf9",
"body": null,
"is_bot": false,
"headline": "3.0.3",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:28:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e8af96a3aaada7205f3b4ab46a1cd2b613fa151",
"body": null,
"is_bot": false,
"headline": "cli: check SKILL.md before skip install",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:28:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b29ddf6bf39cf41ed0255822cb6c1d89ace91f99",
"body": null,
"is_bot": false,
"headline": "cleanup: remove artifacts from skills add test",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:28:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "805009b09787ac87c7ceb7b9a7d1374e7d1243a4",
"body": null,
"is_bot": false,
"headline": "3.0.2",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:27:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a863f6c6500e611070024b581c510719340772b",
"body": null,
"is_bot": false,
"headline": "add SKILL.md with agent-compatible frontmatter",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:27:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "933edb6f947810e4a0ef7ed8815336497c866441",
"body": null,
"is_bot": false,
"headline": "3.0.1",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:09:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "efd1e84b8d2067ec78afa8a01e65770252b9a301",
"body": null,
"is_bot": false,
"headline": "remove postinstall (causes npm warnings)",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T12:09:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "51d836c2fa73b3898daa066867db3ee99bf08a2b",
"body": null,
"is_bot": false,
"headline": "v3.0: restructure into npm pkg + CLI install + MCP server",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T11:32:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "90500a8b56bb3fa518f2f6d67ceecfeabf0dac3e",
"body": "54 files, pure Markdown, zero dependencies.\nOWASP Top 10 2023 · MASVS 2.0 · CVSS 3.1\nWeb + mobile security audit framework for AI agents.",
"is_bot": false,
"headline": "CyberAudit Skill v3.0 Lunaire — English translation",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T10:22:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e9ac9ce46032c050e5ba1df5793a6be905de502a",
"body": null,
"is_bot": false,
"headline": "first commit",
"author_name": "ArisRoman",
"author_login": "ArisRoman",
"committed_at": "2026-07-19T10:19:57Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 14,
"commits_last_year": 40,
"latest_release_at": "2026-07-19T19:57:16Z",
"latest_release_tag": "v3.2.0",
"releases_from_tags": true,
"days_since_last_push": 0,
"active_weeks_last_year": 1,
"days_since_latest_release": 5,
"mean_days_between_releases": 0
},
"community": {
"has_readme": true,
"has_license": false,
"has_description": true,
"has_contributing": true,
"health_percentage": 57,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "cyberaudit-skill",
"exists": true,
"license": "MIT",
"keywords": [
"mcp",
"security",
"audit",
"cybersecurity",
"owasp",
"pentest",
"skill",
"ai-agent",
"opencode",
"claude-code",
"cursor"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/cyberaudit-skill",
"is_deprecated": false,
"latest_version": "3.2.0",
"repository_url": "https://github.com/ArisRoman/cyberaudit-skill",
"versions_count": 15,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2331,
"first_published_at": "2026-07-19T12:06:01.769000Z",
"latest_published_at": "2026-07-19T19:57:30.552000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 26291,
"source_files_sampled": 14,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 1,
"malicious_count": 0,
"assessed_package": "npm:cyberaudit-skill@3.2.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "commander",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^12.0.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 1,
"merged_prs": 1,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "ArisRoman",
"commits": 40,
"avatar_url": "https://avatars.githubusercontent.com/u/165471526?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": false,
"has_tests": true,
"ci_workflows": [],
"has_docs_dir": false,
"linter_configs": [
"eslint.config.js"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 0,
"reason": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/20 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": null,
"reason": "no workflows found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 0,
"reason": "license file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": null,
"reason": "no dependencies found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": null,
"reason": "No tokens found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "3ed2a0236a8d68424aff3dc98dd711107652bc62",
"ran_at": "2026-07-25T18:57:30Z",
"aggregate_score": 2.8,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": null,
"oldest_open_prs": [
{
"number": 2,
"created_at": "2026-07-25T08:25:13Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-19T19:46:24Z",
"ci_last_conclusion": null,
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/ArisRoman/cyberaudit-skill",
"host": "github.com",
"name": "cyberaudit-skill",
"owner": "ArisRoman"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 47,
"inputs": {
"security": 42,
"vitality": 66,
"community": 30,
"governance": 47,
"engineering": 44
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "moderate",
"name": "Vitality",
"value": 66,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 51,
"inputs": {
"commits_last_year": 40,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 1
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "1/52 weeks with commits",
"points": 0.7,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 1
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "40 commits in the last year",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 40
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 88,
"inputs": {
"releases_count": 14,
"latest_release_tag": "v3.2.0",
"releases_from_tags": true,
"days_since_latest_release": 5,
"mean_days_between_releases": 0
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "14 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 14
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 30,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "at_risk",
"name": "Community health",
"note": null,
"notes": [],
"value": 45,
"inputs": {
"has_readme": true,
"has_license": false,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "no license file detected",
"points": 0,
"status": "missed",
"details": [
{
"code": "license_absent",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 56,
"inputs": {
"packages": [
"cyberaudit-skill"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 2331
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,331 downloads/month across npm",
"points": 44.9,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2331,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 47,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 72,
"inputs": {
"merged_prs": 1,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "1/1 decided PRs merged",
"points": 38.2,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 1,
"decided": 1
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/20 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "critical",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 25,
"inputs": {
"followers": 0,
"owner_type": "User",
"is_verified": null,
"owner_login": "ArisRoman",
"public_repos": 4,
"account_age_days": 847
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of ArisRoman",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "ArisRoman"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "4 public repos, account ~2 yr old",
"points": 9.7,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 4
}
},
{
"code": "account_age_years",
"params": {
"years": 2
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"cyberaudit-skill"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "15 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 15
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "at_risk",
"name": "Engineering Quality",
"value": 44,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "at_risk",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_ci": false,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.js",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 42,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"dangerous_workflow",
"packaging",
"pinned_dependencies",
"signed_releases",
"token_permissions"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 28,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 13,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 5,
"scorecard_aggregate": 2.8
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/20 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no workflows found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "No tokens found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:cyberaudit-skill@3.2.0 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:cyberaudit-skill@3.2.0",
"assessed": 1
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 1,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 1,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 54,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 39,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.725,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "29 of 40 human commits state their intent (structured subject or explanatory body)",
"points": 38.7,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 29,
"sampled": 40
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_pinned_dependencies"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.js",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 40",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 40
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 26291,
"source_files_sampled": 14,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/14 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 14,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "critical",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T18:57:37.758176Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/ArisRoman/cyberaudit-skill.svg",
"full_name": "ArisRoman/cyberaudit-skill",
"license_state": "absent",
"license_spdx": null
}