Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 2.4.0 · 2026-07-29 11:40 UTC

chanceryhq / chancery

The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.

Go · HTMLApache-2.0★ 25 Sterne⑂ 1 Forkseit Juli 2026Auf GitHub ansehen ↗
ArtMCP-ServerKommandozeilenwerkzeugwie das ermittelt wird

chanceryhq/chancery erreicht einen Gesundheitsindex von 59 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (67/100) ab, am schwächsten bei Community & Adoption (44/100). Zuletzt vor 8 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

59
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer standardisierten Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr gewichtetes Mittel, kalibriert auf die Verteilung des öffentlichen Registers, sodass die Stufen Perzentilbedeutung tragen; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze Gefährdet von 34.

59
Außergewöhnlich93-100Die Spitzengruppe des Registers (≈ obere 5 %); erfüllt im Wesentlichen alle geprüften Kriterien
Exzellent80-92Durchgehend stark; geringfügige Lücken
Gut65-79Gesund; Lücken sind begrenzt und beherrschbar
Mittel50-64Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Schwach35-49Wesentliche Schwächen in mehreren Bereichen
Gefährdet20-34Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-19Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Der gewichtete Gesamtwert 56 wird auf der veröffentlichten Indexskala auf 59 kalibriert (Register-Kalibrierung 2026-08-02).

Eigentümerschaft

chanceryhqOrganisation
0 Follower2 öffentliche Reposseit Juli 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/chanceryhq/chanceryv0.2.0-3vor 8 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

67Gut · 21 % des Gesamtindex
Wie die Bewertung erfolgt
28.8/36Push-Aktualität — letzter Push vor 8 Tagen
2.1/36Commit-Rhythmus — 3/52 Wochen mit Commits
15.4/18Commit-Volumen — 51 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year51
human_commit_share1
days_since_last_push8
active_weeks_last_year3

Release-Disziplin

98Außergewöhnlich
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 2 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 8 Tagen
27/27Release-Rhythmus — ein Release etwa alle 8,7 Tage
8/10OpenSSF Scorecard: Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
Verwendete Eingangsdaten
releases_count2
latest_release_tagv0.2.0
releases_from_tagsnein
days_since_latest_release8
mean_days_between_releases8,7

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

44Schwach · 17 % des Gesamtindex
Wie die Bewertung erfolgt
22.4/60Stars — 25 Stars
0/25Forks — 1 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks1
stars25
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (Apache-2.0)
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
readme_badges
has_contributingja
has_issue_templatenein
has_code_of_conductnein
readme_badge_services
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

48Schwach · 23 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
42/42Issue-Lösungsquote — 100 % der Issues geschlossen
0/30PR-Annahme — keine entschiedenen Pull Requests oder keine Daten
0/13Newcomer PR acceptance — kein PR eines Erstbeitragenden in 30 Tagen entschieden
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs0
open_issues0
closed_issues6
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs0
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): PR-Annahme, newcomer_pr_acceptance. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
0/25Reichweite des Inhabers — 0 Follower von chanceryhq
3.6/25Kontohistorie — 2 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers0
owner_typeOrganization
is_verified
owner_loginchanceryhq
public_repos2
account_age_days24

Paketpflege

92Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 8 Tagen
12/20Versionshistorie — 3 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/chanceryhq/chancery
ecosystemsgo
any_deprecatednein
min_days_since_publish8

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

66Gut · 19 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 2 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
10/10Topics — 20 Topics
0/10Wiki
Verwendete Eingangsdaten
topicsai-agents, iam, identity, mcp, security, agents, credentials, tools, multi-agent, spawn, browser, browser-automation, hierarchy, cookies, password, mcp-client, mcp-server, mcp-tools, audit, audit-log
has_wikinein
homepage
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

52Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
2/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests. Die verbleibenden Gewichte wurden renormalisiert.

Abhängigkeits-Advisories

100Außergewöhnlich
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
0/25Indirekte Abhängigkeiten ohne bekannte Advisories — transitive Menge in diesem Bereich nicht von Entwicklungs- und Test-Abhängigkeiten trennbar
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages15
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Indirekte Abhängigkeiten ohne bekannte Advisories, Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. 15 aufgelöste Abhängigkeiten wurden mit OSV abgeglichen. Dieses Repository veröffentlicht kein Paket, das der Index auflöst; bewertet wurde daher der Abhängigkeitsgraph des Repositorys. Dieser Graph vermischt Entwicklungs- und Test-Pins mit ausgelieferten Abhängigkeiten, daher werden nur die deklarierten Laufzeit-Abhängigkeiten bewertet; transitive Befunde werden als Kontext ausgewiesen und fließen nicht in die Bewertung ein. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Trägt ein bewusst kleines Gewicht (4 %): Agenten-Tooling ist ein echtes Pflegesignal, doch ein Repository ohne jedes Signal kann weiterhin 100/100 erreichen.

57Mittel · 4 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 49 von 51 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,961
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — Go (statisch typisiert)
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 51
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesgo.sum
has_dockerfileja
typed_languageja
bootstrap_filesMakefile
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/43 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes54.882
source_files_sampled43
oversized_source_files0
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

25GitHub-Sterne
1Mitwirkende
51Commits, letzte 12 Monate
8Tage seit letztem Push
2Releases
1Bus-Faktor
0offene Issues
GoPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Weitere Details

OpenSSF Scorecard 4.0 / 10
4.0Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-29 11:40 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
4Security-Policysecurity policy file detected
8Signed-Releases2 out of the last 2 releases have a total of 2 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direkte Abhängigkeiten 4
RegistryPaketVersionsvorgabeManifest
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/oklog/ulid/v2v2.1.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gomodernc.org/sqlitev1.53.0go.mod
Alle Abhängigkeiten 15

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 4 direkte und 11 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Gogithub.com/golang-jwt/jwt/v5v5.3.1direkt
Gogithub.com/oklog/ulid/v2v2.1.1direkt
Gogithub.com/spf13/cobrav1.10.2direkt
Gomodernc.org/sqlitev1.53.0direkt
Gogithub.com/dustin/go-humanizev1.0.1indirekt
Gogithub.com/google/uuidv1.6.0indirekt
Gogithub.com/inconshreveable/mousetrapv1.1.0indirekt
Gogithub.com/mattn/go-isattyv0.0.20indirekt
Gogithub.com/ncruces/go-strftimev1.0.0indirekt
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daecindirekt
Gogithub.com/spf13/pflagv1.0.9indirekt
Gogolang.org/x/sysv0.44.0indirekt
Gomodernc.org/libcv1.73.4indirekt
Gomodernc.org/mathutilv1.7.1indirekt
Gomodernc.org/memoryv1.11.0indirekt
Abhängigkeits-Advisories 0

Dieses Repository veröffentlicht kein vom Index auflösbares Paket, daher wurde sein eigener Abhängigkeitsgraph bewertet – 15 Pakete, darunter auch Entwicklungs- und Test-Pins, die nie ausgeliefert werden: 0 tragen bekannte Advisories, davon 0 direkte.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "iam",
        "identity",
        "mcp",
        "security",
        "agents",
        "credentials",
        "tools",
        "multi-agent",
        "spawn",
        "browser",
        "browser-automation",
        "hierarchy",
        "cookies",
        "password",
        "mcp-client",
        "mcp-server",
        "mcp-tools",
        "audit",
        "audit-log"
      ],
      "is_fork": false,
      "size_kb": 3499,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 334383,
        "CSS": 13532,
        "HTML": 44856,
        "Shell": 2180,
        "Makefile": 194,
        "Dockerfile": 367,
        "JavaScript": 8009
      },
      "pushed_at": "2026-07-21T07:39:20Z",
      "created_at": "2026-07-04T12:50:16Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T07:40:02Z",
      "description": "The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "HTML"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "chanceryhq",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/299839401?v=4",
      "created_at": "2026-07-04T12:48:19Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 24
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-20T13:47:41Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T22:04:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
          "body": "A broken ring forming a C, holding two bars that narrow. A chancery is\nthe office that keeps the seal, and the narrowing bars are the property\nthe whole product rests on: delegated authority can only shrink. The\nold mark was a generic pillar that said nothing specific and tied to\nthe name not at all\n[…]\nnly variant because the inner bars merge below\nabout 20px. Site favicon links move from an inline data URI to real\nPNGs, versioned so the old cached icon is replaced. README gets a\ntheme-aware lockup.",
          "is_bot": false,
          "headline": "brand: new mark, the seal",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-21T07:39:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80d9cd58cbe2238b0e143453390862dd1d5a9b6c",
          "body": "A different UID is the only boundary that actually holds here: ptrace\nchecks credentials, so being an ancestor stops helping. --run-as <user>\nspawns the server under its own UID, and the sealed-file run dir and\nits contents are chowned to that user so --secret-file keeps working.\n\nApproaches that lo\n[…]\n--confine).\n\nTightens the SECURITY.md invariant: 'agents never hold credentials' is\nprecise about the model's context and the agent's environment, not\nOS-level isolation from same-UID code. 109 tests.",
          "is_bot": false,
          "headline": "G17: ship --run-as privilege separation for the tool server",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:49:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a138f5c9f7ea2e54965fc7ef98452a9410a33f8",
          "body": "…bounded\n\nSealed secrets are injected into the tool server's environment, so\n/proc/<pid>/environ exposes them to any same-UID process — and to\nancestors under the default yama ptrace_scope=1. Since the agent\nruntime typically spawns the wrap, a hostile runtime (distinct from a\nprompt-injected model)\n[…]\nsolation from hostile code sharing the UID, and the tables now say so.\nDeployment guidance gains the mitigation: separate OS user, or\nptrace_scope>=2.\n\nReported by u/Psychological_Arm645 on r/AutoGPT.",
          "is_bot": false,
          "headline": "SECURITY: add G17 — credential isolation is UID-bounded, not process-…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:43:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d32ccacf283db6071737e282c3084043d1b30983",
          "body": "Anyone who loaded the page while /assets/* still carried\n'immutable, max-age=31536000' holds that CSS for a year and would never\nsee the aspect-ratio fix. A changed URL is a different cache entry, so\n?v=2 forces one clean refetch; the corrected Cache-Control keeps future\nedits reachable without this.",
          "is_bot": false,
          "headline": "site: version asset URLs to break the poisoned immutable cache",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:34:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c01ee77b008d9ce94938268146645d33d5fcb2e",
          "body": "/assets/* was pinned for a year with immutable, which covers style.css\nand app.js — filenames that never change. Any returning visitor would\nhave been stuck with stale CSS indefinitely (exactly how the squashed\n-image fix failed to appear). Images keep the year; CSS/JS revalidate\nwith ETag.",
          "is_bot": false,
          "headline": "site: don't immutably cache un-hashed CSS/JS",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:31:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4c1fb76583a8920460165fbc050caca3b950ae7",
          "body": "Images declared width/height 1600x1000 against real 2880x1720 assets,\nand the img rule lacked height:auto — so max-width squashed both\ndashboard shots. Corrected the declarations and added height:auto.\n\nCopy moves from personal-project voice to product voice: drops the\nfooter byline, 'Talk to me' becomes 'Get in touch', and the mailto\ntemplate loses its first-name salutation.\n\nPages is disabled (Vercel is canonical at chanceryai.vercel.app), so\nits deploy workflow goes with it.",
          "is_bot": false,
          "headline": "site: fix squashed screenshots, product voice, drop GitHub Pages",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:30:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8793fe7416176ba919088a83e052b1bd7572148f",
          "body": "Above-the-fold content was gated behind IntersectionObserver plus a\nstagger, so the hero sat blank for ~1s on load — bad on slow connections\nand worse for link-preview crawlers (Product Hunt, LinkedIn) that\nscreenshot early. You don't animate what's already on screen at load.",
          "is_bot": false,
          "headline": "site: render the hero immediately, animate only below the fold",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:25:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aa3eecf5267789b3dbcef3f1d937c0846ec2250",
          "body": "…rprise CTA\n\nReplaces the static brochure with a real page: a typed terminal replaying\nthe enforcement story (grant → allow → deny → revoke → deny), scroll\nreveals, a flow diagram of the gate, tabbed workflows, dashboard shots,\nand an enterprise section with a prefilled mailto.\n\nAccessibility/robust\n[…]\nmotion renders everything static.\n\nZero third-party requests: system fonts, no CDN, no analytics — which\nlets the CSP be default-src 'none' with 'self' for script and style, no\nunsafe-inline anywhere.",
          "is_bot": false,
          "headline": "site: proper landing page — animated terminal, interactive tabs, ente…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:24:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a994cad55be9fa2f2df015fb43a2dc34f68a3626",
          "body": "The README had grown into a manual — 280 lines, five inlined feature\nwalkthroughs, and a 19-row RFC table. Now 126 lines: what it is, why,\ninstall, one real end-to-end example, a compact capability list, and a\ndocs table pointing at the material that already exists elsewhere.\n\nrfcs/README.md is a ge\n[…]\nthem.\n\nAdds vercel.json (static site/ deploy, security headers, immutable\nasset caching) and puts the dashboard screenshots on the landing page,\nwhere they earn their space, rather than in the README.",
          "is_bot": false,
          "headline": "README: cut to essentials; RFC index moves to rfcs/README.md",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:53:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2951e92fed8107967433eb31976ade7c7abaee81",
          "body": "Drops the pre-alpha label. Every design RFC moves from In Review to\nLocked (design settled and implemented); README gains a Status section\nstating what beta does and doesn't promise — the security model is\nsettled and gaps are published, but CLI/REST may still break before\n1.0.\n\nAdds CHANGELOG.md (v\n[…]\ne landing page from\nRFC-010's MVP item 8, deployed to Pages by a workflow. Assets are\nlocal to site/ because raw.githubusercontent serves a sandbox CSP that\nblocks embedding.\n\n105 tests, go vet clean.",
          "is_bot": false,
          "headline": "v0.2.0: beta — lock all 19 RFCs, add changelog and landing page",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:44:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f8ae24a4e62376dc098647d28a20b9ffff852df",
          "body": "POST /v1/leases/verify accepts optional xref=<system>:<opaque-id>\n(shape-checked, 400 on malformed). On a VALID lease it is recorded as\nmcp.call_xref carrying the lease's writ, agent, and resource plus the\nopaque foreign id — the one moment two audit chains describe the same\nevent. Invalid leases re\n[…]\n cooperating servers read wid/blk from the lease they\nalready hold.\n\nVerifyLease now returns full LeaseInfo claims. Dashboard event map,\nverify.md walkthrough, RFC-015 amendment; 105 tests. Closes #6.",
          "is_bot": false,
          "headline": "RFC-015 §10: audit cross-references at lease-verify (xref)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T11:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2af06ebc129d9273eb227fc369b2c2514041c525",
          "body": "What-you-get bullet list up top (one line per RFC arc); the RFC-015-018\nmechanisms broken out of the dense paragraph into two sections with\nrunnable commands (callee trust: install/pin/confine/dry-run; per-call:\ntask/intent/lease); matching subheadings for the spawn, wrap, browser,\nand control-plane blocks so 'Try it' reads as one tour.",
          "is_bot": false,
          "headline": "README: capability summary + structured tour",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T10:04:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "571e1a2963ada4a3f5575395681b03daea3a0dc0",
          "body": "chancery mcp install <pkg>@<exact-version>: one-time npm install\n(scripts disabled, local paths copied not symlinked) into\n$CHANCERY_DATA/servers/<ns>, Merkle tree-pinned automatically;\nmutable specs refused — a mutable reference is not an identity. A\ntree pin now follows its namespace: plain wraps \n[…]\n), G16 added (host-granular\negress; Linux egress cooperative until netns). 104 tests / 11\npackages, including confinement against the real OS sandbox and the\ninstall→pin→poison→refusal arc. Closes #5.",
          "is_bot": false,
          "headline": "RFC-018: frozen installs and manifest-bounded confinement",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T18:02:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17188a83ae5cb093f26c31dd322055bde05a5bc3",
          "body": "Pins are now (kind, identity) pairs — strongest applicable tier wins:\n\nT3 digest: a container image reference pinned by digest in the server\nargs (image@sha256:...) becomes the identity automatically; mutable\ntags are never identities. Chancery verifies the reference, the\ncontainer runtime verifies \n[…]\ndence, poisoned-dependency e2e).\nG13 narrowed in SECURITY.md/RFC-009: the gap is now the DEFAULT's,\nwith shipped opt-in mitigations; RFC-016 rewritten around the tiers;\nREADME/concepts/verify updated.",
          "is_bot": false,
          "headline": "RFC-016 T2/T3: tree pinning and image-digest pinning",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T17:32:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f58fa4dabcd50b6d276d4b45c78b96dd81c2397",
          "body": "Closes three roadmap issues born from practitioner review:\n\nRFC-015 (#2): the audit trail now distinguishes admitted from happened\n(mcp.call_result committed/failed), and 'mcp wrap --lease' stamps each\nadmitted call with a 30s signed lease in params._meta that cooperating\nservers verify via POST /v1\n[…]\ns only. Arguments pass through transiently and are\nnever stored.\n\n89 tests across 10 packages; gaps G13-G15 added to SECURITY.md and\nRFC-009; RFC-000/005/008 amended; concepts/verify/playbook updated.",
          "is_bot": false,
          "headline": "RFC-015/016/017: call lifecycle + leases, server pinning, intent socket",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T13:40:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c5b18a698b73f9996d4ec7da119e81c678d0227",
          "body": null,
          "is_bot": false,
          "headline": "README: dashboard screenshots (audit timeline, writ delegation tree)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T09:10:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f6dda69f002ff36396e2bde4ed36b6eeef33258",
          "body": "asciinema cast + GIF (embedded in README) recorded against the\nbrew-installed v0.1.0 binary in an isolated CHANCERY_DATA dir;\ndemo/demo-driver.sh regenerates it.",
          "is_bot": false,
          "headline": "Demo recording: 40-second grant/allow/revoke/deny/audit arc",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T08:27:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da257f750e929f7481066130ac5b328b88b08935",
          "body": "Without it, macOS quarantines the un-notarized binary and newer\nreleases delete it from the Caskroom seconds after install, leaving\na dangling /opt/homebrew/bin/chancery symlink.",
          "is_bot": false,
          "headline": "Cask post-install hook: strip Gatekeeper quarantine from the binary",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T22:01:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21d06772e4ede9099ee70fa1feb02c98dc9fe0b0",
          "body": null,
          "is_bot": false,
          "headline": "Ignore local Stitch design exports",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:53:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae937837791311f5b3b92ffdf7314571a14fe9d1",
          "body": "Void background, seal-purple accent, dual-font ledger (Inter UI /\nmono identity data), per-tab stat cards, uppercase mono table\nheaders, writ cards with boxed delegation-tree nodes and right-angle\nconnectors. Same read-only data plumbing: token gate, 4s polling,\nintegrity pill, text-node-only rendering.",
          "is_bot": false,
          "headline": "Dashboard visual redesign from the Stitch design system",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:40:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bda521f3cb7340b4090aa36ff1290bd46d259e6",
          "body": "…ty chips\n\n- timeline speaks human: 'Authority granted to deploy-bot', 'Agent\n  spawned: worker-1', 'Spawn refused' — raw event name demoted to a\n  small mono subline; category dots (grant/action/security/lifecycle)\n- times are relative ('12m ago', 'in 2h') with the full timestamp on\n  hover; templa\n[…]\nnt/caveats\n  (display only, unverified) so narrowing is visible at a glance\n- owners shown as emails (user: prefix stripped); writ ids demoted to\n  hover/sublines; agents show 'spawned by orch' origin",
          "is_bot": false,
          "headline": "Dashboard readability: plain-English events, relative times, capabili…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:38:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e87f007d2020e4c69ada4cae36aefb66db9246b3",
          "body": "The product's proof is visual — the timeline and the delegation tree —\nso chancery serve now ships a dependency-free, go:embed'd dashboard:\n\n- live audit timeline (filterable, ALLOW/DENY pills, agent names\n  resolved) with a permanent integrity badge backed by audit verify\n- agent roster with state \n[…]\nee, JWS omitted) — the\n  route RFC-008 documented but the MVP never implemented\n- verified live in a browser across all four views; 79 tests; docs,\n  playbook step 8, SECURITY G12, RFC-000/009 updated",
          "is_bot": false,
          "headline": "RFC-014: embedded read-only dashboard at /ui",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:32:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba10d2e3f466d755936ce507a950853210337b51",
          "body": "Denials are answered immediately by the proxy while allowed calls\nround-trip through the server, so the deny usually prints first; the\nsh stub always replies with id 0. Show the exact expected lines and\nadd a troubleshooting row so neither reads as a failure.",
          "is_bot": false,
          "headline": "Playbook step 5: document response ordering and the stub's id:0",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T07:43:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db1a4e2b7c469a7fcbf5a8160cd04a963bbd345b",
          "body": "One ~20-minute sitting: identity/versioning, delegation-only-narrows,\nsealed secrets (grep-for-plaintext), layered policy (allowlist\nsubtracts at the ACTING agent's block, never adds), in-path MCP\nenforcement as the delegated agent, audit tamper detection, lifecycle\nterminality, DENY-as-200 over HTT\n[…]\n the real pitfalls hit\nduring Vantage dogfooding (zsh comments, split heredocs, lost env\nvars, silenced stderr, wrap-awaits-client, exact host matching).\nLinked from README, docs index, and verify.md.",
          "is_bot": false,
          "headline": "Add docs/testing-playbook.md: guided run of every feature (001-013)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-06T04:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33a6c83780c65f4d56f517e94f71b26057ff2c12",
          "body": "Browser agents inherit human sessions — bearer, unscoped, invisible to\nIAM. This makes the session a credential and the navigation an action:\n\n- session custody: mcp wrap --secret-file materializes sealed storage\n  state (cookies) as a 0600 file in a private run dir the SERVER reads\n  (chancery-file\n[…]\naywright MCP recipe\n  (--isolated --storage-state=chancery-file:STATE)\n- 6 new tests incl. full browser e2e (78 total); RFC-000/005/009\n  amended; SECURITY.md gap G11; concepts + verify guides updated",
          "is_bot": false,
          "headline": "RFC-013: browser sessions and tokens as governed credentials",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T18:15:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d19a05fa20aaa000337c5f2a8aeabff8bf4d683",
          "body": "Orchestrators that create agents at runtime (the common multi-agent\npattern) no longer need the admin token. Spawning is itself a\nwrit-governed action:\n\n- admin verb joins the capability grammar (RFC-004 amended);\n  Cap.Implies subsumption for template ceilings\n- templates: human-approved max caps +\n[…]\nly (ActiveErr everywhere);\n  chancery agent sweep retires; agent list shows expired state\n- 10 new tests (72 total); RFC-000/004/007/008/009 amended;\n  SECURITY.md gap G10; docs + verify guide updated",
          "is_bot": false,
          "headline": "RFC-012: dynamic agent creation — writ-gated runtime spawn",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T17:49:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a125b8f2e82d63681ac9488bdd1e5fcd3753809",
          "body": "All four surfaced by testing against a real multi-agent system:\n\n#1 (footgun) mcp wrap --agent X now evaluates X's own writ block, not\n   the writ's latest block (which may belong to a delegated sub-agent).\n   New store.BlockForSubject; explicit --block is verified against\n   --agent. Previously a r\n[…]\n\n   check) — no more granting writs to revoked agents.\n\nTests: block-for-subject selection + narrowing, grant-refuses-inactive,\nno-block-for-agent is ErrNotFound. All 10 packages green; verified live.",
          "is_bot": false,
          "headline": "Fix 4 findings from live Vantage dogfooding",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T10:14:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a9575a3e62c91ef3c30492e55890a1e0a6bbb9b",
          "body": "User-facing verification guide: hands-on, CLI-only, copy-paste checks\nthat each RFC 001-009 does what it claims, with real expected output,\nseparate from the go test suite. Every block was run to capture real\noutput before documenting (caught and fixed an allow-list usage error\nin the draft).\n\nAlso \n[…]\nCLI surface (re-register errored). Added\n'chancery agent version <name>' + service.AddVersion (immutable, keeps\nhistory, emits shadow-agent event on unknown agent), tested. README\nlinks the new guide.",
          "is_bot": false,
          "headline": "Add docs/verify.md (verify each RFC by hand) + agent version command",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T09:04:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6ed6e38b6b0299014391a47ef9d9bd860bd1951",
          "body": "Adds the honest general-purpose story and a non-MCP setup+test\nwalkthrough. Distinguishes the two governance modes: in-path/enforced\n(MCP today, unbypassable) vs advisory/check (any agent, any language,\ntoday via POST /v1/writs/{id}/check + SDK Guard). Shows a plain DB ETL\nagent governed by read:/write: writs with instant revocation and\ntamper-evident audit — verified working via CLI and HTTP before\ndocumenting. README gains the MCP-first-not-MCP-only framing up top.",
          "is_bot": false,
          "headline": "docs: governing any agent (MCP-first, not MCP-only)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:52:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0588ee17c51534a86b5a27062c72789de75c121e",
          "body": "Fills the developer-setup gap: prerequisites (Go 1.26+, no CGO), build,\nrunning tests (incl. -short to skip the subprocess integration test and\nmake demo), a table mapping all 10 packages' tests to the RFC each\nproves, the repo layout, conventions (RFC discipline, the two non-\nnegotiable invariants), and the DCO (no CLA) contribution flow. README\ngains a 'Build & test from source' section linking it.",
          "is_bot": false,
          "headline": "Add CONTRIBUTING.md: build, test, repo layout, RFC-to-test map",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:13:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f131570e62cce1866e03039cecac971fcda80039",
          "body": "Captures the launch checklist durably (out of chat): pre-tag gates\n(3 real users, demo cast, quickstart re-verified), one-time org/repo\nsettings (public packages, chancery.dev, Pages, vuln reporting), the\nrelease cut + verify steps, announce channels, and known non-blocking\nfollow-ups. Release pipeline proven via a private v0.0.1 dry-run.",
          "is_bot": false,
          "headline": "Add LAUNCH.md — go-live runbook and gates",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:48:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bf60180aa7a9f2008e5b24bb637e5c867287537",
          "body": "The homebrew_casks repository block had no token, so goreleaser used\nthe default Actions token (cannot write cross-repo) and the tap push\n403'd. Point it at HOMEBREW_TAP_GITHUB_TOKEN (set from the\nTAP_GITHUB_TOKEN secret in release.yml).",
          "is_bot": false,
          "headline": "release: use the tap PAT for the Homebrew cask push",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:36:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ca5aa7ac8534a2d1a534cea9644079b27dde453",
          "body": "… docs\n\nWeek 4 (quickstart): QUICKSTART.md walks governing the real official\nfilesystem MCP server; a permanent CI-safe end-to-end test\n(cmd/chancery/wrap_integration_test.go) spawns a real child MCP server\nprocess and proves list-filter/allow/deny/mid-session-revoke + audit\nintegrity. Verified manu\n[…]\nd against a real\nhttptest control plane.\n\nWeek 8 (docs): docs/ for GitHub Pages (native Jekyll from /docs, no CI),\nindex + concepts; README gains a Guides section.\n\nAll 10 packages green; gofmt clean.",
          "is_bot": false,
          "headline": "weeks4-8: real-server quickstart, examples, shadow-agent obs, Go SDK,…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T19:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac965281b9e04516f8498cf2b57a0ad9eac2f3fe",
          "body": "Cross-platform static binaries (linux/darwin x amd64/arm64), multi-arch\ndistroless image to ghcr.io (dockers_v2 + buildx), Homebrew cask on\nchanceryhq/homebrew-tap, per-archive SBOM (syft), keyless cosign signing\nof checksums via GitHub OIDC. Version/commit/date injected via ldflags;\nchancery --vers\n[…]\n+ generated cask). Image cosign signing is a noted\nfast-follow pending dockers_v2 signing surface.\n\nPrereqs for first real release: create chanceryhq/homebrew-tap repo and\nset TAP_GITHUB_TOKEN secret.",
          "is_bot": false,
          "headline": "weeks2-3: release packaging — goreleaser, cosign, SBOM, Docker, brew",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:16:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7129083f873f8c9dda21496e9220f945bb4aa81",
          "body": "CLI register/instance-start/grant/delegate/check now call\ninternal/service (RFC-008 §4: one implementation shared with the HTTP\nAPI) instead of duplicating store+writ+policy logic; the mcp wrap\ndecider reuses service.Decide, keeping only the PEP-specific instance-\nliveness gate. Removes ~120 lines o\n[…]\ndecision for PEPs) and\nstore.AuditSince (tail cursor). New: chancery audit --follow streams\nevents live for the demo (ALLOW scrolls, DENY appears on revoke).\nAll tests green; demo and follow verified.",
          "is_bot": false,
          "headline": "week1: route CLI through the service layer; add audit --follow",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:11:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7d2dbe68328369e5898d40acc5173c09c95a0668",
          "body": null,
          "is_bot": false,
          "headline": "gitignore: exclude local tooling state",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57463e9fcc76f52877e402045bfae85b02943f79",
          "body": "Founder decision: defer chancery.dev (~$12/yr) until revenue; docs on\nchanceryhq.github.io; vulnerability reporting via GitHub private\nreporting (an improvement regardless — no email infra, built-in CVE\nworkflow). Squatting risk on the public name recorded in RFC-010.",
          "is_bot": false,
          "headline": "Free-domain path: GitHub Pages + private vulnerability reporting",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a86663237e5e0dcac9a95dde22c09690298bcf2",
          "body": "Locks: boundary test (single-trust-domain security/operability = OSS;\norg-scale value = enterprise); two published promises (no license\nflip ever; security never paywalled — all G1-G9 close in OSS); locked\nledger (Cedar/approvals/Postgres/all PEPs OSS; SSO/SCIM, multi-\ntenancy, SIEM exporters, compl\n[…]\nin OSS schema;\nchancery-ee orchestrates per-tenant cores over the public API); DCO\nno CLA (relicensing door welded shut); lockstep releases. Apache-2.0\nLICENSE at root. This closes RFC series 000-011.",
          "is_bot": false,
          "headline": "RFC-011: open-core boundary — the test, the ledger, the two promises",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c006c9542f6a94614e552c3a0316192d49a409ca",
          "body": "Locks: MVP = v0.1.0 with the enforcement wedge (registry inside it);\n12-week plan (CLI->service migration, packaging w/ cosign+SBOM, real-\nserver quickstart, Claude Code + LangGraph examples, shadow-agent\nobservation v0, Go SDK, docs, 3 external users before tag); demo\nscript locked word-for-word; c\n[…]\nadmap, HTTP/shell/browser PEPs, PoP, Cedar, Postgres to v1).\nShips: SECURITY.md (gap table G1-G9, invariants you can hold us to),\nMakefile, scripts/demo.sh (the 60-second arc, CI-runnable — verified).",
          "is_bot": false,
          "headline": "RFC-010: MVP scope — the 90-day build, demo locked, cutlines named",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a1385a3340e2cf8d1a5984481726a8e65a04dce",
          "body": "Research at series close (OWASP ASI, CSA MAESTRO/agentic IAM, Gartner\nguardian agents + agent sprawl): the five defining questions were all\noutbound and known-population. Added Q6 (inbound/agent-to-agent trust\n- ASI07, ~24% org visibility) and Q7 (unregistered agents - discovery\nas a byproduct of en\n[…]\nis\nthe product, ASI06 memory poisoning is the argued scope line) and\nadopts MAESTRO as process reference. Positioning notes: deterministic\nguardian layer, proportional governance as writ policy packs.",
          "is_bot": false,
          "headline": "RFC-000/009 addenda: extended question set and agentic Top 10 mapping",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61d1ed6a95da0469e2c2d6b28e33841d2ab8c1c2",
          "body": "…table\n\nLocks: trust boundaries (model untrusted, operator trusted in MVP,\nserver semi-trusted); STRIDE walk per component; OWASP LLM Top 10\nmapping (LLM06 excessive agency is the product); abuse cases walked;\npublished MVP gap table G1-G9 each with owner and phase (bearer docs,\nsingle admin token, \n[…]\nI-gated:\nalg:none rejection for both token types, HS256 key-confusion rejection,\ncross-writ block substitution, unsigned delegation block on signed\nchain, exp-required, capability-free grants refused.",
          "is_bot": false,
          "headline": "RFC-009: threat model — STRIDE, OWASP LLM Top 10, and the honest gap …",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:39:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb12309ebc1cdce1d65b1576e9eea3c738328596",
          "body": "… serve\n\nLocks: Vault-style REST/JSON under /v1 mirroring the principal model;\nDDL as the data contract (SQLite->Postgres behind the store seam);\ndigests-only registration (D6 extended to the wire); admin bearer token\n(hashed at rest, constant-time compare, failures audited) with v1 path\nto identity\n[…]\ntest full flow (register->instance->grant->ALLOW->revoke->\nDENY-at-registry->resurrection-blocked), auth rejection + audit, DENY-as-\n200, delegation+attenuation over HTTP, token never in audit stream.",
          "is_bot": false,
          "headline": "RFC-008: data model and APIs — REST/JSON /v1, service layer, chancery…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:36:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2779517ee71678f960df1621d7b87ff7e38acf4",
          "body": "…eans terminal\n\nLocks: per-layer state machines (agent active⇄suspended→retired/revoked,\norphaned exits only via ownership transfer); terminality enforced at the\ndata layer (no client can resurrect); suspend/revoke/retire/orphan as\ndistinct audited verbs; nothing ever deleted; cascade-by-check (one\n\n[…]\n TTL.\nchancery agent retire/orphan/transfer + terminality warnings.\nTests: full transition matrix, no-resurrection property, orphan blocks\nissuance until transfer, retired names not silently reusable.",
          "is_bot": false,
          "headline": "RFC-007: lifecycle and revocation — locked state machines, terminal m…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:32:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05f6f7fa1748ecce37a4f252c617a6cc2e1c7cff",
          "body": "Locks: fixed metadata-only schema (no payload columns — D6 by DDL),\nhash-chained events (prev_hash + SHA-256 over canonical encoding,\ngenesis sentinel), single-writer chain append, locked event taxonomy,\nattribution embedded per row (agent/instance/writ/lineage), NDJSON\nexport, deny-on-audit-failure\n[…]\nappen). chancery audit verify walks the chain and names the first\nbreak. Tests: clean verify, edit/deletion detection with prefix\nproperty, attribution round-trip, allowed-but-unauditable call denied.",
          "is_bot": false,
          "headline": "RFC-006: audit and attribution — hash-chained, metadata-only evidence",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:29:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26b52f631392dc52407f3bb27ba87663fad8672a",
          "body": "Locks: protocol-aware stdio proxy that owns the server process; per-call\nPDP with fresh registry state (revocation = next call, not next TTL);\ntools/list filtered, tools/call enforced (filtering is UX, the call path\nis the boundary); JSON-RPC -32001 denials naming the layer; sealed\nsecrets injected \n[…]\nrnal/mcp +\nchancery mcp wrap. Unit tests: forward/deny/filter/malformed/no-name/\npassthrough. Live integration test passed: mid-session agent revocation\nblocked the next call with attributed timeline.",
          "is_bot": false,
          "headline": "RFC-005: runtime enforcement — the MCP proxy, in-path and unbypassable",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:19:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44e030d20c5683cf7b0f700a0c5bfaadf9169242",
          "body": "Locks: conjunction of layers where only the writ grants (L1) and every\nother layer only denies — allow-lists (L2, MVP), Cedar org policy (L3,\nv1), approvals with reserved 'hold' effect (L4, v1); default-deny;\ncapability grammar locked (verb registry, /-segmented resources,\ntrailing-* with subtree-vs\n[…]\n delegates to it;\nper-agent tool_allowlists + 'chancery agent allow'. Tests: grammar\nvalidity table, match semantics table, layer attribution, empty-list vs\n!none sentinel, nil-authority default deny.",
          "is_bot": false,
          "headline": "RFC-004: policy and authorization — layered PDP, locked grammar",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:14:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d739d54d8f43991617a8e6d367280dc4f6d0090c",
          "body": "Locks: one sealed store (AES-256-GCM, per-entry nonces, name-bound AEAD),\ninjection at the enforcement point per action after writ+policy checks,\ncredential classes sequenced static->OAuth->STS->mTLS, rotation as one\nre-seal. internal/seal + chancery secret put/list/rm. Tests: roundtrip,\nno plaintext on disk, cross-name swap rejected, wrong-key fail-closed,\ntamper rejection, metadata-only listing.",
          "is_bot": false,
          "headline": "RFC-003: credential broker — sealed store, agents never hold secrets",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:10:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1b9e5f2e6a094aff9140db2df398e17803c83b",
          "body": "RFC-001/002 running code: SQLite registry (agents/versions/instances,\nthree-layer revocation, fail-closed CheckIssuable), ES256 identity\ndocuments (5-min TTL, WIMSE-style claims, cnf reserved), writ grant/\ndelegate/verify/check with structural attenuation, delegation trees in\nthe registry, metadata-only audit timeline, cobra CLI, CI. Tests cover\nthe RFC invariants: widening unrepresentable, TTL monotonic, depth\nbounded, null-authority refused, tamper detection, revocation at every\nlayer.",
          "is_bot": false,
          "headline": "chancery: registry, identity documents, and writs — first working slice",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ca61e7fb9b250f0bcc376c0e4d25e0e20510b20",
          "body": "Locks: authority as a JWS grant-chain where block 0 grants capabilities\nand later blocks may only add caveats (widening unrepresentable);\neffective authority = grant ∩ caveats; TTL monotonicity; bounded depth;\nthe chain IS the lineage (user -> agent -> sub-agent), embedded in the\ncredential; subtree revocation at any block. Central append in MVP,\nBiscuit-style offline attenuation reserved for v1 (dk field).",
          "is_bot": false,
          "headline": "RFC-002: lineage and delegation — the writ",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "779f3c58a1fd64915b7b6cd1588118b4a7699240",
          "body": "Locks: agent as third principal class; three-layer identity\n(Agent -> Version -> Instance) with content-addressed versions;\nSPIFFE-compatible naming, WIMSE-compatible identity documents (ES256,\n5-min TTL, cnf slot from day one); registry-born, attestation-confirmed\nbirth model; three-layer revocation. Also: Chancery confirmed as final\nproduct name (RFC-000 D7 updated).",
          "is_bot": false,
          "headline": "RFC-001: agent identity model",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:52:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a70c3367294cced7170e4fb6e8dc20ce9f577091",
          "body": "…gents\n\nLocks: positioning (neutral self-hosted system of record), open-core\nApache-2.0, Go, MCP-first wedge, control-plane-first with own minimal\nbroker, metadata-only audit invariant, codename Chancery.",
          "is_bot": false,
          "headline": "RFC-000: vision and plan for Chancery, the identity provider for AI a…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 2,
      "commits_last_year": 51,
      "latest_release_at": "2026-07-20T13:47:41Z",
      "latest_release_tag": "v0.2.0",
      "releases_from_tags": false,
      "days_since_last_push": 8,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 8.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/chanceryhq/chancery",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/chanceryhq/chancery",
          "is_deprecated": false,
          "latest_version": "v0.2.0",
          "repository_url": "https://github.com/chanceryhq/chancery",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T13:44:37Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 25,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-17",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 54882,
      "source_files_sampled": 43,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 15,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/oklog/ulid/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": true,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.53.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.73.4",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 15,
        "direct_count": 4,
        "indirect_count": 11
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 6,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "anee769",
          "commits": 51,
          "avatar_url": "https://avatars.githubusercontent.com/u/67168113?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "2 out of the last 2 releases have a total of 2 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
        "ran_at": "2026-07-29T11:40:42Z",
        "aggregate_score": 4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T07:40:02Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/chanceryhq/chancery",
    "host": "github.com",
    "name": "chancery",
    "owner": "chanceryhq"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 56 is calibrated to 59 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 56,
            "calibrated": 59,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 59,
      "inputs": {
        "security": 52,
        "vitality": 67,
        "community": 44,
        "governance": 48,
        "calibration": "2026-08-02",
        "engineering": 66,
        "ai_readiness": 57,
        "weighted_overall_raw": 56
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 67,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "weak",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "commits_last_year": 51,
              "human_commit_share": 1,
              "days_since_last_push": 8,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "51 commits in the last year",
                "points": 15.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v0.2.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 8.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "weak",
        "name": "Community & Adoption",
        "value": 44,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "forks": 1,
              "stars": 25,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "25 stars",
                "points": 22.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "weak",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): PR acceptance, Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "pr_acceptance",
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 74,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 6,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 0,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "chanceryhq",
              "public_repos": 2,
              "account_age_days": 24
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of chanceryhq",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "chanceryhq"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 3.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/chanceryhq/chancery"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "3 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "ai-agents",
                "iam",
                "identity",
                "mcp",
                "security",
                "agents",
                "credentials",
                "tools",
                "multi-agent",
                "spawn",
                "browser",
                "browser-automation",
                "hierarchy",
                "cookies",
                "password",
                "mcp-client",
                "mcp-server",
                "mcp-tools",
                "audit",
                "audit-log"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 52,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 15 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 15
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 15,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 15,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.961,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "49 of 51 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 49,
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 51",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 54882,
              "source_files_sampled": 43,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/43 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 43,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "weak",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "application"
      ],
      "labels": [
        "mcp-server",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "library": 3,
        "mcp-server": 4
      },
      "primary": "mcp-server",
      "evidence": [
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:github.com/spf13/cobra",
          "weight": 4
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:go",
          "weight": 3
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-server",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-tools",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "low",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": false
    },
    "metrics_version": "2.4.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T11:40:48.003499Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chanceryhq/chancery.svg",
  "full_name": "chanceryhq/chancery",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v2.4.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.