Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-27 16:48 UTC

cliwant / mcp-sam-gov

Keyless-first MCP server — 150 tools for US federal + state/local (SLED) government contracting, spending, regulation & partner vetting. SAM.gov, USAspending, Grants.gov, OFAC, FDIC, EPA, CourtListener + 45 more. No API key. Honesty-hardened.

JavaScript · TypeScriptMIT★ 4 Sterne⑂ 1 Forkseit Apr. 2026Auf GitHub ansehen ↗

cliwant/mcp-sam-gov erreicht einen Gesundheitsindex von 58 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (75/100) ab, am schwächsten bei AI Readiness (40/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

58
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

58
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

cliwantOrganisation
3 Follower14 öffentliche Reposseit Jan. 2024

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

75Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
3.5/36Commit-Rhythmus — 5/52 Wochen mit Commits
18/18Commit-Volumen — 273 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year273
human_commit_share1
days_since_last_push0
active_weeks_last_year5

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 10 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 3 Tagen
27/27Release-Rhythmus — ein Release etwa alle 9,6 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count10
latest_release_tagv1.12.0
releases_from_tagsnein
days_since_latest_release3
mean_days_between_releases9,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

47Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
7.7/60Stars — 4 Stars
0/25Forks — 1 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks1
stars4
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templatenein
Wie die Bewertung erfolgt
45.2/80Downloads pro Monat — 2.461 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packages@cliwant/mcp-sam-gov
dependents
ecosystemsnpm
total_downloads
monthly_downloads2.461
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

54Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
38/38.3PR-Annahme — 267/269 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs267
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs2
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
4.3/25Reichweite des Inhabers — 3 Follower von cliwant
13.6/25Kontohistorie — 14 öffentliche Repos, Kontoalter ca. 2 Jahre
Verwendete Eingangsdaten
followers3
owner_typeOrganization
is_verified
owner_logincliwant
public_repos14
account_age_days917

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 3 Tagen
20/20Versionshistorie — 15 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packages@cliwant/mcp-sam-gov
ecosystemsnpm
any_deprecatednein
min_days_since_publish3

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

62Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 5 Workflow(s)
0/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsnein
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

90Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://cliwant.github.io/mcp-sam-gov/
10/10Repository-Beschreibung
10/10Topics — 20 Topics
0/10Wiki
Verwendete Eingangsdaten
topicsai-agents, anthropic, claude, federal-government, govcon, government-contracting, govtech, keyless, llm-tools, mcp, mcp-server, model-context-protocol, open-data, procurement, public-data, rfp, sam-gov, sled, typescript, usaspending
has_wikinein
homepagehttps://cliwant.github.io/mcp-sam-gov/
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

50Mittel · 16 % des Gesamtindex

Sicherheitslage

41Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — keine Daten
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
2.2/7.5Vulnerabilities — 7 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4,1
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
13.2/25Indirekte Abhängigkeiten ohne bekannte Advisories — 1 betroffen: @hono/node-server 1.19.15 (moderate 5.9)
40/40Keine offenen Advisories — kein Advisory ist länger als 90 Tage öffentlich
Verwendete Eingangsdaten
sourceosv
advisories1
affected_packages1
assessed_packages96
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:@cliwant/mcp-sam-gov@1.12.0 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 96 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

40Gefährdet · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 100 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
0/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
10/10Belegte Agentenpraxis — 70 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
2/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
Verwendete Eingangsdaten
has_nixnein
has_testsnein
lockfilespackage-lock.json
has_dockerfilenein
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configstsconfig.json
agent_commit_share0,7
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
27/45Typprüfbarer Code — JavaScript mit Typprüfungs-Konfiguration (tsconfig.json)
50.4/55Handhabbare Dateigrößen — 7/84 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageJavaScript
largest_source_bytes1.963.423
source_files_sampled84
oversized_source_files7
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
20/20MCP-Server
0/40Lauffähige Beispiele
Verwendete Eingangsdaten
example_dirs
has_mcp_signalja
api_schema_files

Eckdaten

4GitHub-Sterne
1Mitwirkende
273Commits, letzte 12 Monate
0Tage seit letztem Push
10Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 4.1 / 10
4.1Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-27 16:47 UTC

10Binary-Artifactsno binaries found in the repo
k. A.Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
3Vulnerabilities7 existing vulnerabilities detected
Direkte Abhängigkeiten 3
RegistryPaketVersionsvorgabeManifest
npm@modelcontextprotocol/sdk^1.20.0package.json
npmunpdf^1.6.2package.json
npmzod^3.24.0package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 1

Die Installation von npm:@cliwant/mcp-sam-gov@1.12.0 zieht 96 Pakete nach sich, direkt und transitiv: 1 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
@hono/node-server1.19.15indirektmittel12.0.5

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "anthropic",
        "claude",
        "federal-government",
        "govcon",
        "government-contracting",
        "govtech",
        "keyless",
        "llm-tools",
        "mcp",
        "mcp-server",
        "model-context-protocol",
        "open-data",
        "procurement",
        "public-data",
        "rfp",
        "sam-gov",
        "sled",
        "typescript",
        "usaspending"
      ],
      "is_fork": false,
      "size_kb": 9693,
      "has_wiki": false,
      "homepage": "https://cliwant.github.io/mcp-sam-gov/",
      "languages": {
        "JavaScript": 2599454,
        "TypeScript": 1969711
      },
      "pushed_at": "2026-07-27T07:25:48Z",
      "created_at": "2026-04-29T04:20:55Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T08:50:50Z",
      "description": "Keyless-first MCP server — 150 tools for US federal + state/local (SLED) government contracting, spending, regulation & partner vetting. SAM.gov, USAspending, Grants.gov, OFAC, FDIC, EPA, CourtListener + 45 more. No API key. Honesty-hardened.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "cliwant",
      "company": null,
      "location": "Korea, South",
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/157332145?v=4",
      "created_at": "2024-01-22T01:52:30Z",
      "is_verified": null,
      "public_repos": 14,
      "account_age_days": 917
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-07-24T06:45:01Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2026-07-20T04:21:04Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2026-07-19T16:09:07Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-07-19T04:00:24Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-07-19T01:53:54Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-07-18T14:27:49Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-07-18T14:18:43Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-04-29T07:41:18Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-04-29T06:27:29Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-04-29T06:18:56Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "b27682fa1d133f8ca8a820c60af808dde1ac5492",
          "body": "… LAST dark state (presence -> 100%) (#269)\n\nCOVERAGE-LEDGER: SD was the final dark state. SD runs Socrata's Open Expenditures\nproduct; its public dashboard fronts a KEYLESS app-proxy at\nsouthdakota.spending.socrata.com/api/checkbook_data.json (row-level vendor\npayments). The underlying SODA dataset\n[…]\nerified anonymous: count 740980, org filter 109887, sort desc, deep-offset\ntail 0-rows-real-count, bogus filter honest-0.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(open-checkbook): open_checkbook_search — close South Dakota, the…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-24T08:49:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a067c940c41671663c96d4eabe5c1e8f0a6c1aa7",
          "body": "…eau Guest CSV) (#268)\n\nCOVERAGE-LEDGER v0.2 flagged MT as a dark state. MT's ArcGIS has no procurement,\nits Socrata portal is decommissioned, and its 989k-row Checkbook is a Tableau\ndashboard-container (empty CSV export). The one keyless gov-con source: the DOA\n'Contracts Awarded' WORKSHEET, export\n[…]\nCSV primitive — the allowlist grows as more US-gov Tableau\nviews are live-verified (additional localities being scouted).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(tableau): tableau_view_csv tool — close Montana dark state (Tabl…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-24T08:16:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "abddb8861a1cda3daebc583ae52ff301c04c3621",
          "body": "…ward layers (#267)\n\nCOVERAGE-LEDGER v0.1 flagged ND as one of 3 dark states (zero keyless SLED\ncoverage). ND's authoritative statewide checkbook (omb.nd.gov) and procurement\n(ndbuys.nd.gov, Ivalua) are keyless-UNREACHABLE (the 165.234.x state network\nrefuses external connections, verified from two \n[…]\n rails found for the other 2 dark states (MT=Tableau\nGuest CSV, SD=Socrata Open Expenditures) will land in follow-up PRs.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): close North Dakota dark state — +4 NDDOT flex-funding a…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-24T07:49:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c1f3cce48654d554403ccf1f920afb56ec5146c",
          "body": "…ixes) + MCP tool annotations (#266)\n\nSecond large adversarial-dogfooding honesty pass across five sub-agent batches:\n16 confirmed defects fixed under the SDLC (live-reproduced → non-vacuous fault →\nCI 6-gate → snapshot MATCH), dominated by pagination honesty (silent dup/skip\nwalks, off-by-one dupli\n[…]\nt unchanged\n(version is not captured in the tools/list snapshot).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: v1.12.0 — adversarial-dogfood honesty hardening wave 2 (16 f…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-24T06:44:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7f2c84e8c7f4a4463b518773484fc7e832e5b491",
          "body": "…was request-size, counted stubbed invalid ids) (#265)\n\n`bls_timeseries` set `totalAvailable = resolved.length` — the number of series\nREQUESTED. A batch-of-series request has no upstream \"total matching series\"\ncount, and BLS STUBS a nonexistent/typo'd raw seriesId as an empty series\n(obsCount 0 + \n[…]\nool description or\ninput-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bls): timeseries totalAvailable null for a batch-series request (…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T08:54:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "190161a048793a0511ce9828e5b36a5737c46f89",
          "body": "…ll 3 modules) (#264)\n\nopenFDA's `skip`/`limit` pagination hid two P1 lies, both in idioms shared by\nopenfda.ts (enforcement), openfda-device.ts (510k clearances), and\nopenfda-drugsfda.ts (drug approvals).\n\n1) OVER-SKIP 404 fabricates totalAvailable:0. openFDA returns an IDENTICAL\n   HTTP 404 NOT_FO\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(openfda): over-skip total honesty + skip-ceiling poison cursor (a…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T08:39:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6d2a5351c9129f557909de9be762309e62337a23",
          "body": "…nse-in-depth livelock (#263)\n\nAll 7 FDIC BankFind tools computed `hasMore = offset + returned < totalAvailable`\nwith no `returned > 0` guard. `limit` is Zod-clamped to ≥1 for MCP callers, so\nthis is not reachable through the server today — but a DIRECT handler call\n(Zod-bypassing) with limit:0 (or \n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(fdic): guard pagination against an empty page (returned>0) — defe…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T08:25:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "659f2c1dd6c640bff2adad41a1c699208870936a",
          "body": "…#262)\n\nAdds Google's google9e6b58e2e01d8960.html verification file to the Pages root\n(served at https://cliwant.github.io/mcp-sam-gov/google9e6b58e2e01d8960.html)\nso the site can be claimed in Google Search Console via the HTML-file method.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(docs): add Google Search Console HTML-file verification token (…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T08:16:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5f0f76bc8e7106c0387d55090b331cd3689f1326",
          "body": "Adds the google-site-verification meta tag to the GitHub Pages landing page\nso the site can be claimed in Google Search Console (URL-prefix property,\nHTML-tag method) and its sitemap submitted for faster indexing.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(docs): add Google Search Console verification meta tag (#261)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T08:12:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "48b6e8608174e4d448a07470a20f37e0f7c70a05",
          "body": "…t silently dup/skip (P5) (#260)\n\n`nsf_search_awards` presents textbook offset pagination (nextOffset/hasMore) plus\nan exact totalAvailable, implying a caller can walk nextOffset to enumerate the\nresult set. It cannot: NSF's award API has no stable server-side sort/tiebreaker,\nso its result order is\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(nsf): disclose the unstable upstream order so offset-walking can'…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T08:07:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "99cc20e6ee3237c6b655d7be618eea243e007b52",
          "body": "…inuation omits totalCount) (#259)\n\n`clinicaltrials_search_studies` advertises opaque-cursor pagination — page 1\nreturns hasMore:true, a real nextCursor, and a note instructing the caller to\npass it back as `pageToken`. Doing exactly that THREW schema_drift: the module\nALWAYS sends countTotal=true a\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clinicaltrials): stop crashing cursor pagination on page 2+ (cont…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T08:01:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "abdaa48437d74532371014ff582489e3dfcbf5dc",
          "body": "… > pageable rows livelock) (#258)\n\nOpenFEMA's `metadata.count` can EXCEED the rows it will actually serve via\n$skip/$top — the ~822k-row public_assistance set stops serving rows well before\nits count. `shapeResponse` computed `hasMore = offset + returned < totalAvailable`\nwith no `returned > 0` gua\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(fema): terminate pagination on an empty tail page (metadata.count…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T07:55:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b95dd659f8de670e8a2f45738a80a77a1ed3feff",
          "body": "…en as unfiltered) (#257)\n\n`grants_search` ALWAYS sends `oppStatuses` to grants.gov — defaulting to\n`forecasted|posted` when the caller omits it — but only recorded the filter in\n`filtersApplied` when the caller SUPPLIED it. So a defaulted call applied a\nserver-side status filter (excluding CLOSED a\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(grants): disclose the default oppStatuses filter (undercount hidd…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T07:49:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6aea5b865890000152ec21268ea08b903fe48f86",
          "body": "… retryable outage (P2) (#256)\n\nA curated seed slug whose Bonfire portal has moved returns an HTTP 3xx\n(live-observed 307 on sanantonio / kingcounty / rutgers). `getBonfireRss`\nfetched via the default retry path, so the `redirect:\"error\"` TypeError was\nrouted through fetchWithRetry's generic network\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bonfire): classify a drifted-slug redirect as schema_drift, not a…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T07:42:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fc5ecc499ae0c474d94a4fd5b2a460ddb1f94c2f",
          "body": "…icies (#255)\n\nThe MCPB desktop-extension manifest was stale (v0.7.0, '52 tools', no\nprivacy_policies). Updated for the Anthropic Connectors Directory submission:\nversion 1.11.0, 150-tool description, refreshed long_description (SLED +\nvetting + honesty), author email, homepage → the Pages site, key\n[…]\nr starts from production-only\ndeps and lists 150 annotated tools.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(mcpb): refresh manifest.json to v1.11.0/150 tools + privacy_pol…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T07:28:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "779a459ed9a5a3c4f4d2c1792b005007829d6fa8",
          "body": "…y tool (#254)\n\nThe Anthropic Connectors Directory requires every tool to advertise a `title`\nplus the applicable `readOnlyHint`/`destructiveHint`; the server previously\nemitted none. Every tool here is strictly READ-ONLY (queries public data; none\nmutate upstream state) and OPEN-WORLD (calls extern\n[…]\nields a non-empty title (a blank title is a Directory rejection).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(server): add MCP tool annotations (title + readOnlyHint) to ever…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T07:12:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "54c14e07735844aae00e072d39729a16e53ea304",
          "body": "- docs/: a self-contained, SEO-optimized landing + quickstart page for\n  GitHub Pages (served from /docs). Full meta (title, description, canonical,\n  Open Graph, Twitter card), JSON-LD SoftwareApplication + FAQPage structured\n  data, sitemap.xml, robots.txt, and .nojekyll (raw static HTML, no build\n[…]\nivacy Policy\" section (Directory requirement) linking PRIVACY.md.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add GitHub Pages landing/guide site (SEO) + privacy policy (#253)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T06:58:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b2a0d032bf547f98907f8a891d450548fae12327",
          "body": "… validation limit) (#252)\n\nThe MCP Registry enforces description length ≤ 100; the initial refresh was\n116 chars and 422'd at publish. Trimmed to 93 chars (still conveys 150 tools /\nfederal + SLED / contracting-spending-regulation). GitHub OIDC auth succeeded;\nthis was the only validation error.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(registry): trim server.json description to ≤100 chars (registry…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T06:51:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1edda3b018faa396d59faa1f9185f36d3ab24d7f",
          "body": "…-publish workflow (#251)\n\nThe official MCP Registry listing was badly stale — server.json advertised\nv0.7.0 / \"52 tools\" (the live registry entry was older still, v0.3.0 / \"36\ntools\") while the package is v1.11.0 with 150 tools. That under-sells the\nserver ~4x and contradicts its own honesty positi\n[…]\nwith\n  every future release (the tag pins server.json's version).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(registry): refresh server.json to v1.11.0/150 tools + OIDC auto…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T06:48:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c6382d197fc0fa58d3966bda886120980268be2",
          "body": "…ip empty page (P1) (#250)\n\n`nppes_lookup_provider` search-mode set `totalAvailable = skip + returned`\nunconditionally. NPPES exposes no grand total, so that is correct only when\nthe page held rows: a partial/last page is the EXACT total, a full page is a\nlower bound (flagged `totalIsLowerBound`). B\n[…]\nool description or input-schema change\n(registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(nppes): stop reporting the skip offset as the total on an over-sk…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T06:38:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa9b742311310bd0faf61f8221fefff490117d59",
          "body": "…sent award amount (P3) (#249)\n\n`searchRecompetes` (usas_search_expiring_contracts) emitted\n`amount: row[\"Award Amount\"] ?? 0`, collapsing an ABSENT award amount to a\nfabricated $0 — indistinguishable from a genuine $0 award. This is the lone\nP3 (null-never-0) divergence in the module: every sibling\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(usaspending): recompete amount null-never-0 — emit null for an ab…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T06:16:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b1bef95dd27049850dd6a282dade2adca8dfcd79",
          "body": "…en scan truncates (livelock) (#248)\n\n`usas_search_expiring_contracts` (searchRecompetes) scans spending_by_award\nEnd-Date DESC up to `scanBudgetPages`, then serves a client-side page over\nthe in-window rows it collected. When the scan budget was exhausted\n(`scanTruncated`), the tool forced `hasMore\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(usaspending): stop recompete cursor advancing into empty pages wh…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T06:08:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b3b66de56ff410c61471d4d26b433ffd5734c93b",
          "body": "…cate + tail drop) (#247)\n\nOpenGov Procurement's POST /project/list `page` parameter is 1-BASED: a\n`page=0` request CLAMPS to page 1. The tool computed a 0-based page\n(`Math.floor(offset/limit)`), so the first two offsets (0 and `limit`)\nBOTH resolved to page 1 — the tool re-served page 1 as the \"ne\n[…]\nool description or input-schema change (registry snapshot MATCH).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(opengov): send 1-based page to /project/list (was 0-based → dupli…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T06:04:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ba95fa5ed5e7d99b65651a8be0bcbe29e309eab7",
          "body": "…> 2023) (#246)\n\nFound by adversarial dogfooding (v1.12.0 backlog, census-economic.ts:97).\nDEFAULT_YEAR was hard-coded \"2022\" and commented \"the latest confirmed CBP\nvintage,\" but 2023 CBP is published (live-verified 2026-07-20:\napi.census.gov/data/2023/cbp/variables.json -> 200; /data/2024 -> 404).\n[…]\nated (census_business_patterns\ndescription only). 3400/3400 pass.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(census): default CBP year to the latest published vintage (2022 -…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T05:35:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a94b911bcffca39069837e1b68435f411a0d186d",
          "body": "…ows (#245)\n\nFound by adversarial dogfooding (v1.12.0 backlog). ckan_discover_datasets set\ntotalAvailable = result.count (the DATASET match count) but returned =\nresults.length (per-RESOURCE rows, flat-mapped). buildMeta then derived truncated\nfrom returned < totalAvailable -- comparing resource-row\n[…]\nnt turns them RED. 3399/3399 pass; tools-list snapshot unchanged.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ckan): drive discover truncation off datasets, not per-resource r…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T05:24:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c8bcf0621d5f7ae468aea4c0226bb900d8303b7",
          "body": "…ty-changing (#244)\n\nFound by adversarial dogfooding (v1.12.0 backlog). AGGREGATE_SELECT_RE only\nmatched count/sum/avg/min/max + group by, so `$select=distinct state`,\n`count_distinct(...)`, median/stddev/percentile, etc. slipped through: the\ncount(*) companion ran and set totalAvailable to the raw \n[…]\nex turns them\nRED. 3397/3397 pass; tools-list snapshot unchanged.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(socrata): treat DISTINCT / any function-call $select as cardinali…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T05:14:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "20806ed767df525e882ec1293aceb4f342ec4984",
          "body": "…ma-drift guard) (#243)\n\n* fix(gsa-csv): assert the CSV column-header contract before indexing (schema-drift guard)\n\nFound by adversarial dogfooding (v1.12.0 backlog). The GSA Contract-Opportunities\nbulk CSV is parsed by fixed positional column indices (COL), but the 47-column\nheader was discarded w\n[…]\nkeum <134980891+seungdo-keum@users.noreply.github.com>\n\n---------\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gsa-csv): assert CSV column-header contract before indexing (sche…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T05:03:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3931030538a1cce43839c28863bb1f75d307c95b",
          "body": "… Socrata sweep (#242)\n\nBumps version 1.10.0 -> 1.11.0 (package.json + SERVER_VERSION) and cuts the\nCHANGELOG [1.11.0] section. This release is the adversarial-dogfooding honesty\npass: 14 fixes across lda / gao / nhtsa / gsa-perdiem / nist / cbp / grants /\nexclusions / ofac / ZodEffects / sam-offset\n[…]\n0). Fault assertions\n3247 -> 3393; tools-list snapshot unchanged.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: v1.11.0 — adversarial-dogfood honesty hardening (14 fixes) +…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T04:20:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e89473d291e052772b8acf6b15194475ad5202c1",
          "body": "…drop passenger claim (#241)\n\nThree low-severity honesty gaps found by adversarial dogfooding.\n\nD1: border/portName are applied CLIENT-SIDE over the full fetched port set, but\nthe response never said so (inconsistent with QCEW in the same repo, which\ndiscloses its client-side windowing). A note now \n[…]\nnerated (cbp_border_wait_times description only). 3393/3393 pass.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cbp-border): disclose client-side filtering, gate empty filters, …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T03:31:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f04825bba5cbd3ffa56dbd12cbacdeba5ef9c8b4",
          "body": "…thdrawn controls (#240)\n\nFound by adversarial dogfooding, live-verified 2026-07-20 against the OSCAL catalog.\n\nMED-1 (P5 freshness): the tool served control text off the mutable\noscal-content `main` branch but disclosed only \"Rev 5\", never the point\nrelease. The catalog metadata carries version \"5.\n[…]\nnapshot regenerated (nist tool\ndescription only). 3391/3391 pass.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(nist-controls): disclose OSCAL version/last-modified + surface wi…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T03:18:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1dc1caed55d552b5b3ac18dc4a8e58a05b4b613",
          "body": "…rozen 2025 (#239)\n\nFound by adversarial dogfooding. DEFAULT_PERDIEM_YEAR was hard-coded \"2025\"\n(commented \"the current confirmed vintage\"), but today is inside FY2026 (began\nOct 1 2025) — a no-year lookup silently served the EXPIRED prior FY's\nreimbursement ceilings. For any city whose ceiling chan\n[…]\nregenerated (gsa_perdiem_rates description only). 3387/3387 pass.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gsa-perdiem): default to the current federal fiscal year, not a f…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T03:04:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c2bbeb57dfedd5ea706e4f8fc3e17e3ff20f6fa5",
          "body": "…(#238)\n\nFound by adversarial dogfooding, live-verified 2026-07-20.\n\nNHTSA returns HTTP 400 (NOT 200) with body {Count/count:0,\nMessage:\"Results returned successfully\", results:[]} for a VALID\nmake/model/year that simply has ZERO recalls/complaints (e.g. Tesla Model 3\n2015). The module routed every \n[…]\nson throws\non the 400 => RED. 3385/3385 pass; snapshot unchanged.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(nhtsa): return honest empty for NHTSA's HTTP-400-for-empty idiom …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T02:51:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0177dd9c00154d0c59b38ac2509b3408cd2b6dd5",
          "body": "…clusions (#237)\n\nTwo honesty gaps found by adversarial dogfooding of the GAO bid-protest feed.\n\nD1 (P2/P4): the RSS path parsed whatever getText returned with no shape check.\nGAO's edge is Cloudflare/WAF — a challenge or maintenance interstitial returns\n200 HTML, and parseFeed's <item> regex yields\n[…]\nr fix turns them RED. No tool-schema change (snapshot\nunchanged).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gao): guard non-RSS 200 bodies + disclose undetermined-outcome ex…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T02:22:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "07fe391425c21ae50472679931f42890ca5dddb5",
          "body": "…#236)\n\nThe keyless LDA /filings/ endpoint has no server-side government-entity\nfilter — the API silently ignores `government_entity` (live-verified:\nadding it does not narrow `count`; entities are nested per lobbying\nactivity, not a top-level filter). The tool sent it anyway and pushed\n\"agency\" to \n[…]\nistry\nsnapshot regenerated (lda_search_filings description only).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(lda): stop reporting the unsupported `agency` filter as applied (…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-20T02:10:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "20017b384c8bd62acbc4940fd0d641ef816b8905",
          "body": "…(#235)\n\nContinuation of the completeness pass. The npm description still said '144 tools'\nand listed only federal sources; refreshed to 150 tools + SLED sources (OpenGov/\nBonfire/ArcGIS/Socrata) + discovery keywords (sled/state-local/procurement/opengov/\nbonfire/arcgis/socrata/bid-opportunities). T\n[…]\nsh-safe (verified the embedded commit hash was untouched).\n\nDocs/metadata-only -- no runtime/fault/snapshot change (150).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs(meta): refresh package.json + ja/ko READMEs to 150 tools + SLED …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T21:12:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "858af1cf3fa52ae421c6b13f550c7efd54da2edc",
          "body": "The public README still advertised '144 tools across 48 sources' in 6 places and\ndid not mention the SLED bid campaign at all. Refreshed every count to the actual\n150/52 (keyless-first: 48 of 52 need no key); added a State/local procurement bids\n(SLED) capability-table row + a dedicated tool-catalog\n[…]\nck tokens are schema_drift/upstream_unavailable/\nrate_limited error kinds). Docs-only — no runtime/fault/snapshot change.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs(readme): refresh to 150 tools/52 sources + SLED bid campaign (#234)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T20:56:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b8aec0035fd7ef7d04f6552261678fbd7318a62",
          "body": "…(dogfood) (#233)\n\nAdversarial dogfooding of the regulatory/grants cluster found grants_search's\nagency/CFDA note describes the WRONG behavior: it claims Grants.gov 'silently\nignores an unknown code / returns the UNFILTERED set / if too broad, verify.'\nLive-verified the opposite — the filter IS appl\n[…]\nBP/FRED key-throws) clusters came back CLEAN under\nadversarial dogfooding — this stale note was the only actionable item.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(grants): correct stale/back-to-front agency-CFDA disclosure note …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T19:41:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f8b70386054798a21ebe9ef51ca8cadbef625bb",
          "body": "…th (dogfood) (#232)\n\nTwo safe-direction findings from the core-tool adversarial dogfood:\n\nF2 sam_check_exclusions._meta.totalAvailable was the raw free-text hit count\n(page.totalElements — every record sharing a WORD with the query), not the\nname-gated match count. A firm with 0 real matches read a\n[…]\n +\nsubstantial->strong). Fault 3375 -> 3379; no tool/schema change (150; snapshot\nunchanged). Clears the dogfood BACKLOG.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(vetting): sam_check_exclusions totalAvailable + ofac match-streng…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T19:07:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a08dd333918d08e7b85c859d61d15a2c0c1f5e78",
          "body": "…hed a bare {type:string} (#231)\n\nAdversarial dogfooding surfaced a shipped machine-interface defect: the internal\nzodToJsonSchema serializer (used by tools/list) had no ZodEffects branch, so every\ninput schema wrapped in .refine() (cross-field rules like 'npi OR state required')\nfell through to the\n[…]\nt with properties (structural regression guard)\n+ a refine()-wrapped spot-check. Fault 3373 -> 3375; 150 tools unchanged.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(schema): serialize ZodEffects (.refine()) inputs — 7 tools publis…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T18:46:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3045e965dc5d21070605a91da18391a13b07cb4d",
          "body": "Adversarial dogfooding surfaced a silent-wrong-answer: sam_search_opportunities'\nkeyless HAL path hardcoded page=0 and ignored the caller's row offset, yet echoed\nthe requested offset back as if honored -> paging (offset 0/5/10...) returned the\nSAME first page every time, with _meta.filtersDropped:[\n[…]\nsnap+disclosure).\nFault 3369 -> 3373; no tool/schema change (150); live-verified offset 0/5/10 now\nreturn distinct pages.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(sam): keyless offset now actually pages (was a silent no-op) (#230)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T18:37:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a4f2e0dec873e4d1c19bc713604556d335be7b48",
          "body": "…ning) (#229)\n\nAdversarial dogfooding surfaced a latent P1 undercount risk: the RSS item\nextractor matched only a bare '<item>' opening tag, while the <channel[\\s>]\ndrift guard and the inner tag() matcher both tolerate attributes. A namespaced/\nextended Bonfire feed emitting '<item ...attrs>' would \n[…]\nlable:1, not 0). Fault 3368 -> 3369; no tool/schema change (150);\nlive regression clean (harriscountytx total unchanged).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(bonfire): tolerate attributes on the <item> tag (dogfood P1 harde…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T18:06:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "353af56de4b4cad45b09599774b6ff047dbfaa1b",
          "body": "…forms (#228)\n\nWas stale at 144/48. Refreshed to the actual 150/52; added a dedicated\n'SLED bid platforms' section for the 6 new tools (opengov_list_governments,\nopengov_search_solicitations, bonfire_list_organizations,\nbonfire_search_opportunities, arcgis_hub_discover_datasets, arcgis_feature_query\n[…]\nnds / feedback\ncategories / an integrityFlag field value, not tool claims). Docs-only —\nno runtime/fault/snapshot change.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs(skill): refresh SKILL.md to 150 tools/52 sources + SLED bid plat…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T17:38:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e9bfe3c5da5fce7c82f37a931ec820f0fed1f1f6",
          "body": "… (51 -> 53 domains) (#227)\n\nThe clean wins from the diminishing tail of the sweep:\n  - citydata.mesaaz.gov  Mesa AZ (2nd hub, attr 'Office of Management and Budget'): City Expenditures ~15.4M\n  - data.weho.org        City of West Hollywood CA (.org official): Active Contracts (contractor_name/statu\n[…]\nod: mesa 15,401,441\n/ weho 1,030 honest totals; SSRF lookalike rejected. No tool count change (150);\nenum +2. Fault 3368.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(socrata): county/city procurement sweep wave 4 (tail) — +2 hosts…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T17:05:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "395f7ee2c4cd0fb2ff93a04c85a3a0e4c9ca07df",
          "body": "…hosts (42 -> 51 domains) (#226)\n\nExpanded federated-catalog queries (rfp/rfq/disbursement/expenditure/commodity)\n+ offset paging; each provenance-confirmed (api/views attribution or gov domain)\nand count(*)-verified:\n  - datahub.usac.org                   USAC E-Rate open competitive bidding (Form \n[…]\nville 1,006,097 / austin 318,022 honest\ntotals; SSRF lookalike rejected. No tool count change (150); enum +9. Fault 3368.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(socrata): county/city procurement sweep wave 3 — +9 local/state …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T16:47:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7856e08df57e3344bf0430c5ba932fb1cb798483",
          "body": "…sts (34 -> 42 domains) (#225)\n\nSame federated-catalog mining + host-scoped count(*) + /resource 200 bare-array\nverification. Large real checkbook/PO/vendor-payment datasets:\n  - fiscalfocus.pittsburghpa.gov   Pittsburgh PA        (Checkbook ~1.01M)\n  - atlanta.data.socrata.com       City of Atlanta\n[…]\nidence 228,489 honest totals; SSRF lookalike rejected.\nNo tool count change (150); snapshot = domain enum +8. Fault 3368.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(socrata): county/city procurement sweep wave 2 — +8 local-gov ho…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T16:27:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6bce91b641ff141c36908817e3bf72876943ade4",
          "body": "…Socrata/ArcGIS/OpenGov/Bonfire SLED expansion) (#224)\n\nVersion bump 1.9.0 -> 1.10.0 (minor). Batch of 16 unreleased merges since\nv1.9.0, all live-verified before shipping:\n  - 6 new tools (144->150): arcgis_hub_discover_datasets, opengov_list_governments,\n    opengov_search_solicitations, bonfire_l\n[…]\niants (P1/P2/P3/P4/P5 + curated-allowlist SSRF) hold across every\nnew surface. Fault 3368, snapshot 150, CI 6-gate green.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "release: v1.10.0 — SLED bid campaign (6 new keyless tools 144->150 + …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T16:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f69fc072979c7206b93edab4a0a88da645cc2381",
          "body": "… -> 34 domains) (#223)\n\nMined the Socrata federated catalog (api.us.socrata.com) for procurement/bid/\ncontract datasets, then live-verified each new host ($select=count(*) +\n/resource/<4x4>.json 200 bare-array). US local govs only:\n  - data.kcmo.org           Kansas City MO      (Vendor Payments ~1\n[…]\nrichmond 1,387 honest totals; SSRF lookalike\nrejected. No tool count change (150); snapshot = domain enum +6. Fault 3368.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(socrata): county/city procurement sweep — +6 local-gov hosts (28…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T15:44:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccbc33e8f161dfd45b6628a8984bfcd130bd6b5c",
          "body": "… (#222)\n\nHub v3 API axis (arc-scout8.mjs, different index than AGOL content search)\nsurfaced the City of Topeka's aggregate open checkbook (the per-year layers\nseen earlier were ~184 rows each; the aggregate is the real dataset).\n  - topeka_checkbook_aggregate (City of Topeka KS, FY2015-2023; fisca\n[…]\nrs>0 -> 23,658 < full 323,620). No tool count change (150); snapshot =\nservice enum +1. Fault 3368 (45AR assertion >=22).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): add City of Topeka KS checkbook aggregate (23 services)…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T15:22:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1458977778573824114a35cea4b7a3399745c3b",
          "body": "…owa/Oklahoma DOT + Alaska AASHTOWARE) (#221)\n\nContinued Hub-discovery pattern (arc-scout5/6.mjs, state-DOT bid focus).\n+3 verified reachable Esri-hosted state DOT bid/award registers (19 -> 22):\n  - akdot_aashtoware_proposals (Alaska DOT&PF AASHTOWARE proposals/lettings; RefVendor_LongName/AwardedA\n[…]\n a platform, not a named government body. No tool\ncount change (150); snapshot = service enum +3. Fault 3368 (45AR >=20).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): expand arcgis_feature_query allowlist to 22 services (I…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T14:47:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "744c9cfc998a74797d8f21e324a3ccc4d2509793",
          "body": "…as Vegas contracts, Texas DOT, Alaska DOT&PF awards) (#220)\n\nContinued Hub-discovery pattern (arc-scout4.mjs, broader terms). +3 verified\nreachable Esri-hosted US gov procurement/award layers (16 -> 19):\n  - lasvegas_purchasing_contracts (City of Las Vegas NV contract register, ~3,417 all with a su\n[…]\n NULL -> 14,110 < full 85,397). No tool count\nchange (150); snapshot = service enum +3. Fault 3368 (45AR assertion >=17).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): expand arcgis_feature_query allowlist to 19 services (L…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T14:24:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c58297819cbdd8a0dc723880147905948e6c33ff",
          "body": "…as Vegas, Baltimore, Naperville, Worcester checkbooks) (#219)\n\nContinued Hub-discovery pattern (arc-scout3.mjs). +4 verified reachable\nEsri-hosted US municipal spending/checkbook layers (12 -> 16):\n  - lasvegas_checkbook (City of Las Vegas NV, ~373,093)\n  - baltimore_checkbook (Baltimore City MD FY\n[…]\nnge (150); snapshot = service enum +4. Fault\n3368 (45AR allowlist assertion bumped to >=14, host regex covers services1).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): expand arcgis_feature_query allowlist to 16 services (L…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T14:03:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a9b99383d440bdc023f6d7fea6ea307475d0c89",
          "body": "…iami-Dade 2025, Suffolk NY, Mat-Su AK) (#218)\n\nContinued Hub-discovery pattern (arc-scout2.mjs). +3 verified reachable\nEsri-hosted US local-gov procurement layers (9 -> 12):\n  - miamidade_purchase_orders_2025 (Miami-Dade FL INFORMS, CURRENT, ~25,203)\n  - suffolk_county_ny_contracts_2018 (Suffolk Co\n[…]\n\n\nAll live-verified (returnCountOnly + real records). No tool count change (150);\nsnapshot = service enum +3. Fault 3368.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): expand arcgis_feature_query allowlist to 12 services (M…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T13:42:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "accf4cd1e5f4d1ff1d42e107d6a72f883717ecba",
          "body": "…l-gov layers (#217)\n\nFound via arcgis_hub_discover_datasets, each on a reachable Esri-hosted\nservices*.arcgis.com endpoint (NOT WAF-gated) + live-verified returnCountOnly.\narcgis_feature_query grows 4 -> 9 curated services across 4 US govs:\n  - asheville_purchase_orders (Asheville NC, ~62,805)\n  - \n[…]\nded. No tool count change (150);\nsnapshot = service enum +5. Fault 3368 (45AR allowlist assertion updated to\nmulti-host).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): expand arcgis_feature_query allowlist to 5 more US loca…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T13:22:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfe1d2cc4199e29a5eeeceb7d4a40974682bc893",
          "body": "…st (DC PASS) (#216)\n\nThe 150th tool, from the SLED bid campaign. Generic query companion to\narcgis_hub_discover_datasets. First payload: DC OCP PASS procurement layers.\n\n- service = allowlist ENUM (SSRF core): dc_pass_solicitations (live open\n  solicitations ~25k, 46 fields), dc_pass_contracts (~50\n[…]\n: dc_pass_solicitations total=25,104 (returnCountOnly), real DC records.\nFault 3354->3368 (+14, 45AR). Snapshot 149->150.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis): arcgis_feature_query over a curated ArcGIS-REST allowli…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T12:32:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4cb06781f3ab281859f8f36e5a9ce95154494609",
          "body": "…(#215)\n\nThe 148th & 149th tools, from the SLED bid campaign. Thousands of US\nstate/local govs on Bonfire expose a keyless RSS of open opportunities at\n{org}.bonfirehub.com/opportunities/rss.\n\n- bonfire_list_organizations: a curated, live-verified 186-org US seed\n  directory (Bonfire's authoritative\n[…]\nportunities (ref#/name/\ncloseDate/link); solanocounty empty feed honest. Fault 3336->3354 (+18, 45BF).\nSnapshot 147->149.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(bonfire): Bonfire (Euna) per-org open-opportunity RSS (2 tools) …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T11:51:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3225f5034c2f528bb3284899dc6fd954603545d8",
          "body": "…s) (#214)\n\nThe 146th & 147th tools, from the exhaustive US state+local bid-site research.\nOpenGov Procurement hosts 525+ US state/local govs' live open-bid portals.\n\n- opengov_list_governments: whole directory in one keyless GET /api/v1/government\n  (~560 orgs; filter state/query; active non-intern\n[…]\ns; santacruzca 169 public projects (3 open w/ due\ndates + portal links). Fault 3316->3336 (+20, 45OG). Snapshot 145->147.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(opengov): OpenGov Procurement keyless SLED solicitations (2 tool…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T11:19:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "732b81752865a944a213d7f5853596b72659bd58",
          "body": "…/Cincinnati) (#213)\n\nFrom the exhaustive US state+local bid-site research. Three .gov Socrata\nportals with LIVE bid-cycle data (not just award/spend):\n  - datacatalog.cookcountyil.gov (Cook County IL) — Bid Tabulations 32au-zaqn\n    (~5,607) + awards + intent-to-award (17 procurement datasets)\n  - \n[…]\nnt 'Socrata' claim that verification disproved.\n\n+2 fault assertions (42a-sled). Snapshot: +3 domain enum x2 (145 tools).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(socrata): add SLED procurement bid-catalog hosts (Cook County/IL…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T10:43:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82b48a3dc8416316ac70eb49636903a43af5b1e3",
          "body": "…overy) (#212)\n\nThe 145th tool. A large fraction of US state/local/regional/tribal (SLED)\nopen data — GIS, infrastructure, permits, zoning, boundaries, procurement —\nis published on ArcGIS Hub (hub.arcgis.com/api/v3/datasets), which Socrata\nand CKAN do not cover. This opens that layer for keyword di\n[…]\ndirect:error, keyless. +23 fault assertions (145 tools).\n\ndrift-audit 13/13 clean; snapshot 144->145 (only the new tool).\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(arcgis-hub): add arcgis_hub_discover_datasets (keyless SLED disc…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T07:29:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9816c3484b458d4a3c08db4e639f979c18f0a29f",
          "body": "…ederated under-index) (#211)\n\nsocrata_discover_datasets with a specific domain now queries that portal's\nOWN catalog (https://{domain}/api/catalog/v1?search_context=…) instead of\nthe federated api.us.socrata.com aggregator, which under-indexes many hosts.\n\nLive impact (in-process, current branch bu\n[…]\nource). No tool/schema\nchange (144 tools; snapshot MATCH). Fault 3287 -> 3291 (+4: 42p routing).\ndrift-audit 13/13 clean.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(socrata): domain-scoped discover uses host's own catalog (fixes f…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T06:41:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88848a1e721bf834db0adb77e92316855acd3889",
          "body": "First federal Socrata hosts in the curated allowlist (prior tiers were\nstate + local only), all .gov:\n  - data.transportation.gov (US DOT) — e.g. az4n-8mr2 Company Census File\n    (~4.47M motor carriers); 1,873 datasets host-scoped\n  - data.cdc.gov (US CDC) — ~1,100 public-health datasets\n  - data.b\n[…]\niscover_datasets under-reports federal datasets (honest upstream\npartial); socrata_query works normally with a known 4x4.\n\nSigned-off-by: seungdo-keum <134980891+seungdo-keum@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(socrata): add federal open-data portal tier (DOT/CDC/BTS) (#210)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T06:04:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f75cd1ef6a0d83f0f69fdb3c8f5ec2ae256e01c",
          "body": "…election) (#209)\n\nLoop cycle 6 (AGENT-USABILITY, META-elevated). The bundled agent skill advertised a\nstale \"120 tools / 37 sources\" and omitted whole capability lanes — agents couldn't\nselect tools they didn't know existed (the agent-eval failure class).\n\n- Counts → 144 / 48 (keyless 44 of 48).\n- \n[…]\n No version bump ([Unreleased]).\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill): refresh SKILL.md to 144 tools / 48 sources (agent tool-s…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T05:22:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1577d856525ac497899240faf3badd9646d53c2c",
          "body": "…SF/LA) (#208)\n\nLoop cycle 5 (TRACK B). The largest municipal procurement markets, live-verified\n(host-scoped catalog + /resource 200 bare-array), keyless:\n  data.cityofnewyork.us (NYC — City Record notices ~1.1M), data.cityofchicago.org\n  (contracts ~186k), data.sfgov.org (supplier contracts ~48k),\n[…]\n No version bump ([Unreleased]).\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(socrata): add the 4 major-city procurement portals (NYC/Chicago/…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T04:54:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4542a5417fc4b32e256c776c7e650b9d5766a33b",
          "body": "…ease 1.9.0 (#207)\n\nNew tool #144 (loop cycle 3, TRACK B / mode-2 bespoke source). The full in-force\ntext of one CFR section via the eCFR versioner/full endpoint, de-XMLed. Fills the\nagent-eval gap (ecfr_search returns only snippets). Defers FAR/DFARS (title 48) to\nthe richer far_clause_lookup; is t\n[…]\n→[1.9.0], README/counts 143→144.\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ecfr): ecfr_get_section — full CFR section text (any title); rel…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T03:59:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e068906f981f0d9cbe46524ccc189cc4770d01b7",
          "body": "…wlist (#206)\n\nExtends SLED coverage from state portals down to the fragmented local tier.\nEach host is host-scoped-catalog + /resource/<4x4>.json 200-bare-array verified,\nall .gov, keyless, carrying B2G procurement/vendor/contract data:\n  data.austintexas.gov (Austin TX — POs ~318k), data.kingcount\n[…]\nleased] per the release policy).\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(socrata): add 5 live-verified SLED city/county hosts to the allo…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T02:55:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "96d19ff1de5fa546d47f5b2472e1a116c1af835c",
          "body": "…ng, eCFR) (#205)\n\nImprovements surfaced by the new agent-level eval. No tool/schema changes (143);\nall _meta / disclosure clarity.\n\n- \"obligations\" disambiguation: usas_list_toptier_agencies (obligatedAmount =\n  ACCOUNT-level total) and usas_get_agency_awards_summary (obligations =\n  AWARD-level on\n[…]\ns (3274 -> 3276). Version 1.8.0.\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: agent-eval-driven disclosure clarity (obligations, agency spendi…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-19T01:53:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7ba9f546ee4723a708483570ee0cec795b5664b",
          "body": "…current) (#204)\n\nTwo \"keep installed users current\" changes; no tool changes (still 143).\n\n- Startup update notice (update-check.ts): one anonymous GET to the public npm\n  registry for our own `latest`, and — only if strictly newer — one stderr line.\n  Reaches already-installed users (npm is pull-b\n[…]\n up to date\"; CHANGELOG [1.7.0].\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: startup update notice + auto GitHub Release on tag (keep users …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-18T14:27:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "db6236d1a7b77dcd5539325d36d19fbd920655d2",
          "body": "… report links) (#203)\n\nAdds a PULL-only feedback loop so the server improves from real usage without\never posting anything itself (no token, no account, no network call):\n\n- `feedback` tool (143rd, keyless): returns a prefilled GitHub new-issue link\n  (kind = bug/feature/wrong_output) for the human\n[…]\nools; CHANGELOG [1.6.0]; v1.6.0.\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: in-product feedback loop → GitHub issues (feedback tool + error…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-18T13:47:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8327ba63ee621a4e1537d609637625c9231c192",
          "body": "Establish the Developer Certificate of Origin (DCO 1.1) as the\ncontribution mechanism (no CLA): add the standard DCO text, a\nself-contained DCO CI check requiring every PR commit to be signed\noff (git commit -s), and CONTRIBUTING guidance.\n\nAlso clarify the LICENSE copyright holder from the placehol\n[…]\ntors retain their own copyright.\n\nSigned-off-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: adopt DCO for contributions; clarify LICENSE copyright (#202)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-18T12:30:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1dfdec93688bfbc6dd8584c58c8f4422a0d7b96",
          "body": "`.tools/` held the `mcp-publisher` release binary (~28 MB: a Windows\n`.exe` plus its tarball) used locally to push `server.json` to the MCP\nregistry. It is not referenced by package.json, any CI workflow, the\nREADME, or the plugin manifest, and is not needed to install or run the\nserver. Untrack it \n[…]\ngnore` (it is freely\nre-downloadable from the modelcontextprotocol/registry releases).\n\nNo source, dist, test, or user-facing behavior changes.\n\nCo-authored-by: seungdo-keum <seungdo.keum@cliwant.com>",
          "is_bot": false,
          "headline": "chore: stop tracking the local MCP-registry publisher binary (#201)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-18T07:44:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f077aeb1fe0c1edde350f6a8363b878c50bf21c7",
          "body": "원격 환경에서 서버에 npm 토큰을 두지 않고 게시할 수 있도록 GitHub Actions 릴리스\n파이프라인 추가. 공개 레포 키-유출 방지 설계:\n- 트리거 = v*.*.* 태그 push 전용(pull_request 없음). 태그는 write 권한자만 push 가능,\n  fork PR엔 시크릿 미노출 → NPM_TOKEN은 메인테이너 태그 push 시에만 사용 가능.\n- 최소권한 contents:read. id-token:write는 npm provenance(빌드 출처 서명 증명)용뿐.\n- 시크릿은 publish 스텝 env로만\n[…]\nlic.\n\n1회 셋업(메인테이너): npmjs Automation 토큰(2FA 우회) 발급 → GitHub Environments\n'npm-publish' 생성(선택 reviewer) → 시크릿 NPM_TOKEN 추가. 이후 릴리스=버전범프+태그 push.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(release): 태그(v*.*.*) push 시 npm 게시 워크플로우 추가(공개-레포 안전 설계) (#200)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-18T07:12:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "67ff529c3340f9293bbc113fcb0fa7fc9bcafc33",
          "body": "…수정 반영) (#199)\n\n미게시로 누적된 세션 작업(1.4.0/134툴 → main 142툴)을 1.5.0으로 문서·버전 정렬:\n- SERVER_VERSION 1.4.0→1.5.0 (MCP 클라이언트 보고 버전), package.json 1.5.0.\n- README(en/ko/ja): 134→142툴, 44→48소스, keyless \"40→44 무키\" 갱신 + 툴 카탈로그에\n  신규 8툴 추가(그룹 카운트 재조정, 합계 142) + package.json description \"52\"→\"142\".\n- CHANGELOG [1.5.\n[…]\nIST OSCAL·get.gov, GitHub 배포=agency first-party) provenance 공개 명시.\n\n순수 문서·버전; 신규/변경 툴 로직 없음. fault 3247/3247 통과, registry-snapshot MATCH(142툴).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release(1.5.0): 142툴/48소스 문서·버전 최신화 (도메인 스윕 신규 8툴 + dogfooding 정직성 10…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-18T06:16:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b7f3a7ec4fae4bf267869e5ca5fc4b60c05166dd",
          "body": "…/기후) (#198)\n\n체계적 도메인 스윕(헬스/과학/환경/기상 스카우트)의 GO. NWS api.weather.gov(keyless, .gov)로\n현재 활성 기상 watch/warning/advisory — event·severity·urgency·area·effective/expires·\ninstruction. FEMA 3툴(declarations→PA→hazard mitigation→LIVE 활성기상)과 페어를 이뤄\ndisaster-response-readiness 레인 완성: 심각기상이 지금 어디서 활성인가(뒤따를 선언/계\n[…]\nty·non-FC schema_drift·503 THROW. 3240→3247. registry-snapshot\n141→142툴 MATCH.\n\n안전: PUBLIC OPEN DATA만(NWS keyless, 공개 경보·PII無). 키/우회 없음. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): nws_active_alerts — NWS 실시간 기상경보(도메인 스윕 Scout A, 재난…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T07:53:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7b1a0cf5b0fbcb0e4e46a5963d936b2414be8d2f",
          "body": "… 화물/물류) (#197)\n\n체계적 도메인 스윕(운송/물류/무역 스카우트)의 GO. CBP Border Wait Times(bwt.cbp.gov,\nkeyless, .gov 호스트)로 US 캐나다·멕시코 국경 전 포트의 실시간 상용차(+승객) 대기시간 —\n포트별 CV standard/FAST 레인 지연(분)·운영상태·개방레인·최대레인. 화물/물류 벤더 실시간\n국경-교차 situational awareness. 신규 화물/물류 도메인.\n\n미통합 확인. 새 파일 src/cbp-border.ts: 고정호스트 getJson(redirect\n[…]\narray schema_drift·503 THROW. 3233→3240. registry-snapshot 140→141툴 MATCH.\n\n안전: PUBLIC OPEN DATA만(CBP keyless, 집계 포트 데이터·PII無). 키/우회 없음. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): cbp_border_wait_times — CBP 국경 대기시간(도메인 스윕 Scout B,…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T07:28:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fea27f8c5e76694954e8a3439e18096a99786555",
          "body": "…(도메인 스윕 Scout D, Tier-3) (#196)\n\n체계적 도메인 스윕(규제/사이버 스카우트)의 GO. NIST SP 800-53 Rev5 보안·프라이버시 컨트롤\n카탈로그(OSCAL, keyless)로 FedRAMP/CMMC/RMF 컴플라이언스 요구사항 조회 — controlId(AC-2)/\nfamily(Access Control)/keyword로 컨트롤의 title·요구 statement·guidance·enhancements 조회.\nNVD CVE+CISA KEV(취약점 측)를 컨트롤/요구사항 측으로 보완. 우리에게 없던\n[…]\n\n(enhancement 포함)·family·FLOOR schema_drift·503 THROW. 3225→3233. registry-snapshot\n139→140툴 MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): nist_800_53_controls — NIST SP 800-53 Rev5 컨트롤 카탈로그…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T07:03:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "94feb0d9f35d5339dc38d448c04fc861fff43c24",
          "body": "…A, Tier-2) (#195)\n\n체계적 도메인 스윕(헬스/과학 스카우트)의 GO. openFDA Drugs@FDA(/drug/drugsfda.json,\napi.fda.gov — api.data.gov 쿼터와 무관)로 FDA 승인 신약 애플리케이션(NDA/ANDA/BLA):\nsponsor·application_number·승인 제품(brand/active-ingredient·dosage·route·marketing\nstatus)·submission/승인 이력. 제약 벤더 제품/승인 인텔.\n\n미통합 확인. 새 파일 src/openf\n[…]\n·404-empty crux·503 THROW.\n3219→3225. registry-snapshot 138→139툴 MATCH.\n\n안전: PUBLIC OPEN DATA만(openFDA keyless, 공개 승인데이터·PII無). 키/우회 없음. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): openfda_drug_approvals — Drugs@FDA 승인(도메인 스윕 Scout …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T06:35:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8c2b0520efe5b1ac609e7d50e2a55f3712fa000",
          "body": "…터셋 추가(도메인 스윕 Scout C) (#194)\n\n체계적 도메인 스윕(금융/경제/노동 스카우트)의 Tier-1 GO. 기존 treasury.ts 레지스트리 패턴에\n2개 Fiscal Data 데이터셋 순수 가산(신규 툴/모듈/키 0 — enum만 확장):\n- interest_expense(/v2/accounting/od/interest_expense): ACTUAL 이자 PAID = 채무-서비스\n  비용(security type별), avg_interest_rates(이율만)와 구분되는 신규 축. 라이브 total 7245.\n-\n[…]\ntry-snapshot 재생성(treasury_query_dataset\nenum 5→7, 툴 수 138 무변경) MATCH.\n\n안전: PUBLIC OPEN DATA만(Treasury Fiscal Data keyless). 키/PII/우회 없음. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): treasury_query_dataset — interest_expense + tror 데이…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T06:06:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "558821f9435eab510f97222b89fe14bc9db03e02",
          "body": "…-3, 스카우트 백로그 완결) (#193)\n\n5차 스카우트 GO-3 착지 = keyless 스카우트 백로그 완결. CISA get.gov 공식 .gov 도메인\n레지스트리로 (1) 어느 조직이 .gov 도메인을 소유하는지 해소 (2) 연방기관 열거 (3) SLED\n엔티티 맵(주/카운티/시/학교구/특별구/부족) — 다른 어떤 툴도 노출 못 하는 권위적 gov-org\n레지스트리 축. 미통합 확인 후 신규 소스파일 src/gov-domains.ts 배선.\n\n★출처: CISA(=.gov 등록기관)가 공식 발행하는 github.com/cis\n[…]\n정호스트·\nprovenance·헤더리네임 schema_drift·503 THROW. 3209→3217. registry-snapshot 137→138툴 MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/우회 없음. 연락처-PII 제외. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): search_gov_domains — CISA get.gov .gov 도메인 레지스트리(GO…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T05:38:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7d7fdf29c69de690163d2ef2bd3e2fdd184c3ede",
          "body": "… DEFC 긴급기금 축(GO-2) (#192)\n\n5차 스카우트 GO-2 착지. USAspending disaster/DEFC 엔드포인트(keyless, 기존 클라이언트\n재사용)로 \"어느 지리가 COVID/IIJA 구제자금을 확보했나\" — 표준 award 검색이 노출 못 하는\n별개 분석 축. 미통합 확인 후 신규 배선.\n\n신규 2툴:\n- usas_list_disaster_codes: GET references/def_codes/ — 52 DEFC 완전목록(discovery),\n  각 code+group('covid_19'|'infr\n[…]\nOW. 3202→3209 assertions. registry-snapshot 재생성 135→137툴 MATCH.\n\n안전: PUBLIC OPEN DATA만(USAspending keyless, 환자/개인 PII 無—집계 지리). 키/우회 없음. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): usas_list_disaster_codes + usas_disaster_spending —…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T04:46:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6143f35c5513334c6d751bcf24e1cdc9d24e5dcf",
          "body": "… §3 계획된 3rd 툴) (#191)\n\n소스 스카우트가 확인한 keyless 확장. fema.ts 코드 주석이 명시적으로 계획해 둔 backlog\n(\"HMA v4는 3rd-tool backlog item, ADR-0016 §3\")를 착지 — 기존 FEMA 플러밍(SSRF 고정호스트\n+핀 레지스트리·$inlinecount 총계정직·OData $filter 화이트리스트·null-never-0) 전부 재사용.\n\n신규 툴 fema_search_hazard_mitigation: HazardMitigationAssistanceProject\n[…]\n02 assertions.\nregistry-snapshot 재생성 134→135툴 MATCH. (README 툴카운트는 publish 시 갱신.)\n\n안전: PUBLIC OPEN DATA만(OpenFEMA keyless). 키/PII/우회 없음. 순수 가산.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(expand): fema_search_hazard_mitigation — HMA 완화 그랜트(ADR-0016…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T04:16:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14a5423af36befcb8a01adf9fbb5ee1f8f41a647",
          "body": "…size→size) 추종 (#190)\n\nautonomous loop 재검증(쿼터 리셋 후)이 확증한 HIGH 드리프트: data.gov v4 Catalog API가\nfree-text 파라미터를 _q→q, _size→size로 rename. 툴이 옛 _q를 보내 query가 조용히 무시됨\n— 모든 쿼리가 동일한 기본 카탈로그 페이지 반환하는데 filtersApplied:[\"query\"]로 적용됐다\n거짓 주장(confidently-wrong-empty 클래스, subaward 필드rename과 동형). 라이브 확증:\nq=wildfir\n[…]\nimit-note(20>3→노트, 3≤20→무). 3191→3193 assertions. registry-snapshot 재생성 MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 파라미터 드리프트 추종+disclosure.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(drift): datagov_search_datasets — v4 API 파라미터 rename(_q→q, _…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-16T00:31:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "991ad2d81bb950a23b6a970672496fbf4aa7342a",
          "body": "…적 $0 오독 방지) (#189)\n\ntargeted 감사가 확증한 HIGH: #187이 숫자-코드만 loud-fail. 그럴듯하지만 non-canonical한\nNAME(약칭 \"Veterans Affairs\"·소문자·오타)은 exact-match 필터를 통과해 조용한 0 반환 —\nfiltersDropped:[]·무-note라 \"VA가 $0\" 권위적 오독. 최악은 usas_spending_over_time:\n오타 agency가 15년 $0 타임라인을 권위있게 반환(\"이 기관은 IT에 한 번도 안 썼다\"로 오독).\nsubaward dr\n[…]\nzero→무) 비공허\nfixture. 3187→3191 assertions. registry-snapshot MATCH(순수 meta 노트, 스키마 무변경).\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 disclosure 강화.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(honesty): usas spending — agency NAME 무매치 empty를 disclose(권위…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T16:44:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d7cbd883c7a80d5a644911aac6344551c88ffa84",
          "body": "…재무제표 오도 방지 (#188)\n\ntargeted 감사가 확증한 HIGH: resolveCik이 exact ticker/CIK 없으면 case-insensitive\ntitle SUBSTRING로 fallback해 ticker-map 첫 매치 반환. edgar_lookup_cik은 이를 공개하지만\n데이터-반환 형제(company_facts/filings/concept)는 무공개 → {cikOrTicker:\"MICRO\"}가 조용히\nMICROSOFT 재무제표를 권위있게 반환(Micron/AMD/Super Micro 의도한 사용자 오도)\n[…]\nstring 노트(VERIFY);\nEXACT \"MSFT\"→노트 없음(fuzzy-only). 3185→3187 assertions. snapshot MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 disclosure 강화.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(honesty): EDGAR 데이터툴이 title-substring 해소를 disclose — 잘못된 회사 …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T16:38:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "77e9e0c00b3eec31ea2edf6a8feccf2bcdfd5b6f",
          "body": "…loud-fail(조용한 false-empty 근절) (#187)\n\ndogfooding(Capture/Compliance 페르소나)이 확증한 MEDIUM: usas_search_subagency_spending/\nfederal_account_spending/cfda_spending 등에 agency로 toptier 코드(\"036\")를 주면 조용히\n빈 결과 → \"VA가 $0 서브에이전시 지출\" 오독(실제 $66.87B). 근본원인: spending_by_category\nagency 필터는 canonical NAME 매치인데, 형제 \n[…]\nrtions. registry-snapshot 재생성(5 category\n툴에 agency describe, tool-count 무변경) MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 입력검증·disclosure 강화.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(honesty): usas spending_by_category — agency에 toptier 코드 주면 …",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T16:20:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7159415b5f6c7c0dd2baa61fcf99a2b7c79c4d0c",
          "body": "…food 오도 방지 (#186)\n\ndogfooding(헬스케어/제품안전 Risk 페르소나)이 확증한 MEDIUM: category 미지정 시 'drug'로\n기본값 → DEVICE 분석가가 조용히 drug 리콜만 받아 ~197× under-count(예: product:\"pacemaker\"\n무-category → drug 리콜 1건(povidone-iodine prep-pad); category:\"device\" → 진짜 197건\nBoston Scientific/Medtronic Class I). 설명엔 disclosed지만 filt\n[…]\ncho, explicit device→no note. 3179→3183\nassertions. registry-snapshot MATCH(설명·스키마 무변경).\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 disclosure 강화.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(honesty): openfda_enforcement 기본 category=drug 가시화 — device/…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T16:01:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "013183411aa9667592b9d632c91666e8b09bbdd1",
          "body": "…도록 보존 (#185)\n\ndogfooding(Market/Compliance 페르소나) LOW: govinfo_list_collections/search_packages가\nDEMO_KEY 429(OVER_RATE_LIMIT)를 \"Request to govinfo timed out\"(upstream_unavailable)로\n오라벨. 근본원인: fetchWithRetry가 attempt1서 429(rate_limited, retryable)를 받고\nRetry-After 대기 중, getJson의 15s AbortSignal이 발화 →\n[…]\n_unavailable(비공허\n하위호환) 픽스처 추가. lastErr-보존 되돌리면 RED. 3177→3179 assertions. snapshot MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 에러-분류 정직성 수정.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(honesty): rate_limited(429)를 후속 abort의 'timed out'으로 마스킹하지 않…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T15:16:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2119b8644a89840c82c3e57a7d1310cff45eae48",
          "body": "…pientName — 오칭 정정(sub를 매치, prime 아님) (#184)\n\ndogfooding(Capture Manager 페르소나)이 확증한 MEDIUM 의미 결함: 파라미터\n`primeRecipientName`이 실제로는 SUBAWARDEE를 필터. spending_by_award{subawards:true}의\n유일한 keyless 수신자 필터 `recipient_search_text`는 USAspending이 sub-recipient에\n매치(라이브 확증 2026-07-16: recipient_search_text:[\"L\n[…]\nture를 새 이름으로 갱신.\n3175→3177 assertions 통과. registry-snapshot 재생성(param rename만, 134툴) MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 파라미터 의미 정정.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(semantics): usas_search_subawards primeRecipientName→subReci…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T15:07:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "11ca03952dfdb64a2bc8f82169cf4c02818932f4",
          "body": "… 정직성 _meta 봉투 부여 (#183)\n\ndogfooding(Compliance 페르소나) LOW: 이 두 list 툴만 top-level {titles}/{agencies}를\n정직성 봉투({data,meta,__isMetaBundle}) 없이 반환 → 소비자가 r.data 파싱 시 trip,\n_meta의 source/totalAvailable/complete disclosure 부재. 나머지 전 툴은 봉투 보유.\n\nfix: 두 source 함수(ecfr.listTitles/fedreg.listAgencies)를 withMet\n[…]\nthMeta 벗기면 RED). 3170→3175 assertions 통과.\nregistry-snapshot MATCH(inputSchema 무변경, 134툴).\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 출력-형태 일관성 수정.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(consistency): ecfr_list_titles + fed_register_list_agencies에…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T14:50:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "715a9f487763f2e63476ecec078070c1e7b9f5ac",
          "body": "…am-drop 근절) (#182)\n\n2개 독립 dogfooding(SmallBiz·Risk 페르소나)이 재확증한 MEDIUM 체계 결함: 모든 Zod\n입력 스키마가 non-strict라 오타/오인 top-level 키(naicsCode↔naics, keyword↔query)가\n조용히 삭제되고 필터 없이 전 코퍼스를 스캔 → authoritative-looking 오답 반환\n(예: usas_search_awards {naicsCode} → NAICS 드롭 → $1.2T 전체지출; sam {keyword} →\n46,753건 'CIRC\n[…]\nertions 통과. registry-snapshot 재생성(sam_search_opportunities에\n  offset prop 추가, 134툴 무변경) MATCH.\n\n안전: PUBLIC OPEN DATA만. 키/PII/우회 없음. 순수 입력검증 경화.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(honesty): 미지정 입력 키 무음-삭제 → loud invalid_input 전환 (silent par…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T14:43:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c7c4e7da0eb3f1c08f0778841ac46d6d07027a2",
          "body": "… Sub-Awardee Name 우선 매핑 (#181)\n\ndogfooding(Risk/Due-Diligence 페르소나)이 확증한 HIGH 정직성 드리프트: USAspending\nspending_by_award(subawards)가 subawardee 이름 필드를 rename. 레거시 \"Sub-Award\nRecipient\"는 이제 항상 null로 echo되고, 실제 값은 \"Sub-Awardee Name\"에 존재.\n툴이 레거시 필드만 요청·매핑 → 모든 subaward의 subRecipient가 조용히 null이 되어\nteaming\n[…]\npient=null 공존 확인.\n\nfault §36: 비공허 드리프트 fixture 추가 — 라이브값을 Sub-Awardee Name에 두고 레거시는\nnull, fallback 행 별도. 레거시 필드만 읽으면 RED. 3166→3169 assertions.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(drift): usas_search_subawards.subRecipient 상시-null 드리프트 수정 —…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T14:23:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ad85a8cea5ecae8f86962f61a8f4249d2627183",
          "body": "An adversarial re-audit of epa_tri_facilities (shipped in npm 1.4.0) surfaced two\nlow-severity but real honesty edges:\n\nF1 — false filtersApplied via a lone '.' path segment. facilityName/county='.' passed\nthe charclass + the  check + encodeURIComponent unchanged, but WHATWG URL collapses\nthe './' s\n[…]\nguard. fault 3162→3166,\nSNAPSHOT MATCH. The other 9 Wave 6/7 tools audited clean (openfda×2, cpsc, nhtsa×2,\ncourtlistener, nonprofit×2, cms×5).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(epa): 2 honesty edges found by the Wave 6/7 re-audit (#180)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T13:57:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26bfaeb9e2234df5f884be905ac0669145db823a",
          "body": "… bug (#179)\n\nThe C4 live edge test asserted `pagination.nextOffset === returned` for the capped\nspending_by_category (psc) aggregate. But that expectation is wrong: the\nspending_by_category/* endpoints report NO grand total and all six callers post\npage:1 with no offset/page input, so ranked-below-\n[…]\nvalue). This was a live-only NON-BLOCKING edge job (91/92 → now 92/92); no src/dist\nchange; fault-injection 3162 and SNAPSHOT MATCH unaffected.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(edge): fix C4 — psc_spending nextOffset is null BY DESIGN, not a…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T13:43:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0de12fb93c9c359cae5066bf62f2f95b8d8fc5e7",
          "body": "Bumps package.json + SERVER_VERSION 1.3.0→1.4.0, adds the 1.4.0 CHANGELOG entry, and\nrefreshes README/.ko/.ja to 134 tools / 44 sources. Adds 14 keyless tools across\nproduct-safety (openFDA/NHTSA/CPSC), environmental (EPA TRI), legal (CourtListener),\nnonprofit (IRS-990), and healthcare (CMS ×5) vetting/market lanes. Keyless-first\nframing unchanged (still only 4 sources need a free key). fault 3162, SNAPSHOT MATCH.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: 1.4.0 — Waves 6-7 keyless expansion (120→134 tools) (#178)",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T13:32:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4c4dfb9863a4fec546ddc0e2c94960083eb361df",
          "body": "…yless CMS supplier utilization + revocation-list vetting (ADR-0064) (#177)\n\nTwo new keyless tools on data.cms.gov's data-API v1 dataset endpoint, reusing\nthe cms-utilization.ts two-request stats-count pattern (ADR-0061) verbatim —\nonly the dataset UUIDs + field mappings differ:\n\n- cms_dmepos_suppli\n[…]\n-vacuous).\nLive-verified keyless: dmepos VA size 2 → 2 suppliers + totalAvailable 1677;\nrevoked FL size 2 → 2 revocations + totalAvailable 723.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cms-supplier): cms_dmepos_suppliers + cms_revoked_providers — ke…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T12:34:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b351b0043feea6e9dd8141258d257f676f5402ec",
          "body": "…data datasets (ADR-0063) (#176)\n\nAdd cms_facility_directory — a healthcare-facility directory / market-map lane\ngeneralizing cms_hospital_compare (ADR-0062) beyond hospitals to nursing homes,\nhome health agencies, hospices, and dialysis facilities (data.cms.gov\nprovider-data DKAN datastore-query AP\n[…]\nted nursing_home's address column is `address`; it is actually\n`provider_address` (probed live) — covered by the address coalescing candidates.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cms-facility): keyless CMS facility directory across 4 provider-…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T12:16:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "412cd70fa8ce7f76e10bd10cd42c064335360181",
          "body": "…irectory (keyless, ADR-0062) (#175)\n\nAdd `cms_hospital_compare` (tool 131), a keyless CMS Hospital Compare\n\"Hospital General Information\" lookup over data.cms.gov's provider-data\nDKAN datastore-query API. Look up Medicare-certified hospitals by US\nstate and/or facility-name fragment (+ optional hos\n[…]\n\nFault fixtures: new §55e3 (22 non-vacuous OFFLINE assertions) — fault\n3081 → 3103. Registry snapshot regenerated: SNAPSHOT MATCH at 131 tools.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cms-hospital): add cms_hospital_compare — CMS Hospital Compare d…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T11:54:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "377002fc9d14a6886d2effb1f0850b67c4799bc7",
          "body": "…-B provider utilization (ADR-0061) (#174)\n\nA new healthcare-market lane: for a given provider (NPI) or state, the Medicare\nPart-B HCPCS services rendered, beneficiaries served, and submitted /\nMedicare-allowed / Medicare-paid amounts (CMS \"Medicare Physician & Other\nPractitioners — by Provider and \n[…]\nols. Fault suite 3055 → 3081 (26 non-vacuous OFFLINE assertions:\n§55e2). Registry snapshot MATCH at 130. Live-verified keyless on data.cms.gov.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cms): cms_medicare_provider_services — keyless CMS Medicare Part…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T11:41:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e6ee9bb879cb26384bed0635039025a379b0349f",
          "body": "…ia ProPublica (ADR-0060) (#173)\n\nAdd two keyless tools on projects.propublica.org/nonprofits/api/v2 (127→129 tools):\n\n- nonprofit_search — query/state[id]/ntee[id]/page(0-based) over IRS Form 990\n  data. P1: totalAvailable = the API's REAL total_results, NEVER\n  organizations.length; page-based 0-i\n[…]\n search\n\"american red cross\" -> 11 orgs (totalAvailable=total_results); financials EIN\n530196605 -> American National Red Cross, revenue ~3.2B.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(nonprofit): keyless IRS Form 990 nonprofit search + financials v…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T11:12:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b93fe98bf4835ad127e9ec78126e1231bd498bc6",
          "body": "…cilities (keyless) (#172)\n\n126→127툴. data.epa.gov /efservice/tri_facility, KEYLESS (키 없음 — KEY_REGISTRY/\nkeys.ts/API_KEYS.md 무변경). 환경 발자국/이행장소 스크린 레인.\n\n★2-요청 count-total 패턴(P1): 필터 경로 + /count/JSON → TOTALQUERYRESULTS(정확한\n총계, 예 VA=1247)로 totalAvailable 설정 — 절대 슬라이스 길이로 위조하지 않음. count\n서브쿼리 실패/부재 → t\n[…]\n}→필터 부분집합+자체 count 19. bad-table→404,\nfac_closed_ind 라이브값 \"0\"/\"1\"(스키마상 N/Y도 처리).\n\nfault 2990→3015(+25 §55e 비공허), SNAPSHOT MATCH at 127툴, tsc 0.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "research(wave4): ADR-0059 epa_tri_facilities — EPA Envirofacts TRI fa…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T10:49:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "71e8700be26c0efea18c38e470c832544de6f150",
          "body": "…-0058) (#171)\n\nAdd cpsc_recalls (www.saferproducts.gov /RestWebServices/Recall), the\nconsumer-goods / import product-safety vetting lane alongside nhtsa_recalls\n(vehicles) and openfda (medical). 125→126 tools.\n\nKEYLESS — no API key at all (no parameter, no header); touches no key seam\n(KEY_REGISTRY\n[…]\napshot\nMATCH at 126 tools; live smoke {2025-01-01..2025-01-15} => 5 recalls,\ntotalAvailable=5, nested-flatten + NumberOfUnits string confirmed.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cpsc): cpsc_recalls — keyless CPSC consumer-product recalls (ADR…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T10:31:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd2b76c6b74ddebdb743f5a161be5480e49161eb",
          "body": "… safety (ADR-0057) (#170)\n\nAdd two keyless tools on api.nhtsa.gov for vehicle/parts/fleet supplier\nproduct-safety vetting (the cross-agency product-safety family alongside\nopenFDA):\n\n- nhtsa_recalls    /recalls/recallsByVehicle?make=&model=&modelYear=\n- nhtsa_complaints /complaints/complaintsByVehi\n[…]\nrated → SNAPSHOT MATCH at 125. Live smoke\n(honda accord 2020): recalls 5/totalAvailable 5; complaints 335/totalAvailable\n335, no VIN in output.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(nhtsa): nhtsa_recalls + nhtsa_complaints — keyless NHTSA vehicle…",
          "author_name": "seungdo-keum",
          "author_login": "seungdo-keum",
          "committed_at": "2026-07-15T10:18:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 10,
      "commits_last_year": 273,
      "latest_release_at": "2026-07-24T06:45:01Z",
      "latest_release_tag": "v1.12.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 5,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 9.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@cliwant/mcp-sam-gov",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "mcp",
            "model-context-protocol",
            "sam.gov",
            "usaspending",
            "federal-contracting",
            "govcon",
            "claude-desktop",
            "claude-code",
            "codex",
            "cursor",
            "continue",
            "gemini-cli",
            "ai-tools",
            "sled",
            "state-local",
            "procurement",
            "opengov",
            "bonfire",
            "arcgis",
            "socrata",
            "bid-opportunities"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@cliwant/mcp-sam-gov",
          "is_deprecated": false,
          "latest_version": "1.12.0",
          "repository_url": "https://github.com/cliwant/mcp-sam-gov",
          "versions_count": 15,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2461,
          "first_published_at": "2026-04-29T06:57:55.561000Z",
          "latest_published_at": "2026-07-24T06:44:57.919000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 4,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-08",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 1963423,
      "source_files_sampled": 84,
      "oversized_source_files": 7,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 5
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 96,
        "malicious_count": 0,
        "assessed_package": "npm:@cliwant/mcp-sam-gov@1.12.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.20.0"
        },
        {
          "name": "unpdf",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.2"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.24.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 267,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "seungdo-keum",
          "commits": 273,
          "avatar_url": "https://avatars.githubusercontent.com/u/134980891?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "ci.yml",
        "dco.yml",
        "mcp-registry-publish.yml",
        "release.yml",
        "snapshots.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 3,
            "reason": "7 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "b27682fa1d133f8ca8a820c60af808dde1ac5492",
        "ran_at": "2026-07-27T16:47:52Z",
        "aggregate_score": 4.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T07:25:53Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-24T08:49:59Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/cliwant/mcp-sam-gov",
    "host": "github.com",
    "name": "mcp-sam-gov",
    "owner": "cliwant"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 50,
        "vitality": 75,
        "community": 47,
        "governance": 54,
        "engineering": 62
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 273,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 5
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "5/52 weeks with commits",
                "points": 3.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "273 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 273
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 10,
              "latest_release_tag": "v1.12.0",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 9.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "10 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~9.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 9.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 47,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 8,
            "inputs": {
              "forks": 1,
              "stars": 4,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "4 stars",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "@cliwant/mcp-sam-gov"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2461
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,461 downloads/month across npm",
                "points": 45.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2461,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "merged_prs": 267,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "267/269 decided PRs merged",
                "points": 38,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 267,
                      "decided": 269
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "followers": 3,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "cliwant",
              "public_repos": 14,
              "account_age_days": 917
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of cliwant",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "cliwant"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "14 public repos, account ~2 yr old",
                "points": 13.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 14
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@cliwant/mcp-sam-gov"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "15 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 62,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 44,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ai-agents",
                "anthropic",
                "claude",
                "federal-government",
                "govcon",
                "government-contracting",
                "govtech",
                "keyless",
                "llm-tools",
                "mcp",
                "mcp-server",
                "model-context-protocol",
                "open-data",
                "procurement",
                "public-data",
                "rfp",
                "sam-gov",
                "sled",
                "typescript",
                "usaspending"
              ],
              "has_wiki": false,
              "homepage": "https://cliwant.github.io/mcp-sam-gov/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://cliwant.github.io/mcp-sam-gov/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 50,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "7 existing vulnerabilities detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@cliwant/mcp-sam-gov@1.12.0 runtime dependency closure — what installing the published package pulls in — 96 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@cliwant/mcp-sam-gov@1.12.0",
                  "assessed": 96
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 96,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 96,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 40,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.7,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "70 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 70,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 1963423,
              "source_files_sampled": 84,
              "oversized_source_files": 7
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript with type-check config (tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "tsconfig.json",
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "7/84 source files over 60KB",
                "points": 50.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 84,
                      "oversized": 7
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T16:48:09.611997Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cliwant/mcp-sam-gov.svg",
  "full_name": "cliwant/mcp-sam-gov",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.