Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 2.3.1 · 2026-08-02 14:19 UTC

damoqiongqiu / mcp-local-rag

Local-first RAG server for developers. Semantic + keyword search for code and technical docs. Works with MCP or CLI. Fully private, zero setup.

TypeScriptMIT★ 13 Sterne⑂ 0 Forksseit Juli 2026ForkAuf GitHub ansehen ↗
ArtMCP-ServerBibliothekwie das ermittelt wird

damoqiongqiu/mcp-local-rag erreicht einen Gesundheitsindex von 54 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (81/100) ab, am schwächsten bei Community & Adoption (31/100). Zuletzt vor 9 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

54
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer standardisierten Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr gewichtetes Mittel, kalibriert auf die Verteilung des öffentlichen Registers, sodass die Stufen Perzentilbedeutung tragen; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze Gefährdet von 34.

54
Außergewöhnlich93-100Die Spitzengruppe des Registers (≈ obere 5 %); erfüllt im Wesentlichen alle geprüften Kriterien
Exzellent80-92Durchgehend stark; geringfügige Lücken
Gut65-79Gesund; Lücken sind begrenzt und beherrschbar
Mittel50-64Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Schwach35-49Wesentliche Schwächen in mehreren Bereichen
Gefährdet20-34Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-19Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Der gewichtete Gesamtwert 53 wird auf der veröffentlichten Indexskala auf 54 kalibriert (Register-Kalibrierung 2026-08-02).

Eigentümerschaft

大漠穷秋Persönliches Konto
1.446 Follower33 öffentliche Reposseit Juni 2012None

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

81Exzellent · 21 % des Gesamtindex
Wie die Bewertung erfolgt
28.8/36Push-Aktualität — letzter Push vor 9 Tagen
21.5/36Commit-Rhythmus — 31/52 Wochen mit Commits
18/18Commit-Volumen — 636 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year636
human_commit_share1
days_since_last_push9
active_weeks_last_year31

Release-Disziplin

100Außergewöhnlich
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 6 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 22 Tagen
27/27Release-Rhythmus — ein Release etwa alle 0 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count6
latest_release_tagv0.18.5
releases_from_tagsnein
days_since_latest_release22
mean_days_between_releases0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

31Gefährdet · 17 % des Gesamtindex
Wie die Bewertung erfolgt
17.5/60Stars — 13 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars13
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
0/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmenein
has_licensenein
readme_badges
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
readme_badge_services
has_pull_request_templatenein
Wie die Bewertung erfolgt
48.5/80Downloads pro Monat — 4.305 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packages@damoqiongqiu/mcp-local-rag
dependents
ecosystemsnpm
total_downloads
monthly_downloads4.305
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

46Schwach · 23 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
4.8/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 79 % der Commits
9.5/13.5Breite der Beitragenden — 7 Beitragende
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Verwendete Eingangsdaten
bus_factor1
contributors_sampled7
top_contributor_share0,786
Wie die Bewertung erfolgt
0/42Issue-Lösungsquote — keine Issues oder keine Daten
0/30PR-Annahme — keine entschiedenen Pull Requests oder keine Daten
0/13Newcomer PR acceptance — kein PR eines Erstbeitragenden in 30 Tagen entschieden
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs0
open_issues0
closed_issues0
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio
closed_unmerged_prs0
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote, PR-Annahme, newcomer_pr_acceptance. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
22.7/25Reichweite des Inhabers — 1.446 Follower von damoqiongqiu
23.2/25Kontohistorie — 33 öffentliche Repos, Kontoalter ca. 14 Jahre
Verwendete Eingangsdaten
followers1.446
owner_typeUser
is_verified
owner_logindamoqiongqiu
public_repos33
account_age_days5.168
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

100Außergewöhnlich
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 9 Tagen
20/20Versionshistorie — 25 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packages@damoqiongqiu/mcp-local-rag
ecosystemsnpm
any_deprecatednein
min_days_since_publish9

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

52Mittel · 19 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 3 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — biome.json
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.

Dokumentation

10Kritisch
Wie die Bewertung erfolgt
0/30README
0/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
0/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepage
has_readmenein
has_docs_dirnein
has_descriptionnein

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

46Schwach · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,7
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
7.3/25Indirekte Abhängigkeiten ohne bekannte Advisories — 3 betroffen: adm-zip 0.5.18 (high 7.5), sharp 0.33.5 (high 7.3), sharp 0.34.5 (high 7.3)
40/40Keine offenen Advisories — kein Advisory ist länger als 90 Tage öffentlich
Verwendete Eingangsdaten
sourceosv
advisories3
affected_packages3
assessed_packages333
unassessed_packages0
affected_by_severityhigh 3
direct_affected_packages0
Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:@damoqiongqiu/mcp-local-rag@0.21.0 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 333 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Trägt ein bewusst kleines Gewicht (4 %): Agenten-Tooling ist ein echtes Pflegesignal, doch ein Repository ohne jedes Signal kann weiterhin 100/100 erreichen.

69Gut · 4 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — AGENTS.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 96 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,96
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes8.740
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — biome.json
11/11Statische Typprüfung — tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespnpm-lock.yaml
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_configja
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
54.7/55Handhabbare Dateigrößen — 1/162 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes74.957
source_files_sampled162
oversized_source_files1
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
20/20MCP-Server
0/40Lauffähige Beispiele
Verwendete Eingangsdaten
example_dirs
has_mcp_signalja
api_schema_files

Eckdaten

13GitHub-Sterne
7Mitwirkende
636Commits, letzte 12 Monate
9Tage seit letztem Push
6Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Community profile unavailable
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 3.7 / 10
3.7Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-08-02 14:19 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
Direkte Abhängigkeiten 13
RegistryPaketVersionsvorgabeManifest
npm@huggingface/transformers^4.2.0package.json
npm@lancedb/lancedb^0.31.0package.json
npm@modelcontextprotocol/sdk^1.29.0package.json
npm@mozilla/readability0.6.0package.json
npmchokidar^5.0.0package.json
npmcode-chunk^0.1.14package.json
npmignore^7.0.5package.json
npmjsdom^29.1.1package.json
npmmammoth^1.12.0package.json
npmminimatch^10.2.5package.json
npmmupdf^1.28.0package.json
npmturndown7.2.4package.json
npmundici^7.28.0package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 3

Die Installation von npm:@damoqiongqiu/mcp-local-rag@0.21.0 zieht 333 Pakete nach sich, direkt und transitiv: 3 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

PaketVersionBeziehungSchweregradAdvisoriesBehoben in
adm-zip0.5.18indirekthoch10.6.0
sharp0.33.5indirekthoch10.35.0
sharp0.34.5indirekthoch10.35.0

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 2403,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 975,
        "JavaScript": 9097,
        "TypeScript": 1647107
      },
      "pushed_at": "2026-07-23T15:20:07Z",
      "created_at": "2026-07-11T02:05:50Z",
      "owner_type": "User",
      "updated_at": "2026-07-24T02:41:36Z",
      "description": "Local-first RAG server for developers. Semantic + keyword search for code and technical docs. Works with MCP or CLI. Fully private, zero setup.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://gitee.com/mumu-osc",
      "name": "大漠穷秋",
      "type": "User",
      "login": "damoqiongqiu",
      "company": "None",
      "location": "Nanjing, China",
      "followers": 1446,
      "avatar_url": "https://avatars.githubusercontent.com/u/1829010?v=4",
      "created_at": "2012-06-08T01:29:30Z",
      "is_verified": null,
      "public_repos": 33,
      "account_age_days": 5168
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.18.5",
          "kind": "patch",
          "published_at": "2026-07-11T13:40:11Z"
        },
        {
          "tag": "v0.18.4",
          "kind": "patch",
          "published_at": "2026-07-11T13:40:10Z"
        },
        {
          "tag": "v0.18.3",
          "kind": "patch",
          "published_at": "2026-07-11T13:40:00Z"
        },
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2026-07-11T13:39:59Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-07-11T13:39:59Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-11T13:39:50Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3e94e45f842ed9a9119fcd90469f02b78c951a7b",
          "body": "…or bug)\n\nWindows gitignore.test.ts has pre-existing path separator issues\n(\\ vs / in ignore library). Allow test matrix to pass through for\nci gatekeeper so ubuntu/macOS test coverage gates correctly.",
          "is_bot": false,
          "headline": "ci: continue-on-error for test matrix (Windows gitignore path-separat…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T15:12:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "685c3ad134622d3e4849dcecb071dbb05d214c21",
          "body": "Replace join() with normalized p() helper that converts \\ to / for\ncross-platform consistency with the ignore library's path expectations.",
          "is_bot": false,
          "headline": "fix: gitignore test path normalization for Windows",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T15:05:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "336daa211eaef927555a020b0949264e7ffe50a9",
          "body": "Root causes:\n- delete.integration: LRU cache not cleared when tests call server.handleXxx()\n  wrappers directly (vs dispatcher path). Add this.queryCache.clear() to\n  handleIngestFile/Data/Directory, handleDeleteFile, handleConfig,\n  handleReindexStale/All wrappers.\n- rollback: console.error('Rollback failed/completed') logs lost during\n  handleIngestFile extraction. Restore original logging in ingest.ts.\n- manage.test: remove hash-dependent test (node:crypto mock unreliable in CI)",
          "is_bot": false,
          "headline": "fix: flaky CI tests — restore cache invalidation + rollback logs",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:53:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a630eedfedba6b629cc88a026d577eac764c1687",
          "body": "node:crypto mock is unreliable in CI with isolate:false config.\nRemove test case that depends on mocked hash identity.\nKeep 6 tests covering threshold validation and edge cases.",
          "is_bot": false,
          "headline": "fix: remove flaky hash-based dedup test from manage.test.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:35:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7aa12a217a7ca4e9a874ed0ed7458ba1127feca",
          "body": "CI integration tests call server.handleIngestFile() etc. directly.\nRestore 17 thin delegate wrappers that map to extracted handler functions.\nFix ingestFileCore name collision via import alias handleIngestFileCore.",
          "is_bot": false,
          "headline": "fix: restore server.handleXxx() API-compat wrappers for CI tests",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:23:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c910f2b1ccf4024daf9ad53892ead9b5e82ba86",
          "body": "- searchMode presets (exact/code/doc)\n- LRU query cache\n- Server monolith split (2147→611, -71.5%)\n- 5 P0 security fixes + P1 validation\n- Handler unit tests (13 new)\n- reindex_all bug fix",
          "is_bot": false,
          "headline": "chore: bump version to 0.21.0 + update CHANGELOG",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3910f6304168334954cdba751a75a1b9f49d95e7",
          "body": "- handlers/ingest.ts: replace args: any with precise types (IngestDataInput,\n  IngestDirectoryInput, ReindexAllInput)\n- handlers/delete.ts: 6 unit tests (validation, source/filePath modes, existed)\n- handlers/manage.ts: 7 unit tests (threshold validation, duplicate detection)\n- Add IngestDataInput, IngestDirectoryInput, ReindexAllInput imports\n- Tests use vi.hoisted() pattern for mock hoisting in vitest 4.x",
          "is_bot": false,
          "headline": "feat: add direct unit tests for handlers + fix type alignment",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "956657ae98ed1ee63b9f60f05d4007b9add13f42",
          "body": "Handler methods were extracted to separate files but their JSDoc comments\nwere left behind. Identified via script: JSDoc followed by empty space\n(no method declaration) = orphan.\n\n744 → 611 lines (-133 lines, -18%)\"",
          "is_bot": false,
          "headline": "refactor: remove 17 orphan JSDoc blocks from server/index.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d05875e29de0ab5c7e9a148e84ea34279c0b851",
          "body": "Root cause: this.→deps. replacement in handlers/ingest.ts lost the deps\nargument on 3 internal ingestFileCore() calls (reindexStale, reindexAll,\nhandleIngestDirectory). Also missing IngestDeps fields (rawBaseDirs,\nrawBaseDir, sendProgress, excludePaths).\n\nAdditional fixes:\n- IngestFileDeps → IngestD\n[…]\nuter, DocumentParser, IngestDirectoryFileResult\n- Dispatcher: this.handleIngestData/Directory/ReindexStale/ReindexAll → direct calls\n- FileWatcher: this.ingestFileCore → ingestFileCore(deps, filePath)",
          "is_bot": false,
          "headline": "fix: reindex_all crash — ingestFileCore missing deps param",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "174e1b975de47a162dcf722f6852672906325a32",
          "body": "…directly\n\nDelete all 12 delegate methods. Fix 3 remaining dispatcher calls\n(queryDocuments, findDefinition, findReferences) to call extracted\nhandlers directly instead of through this.handleXxx() wrappers.\n\nindex.ts: 1027 → 743 lines (-65% from original 2147)",
          "is_bot": false,
          "headline": "refactor: remove delegate wrapper methods, dispatcher calls handlers …",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f2caa176e73d7ec01d79078f5400805fff7f03e",
          "body": "Remove unused imports, fix interface types, add missing scanBaseDir import,\nfix embedder type for optional 2nd arg, fix ingestFileCore return status cast.",
          "is_bot": false,
          "headline": "fix: ingest.ts imports and type cleanup",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2264d801af7ab66f413537a14012033f866a6b72",
          "body": "index.ts: 2147 → 1030 lines (-52%)\n\nhandlers/\n  search.ts     ✅ queryDocuments\n  code-intel.ts ✅ findDefinition + findReferences\n  manage.ts     ✅ dedupCheck + exportIndex + config\n  system.ts     ✅ healthCheck + status\n  delete.ts     ✅ deleteFile\n  list.ts       ✅ listFiles\n  read-neighbors.ts ✅ r\n[…]\nstate + constructor\n- 4 private helpers (assertConfigOk, resolveChunker, withWarnings, sendProgress)\n- deps getter + setupHandlers dispatcher + thin delegate wrappers\n\nType-check: clean · Build: clean",
          "is_bot": false,
          "headline": "refactor: complete server split — all 14 handlers extracted",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "79dd2e309727aa82e0a1ce14094b2bdd7aea3d46",
          "body": "handler extraction COMPLETE — index.ts: 1382 → 1057\nimport cleanup needed, committing with --no-verify",
          "is_bot": false,
          "headline": "WIP: extract all 6 ingest handlers to handlers/ingest.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3db6b1d0120a846a9a0bae597db20ce5e2b8e8c8",
          "body": "index.ts: 1538 → 1382 lines (-35% total from 2147)",
          "is_bot": false,
          "headline": "refactor: extract handleIngestFile to handlers/ingest.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b7c7ea67b7443aec699d093308f6c4450cab6e9",
          "body": "index.ts: 1610 → 1538 lines",
          "is_bot": false,
          "headline": "refactor: extract handleReadChunkNeighbors to handlers/read-neighbors.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81ec4e5ceebd1e534a36a47b10b1cc700a0a22dd",
          "body": "Remove unused imports (classifyIngestedSources, realpathForMatch,\nnonAbsolutePrefixes, FileEntry, ListFilesResult, SourceEntry).\nindex.ts: 1714 → 1614 lines (-24.8% total)",
          "is_bot": false,
          "headline": "refactor: extract handleListFiles to handlers/list.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "208ffbe035883c621b78bdb819d5b888540687af",
          "body": "Remove unused imports (checkRawDataArtifacts, isEnoent, isPathInRawDataDirLexical,\nDeleteFileResult, unlink).\nindex.ts: 1785 → 1714 lines (-20.2% total)",
          "is_bot": false,
          "headline": "refactor: extract handleDeleteFile to handlers/delete.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50b091864ea607f39d18d3c0ac18995b63e1c1be",
          "body": "Add withWarnings to SystemDeps, unify handleHealthCheck and handleStatus\nunder same interface. Remove unused imports (resolveModel, buildConfigErrorBlock).\nindex.ts: 1801 → 1785 lines",
          "is_bot": false,
          "headline": "refactor: extract handleStatus to handlers/system.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c151ce03beb484a5386e618fc431f3ec9f18efa6",
          "body": "Replace handleConfig body with delegate. Remove unused ConfigResult import.\nindex.ts: 1859 → 1801 lines",
          "is_bot": false,
          "headline": "refactor: extract handleConfig to handlers/manage.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af9d0a951c735bc85917f8ef13a061e5dd8dd0c2",
          "body": "Replace handleHealthCheck body with delegate. Remove now-unused\nimports (constants, access).\nindex.ts: 1955 → 1859 lines",
          "is_bot": false,
          "headline": "refactor: extract health_check to handlers/system.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f471c80ee8fb850c69cc2e37edc1cda0d3b2826",
          "body": "Replace handleExportIndex and handleDedupCheck method bodies with\nthin delegates to handlers/manage.ts. Remove now-unused imports\n(createHash, writeFile, ExportIndexResult, DedupCheckResult).\n\nindex.ts: 2147 → 1955 lines (-9%)",
          "is_bot": false,
          "headline": "refactor: replace manage handler bodies with delegation wrappers",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1c764e4c68e898a82dae86dc7dc2f0950ab4857",
          "body": null,
          "is_bot": false,
          "headline": "refactor: extract dedup_check + export_index to handlers/manage.ts",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d05bdf2091fcc72725180f7d90c8c05df75e2b5f",
          "body": "Invalidate LRU query cache after any mutation via central dispatcher:\n- ingest_file, ingest_data, ingest_directory\n- delete_file\n- reindex_stale, reindex_all\n- config\n\nWrapped in dispatcher switch cases to avoid per-handler code insertion.",
          "is_bot": false,
          "headline": "feat: query cache invalidation on mutation handlers",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a66fe5c239c27535ba19ac2f7b4387a456d9d03b",
          "body": "…st coverage\n\nSecurity (P0→P1):\n- F-001: Sanitize proxy credentials in startup config dump\n- F-002: Runtime input validation for find_definition/find_references\n- F-003: Runtime input validation for config/dedup_check/export_index\n- F-004: Upgrade undici→7.28.0, fast-uri→4.1.1 (CVEs)\n\nFeatures:\n- LR\n[…]\nion.ts: 6 tests\n- pdf-visual/shared.ts: 20 tests\n- pdf-visual/fast.ts: 3 tests\n- bin/install-skills.ts: 12 tests\n- server/lru-cache.ts: 10 tests\n\nAssessment:\n- GStack 4-specialist comprehensive report",
          "is_bot": false,
          "headline": "feat: security fixes, LRU cache, searchMode presets, server split, te…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d2fcca6a7b8a6f75d10b3e7b1df7d64b6be4de3",
          "body": "Adds a health_check tool that actively probes four critical subsystems:\n- Config: BASE_DIR accessibility (access with R_OK)\n- Embedder: model loaded? (probe via embed('health_check probe'))\n- LanceDB: readable? (listFiles + chunk/instance count)\n- Cache: writable? (access with W_OK)\n\nReturns structu\n[…]\nke status (which dumps stored metadata), health_check\nactively probes the system and provides fix suggestions for each\nfailure — no need to dig through stderr or README FAQ.\n\nTools count: 16 (was 15).",
          "is_bot": false,
          "headline": "feat: health_check MCP tool — proactive server diagnostics",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-23T14:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61ad5aeb745a91f94f83c8da44eff547f558360d",
          "body": null,
          "is_bot": false,
          "headline": "Update README_CN.md",
          "author_name": "lumi202507",
          "author_login": "lumi202507",
          "committed_at": "2026-07-22T08:48:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e74db9c296b605166aee7f87a90b38d98ed53ad0",
          "body": "…process\n\nvitest isolate=false means mock-dependent tests (vi.doMock for\ntransformers) must run BEFORE the real module is loaded. The coverage\njob was running everything in one process, causing router.test.ts\nand dtype tests to fail because the real module clobbered the mocks.\n\nSplit coverage into two runs: mock-dependent tests first (no coverage),\nthen main suite with coverage (excluding mock-dependent files).",
          "is_bot": false,
          "headline": "fix(ci): run mock-dependent tests before coverage in isolated vitest …",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T04:57:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ead4b938d3bc1c1076dcb13a0c4aec90c52de65a",
          "body": "onnxruntime-node's postinstall downloads CUDA binaries from NuGet,\ncausing intermittent ETIMEDOUT failures across ALL CI jobs that run\npnpm install. Move the env var to workflow-level so every job skips\nthis unnecessary download (CPU binary is already bundled).",
          "is_bot": false,
          "headline": "fix(ci): set ONNXRUNTIME_NODE_INSTALL=skip at workflow level",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T04:51:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5a3160ea4cb84ef06a9e08c5f117daa5a27e952",
          "body": "onnxruntime-node's postinstall downloads CUDA binaries from NuGet,\nwhich timeouts randomly on CI runners (ETIMEDOUT on Azure). The CPU\nbinary is already bundled — skip the download to eliminate this flaky\nfailure cause.",
          "is_bot": false,
          "headline": "fix(ci): skip onnxruntime-node postinstall in test jobs",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T04:43:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be75e86734e9c49cadef5a72490c423b0839ff3b",
          "body": "Coverage thresholds (70% lines / 60% branches) were set without\nknowing the actual baseline, causing the CI coverage job to fail.\nRemove thresholds for now — the job still runs and reports coverage\nnumbers. Thresholds will be re-enabled once we confirm actual coverage\nlevels.",
          "is_bot": false,
          "headline": "fix(ci): remove coverage thresholds until baseline established",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T04:34:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fcfb8d26689eb3b33a57a697bd83fc533842d1d",
          "body": "- macOS lacks Vulkan support, causing webgpu-main-path to fail\n- @vitest/coverage-v8 4.1.10 conflicts with vitest 4.1.9, causing\n  'Running mixed versions is not supported' warning and potential\n  coverage failures. Downgrade to 4.1.9.",
          "is_bot": false,
          "headline": "fix(ci): remove macOS from webgpu matrix, match vitest-coverage version",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T04:27:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "752ec5157bad297a11bd48b20b54bf0cdbc67326",
          "body": "Added:\n- 35 unit tests for CodeChunker: TS/JS/Python chunking, AST entity\n  extraction, import metadata, scope chain, edge cases (empty/whitespace)\n- isCodeChunkExtension tests for all 17 supported and unsupported extensions\n\nCI/CD:\n- Coverage gate via vitest --coverage (v8): 70% lines / 60% branches\n- macOS runner added to static-checks and test job matrices\n- New coverage job in CI pipeline, gated by ci aggregate check\n\nDev dependency: @vitest/coverage-v8",
          "is_bot": false,
          "headline": "release: v0.19.4 — code-chunker tests + CI coverage gate + macOS runner",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T04:17:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5ed3c1c235da55bb641cec4c9279bbbbc8904d2",
          "body": "pnpm publish with _authToken in .npmrc returns 404 from npm registry,\nlikely due to pnpm 11's auth resolution order conflicting with the\nregistry-level token. npm publish via setup-node's NODE_AUTH_TOKEN\nis the most battle-tested approach.",
          "is_bot": false,
          "headline": "fix(ci): switch to npm publish with NODE_AUTH_TOKEN",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T03:08:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cc637ad5780f29d79b69817913bb95c695db549",
          "body": "pnpm tries OIDC provenance token exchange when id-token: write is set,\nwhich returns 404 because the npm package hasn't enabled provenance yet.\nThis causes the publish to fail even though NPM_TOKEN is available.\n\nFix: remove id-token: write permission, write ~/.npmrc with the token\nexplicitly before running pnpm publish.",
          "is_bot": false,
          "headline": "fix(ci): npm publish workflow — remove OIDC, use explicit .npmrc",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T03:05:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe9c01eee026bb05bcb33b2182efa1376a8488dd",
          "body": "Security:\n- TOCTOU race fix: validateFilePath returns resolved realpath, all internal\n  readFile calls now use the validated canonical path\n- export_index: constrain custom outputPath to dbPath to prevent arbitrary\n  file writes\n- ingest_data: add MAX_INGEST_DATA_SIZE (100MB) guard against DoS via\n \n[…]\nm version polling (2min max)\n- Checkout action pinned to SHA (supply-chain hardening)\n\nHousekeeping:\n- server.json version synced with package.json (was 0.18.9 → 0.19.3)\n- CHANGELOG updated for 0.19.3",
          "is_bot": false,
          "headline": "release: v0.19.3 — security fixes + CI/CD automation",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-22T03:02:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9752ae2dfeec311e5a71c484e289fbc758a45745",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump to 0.19.2",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T06:02:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "346451938efb1df157aa7048600b7f22391911a3",
          "body": null,
          "is_bot": false,
          "headline": "fix: remove npm publish from CI workflow (manual OTP required)",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T06:01:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb06dd18099a5c5d6e060b2bcd1522447210e5c3",
          "body": "Replace startsWith with isUnderOrEqual in validateFilePath to fix\n'outside all configured roots' error when passing the baseDir itself.\nThe withTrailingSeparator adds a trailing / that realpath doesn't return,\ncausing startsWith to fail for exact root matches.\n\nBump to 0.19.1.",
          "is_bot": false,
          "headline": "fix: use isUnderOrEqual for path validation in parser",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T05:54:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8a95dc6e6db319e3206a20b3c900299f05f24d7",
          "body": "…IDC setup)",
          "is_bot": false,
          "headline": "fix: remove --provenance flag from npm publish (requires additional O…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:58:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "368ec796863de28311b3251b8ba4db28930680b6",
          "body": null,
          "is_bot": false,
          "headline": "fix: use vi.hoisted with platform detection for resolver test mock",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:49:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2292d2616bfb1a3fedd205c4fd7f693fe920199",
          "body": "realpath mock now returns paths with sep from node:path,\nmatching resolver's withTrailingSep() which also uses sep.",
          "is_bot": false,
          "headline": "fix: use platform-specific separators in resolver test mock",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:43:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b383fb060ad7bd7e9bf192a1c6ea4767fed05b40",
          "body": null,
          "is_bot": false,
          "headline": "fix: one more cross-platform dbPath assertion",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:36:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b423fcc573d08972411cf45696c43097bea03e42",
          "body": "- Normalize Windows drive letters and backslashes in realpath mock\n- Use path.resolve() for dbPath assertions instead of hardcoded Unix paths",
          "is_bot": false,
          "headline": "fix: cross-platform path handling in resolver tests",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:29:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52133cf030a99ae9078c0f9c449b247765c1473a",
          "body": "- Add router.test.ts to CI isolated mock-dependent tests step\n- Exclude router.test.ts from main test suite on all platforms\n- Add npm publish step to publish workflow (was only MCP Registry)",
          "is_bot": false,
          "headline": "fix: CI Windows mock + npm publish in release workflow",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:24:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19e8b5b0bb85766eeb1e046fc086741f111495dd",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.19.0",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:19:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16cdf40a07b04f0ec925a7353a0379804e2bc12f",
          "body": "Replace single VectorStore + BASE_DIRS with per-project LanceDB isolation.\n\nNew module src/instances/:\n- types.ts: InstanceConfig core types\n- parser.ts: RAG_INSTANCES JSON parser with field-level errors\n- resolver.ts: instance config resolver (RAG_INSTANCES > BASE_DIRS > BASE_DIR)\n- router.ts: Inst\n[…]\nfiles/status get instance parameter\n- CLI: --instance flag support across all 6 subcommands\n- Backward compat: BASE_DIR + DB_PATH single-instance mode preserved\n\n156 tests pass (69 new + 87 affected).",
          "is_bot": false,
          "headline": "feat: multi-instance architecture with RAG_INSTANCES config",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-21T03:15:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "86290392d856b8a85a81121b39b10423ed960f76",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.18.9 — docs restructuring + performance tuning guide",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T13:06:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1babc7e983e1d3f42e47b515922f517546f2f73e",
          "body": "Covers RAG_DTYPE, RAG_DEVICE, CHUNK_MIN_LENGTH with:\n- Comparison tables (fp32 vs fp16 vs q8)\n- How to configure each parameter\n- How to verify it works (check status, startup logs)\n- What to do if it fails (revert steps)\n- Recommended config combinations per scenario\n- Clear warnings about index rebuild requirements\n\nBoth CN and EN versions, consistent structure.",
          "is_bot": false,
          "headline": "docs: add Performance Tuning section to both READMEs",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T12:53:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cd0af58b2ecb668a9a5f438bce4638568c11c22",
          "body": "…rsion",
          "is_bot": false,
          "headline": "docs: make README.md English-only, remove all Chinese from English ve…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T12:31:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce58d323c9ba3171c66080767ba3aa4f50785072",
          "body": "- CN: 741 → 513 lines (-31%), EN: 892 → 514 lines (-42%)\n- 10 numbered sections with consistent hierarchy\n- MCP tools organized into 5 categories with tables:\n  4.1 Ingest, 4.2 Search, 4.3 Management, 4.4 Code Intelligence, 4.5 System\n- Removed duplicated scope/mirror/model explanations\n- Merged \"Why This Exists\" into Features section\n- Merged \"How It Works\" into Core Concepts\n- Flattened troubleshooting into collapsible sections\n- Consistent bilingual format in EN README",
          "is_bot": false,
          "headline": "docs: restructure READMEs with numbered hierarchy, tool categorization",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T12:28:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "111928583f5c541211ee76e8c28a85f85dff2eb5",
          "body": null,
          "is_bot": false,
          "headline": "fix: trim server.json description to ≤100 chars for MCP Registry",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T12:14:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15f36a58d801e9867e3e364d9860881a09a3ec7f",
          "body": "…olation)",
          "is_bot": false,
          "headline": "release: v0.18.8 — docs (7→15 tools), CI green (Windows fix + mock is…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T12:08:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13b7fbc57421448c49df89b6b0889222b9459bef",
          "body": "…r on Windows",
          "is_bot": false,
          "headline": "ci: use single-line commands to avoid PowerShell --exclude parse erro…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T12:03:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4f85192fe62e4d9f835d8f11a6500693e7421c8",
          "body": "- Tool count: 7 → 15 (both README.md and README_CN.md)\n- New sections in both READMEs:\n  * AST Code Intelligence (find_definition, find_references)\n  * Batch Ingest (ingest_directory)\n  * Runtime Configuration (config tool)\n  * System Management (dedup_check, export_index, reindex_all, reindex_stale\n[…]\ne Watching (RAG_WATCH)\n  * Model Selection (6 models table with aliases, RAG_DTYPE)\n- server.json: added HF_ENDPOINT and HF_AUTO_MIRROR env vars,\n  updated description to mention AST code intelligence",
          "is_bot": false,
          "headline": "docs: update README and server.json for 15 MCP tools + new features",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T12:00:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a367f498034db20a8280e55164a0e6cc05718f77",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove unused imports in dtype-pdf-regression test",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T11:49:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "583df98a07b1da04f67407ffa63665c43385ed6c",
          "body": "…link EEXIST, LanceDB residual state\n\nProblem\n-------\nvitest runs with isolate:false (shared module registry). The real\nconnectivity.js module (resolveEndpoint + nextMirror) was loaded by\nearlier tests and then used inside embedder.initialize() — its network\nprobe failures swallowed the transformers\n[…]\nocess gets unique paths,\n   decoupling entirely from isolate:false state sharing\n\n5. AC-008 symlink EEXIST: same cleanup pattern as #3\n\nResult: 74/74 test files pass, 1110/1110 tests pass, 0 failures.",
          "is_bot": false,
          "headline": "test: fix mock isolation — connectivity.js leaks across 5 suites, sym…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T11:49:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "02892acb2d805a411809988f97df815c76d40909",
          "body": "The test job runs pnpm test without building first, so dist/index.js\ndoesn't exist. E2E tests and entry-routing dist tests both prefer the\ncompiled output to avoid tsx's code-chunk resolution issue. When dist/\nis missing they fall back to tsx, which fails on code-chunk's exports.\n\nAdding pnpm run build ensures dist/ is available, letting:\n- e2e tests use dist/index.js (no code-chunk issue)\n- entry-routing.test.ts dist tests run (not skip)",
          "is_bot": false,
          "headline": "ci: build dist/ before running tests (fix e2e code-chunk + dist routing)",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T10:52:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d668757b6f3af96a528cef922cb1db92b7e0995",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove unused stdout variable in entry-routing test",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T10:46:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20385a34e6ca553c8f0140a010b9cc64ccbd52e9",
          "body": "- Add KNOWN_SUBCOMMANDS sync test (source parsing) to detect drift between index.ts and cli-main.ts\n- Add tsx routing tests for known subcommands (skills, status) — verify they are not rejected as unknown\n- Add dist routing tests (status, ingest --help) — exercise full dynamic import path with compiled JS\n- Dual strategy: tsx tests cover routing decisions, dist tests cover full execution",
          "is_bot": false,
          "headline": "test(entry-routing): expand coverage from 4 to 8 tests",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T10:45:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55614e6d8b527932e5ff4619c9d62051021b38d3",
          "body": "The package name is @damoqiongqiu/mcp-local-rag (scoped). npm install\nextracts it to node_modules/@damoqiongqiu/mcp-local-rag/, but the smoke\ntest was looking at node_modules/mcp-local-rag/ (non-scoped path).",
          "is_bot": false,
          "headline": "fix: smoke test lookup path for scoped package name",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T10:35:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6501dda8e6a2e497a88f8b98ef4aaf90dba1f516",
          "body": "…ompatibility\n\n- Refactor src/index.ts to use await import() for cli-main and server-main,\n  preventing tsx from eagerly resolving code-chunk's exports field shape.\n- Inline KNOWN_SUBCOMMANDS set to avoid static import of SUBCOMMANDS.\n- Fix CI smoke test tarball glob: mcp-local-rag-*.tgz → damoqiong\n[…]\nckage name prefix).\n- Bump tsx ^4.22.4 → ^4.23.0.\n- Bump server version 0.18.6 → 0.18.7, add find_definition + find_references tools.\n- E2E test prefers compiled dist/index.js over tsx when available.",
          "is_bot": false,
          "headline": "fix: use dynamic import for cli-main/server-main to avoid tsx ESM inc…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T10:31:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "578b98b6da2eb54ac7e264fb2aeb2651a7fefeca",
          "body": "src/embedder/index.ts imports ProxyAgent/setGlobalDispatcher from 'undici'\nbut it was only available as a transitive dependency. CI builds with\npnpm --frozen-lockfile + @types/node@26 fail with TS2307 because Node 26\ntypes don't include the built-in undici module declarations.\n\nAlso add _tmp_* to .gitignore to prevent git-hook temp file noise.",
          "is_bot": false,
          "headline": "fix: add undici as direct dependency (CI type-check failure)",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T09:38:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d3ca2c17b4ab1f289772dd4993d7bddf93a493f",
          "body": "Unit test for embedder device error handling:\n- Invalid device name → EmbeddingError with original transformers.js message\n- No speculative cache/network guidance injected into init failures\n- Lazy-init path also surfaces device errors correctly\n\nUses vi.doMock + dynamic import for isolate:false compatibility.",
          "is_bot": false,
          "headline": "test: add embedder device validation unit test",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T09:30:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f46d405c148076339d238188b48aeb192407d52",
          "body": "…d_references)\n\n### Added\n- `find_definition` MCP tool: AST-level symbol definition lookup via codeMeta entities/scope\n- `find_references` MCP tool: two-phase reference search (import scan + FTS text search)\n- `codeMeta` end-to-end pipeline: CodeChunker -> VectorChunk -> LanceDB -> SearchResult\n- La\n[…]\n)` and `VectorStore.findTextReferences()`\n\n### Fixed\n- `toSearchResult()` and `toVectorChunk()` missing codeMeta deserialization\n  (LanceDB stores JSON string, parsers must call parseCodeMeta on read)",
          "is_bot": false,
          "headline": "release: v0.18.7 — AST-level code intelligence (find_definition + fin…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T09:27:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c8fbb1494b9a159d66118ebee8830f04e0bb712",
          "body": "- src/utils/gitignore.ts: 新增 stopAbove? 参数,向上遍历到 stopAbove 即停\n- src/server/index.ts: handleListFiles/handleIngestDirectory 传入 stopAbove='baseDir'\n- src/cli/file-collection.ts: CLI ingest 路径传入 stopAbove\n- src/cli/list.ts: CLI list 路径传入 stopAbove\n- 向后兼容:不传 stopAbove 时行为不变\n- 附带修复: S-001 镜像链 URL 过滤 (3 域名)、TS 类型断言、Biome format\n\n验证: AC-007 15/15 ✅ | S-001 10/10 ✅",
          "is_bot": false,
          "headline": "fix: loadGitignore stopAbove 参数完整修复 + S-001 安全测试 + TS/Biome 修复",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-12T08:49:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ae4de3ee23fa6f8761c3608d390ccf112b060bc",
          "body": null,
          "is_bot": false,
          "headline": "docs: add Chinese README",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T14:57:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b47e0b7d1a3936ebc9a5fba75253b8a924426e85",
          "body": null,
          "is_bot": false,
          "headline": "chore: revert to 0.18.6 (matches npm)",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T14:50:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d33f90e0992c6475a6f07acc1f10d0f4b636d35",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.18.7",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T14:48:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f6d09707d744a16b0ba59889f255b08ac6aa1e5",
          "body": "- Update server.json: sync version to 0.18.6, add missing tools (ingest_directory,\n  reindex_stale, reindex_all, config, export_index, dedup_check), add env vars\n  (RAG_WATCH, HTTPS_PROXY, HTTP_PROXY), shorten description to meet 100-char limit\n- Add GitHub Actions workflow: publish-mcp-registry.yml with OIDC auth,\n  triggered on v* tags or manual dispatch",
          "is_bot": false,
          "headline": "chore: add MCP Registry publishing workflow",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T14:47:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e04def03fcd2cdf058d105f82a770ac28d0e0ab7",
          "body": null,
          "is_bot": false,
          "headline": "docs: add CHANGELOG entries for v0.18.0 through v0.18.6",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T13:35:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b51d31f65bafae5fe518d0d1efdd391b611abc6",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.18.6",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T11:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "224de69b524a1e48f850e3732b3456ee9a460381",
          "body": "- setup SKILL.md: 重写「国内网络注意事项」章节\n  - 代理优先推荐(HTTPS_PROXY + setGlobalDispatcher)\n  - 三级镜像链说明(huggingface.co → hf-mirror.com → modelscope.cn)\n  - 清晰的日志输出示例\n- README.md: 修正过时描述\n  - 代理说明升级到 v0.18.5(全局生效)\n  - hf-mirror.com 'redirect-only' → 三级镜像回退\n  - env 变量表: HTTPS_PROXY 版本号 + HF_AUTO_MIRROR 三级链",
          "is_bot": false,
          "headline": "docs: v0.18.5 代理与镜像链使用说明更新",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T11:14:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49360bd29548e8785e1c587aa9a966116519cf3b",
          "body": "Bug #1: fallback 路径中 env.fetch 被置为 undefined\n  - setGlobalDispatcher 后 env.fetch 默认即为代理化全局 fetch\n  - 非 ModelScope fallback 时不应重置为 undefined\n  - 修复: fallback 时重置为 fetch(全局代理化)而非 undefined\n\nBug #2: remotePathTemplate 中多余的 {file} 占位符\n  - @huggingface/transformers v3 默认模板不包含 {file}\n  - MIRROR_CHAIN 写了 {model}/resolve/{revision}/{file}\n  - 导致 URL 中出现字面量 '{file}',如 .../main/{file}/config.json\n  - 修复: 全局替换为 {model}/resolve/{revision}/",
          "is_bot": false,
          "headline": "fix: v0.18.5 - 修复代理下载的两个回归 bug",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T11:10:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c89dd391f7cbb4832d7f638b1f12dfe44a2a49b9",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.18.4",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T10:43:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d258e455626e72b95cfa4643ded328625b577a6",
          "body": "Transformers.js prepends / to {file} values (e.g. /config.json), producing\nFilePath=/config.json in the pathTemplate URL. ModelScope's repo API requires\nFilePath=config.json (no leading slash).\n\nFix:\n- probeApiEndpoint: use GET instead of HEAD for ModelScope (HEAD returns 404),\n  and apply the same \n[…]\npplied in both the initial setup and the\n  mirror fallback path\n\nVerified: Full chain works — huggingface.co → hf-mirror.com → modelscope.cn\nModel downloaded successfully, 384-dim embeddings produced.",
          "is_bot": false,
          "headline": "fix: ModelScope URL fixup — strip leading / from FilePath parameter",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T10:40:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "95578bcd5aa69d00a91b982f2c7c36afc45b7950",
          "body": "Problem: hf-mirror.com Hub API is broken for Chinese users, and\nthere is no further fallback. Users must manually discover and\nconfigure an alternative mirror.\n\nSolution: Add ModelScope.cn as the third mirror in the chain.\nModelScope uses a different URL structure (API-based, not HF Hub\ncompatible),\n[…]\n+ 3-mirror\nchain tests. All existing tests pass without modification.\n\nVerified: ModelScope hosts Xenova/all-MiniLM-L6-v2 with full ONNX\nweights (90MB model.onnx, 23MB quantized, +fp16/int8 variants).",
          "is_bot": false,
          "headline": "feat: v0.18.4 — ModelScope.cn mirror fallback + MirrorConfig refactor",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T10:34:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5af84b0045d33fd6a40bd21e0ce1c1f60b5162d",
          "body": "Problem: hf-mirror.com only mirrors file downloads (/resolve/main/) but\nnot the Hub API (/api/models/). Transformers.js requires the API to list\nmodel files before downloading — this caused opaque download failures.\n\nSolution:\n- Added probeApiEndpoint() to detect whether a mirror supports the full A\n[…]\nsts: 5 new test cases for probeApiEndpoint in connectivity.test.ts\nAll 16 connectivity unit tests pass. Integration/E2E failures are\npre-existing — caused by the very network issue this fix diagnoses.",
          "is_bot": false,
          "headline": "feat: v0.18.3 — HF mirror API completeness probe + targeted diagnostic",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T10:22:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a32eb7262bbd02aa4489b298fde336944aaf071c",
          "body": "#1 connectivity.ts — MIRROR_CHAIN + probeEndpoint(3s HEAD) + resolveEndpoint()\n#2 embedder/index.ts — initialize() rewritten: pre-flight probe → auto-switch → pipeline(); download failure retry with mirror\n#3 server-main.ts — HF_AUTO_MIRROR env var parsing\n#4 server/types.ts — autoMirror config fiel\n[…]\nection section\n\nDesign: three-layer fallback (probe → auto-switch → retry), zero-config for 90% of users. HF_ENDPOINT explicit override disables auto-detect. HF_AUTO_MIRROR=false disables auto-detect.",
          "is_bot": false,
          "headline": "feat: v0.18.2 — HF mirror auto-detection with fallback chain",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T10:01:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47edea7417113d3cd2c8344633deb34584a2ca55",
          "body": "… guide\n\n#1 Model registry (src/embedder/model-registry.ts) — known models whitelist + alias, lookup & validation, dynamic size hint\n#2 embedder/index.ts — dynamic model size log replaces hardcoded '~90MB'\n#3 CLI options.ts — resolveModel for alias expansion, advisory warning for unknown models\n#4 s\n[…]\nmetadata in config/status, alias resolution\n#6 parser/index.ts — .dart added to TEXT_CODE_EXTENSIONS (56 extensions now)\n#7 README.md — WorkBuddy config JSON example + ⚠️ trust button reminder (CN/EN)",
          "is_bot": false,
          "headline": "feat: v0.18.1 — model registry, .dart support, README WorkBuddy trust…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T09:44:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fec12eb8b3e454f8415fd8bae079efa294571f9f",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.18.0",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T08:16:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa2f94588d2c150ed33b18ce09659516ca7e9f7f",
          "body": "… embedder fetch",
          "is_bot": false,
          "headline": "fix: lint — template literal in gitignore.ts, explicit Record type in…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T08:15:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2e27f2eea3126d2712d5d026a3f74836f11b5b0",
          "body": "…ights, status+, watch, config, dedup, time filter, export, model hot-switch\n\n#1 .gitignore auto-respect — walk up and apply .gitignore patterns to both list_files and ingest_directory scans\n#2 reindex_all — new handler that traverses all indexed files and re-ingests them\n#3 Search highlight — build\n[…]\n Time range filter — buildTimePredicate WHERE clause on timestamp column\n#10 export_index — full index export to JSON\n#11 Multi-model hot-switch — config modelName param triggers dispose+init Embedder",
          "is_bot": false,
          "headline": "feat: v0.18.0 — 11 enhancements: gitignore, reindex_all, search highl…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T08:14:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71d75d27bb62306a8101e89a25fa0e755e6e3321",
          "body": "…arcel-cache, .svelte-kit, bower_components, coverage, .nyc_output, .terraform, .serverless\n\nCross-language coverage:\n- Java/Kotlin/Rust: target (Maven/Gradle/Cargo)\n- PHP/Go: vendor (Composer/vendoring)\n- Gradle: .gradle\n- Ruby: .bundle\n- Parcel: .parcel-cache\n- SvelteKit: .svelte-kit\n- Legacy: bower_components\n- General: coverage, .nyc_output, .terraform, .serverless",
          "is_bot": false,
          "headline": "fix: expand SKIP_DIR_NAMES — add target, vendor, .gradle, .bundle, .p…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T06:40:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c92becfa6c8c84a24781f6a93e0a123cb6220cf3",
          "body": "… list_files\n\nNew MCP tools:\n- ingest_directory: batch ingestion with extension filter, recursive support\n- reindex_stale: auto-detect modified files and re-index only changed ones\n\nEnhancements:\n- list_files now compares file mtime against index timestamp, marks stale\n- FileEntry type gains optional stale: boolean field\n- Extracted ingestFileCore() for reuse across ingest_file/ingest_directory/data",
          "is_bot": false,
          "headline": "feat: v0.17.0 — ingest_directory + reindex_stale + stale detection in…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T06:22:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8b4597c758765df6efb9469f991fd455a3d65a3",
          "body": "…es, add CHANGELOG",
          "is_bot": false,
          "headline": "docs: v0.16.4 — expand README with proxy/troubleshooting/rebuild guid…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T05:26:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d66611bef440e221d844299e10117e964740a0a2",
          "body": null,
          "is_bot": false,
          "headline": "0.16.3",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T05:04:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "538c65434c0c078d9ee4d516d1cb6a7806b7c400",
          "body": "Node.js built-in fetch (undici) does NOT respect HTTP_PROXY/HTTPS_PROXY\nenv vars. This change creates a ProxyAgent-aware fetch function when\nHTTPS_PROXY or HTTP_PROXY is set, and passes it to @huggingface/transformers\nvia env.fetch, enabling model downloads through HTTP/HTTPS proxies.",
          "is_bot": false,
          "headline": "feat: proxy-aware fetch via undici ProxyAgent for HTTPS_PROXY/HTTP_PROXY",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T05:03:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a115f7791e792b630afecc1e0731c260f4ff796",
          "body": null,
          "is_bot": false,
          "headline": "0.16.2",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T04:47:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "705a3b96aabcf7529c9aee0510766811059ba893",
          "body": null,
          "is_bot": false,
          "headline": "0.16.1",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T04:44:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d3b5d227b94181a5a4420110bb6620884289fcb",
          "body": null,
          "is_bot": false,
          "headline": "feat: add HF_ENDPOINT/remoteHost support for mirror downloads",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T04:44:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6cb08816bc9e567a8bf9587298c12fc91361c13d",
          "body": "…lback\n\n- Add category, platforms, author, permissions to main SKILL.md\n- Trim description to <300 chars for SkillHub compliance\n- Add frontmatter to all sub-module SKILL.md files\n- Generate 512x512 icon (magnifying glass + code brackets + circuit)\n- Create SKILL.flat.md as single-file fallback (no sub_skills)\n- Ready for skillhub.cn submission",
          "is_bot": false,
          "headline": "feat: complete SkillHub submission prep — frontmatter, icon, flat fal…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T04:12:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82d4b55538a516969646f5249c61ae2b6916ebb9",
          "body": "- README: add fork badge linking to shinpr/mcp-local-rag original\n- LICENSE: append Copyright (c) 2026 damoqiongqiu",
          "is_bot": false,
          "headline": "docs: add fork attribution & copyright for MIT compliance",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T03:48:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb6dfc1f715667803358831ef3c95d2f4a8baedb",
          "body": "- Update package.json: name, repository, mcpName, publishConfig\n- Update server.json: name, vendor, repo URL, tags, identifier\n- Update README: shields, npx commands, config snippets, clone URL\n- Update Skill docs: setup, manage, cli-reference npx commands\n- Update source: CLI help text, install-skills references\n- Update CONTRIBUTING.md and AGENTS.md",
          "is_bot": false,
          "headline": "chore: rename to @damoqiongqiu/mcp-local-rag",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T03:45:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc544dd6dc3b0b2b13bd9bb9650b73d9e1a026fd",
          "body": null,
          "is_bot": false,
          "headline": "chore: add package-lock.json to gitignore",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T03:40:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6a413e7911c0772c22aeaa4b6219f770e2a8266",
          "body": "- Reframe project tagline from document KB to code intelligence\n- Reorder features: code chunking first, then document parsing\n- Add code search trigger words (搜函数, 搜类, 搜 API, etc.)\n- Set code-friendly defaults (RAG_HYBRID_WEIGHT: 0.7)\n- Add Sourcegraph-alternative positioning keywords\n- Skill modules: code search examples prioritized",
          "is_bot": false,
          "headline": "docs: reposition as code intelligence engine for AI coding assistants",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T03:39:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bbd156b954b5f24cbddc651171cd94c8258e3c8",
          "body": "- Every section now shows Chinese first, then English\n- Deleted README.zh-CN.md (redundant after merge)\n- GitHub renders this natively — no language switching needed\n- Net reduction: 656 lines (2 files → 1 file)",
          "is_bot": false,
          "headline": "docs: merge README.zh-CN.md into README.md as bilingual (中文/English)",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T03:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec0c09635de28be1bced2965538c149b59a54624",
          "body": "…nges\n\n- Supported formats: PDF/DOCX/TXT/MD → + HTML + 50+ code file types (TS/JS/Py/Go/...)\n- Chunking strategy: single SemanticChunker → dual-mode (semantic + AST code chunking)\n- Project structure: parser supports code files as UTF-8 text, chunker includes CodeChunker\n- FAQ updated with full format list\n- parseTxt references zeroed across all docs (→ parseContent)\n- overview.md updated to reflect current implementation state",
          "is_bot": false,
          "headline": "docs: sync README/CONTRIBUTING/AGENTS with code chunking & parser cha…",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T03:16:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "881ffbda218ae8a930b80d566a7a16a72d4290a2",
          "body": "## Code Chunking (parse → chunk → embed pipeline)\n\n- Add code-chunk (tree-sitter) dependency for AST-level semantic chunking\n- New CodeChunker class (src/chunker/code-chunker.ts) implementing ChunkerInterface\n- ChunkerInterface abstraction decouples SemanticChunker from embedder pipeline\n- textForEm\n[…]\nnage/setup + references/\n- Chinese trigger phrases in frontmatter descriptions\n- New setup/SKILL.md: model download, HF_ENDPOINT, China network FAQ\n- Code file support documented in ingest tool tables",
          "is_bot": false,
          "headline": "feat: AST-level code chunking + skill docs restructure",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T03:11:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c4d570fb9eed5d4ffc1f33e6f6a4ecddda38321",
          "body": "完整翻译 README.md 为中文,涵盖全部章节:特性、使用方式、配置、故障排查、FAQ、开发指南等,保留所有代码示例和链接。",
          "is_bot": false,
          "headline": "docs: add Chinese README (README.zh-CN.md)",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T02:24:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c6304d37379c8f29ad5eaaceb9e96d7b87665c7",
          "body": "- .gitignore: exclude .workbuddy/ directory from version control\n- AGENTS.md: 添加 AI Agent 开发指南(中文版),涵盖项目架构、代码规范、\n  错误处理模式、测试策略(vi.doMock 规则)、PR 检查清单等",
          "is_bot": false,
          "headline": "chore: add .workbuddy/ to gitignore, add AGENTS.md",
          "author_name": "大漠穷秋",
          "author_login": "damoqiongqiu",
          "committed_at": "2026-07-11T02:24:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 6,
      "commits_last_year": 636,
      "latest_release_at": "2026-07-11T13:40:11Z",
      "latest_release_tag": "v0.18.5",
      "releases_from_tags": false,
      "days_since_last_push": 9,
      "active_weeks_last_year": 31,
      "days_since_latest_release": 22,
      "mean_days_between_releases": 0
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@damoqiongqiu/mcp-local-rag",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "typescript",
            "mcp",
            "mcp-server",
            "model-context-protocol",
            "rag",
            "vector-search",
            "semantic-search",
            "embeddings",
            "lancedb",
            "transformers",
            "huggingface",
            "local-ai",
            "offline",
            "privacy",
            "code-search",
            "code-intelligence",
            "sourcegraph-alternative",
            "developer-tools",
            "claude-code",
            "cursor",
            "codex",
            "skills"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@damoqiongqiu/mcp-local-rag",
          "is_deprecated": false,
          "latest_version": "0.21.0",
          "repository_url": "https://github.com/damoqiongqiu/mcp-local-rag",
          "versions_count": 25,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 4305,
          "first_published_at": "2026-07-11T04:00:23.156000Z",
          "latest_published_at": "2026-07-23T15:20:50.960000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 13,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 74957,
      "source_files_sampled": 162,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 8740
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "adm-zip",
            "direct": false,
            "version": "0.5.18",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-xcpc-8h2w-3j85"
            ],
            "fixed_version": "0.6.0",
            "advisory_count": 1,
            "oldest_advisory_days": 22
          },
          {
            "name": "sharp",
            "direct": false,
            "version": "0.33.5",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.3,
            "advisory_ids": [
              "GHSA-f88m-g3jw-g9cj"
            ],
            "fixed_version": "0.35.0",
            "advisory_count": 1,
            "oldest_advisory_days": 11
          },
          {
            "name": "sharp",
            "direct": false,
            "version": "0.34.5",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.3,
            "advisory_ids": [
              "GHSA-f88m-g3jw-g9cj"
            ],
            "fixed_version": "0.35.0",
            "advisory_count": 1,
            "oldest_advisory_days": 11
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 3
        },
        "advisory_count": 3,
        "affected_count": 3,
        "assessed_count": 333,
        "malicious_count": 0,
        "assessed_package": "npm:@damoqiongqiu/mcp-local-rag@0.21.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@huggingface/transformers",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.2.0"
        },
        {
          "name": "@lancedb/lancedb",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.31.0"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@mozilla/readability",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "0.6.0"
        },
        {
          "name": "chokidar",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        },
        {
          "name": "code-chunk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.14"
        },
        {
          "name": "ignore",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.5"
        },
        {
          "name": "jsdom",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^29.1.1"
        },
        {
          "name": "mammoth",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.12.0"
        },
        {
          "name": "minimatch",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.2.5"
        },
        {
          "name": "mupdf",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.28.0"
        },
        {
          "name": "turndown",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "7.2.4"
        },
        {
          "name": "undici",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.28.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "shinpr",
          "commits": 486,
          "avatar_url": "https://avatars.githubusercontent.com/u/52246947?v=4"
        },
        {
          "type": "User",
          "login": "damoqiongqiu",
          "commits": 99,
          "avatar_url": "https://avatars.githubusercontent.com/u/1829010?v=4"
        },
        {
          "type": "User",
          "login": "mickey-mikey",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/149929346?v=4"
        },
        {
          "type": "User",
          "login": "jarrah31",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/3072303?v=4"
        },
        {
          "type": "User",
          "login": "dburner",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/2664398?v=4"
        },
        {
          "type": "User",
          "login": "rudi193-cmd",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/236912655?v=4"
        },
        {
          "type": "User",
          "login": "lumi202507",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/220155073?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.786
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "publish-mcp-registry.yml",
        "publish-npm.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3e94e45f842ed9a9119fcd90469f02b78c951a7b",
        "ran_at": "2026-08-02T14:19:20Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T15:21:26Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/damoqiongqiu/mcp-local-rag",
    "host": "github.com",
    "name": "mcp-local-rag",
    "owner": "damoqiongqiu"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 53 is calibrated to 54 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 53,
            "calibrated": 54,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 54,
      "inputs": {
        "security": 46,
        "vitality": 81,
        "community": 31,
        "governance": 46,
        "calibration": "2026-08-02",
        "engineering": 52,
        "ai_readiness": 69,
        "weighted_overall_raw": 53
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 81,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "commits_last_year": 636,
              "human_commit_share": 1,
              "days_since_last_push": 9,
              "active_weeks_last_year": 31
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 9 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "31/52 weeks with commits",
                "points": 21.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 31
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "636 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 636
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 6,
              "latest_release_tag": "v0.18.5",
              "releases_from_tags": false,
              "days_since_latest_release": 22,
              "mean_days_between_releases": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "6 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 22 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 31,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "forks": 0,
              "stars": 13,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "13 stars",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "at_risk",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "readme_badges": null,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "packages": [
                "@damoqiongqiu/mcp-local-rag"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 4305
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,305 downloads/month across npm",
                "points": 48.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4305,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "weak",
        "name": "Sustainability & Governance",
        "value": 46,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 29,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.786
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 79% of commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 79
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance, Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance",
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 70,
            "inputs": {
              "followers": 1446,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "damoqiongqiu",
              "public_repos": 33,
              "account_age_days": 5168
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,446 followers of damoqiongqiu",
                "points": 22.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1446,
                      "login": "damoqiongqiu"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "33 public repos, account ~14 yr old",
                "points": 23.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 33
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@damoqiongqiu/mcp-local-rag"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 9
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 9 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "25 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 52,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "critical",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": false,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "weak",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@damoqiongqiu/mcp-local-rag@0.21.0 runtime dependency closure — what installing the published package pulls in — 333 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@damoqiongqiu/mcp-local-rag@0.21.0",
                  "assessed": 333
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 82,
            "inputs": {
              "source": "osv",
              "advisories": 3,
              "affected_packages": 3,
              "assessed_packages": 333,
              "unassessed_packages": 0,
              "affected_by_severity": "high 3",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "3 affected: adm-zip 0.5.18 (high 7.5), sharp 0.33.5 (high 7.3), sharp 0.34.5 (high 7.3)",
                "points": 7.3,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 3,
                      "packages": "adm-zip 0.5.18 (high 7.5), sharp 0.33.5 (high 7.3), sharp 0.34.5 (high 7.3)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 333,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 69,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.96,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 8740
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 74957,
              "source_files_sampled": 162,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/162 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 162,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "mcp-server",
        "library"
      ],
      "scores": {
        "cli": 2,
        "library": 6,
        "mcp-server": 9
      },
      "primary": "mcp-server",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:npm",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "mcp-server",
          "source": "dep:@modelcontextprotocol/sdk",
          "weight": 4
        },
        {
          "tier": "structure",
          "label": "mcp-server",
          "source": "mcp_signal",
          "weight": 3
        },
        {
          "tier": "description",
          "label": "cli",
          "source": "description:cli",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-server",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Community profile unavailable",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-02T14:19:27.848753Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/damoqiongqiu/mcp-local-rag.svg",
  "full_name": "damoqiongqiu/mcp-local-rag",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v2.3.1, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.