Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-24 14:53 UTC

Hei33enberg / mosADD-OS

mosADD — open MCP toolkit for AI-agent comms. End-to-end encrypted 1:1 DMs (X3DH + Double Ratchet), channels, mail, push-to-talk, knowledge, on-device threat classification. 65 MCP tools. Apache-2.0.

TypeScriptApache-2.0★ 1 estrella⑂ 0 forksdesde may 2026Ver en GitHub ↗

Hei33enberg/mosADD-OS tiene un índice de salud de 59 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Engineering Quality (81/100) y la más baja, Sustainability & Governance (43/100). Se actualizó por última vez hace 1 día. Una sola persona concentra la mayor parte del trabajo reciente.

59
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

59
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

hiddenSOCIETY™Cuenta personal
37 seguidores9 repositorios públicosdesde mar 2025RAi Inc.

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
npm@mosadd/ai3.0.0-alpha.2610377hace 27 días
npm@mosadd/mcp3.0.0-alpha.32272831hace 5 díasmosaddmcpmodel-context-protocolagentclaudecursoranthropiccommunicationmessaging
npm@mosadd/core3.0.0-alpha.2613136hace 27 días
npm@mosadd/agent3.0.0-alpha.01862hace 23 díasmosaddagentai-agentcommunicationmessagingclaudeopenrouter
npm@mosadd/crypto3.0.0-alpha.2612816hace 27 díasmosaddcryptoe2ex3dhdouble-ratchetsignal-protocol
npm@mosadd/bridges3.0.0-alpha.269488hace 27 días
npm@mosadd/protocol3.0.0-alpha.2613626hace 27 díasmosaddprotocolzodschemacodec
npm@mosadd/providers3.0.0-alpha.2612306hace 27 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

72Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 1 días
6.2/36Cadencia de commits — 9/52 semanas con commits
18/18Volumen de commits — 352 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year352
human_commit_share1
days_since_last_push1
active_weeks_last_year9
Cómo se puntúa
27/27Publica versiones — 15 versiones publicadas
36/36Recencia de las versiones — última versión hace 2 días
27/27Cadencia de publicación — una versión cada ~1,1 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count15
latest_release_tagv0.2.12
releases_from_tagsno
days_since_latest_release2
mean_days_between_releases1,1

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

49En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 1 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_template
Cómo se puntúa
53.4/80Descargas mensuales — 10.085 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packages@mosadd/ai, @mosadd/mcp, @mosadd/core, @mosadd/agent, @mosadd/crypto, @mosadd/bridges, @mosadd/protocol, @mosadd/providers
dependents
ecosystemsnpm
total_downloads
monthly_downloads10.085
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

43En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — 0% de issues cerradas
37/38.3Aceptación de PR — 29/30 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs29
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs1
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
11.4/25Alcance del propietario — 37 seguidores de Hei33enberg
10.1/25Trayectoria — 9 repos públicos, cuenta de ~1 años
Datos de entrada utilizados
followers37
owner_typeUser
is_verified
owner_loginHei33enberg
public_repos9
account_age_days508
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 8 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 31 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packages@mosadd/ai, @mosadd/mcp, @mosadd/core, @mosadd/agent, @mosadd/crypto, @mosadd/bridges, @mosadd/protocol, @mosadd/providers
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

81Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 16 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
6.4/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfig
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

100Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://mosadd.com
10/10Descripción del repositorio
10/10Topics — 13 topics
10/10Wiki
Datos de entrada utilizados
topicsagents, ai-agents, anthropic, claude, cursor, e2ee, end-to-end-encryption, mcp, mcp-server, messaging, model-context-protocol, open-source, typescript
has_wiki
homepagehttps://mosadd.com
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

46En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool detected: CodeQL
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 45 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3,5
Excluidos de la puntuación (sin datos o no aplicable): ci_tests. Los pesos restantes se han renormalizado.
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
13.2/25Dependencias indirectas libres de avisos conocidos — 1 afectados: @hono/node-server 1.19.14 (moderate 5.9)
40/40Sin avisos pendientes — ningún aviso lleva público más de 90 días
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages113
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Se cotejó el cierre de dependencias en tiempo de ejecución de npm:@mosadd/ai@3.0.0-alpha.26 —lo que arrastra la instalación del paquete publicado—: 113 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

75Bueno · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — AGENTS.md
15/15Documentación legible por máquinas (llms.txt) — llms.txt presente
40/40Historial de commits legible — 97 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txt
legible_history_share0,97
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes3526
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — apps/channel0-ext/tsconfig.json, apps/dev/tsconfig.json, apps/edge/tsconfig.json, apps/embed/tsconfig.json, apps/hub/tsconfig.json, apps/mcp-http/tsconfig.json, apps/murl-www/tsconfig.json, examples/anthropic/tsconfig.json, examples/langchain/tsconfig.json, examples/vercel-ai/tsconfig.json, packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/bridges/tsconfig.json, packages/core/tsconfig.json, packages/crypto/tsconfig.json, packages/mcp/tsconfig.json, packages/protocol/tsconfig.json, packages/providers/tsconfig.json, packages/skins/tsconfig.json, packages/threat-engine/tsconfig.json
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 92 de los últimos 100 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json, pnpm-lock.yaml
has_dockerfileno
typed_language
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configsapps/channel0-ext/tsconfig.json, apps/dev/tsconfig.json, apps/edge/tsconfig.json, apps/embed/tsconfig.json, apps/hub/tsconfig.json, apps/mcp-http/tsconfig.json, apps/murl-www/tsconfig.json, examples/anthropic/tsconfig.json, examples/langchain/tsconfig.json, examples/vercel-ai/tsconfig.json, packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/bridges/tsconfig.json, packages/core/tsconfig.json, packages/crypto/tsconfig.json, packages/mcp/tsconfig.json, packages/protocol/tsconfig.json, packages/providers/tsconfig.json, packages/skins/tsconfig.json, packages/threat-engine/tsconfig.json
agent_commit_share0,92
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
55/55Tamaños de archivo manejables — 0/302 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes41.666
source_files_sampled302
oversized_source_files0
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signal
api_schema_files

Datos clave

1estrellas de GitHub
1contribuidores
352commits en los últimos 12 meses
1días desde el último push
15versiones publicadas
1factor bus
1issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 3.5 / 10
3.5agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-24 14:53 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool detected: CodeQL
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities45 existing vulnerabilities detected
Dependencias directas 35
RegistroPaqueteRestricción de versiónManifiesto
npm@supabase/supabase-js^2.106.2apps/dev/package.json
npm@vercel/analytics^2.0.1apps/dev/package.json
npmnext^15.1.6apps/dev/package.json
npmposthog-js^1.176.0apps/dev/package.json
npmreact^19.0.0apps/dev/package.json
npmreact-dom^19.0.0apps/dev/package.json
npm@supabase/ssr^0.5.2apps/hub/package.json
npm@supabase/supabase-js^2.49.4apps/hub/package.json
npm@vercel/analytics^2.0.1apps/hub/package.json
npmnext^15.2.4apps/hub/package.json
npmreact^19.0.0apps/hub/package.json
npmreact-dom^19.0.0apps/hub/package.json
npm@modelcontextprotocol/sdk^1.0.4apps/mcp-http/package.json
npm@mosadd/mcp3.0.0-alpha.23apps/mcp-http/package.json
npm@vercel/analytics^2.0.1apps/murl-www/package.json
npmnext^15.1.6apps/murl-www/package.json
npmposthog-js^1.176.0apps/murl-www/package.json
npmreact^19.0.0apps/murl-www/package.json
npmreact-dom^19.0.0apps/murl-www/package.json
npm@mosadd/mcpworkspace:*packages/agent/package.json
npm@mosadd/mcpworkspace:*packages/ai/package.json
npm@mosadd/coreworkspace:*packages/bridges/package.json
npm@mosadd/protocolworkspace:*packages/core/package.json
npm@noble/ciphers^2.1.1packages/crypto/package.json
npm@noble/curves^2.0.1packages/crypto/package.json
npm@noble/hashes^2.0.1packages/crypto/package.json
npm@modelcontextprotocol/sdk^1.0.4packages/mcp/package.json
npm@mosadd/cryptoworkspace:*packages/mcp/package.json
npm@mosadd/protocolworkspace:*packages/mcp/package.json
npm@mosadd/providersworkspace:*packages/mcp/package.json
npm@mosadd/threat-engineworkspace:*packages/mcp/package.json
npm@supabase/supabase-js^2.48.0packages/mcp/package.json
npmzod^4.3.6packages/mcp/package.json
npmzod^4.3.6packages/protocol/package.json
npm@mosadd/coreworkspace:*packages/providers/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Avisos de dependencias 1

Instalar npm:@mosadd/ai@3.0.0-alpha.26 arrastra 113 paquetes, directos y transitivos: 1 tienen avisos conocidos, de los cuales 0 son dependencias directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
@hono/node-server1.19.14indirectamoderada12.0.5

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "agents",
        "ai-agents",
        "anthropic",
        "claude",
        "cursor",
        "e2ee",
        "end-to-end-encryption",
        "mcp",
        "mcp-server",
        "messaging",
        "model-context-protocol",
        "open-source",
        "typescript"
      ],
      "is_fork": false,
      "size_kb": 14066,
      "has_wiki": true,
      "homepage": "https://mosadd.com",
      "languages": {
        "CSS": 46841,
        "PHP": 21806,
        "HTML": 32417,
        "Shell": 3800,
        "JavaScript": 31796,
        "TypeScript": 1214414
      },
      "pushed_at": "2026-07-23T02:51:31Z",
      "created_at": "2026-05-27T01:38:50Z",
      "owner_type": "User",
      "updated_at": "2026-07-23T02:51:34Z",
      "description": "mosADD — open MCP toolkit for AI-agent comms. End-to-end encrypted 1:1 DMs (X3DH + Double Ratchet), channels, mail, push-to-talk, knowledge, on-device threat classification. 65 MCP tools. Apache-2.0.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "mosADD.com",
      "name": "hiddenSOCIETY™",
      "type": "User",
      "login": "Hei33enberg",
      "company": "RAi Inc.",
      "location": "Casablanca",
      "followers": 37,
      "avatar_url": "https://avatars.githubusercontent.com/u/201495027?v=4",
      "created_at": "2025-03-02T20:05:20Z",
      "is_verified": null,
      "public_repos": 9,
      "account_age_days": 508
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.2.12",
          "kind": "patch",
          "published_at": "2026-07-21T17:23:47Z"
        },
        {
          "tag": "v0.2.11",
          "kind": "patch",
          "published_at": "2026-07-20T23:32:05Z"
        },
        {
          "tag": "v0.2.10",
          "kind": "patch",
          "published_at": "2026-07-20T04:33:48Z"
        },
        {
          "tag": "v0.2.9",
          "kind": "patch",
          "published_at": "2026-07-16T17:31:05Z"
        },
        {
          "tag": "v0.2.8",
          "kind": "patch",
          "published_at": "2026-07-16T16:38:58Z"
        },
        {
          "tag": "v0.2.6",
          "kind": "patch",
          "published_at": "2026-07-15T15:51:53Z"
        },
        {
          "tag": "v0.2.5",
          "kind": "patch",
          "published_at": "2026-07-14T07:30:21Z"
        },
        {
          "tag": "v0.2.4",
          "kind": "patch",
          "published_at": "2026-07-14T03:50:36Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2026-07-12T06:58:17Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-07-12T06:13:05Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-07-11T02:52:18Z"
        },
        {
          "tag": "desktop-v0.2.0",
          "kind": "other",
          "published_at": "2026-07-03T23:23:02Z"
        },
        {
          "tag": "v3.0.0-alpha.20",
          "kind": "prerelease",
          "published_at": "2026-06-20T23:58:56Z"
        },
        {
          "tag": "v3.0.0-alpha.2",
          "kind": "prerelease",
          "published_at": "2026-05-31T21:08:41Z"
        },
        {
          "tag": "v3.0.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-27T22:01:06Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9d2a3d9a6e2e6e1c1dafec4c75d28422ad222bcb",
          "body": "… decision release\n\nREADME gains the decision protocol (agent asks the human to choose, continues from the\nanswer) and a systemd always-on guide (VPS / Raspberry Pi). Version bump so the CI\n\"Publish to npm\" run ships the decision-capable @mosadd/agent under the alpha tag.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agent): decisions + always-on deploy; bump 3.0.0-alpha.1 for the…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-23T02:51:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a6d597b29479c8832274acdeca1c895e1a92b499",
          "body": "… (T12-2.1)\n\nThe published @mosadd/agent (what `npx @mosadd/agent start` runs on a buyer's VPS/\ndesktop/Pi) was DM-only; the dev-repo responder had decisions, this didn't. Ported\nthe same contract so the sellable artifact reaches full parity with the internal agent:\n\n- src/decisionProtocol.ts: the a\n[…]\nn_responses\n  and continuing from the human's choice. Falls back to the existing text reply.\n\ntsc --noEmit clean; tsup build (esm + dts) clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(agent): decision protocol in the sellable package — emit + react…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-23T02:09:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "629585f05be1e139053b0c561dc77f4755b0ba1a",
          "body": "…over the hero\n\nFounder: on mosadd.dev the mobile menu (Build/The Realm/Hall of Fame/FAQ) overlapped the\nhero headline \"They're apps. We're the layer.\" It was a narrow (min-width:150px) absolutely-\npositioned box dropped at top:28px over a transparent header, so the wide H1 showed around it\nand read\n[…]\n56px nav bar, with the header going opaque while\nopen — a proper mobile menu overlay. Render-verified @375px: width 375, bg rgb(5,5,6), top 56.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(realm): mobile nav = full-width opaque sheet, not a box floating …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-20T22:54:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5568388cffbfd5587d684fc975f1a0458cffac42",
          "body": "mosadd.dev is being retired, so the embed widget's two hardcoded mosadd.dev links would 404 once\nthe domain dies: the \"powered by mosadd\" badge and the at-capacity queue CTA (\"about upgrading\").\nRepointed both to mosadd.com — badge → https://mosadd.com, queue CTA → https://mosadd.com/pricing\n(verifi\n[…]\nfrom source) and refreshed the tracked static copy at\napps/dev/public/v1.js. Verified zero mosadd.dev; mosadd.com + mosadd.com/pricing present.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(embed): widget links mosadd.dev → mosadd.com (badge + queue CTA)",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-19T07:35:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6262d9eda99d9873187ddeaa508da7692351bff8",
          "body": "… alpha.32 changelog\n\nPre-existing count drift: 69→71 total and mIRC 22→24 (from adding mIRC_discover\n+ mIRC_report) had propagated stale across hub, mcp-http, realm (index/llms/readme),\ndocs/architecture, all 5 registry submissions, roadmap, examples (claude-code/\nhermes/vercel-ai), and the npm pac\n[…]\nANGELOG entry (discover/report/discoverable/caps + posture).\nBuild artifacts (dist/, .next-build/) and frozen CHANGELOG history left untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(mcp): sync all promotion surfaces to 71 tools / mIRC 24 + record…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-19T03:11:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7e50b16eb18c671ac72e6257fb8e3136c35c017",
          "body": "…e) + sync tool counts 69→71 / mIRC 22→24\n\nThe prior sweep marketed mIRC private/password channels as \"end-to-end-encrypt\ntheir text\" unqualified — but per docs/security/e2ee-posture.md that is on the\nFORBIDDEN list for toolkit surfaces: mIRC_post_message posts server-readable\nplaintext base64 (the \n[…]\nRC_report:\napps/dev docs (home, hub, mcp, modules, quickstart, blog, og-image, MobileNav,\nllms.txt) 69→71 and mIRC ×22→×24. honesty-lint green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs): correct mIRC encryption posture (toolkit is server-readabl…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-19T03:04:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "93deda7730d083701938b3ec47fdff9193484abd",
          "body": "…posture (v3.0.0-alpha.32)\n\nSync @mosadd/mcp with the 2026-07-19 mIRC backend + fix the public copy that UNDER-stated channel\nencryption (it's in our favour — we're more encrypted than we claimed).\n\nNew MCP tools (mirc.ts): mIRC_discover (public channel directory — channel-manage 'discover'),\nmIRC_r\n[…]\nblanket claims banned; per-channel nuance is allowed). Version bumped to\n3.0.0-alpha.32 across the 5 lint-checked references; skill-lint clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp+docs): add mIRC directory/report tools + correct encryption …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-19T02:42:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e406921069eb83ff8b0fa83d650964a2e879b5c",
          "body": "…he 2026-07-19 mIRC fixes\n\nPost-mIRC-fix accuracy pass (audit found the tools do NOT over-claim channel-voice E2EE — the\ndangerous direction is clean — but several descriptions were behind the shipped changes):\n\n- threat-model.md (A1, the one real over-claim): mTALK/channel voice was labelled \"DTLS-\n[…]\n\n  assigns any role below their own tier.\n\nDescription-only; tsc clean. NOTE: reaches agents only via an @mosadd/mcp npm publish (owner-gated).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp+docs): mIRC tool descriptions + threat-model accurate after t…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-19T00:07:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "50672f5c3fc6895601803e7dba4b6e61129e0d44",
          "body": "…AR-4574)\n\nThe 1200x630 og.png (real mosADD mark — pyramid gates + green sun) has been committed for a\nwhile, but index.html still shipped the placeholder text card, so social scrapers (X, iMessage,\nSlack, Discord, LinkedIn) fell back to a plain summary with no image. Wire it up:\n- og:image + og:ima\n[…]\nute og.png URL 404s for scrapers. (2) GitHub\nrepo Social-preview image upload (Settings → General) for the REPO share card, separate from this.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(realm): enable og:image + large twitter card on mosADD.dev (LINE…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-18T21:23:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "93576c60fd94e53a7efa084496f36c6153941eca",
          "body": "…ADME)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(brand): mosADD mark header on the Manifesto (consistency with RE…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-18T19:42:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ad1d946c0c364c921a668fa03ebfe16bdc159c1d",
          "body": "…(was placeholder/empty)\n\nFounder: the SAME app mark (pyramid gates + green sun) must be used everywhere — favicon, og,\ndocs, GitHub. Closing the gaps:\n\n- .dev favicon: replaced the placeholder inline \"m\" SVG with the REAL mark — copied favicon.svg\n  + favicon.ico + apple-touch-icon.png from the app\n[…]\no Social preview (Settings → Social preview) is a manual upload — owner action; use\napps/realm/og.png (the card already carries the real mark).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(brand): real mosADD mark everywhere — .dev favicon + README logo …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-18T19:41:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "edcd74dc777239e0b72263af6caad6c4531fd7bf",
          "body": "… placeholder\n\nFounder: the .dev icon must be the SAME as the mosADD.com / app icon everywhere. Replaced\nthe made-up green \"m\" with the actual app icon.\n\n- icon-512.png: exact copy of apps/web/public/pwa-512.png — the mosADD pyramid + green-sun mark\n  (the same icon mosadd.com, the APK and the PWA use).\n- og.png: the same real app-icon mark now composited into the link-preview card (top-right,\n  soft green glow), replacing the placeholder.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(realm): use the REAL mosADD app icon (pyramid + green sun), not a…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-18T19:36:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1db53acf443383e50b62814a242ad198824e4d23",
          "body": "…ards\n\nKey-visuals for the .dev link preview (CEO left the og/twitter image tags off to avoid a\n404 — now the graphics ship, so the tags can be enabled and Slack/X/iMessage show a card).\n\n- og.png 1200x630: brand card — dark #050506 + faint grid + top green glow, \"mosADD.dev\"\n  wordmark (ADD in #00f\n[…]\n inline favicon).\n\nBoth self-contained PNGs served at the site root; the index.html og:image/twitter:image +\nicon tags are the CEO's to enable.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(realm): add og.png (1200x630) + icon-512 for mosADD.dev social c…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-18T19:32:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d91d0034539b7fd8b2f82e08799fc32e79989835",
          "body": "Founder QA batch 2026-07-18. Full multi-lens audit (SEO/AEO + UX/content + design-sync vs\nmosADD.com) → enhancement pass; existing voice, content, and tool math preserved.\n\n- SEO/AEO: canonical, theme-color/color-scheme, full Open Graph + Twitter (text) tags;\n  JSON-LD (Organization, WebSite, Softwa\n[…]\no avoid 404 until shipped).\nValidated: both JSON-LD blocks parse; FAQ schema == visible text; robots/sitemap/llms serve 200;\nno console errors.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(realm/mosadd.dev): SEO/AEO + design-sync overhaul (QA item 4)",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-18T19:13:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2c79e2c610f763535d84a83f67a0e50731382146",
          "body": "The advertised tool count has drifted across surfaces repeatedly (68/69/65/61/70+).\nThis vitest test imports TOOL_COUNT (= allTools.length, the one source of truth) and\nasserts the four hardcoded surfaces match it: server.json, the mosadd.dev Realm hero,\nthe dev /docs/mcp page, and the dev OG image.\n[…]\ne-versa) now fails the build. (The app's LP\nMcpToolReference computes its total dynamically and can't drift; the agent README is\nanother repo.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(ci): anti-drift gate — every doc surface must equal TOOL_COUNT",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T10:33:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5a69c83cdb04f925dfae3af250fbd93ed9f8064b",
          "body": "…ev OG image\n\nserver.json advertised 65; apps/dev OG image 61. Both → 69 (canonical TOOL_COUNT).\nmURL is 7 and embed_create is registered now. Historical CHANGELOG entries left as-is\n(point-in-time records).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs): sync tool count to 69 — server.json registry desc + apps/d…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T09:10:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0d5287d6ec9376549800d763176587b3fcf73940",
          "body": "…ere self-contradicting at 65)\n\nThe hero + build headers already said \"69 tools\" but the per-module cards summed\nto 65 — a page that contradicted itself. Synced to the canonical TOOL_COUNT\nbreakdown (packages/mcp/src/tools/index.ts): mURL 4→7 (owner-side claim/branding/\nlifecycle shipped) and the mTALK·mRAG·comms bundle 12→13 (embed widget + capability\ndiscovery). Cards now = 14+22+7+11+13+2 = 69.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(realm/mosadd.dev): module cards sum to 69, matching the header (w…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T08:53:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "99b4414bc5c80263ce91617b5566e5b070640883",
          "body": "… escaping)\n\nThe shields.io status badge used 3.0.0--alpha.30 (double dash = literal dash in\nshields URLs); the earlier exact-dot bump missed it while skill-lint's flexible regex\ncaught it. Synced to alpha.31.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: sync README badge to alpha.31 (skill-lint, double-dash badge…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T05:40:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "de537310f8c7eeaa51f7e9feb4b8ec339e713451",
          "body": "alpha.30 shipped with mURL_create/update using z.record(z.any()) (Zod v3 form) which\nthis project's Zod v4 rejects — the published package's source was pre-fix. alpha.31\ncarries the corrected z.record(z.string(), z.any()) plus the CI-green fixes. Version\nrefs synced across package.json / server.json / server.ts / marketplace.json.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: @mosadd/mcp 3.0.0-alpha.31 — Zod v4 z.record branding fix",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T05:35:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1c6c352305b599149c0b3f91093662a6f663c492",
          "body": "The mp0st_* aliases were retired in alpha.28 (unified on mAYL), so tools/list no longer\nexposes mp0st_send — the smoke test's expected-tool list was stale and failed once the\ntypecheck fix let the job reach the smoke step. Verified by building packages/mcp and\nrunning the exact CI smoke locally: mAYL_send PRESENT, mp0st_send ABSENT, other 4 present.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): smoke expects mAYL_send, not the retired mp0st_send alias",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T05:17:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "49d9266a867017c505bf8fe1cadfcba8e410ccbb",
          "body": "…ord arity\n\nCTO's alpha.30 bump left 4 refs at alpha.28 (marketplace.json, server.json ×2,\nserver.ts serverInfo) → skill-lint failed on version mismatch. And mURL_create/update\nused z.record(z.any()) — Zod v4 requires z.record(keySchema, valueSchema), so packages/mcp\ntypecheck failed TS2554 at murl.\n[…]\nsion refs to 3.0.0-alpha.30 and gave z.record its key schema (z.string()).\nVerified locally: skill-lint clean, packages/mcp tsc --noEmit clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): green main — version drift synced to alpha.30 + Zod v4 z.rec…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T05:13:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cc1d99f0398ecc464ec4325c0ef7c498ad0678ad",
          "body": "…ount 69 (alpha.30)\n\nP3 of the mURL→mIRC rework. The widget + backend (embed-keys, mirc-embed-token\nMAT tiers, embed-plan-settings, embed-dsr-delete) were complete for weeks; the\nsingle gap was the CDN. https://embed.mosadd.com/v1.js is now deployed (served\nby the mosadd Vercel project, verified 200\n[…]\nroot README's stale\n  \"65 live\" badge + stale mURL(4) row fixed; version badges -> alpha.30.\n- CHANGELOG: 3.0.0-alpha.30 entry; package bumped.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): comms_embed_create is REAL — embed.mosadd.com live, tool c…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T03:55:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "630f7963462c4db3fe847259afe69ca27d762458",
          "body": "…ol count (68)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: @mosadd/mcp 3.0.0-alpha.29 — mURL management tools + true to…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-17T01:29:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "594eef0f26f3baa8b3c15a151ff683c80192d26d",
          "body": "…one true tool count (68)\n\nFounder, live-testing: \"ile w końcu jest [narzędzi]? gdzie są narzędzia do\nzakładania, kasowania, zarządzania mURL i mIRC?\" Two real problems:\n\n1) mURL was READ-ONLY over MCP (read/post/presence/list) — no way to create,\n   claim, brand, block or delete a domain channel, e\n[…]\nth so the number can never silently drift again (mirrors\n   THREAT_EVENT_COUNT). Runtime-verified: TOOL_COUNT === 68, mURL === 7, no dup names.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): mURL owner-side management (create/claim/update/delete) + …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-16T23:57:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0db52eb7e1f99c6442883f1d17ddc6d913c549e1",
          "body": "…ndersold)\n\nFounder: the mLIDAR/threat events were a gap — the README said \"the full threat-event taxonomy\"\nbut never quantified it. @mosadd/threat-engine ships THREAT_EVENT_COUNT = 166 events across 9\nintelligence-discipline categories (SIGINT 69 · MASINT 21 · CYBER 21 · BEHAVIORAL 15 · COMINT 12 ·\n[…]\n\nTool count (65 callable) left as-is — it's the honest registered count; the cross-surface\n65-vs-80+ inconsistency is being audited separately.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): surface the Irondome's 166-event threat taxonomy (was u…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-16T22:24:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ad70b079753fdb5a602361ae0ad3f09ca91cc11c",
          "body": "…ercel deploy)\n\nRepurpose mosadd.dev from a dead redirect into the REALM front door for developers\nand contributors — manifesto-for-builders, toolkit quickstart (65 tools), the L0–L5\ncontributor ladder, Hall of Fame, and the honesty/anti-capture pitch. Static page,\nbrand-consistent (dark/mono), deployed to the Vercel \"dev\" project; keeps the\n/murl + /channel0 CWS redirects. mosadd.com = product; mosadd.dev = kingdom.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(realm): mosadd.dev = the builder/community hub (source for the V…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T19:13:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "56a4d8ffaece467901c9f9fdd1759ca044e0d387",
          "body": "…(65 tools)\n\nFounder decision: mAYL is the one name; the mp0st codename leaves every\nuser-visible surface. Unregister the 11 mp0st_* back-compat aliases (they were\n1:1 dupes of mAYL_*), rewrite the mail SKILL to mAYL_*, and correct the honest\ntool count 70+ → 65 across README/badge/package.json/serv\n[…]\nal codename (DB tables / Resend webhook) users never see. Tests\nguard that no mp0st_* tool is registered. skill-lint green, mcp 23/23, 65 tools.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release(mcp): 3.0.0-alpha.28 — retire mp0st_* aliases, unify on mAYL …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T19:02:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a9b9ef07388ae0c31311af1899dbdf14ecfff08",
          "body": "…on to npm\n\nBump @mosadd/mcp alpha.26 → alpha.27 so the re-registered threat_catalog +\nthreat_classify (Pegasus-class events classify as critical/killswitch, action\n\"monitor\", no auto-disconnect) reach the published package. mp0st_* aliases KEPT\n(preserves the public \"70+ tools\" claim) — deprecation copy made version-agnostic\nso nothing lies about an alpha.27 removal that isn't happening. skill-lint green,\nmcp tests 23/23.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release(mcp): 3.0.0-alpha.27 — ship Pegasus-class threat classificati…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T18:49:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7d027e50f4c245a40f3976319555478bc34a09e3",
          "body": "Updated the name 'mosADD' to 'mosADD™' in the manifesto.",
          "is_bot": false,
          "headline": "Change 'mosADD' to 'mosADD™' in manifesto",
          "author_name": "hiddenSOCIETY™",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T17:22:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fd8eae868cf8dcfdbbe7802393fa83ac7622320",
          "body": null,
          "is_bot": false,
          "headline": "Update project name to include trademark symbol",
          "author_name": "hiddenSOCIETY™",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T17:18:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0f2784553c959cf8f3ef304213f8e0f4adb4ae3",
          "body": "Delete the \"503 everything\" middleware (it intercepted before redirects) and\nreplace the dev-portal redirects with a catch-all: every path 301s to\nhttps://mosadd.com/developers. Keep the /murl + /channel0 rules (external, live\nmurl.mosadd.com; Chrome-Web-Store privacy/abuse links must resolve) above the\ncatch-all. mosadd.dev is now a pure alias to the builder front door.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dev): retire mosadd.dev → 301 to mosadd.com/developers",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T17:11:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cd245ee9d772d5f674273ce0e399a5468a312d54",
          "body": "…, no auto-act)\n\nthreat_classify now consults the threat taxonomy: known events\n(PROCESS_INJECTION→critical, STINGRAY_DETECT/MEMORY_INJECTION→killswitch,\nIMSI_CATCHER_SCAN/SS7_PROBE→critical …) return their real severity immediately,\nwith action=\"monitor\" — the engine tells you, it never disconnects\n[…]\n.ts against version drift. Verified: mcp tests 23/23,\nskill-lint clean, live classify of 5 Pegasus-class events → critical/killswitch + monitor.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(threat): classify Pegasus-class events as critical (monitor-only…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T17:09:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7bb97c3c5aa0b681130ad9fe2c0b59fefb7a0c9b",
          "body": "pnpm audit hit the retired legacy audit endpoint (410 Gone) and failed the gate\non every push — a dead endpoint, not a vulnerability. Detect that response and\nskip with a warning; still fail on real high+ advisories if the endpoint answers.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(sbom): tolerate npm's retired audit endpoint (HTTP 410)",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:40:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "902ab9def7170f8c987a85c737b084733cb9cdd6",
          "body": "…ools live\n\n- Founder's name rendered in English everywhere: Joseph Matthew Damian White\n  (GitHub handle @Hei33enberg unchanged). README / GOVERNANCE / MAINTAINERS /\n  HALL_OF_FAME / community/realm.json.\n- README: reflect that threat_catalog + threat_classify are now LIVE (2 defensive\n  classifica\n[…]\n\n- Governance consistency: maintainer promotion = Sovereign ratification (BDFL);\n  \"5+ substantive PRs\" wording aligned with REALM/HALL_OF_FAME.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: founder name in English (Joseph Matthew Damian White); threat t…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:30:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9fda213eafc5993f0bc37fff89d1d35c31de3f1f",
          "body": "Per the founder directive (fix the capability in code, don't trim the copy) and\nthe standing founder decision LINEAR-3498 (\"the catalog is real and must be a\nreal MCP tool, not detoxed away\"). These two tools were commented out 2026-06-27\nagainst that decision. They are PURE: deterministic, offline,\n[…]\nmy; threat_classify runs the pure DECK decision engine. Build +\ntests (threat-engine 11/11, mcp 23/23) + MCP smoke all green; 77 tools register.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(threat): re-register threat_catalog + threat_classify",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:30:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3522cd0f5f3d721768cf2378abb720394e3aac7c",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(skill-lint): add workflow_dispatch for manual gate runs",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:12:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5f587cdf1483cb270a73c898f66ceadc302184ab",
          "body": "setup-node@v5 auto-detects packageManager=pnpm from the root package.json and\nfails with \"Unable to locate executable file: pnpm\" even for jobs that only run\na plain node script. Add pnpm/action-setup@v5 (same pattern as ci.yml).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: install pnpm before setup-node in skill-lint & realm-ledger",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:08:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6a4991a180d183681fd3800958ef06dfbe83f002",
          "body": "…e CTO\n\nAdd \"zero-trace\", \"NSA-proof\", \"cannot be monitored\", \"zero-knowledge\neverywhere\" to the honesty gate (careful regex — the brand motto \"Trust no\ntrace\" is explicitly not flagged). These invite exactly the regulators the\nproject is built to stay honest with.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(honesty-lint): encode the full banned-claims list from the app-sid…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:06:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fbf6acd5f424c4803e567770f60d71eb00612f8f",
          "body": "…nder\n\nAutomation so the project runs itself. GitHub Actions (deterministic) +\nscripts:\n\n- skill-lint.yml + scripts/check-skill-lint.mjs — the drift gate: skill\n  frontmatter, marketplace↔skills sync, version triple-check, and an\n  honesty-lint (bans \"unbannable\"/\"military-grade\"/blanket-encryption/\n[…]\n stays human.\n- AGENTS.md — contributing as/with an AI agent (our signature move: the\n  layer for agents, built by agents coordinating over it).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: the automatic orchestra — self-running repo + community, zero fou…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:00:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b483ad3c0eddd1fae9bbb7a785fcbd0834029463",
          "body": "- skills/murl/SKILL.md — the one missing module skill (open-web rooms).\n  Covers only the four registered mURL_* tools; teaches per-URL keying,\n  read-before-post, and the posture honesty (public by design, never E2EE).\n- docs/rfcs/0005-murl-skill.md (Accepted) — closes the gap noted in\n  skills/REA\n[…]\n the RFC pointer.\n\nThe new skill-lint gate now keeps README/marketplace/server/package versions\nin lockstep, so this drift can't recur silently.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(skills): add mURL skill + RFC 0005, sync versions to alpha.26",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:00:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e95dda0fd465035200c720cfb6b96655f519329d",
          "body": "…oundation)\n\nAdd the two missing charter docs and wire them through the repo:\n\n- MANIFESTO.md — what we believe, honestly: mDM-only E2EE, no scanning\n  backdoors, grassroots/self-funded/no-VC, a kingdom (BDFL) said out loud,\n  and the \"hu(m)an OS to ADD\" name. Passes the e2ee-posture honesty bar.\n- \n[…]\nr surface (levels + generated block).\n- Ghost \"Discord (link in README)\" refs replaced everywhere; identity-recovery\n  arch doc marked Descoped.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: manifesto + realm + sovereign governance + founders (link the f…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-15T16:00:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "24c421631baa6f2dd9b9515dce270112149164cf",
          "body": "Aligns both READMEs with the live mosadd.com positioning (they were still on the older\n'comms layer for AI agents' line):\n- Lead with the product tagline 'They're apps. We're the layer.' + the humans/agents/robots\n  omnichannel framing, one inbox, the [need-human] loop.\n- Honesty front-and-center: '\n[…]\nt on the layer' / Links CTAs (install, hosted\n  gateway mcp.mosadd.com, mint a key, self-host). '70+ tools' verified against the registry (82).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: sharpen the README voice to the mosadd.com brand story",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-14T08:43:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "60a89dc950bd07c1dc173df3ef73f43e905cdff2",
          "body": "# Conflicts:\n#\tREADME.md",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main'",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-14T05:22:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3e611f6fb7c2a04e5a78d81f38407adb9017f63",
          "body": "…dd owner guide & workstation arch\n\nSweep the remaining copy to one story: four modules mDM/mIRC/mURL/mAYL + capabilities, '70+ tools',\nmp0st->mAYL, threat = optional on-device security pillar (drop '166-event moat/kernel', 'Threat\nclassification hooks every call', PSTN dialer remnants), fictional d\n[…]\nd node: identity -> capabilities -> control -> RBAC ->\ncross-machine, security-gated). Root keywords trimmed (-operating-system,-matrix,+e2ee).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: align architecture/examples/skills to the four-module story + a…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-14T05:20:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "429a62ba6c5396a8d747e981cdaa91dc7b4d6de3",
          "body": "…ayer.'\n\nKill the stale 'Iron Dome is the kernel' / threat-scored-MAT story across apps/dev, apps/hub\nand apps/mcp-http. Homepage + RadarHero lead with 'They're apps. We're the layer.' and the four\nmodules (mDM/mIRC/mURL/mAYL) + toolkit with honesty badges (E2EE vs server-readable). Pricing =\n'Free \n[…]\nurl page; docs nav = Modules/Capabilities/Security; /docs/mcp,\nquickstart, security, blog, llms.txt, metadata all to '70+ tools' + mp0st->mAYL.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(site): re-align the dev site + hub to 'They're apps. We're the l…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-14T05:20:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a2f8653772a237b40eb5b6c889b71ec900b148b",
          "body": "…he real brand story\n\nOne story everywhere, matching mosadd.com: 4 modules mDM/mIRC/mURL/mAYL + capabilities\nmTALK/mRAG/comms; '70+ tools' (was drifting 61/64/74); mp0st->mAYL (aliases deprecated);\nadd the mURL row; drop threat_catalog/threat_classify as advertised tools and the\n'166-event radar / d\n[…]\n tool/moat); mark mDM_send_unencrypted DEPRECATED. Package/server.json\ndescriptions + registry one-liners + root README badge/table reconciled.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(mcp): align npm README + registry submissions + root README to t…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-14T05:20:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "24daebc634096565c29a4349633354544d0a972a",
          "body": "…s; align tests to registered set\n\nUnregister the three scaffold tools whose EFs 404/400 every call (their own inline comments\nsay so): mAYL_send_as_agent (mail-provenance), mTALK_ingest_ptt (ptt-ingest), comms_embed_create.\nAn agent must only ever see tools that actually work. Fix the mURL header c\n[…]\nL_post/mAYL_send (threat stays unregistered on-device pillar).\nRegistered surface now 74 tools (public copy: '70+'); build + 23/23 tests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp): unregister dead scaffolds + mp0st->mAYL in tool description…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-14T05:20:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd6bee5cd0c666637c82ca160b588d69951ceac6",
          "body": "Root README (the authoritative \"What's live today\" status doc) had\ninternal contradictions flagged in founder QA:\n\n- Version was stale: badge + header said alpha.23; every workspace\n  package (incl. @mosadd/mcp) is at 3.0.0-alpha.26. Bumped to alpha.26.\n- threat_* was listed as a live tool row while\n[…]\ntable and the code (mail-aliases.ts: removed in alpha.27).\n\nTool count (74 = 63 real + 11 mp0st aliases) is self-consistent and\nleft unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): fix version + threat_/mp0st copy contradictions",
          "author_name": "hei33enberg",
          "author_login": null,
          "committed_at": "2026-07-13T03:18:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "552ce1f5e90693786eb888e6169eb74b4542a463",
          "body": "…o secrets)\n\nFills the documented TODO in docs/registry-submissions/modelcontextprotocol-\nregistry.md (\"add mcp-publisher publish to a GitHub Actions workflow\").\n\n- .github/workflows/publish-mcp-registry.yml: workflow_dispatch → installs\n  mcp-publisher, `login github-oidc` (authenticates as the rep\n[…]\n is now the easiest path; manual CLI stays as the laptop fallback.\n\nOnce listed, Glama / mcp.so / Smithery / mcpservers.org auto-index from it.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(registry): one-click publish to the official MCP Registry (OIDC, n…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-09T20:25:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ff885475afb4fe5ef71b19d94329e667e6a3ce62",
          "body": "…ix tools badge\n\n- Add a \"2c. One-click\" Quickstart line pointing to mosadd.com/mcp, where the\n  Add-to-Cursor / Add-to-VS-Code buttons open the editor and insert the server.\n- Tools badge said \"61 live\" while the body (and server.json) document 74 —\n  bump the badge to 74 to match.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): 1-click install (Cursor/VS Code via mosadd.com/mcp) + f…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-09T20:04:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a4e75d001c820551fa44dfb110396225491a2221",
          "body": "…on fresh publish",
          "is_bot": false,
          "headline": "ci(vtg-mcp): retry smoke-install to tolerate npm CDN propagation lag …",
          "author_name": "Hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-06T23:32:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9d1ef72d02081849d00521eda57d74a85d3415b",
          "body": "…nticity layer)\n\nReciprocal cross-link: the comms layer (this repo) now points to Voice Truthgate — mosADD's\nopen authenticity/trust layer (identity + voiceprint + live-rhythm fusion, signal-not-verdict),\nwith the @mosadd/voice-truthgate-mcp npm badge + npx one-liner. Same @mosadd scope, so the two\nrepos read as one ecosystem. Additive only.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): add Ecosystem section — link Voice Truthgate (the authe…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-06T20:33:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "83d2bb3725be3637403f0c47c66f827bff669e8a",
          "body": "…y push\n\nThe 'mosadd-os' Vercel project (framework:null, no custom domain, live:false) builds\nfrom the REPO ROOT (pnpm -r build → packages, no web output) and so ERRORs on EVERY\npush with a missing-public-dir failure — a red X on every commit (CTO-2 traced it;\nprior commits c1a71cb/15f97d2 all faile\n[…]\nle (delete this file). The right long-term fix is to delete\nthe stale project in the Vercel dashboard (owner), but this silences it safely now.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(vercel): stop the stale repo-root project from building on ever…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-06T19:55:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dba412e882d2970b6b9a0d445d84f7e78d79cae1",
          "body": "The MCP source lives in the public voice-truthgate repo (mcp/); publish runs here because\nthis repo holds the NPM_TOKEN secret. Manual (workflow_dispatch).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: workflow to publish @mosadd/voice-truthgate-mcp to npm",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-06T19:19:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "15f97d2dc48c413e8690db429510daf0396c31c9",
          "body": "…v6 T10, LINEAR-4275)\n\nMain landing was expanded to cover robots + teams as first-class contacts, but the\npublic toolkit repo had zero robot content — agents thoroughly covered, robots only\nmentioned in passing. Fixed:\n\n- New docs/robots-and-agents.md: definition (agents vs robots on the same layer)\n[…]\n  channel, roadmap.\n- README.md: new 'Robots on the same layer' section right before 'Why we're\n  different' with a direct link to the new doc.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: robots + agents on one layer — dedicated integration guide (LP …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-06T18:09:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c1a71cb3d9db1b3672508d6390439131926cca3f",
          "body": "The Next.js viewer here is superseded by the mosADD SPA public viewer at\nmosadd.com/m/:slug (m0ssad-3 commit d32cb2c8). Turn murl.mosadd.com from a 503\n'offline' placeholder into a permanent redirect that preserves path + query:\n  murl.mosadd.com/allegro-pl?x=1 -> https://mosadd.com/m/allegro-pl?x=1\n[…]\ndge as a safety net if the build\never misconfigures. Domain binding on the mosadd-murl Vercel project stays as-is\n(no dashboard change needed).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(murl-www): 301 → mosadd.com/m/<slug> (retire the 503 placeholder)",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-07-05T04:42:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "07ffc3021fe3bdec322475ec67c25651c891cfc3",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(agent): default system prompt name → 'mosadd general'",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-30T22:16:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "50cc868d668a9260742b244ed2146e67c301dd80",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(lockfile): sync pnpm-lock for @mosadd/agent",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-30T21:11:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e6817aec421e01d68faf3edb8bfe9bef0b61e59c",
          "body": "New first-class on-ramp for \"I want an agent on mosadd\". One command:\n\n  npx -y @mosadd/agent start\n\n…turns a hub key + an OpenRouter key into a live mosadd contact that reads and\nreplies to DMs. Pure mosadd brand — the user's first install command no longer\npoints at hermes-agent.nousresearch.com.\n\n[…]\ntsup build green (ESM + dts).\n- bin smoke: `mosadd-agent help` prints usage; `start` without env fails fast\n  with the exact missing-vars list.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(agent): @mosadd/agent package — one-command mosadd-branded agent",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-30T21:09:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aafaeae5985c8fee8ad481ccb89c7a8a52bef9e4",
          "body": "…hub:main HEAD)\n\nThe cursor/marketplace/claude-code install configs ran 'npx github:Hei33enberg/mosadd-os'\n— arbitrary code off main HEAD on every launch (supply-chain risk; effectively a fresh\nbuild each run). @mosadd/mcp is published on npm (alpha = 3.0.0-alpha.26); aligned the 3\noutlier configs to '@mosadd/mcp@alpha' like the rest of the repo. (LINEAR-4083)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(install): pin MCP install to the published npm package (kill git…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-29T23:28:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "aae9bc57b44a4817eeca37ca3f68f39d75879526",
          "body": "…er-URL domain derivation\n\nShips RFC-0004: mURL rooms keyed per-URL. Pairs the murl.ts urlToSlug change (dc1f821) with\nthe edge fix — ensureDomainStatus now derives the host from the slug prefix before \"__\" so\ndomain status/blocking still works for page rooms; bare-domain slugs unaffected. Bumps all 8\n@mosadd/* packages to alpha.26 (lockstep). Push auto-deploys mosadd-edge (deploy-edge.yml);\npublish.yml dispatched separately. LINEAR-4017.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): @mosadd/* → alpha.26 (mURL per-URL RFC-0004) + edge p…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T12:42:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dc1f821a849f1a318eca9322c35f84eb07855b2a",
          "body": "mURL is \"IRC-for-URLs\" but keyed rooms by domain only — collapsing every page on a site into\none room. RAK needs a room per ARTICLE; per-URL keying is the right primitive (founder delegated\nthe call). domainToSlug → urlToSlug: slug = host(\".\"→\"-\") + path segments (\"/\"→\"__\"), query/\nfragment/trailing\n[…]\nllout in docs/rfcs/0004-murl-per-url-keying.md. Ships once CTO#1 deploys\nthe edge + republishes @mosadd/mcp (founder's npm token). LINEAR-4017.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mURL): key rooms PER-URL, not per-domain (RFC-0004)",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T08:50:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "913933d3548b68a372ac1ae88ca85a4995ce0373",
          "body": "…d-token live on prod\n\nP5.1 mURL embed stack: the EFs that mint embeddable mURL channel widgets are\nnow deployed and healthy on prod (rooffhgbxafyjcwmwpsy). The toolkit scaffold\nwas complete already — just needed the registration flip.\n\nBackend (committed in m0ssad-3):\n- embed-keys, mirc-embed-token\n[…]\n/\nalpha.28? Suggest one bump (alpha.26) with all three:\n- mAYL_send_as_agent (P3.1)\n- mTALK_ingest_ptt (P4.1)\n- comms_embed_create (P5.1, this)\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(P5.1/4002): register comms_embed_create — embed-keys + mirc-embe…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T08:50:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "491b3e17c3b885f36a020d8d268c9c19b1499abb",
          "body": "… register tool\n\nCloses the scaffold loop. The old tool shape used an attachment/uploadBlob flow\n+ channel_id/room_id routing that NEVER matched the deployed EF (which expects\n{direction, audio_base64, mime_type, message_id?, thread_id?}). Every call 400'd.\n\nRewritten to the actual contract:\n- audio\n[…]\ns alpha.26 republish into alpha.27 (or\nship alpha.26 first with mAYL_send_as_agent only, then alpha.27 with this).\nInstructions on LINEAR-3998.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(P4.1/3998): align mTALK_ingest_ptt with deployed ptt-ingest EF +…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T08:41:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e466bd72de8058022f2e470f91627ba02be0b78",
          "body": "…with hub-claim provenance\n\nCloses the scaffold loop. Re-targeted the tool from non-existent `hub-claim-mint`\n(TODO Lane A) to the now-shipped `hub-claim-mint` Edge Function — which mints an\nHS256 JWT signed with HUB_JWT_SECRET carrying { sub: user_id, mosadd_hub: true,\nagent_id, task_id?, aud: \"mp0\n[…]\n lockstep bump all 8 packages to 3.0.0-alpha.26 + run\npublish workflow + redeploy mcp.mosadd.com. Detailed instructions in\nLINEAR-3991 comment.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(P3.1/3991): register mAYL_send_as_agent — agent-attributed mail …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T08:10:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5d49f663137a050d84f95821b51e520f35594f58",
          "body": "… alpha.25\n\nThe big coordinated republish (LINEAR-3985 / re-arch 3938). One atomic flip across\ncode + server.json + README + version bump so the public surface stops contradicting\nitself (LP says 4 modules including mAYL, README was still showing mp0st as a module).\n\n- Rename tool tokens mp0st_* → m\n[…]\ned version).\n\nVerified locally: pnpm -r build clean + stdio server lists 74 tools (11 mAYL + 11 mp0st\nalias + 0 threat). publish workflow next.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(P2b/3985): mp0st → mAYL coordinated rename + threat_ unregister;…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T05:45:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "461460315b08f448f3a384158cb23fbbc9fd8cdc",
          "body": "…ive modules; alpha.24\n\nmURL was revived as a full dev module (founder 2026-06-27 re-arch), reversing the stale\n2026-06-10 \"brand surface, not a dev product\" decision. tools/murl.ts was already written +\nits backends are live (mosadd-edge Worker + murl-channels EF), so this just REGISTERS it:\nmURL_r\n[…]\nly: pnpm -r build clean + the stdio server lists 65 tools incl all 4 mURL.\nDeferred to a follow-up release: mp0st→mAYL dual-register (aliases).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): register mURL (4 tools) + accurate counts — 65 tools / 6 l…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T03:09:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "53d6a9700f56a270bbc023edb47e5da801cb47ce",
          "body": "…ublic repo\n\nPublic-hygiene cleanup of mosADD-OS (from the market audit — DX/adoption surface):\n- Delete docs/handoffs/ (4 internal agent→CTO ops notes — mURL/channel0/Vercel-collision —\n  with internal codenames, Vercel IDs and dead surfaces; not developer-facing, bad look in a\n  public repo).\n- Re\n[…]\nBYOK Supabase JWT vs hosted MOSADD_API_KEY)\nis entangled with the toolkit's local-vs-hosted auth contract — needs CTO#1, not a unilateral flip.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: remove internal handoff notes + dead mosadd.dev refs from the p…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T02:03:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0dbbe21c8ca99324814c67278c5d466e2935b950",
          "body": "…only)\n\nRoot README + packages/mcp/README intros now name the four user modules — mDM (1:1 E2EE),\nmIRC (in-app channels), mURL (open/embeddable text rooms), mAYL (email 3.0) — and the\ncomms-layer positioning. Prose only.\n\nLEFT FOR CTO#1 (R1 — coordinated republish): all tool COUNTS (61/56/5-live-mod\n[…]\nname tokens (mp0st_*/mTALK_*/etc.), the module table\nrows, mURL/mROOM/mCALL registration reclassification, and server.json description/version.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): reframe intro to the 4-module model (handoff §5, prose-…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-27T01:13:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7789c3713e33a7433ca0052fe726c4e89159ce48",
          "body": "…s ordering)\n\n`pnpm -r --parallel run build` ignores the workspace dependency graph, so @mosadd/ai\nbuilds its .d.ts before @mosadd/mcp emits dist/index.d.ts -> TS7016 \"Could not find a\ndeclaration file for '@mosadd/mcp'\" -> build fails. CI dodged this by invoking\n`pnpm -r build` directly (topologica\n[…]\narallel so `pnpm -r run build` honors topo order\n(still batches within a graph level). Verified: clean `pnpm run build` exits 0, mcp before ai.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(build): root build script must be topological, not --parallel (dt…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T20:04:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "48cab0840298c1bcab6b5b844ffd93ec4c2ae686",
          "body": "…validation failure)\n\nsetup-node@v5 auto-detected root packageManager=pnpm and its post-step tried to save a\npnpm store the apps never populated (they install with npm) -> \"Path Validation Error:\nPath(s) ... do(es) not exist\" failed all three apps jobs (dev/hub/mcp-http) on the cleanup\nstep — even t\n[…]\nall/Typecheck/Build all passed. Point setup-node at the npm cache\nkeyed on each app's own package-lock.json so the cached path actually exists.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): apps job — cache npm not auto-detected pnpm (post-step path-…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T19:54:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d2db596fadf3921d2b2844b8f8db9f0e466870eb",
          "body": "…o/form-data highs, mcp-http deploy\n\nFaza 0 (pre-sandbox) — unblock the release pipeline so toolkit changes can ship again.\n\n- A1 (red CI): @mosadd/ai tool-count tests hard-coded 20/6/12 and went stale after a\n  tool was unregistered (62->61) -> vitest red on main -> releases shipped on red.\n  Deriv\n[…]\ntall in sync, build+typecheck all 8 pkgs, full vitest suite green\n(mcp 23, ai 13, crypto 30, threat 11, bridges 14), prod high audit gate PASS.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): green the pipeline — stale ai tests, fake lockfile gate, hon…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T19:50:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "400686e9a2b81d3e164e3f60f868df2d1becd8a1",
          "body": "…ss; 62→61)\n\nAdversarially verified every registered tool's request/response contract against the\ndeployed edge functions. Highlights (full list in CHANGELOG):\n\n- invokeFunction now surfaces the REAL edge-function error body + status (was always the\n  opaque \"non-2xx status code\") — every EF-backed \n[…]\n typecheck + build + crypto round-trip green; 61 tools list, no\nscaffolds. Deps unchanged since alpha.22 (still current) so only mcp is bumped.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release(mcp): 3.0.0-alpha.23 — toolkit hardening (tool↔EF contract pa…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T05:44:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b21440ccf3e6dfddacc1ef3f40e9aff350fa5819",
          "body": "…osadd/* dep versions)\n\nalpha.21 crashed on a clean `npm i @mosadd/mcp@alpha`:\n  SyntaxError: '@mosadd/crypto' does not provide an export named 'initRatchetInitiator'\n\nRoot cause: the workspace dep packages (crypto/protocol/providers/threat-engine, also\ncore/ai/bridges) still carried their old alpha\n[…]\neshly-published builds. All 8 build clean; workspace\nsmoke test lists 62 tools, 0 scaffolds. Post-publish clean-install verification to follow.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: lockstep alpha.22 — fix alpha.21 broken-on-install (stale @m…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T04:37:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63498a7eea7749901f96f4f404f9a24319ac1e25",
          "body": "…tools (64→62)\n\nBumps @mosadd/mcp to alpha.21 so the un-register of mp0st_send_as_agent (404 every call)\nand mTALK_ingest_ptt (400 every call) actually ships to users. CHANGELOG alpha.21 entry\nadded; server.json version bumped. Built + smoke-tested locally: server lists 62 tools,\nboth scaffolds absent, core tools (mDM_send/mIRC_post_message/mp0st_send/mRAG_search) present.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release(mcp): 3.0.0-alpha.21 — unregister 2 always-erroring scaffold …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T04:28:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e9d85334be1c1c7fd1b3d1d474f3a2193ece6732",
          "body": "…ffold tools\n\nFollow-up to the un-register: align packages/mcp/README (badge/headline/per-module table/\nbreakdown) with server.json + root README — mp0st 12→11, mTALK 6→5, 62 callable; drop the\nmp0st_send_as_agent + mTALK_ingest_ptt rows and note them as not-registered scaffolds.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(mcp): packages README count 64→62 to match the un-registered sca…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T04:14:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d0c70b466d9c9dc7f1024853328bc36862dfb0cb",
          "body": "…agent, mTALK_ingest_ptt); 64→62\n\nA consistency audit found two REGISTERED tools that fail on every call — shipped in the\npublic toolkit without their \"scaffold\" caveat:\n- mp0st_send_as_agent → POSTs to a non-existent hub-claim-mint endpoint (404 every call) and\n  sends provenance body fields the de\n[…]\nurce for both tools is kept for\nthe rework. Typecheck green.\n\nRe-register once their backend contracts are wired + tested (tracked separately).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp): unregister 2 scaffold tools that error 100% (mp0st_send_as_…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-26T04:12:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9dd43f5faf5a16845b049df0530c91f8d3213ad",
          "body": "…emaining pre-pivot drift\n\nFounder spotted lowercase 'mosadd' as brand + pre-pivot 'm·os·add — operating\nsystem for human communications' still in README. Plus 'man OS add' in RFC 0001.\n\nMass-rename prose mentions (NOT identifiers/CLI/config-keys/package-names which\nstay lowercase by convention):\n- \n[…]\nnames, mosadd.com domain,\nmosadd_* DB columns/env, MOSADD_* env vars, 'mosadd' CLI command + config key\n+ ~/.mosadd path + plugin install name.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(brand): nomenklatura — mosadd → mosADD consistency sweep + kill r…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-22T04:44:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "093932dbb2003299d333c25e72b068d2ee84223e",
          "body": "…I flow\n\nThe previous commit's bulk-add lost this file due to a concurrent write race\n(Write tool reported 'file has been modified since read' after the bulk Edit\nbatch). Old draft on disk still said 'PR to servers/' which no longer exists —\nthat flow was deprecated when the official MCP registry moved to an API service\nat registry.modelcontextprotocol.io (v0.1 freeze 2025-10-24). Rewriting in a\nclean follow-up commit.",
          "is_bot": false,
          "headline": "docs(gtm): retry — rewrite registry draft to current mcp-publisher CL…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-22T04:35:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "639b6ef6c5845ce221b889e123845486cd234679",
          "body": "…EAR-3105 / S14)\n\nGitHub repo Hei33enberg/mosADD-OS description publicly leaked pre-pivot framing\n('A human OS. Add. — Operating system for human communications') and had ZERO\ntopics → invisible to MCP-server discovery. Audit LINEAR-3105.\n\nDone autonomously:\n- gh repo edit: rewrote description ('ope\n[…]\nafts.\n\nOwner-gated remainder (clearly documented): npm republish of alpha.21 with\nmcpName + mcp-publisher login github + mcp-publisher publish.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gtm): prep official MCP registry submission + fix repo meta (LIN…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-22T04:34:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f2572b68d511becf09d19f8dbaea721856a24416",
          "body": "…hitecture doc + embed coming-soon (LINEAR-3526)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(truth): finish post-pivot sweep — remaining apps/dev pages + arc…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-21T00:18:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f60d455d53a969bca8360321dd385148304930f1",
          "body": "…g + naming across toolkit docs (LINEAR-3526)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(truth): post-pivot positioning + alpha.20 + mosadd.com onboardin…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-21T00:07:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6f75f77508f4125a7501ec15f88577aa9679066d",
          "body": "…, honest per-channel encryption scope, mosadd.com onboarding, mosADD-OS rename (LINEAR-3526)",
          "is_bot": false,
          "headline": "docs(readme): post-pivot rewrite — agent-native positioning, alpha.20…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-20T23:57:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4c2374d57b58a3e2874245e11f622545ee29a87",
          "body": "…hub key (LINEAR-2919)\"\n\nThis reverts commit e3d2bb6035ba7ad97840f7457c58e9fa9ae19a43.",
          "is_bot": false,
          "headline": "Revert \"fix(dev-portal): take mosadd.dev online + ensure /keys mints …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-20T23:40:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3d2bb6035ba7ad97840f7457c58e9fa9ae19a43",
          "body": "…(LINEAR-2919)\n\nDelete the global 503 \"we're cooking\" middleware (its own comment said to\ndelete the file to bring the site back) and add /keys as an alias that\nredirects to the canonical /hub mint portal. The hub page already loads\nthe user session, lists existing keys, and auto-issues a fresh\nmosadd_sk_live_* key via the hub-keys Edge Function with one-time display\nand copy. Unblocks S2 onboarding.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dev-portal): take mosadd.dev online + ensure /keys mints hub key …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-20T23:29:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0c3342b06e2fb373508f02b801a34e100c3465c1",
          "body": "…EAR-2919)",
          "is_bot": false,
          "headline": "chore(mcp-http): repin alpha.20 + deploy + attach mcp.mosadd.com (LIN…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-20T23:28:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bee0fd4a63b5d23ee04053e043c3a2e2ba1a748",
          "body": "…kills to match real E2EE (LINEAR-3526)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(honesty): purge false sealed-sender claims; fix mDM/mp0st/mIRC s…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-20T23:02:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "67767cb8acf6516d72f86c644626e3d5bf9a00e1",
          "body": "…(LINEAR-2478)\n\nThe DH ratchet was strict in-order: any index gap threw, so lossy / out-of-order /\nmulti-device transports would drop messages. Add Signal's skipped-message-key cache\nto mdmRatchet.ts: keys for not-yet-consumed indices (within a chain, and the tail of\na chain before a DH ratchet turn\n[…]\nr\na turn; a gap beyond MAX_SKIP is refused. crypto app 29/29, toolkit 30/30; mDM\nround-trip app 11/11, toolkit mcp 23/23. Typecheck clean both.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mdm): bounded skipped-message keys for out-of-order DM delivery …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-20T14:47:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d3f890ce01e608b9d871faff504c729693955010",
          "body": "…(LINEAR-3409)\n\nAdd mdmRatchet.ts — Signal-style DH ratchet step: fresh X25519 entropy is mixed\ninto the root key on each conversation turn, so a key compromised at message N no\nlonger decrypts messages after the next turn (post-compromise security).\n\n- Versioned envelope: new sends use mosadd.e2ee.\n[…]\n crypto app 27/27, toolkit 28/28 (incl. PCS, forward secrecy, strict\norder); mDM round-trip app 11/11, toolkit mcp 23/23. Typecheck clean both.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mdm): DH Double Ratchet (PCS) for DMs via versioned v2 envelope …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-20T13:34:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e605e40f959dbe260a26416ddf4c32ddb23f6c78",
          "body": "…lic surfaces\n\nAudit found public-surface dishonesty after the alpha.19/alpha.20 cleanup:\n- apps/hub/app/page.tsx: '65 live MCP tools across 7 modules' → 64 / 5.\n- examples/hermes/README.md: '70 tools' → '64 tools'.\n- apps/dev/app/murl/page.tsx: 'mROOM — proving it at internet scale' → mIRC.\n\nMCP to\n[…]\nommend channel_id (mIRC); room_id narrowed to mTALK-only PTT rooms.\n- tools/attachments.ts + providers/blob-upload.ts: drop mROOM from headers.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs+tools): scrub stale mROOM/mCALL + wrong tool counts from pub…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-19T23:25:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1ee7be9418eddc3747a1ed1d3d05078de73389a1",
          "body": "From the tool audit (LINEAR-3520):\n- mIRC_reject_request/approve_request sent `request_id`; channel-members-manage\n  reads `target_identity_id` → 400 every call. Use `identity_id` (normalized to\n  target_identity_id). reject now works; approve of an E2EE channel still needs a\n  wrapped group key (LI\n[…]\n → no paging past page 1. Send `before`, read `next_before`.\n  (LINEAR-3524)\n\nTests green: mcp 23/23, ai 13/13. Bump 3.0.0-alpha.19 → alpha.20.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp): mIRC approve/reject field + mDM/mIRC pagination (alpha.20)",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-19T20:57:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b3c4e44d43ea1b834f52801803f817f084abb321",
          "body": "…e as MCP tools\n\nTwo coupled changes across the public toolkit, reconciled atomically so docs\nnever claim more than the live server serves.\n\nREMOVED — mROOM (LINEAR-3414): unregister the 11 mROOM_* tools in\npackages/mcp (index.ts, attachments.ts, embed.ts description); source kept on\ndisk unregister\n[…]\nTests green: mcp 23/23, ai 13/13.\nBump @mosadd/mcp 3.0.0-alpha.18 → alpha.19. mURL brand pages kept (only the\ndead dev-module listing removed).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cleanup(public): remove killed mROOM everywhere + expose threat engin…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-19T18:36:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b2567b9625c55d78adf1ceca379db6f64f1dbe57",
          "body": "…464) (#30)\n\n* feat(mcp): rename mAIL_* email tools to mp0st_* + fix tool counts (LINEAR-3464)\n\nFull rename of the 12 email MCP tool names mAIL_* -> mp0st_* (no aliases,\nfounder decision). Backend Edge Functions (mp0st-*) unchanged. Rebrands the\nuser-facing mAIL module label to mp0st across dev docs\n[…]\ne ops but the\nassertions were never updated. Unrelated to the mp0st rename.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): rename mAIL_* tools to mp0st_* + fix tool counts (LINEAR-3…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-19T13:11:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d790b48b8282dd773e2d958ff61a654ed15bfbc",
          "body": "Bring public default branch up to current (16 commits). Preserves main's\nHermes integration-guide commit alongside agent-coordination content.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge(LINEAR-3465): reconcile main with agent-coordination live work",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-19T12:49:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3128fec8e54ae64ca6c4e40633aaad66e7e73677",
          "body": "Long-running mosadd agent via @mosadd/mcp (BYOK + self-refreshing login,\ncoordination skill, Docker/VPS deploy pattern). Fills the gap between the\neditor integrations (Claude Code/Cursor) and a persistent gateway agent.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(examples): add Hermes Agent integration guide",
          "author_name": "hei33enberg",
          "author_login": null,
          "committed_at": "2026-06-18T00:58:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1dd779edd5f336c7b7399c28f8f6431de885ee4f",
          "body": "…nto the app it generates\n\nNew MCP tool: mints an origin-scoped publishable embed key (embed-keys EF) for a channel and\nreturns a paste-in widget snippet (<div> + <script src=embed.mosadd.com/v1.js data-key=…>).\nThe widget swaps the publishable key for a short-lived channel-scoped JWT at runtime\n(mi\n[…]\nproject and embed.mosadd.com repointed to it (the old dev-portal serving it is offline).\n\nBump @mosadd/mcp → alpha.18. typecheck + build green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): comms_embed_create — builder-agent embeds a live channel i…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-18T00:58:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1644c5b4e68c2a6a48f42295c96516a6bdeed0b5",
          "body": "…ramework)\n\nVercel zero-config treated the package `build` (tsc) as a static build and failed on\n\"No Output Directory\". Set framework:null + a buildCommand that emits a tiny public/\nplaceholder (the `/` and `/mcp` rewrites route to the api/mcp serverless function, so the\nplaceholder is never served)\n[…]\nthed by Bearer mosadd_sk_live_ → hub-key-exchange);\ndomain mcp.mosadd.com attached. Live-verified: bad key → JSON-RPC 401 \"Invalid or revoked\".\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-http): Vercel config for serverless-only gateway (no static f…",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-18T00:36:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "daf5d25fdf2a36562235af07bdc8a74936872d4a",
          "body": "Long-running mosadd agent via @mosadd/mcp (BYOK + self-refreshing login,\ncoordination skill, Docker/VPS deploy pattern). Fills the gap between the\neditor integrations (Claude Code/Cursor) and a persistent gateway agent.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(examples): add Hermes Agent integration guide",
          "author_name": "hei33enberg",
          "author_login": null,
          "committed_at": "2026-06-18T00:29:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1150b8b55294a497ac7a5632600e76f46686689e",
          "body": "…+ durable login + reconciled docs)\n\nVersion bump so a republish ships to npm what landed since alpha.16:\n- Action Links screen share: comms_action_create `screen_share` type + comms_action_frame_get\n  (agent reads the recipient's shared screen, consent-gated).\n- Durable `mosadd login` (refresh-at-b\n[…]\nth path order).\n\nPublish via the existing CI workflow (publish.yml, workflow_dispatch, NPM_TOKEN secret) on\nthis branch — no local npm publish.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(mcp): bump @mosadd/mcp 3.0.0-alpha.16 → alpha.17 (screen-share …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-17T23:59:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9ab8050e70b6652a34c6a81b0c44d1416bf0a52c",
          "body": "…deploy-ready\n\nVercel deploys apps/mcp-http as a standalone project (Root Directory apps/mcp-http) with\nplain npm, which can't resolve the old file:../../packages/mcp monorepo ref. Switch to the\npublished @mosadd/mcp@^3.0.0-alpha.16; verified its @mosadd/{crypto,protocol,providers} deps\nare on npm, \n[…]\nct on team hei33enberg + attach mcp.mosadd.com). Local dev note: use\n`npm link ../../packages/mcp` to test against unpublished package changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "build(mcp-http): switch gateway dep to published @mosadd/mcp@alpha — …",
          "author_name": "hei33enberg",
          "author_login": "Hei33enberg",
          "committed_at": "2026-06-17T23:43:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 15,
      "commits_last_year": 352,
      "latest_release_at": "2026-07-21T17:23:47Z",
      "latest_release_tag": "v0.2.12",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 2,
      "mean_days_between_releases": 1.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@mosadd/ai",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/ai",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.26",
          "repository_url": "https://github.com/Hei33enberg/mosadd-os",
          "versions_count": 7,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1037,
          "first_published_at": "2026-05-31T00:39:22.907000Z",
          "latest_published_at": "2026-06-27T12:55:22.104000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        },
        {
          "name": "@mosadd/mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mosadd",
            "mcp",
            "model-context-protocol",
            "agent",
            "claude",
            "cursor",
            "anthropic",
            "communication",
            "messaging"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/mcp",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.32",
          "repository_url": "https://github.com/Hei33enberg/mosADD-OS",
          "versions_count": 31,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2728,
          "first_published_at": "2026-05-31T00:39:15.674000Z",
          "latest_published_at": "2026-07-19T02:43:30.180000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@mosadd/core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/core",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.26",
          "repository_url": "https://github.com/Hei33enberg/mosadd-os",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1313,
          "first_published_at": "2026-05-31T00:38:51.980000Z",
          "latest_published_at": "2026-06-27T12:55:14.537000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        },
        {
          "name": "@mosadd/agent",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mosadd",
            "agent",
            "ai-agent",
            "communication",
            "messaging",
            "claude",
            "openrouter"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/agent",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.0",
          "repository_url": "https://github.com/Hei33enberg/mosADD-OS",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 186,
          "first_published_at": "2026-06-30T21:13:29.098000Z",
          "latest_published_at": "2026-06-30T21:13:29.338000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 23
        },
        {
          "name": "@mosadd/crypto",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mosadd",
            "crypto",
            "e2e",
            "x3dh",
            "double-ratchet",
            "signal-protocol"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/crypto",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.26",
          "repository_url": "https://github.com/Hei33enberg/mosadd-os",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1281,
          "first_published_at": "2026-05-31T00:38:38.759000Z",
          "latest_published_at": "2026-06-27T12:55:10.839000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        },
        {
          "name": "@mosadd/bridges",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/bridges",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.26",
          "repository_url": "https://github.com/Hei33enberg/mosadd-os",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 948,
          "first_published_at": "2026-05-31T00:39:07.142000Z",
          "latest_published_at": "2026-06-27T12:55:18.228000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        },
        {
          "name": "@mosadd/protocol",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mosadd",
            "protocol",
            "zod",
            "schema",
            "codec"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/protocol",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.26",
          "repository_url": "https://github.com/Hei33enberg/mosadd-os",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1362,
          "first_published_at": "2026-05-31T00:38:30.158000Z",
          "latest_published_at": "2026-06-27T12:55:08.990000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        },
        {
          "name": "@mosadd/providers",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@mosadd/providers",
          "is_deprecated": false,
          "latest_version": "3.0.0-alpha.26",
          "repository_url": "https://github.com/Hei33enberg/mosadd-os",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1230,
          "first_published_at": "2026-05-31T00:38:45.495000Z",
          "latest_published_at": "2026-06-27T12:55:12.653000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": true,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "apps/channel0-ext/tsconfig.json",
        "apps/dev/tsconfig.json",
        "apps/edge/tsconfig.json",
        "apps/embed/tsconfig.json",
        "apps/hub/tsconfig.json",
        "apps/mcp-http/tsconfig.json",
        "apps/murl-www/tsconfig.json",
        "examples/anthropic/tsconfig.json",
        "examples/langchain/tsconfig.json",
        "examples/vercel-ai/tsconfig.json",
        "packages/agent/tsconfig.json",
        "packages/ai/tsconfig.json",
        "packages/bridges/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/crypto/tsconfig.json",
        "packages/mcp/tsconfig.json",
        "packages/protocol/tsconfig.json",
        "packages/providers/tsconfig.json",
        "packages/skins/tsconfig.json",
        "packages/threat-engine/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 41666,
      "source_files_sampled": 302,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 3526
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 2
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 113,
        "malicious_count": 0,
        "assessed_package": "npm:@mosadd/ai@3.0.0-alpha.26",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@supabase/supabase-js",
          "manifest": "apps/dev/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.106.2"
        },
        {
          "name": "@vercel/analytics",
          "manifest": "apps/dev/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.1"
        },
        {
          "name": "next",
          "manifest": "apps/dev/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.1.6"
        },
        {
          "name": "posthog-js",
          "manifest": "apps/dev/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.176.0"
        },
        {
          "name": "react",
          "manifest": "apps/dev/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "react-dom",
          "manifest": "apps/dev/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "@supabase/ssr",
          "manifest": "apps/hub/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.5.2"
        },
        {
          "name": "@supabase/supabase-js",
          "manifest": "apps/hub/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.49.4"
        },
        {
          "name": "@vercel/analytics",
          "manifest": "apps/hub/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.1"
        },
        {
          "name": "next",
          "manifest": "apps/hub/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.2.4"
        },
        {
          "name": "react",
          "manifest": "apps/hub/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "react-dom",
          "manifest": "apps/hub/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "apps/mcp-http/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.4"
        },
        {
          "name": "@mosadd/mcp",
          "manifest": "apps/mcp-http/package.json",
          "ecosystem": "npm",
          "version_constraint": "3.0.0-alpha.23"
        },
        {
          "name": "@vercel/analytics",
          "manifest": "apps/murl-www/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.1"
        },
        {
          "name": "next",
          "manifest": "apps/murl-www/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.1.6"
        },
        {
          "name": "posthog-js",
          "manifest": "apps/murl-www/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.176.0"
        },
        {
          "name": "react",
          "manifest": "apps/murl-www/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "react-dom",
          "manifest": "apps/murl-www/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "@mosadd/mcp",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@mosadd/mcp",
          "manifest": "packages/ai/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@mosadd/core",
          "manifest": "packages/bridges/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@mosadd/protocol",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@noble/ciphers",
          "manifest": "packages/crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "@noble/curves",
          "manifest": "packages/crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.1"
        },
        {
          "name": "@noble/hashes",
          "manifest": "packages/crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.1"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.4"
        },
        {
          "name": "@mosadd/crypto",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@mosadd/protocol",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@mosadd/providers",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@mosadd/threat-engine",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@supabase/supabase-js",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.48.0"
        },
        {
          "name": "zod",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "zod",
          "manifest": "packages/protocol/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "@mosadd/core",
          "manifest": "packages/providers/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 29,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "Hei33enberg",
          "commits": 347,
          "avatar_url": "https://avatars.githubusercontent.com/u/201495027?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "coordinate-parity.yml",
        "deploy-edge.yml",
        "gitleaks.yml",
        "license-check.yml",
        "link-check.yml",
        "publish-mcp-registry.yml",
        "publish-vtg-mcp.yml",
        "publish.yml",
        "realm-ledger.yml",
        "release-drafter.yml",
        "sbom.yml",
        "skill-lint.yml",
        "stale.yml",
        "welcome.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool detected: CodeQL",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "45 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9d2a3d9a6e2e6e1c1dafec4c75d28422ad222bcb",
        "ran_at": "2026-07-24T14:53:18Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T06:35:33Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-06-19T13:11:57Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 31,
          "created_at": "2026-07-20T07:33:33Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Hei33enberg/mosADD-OS",
    "host": "github.com",
    "name": "mosADD-OS",
    "owner": "Hei33enberg"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 46,
        "vitality": 72,
        "community": 49,
        "governance": 43,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 72,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 352,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "352 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 352
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 15,
              "latest_release_tag": "v0.2.12",
              "releases_from_tags": false,
              "days_since_latest_release": 2,
              "mean_days_between_releases": 1.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "15 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 49,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 67,
            "inputs": {
              "packages": [
                "@mosadd/ai",
                "@mosadd/mcp",
                "@mosadd/core",
                "@mosadd/agent",
                "@mosadd/crypto",
                "@mosadd/bridges",
                "@mosadd/protocol",
                "@mosadd/providers"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 10085
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "10,085 downloads/month across npm",
                "points": 53.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 10085,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 43,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 37,
            "inputs": {
              "merged_prs": 29,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "29/30 decided PRs merged",
                "points": 37,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 29,
                      "decided": 30
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 39,
            "inputs": {
              "followers": 37,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "Hei33enberg",
              "public_repos": 9,
              "account_age_days": 508
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "37 followers of Hei33enberg",
                "points": 11.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 37,
                      "login": "Hei33enberg"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "9 public repos, account ~1 yr old",
                "points": 10.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 9
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@mosadd/ai",
                "@mosadd/mcp",
                "@mosadd/core",
                "@mosadd/agent",
                "@mosadd/crypto",
                "@mosadd/bridges",
                "@mosadd/protocol",
                "@mosadd/providers"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "8 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 8,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "31 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "16 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "agents",
                "ai-agents",
                "anthropic",
                "claude",
                "cursor",
                "e2ee",
                "end-to-end-encryption",
                "mcp",
                "mcp-server",
                "messaging",
                "model-context-protocol",
                "open-source",
                "typescript"
              ],
              "has_wiki": true,
              "homepage": "https://mosadd.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://mosadd.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "13 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected: CodeQL",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "45 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@mosadd/ai@3.0.0-alpha.26 runtime dependency closure — what installing the published package pulls in — 113 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@mosadd/ai@3.0.0-alpha.26",
                  "assessed": 113
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 113,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.14 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.14 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 113,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 75,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 0.97,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 3526
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "apps/channel0-ext/tsconfig.json",
                "apps/dev/tsconfig.json",
                "apps/edge/tsconfig.json",
                "apps/embed/tsconfig.json",
                "apps/hub/tsconfig.json",
                "apps/mcp-http/tsconfig.json",
                "apps/murl-www/tsconfig.json",
                "examples/anthropic/tsconfig.json",
                "examples/langchain/tsconfig.json",
                "examples/vercel-ai/tsconfig.json",
                "packages/agent/tsconfig.json",
                "packages/ai/tsconfig.json",
                "packages/bridges/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/crypto/tsconfig.json",
                "packages/mcp/tsconfig.json",
                "packages/protocol/tsconfig.json",
                "packages/providers/tsconfig.json",
                "packages/skins/tsconfig.json",
                "packages/threat-engine/tsconfig.json"
              ],
              "agent_commit_share": 0.92,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "apps/channel0-ext/tsconfig.json, apps/dev/tsconfig.json, apps/edge/tsconfig.json, apps/embed/tsconfig.json, apps/hub/tsconfig.json, apps/mcp-http/tsconfig.json, apps/murl-www/tsconfig.json, examples/anthropic/tsconfig.json, examples/langchain/tsconfig.json, examples/vercel-ai/tsconfig.json, packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/bridges/tsconfig.json, packages/core/tsconfig.json, packages/crypto/tsconfig.json, packages/mcp/tsconfig.json, packages/protocol/tsconfig.json, packages/providers/tsconfig.json, packages/skins/tsconfig.json, packages/threat-engine/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "apps/channel0-ext/tsconfig.json, apps/dev/tsconfig.json, apps/edge/tsconfig.json, apps/embed/tsconfig.json, apps/hub/tsconfig.json, apps/mcp-http/tsconfig.json, apps/murl-www/tsconfig.json, examples/anthropic/tsconfig.json, examples/langchain/tsconfig.json, examples/vercel-ai/tsconfig.json, packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/bridges/tsconfig.json, packages/core/tsconfig.json, packages/crypto/tsconfig.json, packages/mcp/tsconfig.json, packages/protocol/tsconfig.json, packages/providers/tsconfig.json, packages/skins/tsconfig.json, packages/threat-engine/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "92 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 92,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 41666,
              "source_files_sampled": 302,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/302 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 302,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T14:53:23.602339Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/h/Hei33enberg/mosADD-OS.svg",
  "full_name": "Hei33enberg/mosADD-OS",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.