Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 2.5.0 · 2026-07-29 11:40 UTC

chanceryhq / chancery

The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.

Go · HTMLApache-2.0★ 25 estrellas⑂ 1 forkdesde jul 2026Ver en GitHub ↗
TipoServidor MCPHerramienta de línea de comandoscómo se determina

chanceryhq/chancery tiene un índice de salud de 59 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (67/100) y la más baja, Community & Adoption (44/100). Se actualizó por última vez hace 8 días. Una sola persona concentra la mayor parte del trabajo reciente.

59
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala estandarizada de 1 a 100. El resultado global parte de su media ponderada, calibrada contra la distribución del registro público para que las bandas tengan significado percentil; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe un límite «En riesgo» de 34.

59
Excepcional93-100El nivel más alto del registro (≈ el 5% superior); cumple prácticamente todos los criterios evaluados
Excelente80-92Sólido en todos los frentes; carencias menores
Bueno65-79Saludable; carencias limitadas y manejables
Moderado50-64Aceptable con carencias notables; se recomienda revisión
Débil35-49Debilidades sustanciales en varias áreas
En riesgo20-34Debilidades significativas; su adopción exige cautela
Crítico1-19Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

El resultado global ponderado 56 se calibra a 59 en la escala publicada del índice (calibración del registro 2026-08-02).

Titularidad

chanceryhqOrganización
0 seguidores2 repositorios públicosdesde jul 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/chanceryhq/chanceryv0.2.0-3hace 8 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

67Bueno · 21% del índice global
Cómo se puntúa
28.8/36Recencia de push — último push hace 8 días
2.1/36Cadencia de commits — 3/52 semanas con commits
15.4/18Volumen de commits — 51 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year51
human_commit_share1
days_since_last_push8
active_weeks_last_year3
Cómo se puntúa
27/27Publica versiones — 2 versiones publicadas
36/36Recencia de las versiones — última versión hace 8 días
27/27Cadencia de publicación — una versión cada ~8,7 días
8/10OpenSSF Scorecard: Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
Datos de entrada utilizados
releases_count2
latest_release_tagv0.2.0
releases_from_tagsno
days_since_latest_release8
mean_days_between_releases8,7

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

44Débil · 17% del índice global
Cómo se puntúa
22.4/60Estrellas — 25 estrellas
0/25Forks — 1 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks1
stars25
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
18/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
readme_badges
has_contributing
has_issue_templateno
has_code_of_conductno
readme_badge_services
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

48Débil · 23% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
42/42Resolución de issues — 100% de issues cerradas
0/30Aceptación de PR — sin PR decididos o sin datos
0/13Newcomer PR acceptance — ningún PR de un contribuyente primerizo decidido en 30 d
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues0
closed_issues6
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs0
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Excluidos de la puntuación (sin datos o no aplicable): Aceptación de PR, newcomer_pr_acceptance. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
0/25Alcance del propietario — 0 seguidores de chanceryhq
3.6/25Trayectoria — 2 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers0
owner_typeOrganization
is_verified
owner_loginchanceryhq
public_repos2
account_age_days24
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 8 días
12/20Historial de versiones — 3 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/chanceryhq/chancery
ecosystemsgo
any_deprecatedno
min_days_since_publish8

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

66Bueno · 19% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 2 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
10/10Topics — 20 topics
0/10Wiki
Datos de entrada utilizados
topicsai-agents, iam, identity, mcp, security, agents, credentials, tools, multi-agent, spawn, browser, browser-automation, hierarchy, cookies, password, mcp-client, mcp-server, mcp-tools, audit, audit-log
has_wikino
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

52Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
2/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4
Excluidos de la puntuación (sin datos o no aplicable): ci_tests. Los pesos restantes se han renormalizado.
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
0/25Dependencias indirectas libres de avisos conocidos — el conjunto transitivo no es separable de las dependencias de desarrollo y prueba en este alcance
0/40Sin avisos pendientes — ningún aviso tiene fecha de publicación
Datos de entrada utilizados
sourceosv
advisories0
affected_packages0
assessed_packages15
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluidos de la puntuación (sin datos o no aplicable): Dependencias indirectas libres de avisos conocidos, Sin avisos pendientes. Los pesos restantes se han renormalizado. Se cotejaron 15 dependencias resueltas con OSV. Este repositorio no publica ningún paquete que el índice resuelva, por lo que se evaluó en su lugar el grafo de dependencias del repositorio. Ese grafo mezcla fijaciones de desarrollo y prueba con las dependencias distribuidas, de modo que solo se puntúan las dependencias declaradas en tiempo de ejecución; los hallazgos transitivos se informan como contexto y quedan excluidos de la puntuación. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Tiene un peso deliberadamente pequeño (4%): las herramientas para agentes son una señal real de mantenimiento, pero un repositorio sin ninguna puede alcanzar igualmente 100/100.

57Moderado · 4% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 49 de 51 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,961
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
18/18Arranque con un solo comando — Makefile
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — Dockerfile, lockfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 51
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
55/55Tamaños de archivo manejables — 0/43 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes54.882
source_files_sampled43
oversized_source_files0
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
0/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signalno
api_schema_files

Datos clave

25estrellas de GitHub
1contribuidores
51commits en los últimos 12 meses
8días desde el último push
2versiones publicadas
1factor bus
0issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Más detalle

OpenSSF Scorecard 4.0 / 10
4.0agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-29 11:40 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
4Security-Policysecurity policy file detected
8Signed-Releases2 out of the last 2 releases have a total of 2 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Dependencias directas 4
RegistroPaqueteRestricción de versiónManifiesto
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/oklog/ulid/v2v2.1.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gomodernc.org/sqlitev1.53.0go.mod
Todas las dependencias 15

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 4 paquetes directos y 11 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
Gogithub.com/golang-jwt/jwt/v5v5.3.1directa
Gogithub.com/oklog/ulid/v2v2.1.1directa
Gogithub.com/spf13/cobrav1.10.2directa
Gomodernc.org/sqlitev1.53.0directa
Gogithub.com/dustin/go-humanizev1.0.1indirecta
Gogithub.com/google/uuidv1.6.0indirecta
Gogithub.com/inconshreveable/mousetrapv1.1.0indirecta
Gogithub.com/mattn/go-isattyv0.0.20indirecta
Gogithub.com/ncruces/go-strftimev1.0.0indirecta
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daecindirecta
Gogithub.com/spf13/pflagv1.0.9indirecta
Gogolang.org/x/sysv0.44.0indirecta
Gomodernc.org/libcv1.73.4indirecta
Gomodernc.org/mathutilv1.7.1indirecta
Gomodernc.org/memoryv1.11.0indirecta
Avisos de dependencias 0

Este repositorio no publica ningún paquete que el índice resuelva, así que se evaluó su propio grafo de dependencias — 15 paquetes, que incluyen también fijaciones de desarrollo y prueba que nunca se distribuyen: 0 tienen avisos conocidos, de los cuales 0 son directas.

Ningún aviso conocido afecta a las dependencias evaluadas.

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "iam",
        "identity",
        "mcp",
        "security",
        "agents",
        "credentials",
        "tools",
        "multi-agent",
        "spawn",
        "browser",
        "browser-automation",
        "hierarchy",
        "cookies",
        "password",
        "mcp-client",
        "mcp-server",
        "mcp-tools",
        "audit",
        "audit-log"
      ],
      "is_fork": false,
      "size_kb": 3499,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 334383,
        "CSS": 13532,
        "HTML": 44856,
        "Shell": 2180,
        "Makefile": 194,
        "Dockerfile": 367,
        "JavaScript": 8009
      },
      "pushed_at": "2026-07-21T07:39:20Z",
      "created_at": "2026-07-04T12:50:16Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T07:40:02Z",
      "description": "The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "HTML"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "chanceryhq",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/299839401?v=4",
      "created_at": "2026-07-04T12:48:19Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 24
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-20T13:47:41Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T22:04:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
          "body": "A broken ring forming a C, holding two bars that narrow. A chancery is\nthe office that keeps the seal, and the narrowing bars are the property\nthe whole product rests on: delegated authority can only shrink. The\nold mark was a generic pillar that said nothing specific and tied to\nthe name not at all\n[…]\nnly variant because the inner bars merge below\nabout 20px. Site favicon links move from an inline data URI to real\nPNGs, versioned so the old cached icon is replaced. README gets a\ntheme-aware lockup.",
          "is_bot": false,
          "headline": "brand: new mark, the seal",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-21T07:39:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80d9cd58cbe2238b0e143453390862dd1d5a9b6c",
          "body": "A different UID is the only boundary that actually holds here: ptrace\nchecks credentials, so being an ancestor stops helping. --run-as <user>\nspawns the server under its own UID, and the sealed-file run dir and\nits contents are chowned to that user so --secret-file keeps working.\n\nApproaches that lo\n[…]\n--confine).\n\nTightens the SECURITY.md invariant: 'agents never hold credentials' is\nprecise about the model's context and the agent's environment, not\nOS-level isolation from same-UID code. 109 tests.",
          "is_bot": false,
          "headline": "G17: ship --run-as privilege separation for the tool server",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:49:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a138f5c9f7ea2e54965fc7ef98452a9410a33f8",
          "body": "…bounded\n\nSealed secrets are injected into the tool server's environment, so\n/proc/<pid>/environ exposes them to any same-UID process — and to\nancestors under the default yama ptrace_scope=1. Since the agent\nruntime typically spawns the wrap, a hostile runtime (distinct from a\nprompt-injected model)\n[…]\nsolation from hostile code sharing the UID, and the tables now say so.\nDeployment guidance gains the mitigation: separate OS user, or\nptrace_scope>=2.\n\nReported by u/Psychological_Arm645 on r/AutoGPT.",
          "is_bot": false,
          "headline": "SECURITY: add G17 — credential isolation is UID-bounded, not process-…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:43:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d32ccacf283db6071737e282c3084043d1b30983",
          "body": "Anyone who loaded the page while /assets/* still carried\n'immutable, max-age=31536000' holds that CSS for a year and would never\nsee the aspect-ratio fix. A changed URL is a different cache entry, so\n?v=2 forces one clean refetch; the corrected Cache-Control keeps future\nedits reachable without this.",
          "is_bot": false,
          "headline": "site: version asset URLs to break the poisoned immutable cache",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:34:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c01ee77b008d9ce94938268146645d33d5fcb2e",
          "body": "/assets/* was pinned for a year with immutable, which covers style.css\nand app.js — filenames that never change. Any returning visitor would\nhave been stuck with stale CSS indefinitely (exactly how the squashed\n-image fix failed to appear). Images keep the year; CSS/JS revalidate\nwith ETag.",
          "is_bot": false,
          "headline": "site: don't immutably cache un-hashed CSS/JS",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:31:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4c1fb76583a8920460165fbc050caca3b950ae7",
          "body": "Images declared width/height 1600x1000 against real 2880x1720 assets,\nand the img rule lacked height:auto — so max-width squashed both\ndashboard shots. Corrected the declarations and added height:auto.\n\nCopy moves from personal-project voice to product voice: drops the\nfooter byline, 'Talk to me' becomes 'Get in touch', and the mailto\ntemplate loses its first-name salutation.\n\nPages is disabled (Vercel is canonical at chanceryai.vercel.app), so\nits deploy workflow goes with it.",
          "is_bot": false,
          "headline": "site: fix squashed screenshots, product voice, drop GitHub Pages",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:30:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8793fe7416176ba919088a83e052b1bd7572148f",
          "body": "Above-the-fold content was gated behind IntersectionObserver plus a\nstagger, so the hero sat blank for ~1s on load — bad on slow connections\nand worse for link-preview crawlers (Product Hunt, LinkedIn) that\nscreenshot early. You don't animate what's already on screen at load.",
          "is_bot": false,
          "headline": "site: render the hero immediately, animate only below the fold",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:25:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aa3eecf5267789b3dbcef3f1d937c0846ec2250",
          "body": "…rprise CTA\n\nReplaces the static brochure with a real page: a typed terminal replaying\nthe enforcement story (grant → allow → deny → revoke → deny), scroll\nreveals, a flow diagram of the gate, tabbed workflows, dashboard shots,\nand an enterprise section with a prefilled mailto.\n\nAccessibility/robust\n[…]\nmotion renders everything static.\n\nZero third-party requests: system fonts, no CDN, no analytics — which\nlets the CSP be default-src 'none' with 'self' for script and style, no\nunsafe-inline anywhere.",
          "is_bot": false,
          "headline": "site: proper landing page — animated terminal, interactive tabs, ente…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:24:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a994cad55be9fa2f2df015fb43a2dc34f68a3626",
          "body": "The README had grown into a manual — 280 lines, five inlined feature\nwalkthroughs, and a 19-row RFC table. Now 126 lines: what it is, why,\ninstall, one real end-to-end example, a compact capability list, and a\ndocs table pointing at the material that already exists elsewhere.\n\nrfcs/README.md is a ge\n[…]\nthem.\n\nAdds vercel.json (static site/ deploy, security headers, immutable\nasset caching) and puts the dashboard screenshots on the landing page,\nwhere they earn their space, rather than in the README.",
          "is_bot": false,
          "headline": "README: cut to essentials; RFC index moves to rfcs/README.md",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:53:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2951e92fed8107967433eb31976ade7c7abaee81",
          "body": "Drops the pre-alpha label. Every design RFC moves from In Review to\nLocked (design settled and implemented); README gains a Status section\nstating what beta does and doesn't promise — the security model is\nsettled and gaps are published, but CLI/REST may still break before\n1.0.\n\nAdds CHANGELOG.md (v\n[…]\ne landing page from\nRFC-010's MVP item 8, deployed to Pages by a workflow. Assets are\nlocal to site/ because raw.githubusercontent serves a sandbox CSP that\nblocks embedding.\n\n105 tests, go vet clean.",
          "is_bot": false,
          "headline": "v0.2.0: beta — lock all 19 RFCs, add changelog and landing page",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:44:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f8ae24a4e62376dc098647d28a20b9ffff852df",
          "body": "POST /v1/leases/verify accepts optional xref=<system>:<opaque-id>\n(shape-checked, 400 on malformed). On a VALID lease it is recorded as\nmcp.call_xref carrying the lease's writ, agent, and resource plus the\nopaque foreign id — the one moment two audit chains describe the same\nevent. Invalid leases re\n[…]\n cooperating servers read wid/blk from the lease they\nalready hold.\n\nVerifyLease now returns full LeaseInfo claims. Dashboard event map,\nverify.md walkthrough, RFC-015 amendment; 105 tests. Closes #6.",
          "is_bot": false,
          "headline": "RFC-015 §10: audit cross-references at lease-verify (xref)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T11:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2af06ebc129d9273eb227fc369b2c2514041c525",
          "body": "What-you-get bullet list up top (one line per RFC arc); the RFC-015-018\nmechanisms broken out of the dense paragraph into two sections with\nrunnable commands (callee trust: install/pin/confine/dry-run; per-call:\ntask/intent/lease); matching subheadings for the spawn, wrap, browser,\nand control-plane blocks so 'Try it' reads as one tour.",
          "is_bot": false,
          "headline": "README: capability summary + structured tour",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T10:04:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "571e1a2963ada4a3f5575395681b03daea3a0dc0",
          "body": "chancery mcp install <pkg>@<exact-version>: one-time npm install\n(scripts disabled, local paths copied not symlinked) into\n$CHANCERY_DATA/servers/<ns>, Merkle tree-pinned automatically;\nmutable specs refused — a mutable reference is not an identity. A\ntree pin now follows its namespace: plain wraps \n[…]\n), G16 added (host-granular\negress; Linux egress cooperative until netns). 104 tests / 11\npackages, including confinement against the real OS sandbox and the\ninstall→pin→poison→refusal arc. Closes #5.",
          "is_bot": false,
          "headline": "RFC-018: frozen installs and manifest-bounded confinement",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T18:02:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17188a83ae5cb093f26c31dd322055bde05a5bc3",
          "body": "Pins are now (kind, identity) pairs — strongest applicable tier wins:\n\nT3 digest: a container image reference pinned by digest in the server\nargs (image@sha256:...) becomes the identity automatically; mutable\ntags are never identities. Chancery verifies the reference, the\ncontainer runtime verifies \n[…]\ndence, poisoned-dependency e2e).\nG13 narrowed in SECURITY.md/RFC-009: the gap is now the DEFAULT's,\nwith shipped opt-in mitigations; RFC-016 rewritten around the tiers;\nREADME/concepts/verify updated.",
          "is_bot": false,
          "headline": "RFC-016 T2/T3: tree pinning and image-digest pinning",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T17:32:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f58fa4dabcd50b6d276d4b45c78b96dd81c2397",
          "body": "Closes three roadmap issues born from practitioner review:\n\nRFC-015 (#2): the audit trail now distinguishes admitted from happened\n(mcp.call_result committed/failed), and 'mcp wrap --lease' stamps each\nadmitted call with a 30s signed lease in params._meta that cooperating\nservers verify via POST /v1\n[…]\ns only. Arguments pass through transiently and are\nnever stored.\n\n89 tests across 10 packages; gaps G13-G15 added to SECURITY.md and\nRFC-009; RFC-000/005/008 amended; concepts/verify/playbook updated.",
          "is_bot": false,
          "headline": "RFC-015/016/017: call lifecycle + leases, server pinning, intent socket",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T13:40:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c5b18a698b73f9996d4ec7da119e81c678d0227",
          "body": null,
          "is_bot": false,
          "headline": "README: dashboard screenshots (audit timeline, writ delegation tree)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T09:10:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f6dda69f002ff36396e2bde4ed36b6eeef33258",
          "body": "asciinema cast + GIF (embedded in README) recorded against the\nbrew-installed v0.1.0 binary in an isolated CHANCERY_DATA dir;\ndemo/demo-driver.sh regenerates it.",
          "is_bot": false,
          "headline": "Demo recording: 40-second grant/allow/revoke/deny/audit arc",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T08:27:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da257f750e929f7481066130ac5b328b88b08935",
          "body": "Without it, macOS quarantines the un-notarized binary and newer\nreleases delete it from the Caskroom seconds after install, leaving\na dangling /opt/homebrew/bin/chancery symlink.",
          "is_bot": false,
          "headline": "Cask post-install hook: strip Gatekeeper quarantine from the binary",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T22:01:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21d06772e4ede9099ee70fa1feb02c98dc9fe0b0",
          "body": null,
          "is_bot": false,
          "headline": "Ignore local Stitch design exports",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:53:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae937837791311f5b3b92ffdf7314571a14fe9d1",
          "body": "Void background, seal-purple accent, dual-font ledger (Inter UI /\nmono identity data), per-tab stat cards, uppercase mono table\nheaders, writ cards with boxed delegation-tree nodes and right-angle\nconnectors. Same read-only data plumbing: token gate, 4s polling,\nintegrity pill, text-node-only rendering.",
          "is_bot": false,
          "headline": "Dashboard visual redesign from the Stitch design system",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:40:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bda521f3cb7340b4090aa36ff1290bd46d259e6",
          "body": "…ty chips\n\n- timeline speaks human: 'Authority granted to deploy-bot', 'Agent\n  spawned: worker-1', 'Spawn refused' — raw event name demoted to a\n  small mono subline; category dots (grant/action/security/lifecycle)\n- times are relative ('12m ago', 'in 2h') with the full timestamp on\n  hover; templa\n[…]\nnt/caveats\n  (display only, unverified) so narrowing is visible at a glance\n- owners shown as emails (user: prefix stripped); writ ids demoted to\n  hover/sublines; agents show 'spawned by orch' origin",
          "is_bot": false,
          "headline": "Dashboard readability: plain-English events, relative times, capabili…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:38:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e87f007d2020e4c69ada4cae36aefb66db9246b3",
          "body": "The product's proof is visual — the timeline and the delegation tree —\nso chancery serve now ships a dependency-free, go:embed'd dashboard:\n\n- live audit timeline (filterable, ALLOW/DENY pills, agent names\n  resolved) with a permanent integrity badge backed by audit verify\n- agent roster with state \n[…]\nee, JWS omitted) — the\n  route RFC-008 documented but the MVP never implemented\n- verified live in a browser across all four views; 79 tests; docs,\n  playbook step 8, SECURITY G12, RFC-000/009 updated",
          "is_bot": false,
          "headline": "RFC-014: embedded read-only dashboard at /ui",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:32:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba10d2e3f466d755936ce507a950853210337b51",
          "body": "Denials are answered immediately by the proxy while allowed calls\nround-trip through the server, so the deny usually prints first; the\nsh stub always replies with id 0. Show the exact expected lines and\nadd a troubleshooting row so neither reads as a failure.",
          "is_bot": false,
          "headline": "Playbook step 5: document response ordering and the stub's id:0",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T07:43:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db1a4e2b7c469a7fcbf5a8160cd04a963bbd345b",
          "body": "One ~20-minute sitting: identity/versioning, delegation-only-narrows,\nsealed secrets (grep-for-plaintext), layered policy (allowlist\nsubtracts at the ACTING agent's block, never adds), in-path MCP\nenforcement as the delegated agent, audit tamper detection, lifecycle\nterminality, DENY-as-200 over HTT\n[…]\n the real pitfalls hit\nduring Vantage dogfooding (zsh comments, split heredocs, lost env\nvars, silenced stderr, wrap-awaits-client, exact host matching).\nLinked from README, docs index, and verify.md.",
          "is_bot": false,
          "headline": "Add docs/testing-playbook.md: guided run of every feature (001-013)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-06T04:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33a6c83780c65f4d56f517e94f71b26057ff2c12",
          "body": "Browser agents inherit human sessions — bearer, unscoped, invisible to\nIAM. This makes the session a credential and the navigation an action:\n\n- session custody: mcp wrap --secret-file materializes sealed storage\n  state (cookies) as a 0600 file in a private run dir the SERVER reads\n  (chancery-file\n[…]\naywright MCP recipe\n  (--isolated --storage-state=chancery-file:STATE)\n- 6 new tests incl. full browser e2e (78 total); RFC-000/005/009\n  amended; SECURITY.md gap G11; concepts + verify guides updated",
          "is_bot": false,
          "headline": "RFC-013: browser sessions and tokens as governed credentials",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T18:15:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d19a05fa20aaa000337c5f2a8aeabff8bf4d683",
          "body": "Orchestrators that create agents at runtime (the common multi-agent\npattern) no longer need the admin token. Spawning is itself a\nwrit-governed action:\n\n- admin verb joins the capability grammar (RFC-004 amended);\n  Cap.Implies subsumption for template ceilings\n- templates: human-approved max caps +\n[…]\nly (ActiveErr everywhere);\n  chancery agent sweep retires; agent list shows expired state\n- 10 new tests (72 total); RFC-000/004/007/008/009 amended;\n  SECURITY.md gap G10; docs + verify guide updated",
          "is_bot": false,
          "headline": "RFC-012: dynamic agent creation — writ-gated runtime spawn",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T17:49:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a125b8f2e82d63681ac9488bdd1e5fcd3753809",
          "body": "All four surfaced by testing against a real multi-agent system:\n\n#1 (footgun) mcp wrap --agent X now evaluates X's own writ block, not\n   the writ's latest block (which may belong to a delegated sub-agent).\n   New store.BlockForSubject; explicit --block is verified against\n   --agent. Previously a r\n[…]\n\n   check) — no more granting writs to revoked agents.\n\nTests: block-for-subject selection + narrowing, grant-refuses-inactive,\nno-block-for-agent is ErrNotFound. All 10 packages green; verified live.",
          "is_bot": false,
          "headline": "Fix 4 findings from live Vantage dogfooding",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T10:14:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a9575a3e62c91ef3c30492e55890a1e0a6bbb9b",
          "body": "User-facing verification guide: hands-on, CLI-only, copy-paste checks\nthat each RFC 001-009 does what it claims, with real expected output,\nseparate from the go test suite. Every block was run to capture real\noutput before documenting (caught and fixed an allow-list usage error\nin the draft).\n\nAlso \n[…]\nCLI surface (re-register errored). Added\n'chancery agent version <name>' + service.AddVersion (immutable, keeps\nhistory, emits shadow-agent event on unknown agent), tested. README\nlinks the new guide.",
          "is_bot": false,
          "headline": "Add docs/verify.md (verify each RFC by hand) + agent version command",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T09:04:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6ed6e38b6b0299014391a47ef9d9bd860bd1951",
          "body": "Adds the honest general-purpose story and a non-MCP setup+test\nwalkthrough. Distinguishes the two governance modes: in-path/enforced\n(MCP today, unbypassable) vs advisory/check (any agent, any language,\ntoday via POST /v1/writs/{id}/check + SDK Guard). Shows a plain DB ETL\nagent governed by read:/write: writs with instant revocation and\ntamper-evident audit — verified working via CLI and HTTP before\ndocumenting. README gains the MCP-first-not-MCP-only framing up top.",
          "is_bot": false,
          "headline": "docs: governing any agent (MCP-first, not MCP-only)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:52:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0588ee17c51534a86b5a27062c72789de75c121e",
          "body": "Fills the developer-setup gap: prerequisites (Go 1.26+, no CGO), build,\nrunning tests (incl. -short to skip the subprocess integration test and\nmake demo), a table mapping all 10 packages' tests to the RFC each\nproves, the repo layout, conventions (RFC discipline, the two non-\nnegotiable invariants), and the DCO (no CLA) contribution flow. README\ngains a 'Build & test from source' section linking it.",
          "is_bot": false,
          "headline": "Add CONTRIBUTING.md: build, test, repo layout, RFC-to-test map",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:13:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f131570e62cce1866e03039cecac971fcda80039",
          "body": "Captures the launch checklist durably (out of chat): pre-tag gates\n(3 real users, demo cast, quickstart re-verified), one-time org/repo\nsettings (public packages, chancery.dev, Pages, vuln reporting), the\nrelease cut + verify steps, announce channels, and known non-blocking\nfollow-ups. Release pipeline proven via a private v0.0.1 dry-run.",
          "is_bot": false,
          "headline": "Add LAUNCH.md — go-live runbook and gates",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:48:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bf60180aa7a9f2008e5b24bb637e5c867287537",
          "body": "The homebrew_casks repository block had no token, so goreleaser used\nthe default Actions token (cannot write cross-repo) and the tap push\n403'd. Point it at HOMEBREW_TAP_GITHUB_TOKEN (set from the\nTAP_GITHUB_TOKEN secret in release.yml).",
          "is_bot": false,
          "headline": "release: use the tap PAT for the Homebrew cask push",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:36:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ca5aa7ac8534a2d1a534cea9644079b27dde453",
          "body": "… docs\n\nWeek 4 (quickstart): QUICKSTART.md walks governing the real official\nfilesystem MCP server; a permanent CI-safe end-to-end test\n(cmd/chancery/wrap_integration_test.go) spawns a real child MCP server\nprocess and proves list-filter/allow/deny/mid-session-revoke + audit\nintegrity. Verified manu\n[…]\nd against a real\nhttptest control plane.\n\nWeek 8 (docs): docs/ for GitHub Pages (native Jekyll from /docs, no CI),\nindex + concepts; README gains a Guides section.\n\nAll 10 packages green; gofmt clean.",
          "is_bot": false,
          "headline": "weeks4-8: real-server quickstart, examples, shadow-agent obs, Go SDK,…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T19:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac965281b9e04516f8498cf2b57a0ad9eac2f3fe",
          "body": "Cross-platform static binaries (linux/darwin x amd64/arm64), multi-arch\ndistroless image to ghcr.io (dockers_v2 + buildx), Homebrew cask on\nchanceryhq/homebrew-tap, per-archive SBOM (syft), keyless cosign signing\nof checksums via GitHub OIDC. Version/commit/date injected via ldflags;\nchancery --vers\n[…]\n+ generated cask). Image cosign signing is a noted\nfast-follow pending dockers_v2 signing surface.\n\nPrereqs for first real release: create chanceryhq/homebrew-tap repo and\nset TAP_GITHUB_TOKEN secret.",
          "is_bot": false,
          "headline": "weeks2-3: release packaging — goreleaser, cosign, SBOM, Docker, brew",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:16:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7129083f873f8c9dda21496e9220f945bb4aa81",
          "body": "CLI register/instance-start/grant/delegate/check now call\ninternal/service (RFC-008 §4: one implementation shared with the HTTP\nAPI) instead of duplicating store+writ+policy logic; the mcp wrap\ndecider reuses service.Decide, keeping only the PEP-specific instance-\nliveness gate. Removes ~120 lines o\n[…]\ndecision for PEPs) and\nstore.AuditSince (tail cursor). New: chancery audit --follow streams\nevents live for the demo (ALLOW scrolls, DENY appears on revoke).\nAll tests green; demo and follow verified.",
          "is_bot": false,
          "headline": "week1: route CLI through the service layer; add audit --follow",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:11:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7d2dbe68328369e5898d40acc5173c09c95a0668",
          "body": null,
          "is_bot": false,
          "headline": "gitignore: exclude local tooling state",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57463e9fcc76f52877e402045bfae85b02943f79",
          "body": "Founder decision: defer chancery.dev (~$12/yr) until revenue; docs on\nchanceryhq.github.io; vulnerability reporting via GitHub private\nreporting (an improvement regardless — no email infra, built-in CVE\nworkflow). Squatting risk on the public name recorded in RFC-010.",
          "is_bot": false,
          "headline": "Free-domain path: GitHub Pages + private vulnerability reporting",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a86663237e5e0dcac9a95dde22c09690298bcf2",
          "body": "Locks: boundary test (single-trust-domain security/operability = OSS;\norg-scale value = enterprise); two published promises (no license\nflip ever; security never paywalled — all G1-G9 close in OSS); locked\nledger (Cedar/approvals/Postgres/all PEPs OSS; SSO/SCIM, multi-\ntenancy, SIEM exporters, compl\n[…]\nin OSS schema;\nchancery-ee orchestrates per-tenant cores over the public API); DCO\nno CLA (relicensing door welded shut); lockstep releases. Apache-2.0\nLICENSE at root. This closes RFC series 000-011.",
          "is_bot": false,
          "headline": "RFC-011: open-core boundary — the test, the ledger, the two promises",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c006c9542f6a94614e552c3a0316192d49a409ca",
          "body": "Locks: MVP = v0.1.0 with the enforcement wedge (registry inside it);\n12-week plan (CLI->service migration, packaging w/ cosign+SBOM, real-\nserver quickstart, Claude Code + LangGraph examples, shadow-agent\nobservation v0, Go SDK, docs, 3 external users before tag); demo\nscript locked word-for-word; c\n[…]\nadmap, HTTP/shell/browser PEPs, PoP, Cedar, Postgres to v1).\nShips: SECURITY.md (gap table G1-G9, invariants you can hold us to),\nMakefile, scripts/demo.sh (the 60-second arc, CI-runnable — verified).",
          "is_bot": false,
          "headline": "RFC-010: MVP scope — the 90-day build, demo locked, cutlines named",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a1385a3340e2cf8d1a5984481726a8e65a04dce",
          "body": "Research at series close (OWASP ASI, CSA MAESTRO/agentic IAM, Gartner\nguardian agents + agent sprawl): the five defining questions were all\noutbound and known-population. Added Q6 (inbound/agent-to-agent trust\n- ASI07, ~24% org visibility) and Q7 (unregistered agents - discovery\nas a byproduct of en\n[…]\nis\nthe product, ASI06 memory poisoning is the argued scope line) and\nadopts MAESTRO as process reference. Positioning notes: deterministic\nguardian layer, proportional governance as writ policy packs.",
          "is_bot": false,
          "headline": "RFC-000/009 addenda: extended question set and agentic Top 10 mapping",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61d1ed6a95da0469e2c2d6b28e33841d2ab8c1c2",
          "body": "…table\n\nLocks: trust boundaries (model untrusted, operator trusted in MVP,\nserver semi-trusted); STRIDE walk per component; OWASP LLM Top 10\nmapping (LLM06 excessive agency is the product); abuse cases walked;\npublished MVP gap table G1-G9 each with owner and phase (bearer docs,\nsingle admin token, \n[…]\nI-gated:\nalg:none rejection for both token types, HS256 key-confusion rejection,\ncross-writ block substitution, unsigned delegation block on signed\nchain, exp-required, capability-free grants refused.",
          "is_bot": false,
          "headline": "RFC-009: threat model — STRIDE, OWASP LLM Top 10, and the honest gap …",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:39:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb12309ebc1cdce1d65b1576e9eea3c738328596",
          "body": "… serve\n\nLocks: Vault-style REST/JSON under /v1 mirroring the principal model;\nDDL as the data contract (SQLite->Postgres behind the store seam);\ndigests-only registration (D6 extended to the wire); admin bearer token\n(hashed at rest, constant-time compare, failures audited) with v1 path\nto identity\n[…]\ntest full flow (register->instance->grant->ALLOW->revoke->\nDENY-at-registry->resurrection-blocked), auth rejection + audit, DENY-as-\n200, delegation+attenuation over HTTP, token never in audit stream.",
          "is_bot": false,
          "headline": "RFC-008: data model and APIs — REST/JSON /v1, service layer, chancery…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:36:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2779517ee71678f960df1621d7b87ff7e38acf4",
          "body": "…eans terminal\n\nLocks: per-layer state machines (agent active⇄suspended→retired/revoked,\norphaned exits only via ownership transfer); terminality enforced at the\ndata layer (no client can resurrect); suspend/revoke/retire/orphan as\ndistinct audited verbs; nothing ever deleted; cascade-by-check (one\n\n[…]\n TTL.\nchancery agent retire/orphan/transfer + terminality warnings.\nTests: full transition matrix, no-resurrection property, orphan blocks\nissuance until transfer, retired names not silently reusable.",
          "is_bot": false,
          "headline": "RFC-007: lifecycle and revocation — locked state machines, terminal m…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:32:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05f6f7fa1748ecce37a4f252c617a6cc2e1c7cff",
          "body": "Locks: fixed metadata-only schema (no payload columns — D6 by DDL),\nhash-chained events (prev_hash + SHA-256 over canonical encoding,\ngenesis sentinel), single-writer chain append, locked event taxonomy,\nattribution embedded per row (agent/instance/writ/lineage), NDJSON\nexport, deny-on-audit-failure\n[…]\nappen). chancery audit verify walks the chain and names the first\nbreak. Tests: clean verify, edit/deletion detection with prefix\nproperty, attribution round-trip, allowed-but-unauditable call denied.",
          "is_bot": false,
          "headline": "RFC-006: audit and attribution — hash-chained, metadata-only evidence",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:29:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26b52f631392dc52407f3bb27ba87663fad8672a",
          "body": "Locks: protocol-aware stdio proxy that owns the server process; per-call\nPDP with fresh registry state (revocation = next call, not next TTL);\ntools/list filtered, tools/call enforced (filtering is UX, the call path\nis the boundary); JSON-RPC -32001 denials naming the layer; sealed\nsecrets injected \n[…]\nrnal/mcp +\nchancery mcp wrap. Unit tests: forward/deny/filter/malformed/no-name/\npassthrough. Live integration test passed: mid-session agent revocation\nblocked the next call with attributed timeline.",
          "is_bot": false,
          "headline": "RFC-005: runtime enforcement — the MCP proxy, in-path and unbypassable",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:19:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44e030d20c5683cf7b0f700a0c5bfaadf9169242",
          "body": "Locks: conjunction of layers where only the writ grants (L1) and every\nother layer only denies — allow-lists (L2, MVP), Cedar org policy (L3,\nv1), approvals with reserved 'hold' effect (L4, v1); default-deny;\ncapability grammar locked (verb registry, /-segmented resources,\ntrailing-* with subtree-vs\n[…]\n delegates to it;\nper-agent tool_allowlists + 'chancery agent allow'. Tests: grammar\nvalidity table, match semantics table, layer attribution, empty-list vs\n!none sentinel, nil-authority default deny.",
          "is_bot": false,
          "headline": "RFC-004: policy and authorization — layered PDP, locked grammar",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:14:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d739d54d8f43991617a8e6d367280dc4f6d0090c",
          "body": "Locks: one sealed store (AES-256-GCM, per-entry nonces, name-bound AEAD),\ninjection at the enforcement point per action after writ+policy checks,\ncredential classes sequenced static->OAuth->STS->mTLS, rotation as one\nre-seal. internal/seal + chancery secret put/list/rm. Tests: roundtrip,\nno plaintext on disk, cross-name swap rejected, wrong-key fail-closed,\ntamper rejection, metadata-only listing.",
          "is_bot": false,
          "headline": "RFC-003: credential broker — sealed store, agents never hold secrets",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:10:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1b9e5f2e6a094aff9140db2df398e17803c83b",
          "body": "RFC-001/002 running code: SQLite registry (agents/versions/instances,\nthree-layer revocation, fail-closed CheckIssuable), ES256 identity\ndocuments (5-min TTL, WIMSE-style claims, cnf reserved), writ grant/\ndelegate/verify/check with structural attenuation, delegation trees in\nthe registry, metadata-only audit timeline, cobra CLI, CI. Tests cover\nthe RFC invariants: widening unrepresentable, TTL monotonic, depth\nbounded, null-authority refused, tamper detection, revocation at every\nlayer.",
          "is_bot": false,
          "headline": "chancery: registry, identity documents, and writs — first working slice",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ca61e7fb9b250f0bcc376c0e4d25e0e20510b20",
          "body": "Locks: authority as a JWS grant-chain where block 0 grants capabilities\nand later blocks may only add caveats (widening unrepresentable);\neffective authority = grant ∩ caveats; TTL monotonicity; bounded depth;\nthe chain IS the lineage (user -> agent -> sub-agent), embedded in the\ncredential; subtree revocation at any block. Central append in MVP,\nBiscuit-style offline attenuation reserved for v1 (dk field).",
          "is_bot": false,
          "headline": "RFC-002: lineage and delegation — the writ",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "779f3c58a1fd64915b7b6cd1588118b4a7699240",
          "body": "Locks: agent as third principal class; three-layer identity\n(Agent -> Version -> Instance) with content-addressed versions;\nSPIFFE-compatible naming, WIMSE-compatible identity documents (ES256,\n5-min TTL, cnf slot from day one); registry-born, attestation-confirmed\nbirth model; three-layer revocation. Also: Chancery confirmed as final\nproduct name (RFC-000 D7 updated).",
          "is_bot": false,
          "headline": "RFC-001: agent identity model",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:52:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a70c3367294cced7170e4fb6e8dc20ce9f577091",
          "body": "…gents\n\nLocks: positioning (neutral self-hosted system of record), open-core\nApache-2.0, Go, MCP-first wedge, control-plane-first with own minimal\nbroker, metadata-only audit invariant, codename Chancery.",
          "is_bot": false,
          "headline": "RFC-000: vision and plan for Chancery, the identity provider for AI a…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 2,
      "commits_last_year": 51,
      "latest_release_at": "2026-07-20T13:47:41Z",
      "latest_release_tag": "v0.2.0",
      "releases_from_tags": false,
      "days_since_last_push": 8,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 8.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/chanceryhq/chancery",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/chanceryhq/chancery",
          "is_deprecated": false,
          "latest_version": "v0.2.0",
          "repository_url": "https://github.com/chanceryhq/chancery",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T13:44:37Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 25,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-17",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 54882,
      "source_files_sampled": 43,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 15,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/oklog/ulid/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": true,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.53.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.73.4",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 15,
        "direct_count": 4,
        "indirect_count": 11
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 6,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "anee769",
          "commits": 51,
          "avatar_url": "https://avatars.githubusercontent.com/u/67168113?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "2 out of the last 2 releases have a total of 2 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
        "ran_at": "2026-07-29T11:40:42Z",
        "aggregate_score": 4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T07:40:02Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/chanceryhq/chancery",
    "host": "github.com",
    "name": "chancery",
    "owner": "chanceryhq"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 56 is calibrated to 59 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 56,
            "calibrated": 59,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 59,
      "inputs": {
        "security": 52,
        "vitality": 67,
        "community": 44,
        "governance": 48,
        "calibration": "2026-08-02",
        "engineering": 66,
        "ai_readiness": 57,
        "weighted_overall_raw": 56
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 67,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "weak",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "commits_last_year": 51,
              "human_commit_share": 1,
              "days_since_last_push": 8,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "51 commits in the last year",
                "points": 15.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v0.2.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 8.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "weak",
        "name": "Community & Adoption",
        "value": 44,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "forks": 1,
              "stars": 25,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "25 stars",
                "points": 22.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "weak",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): PR acceptance, Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "pr_acceptance",
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 74,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 6,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 0,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "chanceryhq",
              "public_repos": 2,
              "account_age_days": 24
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of chanceryhq",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "chanceryhq"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 3.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/chanceryhq/chancery"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "3 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "ai-agents",
                "iam",
                "identity",
                "mcp",
                "security",
                "agents",
                "credentials",
                "tools",
                "multi-agent",
                "spawn",
                "browser",
                "browser-automation",
                "hierarchy",
                "cookies",
                "password",
                "mcp-client",
                "mcp-server",
                "mcp-tools",
                "audit",
                "audit-log"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 52,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 15 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 15
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 15,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 15,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.961,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "49 of 51 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 49,
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 51",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 54882,
              "source_files_sampled": 43,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/43 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 43,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "weak",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "application"
      ],
      "labels": [
        "mcp-server",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "library": 3,
        "mcp-server": 4
      },
      "primary": "mcp-server",
      "evidence": [
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:github.com/spf13/cobra",
          "weight": 4
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:go",
          "weight": 3
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-server",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-tools",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "low",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": false
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T11:40:48.003499Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chanceryhq/chancery.svg",
  "full_name": "chanceryhq/chancery",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v2.5.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.