Registro público
Informe de salud del softwareesquema 0.30.0 · métricas 2.3.1 · 2026-08-03 07:51 UTC

delimit-ai / delimit-mcp-server

The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.

Python · JavaScriptMIT★ 21 estrellas⑂ 5 forksdesde mar 2026Ver en GitHub ↗
TipoHerramienta de línea de comandosBibliotecaServicio de redcómo se determina

delimit-ai/delimit-mcp-server tiene un índice de salud de 78 sobre 100, lo que lo sitúa en la banda Bueno. Su puntuación más alta es Vitality (87/100) y la más baja, AI Readiness (49/100). Se actualizó por última vez hace 6 días. Una sola persona concentra la mayor parte del trabajo reciente.

78
global / 100
Bueno

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala estandarizada de 1 a 100. El resultado global parte de su media ponderada, calibrada contra la distribución del registro público para que las bandas tengan significado percentil; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe un límite «En riesgo» de 34.

78
Excepcional93-100El nivel más alto del registro (≈ el 5% superior); cumple prácticamente todos los criterios evaluados
Excelente80-92Sólido en todos los frentes; carencias menores
Bueno65-79Saludable; carencias limitadas y manejables
Moderado50-64Aceptable con carencias notables; se recomienda revisión
Débil35-49Debilidades sustanciales en varias áreas
En riesgo20-34Debilidades significativas; su adopción exige cautela
Crítico1-19Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

El resultado global ponderado 67 se calibra a 78 en la escala publicada del índice (calibración del registro 2026-08-02).

Titularidad

Delimit.aiOrganización
2 seguidores17 repositorios públicosdesde mar 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

87Excelente · 21% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 6 días
14.5/36Cadencia de commits — 21/52 semanas con commits
18/18Volumen de commits — 456 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year456
human_commit_share1
days_since_last_push6
active_weeks_last_year21
Cómo se puntúa
27/27Publica versiones — 45 versiones publicadas
36/36Recencia de las versiones — última versión hace 10 días
27/27Cadencia de publicación — una versión cada ~3,9 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count45
latest_release_tagv4.16.4
releases_from_tagsno
days_since_latest_release10
mean_days_between_releases3,9
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

57Moderado · 17% del índice global
Cómo se puntúa
21.1/60Estrellas — 21 estrellas
5/25Forks — 5 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks5
stars21
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
readme_badges4
has_contributing
has_issue_templateno
has_code_of_conduct
readme_badge_servicesshields.io
has_pull_request_template
Cómo se puntúa
47.5/80Descargas mensuales — 3625 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesdelimit-cli
dependents
ecosystemsnpm
total_downloads
monthly_downloads3625
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

55Moderado · 23% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
42/42Resolución de issues — 100% de issues cerradas
28.8/30Aceptación de PR — 165/172 PR decididos fusionados
0/13Newcomer PR acceptance — ningún PR de un contribuyente primerizo decidido en 30 d
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs165
open_issues0
closed_issues3
prs_merged_7d1
prs_decided_7d1
prs_merged_30d41
prs_decided_30d42
issue_closed_ratio1
closed_unmerged_prs7
first_time_authors_30d0
first_time_prs_merged_30d0
first_time_prs_decided_30d0
Excluidos de la puntuación (sin datos o no aplicable): newcomer_pr_acceptance. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
3.4/25Alcance del propietario — 2 seguidores de delimit-ai
9.9/25Trayectoria — 17 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers2
owner_typeOrganization
is_verified
owner_logindelimit-ai
public_repos17
account_age_days147
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 10 días
20/20Historial de versiones — 237 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesdelimit-cli
ecosystemsnpm
any_deprecatedno
min_days_since_publish10

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

81Excelente · 19% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 8 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentación

100Excepcional
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://delimit.ai
10/10Descripción del repositorio
10/10Topics — 14 topics
10/10Wiki
Datos de entrada utilizados
topicsapi-governance, breaking-changes, openapi, claude-code, codex, mcp, mcp-server, cursor, ai-governance, cross-model, deliberation, devtools, gemini-cli, model-context-protocol
has_wiki
homepagehttps://delimit.ai
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

57Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 14 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4,6
Excluidos de la puntuación (sin datos o no aplicable): signed_releases. Los pesos restantes se han renormalizado.
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
25/25Dependencias indirectas libres de avisos conocidos — ninguna dependencia indirecta tiene un aviso conocido
0/40Sin avisos pendientes — ningún aviso tiene fecha de publicación
Datos de entrada utilizados
sourceosv
advisories0
affected_packages0
assessed_packages136
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluidos de la puntuación (sin datos o no aplicable): Sin avisos pendientes. Los pesos restantes se han renormalizado. Se cotejó el cierre de dependencias en tiempo de ejecución de npm:delimit-cli@4.16.4 —lo que arrastra la instalación del paquete publicado—: 136 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Tiene un peso deliberadamente pequeño (4%): las herramientas para agentes son una señal real de mantenimiento, pero un repositorio sin ninguna puede alcanzar igualmente 100/100.

49Débil · 4% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 99 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,99
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
0/11Verificación estática de tipos
10/10Entorno reproducible — Dockerfile, lockfile
10/10Práctica demostrada con agentes — 24 de los últimos 100 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0,24
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
0/45Código verificable por tipos — Python sin configuración de verificación de tipos
52.2/55Tamaños de archivo manejables — 11/218 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languagePython
largest_source_bytes709.008
source_files_sampled218
oversized_source_files11
Cómo se puntúa
40/40Esquema de API (OpenAPI/GraphQL/proto) — api/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml
0/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signalno
api_schema_filesapi/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml

Datos clave

21estrellas de GitHub
1contribuidores
456commits en los últimos 12 meses
6días desde el último push
45versiones publicadas
1factor bus
0issues abiertas
npm, PyPIecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

Historial de estrellas y forks 0 ★ / 5 ⇿
0Estrellas
5Forks
6Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

2334455522026-032026-042026-04
Mayor 0Menor 2Parche 4
OpenSSF Scorecard 4.6 / 10
4.6agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-08-03 07:51 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities14 existing vulnerabilities detected
Dependencias directas 7
RegistroPaqueteRestricción de versiónManifiesto
npmaxios^1.16.0package.json
npmchalk^4.1.2package.json
npmcommander^12.1.0package.json
npmexpress^4.18.0package.json
npminquirer^8.2.0package.json
npmjs-yaml^4.1.0package.json
npmminimatch^5.1.0package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Avisos de dependencias 0

Instalar npm:delimit-cli@4.16.4 arrastra 136 paquetes, directos y transitivos: 0 tienen avisos conocidos, de los cuales 0 son dependencias directas.

Ningún aviso conocido afecta a las dependencias evaluadas.

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "api-governance",
        "breaking-changes",
        "openapi",
        "claude-code",
        "codex",
        "mcp",
        "mcp-server",
        "cursor",
        "ai-governance",
        "cross-model",
        "deliberation",
        "devtools",
        "gemini-cli",
        "model-context-protocol"
      ],
      "is_fork": false,
      "size_kb": 4756,
      "has_wiki": true,
      "homepage": "https://delimit.ai",
      "languages": {
        "Shell": 75636,
        "Python": 2456913,
        "Dockerfile": 1292,
        "JavaScript": 1187074
      },
      "pushed_at": "2026-07-28T03:12:38Z",
      "created_at": "2026-03-09T03:53:35Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-28T03:12:45Z",
      "description": "The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://delimit.ai",
      "name": "Delimit.ai",
      "type": "Organization",
      "login": "delimit-ai",
      "company": null,
      "location": null,
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/266560012?v=4",
      "created_at": "2026-03-08T19:47:12Z",
      "is_verified": null,
      "public_repos": 17,
      "account_age_days": 147
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v4.16.4",
          "kind": "patch",
          "published_at": "2026-07-24T02:51:54Z"
        },
        {
          "tag": "v4.16.3",
          "kind": "patch",
          "published_at": "2026-07-18T20:08:55Z"
        },
        {
          "tag": "v4.16.2",
          "kind": "patch",
          "published_at": "2026-07-17T22:45:43Z"
        },
        {
          "tag": "v4.16.1",
          "kind": "patch",
          "published_at": "2026-07-16T06:10:25Z"
        },
        {
          "tag": "v4.16.0",
          "kind": "minor",
          "published_at": "2026-07-14T21:56:44Z"
        },
        {
          "tag": "v4.14.0",
          "kind": "minor",
          "published_at": "2026-06-27T16:19:34Z"
        },
        {
          "tag": "v4.13.1",
          "kind": "patch",
          "published_at": "2026-06-21T01:54:15Z"
        },
        {
          "tag": "v4.13.0",
          "kind": "minor",
          "published_at": "2026-06-21T01:13:02Z"
        },
        {
          "tag": "v4.12.1",
          "kind": "patch",
          "published_at": "2026-06-20T01:16:26Z"
        },
        {
          "tag": "v4.12.0",
          "kind": "minor",
          "published_at": "2026-06-19T03:39:58Z"
        },
        {
          "tag": "v4.11.1",
          "kind": "patch",
          "published_at": "2026-06-17T13:57:12Z"
        },
        {
          "tag": "v4.11.0",
          "kind": "minor",
          "published_at": "2026-06-17T13:17:45Z"
        },
        {
          "tag": "v4.10.0",
          "kind": "minor",
          "published_at": "2026-06-16T22:46:24Z"
        },
        {
          "tag": "v4.9.0",
          "kind": "minor",
          "published_at": "2026-06-15T17:37:50Z"
        },
        {
          "tag": "v4.8.0",
          "kind": "minor",
          "published_at": "2026-06-10T18:26:58Z"
        },
        {
          "tag": "v4.7.10",
          "kind": "patch",
          "published_at": "2026-06-09T19:55:20Z"
        },
        {
          "tag": "v4.7.9",
          "kind": "patch",
          "published_at": "2026-06-09T17:40:39Z"
        },
        {
          "tag": "v4.7.8",
          "kind": "patch",
          "published_at": "2026-06-09T14:51:44Z"
        },
        {
          "tag": "v4.7.7",
          "kind": "patch",
          "published_at": "2026-06-09T04:59:58Z"
        },
        {
          "tag": "v4.7.6",
          "kind": "patch",
          "published_at": "2026-06-09T03:51:22Z"
        },
        {
          "tag": "v4.7.3",
          "kind": "patch",
          "published_at": "2026-06-04T17:08:54Z"
        },
        {
          "tag": "v4.7.2",
          "kind": "patch",
          "published_at": "2026-06-04T11:47:57Z"
        },
        {
          "tag": "v4.7.1",
          "kind": "patch",
          "published_at": "2026-06-04T03:49:38Z"
        },
        {
          "tag": "v4.7.0",
          "kind": "minor",
          "published_at": "2026-06-04T02:15:22Z"
        },
        {
          "tag": "v4.5.13",
          "kind": "patch",
          "published_at": "2026-05-08T18:21:26Z"
        },
        {
          "tag": "v4.5.12",
          "kind": "patch",
          "published_at": "2026-05-08T14:52:37Z"
        },
        {
          "tag": "v4.5.10",
          "kind": "patch",
          "published_at": "2026-05-08T14:19:57Z"
        },
        {
          "tag": "v4.5.9",
          "kind": "patch",
          "published_at": "2026-05-08T02:45:43Z"
        },
        {
          "tag": "v4.5.8",
          "kind": "patch",
          "published_at": "2026-05-08T02:19:19Z"
        },
        {
          "tag": "v4.5.7",
          "kind": "patch",
          "published_at": "2026-05-08T00:35:29Z"
        },
        {
          "tag": "v4.5.6",
          "kind": "patch",
          "published_at": "2026-05-07T21:35:53Z"
        },
        {
          "tag": "v4.5.5",
          "kind": "patch",
          "published_at": "2026-05-07T03:57:17Z"
        },
        {
          "tag": "v4.5.4",
          "kind": "patch",
          "published_at": "2026-05-07T03:47:46Z"
        },
        {
          "tag": "v4.5.3",
          "kind": "patch",
          "published_at": "2026-05-07T03:40:29Z"
        },
        {
          "tag": "v4.3.4",
          "kind": "patch",
          "published_at": "2026-04-23T23:59:07Z"
        },
        {
          "tag": "v4.3.3",
          "kind": "patch",
          "published_at": "2026-04-23T23:30:55Z"
        },
        {
          "tag": "v4.3.1",
          "kind": "patch",
          "published_at": "2026-04-23T17:38:35Z"
        },
        {
          "tag": "v4.3.0",
          "kind": "minor",
          "published_at": "2026-04-23T13:33:28Z"
        },
        {
          "tag": "v4.2.0",
          "kind": "minor",
          "published_at": "2026-04-22T03:02:14Z"
        },
        {
          "tag": "v4.1.38",
          "kind": "patch",
          "published_at": "2026-04-04T21:03:40Z"
        },
        {
          "tag": "v3.10.3",
          "kind": "patch",
          "published_at": "2026-03-21T21:40:22Z"
        },
        {
          "tag": "v3.9.2",
          "kind": "patch",
          "published_at": "2026-03-21T14:29:18Z"
        },
        {
          "tag": "v3.8.1",
          "kind": "patch",
          "published_at": "2026-03-21T04:01:01Z"
        },
        {
          "tag": "v3.6.11",
          "kind": "patch",
          "published_at": "2026-03-21T00:06:35Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-03-18T14:57:59Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ec7ee651640dcd6bb7adc4d4351a45d3c643738a",
          "body": "…(#186)\n\nfix(LED-4078): classify gateway/ai/thinktank_pipeline.py as internal.\n\nDeliberation-as-review (single-contributor org carve-out): operational scope, author infracore, org repo, green CI (13/13 incl. Bundle fail-closed guards). UNANIMOUS APPROVE: /root/.delimit/deliberations/2026-07-27-pr186\n[…]\ne (shipping controlled by package.json files allowlist, which already omits the module). npm publish remains a separate founder-gated hard stop.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(LED-4078): classify gateway/ai/thinktank_pipeline.py as internal …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-28T03:12:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31f50d796a8e8f2b499aacd17c0069a9f39089d7",
          "body": "…allthrough (LED-1964) (#185)\n\nDeliberation-as-review (delimit-ai org, infracore author, operational scope, green CI 14/14): UNANIMOUS APPROVE, quorum 3 panelists / 3 vendors (Anthropic+OpenAI+xAI). Implements the two nits the #183 review flagged (LED-1964). Transcript: /tmp/claude-0/-root/58afc023-0a21-4d52-8df3-76422ba1c3c8/scratchpad/led1964-review.json.",
          "is_bot": false,
          "headline": "fix(chat): time-box migration spawn + reviveSoulForLaunch candidate f…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-24T03:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "739c9cbb5a1e0b921dd13fb201b985f5fc5dbaf8",
          "body": "Release 4.16.4. Founder-approved (classification of 25 LED-1946 mailbox files as INTERNAL + publish, 2026-07-24) — founder approval is the human review. CI dry-run against the branch passed (Pre-publish Validation + npm publish --dry-run). Proprietary prune verified (license_core.py excluded, hard-assert clean).",
          "is_bot": false,
          "headline": "release: v4.16.4 (#184)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-24T02:48:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "befddb0d5aff9009528fd9efc16d26b60da5538a",
          "body": "… (#183)\n\nDeliberation-as-review (delimit-ai org, infracore author, operational scope, green CI 14/14): UNANIMOUS APPROVE, quorum verified 3 panelists / 3 vendors (Anthropic+OpenAI+Google). Two non-blocking nits logged as LED-1964 (migration spawnSync timeout; reviveSoulForLaunch candidate-loop early return) per the merge condition. Transcript: /tmp/claude-0/-root/58afc023-0a21-4d52-8df3-76422ba1c3c8/scratchpad/led1962-chat-review.json. npm publish NOT included — separate founder gate.",
          "is_bot": false,
          "headline": "fix(chat): reliable cross-agent continuity in delimit chat (LED-1962)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-24T01:43:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de4cd930be12b86ec414d0717ed1345807ca5f38",
          "body": "…D-1962) (#182)\n\nDeliberation-as-review (delimit-ai org, infracore author, operational scope, green CI): UNANIMOUS APPROVE after a REJECT→fix→APPROVE cycle. Round 1 (claude+codex) REJECTED a cross-project soul-bleed risk (global-most-recent default-on); fixed in b937cb4 (current-project default + se\n[…]\nle). Transcripts: /tmp/claude-0/-root/58afc023-0a21-4d52-8df3-76422ba1c3c8/scratchpad/led1962-review.json (reject) + led1962-review-v2.json (approve). npm publish NOT included — separate founder gate.",
          "is_bot": false,
          "headline": "feat(setup): auto-revive last soul on session start across agents (LE…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-23T21:49:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "849819b4108c2d0d6229433996bd9a9570a14a6d",
          "body": "…ization guard) (#181)\n\nDeliberation-as-review (LED-1872 carve-out, all 9 conditions verified): SECOND-PASS UNANIMOUS AGREE after first-pass DISAGREE remediation (.sh fail-open gap closed, seeded-violation proof, audited self-annotations). Operational panel claude+codex+grok, quorum met (LED-1908). \n[…]\niberation.md (AGREE) in session 2026-07-20 scratchpad. CI all green incl. the gate passing on its own PR. Admin-merge substitutes REVIEW_REQUIRED per carve-out; gate NOT made required (founder-gated).",
          "is_bot": false,
          "headline": "LED-3799: fail-closed identity-strings content gate (PR-time deanonym…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-20T23:57:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8edea53852b50bf233b6fa2100528fe6a8ddfb11",
          "body": "…180)\n\nBundle sync for 4.16.3 anti-drift fix. Founder-approved release completion. Both bundle guards green; heartbeat.py (public, #306) synced; license_core.py untracked.",
          "is_bot": false,
          "headline": "chore(bundle): sync gateway bundle for 4.16.3 (heartbeat.py drift) (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T20:05:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8fce005e53641d5c7267302d9e4d2f40b29a724",
          "body": "Release delimit-cli 4.16.3 — founder-approved publish (explicit 'go'). Ships SessionEnd auto-capture hook fix (#178) + author-audit workflow (#177) + bundle-classification (#176). All deploy gates green: test smoke 331/331, security clean, bundle classification + parity green, changelog updated. Zero gateway source-content changes.",
          "is_bot": false,
          "headline": "release: v4.16.3 (#179)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T19:58:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "680c59fcd13d076eda3baeffdf43d898173b5f3d",
          "body": "…session-end handoff (#178)\n\nfix(hooks): install a SessionEnd hook so session handoff auto-captures on real exit (all users).\n\nThe Stop hook fires at end-of-TURN, not on real exit (/exit, window close), so nothing captured a handoff on exit and users had to manually prompt delimit_soul_capture. Inst\n[…]\nlib_sessionend_hook_178.md. All CI green (Test Node 18/20/22, identity-guard, Bundle guards, CodeQL); 7 new tests + setup-no-clobber green. Ships to users only on the next npm publish (founder-gated).",
          "is_bot": false,
          "headline": "fix(hooks): install SessionEnd capture hook in nested shape for auto …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T19:25:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41b3eda0a8ae4e14678c4c8310752f1c69a03ff9",
          "body": "Deliberation-as-Review (all 9 conditions met): UNANIMOUS MERGE, claude+codex+grok = 3 respondents/3 vendors (quorum met). Transcript: scratchpad/delib_opsec_preventive_prs.md. Opsec preventive control LED-3830. Additive CI-only, no runtime/secret change. — always-on scheduled author-email audit, un-bypassable by --admin, fail-closed on empty email.",
          "is_bot": false,
          "headline": "ci(opsec): add always-on scheduled author-audit (LED-3830) (#177)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T13:47:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14bcbd30986393a807df9f8a8586e76a3956be4c",
          "body": "…176)\n\nLED-1938 — classify internal outreach modules for the npm bundle.\n\nDeliberation-as-Review (single-human org; all 9 conditions met):\n- Scope: operational/maintenance (bundle data-file classification; no code/tool-surface change).\n- CI: all green — Bundle fail-closed guards (classification + pa\n[…]\nlic tool; server.py already imported the (already-excluded) outreach_loop_daemon/outreach_substantive, so the public surface was already internal-only.\n\nLedger: LED-3829 (LED-1919 go-live) / LED-1938.",
          "is_bot": false,
          "headline": "fix(bundle): classify outreach_submit + wiring INTERNAL (LED-1938) (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T11:03:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ce2d1e427e1ef03087e2416389f7a964d74c605",
          "body": "Classify firewall files internal-exclude (unblocks 4.16.2 publish). Green CI incl. bundle fail-closed guards.",
          "is_bot": false,
          "headline": "fix(bundle): classify firewall files as INTERNAL-EXCLUDE (#175)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T22:41:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca4af141596fef6c2d887a67bb71a298d010f223",
          "body": "Release 4.16.2 (runtime slug fix synced from gateway #301 + onboarding #172 + codex --model fix #173). Green CI incl. bundle fail-closed guards + identity-guard. Tag v4.16.2 triggers publish.yml OIDC publish.",
          "is_bot": false,
          "headline": "release: v4.16.2 (#174)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T22:28:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "644c3a61cb522d7598d10c242fe04a58a3e2ed66",
          "body": "…ure (#173)\n\nMerged on founder authority (npm publish prep, 2026-07-17). Fixes 'delimit chat --model codex' TTY probe false-negative (classify 'stdin is not a terminal' as reachable→proceed, not probe_error). noreply-authored, green CI. Ships in 4.16.2.",
          "is_bot": false,
          "headline": "fix(chat): treat codex TTY probe error as reachable, not a probe fail…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T22:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "325c01aa1d67ac02a85d1a204a5755d24af1455a",
          "body": "…mplate (#172)\n\nMerged on founder authority ('merge B when ready', 2026-07-17) + audit D1. Repoints the dead delimit-api-governance Marketplace slug (404) → delimit-merge-gate-for-ai-written-code in lib/delimit-template.js — the CLAUDE.md onboarding template 'delimit setup' writes into every user repo. noreply-authored, green CI. Companion to delimit-action #42 + gateway #301.",
          "is_bot": false,
          "headline": "fix: repoint dead Marketplace slug in shipped CLAUDE.md onboarding te…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T21:40:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e932924b118c83dd34148b82490c892ae516ab9a",
          "body": "Merged on founder authority ('yes to all', 2026-07-17) + audit deliberation. D1: repoint 3 README Marketplace links off the dead delimit-api-governance slug. Docs-only, green CI.",
          "is_bot": false,
          "headline": "fix(readme): repoint dead Marketplace links to live listing slug (#171)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T21:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f106126f2476cbefd2a9cccc50b90d92c20f4db",
          "body": "…t (unblocks 4.16.1) (#170)\n\nMerge basis: founder 4.16.1 release authorization (operational panel below quorum, LED-1915 fail-closed hold). CI infra fix unblocking the authorized publish. CI green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): exclude generated checksums.sha256 from the anti-drift asser…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T06:07:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7df53f6987db5b0fc1614cd0ac7a044ee668d444",
          "body": "Founder-authorized 4.16.1 release chain ('publish 4.16.1 with the phoenix fixes'). All guards green on the release content; leak-prune + marker fixes verified in-commit.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: v4.16.1 (#169)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T01:16:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bde083dd7ca0a11f48bef324db4a4b763b5bd8bd",
          "body": "…r catch #4) (#168)\n\nMerge basis: founder release authorization (4.16.1 chain; operational panel below quorum per LED-1915 fail-closed hold). One-line INTERNAL classification; sync-verifier catch #4; CI green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(bundle): classify ai/schemas/__init__.py INTERNAL (sync-verifie…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T01:08:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5a9bcd137a80db0d3ece960e1c37401b922f7667",
          "body": "…n INTERNAL, changelog, bundle resync (#167)\n\nMerge basis: FOUNDER RELEASE AUTHORIZATION ('publish 4.16.1 with the phoenix fixes', 2026-07-15) — release-prep within the authorized chain, same basis as the 4.16.0 release merges. Review record: two deliberation passes, both 2-respondent (antigravity: \n[…]\nnimous APPROVE on the merits. Transcripts: /root/.claude/jobs/027af2c2/tmp/delib_pr167.md + _v2.md. First live enforcement of canon condition 9.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): prep 4.16.1 — classify audit_stream PUBLIC / custodia…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T01:05:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "82f9bf9bbf3ce056b231f0b4d84e66fc32b82400",
          "body": "…(LED-3432, LED-3433) (#166)\n\nDeliberation-as-review UNANIMOUS APPROVE (LED-1906, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr166.md). LED-3432 (TTL failover recovery) + LED-3433 (deterministic quota probe, codex probed). Ships to installed users at NEXT publish; delimit doctor mandatory pre-publish.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(chat): TTL-expiring Phoenix failover + deterministic quota probe …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-15T17:11:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "00bc029d9850bec61127e131ef7b2a9b7234477a",
          "body": "…(#165)\n\nDeliberation-as-review basis: mechanical release-blocker fix under the founder's standing publish authorization; third live guard catch (anti-drift assert on marker ordering). CI green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(release): gateway/VERSION marker must reflect the bumped version …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T21:53:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8453264545bb4f87adcf77984eef60a3e7b7d7de",
          "body": "Founder-authorized release ('publish 4.16.0' + publish.yml re-confirm after the LED-1900 fix). Release commit leak-free (prune+assert active); all guards green on the release content itself.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: v4.16.0 (#164)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T19:47:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b7934d25a4c7ac61f90a23fa856cb303e661a0d5",
          "body": "…epo (LED-1900) (#163)\n\nDeliberation-as-review UNANIMOUS APPROVE (LED-1901, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr163.md). LED-1900 incident fix: release.sh prunes internal-exclude paths + fail-closed hard-assert before commit. Follow-up ledgered: exclude-list canary test. Founder re-confirmed publish via publish.yml.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(release): never commit proprietary gateway source to the public r…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T19:07:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "aad6bc3956661daa3a9d616bd7f209179a18abf1",
          "body": "Deliberation-as-review UNANIMOUS APPROVE (LED-1899, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr162.md). Spot-check recorded per panel condition: removed-vs-4.14.2 file count verified against the actual packed artifact (140 gateway files removed), both CI guards present. Pack-derived changelog closes the LED-1896 phantom class.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: CHANGELOG 4.16.0 entry (pack-derived, real merged PRs only) (#162)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T17:37:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5a1449b8da032f67076bf88cdd508a347a7dea8f",
          "body": "Deliberation-as-review UNANIMOUS APPROVE (LED-1894, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr161.md). Truth-audit corrections: banned-phrase removal (vocabulary canon enforcement), CHANGELOG phantom-features correction (public-truth), gateway/VERSION marker (parity 137). Merge only — npm publish remains separately gated on the full deploy chain + founder go.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs): truth-audit factual corrections (LED-1889) (#161)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T14:53:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1a4ec68386756431b88e635e44bceb9a3fc28277",
          "body": "…#160)\n\nDeliberation-as-review UNANIMOUS APPROVE (LED-1893, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr160.md). SECOND LIVE GUARD CATCH: the anti-drift assert blocked the Gate-5 dry-run on a stale committed bundle — the exact defect that silently shipped in the v4.14.2/v4.15.0 tags. One allo\n[…]\n resynced (memory_bridge.py, LED-1885-approved); transient proprietary license_core.py removed PRE-COMMIT and provably absent (pack==allowlist).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(bundle): resync gateway bundle (memory projection budget fix) (…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T04:26:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4429e840eaa605b5be6fb97dad5048dcdc07331f",
          "body": "Deliberation-as-review UNANIMOUS APPROVE (LED-1892, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr159.md). FIRST LIVE CATCH of the fail-closed classification guard: brand_notes.py (LED-1880 internal brand engine) blocked at the Gate-5 publish dry-run instead of silently shipping — the exact failure class LED-1879 was built to end.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(bundle): classify brand_notes.py INTERNAL (guard catch #1) (#159)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T04:18:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "53d0eff8a86e42479d56f0e39061aa12e19e0e11",
          "body": "…9) (#158)\n\nFounder-directed sequence (\"build the fix, then panel review before publish\") + strategic-panel conditional GO (LED-1888) with all 4 evidence gates closed (CI green incl bundle-guards; extracted-tarball scans clean; clean-env internal-tool no-op invocation; credential scan of removed fil\n[…]\narball; no credentials found in them.\n\nsecurity(bundle): fail-CLOSED allowlist is now the boundary — unclassified gateway files block the build.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security(bundle): invert npm bundle to fail-CLOSED allowlist (LED-187…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T03:45:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fcf1e9d324d3b31a2f96c8ebfbb31ba805ed4a2a",
          "body": "…157)\n\nDeliberation-as-review: unanimous (3 models, 3 rounds)\nDeliberation ID: deliberation_20260713_185242_cb11df09\nTranscript: /root/.delimit/deliberations/deliberation_20260713_185355.json\nTranscript SHA-256: 39440e7f66a13d75f656902aae922fe97ef342b8905bc8c157a69a636ff01010\nSource-of-truth merge: delimit-ai/delimit-gateway#290 (41d1f8e)\nVerification: 10/10 GitHub checks; npm 323/323; bundled Python regression 9/9; security/parity/smoke green.\nNo npm publish or @v1 deploy included.",
          "is_bot": false,
          "headline": "fix(handoff): mirror cross-namespace receipt resolution (LED-2451) (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-13T22:54:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c50ebff74fab4058fdea87228f26d341a5fd0e23",
          "body": "… (#156)\n\nDeliberation-as-review (2026-05-11 carve-out): org repo, infracore-authored, operational scope (additive CLI flag), green CI, fresh unanimous operational-panel deliberation over the diff.\n\nVerdict: UNANIMOUS AGREEMENT (round 2) — Codex APPROVE.\nTranscript: /root/.claude/jobs/027af2c2/tmp/d\n[…]\n\nNever-break-installs: adds one `--model <id>` option to `delimit chat`; removes/renames nothing; default behavior byte-identical.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(chat): add `delimit chat --model <id>` per-launch model selector…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-13T19:54:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "35ae9392a9418e2aa2f07beb7dde8c533987d2fd",
          "body": "…(#155)\n\nFable doc-33: delimit-chat launch pre-brief (N approvals/agents/P0s, best-effort 1.5s timeout, degrades silent) + 'phoenix' alias (session was taken; avoids CLI crash) + honest help. chat behavior unchanged; never-break-installs held. 323 tests pass. Founder-approved 2026-07-12 (phoenix alias).",
          "is_bot": false,
          "headline": "feat(chat): launch pre-brief + honest launcher naming (Fable doc-33) …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-12T21:39:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f800d801ba1cf2443e0b85ab25ab10e80de67df3",
          "body": "…json version (#152)\n\nGlama coherence: DELIMIT_TOOLSET=core Docker pin (Glama crawler surface only) + server.json version-sync (LED-3717 drift 4.7.3→4.15.0) + release.sh guard. Reviewed: NON-BREAKING for installs — verified ai/server.py resolves unset/unknown DELIMIT_TOOLSET to 'full' (gating wrapper only installed when !=full), so npm/CLI installs are byte-identical; core applies to the Docker image only. All CI green. Founder-authorized 'review and merge' 2026-07-12.",
          "is_bot": false,
          "headline": "fix(glama): pin Docker crawler surface to core toolset + sync server.…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-12T17:01:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d38ad707ec0f0f4f5fcb6bf6f3accc8d3d49371",
          "body": "…ities) (#154)\n\nFounder-approved merge 2026-07-10 (in-session, explicit 'all yes'). Additive, green CI. CI identity-guard",
          "is_bot": false,
          "headline": "ci: add fail-closed identity-guard (block non-anonymized commit ident…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-10T04:52:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "264efaa30edf420b760473bd98240bc08da22263",
          "body": "…leak prevention) (#153)\n\nProprietary-leak prevention + remediation. Founder-approved (remove-from-HEAD, accept-history) 2026-07-09. (1) sync-gateway.sh exclude list fixed 5/27→27/27, DERIVED from package.json (SSOT) so it can't drift; (2) parity guard (check-bundle-parity.sh) wired into prepublishO\n[…]\n scrub deliberately NOT done (public-repo force-push is disruptive + cannot un-publish already-cloneable code). Node 18/20/22 green. Does NOT affect the published npm package (already excluded these).",
          "is_bot": false,
          "headline": "fix(bundle): sync-gateway exclude parity + parity guard (proprietary-…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-09T22:49:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8b3d9759cd828e401c570e3e3eb44eadb6d0a71",
          "body": "…gest echo + subagent flight-recorder) (#151)\n\nSTR-2202 hook half — 'tools fire tools' SessionStart digest+heartbeat echo + subagent flight-recorder. Founder-directed merge after orchestrator diff review 2026-07-07.\n\nREVIEW (clean): hook code is additive, reversible (removeClaudeHooks strips both), \n[…]\non-promise value from #150 (verified), MERGEABLE = no conflict.\n\nTakes effect for installed users only after a gated npm publish (production deploy); this merge only stages it. No out-of-band publish.",
          "is_bot": false,
          "headline": "feat(hooks): STR-2202 \"tools fire tools\" — HOOK half (SessionStart di…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-08T01:36:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7b7e9241716f0bf5a5345a2fe2465bccaff7896",
          "body": "Founder-directed merge 2026-07-07 (explicit in-session): 'merge PR #150 into the release train.' Public copy founder-ratified (LED-3700, STR-2195). Rebased onto 4.15.0. Rides next regular release publish-gate chain; NOT published out-of-band.",
          "is_bot": false,
          "headline": "docs(npm): on-promise package description (LED-3700, STR-2195) (#150)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-07T20:03:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "874743107511855d0957d2e23415d49f55f8f350",
          "body": null,
          "is_bot": false,
          "headline": "v4.15.0",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-05T05:35:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a7fc60283b9e5cac8e2882a58c55f9fa7609cb4",
          "body": null,
          "is_bot": false,
          "headline": "docs: Update changelog for v4.15.0",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-05T05:35:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cbb9ee551f09a7e3d67e4099d03654c45a3fc44",
          "body": null,
          "is_bot": false,
          "headline": "fix: Revert to NPM token auth for publishing (LED-3262)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-05T00:08:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b62bfee00769d3b58647e276e2ab4ac8450283e",
          "body": null,
          "is_bot": false,
          "headline": "feat: Radar reply lane v2 instrumentation (LED-3222)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:18:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1bd7160ddfcd106072ba24a1be6a1b0a87f8a05",
          "body": "… (LED-3274)",
          "is_bot": false,
          "headline": "feat: Implement delimit_product_lookup for e-commerce spec extraction…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:12:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb0b58cefe8421a6fc5f24418679790d64f4e3a3",
          "body": null,
          "is_bot": false,
          "headline": "feat: Integrate link path checking into delimit_repo_diagnose (LED-3272)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:11:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e95b72cd31e14d7fa0ffd53f8a10100e08c3515",
          "body": null,
          "is_bot": false,
          "headline": "feat: Add delimit_json_validate tool (LED-3271)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:11:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ac4f237cb8b79ce50edac14a32454b5aeb5e5ff",
          "body": null,
          "is_bot": false,
          "headline": "docs(strategy): Workstream A deliverables + roadmap (LED-3686..3696)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T19:19:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a15fb6758a87c374aa2a4c00195a453b6e70ba7",
          "body": "… (#149)\n\nMerged via deliberation-as-review carve-out (2026-05-11). UNANIMOUS operational deliberation. Post-publish bookkeeping for live delimit-cli@4.14.2: version→main (closes LED-3684 divergence), CHANGELOG 4.14.2, remove dead test_state_validator.py (tests a class the gateway no longer defines)\n[…]\nved out-of-tree (delimit-private/wip-preserve-2026-07-04/) for a separate finish-and-wire follow-up. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr149-postpublish.md.",
          "is_bot": false,
          "headline": "chore(release): record 4.14.2 on main + stale-test cleanup (LED-3684)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T17:21:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ff77ab52564ca00942b352c570171242cd4b7c5",
          "body": "Merged via deliberation-as-review carve-out (2026-05-11). UNANIMOUS operational deliberation. Fixes clean-tree guard false-positive on the publish-time version bump (allowlist package.json + package-lock.json; stray code still blocks). 6/6 green, 302/302 tests. Unblocks delimit-cli 4.14.2. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr148-guardfix.md. STR-2169.",
          "is_bot": false,
          "headline": "fix(publish): clean-tree guard allows publish-time version bump (#148)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T17:06:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74f720f258b306db9e37fc13f94a4ac51364185d",
          "body": "…es + main clean-tree guard) (#147)\n\nMerged via deliberation-as-review carve-out (2026-05-11). UNANIMOUS operational deliberation. Reconciles the npm 4.14.x release line into main (chat-repl transient-429 fix + clean-tree guard + StateValidator superset; version 4.14.1). Prevents a customer chat regression + version downgrade on the 4.14.2 publish. All CI green. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr147-reconcile.md. STR-2169 / LED-3684.",
          "is_bot": false,
          "headline": "fix: reconcile npm 4.14.x release line (union of published 4.14.1 fix…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T16:56:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1dd56f465ca5f784e385fbf79cdc9246556960dd",
          "body": "Merged via deliberation-as-review carve-out (2026-05-11). Fresh UNANIMOUS operational deliberation over the diff substitutes for the 2nd human reviewer. Conditions: org-owned, infracore-authored, operational (npm publish gate — additive, no customer runtime impact), green CI 9/9, CLI operational panel. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr146.md. STR-2169 D2; supersedes closed #145.",
          "is_bot": false,
          "headline": "chore(publish): block npm publish from a dirty tree (STR-2169 D2) (#146)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T15:44:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b07703e2517018dc41d5dec0f32af82b2a0094db",
          "body": "fix: prevent zombie MCP processes",
          "is_bot": false,
          "headline": "Merge pull request #143 from delimit-ai/fix/issue-142",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-26T05:31:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "356df0632269214076374463c2c99a2c2b4a97e0",
          "body": null,
          "is_bot": false,
          "headline": "fix(mcp): prevent zombie processes on client disconnect (Issue #142)",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-26T05:30:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc41e452da90345c1c7e27368da73fe412ad91fa",
          "body": "- Created StateValidator to check state changes.\n- Added it to ResilientToolCaller to abort retries when state hasn't changed.\n- Added pytest to CI workflow.\n- Created test_state_validator.py covering file_system and command categories.",
          "is_bot": false,
          "headline": "Implement StateValidator logic and test harness (LED-3250)",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-26T04:31:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4847017080af3e6a2ff5af4db14fe5cfca1cff7",
          "body": "'Delimit OS' (and product-as-operating-system framing) is banned EVERYWHERE\nper the vocabulary governance — it's the retired layer-collapse failure mode.\nTwo shipped, customer-facing surfaces still carried it:\n  - bin/delimit-os.sh: header 'the AI developer operating system' + three\n    '[Delimit OS\n[…]\nNote: the marketing-copy-lint does not scan bin/ lib/, which is why these\nslipped through — extending its coverage is a follow-up.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(canon): remove banned 'Delimit OS' framing from shipped CLI strings",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-21T13:34:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eb8d0d6a7d7604df1bb6f27c2f87d69c505993ac",
          "body": "The v4.20 remember/recall suites overrode HOME but not DELIMIT_HOME. The\nmemory path resolves as process.env.DELIMIT_HOME || os.homedir()/.delimit,\nso where DELIMIT_HOME is set (founder box: /root/.delimit) it won —\n'remember' wrote to the REAL store, the tmp memory dir was never created,\nand the te\n[…]\nforced --no-verify);\nit also polluted ~/.delimit/memory. Pin DELIMIT_HOME to the suite's tmp\n.delimit dir. Full npm test: 302/302.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: pin DELIMIT_HOME in remember/recall tests (hermeticity)",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-21T12:30:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9fc0a0d7db3c6e76d93ecc8f3e5bdbe0e262d4f0",
          "body": "4.13.0 shipped the ephemeral v0.2 producer TEST key (fb50eaaa) as\nseal_pubkey.ed25519 (PR #240 mis-commit), so real producer-issued\nattestations failed to verify against the bundled verifier. 4.13.1\nre-syncs the gateway with the authoritative seal-primary 13f6149a +\nits matching constitution signature. No other change from 4.13.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: 4.13.1 — correct the bundled Seal verification key (13f6149a)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-21T01:48:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3ff65e4d921ceeae6f3c8a5355ef59be9d6bab44",
          "body": "Re-syncs the gateway bundle (stale since 2026-06-09) and ships ~2 weeks\nof accumulated work as a proper minor release. Founder-ratified scope.\n\nHEADLINE (customer-facing): Free/Pro tier realignment (LED-1454/1738/1740/\n1741). 12 zero-marginal-cost tools move to FREE; 16 real-cost tools become\nPro be\n[…]\nr.py (issuance side; not imported by any shipped tool). Kept\nsocial_archetypes.py (the shipped vendor_news_draft tool imports it).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: 4.13.0 — Free/Pro tier realignment + Seal v0.2 attestation",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-21T00:32:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8056722ebc7b4bed9ef15e0a70bfc96d8a3d9a66",
          "body": "…141)\n\nFounder-authorized 4.12.1 release (antigravity shim fix + README). Gates: security clean, 245 tests pass, doctor 12 pass, tdqs grade A. Irreversible npm publish gated separately on founder go.",
          "is_bot": false,
          "headline": "release: 4.12.1 — gemini shim → Antigravity (agy) + README refresh (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-20T01:07:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa8b070e8265c13830e4aa07f125925a7fc0c7fe",
          "body": "…(#140)\n\nDeliberation-as-review (2026-05-11 carve-out): a fresh unanimous delimit_deliberate verdict substitutes for the absent human reviewer. Conditions met: org-owned (delimit-ai), infracore-authored, docs scope, green CI, fresh per-diff deliberation, unanimous. Transcript: /home/delimit/delimit-private/deliberations/2026-06-19-docs-freshness-prs-140-28.md",
          "is_bot": false,
          "headline": "docs: document the zero-config `delimit check` command in the README …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-19T22:53:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dbaa6172beec582561de3a46f05a6ebdf46175f",
          "body": "Deploy-gate security audit (pre-publish) flagged 2 dependency advisories:\n- form-data (transitive): CRLF injection — HIGH\n- js-yaml (direct ^4.1.0): merge-key quadratic DoS — moderate\nnpm audit fix resolves both (0 vulns). js-yaml -> 4.1.1; verified the gate still\nparses YAML and catches breaking ch\n[…]\nnistic breaking-change + secret detection, content-pinned --record.\n\nCo-authored-by: infracore <infracore@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): fix HIGH/moderate dep vulns + bump to 4.12.0 (#139)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-19T03:30:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ad31aaf8fec3e59caec23293323923ee2adcd8aa",
          "body": "…ay move) (#138)\n\n* feat(check): zero-config PR safety gate — no init required\n\n`delimit check` previously errored out without .delimit/policies.yml. It now\nruns with deterministic defaults out-of-the-box on any repo (the zero-config\n30-day-gate wedge). Backward-compatible: when a policy file exists\n[…]\nBy: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: infracore <infracore@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(check): zero-config PR safety gate — no init + secret scan (30-d…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-19T03:21:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "55ac4155ca254ce7a38d9f2e6371b7b17fea4410",
          "body": "…#137)\n\nCo-authored-by: infracore <infracore@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: cross-link all 12 worked-example reports in README (LED-3462) (…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T17:38:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f881f72d0d40ddefb0bbf1b647d7ff03f92e42b5",
          "body": "…D-1454 enforcement) (#136)\n\nFounder-approved 'flip customers' 2026-06-17. Release bump; the v4.11.1 tag triggers the publish. v3.10.0 .so live + Vercel-verified.",
          "is_bot": false,
          "headline": "release: v4.11.1 — proModuleVersion 3.9.0->3.10.0 (binary-customer LE…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T13:51:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1131d39c923568c5de3e281cb0d091b07e3c63",
          "body": "…n-Path README, security_audit dedup, twitter freshness gate (#135)\n\nFounder-directed 'deliberate, build, and ship' + explicit 'Publish 4.11.0' go (2026-06-17). Release bump only; the v4.11.0 tag (separate, next) triggers the publish. Deploy gate: security_audit clean, 51 scoped tests green.",
          "is_bot": false,
          "headline": "release: v4.11.0 — repo_diagnose/test_coverage free (LED-1454), Golde…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T13:12:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24f1742f211df92a46cab7c62791e2f1df3efb4d",
          "body": "…gh (#134)\n\nFounder-ratified (Ship to README) + explicitly directed 'deliberate and merge' 2026-06-17. Unanimous delimit_deliberate verdict (Claude + Codex AGREE, round 2, no blocker). Transcript: /home/delimit/delimit-private/deliberations/2026-06-17-pr235-pr134-merge-review.md. Docs-only, canon-clean, both false claims re-verified at source. npm publish held separately (founder-gated).",
          "is_bot": false,
          "headline": "docs(readme): add Golden-Path \"first 10 minutes\" merge-gate walkthrou…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T04:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f295851e35ef8a28edd606919803c05af76783b",
          "body": "…ce), scan_bridge precision, Glama/TDQS/secrets, grace-aware gate (LED-1724/1738/1740/1741) (#133)\n\nMerged on EXPLICIT FOUNDER GO ('go with the push using delimit'). Release vehicle for the founder-ratified pricing publish. Deploy-gate chain: delimit_security_audit CLEAN (ev-1781649113), dry-run ver\n[…]\ned 'cannot republish 4.9.0' guard), CI green (Node 18/20/22 + CodeQL + API Check). Tag v4.10.0 next → publish.yml ships gateway main. 90-day grace = no existing user hard-cut. LED-1724/1738/1740/1741.",
          "is_bot": false,
          "headline": "release: v4.10.0 — Pro tier rebalance (12 free / 12 Pro w/ 90-day gra…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-16T22:43:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c2c2f63a17ea395c32d785174b32cc78c7b09dd",
          "body": "…D-3149) (#132)\n\nReconciles main to the already-published delimit-cli@4.9.0 (live on npm; tag v4.9.0).\n\nMerged under the deliberation-as-review carve-out (2026-05-11): org-owned repo, infracore-authored, operational/release scope, no required status checks failing (Node 18/20/22 pass), fresh UNANIMO\n[…]\n.8.0→4.9.0 (proModuleVersion 3.9.0 unchanged) + CHANGELOG. Already published + verified end-to-end (published verifier validated a real production v0.2 receipt). Founder-authorized publish 2026-06-15.",
          "is_bot": false,
          "headline": "release: v4.9.0 — hardened v0.2 attestation verification (LED-3127/LE…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-15T17:44:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5708b8a309ee3461790b945b074aeefa5fc143d9",
          "body": "…on 3.9.0 (clean ungated Pro engine) (#131)\n\nrelease: v4.8.0 — delimit handoff command (#129) + proModuleVersion 3.9.0 (#130, clean ungated Pro engine). Merged under explicit founder authority following delimit publish protocol; 9/9 CI green; gates: security_audit clean, doctor 9/10, publish.yml dry-run Pre-publish Validation success + clean tarball.",
          "is_bot": false,
          "headline": "release: v4.8.0 — delimit handoff command (LED-1710) + proModuleVersi…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-10T18:24:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06e39786a80abfeea4636c2a50f91b981984f1f4",
          "body": "… published to delimit.ai/releases/v3.9.0) (#130)\n\nchore: bump proModuleVersion 3.8.2 -> 3.9.0 (clean ungated Pro engine live at delimit.ai/releases/v3.9.0). Merged under explicit founder authority; 9/9 checks green. Points delimit setup at the v3.9.0 engine; reaches installs via the next npm CLI publish.",
          "is_bot": false,
          "headline": "chore: bump proModuleVersion 3.8.2 -> 3.9.0 (clean ungated Pro engine…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-10T18:13:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba7637c85021cd9057944cea92526ce86cd8f994",
          "body": "…hoenix (LED-1710 Phase 2) (#129)\n\nLED-1710 Phase 2: wire handoff preflight into both live handoff paths (sending=chat-repl GIT_* scrub + preflight; receiving=SessionStart post-flight) + `delimit handoff [check|fix]` actionable repair + de-hardcode-sync the committed preflight bundle (removes 8 infr\n[…]\ne.md\nFollow-ups tracked LED-1717: npm-CI identity-strings gate + 3 remaining public-repo infracore literals + a `handoff fix` identity-refusal test. No npm publish (publish.yml fires on v* tags only).",
          "is_bot": false,
          "headline": "feat(chat): wire handoff preflight + GIT_* env-scrub into live Auto-P…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T22:09:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15ca2f1d71eeab222c1e7717ae2de3389bf5cf6c",
          "body": "…k (#128)\n\nAutonomous-afternoon batch (LED-1716), founder-approved. Bundle rebuilt from fixed gateway main by sync-gateway at publish.",
          "is_bot": false,
          "headline": "release: v4.7.10 — handoff_preflight + test hygiene + parser tail-see…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:48:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56167b2a97fc4afa0ae833fa893a690c9acf1c76",
          "body": "…cal) (#127)\n\nAutonomous-afternoon LED-1716 item; founder-approved merge+release. Held-PR review-substitute satisfied (transcript + tests in PR body).",
          "is_bot": false,
          "headline": "LED-1710: sync handoff_preflight validator to npm bundle (byte-identi…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:21:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ff580b73fa6805ec43ac1fa5ea34bbebf97424d",
          "body": "…ator (#126)\n\nAutonomous-afternoon LED-1716 item; founder-approved merge+release. Held-PR review-substitute satisfied (transcript + tests in PR body).",
          "is_bot": false,
          "headline": "LED-1714: sync seek-tail transcript read into npm bundle + hook gener…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:21:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20f7162df50c4baa46f9a44ddd2dd93be820bd18",
          "body": "…entinel (#125)\n\nAutonomous-afternoon LED-1716 item; founder-approved merge+release. Held-PR review-substitute satisfied (transcript + tests in PR body).",
          "is_bot": false,
          "headline": "LED-1716: make npm test git subprocesses hermetic + add .git/config s…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:21:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ded14ce0b7e6b29e4eff6891a7f178458a943a8",
          "body": "…(#124)\n\nControl plane Phase 0+1: unified queue + interactive CLI + approve/reject via existing inbox ack. Founder-approved ship. Publish via gated tag.",
          "is_bot": false,
          "headline": "v4.7.9 — control plane: delimit control + delimit_control (LED-1709) …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T17:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3aa22fbd10ff0b62230a1fe79b1f484a10ee2ed0",
          "body": "Fix hardcoded /home/delimit/delimit-gateway dev-path defaults (reaper/dispatch/loop/continuity/inbox/content-grounding) → portable _paths resolver. Zero behavior change where dev path was correct. Founder-approved ship. Publish via gated tag.",
          "is_bot": false,
          "headline": "v4.7.8 — portable gateway paths (LED-1715) (#123)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T14:35:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1726c537e4eb62996fdcc43b6621cf298abbe42a",
          "body": "delimit chat: fix false 'out of quota' probe (timeout/143 misclassification), fix Auto-Phoenix context-loss (hardcoded dev sys.path → bundled/installed resolution), DELIMIT CHAT dynamic banner. Founder-approved ship. Publish via gated tag.",
          "is_bot": false,
          "headline": "v4.7.7 — delimit chat resilience (probe + Auto-Phoenix + banner) (#122)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T04:54:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72cb6a929029b395ad90089a5f8bdafbe99c76f7",
          "body": "Docs-only changelog curation preceding the v4.7.6 publish. Founder-approved publish sequence.",
          "is_bot": false,
          "headline": "docs(changelog): 4.7.6 + retroactive 4.7.5 (#121)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T03:41:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7682e466a79b11ce5cc1e2db136c2de2dd0c0171",
          "body": "… (#120)\n\nCompletes the binding follow-up to #119: parse_transcript_tail empty-on-thinking-tail fixed (prefer text, fallback [thinking], widen scan). 24 tests; floor handoffs now carry content. Additive.\n\nDeliberation-as-review unanimous (LED-1714, 7 conditions met). Transcript: /home/delimit/delimit-private/deliberations/2026-06-09-led1713-parser-fix-review.md\nVersion held 4.7.6 (unpublished); publish gated.",
          "is_bot": false,
          "headline": "LED-1713: transcript-tail parser thinking-fallback (folds into 4.7.6)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T03:05:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2d77a2825fc6f363079a0f2d9af4ba081833b35",
          "body": "Customer-facing half of the session-lifecycle loop (gateway side: #217/#218, 5,552 tests). Additive — no tool/CLI removed, no signature changed; degrades safely to the prior no-handoff behavior.\n\nDeliberation-as-review (CLAUDE.md 2026-05-11, 7 conditions met) — re-run with the actual crash-recovery \n[…]\n6-06-09-pr119-led1705-476-review-r2.md\nBINDING FOLLOW-UP (panel condition): parse_transcript_tail completion — ships next.\nPublish HELD: no v4.7.6 tag; npm publish gated behind founder + deploy chain.",
          "is_bot": false,
          "headline": "LED-1705: deterministic session capture + crash recovery (v4.7.6) (#119)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T02:40:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46ed41a3919dd6d2320d1a695d0719b1e60d6792",
          "body": "Byte-identical reconciliation of main to the verified-published delimit-cli@4.7.5 (0 source mismatches vs npm tarball). Operational scope; zero live-customer regression (code already shipped).\n\nDeliberation-as-review (CLAUDE.md 2026-05-11, 7 conditions met): org-owned + infracore-authored + operatio\n[…]\non (LED-1712).\nTranscript: /home/delimit/delimit-private/deliberations/2026-06-09-pr118-reconcile-main-to-475.md\nRetroactive v4.7.5 tag intentionally NOT pushed (avoids publish.yml republish-failure).",
          "is_bot": false,
          "headline": "Reconcile main to published v4.7.5 (orphaned local-only release) (#118)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T02:05:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c29394a9bc56bc134ccd82bd7d9eaf34c5d7af4",
          "body": "…e correction (#117)\n\nPhase 3 of the founder-ratified LED-1695 public-surface plan (unanimous strategic deliberation 2026-06-04, transcript .../2026-06-04-public-surface-presentation-plan.md; founder: 'launch all phases now'). Docs+metadata only, CI green, gates clean.",
          "is_bot": false,
          "headline": "release: v4.7.3 — docs/metadata: min-privilege README on npm + 28-typ…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T17:05:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8de02ed269face0e8ba4d12013e136f4c80ee3ec",
          "body": "Item #4 of the founder-ratified 2026-06-04 strategic plan (the plan's strategic deliberation explicitly ranked this item; transcript /home/delimit/delimit-private/deliberations/2026-06-04-post-task-strategic-plan.md). Docs-only README change, CI green. README updates on npm at the next publish; GitHub renders immediately.",
          "is_bot": false,
          "headline": "docs: minimum-privilege adoption path (LED-2305) (#116)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T16:03:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19d1329f79afe8340cae13ec4b2d8c978bf10347",
          "body": "P0 hygiene gate from the ratified 2026-06-04 strategic plan (strategic deliberation, panel-unanimous: 'a P0 security vulnerability isn't a strategic choice to be ranked; it is a mandatory, non-negotiable gate' — transcript .../2026-06-04-post-task-strategic-plan.md; founder ratified the plan). Lockfile-only, express 4.x line, npm audit 0 vulnerabilities after, tests green. Rides the next release; no tag pushed.",
          "is_bot": false,
          "headline": "fix(deps): bump express/qs — resolve transitive qs DoS (LED-1680) (#115)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T12:46:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a564bb2bffb0ffcd75e883fe17424584d816e3b",
          "body": "…(#114)\n\nShips gateway recorder fix (record_call persists to ~/.delimit/tool_usage.jsonl) + tool activation (toolcard usage/dormancy report; additive next-step chains). Gateway code via CI sync-gateway from delimit-gateway main (d905bd4 + 40963df).\n\nAuthorization: founder-directed ship. CI green (No\n[…]\ntry data; 103 insertions/7 deletions). Additive, customer-protection safe. Activation plan LED-1693. Separate live item (not a blocker): LED-1680 transitive qs/express dep DoS (pre-existing in 4.6.2).",
          "is_bot": false,
          "headline": "release: v4.7.2 — tool-usage telemetry fix + dormant-tool activation …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T11:45:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f44162574aa199ec93dfb52a06d95fab55a99588",
          "body": "…ublishing (#113)\n\nv4.7.1 OIDC publish ENEEDAUTH = publish step ran npm 10.x (separate -g upgrade didn't carry over). Node 24 bundles npm >= 11.5.1 -> OIDC-capable npm in the publish step. registry-url stays removed; validate stays Node 20.\n\nCarve-out (7): org-owned; infracore; operational (workflow\n[…]\nodeQL + Delimit API Check); deliberation UNANIMOUS (/home/delimit/delimit-private/deliberations/2026-06-03-oidc-node24-pr113.md, LED-1690); audit=this body. Tags-only trigger -> no merge-time publish.",
          "is_bot": false,
          "headline": "ci(publish): run publish job on Node 24 (npm 11.x) for OIDC trusted p…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T03:36:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e53f479c43203a1ab588cf829c6c98a978e82322",
          "body": "Fixes v4.7.1 OIDC publish E404: setup-node@v4 + registry-url wrote a dummy NODE_AUTH_TOKEN placeholder + always-auth, forcing garbage-token auth instead of OIDC. Removed registry-url; npm defaults to npmjs.org and uses OIDC.\n\nCarve-out (all 7): org-owned; infracore; operational (CI workflow, not shi\n[…]\nff = UNANIMOUS (/home/delimit/delimit-private/deliberations/2026-06-03-oidc-registry-url-fix-pr112.md, LED-1688); audit = this body. publish.yml triggers on v* tags only -> no merge-time publish risk.",
          "is_bot": false,
          "headline": "ci(publish): drop registry-url so OIDC trusted publishing works (#112)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T03:24:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b57959d9ea60ed4bd2666389ea38ccdb2fd4b14",
          "body": "…) (#111)\n\nPatch bump to cut the first release via npm Trusted Publishing (OIDC) -> sigstore provenance (4.7.0 was manually published without it). No functional package changes (.github/ not bundled).\n\nCarve-out (all 7): org-owned; infracore; operational; CI green (Delimit API Check + Node 18/20/22 \n[…]\nimit/delimit-private/deliberations/2026-06-03-v4.7.1-oidc-verify-pr111.md, LED-1687); audit = this body. Founder direct order: publish v4.7.1 to verify. Gates: security_audit clean, test_smoke fail 0.",
          "is_bot": false,
          "headline": "release: v4.7.1 — verify OIDC trusted-publishing pipeline (provenance…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T03:09:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4366ece19b8828a89b4668d4f925aa69d6c80b2",
          "body": "… (#110)\n\nMoves the publish job to npm OIDC Trusted Publishing: npm@^11 (>=11.5.1 for OIDC), NODE_AUTH_TOKEN removed from both publish steps, id-token:write already present, --provenance kept. Fixes the expired-NPM_TOKEN failure that shipped v4.7.0 without provenance (LED-2301).\n\nCarve-out (all 7): \n[…]\n Actions, repo delimit-ai/delimit-mcp-server, workflow publish.yml, BEFORE the next publish, or OIDC auth fails (no token fallback). publish.yml triggers on v* tags only -> no merge-time publish risk.",
          "is_bot": false,
          "headline": "ci(publish): switch npm publish to OIDC Trusted Publishing (no token)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T02:39:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6eff966b62e7f7267ad3745be73e4902ffbfd65d",
          "body": "…109)\n\nFixes the v4.7.0 publish blocker: nested 'npm pack' under 'npm publish' (npm 10.x) writes no file, so security-check.sh's 'ls $TMPDIR/*.tgz' failed (exit 2). Now enumerates shipped files via write-free 'npm pack --dry-run --json'; grep scan blocks unchanged.\n\nCarve-out (all 7): org-owned; inf\n[…]\npr109.md, LED-1682); audit = this body.\nVerified local: standalone clean; injected-secret negative test FAILS (gate intact); npm publish --dry-run passes nested. npm publish still HELD; no tag pushed.",
          "is_bot": false,
          "headline": "fix(ci): make security-check.sh re-entrancy-safe under npm publish (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T02:00:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69570ae00faf20cc9ff954e0606d64f8ca371338",
          "body": "…blocker) (#108)\n\nFixes the v4.7.0 publish dry-run failure: the bundled PUBLIC ed25519 key matched the secrets-scan \\.key$ pattern (false positive). Renamed to seal_pubkey.ed25519 (pilot canon); scan not weakened.\n\nCarve-out (all 7): org-owned; infracore; operational; CI green (Node 18/20/22 + CodeQ\n[…]\nRESOLVED: npm pack confirms seal_pubkey.ed25519 IS bundled (65B), public.key gone; no literal-filename entry in package.json files[] or .npmignore. Mirrors gateway fix 24fa16d. npm publish still HELD.",
          "is_bot": false,
          "headline": "fix(seal): rename bundled public key to seal_pubkey.ed25519 (publish-…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T01:48:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e1e8c425f23014b84aa2f9e6d997a6515ec71c0",
          "body": "Re-land of the seal fold via the compliant carve-out path (prior direct-push bypass reverted in #106).\n\nDeliberation-as-review carve-out (2026-05-11) — all 7 conditions met:\n1. Org-owned: delimit-ai/delimit-mcp-server\n2. Author: infracore\n3. Scope: operational (additive free tool/command; not pricin\n[…]\nr single-contributor org repo). Pre-publish note from the panel: mechanically confirm the verifier's verification_unavailable non-throw path before publish. npm publish remains HELD; no v* tag pushed.",
          "is_bot": false,
          "headline": "feat: delimit seal-verify + open-core Seal verifier (v4.7.0) (#107)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T01:29:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c98a7e2e854682c7a955314f249a978a2054b866",
          "body": "…PR (#106)\n\nReverts 7d723cc, which landed on main via a direct push that auto-bypassed the Protect Main PR ruleset.\n\nAuthorization: direct founder instruction this session (revert + redo as PR). Audit: LED-2297.\nMerged via sanctioned gh pr merge --admin (carve-out mechanism): CI green (Node 18/20/22\n[…]\ndeliberation-as-review carve-out for single-contributor org repos. The seal fold re-lands in the follow-up PR with a fresh deliberation over the diff.\n\nnpm publish remains held; no version tag pushed.",
          "is_bot": false,
          "headline": "Revert v4.7.0 seal fold (landed via ruleset bypass) — re-landing via …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T01:22:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7d723cc9af18009501617d237b12d4d6529d1492",
          "body": "…v4.7.0)\n\nAdd 'delimit seal-verify <receipt.json>' and the free delimit_seal_verify MCP tool. Bundles gateway/ai/seal/ (verifier, content-hashed constitution, public key, sample receipt). The verifier lazy-imports cryptography and fails closed if absent -- it never blocks install or any other tool.\n\n[…]\nligion/secret scans clean; security-check.sh clean; repo diagnose healthy. npm publish intentionally HELD for explicit founder go.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: delimit seal-verify command + bundled open-core Seal verifier (…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T00:56:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0648d431e6b7b627115f06a35d017174fdbf40de",
          "body": "…er FP; diff-engine context severity; CLI recall fix (#105)\n\nRelease v4.6.2. Founder authorized 'ship it once CI green' (2026-05-27); CI all-green (Node 18/20/22 + CodeQL + API Check). Bundles already-merged+deliberated gateway changes: memory_search/revive/legacy-store (PR #215), scanner FP (LED-2278), diff-engine $ref drift + LED-1600 context-severity (PR #216, deliberation LED-1611). Tag push triggers publish.yml (provenance + secret-scan).",
          "is_bot": false,
          "headline": "release: v4.6.2 — restore memory_search + cross-venture revive; scann…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-27T18:46:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4810c65ea2ae1a1491238c202f597970923f5ef3",
          "body": "LED-1564: pin pytest into the npm-side setup chain so fresh installs auto-provision ~/.delimit/venv with pytest. Single-file change in bin/delimit-setup.js (+7/-3) covering reqFile-branch + inline-fallback + global-pip-fallback. Install-time only; no publish.\n\nCarve-out: merged under delimit-ai/* de\n[…]\nsetup.js only via gh pr diff before merge).\n- Founder explicit override at the moment of merge: 'finish'.\n- Transcript: /home/delimit/delimit-private/deliberations/2026-05-22-pr104-setup-pytest-pin.md",
          "is_bot": false,
          "headline": "fix(setup): LED-1564 — pin pytest into the venv install chain (#104)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-23T01:52:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab73ae9c32edd8f4d78da4dec09f9f47dafb4e0e",
          "body": "… (#103)\n\nDocuments what shipped in 4.6.1 (already published 2026-05-22). Forward-prep for the next customer-visible changelog ship at 4.6.2 — not a retroactive fix to the tarball already on npm. Captures the 7 gateway PRs (cross-post dedup, inline follow-up drafts, STR-195 binding decisions, LED-12\n[…]\ns AGREE (Gemini + Claude + Codex), round 2 ✓\n- Transcript: /home/delimit/delimit-private/deliberations/2026-05-22-pr103-changelog-461.md\n\nNo publish, no tag — rides forward to next functional release.",
          "is_bot": false,
          "headline": "docs(changelog): 4.6.1 entry — bundle hygiene + 7 gateway carry-overs…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-23T00:34:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "76e7ec6bc34ae3f4d770ba5c82b91340b04de3fa",
          "body": "Release reconciliation: post-publish bump + 110-file gateway sync for delimit-cli@4.6.1, which already shipped to https://registry.npmjs.org/delimit-cli/4.6.1 (shasum 8d6807b497487cc5a43f2ed28af4494457f3d0d4, 1.0MB / 202 files).\n\nCarve-out: merged under delimit-ai/* deliberation-as-review pattern (C\n[…]\ny sync transports 7 already-deliberated gateway PRs (#199-205) — not a re-litigation.\n\nPost-merge: tag v4.6.1 + push tag; the GHA publish.yml workflow may fire and will no-op on duplicate npm version.",
          "is_bot": false,
          "headline": "4.6.1 (#102)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-22T20:25:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7881a4cf773be9c289c1e505663efd6a87c42f58",
          "body": "… (#101)\n\nExcludes 3 publish-time-only scripts (build-license-core.sh, security-check.sh, test-license-core-so.sh) from the npm tarball. They stay on the dev machine where prepublishOnly runs them; they no longer ship to customer installs. Closes the meta-leak where the scripts' own leak-detection g\n[…]\npackage.json: 166 → 163 files; 3 scripts gone.\n  - Manifest scan: 0 identity-string hits in shipped files (was 3).\n  - prepublishOnly invocation chain unchanged — scripts still resolve on dev machine.",
          "is_bot": false,
          "headline": "chore(npm): exclude dev-only build scripts from the published tarball…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-22T02:02:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50f91706eae28ad7d3c8d58dd3590a91aff2366b",
          "body": "…or (LED-1207) (#100)\n\nOn some npm-arborist environments `npx delimit-cli` crashes with \"Cannot read properties of\nundefined (reading 'extraneous')\" before reaching the CLI itself. That silently breaks the\npre-commit/pre-push gate and forces --no-verify, violating the no-silent-no-verify rule.\n\nFix:\n[…]\npre-commit-npx-bypass.md\nVerdict: UNANIMOUS AGREEMENT at round 2 (Gemini, Claude Opus 4.7, Codex GPT-5.3-codex).\n\nCloses LED-1207.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): bypass broken npx fallback in pre-commit/pre-push generat…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-15T05:13:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f2c46edfee297f31e62c23a75fd4ebe3735ef28b",
          "body": "The 4.6.0 entry's \"Known issue (pre-existing, fix tracked)\" line about\ndelimit attest mcp exit codes was incorrect. The original test failure\nthat triggered the note was a phantom — caused by a corrupted local git\nworktree state (LED-1401), not a real CLI bug. On a clean clone, all\nattest-mcp test s\n[…]\nion carve-out. Same direct-push pattern as the 4.6.0 version\nbump (c860c96), which was also implicit in the publish authorization.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): retract incorrect 4.6.0 'known issue' line (LED-1403)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-15T04:38:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 45,
      "commits_last_year": 456,
      "latest_release_at": "2026-07-24T02:51:54Z",
      "latest_release_tag": "v4.16.4",
      "releases_from_tags": false,
      "days_since_last_push": 6,
      "active_weeks_last_year": 21,
      "days_since_latest_release": 10,
      "mean_days_between_releases": 3.9
    },
    "artifacts": {
      "collected": true,
      "structure": [
        "tree.dockerfile"
      ],
      "declarations": [
        {
          "name": "delimit-cli",
          "path": "package.json",
          "tokens": [
            "npm.bin",
            "npm.entry"
          ],
          "ecosystem": "npm"
        }
      ]
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "readme_badges": {
        "hosts": [
          "shields.io"
        ],
        "total": 4,
        "header": 4,
        "collected": true,
        "has_inspect_badge": false
      },
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "delimit-cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "openapi",
            "swagger",
            "api",
            "breaking-changes",
            "semver",
            "lint",
            "linter",
            "api-governance",
            "api-contracts",
            "ci-cd",
            "github-actions",
            "migration",
            "diff",
            "schema-validation",
            "api-versioning",
            "eslint",
            "delimit",
            "openapi-diff",
            "api-linter",
            "contract-testing",
            "mcp",
            "mcp-server",
            "model-context-protocol",
            "claude-code",
            "codex",
            "gemini-cli",
            "cursor",
            "ai-governance",
            "ai-agents",
            "ai-code-review",
            "ci-governance",
            "merge-gate",
            "attestation",
            "signed-attestation",
            "sigstore",
            "sbom",
            "supply-chain-security",
            "json-schema",
            "json-schema-diff",
            "policy-as-code",
            "audit-trail",
            "ai-coding-assistant",
            "pull-request",
            "pr-comment",
            "developer-tools"
          ],
          "ecosystem": "npm",
          "categories": [],
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/delimit-cli",
          "declared_type": null,
          "is_deprecated": false,
          "latest_version": "4.16.4",
          "repository_url": "https://github.com/delimit-ai/delimit-mcp-server",
          "versions_count": 237,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3625,
          "first_published_at": "2026-03-06T21:16:29.723000Z",
          "latest_published_at": "2026-07-24T02:51:40.136000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        }
      ]
    },
    "popularity": {
      "forks": 5,
      "stars": 21,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-29",
            "count": 2
          },
          {
            "date": "2026-04-15",
            "count": 1
          },
          {
            "date": "2026-04-21",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 5,
        "total_forks": 5
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [
        "api/openapi.yaml",
        "examples/breaking-change-demo/openapi.yaml",
        "examples/monorepo-demo/services/orders/api/openapi.yaml",
        "examples/monorepo-demo/services/users/api/openapi.yaml",
        "examples/openapi-basic/api/openapi.yaml",
        "examples/safe-change-demo/openapi.yaml"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 709008,
      "source_files_sampled": 218,
      "oversized_source_files": 11,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "gateway/requirements.txt",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 136,
        "malicious_count": 0,
        "assessed_package": "npm:delimit-cli@4.16.4",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "axios",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.16.0"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.2"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "express",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.18.0"
        },
        {
          "name": "inquirer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.2.0"
        },
        {
          "name": "js-yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "minimatch",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.1.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 165,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 3,
        "closed_unmerged_prs": 7
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "infracore",
          "commits": 269,
          "avatar_url": "https://avatars.githubusercontent.com/u/266558014?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "api-governance.yml",
        "author-audit.yml",
        "ci.yml",
        "claude.yml",
        "identity-guard.yml",
        "identity-strings-gate.yml",
        "publish.yml",
        "weekly-tweet.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "14 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ec7ee651640dcd6bb7adc4d4351a45d3c643738a",
        "ran_at": "2026-08-03T07:51:05Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "recent_prs": {
        "merged_7d": 1,
        "decided_7d": 1,
        "merged_30d": 41,
        "authors_30d": 1,
        "decided_30d": 42,
        "sample_size": 60,
        "window_days": 30,
        "sample_exhausted": false,
        "authors_probed_30d": 1,
        "newcomer_merged_30d": 0,
        "bot_prs_excluded_30d": 0,
        "newcomer_authors_30d": 0,
        "newcomer_decided_30d": 0
      },
      "ci_last_run_at": "2026-08-02T08:36:57Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-28T03:12:39Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/delimit-ai/delimit-mcp-server",
    "host": "github.com",
    "name": "delimit-mcp-server",
    "owner": "delimit-ai"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": "The weighted overall 67 is calibrated to 78 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 67,
            "calibrated": 78,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 78,
      "inputs": {
        "security": 57,
        "vitality": 87,
        "community": 57,
        "governance": 55,
        "calibration": "2026-08-02",
        "engineering": 81,
        "ai_readiness": 49,
        "weighted_overall_raw": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 87,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 456,
              "human_commit_share": 1,
              "days_since_last_push": 6,
              "active_weeks_last_year": 21
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "21/52 weeks with commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "456 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 456
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 45,
              "latest_release_tag": "v4.16.4",
              "releases_from_tags": false,
              "days_since_latest_release": 10,
              "mean_days_between_releases": 3.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "45 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 45
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 10 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 57,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 26,
            "inputs": {
              "forks": 5,
              "stars": 21,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "21 stars",
                "points": 21.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "5 forks",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": 4,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [
                "shields.io"
              ],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "delimit-cli"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3625
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,625 downloads/month across npm",
                "points": 47.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3625,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 81,
            "inputs": {
              "merged_prs": 165,
              "open_issues": 0,
              "closed_issues": 3,
              "prs_merged_7d": 1,
              "prs_decided_7d": 1,
              "prs_merged_30d": 41,
              "prs_decided_30d": 42,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 7,
              "first_time_authors_30d": 0,
              "first_time_prs_merged_30d": 0,
              "first_time_prs_decided_30d": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "165/172 decided PRs merged",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 165,
                      "decided": 172
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "weak",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 43,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "delimit-ai",
              "public_repos": 17,
              "account_age_days": 147
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of delimit-ai",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "delimit-ai"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "17 public repos, account ~0 yr old",
                "points": 9.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 17
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "delimit-cli"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 10
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 10 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "237 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 237
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "8 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "exceptional",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "api-governance",
                "breaking-changes",
                "openapi",
                "claude-code",
                "codex",
                "mcp",
                "mcp-server",
                "cursor",
                "ai-governance",
                "cross-model",
                "deliberation",
                "devtools",
                "gemini-cli",
                "model-context-protocol"
              ],
              "has_wiki": true,
              "homepage": "https://delimit.ai",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://delimit.ai",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "14 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 57,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "14 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:delimit-cli@4.16.4 runtime dependency closure — what installing the published package pulls in — 136 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:delimit-cli@4.16.4",
                  "assessed": 136
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 136,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 136,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "weak",
        "name": "AI Readiness",
        "value": 49,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "weak",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.24,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "24 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 24,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 709008,
              "source_files_sampled": 218,
              "oversized_source_files": 11
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "11/218 source files over 60KB",
                "points": 52.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 218,
                      "oversized": 11
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "excellent",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "api/openapi.yaml",
                "examples/breaking-change-demo/openapi.yaml",
                "examples/monorepo-demo/services/orders/api/openapi.yaml",
                "examples/monorepo-demo/services/users/api/openapi.yaml",
                "examples/openapi-basic/api/openapi.yaml",
                "examples/safe-change-demo/openapi.yaml"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "api/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "api/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "cli",
        "library",
        "network-service"
      ],
      "scores": {
        "cli": 16,
        "library": 14,
        "mcp-server": 2,
        "network-service": 7
      },
      "primary": "cli",
      "evidence": [
        {
          "tier": "declared",
          "label": "cli",
          "source": "npm.bin",
          "weight": 10
        },
        {
          "tier": "declared",
          "label": "library",
          "source": "npm.entry",
          "weight": 8
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:npm",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:commander",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "network-service",
          "source": "dep:express",
          "weight": 4
        },
        {
          "tier": "structure",
          "label": "network-service",
          "source": "api_schema",
          "weight": 3
        },
        {
          "tier": "description",
          "label": "cli",
          "source": "description:cli",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-server",
          "weight": 2
        }
      ],
      "artifacts": [
        {
          "path": "package.json",
          "labels": [
            "cli",
            "library"
          ],
          "ecosystem": "npm"
        }
      ],
      "confidence": "high",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-03T07:51:23.236512Z",
  "schema_version": "0.30.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/delimit-ai/delimit-mcp-server.svg",
  "full_name": "delimit-ai/delimit-mcp-server",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v2.3.1, esquema v0.30.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.