Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-27 06:19 UTC

MelloB1989 / KARMAX

Go · TypeScriptMIT★ 1 star⑂ 1 forksince May 2026View on GitHub ↗

MelloB1989/KARMAX holds a health index of 50 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (74/100) and lowest on Security (26/100). It was last updated 3 days ago. A single contributor accounts for most of its recent work.

50
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

50
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Kartik DeshmukhPersonal account
50 followers167 public repossince Apr 2020Lyzn

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/MelloB1989/karmaxv0.1.2-323 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

71Good · 22% of overall
How it's scored
36/36Push recency — last push 3 days ago
4.2/36Commit cadence — 6/52 weeks with commits
18/18Commit volume — 112 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year112
human_commit_share1
days_since_last_push3
active_weeks_last_year6
How it's scored
27/27Ships releases — 3 releases published
36/36Release recency — latest release 23 days ago
27/27Release cadence — a release every ~0 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count3
latest_release_tagv0.1.2
releases_from_tagsno
days_since_latest_release23
mean_days_between_releases0

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

36At risk · 18% of overall
How it's scored
0/60Stars — 1 stars
0/25Forks — 1 forks
0/15Watchers — 0 watchers
Inputs used
forks1
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

39At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
2.8/22.5Commit distribution — top contributor authored 88% of commits
2.7/13.5Contributor breadth — 2 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.875
How it's scored
0/46.8Issue resolution — no issues or no data
0/38.3PR acceptance — no decided pull requests or no data
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
12.3/25Owner reach — 50 followers of MelloB1989
25/25Track record — 167 public repos, account ~6 yr old
Inputs used
followers50
owner_typeUser
is_verified
owner_loginMelloB1989
public_repos167
account_age_days2,297
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 23 days ago
12/20Version history — 3 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/MelloB1989/karmax
ecosystemsgo
any_deprecatedno
min_days_since_publish23

Engineering Quality

Are baseline engineering and documentation practices in place?

74Good · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.js
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.

Documentation

65Moderate
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
0/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionno

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

26Critical · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — no data
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 42 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate2.6
Excluded from scoring (no data or not applicable): ci_tests, packaging. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

72Good · 0% of overall
How it's scored
18/45Agent instructions — app/AGENTS.md, app/CLAUDE.md (stub)
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_filesapp/AGENTS.md, app/CLAUDE.md
agent_instruction_max_bytes118
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
11/11Lint / format config — eslint.config.js
11/11Static type checking — app/tsconfig.json
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileno
typed_languageyes
bootstrap_filesMakefile
has_devcontainerno
has_linter_configyes
typecheck_configsapp/tsconfig.json
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
55/55Manageable file sizes — 0/157 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes45,325
source_files_sampled157
oversized_source_files0

Key facts

1GitHub stars
2contributors
112commits, last 12 months
3days since last push
3releases
1bus factor
0open issues
Go, npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 2.6 / 10
2.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-27 06:19 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/aCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities42 existing vulnerabilities detected
Direct dependencies 64
RegistryPackageVersion constraintManifest
npm@expo-google-fonts/jetbrains-mono^0.4.1app/package.json
npm@expo-google-fonts/space-mono^0.4.2app/package.json
npm@expo/ui~56.0.18app/package.json
npm@react-three/fiber^9.6.1app/package.json
npm@tailwindcss/postcss^4.3.1app/package.json
npm@tanstack/react-query^5.101.0app/package.json
npmclsx^2.1.1app/package.json
npmexpo~56.0.12app/package.json
npmexpo-background-task~56.0.19app/package.json
npmexpo-calendar~56.0.8app/package.json
npmexpo-clipboard^56.0.4app/package.json
npmexpo-constants~56.0.18app/package.json
npmexpo-contacts~56.0.9app/package.json
npmexpo-dev-client~56.0.20app/package.json
npmexpo-device~56.0.4app/package.json
npmexpo-font~56.0.7app/package.json
npmexpo-gl~56.0.5app/package.json
npmexpo-glass-effect~56.0.4app/package.json
npmexpo-image~56.0.11app/package.json
npmexpo-linking~56.0.14app/package.json
npmexpo-notifications~56.0.18app/package.json
npmexpo-router~56.2.11app/package.json
npmexpo-secure-store~56.0.4app/package.json
npmexpo-speech~56.0.3app/package.json
npmexpo-speech-recognition^56.0.1app/package.json
npmexpo-splash-screen~56.0.10app/package.json
npmexpo-status-bar~56.0.4app/package.json
npmexpo-symbols~56.0.6app/package.json
npmexpo-system-ui~56.0.5app/package.json
npmexpo-task-manager~56.0.19app/package.json
npmexpo-updates~56.0.19app/package.json
npmexpo-web-browser~56.0.5app/package.json
npmnativewind5.0.0-preview.4app/package.json
npmreact19.2.3app/package.json
npmreact-dom19.2.3app/package.json
npmreact-native0.85.3app/package.json
npmreact-native-css3.0.7app/package.json
npmreact-native-gesture-handler~2.31.1app/package.json
npmreact-native-markdown-display^7.0.2app/package.json
npmreact-native-reanimated4.3.1app/package.json
npmreact-native-safe-area-context~5.7.0app/package.json
npmreact-native-screens4.25.2app/package.json
npmreact-native-web~0.21.0app/package.json
npmreact-native-worklets0.8.3app/package.json
npmtailwind-merge^3.6.0app/package.json
npmtailwindcss^4app/package.json
npmthree^0.184.0app/package.json
npmzod^4.4.3app/package.json
npmzustand^5.0.14app/package.json
Gogithub.com/MelloB1989/karmav1.19.1go.mod
Gogithub.com/MelloB1989/karmax-loopsv0.0.0-20260723211929-ac1f3852431ego.mod
Gogithub.com/bwmarrin/discordgov0.29.0go.mod
Gogithub.com/charmbracelet/bubblesv1.0.0go.mod
Gogithub.com/charmbracelet/bubbleteav1.3.10go.mod
Gogithub.com/charmbracelet/lipglossv1.1.0go.mod
Gogithub.com/go-chi/chi/v5v5.2.1go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/grandcat/zeroconfv1.0.0go.mod
Gogithub.com/joho/godotenvv1.5.1go.mod
Gogithub.com/mattn/go-sqlite3v1.14.24go.mod
Gogithub.com/robfig/cron/v3v3.0.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogo.uber.org/zapv1.27.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1118,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 619073,
        "CSS": 907,
        "Shell": 9157,
        "Makefile": 531,
        "JavaScript": 6164,
        "PowerShell": 4453,
        "TypeScript": 139480
      },
      "pushed_at": "2026-07-23T21:21:27Z",
      "created_at": "2026-05-28T21:46:34Z",
      "owner_type": "User",
      "updated_at": "2026-07-23T21:21:31Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://mellob.in",
      "name": "Kartik Deshmukh",
      "type": "User",
      "login": "MelloB1989",
      "company": "Lyzn",
      "location": "India",
      "followers": 50,
      "avatar_url": "https://avatars.githubusercontent.com/u/63499572?v=4",
      "created_at": "2020-04-11T11:21:23Z",
      "is_verified": null,
      "public_repos": 167,
      "account_age_days": 2297
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-07-03T20:08:17Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-07-03T19:31:31Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-03T19:00:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "eb1514c4604c4a31ce027c96b24767577dd1c8c8",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to ac1f385 (commands -> full orchestrator)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-23T21:21:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b784cc830f03f0c291537dd62031c2cba155ae52",
          "body": "…(self-reply bug)\n\nThe operator also uses the KARMAX WhatsApp account directly. When they typed a\nmessage to a contact from it, wacli fired an outgoing_message (source\nwhatsapp_event) — and routeEvent only skipped source 'wacli_api', so it routed\nthe operator's OWN message as inbound and KARMAX repl\n[…]\nthe operator typing on the same account. Operator commands\nare unaffected: those arrive from the operator's personal number as\nincoming_message.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(whatsapp): never respond to the operator's own outgoing messages …",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-23T21:15:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c5fc6fbd6383ff51b46cdba696b7bdd44b67bc8a",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 7134087 (duplicate-send fixes)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-23T07:13:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b74cfa9eccad444747fb390fd5a5af5c96214b57",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to fcd71bc (no re-reply on follow-up pass)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-23T07:05:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bde072be89e2d8ec275a15ee06d9d0c41889524f",
          "body": "… tool)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 567fec5 (wa-monitor lends gateway a wacli…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T12:26:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e28452271ee07145b4a449d403cc5abf8dd0cff1",
          "body": "Making the gateway the default path traded capability for cost: with no tools it\ncan only see what the loop hands it, so wa-monitor started refusing things\nclaude_code used to do ('No visibility on that from my end — I can only see this\nchat' when asked about another conversation).\n\nRather than grow\n[…]\nreturned to the MODEL so it can\nadapt instead of aborting the run.\n\nThis keeps the core small while letting each loop be as capable as it needs.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loopkit): loops can lend the gateway temporary tools",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T12:23:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "295c216721038a21c9de7ceefdc6cc02f4dd5df0",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 0fb5bce (gateway-first wa-monitor)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T09:09:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a8b5a7a87a919e8dc592aee2fabfaeed5e2c271",
          "body": "…aulting to claude_code\n\nLoops only had Ask (full agent), Summarize (weak summary model), or Harness\n(spawns a whole Claude Code CLI run). wa-monitor therefore fired a claude_code\ninvocation for EVERY incoming WhatsApp message — 62 in the last day, ~15-30s\neach — even to send a one-line reply.\n\nGate\n[…]\npt in, text out, seconds not minutes. Loops should try it FIRST and\nescalate to Harness only when the work genuinely needs tools/shell/research.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loopkit): Kit.Gateway — cheap main-model call, so loops stop def…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T09:05:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a95819cef6b2e00a8c84240773bf04be2dcc561",
          "body": "…ment loop env\n\n- linux installer now writes StandardOutput/StandardError=append to\n  $DATA_DIR/karmax.log, and installs a logrotate config plus a daily user timer\n  (copytruncate — systemd holds the append fd, so a rename would leave the\n  daemon writing into the rotated copy). Skips gracefully if \n[…]\noperator name, trusted\n  reply groups, bot-mention fallback, @all threshold) so a rebuilt host is\n  reproducible without committing any secrets.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore(packaging): flat-file logging + rotation in the installer, docu…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T09:04:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "109f82cc3f9ec5fb75a2ac1fc3edb4f10cc41f6c",
          "body": "…emory)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 0dbcd69 (reply-to + per-chat short-term m…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T08:55:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fcc3f54200d2e5f4f08e25cdbd9f2c75c021efd",
          "body": "…-to plumbing\n\nLoops needed the opposite of long-term memory: cheap scratch state scoped to\nwhat they're working on ('what did I just tell this chat', 'they asked me to\nstop'), that expires on its own and never pollutes curated recall.\n\n- New kv_memory table + store engine: durable grouped key/value\n[…]\n think about expiry.\n- Thread wacli_message_id into the comms.message payload so a loop can reply\n  quoting the exact message that triggered it.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loopkit): short-term memory engine (grouped KV with TTL) + reply…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T08:52:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58ae38d11d3a90a8f8522edac49ef96e2c0c7993",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 01b559a (per-chat reply gate)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T08:48:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0087b30a5399fd634c8b68aae1525fbee120e560",
          "body": "whatsapp.monitor add/remove recreates the wacli webhook (there's no update op).\nWithout passing --include-mentions it would silently drop out-of-scope mention\ndelivery, killing the loop's 'reply whenever KARMAX is @-mentioned anywhere'\nrule on the next chat add.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(monitor): keep --include-mentions when rebuilding the webhook",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T07:52:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93db161e5e7810d041e998571daaf990afaaf669",
          "body": "Carry wacli's mention_count through the webhook envelope and the comms.message\nbus payload so the proxy loop can distinguish a direct @-mention from an\n'@all' blast.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(whatsapp): thread mention_count to the wa-monitor loop",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-22T07:49:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98f230701399646acb9710e576ae001927eee8e7",
          "body": "- Add MIT LICENSE, CONTRIBUTING, SECURITY policy (threat model + secret\n  handling), and CI (gofmt + vet + build + test with CGO) alongside the\n  existing release workflow.\n- Add issue/PR templates that enforce the loop/approval/no-secrets conventions.\n- gofmt the Go files touched during recent feature work so CI is green.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: open-source scaffolding + gofmt",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-21T21:11:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "072ffbea606df21bbf40fa874403fde86e8a1cd7",
          "body": "…-monitor\n\nwacli now computes (generically, from its own identity) whether an incoming\nmessage @-mentions the bot or replies to a bot-sent message. Parse both from the\nwebhook (wacliMessage), carry them through the comms.message metadata + bus\nevent payload so the wa-monitor proxy can trigger on a reply-to-KARMAX or an\n@-mention without any hardcoded numbers.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(whatsapp): thread mentions_me/quoted_is_from_me from wacli to wa…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-20T19:26:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2184d4b2d5493c93cd39734acbf0a870b489b3ff",
          "body": "…mmand)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to a9534f2 (wa-monitor bot-mention direct co…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-20T19:16:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1194133660be6302aef73b6223c6c4a292c1bdd1",
          "body": "…als)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to a4f687c (INFORM outcome — FYIs not approv…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-20T08:51:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e581b5c24f6744e77dc6694160e578ac62cc372",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 2fb9662 (wa-monitor trusted reply-groups)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-20T08:44:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44ed1db3dfddf41f25553f88fa1950a98aea661e",
          "body": "…on logging)\n\nCo-Authored-by: MelloB coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to bc362f6 (wa-monitor never-silent + decisi…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-20T08:34:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a25880e4dd66c171098ac922dff6cb8668faf8fc",
          "body": "Audited all 15 loops. Two were dead weight:\n- memory-bootstrap: a ONE-TIME WhatsApp-history deep scan that completes then\n  goes dormant (marked done since Jul 5). It was still firing @6h to no-op.\n- act-on-pending: drains the pending-actions queue — but memory-bootstrap is\n  the ONLY producer of th\n[…]\n(maintenance SQL @1h, review Q&A @45m, merge LLM @3h); the two\nhealth monitors watch different things (brain-monitor @10m, webhook-health\n@15m).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "loops: remove dead memory-bootstrap + act-on-pending",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-19T20:49:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "662876b9bfc69551289a6a6c73ace29ce7956fb3",
          "body": "tsc flagged the Contact cast as incompatible with updateContactAsync's\n{id: string} & Partial<ExistingContact> param. Cast to the function's exact\nparameter type instead so it typechecks.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(app): correct updateContactAsync arg type in upsertContactName",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-19T20:35:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f104d138a74a5e08786598e983dd50df97eb51c1",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 72fd232 (gchat-watch auth resilience)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-19T20:26:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b51cb8df0b51ab4bdaceecddc63f7a583b6fb9fd",
          "body": "The app couldn't create calendar events/reminders or save contacts because\nInfo.plist was missing required usage strings:\n- NSContactsUsageDescription was ABSENT -> iOS blocked all contacts access\n  (create/lookup/update all failed).\n- NSCalendarsFullAccessUsageDescription was ABSENT -> on iOS 17+ (\n[…]\nxes a wrong name.\n\nNOTE: the app changes require an EAS rebuild + reinstall to take effect; the\nKARMAX-side contact.update tool is already live.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(device-actions): iOS permission strings + contact name update",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-19T20:23:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf06c2ed4c8de0945646a63a2ccb57436008e457",
          "body": "…ncile strays\n\nRoot cause of 'webhooks not working for every contact': a second webhook (no\nHMAC secret) had been added out-of-band watching one contact; every delivery\nfrom it failed KARMAX's signature check with 401, so that contact's messages\nsilently vanished while a healthy webhook served the r\n[…]\nt repairs one.\n\nLive incident already cleaned up (collapsed 2 webhooks -> id 14, 10 chats, all\nsecured, including the previously-401'd contact).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(webhooks): tighten wacli webhook — one secured webhook, auto-reco…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-19T20:16:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8b9e95f1eb7f8716170ca8e0c6e076862d360976",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to 3989fa5 (away-note operator-name fix)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-15T06:53:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9d3d2ed62b8a4345ec9e54e3ec9bc5f18f69a5d",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to e5271ab (LLM-composed away-note)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-15T06:51:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45d36e37453b14f087444f9388950ec8e43c9dfe",
          "body": "…t away-note)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karmax-loops to add1561 (wa-monitor reply-bias + assistan…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-15T06:43:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c88a5bea86048bb2de644c2644c123fc67bddb42",
          "body": "… 256)\n\nThe brain-monitor pinged the model with MaxTokens: 8. The Claude thinking\nmodels now in use (sonnet-4.6 / opus-4.6) emit internal thinking first, so an\n8-token budget is exhausted before any text and the call fails with a\nmisleading 'context deadline exceeded' — every single time. Result: af\n[…]\n fails in 227ms, 64 fails in 1.8s, 256 returns\n'OK' in 2s. Bumped the ping to 256. Verified: monitor now reports healthy with\nno deadline error.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(brain-monitor): stop false 'brain is DOWN' alarms (MaxTokens 8 ->…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-15T06:37:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8518d1861c0e6ffafbc68a724c5a67a68d628ac4",
          "body": "Phase 4 — active capture: hot-sync now runs every 2h (was 4h) with a broader\nmemory-capture prompt (bumped karmax-loops to dd583c2), so durable facts land\nsteadily instead of only when the agent saves one mid-turn.\n\nPhase 5 — consolidation: new internal/memmerge + a 'memory-merge' runtime loop\n(@3h)\n[…]\n9 canonical\nfacts (377 -> 366), including correcting a contradiction (Anurag vs Andhra\nUniversity) and consolidating the CampX payment schedule.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(memory): active-capture cadence + LLM merge/consolidation engine",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-10T07:48:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69bd1efac958d6cc70e9f7cbed0a382b07f1e2c2",
          "body": "… true graph total\n\nThree-part memory upgrade (kiro now serves real Claude — verified sonnet-4.6 /\nopus-4.6 / haiku-4.5 complete cleanly with tool-calling):\n\n1) BRAIN. Main + memory models moved off the flaky glm-5 (context-deadline\n   timeouts, fabricated tool calls) to claude-sonnet-4.6; summaries\n[…]\nte links over the most-recent graphLinkLimit=160, and\n   return total/shown/capped so the app displays the real memory size (377 and\n   rising).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(memory): sonnet-4.6 brain + PageIndex tree-traversal retrieval +…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-10T07:41:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8e018c524130b7041100b30e0426f66bd3ec673f",
          "body": "The scan loops (chat-sweep/wa-monitor/gchat-watch) get a placeholder APPROVE\nline from the harness now and then ('APPROVE: none', 'APPROVE (none)',\n'APPROVE — none') that really means 'nothing to approve'. Those turned into\nblank approval requests in the inbox.\n\nGuard at the single choke point Creat\n[…]\n version whose ParseScanOutcomes\ndrops these placeholder items at the source (MeaningfulItem filter), so all\nthree outcome categories are clean.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(proposals): stop empty 'Decision — (none)' approvals",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-10T05:20:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d2a1426538292941a13f69c68b27b58098bb034c",
          "body": "…29 links)\n\nTwo root causes, both fixed:\n\n1) FROZEN LINKS. memory_links were generated exactly ONCE — the first time the\n   app opened the graph with zero links (2026-06-26) — and never again. The\n   generator only ran on len(links)==0 or a manual POST rebuild, so as memory\n   grew to 349 entries ev\n[…]\nrns the stored set instead).\n\nVerified: rebuild now yields 160 nodes / 99 links (same person, part of, led\nto, …) even with the kiro brain down.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(memory-graph): unfreeze the 3D memory graph (stuck at 55 nodes / …",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-09T07:29:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8de7dd88a8710b14d23ff2befdf788b1d13492b",
          "body": "Two new agent tools + incoming-media plumbing:\n\n- whatsapp.send_media: sends any local file (image/PDF/Excel/CSV/doc/video) as\n  a WhatsApp media message via 'wacli send --media', with an optional caption.\n  Pair with claude_code.call to generate a report/export and deliver it.\n\n- whatsapp.view_medi\n[…]\nhatsapp.view_media with chat=… message_id=…]' — plus any caption, so the\n  agent (and the wa-monitor proxy) know a file came in and can view it.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(whatsapp): media send + view support (images, PDFs, Excel, docs)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-08T18:46:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bdbf9f33bb0a9f74dd6c3b78fdcffa5a63d4eac3",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "deps: wa-monitor v1.1.0 — deterministic @-mention detection in groups",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-08T18:36:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fcd43e25449508ff4711e2ffe3cb8f4446fc5394",
          "body": "…estions\n\nApproval flood: the proxy/scan loops (wa-monitor on every message, chat-sweep,\ngchat-watch) re-flagged the same item as APPROVE on every run — e.g. 5 duplicate\n'Decision — shiva charan' proposals. CreateProposal now dedups: skip if the same\ntitle is already pending or was raised in the las\n[…]\n(verified: pending Aadhaar update, an HR report-back\nwhose time has passed, etc.) while staying latched (never re-asks) so it can't\nbecome spam.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix: dedup approval proposals (stop the flood); ask more staleness qu…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-08T13:02:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f5a728be5c242f1c94de8cc1cbd98ae59b4d08a2",
          "body": "…r, act-evidence guard\n\nFixes from debugging the \"confused about dates / WhatsApp reply did nothing\"\nreport:\n\n- Current date/time is now injected into the agent's context every turn\n  (buildTimeContext). It was date-blind — it would web-search for \"today's\n  date\" and couldn't reason about ages/dead\n[…]\nalls in the full 24-tool context — the guard\ncatches it but the model doesn't always recover; a stronger brain or tool\ndeferral is the real fix.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: current-date context, per-turn model timeout, brain self-monito…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-07T09:45:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e125b4f240ed23880b42acdd17499518bbb94aab",
          "body": "…anywhere\n\nMakes memory feel alive: it knows how old every fact is, notices when\ntime-sensitive things go stale, and asks — once, gently — whether they're\nstill relevant, resolvable from the app OR WhatsApp.\n\nTemporal awareness:\n- mem_search / mem_recent now stamp each fact with its age (\"stored 3 w\n[…]\nquence to memory (keep / update / forget).\n\nAlso fixes the SDK 56 calendar/reminders permission API (all device actions\nwere failing on-device).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(memory): time-aware memory + staleness check-ins you can answer …",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-07T09:23:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a8341c4acfb28cb57a491cf1a86ba9abe11a28b3",
          "body": "…ice-action failures)\n\nexpo-calendar SDK 56 renamed requestCalendarPermissionsAsync ->\nrequestCalendarPermissions and requestRemindersPermissionsAsync ->\nrequestRemindersPermissions. The old names now fail, so every calendar.add\nand reminder.add the daemon queued was failing on-device (23 reminders + 3\nevents, all status=failed with the deprecation message in the result). The\ncore createEventAsync/createReminderAsync APIs are unchanged.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(app): use SDK 56 calendar/reminders permission API (fixes all dev…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-07T08:49:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22ba699b6fc124fdec9797720a6455b9534378b6",
          "body": "…ics, async delegation\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "docs(roadmap): round-2 hermes deep dive — security layer, loop mechan…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T21:21:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c71bd8d47ef3dc44ed9bdf9cb3e16b98dc2e51f",
          "body": "…o KARMAX\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "docs: agentic roadmap — hermes-agent + supermemory research applied t…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T21:17:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2206ba2398edb5877d97298d9bc98a824efbcec",
          "body": "…ion 90683)\n\nexpo-clipboard's iOS module references the photo-library API (for image\nclipboard support), so Apple requires the purpose string even though the app\nonly copies text. Added an honest, clipboard-scoped string.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "app(ios): add NSPhotoLibraryUsageDescription (fixes App Store validat…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T20:15:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66c8435ff6fa22103b12414d2a45fd5cdd92653b",
          "body": "…niversal build\n\n- macOS/Linux install.sh now locate the karmax binary at the repo root too, so\n  `make build && bash packaging/<os>/install.sh` works from a source checkout,\n  not only from a release archive.\n- The release workflow ad-hoc signs the lipo'd macOS universal binary, so even\n  unsigned \n[…]\nuilds run on Apple Silicon (lipo can invalidate Go's per-slice\n  signatures). Real Developer ID signing still overrides this when secrets exist.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "packaging: installers find a source-built binary; ad-hoc sign macOS u…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T20:01:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "498a46179f2d0a7165f2a2e2dfd44f0ad8334ccb",
          "body": "… Authenticode)\n\nBoth are guarded on their certificate secrets, so the pipeline keeps producing\nunsigned binaries until the secrets are added — then it signs automatically with\nno workflow change:\n- macOS: imports the Developer ID cert into a temp keychain, codesigns with a\n  hardened runtime + secu\n[…]\nndows: signtool Authenticode signing (SHA-256 + RFC-3161 timestamp) from a\n  base64 .pfx.\n\nREADME documents the required GitHub Actions secrets.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "ci: optional code signing + notarization (macOS Developer ID, Windows…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T19:27:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6654ea07e69bfa89124855badbe019c00636ac2",
          "body": "Discovery — the app probes http://karmax.local:9091 but the daemon advertised\nits A record under the machine's real hostname (mellob.local), so the name\nnever resolved. Now advertiseMDNS uses zeroconf RegisterProxy to claim a stable\n\"karmax.local\" (override KARMAX_MDNS_HOST) with the host's real WiF\n[…]\ne iOS audio session to `playback`\n(loud bottom speaker, plays through silent mode) before every utterance and\npasses volume: 1.0. No-op off iOS.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix: reliable LAN auto-discovery (karmax.local) + louder iOS TTS",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T19:26:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d87bdd9e0a27b51ad6bd5d5ac5b6875ca52660e",
          "body": ".github/workflows/release.yml builds installable binaries on native runners\n(CGO/SQLite is mandatory, so no cross-compile): Linux amd64 + arm64, a macOS\nuniversal binary (arm64+amd64 via lipo), and Windows amd64. On a `v*` tag (or\nmanual dispatch) it packages per-OS archives and publishes a GitHub R\n[…]\ns that detect OS/arch, download\n                       the right release archive, and run its installer\n\nREADME documents the one-line installs.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "ci: cross-platform release pipeline + background-service installers",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T18:57:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1a2f92e1dedce1b7e39e750dfa8f9779077bdf7",
          "body": "The hourly forgetting pass (TTL pruning + capacity cap) is no longer a\nhidden goroutine inside the memory manager: the runtime registers it as\nthe 'memory-maintenance' loop — visible in karmax loops list,\ndisableable, and manually triggerable — calling Maintain() across every\nnamespace. This was the\n[…]\n not depend on the loop system being healthy.\n\nLoop manifests gain informational events/webhook trigger fields;\nkarmax loops info displays them.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: memory maintenance becomes a loop; manifest trigger fields",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T14:14:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b401878a3fd7617de92a8ea956cd85770e1bd3db",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: install wa-monitor; loops list shows event/webhook triggers",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T13:29:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "edea09242c576aa7283308d13f7122427436ba8e",
          "body": "… core\n\nLoops can now declare Events: []string{\"comms.message\", ...} and fire on\nmatching internal bus events — fully event-driven, no polling, with the\nevent payload in Kit.Trigger().Payload. GET /api/loops reports event\ntriggers.\n\nThe proactive WhatsApp proxy (monitored-chat handling) is no longer\n[…]\n-triggered wa-monitor marketplace loop owns them now. Same\nevent-driven wacli-webhook flow, zero extra tokens, but relocated into a\nproper loop.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loopkit): event-triggered loops; WhatsApp proxy leaves the agent…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T13:26:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc4af9a06169dfd410964b147a1723837c5b38fb",
          "body": "…n config\n\ninstalledloops now imports tech-news, hot-sync, profile-refresh, and\ndaily-briefing from the marketplace registry by default (plus this\nmachine's installed loops: chat-sweep, act-on-pending, memory-bootstrap,\ngchat-watch, cold-scan). cold_scan: removed from karmax.yaml — the loop\nreads KARMAX_LOOP_COLD_SCAN_* env keys instead.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: ship the 4 default marketplace loops; drop deprecated cold_sca…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T12:59:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40964b4466a81ae319b6b3994b037070d0e1898c",
          "body": "…ove to the marketplace\n\nAll built-in loops (tech-news, hot-sync, profile-refresh, daily-briefing,\nchat-sweep, act-on-pending, memory-bootstrap, gchat-watch) and the cold-scan\nworker leave this repo — they now live in the public registry\n(MelloB1989/karmax-loops) as marketplace loops. internal/loops\n[…]\nmodel, no tools/memory\n- ChatSummary/SaveChatSummary: the cold-memory per-chat records the\n  retrieval sub-agent reads (cold-scan is the writer)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loopkit): Kit gains HostTool/Summarize/ChatSummary; core loops m…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T12:51:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8a3500a02149504b051620b52a46259c9c5b236",
          "body": "The marketplace is a single public GitHub registry repo\n(MelloB1989/karmax-loops, override with $KARMAX_LOOPS_REGISTRY):\n- loops/<name>/loop.json manifests; loop code lives either right in the\n  registry (default — no repo of your own needed) or in the author's own\n  module (manifest-only entry). Bo\n[…]\nanded a smoke loop (compile check +\ndirect commit); install hn-digest -> loop live in the daemon -> remove ->\nclean, service healthy throughout.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: public loops marketplace — registry repo, website, and CLI toolkit",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T11:46:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c45fa203e46a1d8407dc0b0f2bc318104df04f1",
          "body": "Auto-reminders (REMIND category):\n- Scan flows now have three deterministic outcomes instead of two:\n  ACTED -> notification, APPROVE -> approvals-inbox proposal, and new\n  REMIND -> a reminder created automatically on the operator's phone for\n  things ONLY they can personally do (send a document th\n[…]\nt now prefers it (the CLI's local registry can't see runtime-\n  registered loops), falling back to the local registry when the daemon\n  is down.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: auto-reminders from scans; cold-scan becomes a loopkit loop",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T11:01:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19024f3a869aab23732a3d1325491cbc39e0c54a",
          "body": "Four proactive paths surfaced APPROVE outcomes as plain app notifications\n(\"Needs your decision\"), which are informational and non-actionable — the\noperator had nothing to approve and nothing executed:\n- the WhatsApp proactive proxy (reportProxyOutcome)\n- the chat-sweep, act-on-pending, and gchat-wa\n[…]\nnever lost.\n\nloopkit: Kit gains Propose(title, summary, action) — loops must use it\n(never Notify) for anything needing the operator's decision.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix: route decisions to the approvals inbox, not the notification feed",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-03T10:42:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af0d70ad646c3c5c6f726cca26a9d98c8a085018",
          "body": "…ting fixes\n\nAudit of the orchestrator flow, CLI completeness, and hardcoded values.\n\nCLI parity (structural, not a hand-maintained list):\n- Agent now exposes its live bound toolset (ToolManifests/ExecuteTool) over\n  new API endpoints GET /api/tools and POST /api/tools/{name} — includes\n  agent-scop\n[…]\nent's memory namespace explicitly; loop\n  Harness() calls pass it through.\n- Env overrides documented in .env.example; README documents the CLI.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: full CLI/harness tool parity, centralized host paths, event-rou…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-02T20:34:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29f69d030f4fe8dea9f7375601096ea735ffaf31",
          "body": "Monitoring a group did nothing: the proxy path skipped every group message\n(isGroup → return with no action, no notification), so a monitored group could\nnever be addressed — the exact contradiction the operator hit on the CampX\ngroup.\n\nNow group messages go through the proactive proxy too, with a g\n[…]\nddressed.\n\nVerified on the live CampX group: a client's \"I'll update you\" acknowledgment\nis now correctly surfaced (APPROVE) instead of dropped.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(agent): monitored GROUP chats are handled, not silently skipped",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-02T08:49:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c280f27d6ab7c09c771f16d930dbda93d1055660",
          "body": "At high reasoning effort a turn can take a minute+, during which the operator\nsaw nothing and assumed the message was dropped. Now, for an incoming chat\nevent, if the turn is still running after ~6s, KARMAX sends a lightweight\n\"👀 on it…\" to the originating chat so the message is acknowledged immedia\n[…]\no\nextra ack). Complements the system-prompt guidance to narrate progress via\ncomms.send as work proceeds, rather than only reporting at the end.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(agent): slow-turn acknowledgement watchdog (visibility)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-02T08:44:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af70275070551d5974d604254b71a373ebd68d5a",
          "body": "Per feedback: whether to delegate to claude_code is an intelligence decision\nand must be made by KARMAX (the model), not by hardcoded keyword lists.\n\n- Removed the keyword-based pre-delegation and post-turn escalation\n  (isActionableTask / isSimpleTask / isClarifyingQuestion) and the associated\n  de\n[…]\nous background loops (proxy/sweep/gchat/bootstrap) keep using the\nharness as their executor, where the judgment comes from Claude, not keywords.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "refactor(agent): KARMAX decides delegation — no hardcoded routing",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-02T07:51:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e101ff17757c09dd0b4d864c682166d27d19442",
          "body": "sessions, simple-task triage\n\nGoogle Chat (gchat-watch loop): cheap Go-side polling of `gws chat spaces\nlist` every 2m — the LLM is only invoked when a space has NEW activity. The\nClaude harness then reads the thread and acts on the operator's behalf:\nroutine dev chores (e",
          "is_bot": false,
          "headline": "feat: Google Chat watch loop, memory context for claude_code, ephemeral",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-02T07:45:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "322b41c96e1c09a88a3b9a303fcf688ceb1b1a88",
          "body": "Per feedback: the \"act on scan findings\" logic didn't belong hardcoded inside\nthe memory-bootstrap loop. Extracted it into its own loopkit loop.\n\n- memory-bootstrap now only DISCOVERS: it distills facts (→ memory) and pending\n  actionable items (→ a persisted queue), then triggers the executor.\n- Ne\n[…]\nue) decouples the two and\n  survives restarts.\n- loopkit Kit gains RunLoop(name) so one loop can trigger another instead of\n  inlining its work.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "refactor(loops): act-on-pending loop (decouple discovery from execution)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-02T05:42:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7de81a6009dfd2f81671b8f00c2cde10e6a2ee8d",
          "body": "The webhook proxy only reacts to NEW incoming messages, so items already\npending in monitored chats (an unanswered question, a promised action, a\ndeadline) were never acted on — KARMAX looked idle right after monitoring was\nenabled.\n\nNew `chat-sweep` loop (every 4h + manual): reads the monitored-cha\n[…]\newed 6 chats — 0 auto-acted, 2 correctly\nescalated for approval (a business offer-letter request and two open items),\neach with a drafted reply.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loops): chat-sweep — proactively handle the pending backlog",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-02T05:30:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc912963e0055e26e725ef8a6e6cd44ed879d76a",
          "body": "Deep initial memory: a new `memory-bootstrap` loop scans the operator's\nWhatsApp history and builds detailed long-term memory. The heavy\nreading/distillation runs in the Claude harness sub-agent (its own token\nbudget — not the codex main model): each batch of 4 chats is read via the\nwacli CLI (250 m\n[…]\nxy delegation failures now push an alert (\"couldn't handle —\nX\") instead of dying silently, so nothing goes unhandled while the operator\nsleeps.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(memory): WhatsApp history bootstrap + monitored-chat management",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T20:16:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0df6ea99e517f879d02be604a28f5b3a678ad8ee",
          "body": "KARMAX now watches a CURATED set of chats and acts on the operator's behalf,\ninstead of only reacting when told. Which chats are watched is decided by the\nwacli webhook scope (selected_chats), which KARMAX curates via the `wacli` tool\n— community/promo groups are never monitored, so no wasted LLM ca\n[…]\ns manager event,\nand an operator-chat identity (SetOperatorChats) so command vs proxy is\ndistinguished across the WhatsApp phone-JID/@lid split.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(agent): proactive WhatsApp proxy — act on the operator's behalf",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T19:29:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88c27beed7c2ce776e30731d5784cd4b6501e574",
          "body": "Even with post-turn delegation, the mini model still leaked a fabricated\ncompletion: it calls comms.send(\"Done, I added it\") mid-turn (before the tool\nloop returns), so the fake reply reached the user before the real work — and\nthat mid-turn send isn't reliably visible to the post-turn guard.\n\nFix: \n[…]\nied live: delegated \"setup a meet + add to calendar\" -> claude_code created\nthe Google Calendar event with a Meet link and invited the attendee.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(agent): pre-delegate actionable tasks (kill the fabricated \"done\")",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T18:49:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cea67fc9194271e973b2b7c9db97c60def1bf5f0",
          "body": "The mini orchestration model (gpt-5.4-mini-high) fabricates completion for\nactionable requests — e.g. it replied \"Done, I added the calendar event\" while\nmaking ZERO tool calls, so nothing happened and the user was misled.\n\n- When an incoming chat message is an actionable task but the model produced\n[…]\n- Fix the google_workspace tool path: gws lives at ~/.hermes/node/bin/gws, not\n  ~/.local/bin/gws, so the tool was pointing at a missing binary.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(agent): delegate unexecuted tasks to claude_code; fix gws path",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T18:22:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca96502e0a0c3931632e7c8b46d6a2d4b25af29e",
          "body": "Incoming WhatsApp/chat messages could go stale with no response: the agent\ngenerated a reply but only delivered it if the model explicitly called\ncomms.send. The small orchestration model often just returns text (or\nacknowledges a task without acting), so its reply was logged and thrown away —\nthe u\n[…]\n\n\nSkipped when comms.send was called (no double-send) or when the model acted via\nanother tool but returned no text (avoids a misleading error).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(agent): never silently drop a chat reply (fallback auto-delivery)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T18:06:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d56562c4ee1e74063747b4fa0847460bcd46dda9",
          "body": "… after\n\nThe approval gate previously fired on every third-party message, which is\nKARMAX's core job — so it asked constantly. Switch messaging to act-and-inform:\n\n- `propose` now gates ONLY genuinely critical, hard-to-undo actions: spending\n  money/purchases, posting publicly, or deleting/overwriti\n[…]\ner).\n\nAlso registers memory.forget as an agent-scoped tool so it stops being flagged\n\"unknown (skipped)\" and is properly available to the agent.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(comms): act-and-inform — send to others without approval, notify…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T13:34:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d573a8c000152107df44c9273942fd93af43ada",
          "body": "Make memory prioritized, reinforced, self-correcting, and self-pruning\ninstead of a flat append-only keyword store.\n\nStructured metadata (real columns, not brittle \"[cat][imp]\" text prefixes):\n- memory_entries gains category, importance (1=low..4=critical), pinned,\n  access_count, last_accessed_at, \n[…]\nstaff. System prompt updated to use pin/rate/ttl/forget.\n\nAdds relevanceBoost unit tests (importance ordering, recency decay, pinned\ndominance).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(memory): agentic, personal-assistant long-term memory",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T08:04:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f5eb3b01497e0eabcaeefbb3b300ccb2cb9c03a2",
          "body": "… bridge\n\nWhatsApp is now event-driven and KARMAX no longer hardcodes any chat.\n\nConsumer model (no polling, no hardcoded chats):\n- The channel is a pure webhook consumer: it exposes /comms/whatsapp on the\n  webhook server, verifies the wacli HMAC signature (X-WACLI-Signature, secret\n  from WHATSAPP\n[…]\net and system prompt.\n\nAlso narrows the `propose` approval tool to critical/third-party/irreversible\nactions only (was gating ordinary replies).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(whatsapp): event-based via wacli webhooks + agent control of the…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T07:44:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5233a85061f247ec2cffa1ad75bb53d0674dc625",
          "body": "Loops can now fire on three trigger kinds, not just cron:\n- schedule (cron / interval), webhook (route), and manual (on-demand).\n- loopkit.Loop gains a Webhook field; Kit gains Trigger() so a loop can\n  see how it was invoked. Manual-only loops (no schedule, no webhook) are\n  valid. Runtime register\n[…]\n monitor and the command channel actually dispatch new\nmessages. Verified end-to-end: operator message → agent → reply, with\nno self-reply loop.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loops+comms): multi-trigger loops + WhatsApp command channel",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-07-01T01:39:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0882ce1c4527e21d398e62cc2a220eb2876e47e5",
          "body": "…rune\n\nLoops:\n- disable/enable any loop by name without a rebuild (~/.karmax/loops-disabled.txt);\n  the runtime skips disabled loops and the `karmax loops` TUI gains an\n  Enable/disable toggle screen. Works for built-in and installed loops.\n- prune stale persisted scheduler jobs on startup (old YAML\n[…]\nropped the placeholder actions that had no backing endpoint.\n- `karmax doctor` gained a loop-build environment section (Go/git/cc/source/loops).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: loop disable/enable, setup wizard, real CLI commands, doctor, p…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-30T17:23:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa06116371867e2d222d16d186063fd12a21c2b9",
          "body": "Replace the hand-rolled os.Args switch in main.go with a cobra command tree,\nsplit into focused files:\n  main.go         entry + shared helpers (loadDotEnv, findConfig, Version)\n  root.go         root command, --config persistent flag, wiring (Execute)\n  runtime_cmd.go  start, init, doctor, status\n \n[…]\nelp + shell completion. Behavior preserved; 'karmax start' (the\nsystemd entrypoint) verified to still boot. Drops the custom min() (Go builtin).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "refactor(cli): rebuild the CLI on spf13/cobra, well-structured",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-30T15:26:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e807c2c7db302b91f22616132b3f146c0b94f77f",
          "body": "… delivery\n\nAdd Kit.SendWhatsApp(ctx, target, content) (backed by the comms manager) so a\nloop can deliver to a WhatsApp recipient directly. Rework daily-briefing: the\nagent only COMPILES the briefing text now; the loop delivers it deterministically\nvia Notify (app feed) + SendWhatsApp (number from \n[…]\n dependency on a smaller model remembering to call both delivery\ntools. Verified live: briefing landed in the app feed AND was sent to WhatsApp.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loopkit): SendWhatsApp capability + deterministic daily-briefing…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-30T15:01:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a57b8194befe1f39fcb2b2da5db1122d553f098",
          "body": "Port tech-news, hot-sync, profile-refresh, and daily-briefing out of the\nkarmax.yaml loops: section into internal/loops/core (loopkit Go loops),\nblank-imported by cmd/karmax. The live karmax.yaml loops list is now empty.\n\n- tech-news runs via the Claude harness (k.Harness) + k.Remember; guards again\n[…]\nurce. The hndigest example is deactivated (kept as a template).\n\nVerified: all 4 register at startup; tech-news fetches + ingests a real digest.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loops): migrate built-in loops from YAML to loopkit plugins",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-30T13:50:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44123818b8d2925ebf53240813da31c0d07956d1",
          "body": "Loops can now be authored as real Go code instead of one-line YAML prompts:\n\n- pkg/loopkit: public SDK (importable as github.com/MelloB1989/karmax/pkg/loopkit).\n  Loop{Name,Description,Schedule,Run} + a Kit capability interface\n  (Ask/Harness/Remember/Recall/Notify/ReadWhatsApp/HTTP/Config/Logf) + R\n[…]\nns, like Caddy/xcaddy).\nVerified end-to-end: hn-digest fetches HN, summarizes via the harness, and\npushes a digest to the app notification feed.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(loops): loopkit SDK + installable third-party loops + TUI",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-29T21:38:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c18a54bb042f64d8e9960d37e4b5d854f5e1a86b",
          "body": "When a proposal is rejected WITH a note, feed that feedback back to the agent\nso it reworks its approach and submits a revised proposal via the propose tool.\nPlain reject (no note) still just drops it.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(api): reject-with-feedback retries instead of silently dropping",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-29T21:13:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53cfa44c4253a26bfec11b3f20835ebc9a3ab9f7",
          "body": "TTS (expo-speech): listen/stop on assistant replies and notifications\n(briefings read aloud), markdown-stripped speech, and a persisted auto-speak\ntoggle in settings (useSpeech store; stops on dictation so they don't overlap).\n\nSTT (expo-speech-recognition): a mic button in the chat composer dictate\n[…]\nd: bun run lint clean, tsc --noEmit exit 0 (was 5 errors). Both voice\npackages are native modules — they activate in a fresh dev/internal build.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(app): voice — text-to-speech + speech-to-text",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-29T03:34:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1b9fde090d19c51b6c314dbbf77c482f61ff413",
          "body": "The current Claude CLI rejects '--session-id X --resume' ('--session-id can\nonly be used with --continue/--resume if --fork-session is set'), so resuming a\nprior coding session was silently broken. Use '--resume <id>' to resume and\n'--session-id <id>' only for new sessions (CLI- and end-to-end verif\n[…]\nhe task description with a\n  containment metric (was Jaccard over description+full-output, which tanked\n  the score even for an identical task).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix: claude_code session resume + harden multi-session continuity",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-28T14:01:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30dd7687b9bf4b5fc2815967fa0675446b77a9a6",
          "body": "…-feedback\n\nBackend:\n- notifications subsystem: notifications table + store + API\n  (GET /api/notifications, /{id}/read, /read-all). app.push now persists every\n  notification before pushing, so the in-app feed survives missed pushes.\n- loop \"harness\" option: a loop can run its prompt directly throu\n[…]\ned cards show the note.\n- inbox tab badge counts pending approvals + unread notifications.\n- notification taps deep-link to the right inbox tab.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: in-app notifications feed, codex-independent loops, reject-with…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-28T10:59:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "775d63d0bfc6b2770b5576575ebb3d53e3671eb7",
          "body": "Fixes the 502 on tool-heavy Codex requests: dotted tool-name sanitize+restore,\nstrips the history:null schema leak (the real blocker), and item_id/call_id arg\ncorrelation. Verified: the full 20-tool agent runs on gpt-5.5-high over WebSocket.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karma to v1.19.1 — Codex now runs the full tool-using agent",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T20:59:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7c83bd6069f3ea77d39bc66bbd09896e7e56edd",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karma to v1.19.0 (Codex WebSocket transport + HTTP fallback)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T19:02:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "baf93f1c286f99816a92e668942e17409c63bedb",
          "body": "…ry-After backoff)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bump karma to v1.18.2 (shared Codex session, CF detection, Ret…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T18:25:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a86576ccc68417ac432ce86af04a222a9326c4fc",
          "body": "- Bump karma to v1.18.1 (Codex SSE errors now classified as *APIError with an\n  HTTP-equivalent status: rate_limit->429, codeless response.failed->502, etc.,\n  plus an in-handler retry for transient failures).\n- karmahelper.isRetryableError now uses ai.IsCodexRetryable(err) so transient\n  Codex failures (429/5xx, codeless response.failed) are retried with backoff\n  instead of aborting the fallback chain.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: karma v1.18.1 — surface real Codex errors + retry transient ones",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T11:38:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ade87294375d1f5165222d8852059097213a3a3",
          "body": "getContactsAsync/addContactAsync were moved out of the main expo-contacts entry\nin SDK 56; import them from expo-contacts/legacy so the sync works.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(app): import expo-contacts legacy API to fix contacts sync (SDK 56)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T11:13:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b45a89453b3b79b5156cfcc4e412350867bc4b64",
          "body": "- Config tab: a 'contacts' section with a 'sync contacts' button (reads the\n  phone directory and uploads it) plus result feedback.\n- Memory screen: a status line showing how many contacts are linked.\n- Hooks: useContactsStatus (GET /api/contacts) + useSyncContactsNow.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat(app): contacts sync button in config + linked-count in memory",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T11:11:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddca89f17289ef4296bfbfede18544eeae0e6b17",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "docs: use a fake example number in contact-resolution comments",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T11:07:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4308d8097fe99b31b262c4b65e2e106cf90bcb49",
          "body": "- Backend: contacts table + store (upsert/lookup with country-code-tolerant\n  suffix match) + POST /api/contacts/sync, GET /api/contacts.\n- whatsapp.read now resolves sender/chat JIDs to the operator's saved contact\n  names (sender_name / chat_name / contact_name), so the agent — and therefore\n  mem\n[…]\npeople by name, not number.\n- App: getAllContacts() reads the phone directory; useContactSync uploads it to\n  KARMAX once per session on launch.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: link phone contacts -> resolve WhatsApp numbers to saved names",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T11:06:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "393bf525d808eec9af933ef6643b56b3b4074f7b",
          "body": "Conversation turns (chat questions, agent replies, incoming WhatsApp messages)\nand compaction summaries were auto-stored, flooding memory with chatter that\npolluted the cleanup and relationship graph. Both auto-ingest paths are now\nno-ops; durable facts come only from explicit memory.ingest calls.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(memory): stop auto-ingesting chat turns & compaction summaries",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T10:46:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9daf607e028b117724247e4c963368e1b2b52fca",
          "body": "- Bump github.com/MelloB1989/karma to v1.18.0 (adds the in-process Codex\n  provider: gpt-5.5 / gpt-5.4 / gpt-5.4-mini, auth via ~/.codex/auth.json).\n- karmahelper: map provider \"codex\" -> ai.Codex so KARMAX can run Codex models\n  directly (bypassing the gateway). Codex model slugs pass through resol\n[…]\n memory retrieval, cleanup, and the relationship graph run on\nCodex when Claude access is unavailable. (Live model selection is in karmax.yaml.)\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: karma v1.18.0 + native Codex provider",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T10:16:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f316aa8aa5f8b3ded203aee5fea38f610d2dd066",
          "body": "- New memory_links table + store; an LLM (api/graph.go) maps relationships\n  between memory entries (same person, part-of, depends-on, led-to, …) using\n  short ids it can echo reliably, stored and served via GET /api/memory/graph\n  and POST /api/memory/graph/rebuild.\n- App: the 3D memory tab is now \n[…]\nh Claude access down the\ngateway fallbacks can't produce it (deepseek/Kiro refuses, glm-5 too slow), so\nit populates once Claude access returns.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: LLM-generated relationship memory graph",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T09:11:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a7fd354afbdb9883032809edaf250b37eb1626e",
          "body": "- Memory cleanup: filter AI/system/scaffolding entries out of candidates and a\n  relevance-focused prompt (specific questions about the operator's people/\n  projects/commitments, relationship-aware, never about the AI/system).\n- Contacts: add expo-contacts (lookupNameByPhone + createContact), a\n  create_contact device action, and a backend contact.add tool so KARMAX can\n  save a name+number to the phone (WhatsApp only exposes numbers).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: relevance-focused memory cleanup + contacts (resolve/create)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T08:49:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "addd340a0f9a9b04ca51083adff5fc0c478f62f2",
          "body": "…cale fix\n\nBackend cleanup:\n- Remove the entire web dashboard (the app replaces it) and all its wiring,\n  config (DashboardConfig + defaults), and references.\n- Remove the unused config watcher and 14 dead functions (verified via\n  deadcode); gofmt the tree.\n\nApp:\n- iOS background execution: expo-ba\n[…]\n connectivity: NSAppTransportSecurity (allow cleartext to the\n  CGNAT 100.x range, which iOS otherwise blocks) + NSLocalNetworkUsageDescription.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: remove dashboard + dead code; app background execution + Tails…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-26T07:53:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4a669dee40cdf767d9c1a6a1e09e8be4169e874",
          "body": "Co-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "docs: add KARMAX logo to README",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-25T20:28:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9161a0fda5b6dbc873de3c785a7d76d228f1410",
          "body": "- Add /app — the Expo/React Native cockpit (chat, inbox, activity, memory\n  explorer with 3D page-index, config) — source only (node_modules ignored).\n- Add a proper top-level README (overview, architecture, setup, security).\n- Scrub personal data for public release: generic connection defaults and\n  settings placeholder (no hardcoded Tailscale/LAN IPs).\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "chore: bring companion app into the monorepo + add README",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-25T20:22:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f52e072d171d6956efe361c4074fde1bffb9c394",
          "body": "…D details\n\n- /api/messages now serves a dedicated app_messages thread (not the agent's full\n  working history); add new-conversation reset endpoint.\n- Fix coding harnesses: run claude/codex with KARMAX's gateway env stripped and\n  --dangerously-skip-permissions so web search/tools actually work (te\n[…]\norrection.\n- Cold scan: skip community/promo groups by the operator's own-message ratio.\n- Scrub personal phone number from karmax.yaml.example.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: app-only chat thread, harness web-search fix, memory cleanup, 3…",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-25T20:20:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3457fae3a4e6fffbce2fcd8eee749f69bd746ca",
          "body": "- Decide cold vs hot by the operator's OWN last message in a chat (not the\n  chat's overall activity), so busy groups the operator no longer texts in\n  correctly go cold.\n- Don't skip \"locked\" chats: with wacli access control unconfigured every chat\n  defaults to locked yet reads work, so skipping t\n[…]\n re-check at most once\n  per 24h; bound wacli lookups per tick.\n- Process oldest chats first so genuinely-cold conversations summarize promptly.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "fix(coldscan): key hot/cold on operator's own-message recency",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-25T18:43:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82b26e6f0070851ec83050ad9680bbccafd801c3",
          "body": "Memory (this round):\n- memory.retrieve is now an agentic opus-4.6 sub-agent with its own tools\n  (profile_read, mem_search, mem_recent, tree_search, chat_summaries, live\n  whatsapp.read) that runs multi-query retrieval and returns synthesized\n  context — mirrors the page-index retrieve_context patte\n[…]\n server (chat/proposals/activity/memory/profile/device-actions/\nintegrations) + mDNS, push tokens, device actions, calendar/reminder/push tools.\n\nCo-Authored by MelloB's coding agent <build@mellob.in>",
          "is_bot": false,
          "headline": "feat: agentic memory overhaul + hot/cold pipeline (and session buildout)",
          "author_name": "Kartik Deshmukh",
          "author_login": "MelloB1989",
          "committed_at": "2026-06-25T18:28:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d818ddccd9fdd4b345d3ef3cb5098c427e20a9c2",
          "body": "- Detect proxy error messages returned as response content (quota exceeded,\n  rate limit, etc.) and treat as retryable instead of forwarding to Discord\n- Add scheduler.add tool so the agent can schedule delayed and recurring tasks\n  (e.g., \"remind me in 5 mins\", \"check status every hour\")\n- Register scheduler tool in runtime with access to the scheduler instance\n\nGenerated by MelloB's coding agent <kartik@lyzn.ai>",
          "is_bot": false,
          "headline": "feat: detect proxy quota-exceeded responses, add scheduler tool",
          "author_name": "KODEXIS -MelloB's Coding Agent",
          "author_login": "mellob-ai",
          "committed_at": "2026-06-04T19:27:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "994acfc9a59b460ba8e9963d0ec15119b0d044af",
          "body": "Root cause: with UseMCPExecution=true, karma executes comms_send\ninternally but does NOT report it in toolCalls. So every check\nfor \"did comms_send fire?\" was always false, triggering the fallback\nauto-reply on top of the LLM's own comms_send call.\n\nFix: remove ALL auto-reply paths. The LLM replies \n[…]\nol loop. If it doesn't\ncall comms_send, that's intentional (internal processing).\n\nAlso: WhatsApp poll interval 5s → 30s to prevent quota flooding.\n\nGenerated by MelloB's coding agent <kartik@lyzn.ai>",
          "is_bot": false,
          "headline": "fix: completely remove auto-reply, throttle WhatsApp polling to 30s",
          "author_name": "KODEXIS -MelloB's Coding Agent",
          "author_login": "mellob-ai",
          "committed_at": "2026-06-04T19:14:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8109aeef9b69a87285aa688329cc10d32e34cf62",
          "body": "- Remove auto-reply: LLM now replies exclusively via comms_send tool call.\n  Only sends a fallback if the LLM did NOT call comms_send during its turn.\n- Fix AlertAlternative: skip channels with no known target instead of sending\n  to empty string (which caused Discord 405 Method Not Allowed)\n- Update system prompt: LLM must always use comms_send to reply, text response\n  is internal only\n\nGenerated by MelloB's coding agent <kartik@lyzn.ai>",
          "is_bot": false,
          "headline": "fix: eliminate duplicate Discord replies, fix empty target 405 errors",
          "author_name": "KODEXIS -MelloB's Coding Agent",
          "author_login": "mellob-ai",
          "committed_at": "2026-06-04T18:58:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 3,
      "commits_last_year": 112,
      "latest_release_at": "2026-07-03T20:08:17Z",
      "latest_release_tag": "v0.1.2",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 23,
      "mean_days_between_releases": 0
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": true,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/MelloB1989/karmax",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/MelloB1989/karmax",
          "is_deprecated": false,
          "latest_version": "v0.1.2",
          "repository_url": "https://github.com/MelloB1989/karmax",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-03T20:01:07Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 23
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-04",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "app/tsconfig.json"
      ],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 45325,
      "source_files_sampled": 157,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "app/AGENTS.md",
        "app/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 118
    },
    "dependencies": {
      "manifests": [
        "app/package.json",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "@expo-google-fonts/jetbrains-mono",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "@expo-google-fonts/space-mono",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.2"
        },
        {
          "name": "@expo/ui",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.18"
        },
        {
          "name": "@react-three/fiber",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.6.1"
        },
        {
          "name": "@tailwindcss/postcss",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.1"
        },
        {
          "name": "@tanstack/react-query",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.101.0"
        },
        {
          "name": "clsx",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "expo",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.12"
        },
        {
          "name": "expo-background-task",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.19"
        },
        {
          "name": "expo-calendar",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.8"
        },
        {
          "name": "expo-clipboard",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^56.0.4"
        },
        {
          "name": "expo-constants",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.18"
        },
        {
          "name": "expo-contacts",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.9"
        },
        {
          "name": "expo-dev-client",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.20"
        },
        {
          "name": "expo-device",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.4"
        },
        {
          "name": "expo-font",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.7"
        },
        {
          "name": "expo-gl",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.5"
        },
        {
          "name": "expo-glass-effect",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.4"
        },
        {
          "name": "expo-image",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.11"
        },
        {
          "name": "expo-linking",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.14"
        },
        {
          "name": "expo-notifications",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.18"
        },
        {
          "name": "expo-router",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.2.11"
        },
        {
          "name": "expo-secure-store",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.4"
        },
        {
          "name": "expo-speech",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.3"
        },
        {
          "name": "expo-speech-recognition",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^56.0.1"
        },
        {
          "name": "expo-splash-screen",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.10"
        },
        {
          "name": "expo-status-bar",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.4"
        },
        {
          "name": "expo-symbols",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.6"
        },
        {
          "name": "expo-system-ui",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.5"
        },
        {
          "name": "expo-task-manager",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.19"
        },
        {
          "name": "expo-updates",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.19"
        },
        {
          "name": "expo-web-browser",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~56.0.5"
        },
        {
          "name": "nativewind",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "5.0.0-preview.4"
        },
        {
          "name": "react",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "19.2.3"
        },
        {
          "name": "react-dom",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "19.2.3"
        },
        {
          "name": "react-native",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.85.3"
        },
        {
          "name": "react-native-css",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "3.0.7"
        },
        {
          "name": "react-native-gesture-handler",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~2.31.1"
        },
        {
          "name": "react-native-markdown-display",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.2"
        },
        {
          "name": "react-native-reanimated",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.3.1"
        },
        {
          "name": "react-native-safe-area-context",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~5.7.0"
        },
        {
          "name": "react-native-screens",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.25.2"
        },
        {
          "name": "react-native-web",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "~0.21.0"
        },
        {
          "name": "react-native-worklets",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.8.3"
        },
        {
          "name": "tailwind-merge",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.6.0"
        },
        {
          "name": "tailwindcss",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4"
        },
        {
          "name": "three",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.184.0"
        },
        {
          "name": "zod",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "zustand",
          "manifest": "app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.14"
        },
        {
          "name": "github.com/MelloB1989/karma",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.1"
        },
        {
          "name": "github.com/MelloB1989/karmax-loops",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260723211929-ac1f3852431e"
        },
        {
          "name": "github.com/bwmarrin/discordgo",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.29.0"
        },
        {
          "name": "github.com/charmbracelet/bubbles",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/charmbracelet/bubbletea",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.10"
        },
        {
          "name": "github.com/charmbracelet/lipgloss",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/go-chi/chi/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.2.1"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/grandcat/zeroconf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/joho/godotenv",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.1"
        },
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.24"
        },
        {
          "name": "github.com/robfig/cron/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.27.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "MelloB1989",
          "commits": 98,
          "avatar_url": "https://avatars.githubusercontent.com/u/63499572?v=4"
        },
        {
          "type": "User",
          "login": "mellob-ai",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/251566315?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.875
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "42 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "eb1514c4604c4a31ce027c96b24767577dd1c8c8",
        "ran_at": "2026-07-27T06:19:52Z",
        "aggregate_score": 2.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T21:23:27Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/MelloB1989/KARMAX",
    "host": "github.com",
    "name": "KARMAX",
    "owner": "MelloB1989"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 50,
      "inputs": {
        "security": 26,
        "vitality": 71,
        "community": 36,
        "governance": 39,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 71,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 112,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "112 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 112
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 3,
              "latest_release_tag": "v0.1.2",
              "releases_from_tags": false,
              "days_since_latest_release": 23,
              "mean_days_between_releases": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "3 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 23 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 23
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 36,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 39,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.875
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 88% of commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 88
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "followers": 50,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "MelloB1989",
              "public_repos": 167,
              "account_age_days": 2297
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "50 followers of MelloB1989",
                "points": 12.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 50,
                      "login": "MelloB1989"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "167 public repos, account ~6 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 167
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 6
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/MelloB1989/karmax"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 23
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 23 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 23
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "3 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 26,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 26,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 2.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "42 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 72,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "moderate",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "app/AGENTS.md",
                "app/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 118
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "app/AGENTS.md, app/CLAUDE.md (stub)",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "app/AGENTS.md, app/CLAUDE.md"
                    }
                  },
                  {
                    "code": "agent_instructions_stub",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "app/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "app/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "app/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 45325,
              "source_files_sampled": 157,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/157 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 157,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T06:19:56.967413Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/MelloB1989/KARMAX.svg",
  "full_name": "MelloB1989/KARMAX",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.