Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-28 18:55 UTC

SVGreg / skill-guard

Security, signing & provenance toolchain for Agent Skills (`SKILL.md`).

Go · PythonNo license detected★ 1 star⑂ 0 forkssince Jul 2026View on GitHub ↗

SVGreg/skill-guard holds a health index of 48 out of 100, placing it in the At risk band. It scores highest on Engineering Quality (70/100) and lowest on Community & Adoption (12/100). It was last updated today. A single contributor accounts for most of its recent work.

48
overall / 100
At risk

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

48
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Sergii TarasovPersonal account
5 followers7 public repossince Jul 2012

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/SVGreg/skill-guardv0.1.11-120 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

69Moderate · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
1.4/36Commit cadence — 2/52 weeks with commits
17.5/18Commit volume — 87 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year87
human_commit_share0.872
days_since_last_push0
active_weeks_last_year2
How it's scored
27/27Ships releases — 12 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~0.8 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count12
latest_release_tagv0.1.11
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases0.8

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

12Critical · 18% of overall
How it's scored
0/60Stars — 1 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
0/22.5License — no license file detected
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

49At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
23.4/46.8Issue resolution — 50% of issues closed
38.2/38.3PR acceptance — 74/74 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/28 approved changesets -- score normalized to 0
Inputs used
merged_prs74
open_issues8
closed_issues8
issue_closed_ratio0.5
closed_unmerged_prs0
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
5.6/25Owner reach — 5 followers of SVGreg
18.6/25Track record — 7 public repos, account ~14 yr old
Inputs used
followers5
owner_typeUser
is_verified
owner_loginSVGreg
public_repos7
account_age_days5,116
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 0 days ago
20/20Version history — 12 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/SVGreg/skill-guard
ecosystemsgo
any_deprecatedno
min_days_since_publish0

Engineering Quality

Are baseline engineering and documentation practices in place?

70Good · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
18/20OpenSSF Scorecard: CI-Tests — 29 out of 30 merged PRs checked by a CI test -- score normalized to 9
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

33At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.2/2.5CI-Tests — 29 out of 30 merged PRs checked by a CI test -- score normalized to 9
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/28 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5License — license file not detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3.3

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

70Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 82 of 82 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes8,877
How it's scored
12.6/18One-command bootstrap — go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 71 of the last 94 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.755
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
53.4/55Manageable file sizes — 1/34 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes69,625
source_files_sampled34
oversized_source_files1
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalyes
api_schema_files

Key facts

1GitHub stars
1contributors
87commits, last 12 months
0days since last push
12releases
1bus factor
8open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 3.3 / 10
3.3aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-28 18:55 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
9CI-Tests29 out of 30 merged PRs checked by a CI test -- score normalized to 9
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/28 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 2
RegistryPackageVersion constraintManifest
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 667,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 202642,
        "Shell": 4542,
        "Python": 35981
      },
      "pushed_at": "2026-07-28T18:45:07Z",
      "created_at": "2026-07-17T13:19:04Z",
      "owner_type": "User",
      "updated_at": "2026-07-28T09:33:16Z",
      "description": "Security, signing & provenance toolchain for Agent Skills (`SKILL.md`).",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Sergii Tarasov",
      "type": "User",
      "login": "SVGreg",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/2041723?v=4",
      "created_at": "2012-07-25T17:13:56Z",
      "is_verified": null,
      "public_repos": 7,
      "account_age_days": 5116
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.11",
          "kind": "patch",
          "published_at": "2026-07-28T06:53:13Z"
        },
        {
          "tag": "v0.1.10",
          "kind": "patch",
          "published_at": "2026-07-26T21:35:18Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-07-25T17:44:39Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-07-25T07:27:51Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-07-24T09:17:14Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-07-24T08:23:02Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-07-23T22:19:21Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-07-23T17:35:18Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-07-22T11:46:15Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-07-20T16:50:03Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-07-20T12:50:43Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-19T17:13:26Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "530c0818989df8bf3c46a70dc50f304b4beee795",
          "body": "…A) (#90)\n\nFiles an uncovered, unplanned AST04/AST01 threat: a bundled MCP tool/server\ndescription engineered to bias the agent's tool selection (\"always use this\ntool\", \"the only reliable option\", \"do not use any other server\"), so a rogue\nserver intercepts calls meant for a trusted tool. Distinct \n[…]\nority section in\nrule-verification.md + P2 backlog row. Tracking issue #89. Source: MPMA\nwrite-ups; Adversa AI MCP resources; OWASP MCP Top 10.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-MCP-002 — MCP tool preference manipulation (MPM…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-28T09:32:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a92398becc8b7a58f17a4bd6d521c7d98dd5a8bb",
          "body": "The corpus fetcher can write additional batches (e.g. clawhub_more/) via its\nOUTDIR override, but .gitignore only named clawhub/, leaving the expansion dirs\nuntracked — a future `git add -A` could commit hundreds of fetched skill\nbundles. Broaden to the clawhub* glob so every batch stays local.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: gitignore evaluation/clawhub* expansion corpus dirs (#88)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-28T09:27:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d9f601759b8115ef25b18ba30029a8240219b249",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.11 (#77)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-28T06:52:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3de0c28629ff08025b1c3186d0384e32479f6c8c",
          "body": "…(#87)\n\nA skill's description is its activation trigger — the agent reads it to decide\nrelevance. A description claiming the skill applies to any/every task (rather\nthan a scoped domain) over-claims that trigger and steers the agent onto\nunrelated work: the activation-surface analogue of over-broad \n[…]\nn 240 skills: 0 SG-TRIG-001 findings, no FPs.\nDocs: rule-verification §SG-TRIG-001 marked implemented, planned-rules,\nowasp-ast-taxonomy AST04.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-TRIG-001 — over-broad activation trigger (AST04) …",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-28T06:51:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "970e438701ca6783bd353f604fb7f502c7a2e2c9",
          "body": "SG-EXE-002 only saw `rm -rf`, `shutil.rmtree`, `chmod -R 777`, and `mkfs`/`dd`,\nso a destructive wipe expressed any other way slipped through: `find … -delete`\n/ `-exec rm`, Node `fs.rmSync({recursive,force})` / `rimraf()`, Python\n`os.remove`/`os.unlink` on a broad path, PowerShell `Remove-Item -Rec\n[…]\nuctiveFilesystemCoversVariants (15 TP, 8 benign). Corpus regen 240\nskills: 0 → 0 SG-EXE-002 findings, no FPs, no lost detections. Docs updated.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-EXE-002 to cover non-rm-rf destructive ops (#86)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-28T06:45:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "75dea6fa774d72c585ef15cdaf9ba4f68d3dd9d5",
          "body": "… language (#85)\n\nclassify()'s shebang fallback recognized only sh/python/node/ruby and labeled\nevery match \"bash\". Two consequences:\n\n- An executable shipped without a script extension but with a `#!/usr/bin/perl`\n  or `#!/usr/bin/php` shebang — both languages scriptExt already covers by\n  extensio\n[…]\ng the real language.\nAdds TestShebangClassifiesExtensionlessScripts (8 cases incl. the perl/php/python\nregressions and two non-shebang assets).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(skill): classify extensionless perl/php scripts and label shebang…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-28T06:44:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3639772e2008fe15d1ac9816842696d2688b2c8b",
          "body": "… (#84)\n\nA skill that tells the agent to hide its own action from the user (\"do not\nmention this to the user\", \"act silently and do not report\", \"without the\nuser's knowledge\") turns the agent into a co-conspirator: it performs a\nsensitive step and suppresses the disclosure the user would otherwise \n[…]\nJ-010 findings, no FPs. Docs: rule-verification §SG-INJ-010,\nplanned-rules -> implemented, owasp-ast-taxonomy AST01 in-scope list.\n\nCloses #82.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-INJ-010 — concealment / secrecy directive (AST01)…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-28T06:43:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd7025f3bc7d8ef0cb2b4dd887697d8e92ef1373",
          "body": "…research (#83)\n\nFiles a genuinely-uncovered AST01 threat: skill prose that tells the agent to\nhide an action from the user (\"do not mention this to the user\", \"act silently\nand do not report\", \"keep this hidden\"). A standalone deception primitive —\nSG-INJ-001 needs an override verb, SG-INJ-009 is r\n[…]\nd §7a + P1 backlog row in planned-rules.md. Tracking issue #82.\nSource: \"Do Not Mention This to the User\" (arXiv 2602.06547); Snyk ToxicSkills.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-INJ-010 — concealment / secrecy directive from …",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T15:29:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2a18b6a5fe6a2c79261e626a4219d1e781752605",
          "body": "…T01) (#81)\n\nA logic bomb scans clean and behaves benignly during review, then activates a\ndestructive or exfiltrating branch once a hidden trigger fires — a future\ncalendar date, an invocation counter, or a \"nobody is watching\" / \"only in\nproduction\" gate. A rule that looked only for the action wou\n[…]\nkills: 0 SG-INJ-008 findings, no FPs. Docs: rule-verification §SG-INJ-008,\nplanned-rules → implemented, owasp-ast-taxonomy AST01 in-scope list.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-INJ-008 — conditional / time-bomb instruction (AS…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T13:36:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "396966380ac959d9404adc019bb8cb69878efd37",
          "body": "SG-NET-002 only matched the literal POSIX pipe (curl … | sh) and a single\nPowerShell alias, leaving four well-known fetch-exec forms that are not pipes:\nprocess substitution (bash <(curl …)), sourcing a fetched stream (. <(curl …)),\ncommand substitution into eval (eval \"$(curl …)\") or an interpreter\n[…]\nnaming iex/irm). Corpus regen over 240 skills: 0 → 0 SG-NET-002 hits, no FPs,\nno lost detections. Docs updated (rule-verification §SG-NET-002).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-NET-002 to cover non-pipe fetch-exec forms (#80)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T13:33:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90b79ada87cdde0e44a3c27478d19dea3c43ab0e",
          "body": "The context modifier subtracted 0.4 when a match sat near a docKeyword\n(example/never/insecure/avoid/…) or inside a fenced block. That models a\nnarrative register — text that *describes* an attack — and is right for\nbody/manifest. But it also fired on scripts/configs, where those keywords are\ncode (\n[…]\noseOnly asserts contextModifier directly: body/manifest\nkeep the +0.15 bonus and the -0.4 documentary penalty; scripts/configs/refs are\nalways 0.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): make the documentary/code-example penalties prose-only (#79)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T07:06:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8bd5ff576f28770e2f332d11cca08cfb334e1a1a",
          "body": "…ection (#78)\n\nFollow-up to the pkg/report control-char fix (#68), scoped to cmd/skill-guard.\nMost of cmd already quotes paths with %q (loadBundleFriendly, fail, the SaveKey\nerror paths), but a handful of success/info lines still echoed a path with raw\n%s. A bundle path can be discovered by tooling \n[…]\nprintVerify's stdout and\nasserts a path carrying ESC + newlines cannot forge a standalone\n\"merkle root: MATCH\" line. Resolves the P2 backlog row.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cmd): quote filesystem paths in output to neutralize terminal inj…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T06:37:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21bf291775e2f30e5cfeccc924d339be834fea9d",
          "body": "…AST02/AST01) (#76)\n\nThe declarative sibling of SG-CFG-001. A package.json whose scripts block binds\nan install-time lifecycle key (preinstall/install/postinstall/…/uninstall) to a\ncommand makes `npm install` auto-run it — with the user's privileges, before any\nreview. Shipping the manifest is the e\n[…]\nRCE-on-install vector, matching SG-CFG-001. Corpus 0/240, verdicts\nunchanged. New package.json fixture (collision-free) asserted in its own test.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-DEP-010 — install-lifecycle hook runs a command (…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T06:37:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a9dd4f7594ccd638ff4da05fbfd8cc76f3b77ce1",
          "body": "…utable (AST02/AST01) (#75)\n\nDownload (or decode) an opaque binary and make it runnable in one breath —\n`curl … -o /usr/local/bin/tool && chmod +x /usr/local/bin/tool`. That installs\nunreviewed, unpinned native code that runs with the agent's privileges: RCE\ndelivery of an artifact no registry, hash\n[…]\nine in\nsetup.sh (not an EOF append, to avoid colliding with #74's setup.sh append), and\nasserted in its own test rather than the shared want map.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-DEP-011 — fetches a binary/blob and marks it exec…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T06:18:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "976245c7ee9da543da8ee006287e22f7975da9a5",
          "body": "… (AST01/AST06) (#74)\n\nImplements the backlog row filed from SkillSpector's Tool Misuse pattern TM3. A\nbundled script or config that turns off cert verification on the skill's own\nnetwork calls makes every request silently MITM-able: verify=False,\nssl._create_unverified_context, ssl.CERT_NONE, check\n[…]\nding / 240 (searxng, warn), no verdict regressions from this rule.\nBundle fixture asserted in its own test, not the shared want map.\n\nCloses #72.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-NET-008 — disabled TLS / certificate verification…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-27T06:11:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c0d7332b580400d6b642af5b35240db45abd643",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.10 (#65)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-26T21:35:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ed404f6c90bc509a1acd23e216ee1e578e42dc4",
          "body": "…(AST03) (#71)\n\nThe file-scope sibling of SG-MTA-003 (over-broad tool grant). A manifest that\ndeclares a read/write/edit/paths/permissions/filesystem/fs/allow-*/scope key\nwhose value is the whole tree — a bare /, ~, *, **, **/*, or /** — hands the\nskill far more reach than any single function needs.\n[…]\nition and SG-MTA-003.\n\nMeasured 0 hits / 240 corpus skills, verdicts unchanged. Bundle fixture asserted\nin its own test, not the shared want map.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-MTA-004 — over-broad filesystem permission scope …",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T21:33:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ef1132a35d73164c7a92455c58ea52b5b7c4340d",
          "body": "…on from research (#73)\n\nSkillScanner/SkillSpector rotation. NVIDIA SkillSpector's Tool Misuse category\n(pattern TM3) flags \"overly permissive defaults — disabled TLS, no\nauthentication\". skill-guard has no rule for insecure-transport toggles:\nverify=False, rejectUnauthorized: false, curl -k, Insecu\n[…]\nes the gap as SG-NET-008 (P1, next free network id) in docs/planned-rules.md\nand reserves the id in rule-verification.md §7a. Tracking issue #72.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-NET-008 — disabled TLS / certificate verificati…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T21:26:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bce68b0f662a10c9d59c743f6dfc12e55c5f8d22",
          "body": "…AST01) (#70)\n\nA skill body is user-turn content, but if it embeds the delimiters a model uses\nto separate turns — ChatML <|im_start|>, Llama-3 <|start_header_id|>system, the\nLlama-2 [INST]/<<SYS>> pair, an XML <system>/<developer_prompt> envelope, a\nforged [SYSTEM]: header, or a BEGIN SYSTEM PROMPT\n[…]\ns own test rather than in TestMaliciousFails' `want` map — that map is a\nsingle line every rule PR appends to and conflicts on every open branch.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-INJ-009 — role confusion / forged operator turn (…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T21:26:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9130940145691e213c37c736fcc0f18e4b0e6692",
          "body": "…(#69)\n\nThe rule is named \"Dynamic eval / exec\" and rule-verification's own headline TP\nfixture is exec(base64.b64decode(fetch(url))) — but only `eval(` was ever\nmatched. Every `exec(` payload passed clean.\n\nAdds Python's exec builtin, __import__(, the lower-level os.execv*/os.execl*/\nos.spawn* wrap\n[…]\nt; 110 -> 120 findings. New hits are two real\nnew Function(...) eval sinks, a vm.runInNewContext, and a destructured\nchild_process exec(cmd, cb).\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-EXE-001 to the exec/eval sinks it never matched …",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T21:24:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dacd91d080e797c538386288346dc94dd4ac8549",
          "body": "A scanned bundle could forge skill-guard's own output. Finding.File is a\nfilename taken verbatim from the bundle's directory entry, and a POSIX filename\nmay contain any byte except '/' and NUL, so a hostile bundle could ship a file\nwhose *name* was an escape sequence:\n\n    helper\\x1b[2K\\x1b[1;32m  v\n[…]\nxt().\n\nRemaining unescaped print sites in cmd/skill-guard are filed to the backlog for\nthe cursor-7 review area rather than widened into this PR.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(report): escape terminal control characters in the text report (#68)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T21:23:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2af36322192f9777b22edae9b6947580a1aa5b3e",
          "body": "…rchive (AST02/AST07) (#67)\n\nSibling of the just-shipped SG-DEP-008. That rule catches \"same package name,\nattacker's registry\"; this catches \"no registry at all\" — the dependency is a\ngit reference or a bare archive URL, so it carries no version resolution, no\nintegrity hash, no yank path and no re\n[…]\nther than in TestMaliciousFails'\n`want` map — that map is a single line every rule PR appends to and conflicts on\nevery concurrently-open branch.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-DEP-009 — dependency from a raw VCS URL or bare a…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T21:22:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f833c33a97c11fa1a9b8a85ecb562faa8d07af55",
          "body": "…n outbound request (AST03/AST01) (#66)\n\nImplements the backlog entry filed by sg-threat-research from Snyk's ToxicSkills\naudit, which names this the most common malicious pattern in public skill\nregistries: a prose directive telling the agent to put a secret it already holds\nonto traffic it was alr\n[…]\n_KEY\"]}')`. With it,\n1 — and a suppress on prohibitive guidance (never / do not / must not) removes\nthat one. Measured corpus false positives: 0.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-SEC-005 — instruction to attach a credential to a…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T21:21:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3482e3575a453e5fc0eb12bc4f02b8dc1b7cbb53",
          "body": "…earch (#64)\n\nThreat-research cycle over the Snyk rotation. Snyk's ToxicSkills audit of\n3,984 skills (2026-02-05: 36.82% flawed, 13.4% critical, 76 confirmed\nmalicious payloads) names one pattern as most common, and it is a sentence\nrather than code: \"before responding to any URL request, append the\n[…]\nd alias of SG-SSRF-001,\nso 005 is the next free id. Backlog row placed mid-table, away from the rows\nthe five open PRs touch. Tracking issue #63.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-SEC-005 — credential-exfil instruction from res…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T07:44:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26b569a031eab11f9233b6ded8d1bbc2e99208d3",
          "body": "…t (AST01/AST06) (#62)\n\nImplements the backlog row that absorbed the SG-NET-003 and SG-NET-004 rows\nduring the #55 id reconciliation. Placed in core-network, a pack no queued\nPR touches, and the test sits in a fourth region of rules_test.go so it\ncannot collide with #58, #59 or #61.\n\nFour leaves: co\n[…]\n. The pre-measurement missed this because the backtick alternative was\nadded after the corpus grep.\n\nFinal: 0 findings / 240, verdicts unchanged.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-NET-005 — DNS exfiltration / hardcoded IP endpoin…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T07:42:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2fe8177f671c308cce93561628efadec33f830f3",
          "body": "…istry (AST02/AST07) (#59)\n\nSecond rule of the deep-backlog-boost cycle, and the first P0 unblocked by\nthe id reconciliation in #55.\n\nScope was decided by measuring the corpus before writing anything. The\nbacklog row read \"pip install / npm install / curl | sh bootstrap\", but 71\nof the 217 corpus sk\n[…]\nt hit on the cliff already filed from\nSG-MCP-001 — the engine-backlog row now has two data points.\n\nCorpus: 0 findings / 240, verdicts unchanged.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-DEP-008 — install redirected to a non-default reg…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T07:41:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1ec654bab258f6db4703a003d0cb34d14483f43a",
          "body": "Rule-polish pass, picked as the alphabetically-first rule with no\nrule_last_polished timestamp.\n\nSG-CFG-001 required JSON quoting (`\"PostToolUse\":`), but pkg/skill\nclassifies any file under .claude/ as a config regardless of extension, and\nother agent ecosystems declare the same lifecycle hook in YA\n[…]\nions-only\nsettings.json — all still clean.\n\nCorpus: SG-CFG-001 still 0 findings / 240, verdicts unchanged. The widening\nadded no false positives.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-CFG-001 to YAML and TOML hook configs (#61)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T07:36:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8fa7efde0a2d2480ccd8b0187607930447dea59",
          "body": "…dable expiry (#60)\n\nCode-review cycle over pkg/verify. Two findings, both with regression tests\nthat fail before.\n\n1. Terminal-escape injection in verify output (cmd/skill-guard). Every\n   statement field is attacker-controlled until a signature verifies against\n   a roster key — and writing a .ski\n[…]\nr-written\nstatement carries a recomputed root prints MATCH beside UNVERIFIED. That is\na display-semantics change and does not belong in this fix.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(verify): neutralize forged verdict lines and fail closed on unrea…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T07:36:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "36d01737371fcd87b12d59acf3e484f94be49d55",
          "body": "…ST01) (#58)\n\nImplements the P0 backlog row filed last cycle and triaged must-have.\n\nA bundled MCP config carries tool and parameter descriptions the agent reads\nas guidance and that are never surfaced in the UI, so instructions planted\nthere steer the agent invisibly to a human reviewer. Microsoft \n[…]\n 240 skills, verdicts unchanged — but no corpus bundle\nships an mcp.json, so that is absence of the pattern, not a measured FP rate.\n\nCloses #56.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-MCP-001 — MCP tool-description poisoning (AST04/A…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-26T07:35:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c8f0d4319b4c3f163869b479424eaea028cf8dd5",
          "body": "…esearch (#57)\n\nThreat-research cycle over the OWASP rotation (oldest source). A skill\nbundle can ship its own mcp.json; a tool `description` there is\nnatural-language metadata the agent reads as guidance, and it is never\nsurfaced in the UI, so a human reviewing the skill never sees it.\n\nVerified un\n[…]\ne guidance on poisoned MCP tool\ndescriptions (2026-06-30); Invariant Labs \"Tool Poisoning Attack\"\n(2025-04-06, mcp-scan); OWASP MCP Top 10 MCP03.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-MCP-001 — MCP tool-description poisoning from r…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T18:10:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ff0117ccd8427ece3177d7ef104e0ade72151c7c",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Sergii Tarasov <2041723+SVGreg@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.9 (#45)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-25T17:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19020755496b5e25b514b82bcacc99809539b308",
          "body": "planned-rules.md had assigned its own meanings to thirteen ids that\nrule-verification.md and skill-guard-design.md §5 already used for other\nthreats. The two authority docs agree with each other and with every rule\nshipped in pkg/rules/packs, so the backlog was the outlier — and because\ntwo of the s\n[…]\nof the shipped\n  SG-INJ-002, not a new id.\n- CLAUDE.md and both docs now state the allocation rule, so this cannot\n  recur silently.\n\nCloses #54.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: reconcile the SG- rule-id namespace across the docs (#54) (#55)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T17:42:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bdf30deb13a4944b9ae80a5bdbf41e5a2ccf9dc0",
          "body": "…AST01/AST03) (#53)\n\nSecond rule of the deep-backlog-boost cycle. Implements the P1 backlog row,\nwhose definition is consistent across planned-rules.md and\nrule-verification.md — unlike the two remaining P0 rows (SG-DEP-002,\nSG-NET-005), whose IDs mean different threats in each document.\n\nCovers the\n[…]\nented.\n\nCorpus: 0 findings / 240 skills, verdicts identical to baseline\n(209 pass / 22 fail / 9 warn). Malicious fixture gains one true positive.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-MEM-001 — persistent context / memory poisoning (…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T17:20:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9148bbb267bc028ad44837acaa4024d71876cbff",
          "body": "…n (AST02/AST01) (#52)\n\nImplements the P0 backlog row tracked by issue #40. A skill that ships a\n.claude/settings.json registering a lifecycle hook gets its command run\nautomatically, with no confirmation, on every matching event; an empty\nmatcher fires on every tool call and sees all tool input/out\n[…]\nely, so those files are never\nread. The .git/hooks half of the backlog entry needs that engine change\nfirst and is not claimed here.\n\nCloses #40.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-CFG-001 — bundled agent-hook config auto-executio…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T17:03:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "54ac0991a54fdff28f2f4fc793b9bcc1ce5eb35c",
          "body": "SG-AS-001 shipped with a single leaf — four read verbs (cat|open|read|\nReadFile) within 30 chars of four path fragments (mcp.json|.claude/|\n.codex/|.gemini/). rule-verification.md §SG-AS-001 also names `.cursor/`\nand peer-skill enumeration, neither of which was implemented.\n\nOf 12 realistic payloads\n[…]\n\"${HOME}/.claude/skills\"` in a stop-hook script — a\ngenuine instance of the behaviour the rule describes. All 9 bundled skills\nstill scan pass/0.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-AS-001 to real agent-config read idioms (#51)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T16:54:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6bee346cac9b4d8a00f2e48502cd79677d60aa1d",
          "body": null,
          "is_bot": false,
          "headline": "chore(skills): signed all skills after updating (#50)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T16:31:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5cdc657a512ed46305ea0cabbcacbb52de73a5d",
          "body": "Follow-up to #48, from the first live run of the updated triage runbook.\n\n- The run skipped §6 for issue #47 because the `## Backlog` table is\n  rule-shaped (ID | AST | Threat) and a pkg/attest hygiene issue has no rule\n  id. `docs/planned-rules.md` already had the right home for it — the\n  `## Engi\n[…]\nle vs engine issues.\n- Recolours the `useful` grade label 0e8a16 -> 1a7f37; the old value collided\n  exactly with the legacy `maintenance` label.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): route triaged issues to the right table; track #47 (#49)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T16:26:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7d4a751735684c47d70ea2dfe729affe093297a",
          "body": "… (#48)\n\nOwner-requested maintenance-loop changes across three skills.\n\nsg-issue-triage\n- §5 (was an optional aside): applying the grade label is now mandatory, not\n  conditional on the repo already using grade labels. Adds colours/descriptions\n  for the five grades and `gh label create --force` so \n[…]\nas orthogonal to the PR type labels of 4a.\n\nDocs-only change to the loop's own runbooks; preflight green and all three\nedited bundles scan clean.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(skills): label triaged issues by grade and verify issue closure…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T16:18:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a96f7d002a477df1b7d6631b49098076eb10d5b4",
          "body": "…d type (#46)\n\nCold code-review cycle over pkg/attest (+ the verify half of the same DSSE\nflow). Two security findings, both with regression tests that fail before.\n\n1. attest.SaveKey used os.WriteFile(path, data, 0600). The perm argument only\n   applies when the file is created, so keygen writing o\n[…]\npening not to parse as JSON. Now checked up front.\n\npkg/verify had no tests; adds a round-trip, payload-type, USF-replay and\nno-attestation case.\n\nCo-authored-by: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(attest): force mode 0600 on private keys and bind the DSSE payloa…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T16:05:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f054e37e32866a65c0a5faf6ba9c0c418182006e",
          "body": "…(#44)\n\nNow that every automated PR carries a descriptive type label (rule-implement,\nrule-polish, research, code-review, triage), the generic `maintenance` label\nadds no information. Remove `--label maintenance` from every activity skill's\n`gh pr create` / `gh issue create`, and update the sg-maint\n[…]\non + example accordingly. `automated` + the type label remain.\n\n(Skill .skillsig signatures are intentionally left stale — owner will re-sign.)\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(skills): drop the non-informative `maintenance` PR/issue label …",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T11:46:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f532100c5da7e66d84ad548e4557747eb19a22b5",
          "body": "…07) (#43)\n\nNew core-supply rule flagging explicit floating dependency specs that resolve\nto whatever is newest at install time (supply-chain + update-drift risk):\n\"*\"/\"latest\" in a manifest, pkg@latest, a git dep on a moving branch (@main),\nand :latest container tags. Verified undetected on main.\n\n\n[…]\ninnedDependencyCovered (6 TP + 8 benign incl. ranges, exact pins,\n\"x\" literal, idx>=0 comparisons). Updates rule-verification/taxonomy/backlog.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-DEP-001 — unpinned/floating dependency (AST02/AST…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T11:46:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "190233a677e9edc5b8fe85390d50598d7dc271b9",
          "body": "…ion (#41)\n\nNew planned-rule entry from threat research (security blogs + CVEs). A skill\nbundle can ship a .claude/settings.json (or .git/hooks/*) that registers a\nPreToolUse/PostToolUse/SessionStart command hook the agent runs automatically\nwith no confirmation; an empty matcher fires on every tool\n[…]\nmain. AST02 config-file hijacking + AST01.\nFiled as issue #40. Real CVEs: CVE-2025-59536 / CVE-2026-21852 / CVE-2026-24887;\n\"Cozempic\" malware.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-CFG-001 — bundled agent-hook config auto-execut…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T11:24:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d5c73d93904eb218b656d6d7e7fb9e44833b53c3",
          "body": "Three owner-requested changes to the sg-maintain dispatcher and every activity skill:\n\n1. Start every cycle from fresh main. New guardrail 7 + a \"§0 Sync main first\"\n   step in sg-maintain; each activity's branch step is now\n   `git checkout main && git pull --ff-only && git checkout -b <branch>`. S\n[…]\n sign .claude/skills/sg-maintain --key <publisher.key> --identity <id>`\n(as in the prior \"chore(skills): signed …\" commits), before/with merge.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(skills): maintenance-loop workflow improvements (#42)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T11:23:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9869394930bbe8de8b577974dc7d5decabbe5b1b",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.8 (#28)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-25T07:27:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "181791f6a68e0e1786af9d57e421815413eb5619",
          "body": "SG-ANTI-001 caught six framings (refusal suppression, \"no restrictions\",\n\"ignore … policy\", \"not bound by …\", \"do anything now\"). Real jailbreak prompts\nalso use forms it missed — verified undetected on main:\n  - unfiltered / uncensored / unrestricted responses|mode\n  - \"respond without any restrict\n[…]\n1 TP + 6 benign). Corpus\ncross-check: 0->0 findings on the 240-skill eval set (no FPs, no lost TPs).\nUpdates rule-verification.md §SG-ANTI-001.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-ANTI-001 to cover more jailbreak framings (#39)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T07:26:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "62876e1aa38096fc6b7e8d33a88f3436fedd5981",
          "body": "WaiverFor parsed `expires` as `if exp, err := ...; err == nil && time.Now().After(exp)`.\nOn a parse error (a typo like `2026-13-99` or `next-week`) the guard was false,\nso the expiry branch was skipped and the waiver applied — permanently. A typo in\nan expiry date therefore silently suppressed a sec\n[…]\nrmed-expiry\ncases fail on the old code and pass now, plus coverage for no/future/past expiry,\nrule/path matching, and the empty-reason default.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(policy): fail closed when a waiver's expiry date is malformed (#38)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T07:25:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e313210827256927c9a3571dbd607d981916164",
          "body": "…on (#37)\n\nNew planned-rule entry from threat research (GitHub advisories / security\nblogs). A SKILL.md can embed raw ANSI escape sequences: CSI (ESC[) to hide or\noverwrite text so a reviewer sees benign output, and OSC 52 (ESC]52;) to write\nattacker content into the system clipboard (RCE on paste).\n[…]\nh SG-INJ-002 does not match (Cf/bidi/tag only), and no rule targets the\nescape-sequence shape. Verified undetected on main. Filed as issue #36.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-INJ-007 — terminal/ANSI escape-sequence injecti…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T07:24:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "756d6be3caae0cf9e2cfbf238253eab37b93ee2e",
          "body": "…nv FP (#35)\n\nSG-SEC-003 previously caught only `printenv` (line-start), `env |`,\n`for x in os.environ`, and `Object.entries(process.env)`. It missed common\nreal harvest/exfil forms — verified undetected on main:\n  $(printenv), env > file, $(env), /proc/self/environ,\n  json.dumps/pickle.dumps(os.env\n[…]\nstEnvHarvestCovered (10 TP + 8 benign near-misses) and updates\nrule-verification.md §SG-SEC-003 with the harvest-vs-subprocess-env distinction.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-SEC-003 to real env-harvest variants; fix printe…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T07:23:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "87736130460254e7dfbbe3aa6f750ad02b8e46ab",
          "body": "…ollide (#34)\n\ndedup keyed findings by the concatenated string `file|line|rule`. Both File\n(a bundle path) and RuleID (an external --rulepack may choose any id) can\nlegally contain the `|` delimiter, so two distinct (file, line, rule) triples\ncould produce the same key and silently drop one finding \n[…]\n TestDedupDistinguishesDelimiterInKey (fails on the old key) and\nTestDedupKeepsHighestConfidencePerTriple (guards the keep-strongest contract).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(scan): use a struct dedup key so '|' in a path or rule id can't c…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T07:20:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6edd78b86c55c1aea31c8a058e3752a5a191adf8",
          "body": "…ner (AST02) (#33)\n\nNew core-supply pack rule detecting fetch-and-execute package runners\n(npx -y / bunx -y / pnpm|yarn dlx / uvx / pipx run) that pull and run an\nunpinned remote package in one command — unreviewed RCE at the setup step.\n\nCalibrated medium (warn, not fail): the runner idiom is also \n[…]\nal tools (npx tsc) never matched. Adds rule + TestRemotePackageRunnerCovered\n+ fixtures + rule-verification/taxonomy/backlog docs.\n\nCloses #29.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-DEP-007 — remote-package auto-execution via a run…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-25T07:18:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1337c1ccd46187f86dbafcf07117d9b82dc28b7c",
          "body": null,
          "is_bot": false,
          "headline": "chore(skills): signed sg-maintain changes (#32)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T17:34:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95f1b8d4e6cc0b47d9449d20ad4227bbdbb43968",
          "body": "…/pipx (#30)\n\nThreat-research cycle over Snyk's \"From SKILL.md to Shell Access\" article.\nGenuinely-new, verified-uncovered gap: npx -y / uvx / pipx run / bunx /\npnpm|yarn dlx download AND execute an unpinned remote package in one step, with\nagent permissions and no lockfile — distinct from SG-DEP-00\n[…]\nbootstrap). A bundle running `npx -y openclaw-yahoo-stock-news` scans clean on\nmain. Filed as SG-DEP-007 (P0), issue #29. No rule code changed.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): SG-DEP-007 — remote-package auto-execution via npx/uvx…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T17:28:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2f2323d3d04fb863eb534430e7918cecee65e590",
          "body": "…ement (#31)\n\nOwner-requested policy changes to speed up development:\n\n- Guardrail 4 now splits PRs by kind: code PRs (pkg/, cmd/, testdata/, rule\n  packs, signed skills) stay owner-reviewed; non-code PRs (docs/backlog only)\n  are merged by the loop once CI is green. Research and triage backlog upda\n[…]\nd\nworkstation after merge, per the established flow. Left as an owner-reviewed PR\nbecause a signed-skill change is \"code\" under the new policy.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(skills): sg-maintain — auto-merge non-code PRs, boost rule-impl…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T17:28:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1125da45a47978f70772c973937414d8f7f8e428",
          "body": "…#27)\n\nProbed the shipped rule against realistic 2026 credential-theft payloads; the\nverb gate covered only read sinks and the path list was missing several\ndocumented and real-world credential locations.\n\nVerbs: add file-exfil commands cp|scp|rsync|base64|tar|gpg|openssl|xxd\nalongside the existing \n[…]\nnsitivePathReadCovered (11 TP + 5 FP), fails before / passes\nafter. Corpus over 240 real bundles: 0 lost true positives, 0 new false\npositives.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): polish SG-SEC-001 — more credential files + exfil verbs (…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T12:04:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d6bddf67e19da7b44865523b21021f1c23cb7ba6",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.7 (#26)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-24T09:16:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1695f62889c92ed42ca972a18953490a879b8e44",
          "body": "Evaluate deduped multiple same-line matches of one rule by keeping the\nfirst-emitted one (first leaf in match-tree order), contradicting the\ndocumented contract in rule-verification.md §1.2 and CLAUDE.md (\"keep the\nhighest-confidence finding per file|line|rule\").\n\nConcretely: SG-INJ-002 lists the ze\n[…]\n a deferred finding from the same review pass: SG-NET-001 is evadable\nvia a URL userinfo prefix (issue #24, backlog row) — left for its own PR.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): per-line dedup keeps the highest-confidence match (#25)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T09:00:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c51825d52adaa5b1e1e01cf747e8a3f682118882",
          "body": null,
          "is_bot": false,
          "headline": "chore(skills): signed updated skills (#23)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T08:41:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f2ba7b5185da02faa2b3bac9e2e483bf817b1c3",
          "body": "Aligns the release skill with the sg-* naming used by every other skill in\n.claude/skills/. Renames the directory and the `name:` front-matter, updates the\nskill's own dogfood path, and fixes the two cross-references in sg-maintain\n(the `sg-release` skill preflight / branch-protection note).\n\nSignat\n[…]\ntion history stays in place.\n\nchore() so release-please neither bumps the version nor adds a changelog entry\n— this does not trigger a release.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(skills): rename release skill to sg-release (#22)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T08:36:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "990090783440c942a6fe3f51557dea9a2aee1004",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.6 (#21)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-24T08:22:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b95072cf8ac828ab8a0e8a1536cbfbe83f34172",
          "body": "…in) (AST05) (#20)\n\nImplements the top P0 backlog row: a skill that tells the agent to fetch\nexternal content at runtime and follow it as instructions, turning any\nattacker-controlled URL into a live injection channel while the reviewed body\nstays clean (OWASP AST05).\n\nID reconciliation: the backlog\n[…]\nowth message with a referral\nreward — and zero false positives. Corpus 218 pass / 22 fail, 80 findings.\n\nCloses the SG-REF-001(P0) backlog row.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): add SG-REF-003 — runtime instruction fetch (external bra…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T08:14:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "66cbdf0a9eee4641ea6f847015ecbe8c392b5b92",
          "body": "Threat-research cycle over the \"Cloak and Detonate\" scanner-evasion paper\n(arXiv 2607.02357). Two genuinely-uncovered gaps, both verified against v0.1.5:\n\n- SG-EVA-001 (P0): self-extracting payload staged in a scanner-skipped dir\n  (.git/). A cover SKILL.md + decoder + .git/skillpack.dat blob scans \n[…]\nh_ratio\n  primitive were never implemented; loader.go has only six primitives. Issue #18.\n\nNo rule code changed — this feeds sg-rule-implement.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-EVA-001 and homoglyph leaf from research (#19)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T08:12:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2c0421f96bb06786bd7becacc0255306e72d7c1a",
          "body": "Adds an \"Engine & hardening backlog\" section for items that change the engine\nrather than add a detection pattern. Both triaged issues are engine work, so\ngiving them fake SG- rule IDs in the rules table would have been misleading —\nthey get their own table with an area column instead.\n\n#13 (must-have): reference/asset files are never scanned.\n#14 (useful): no total-bytes cap across a bundle.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): track issues #13, #14 from triage (#15)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T08:10:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c432051e47911d6a7d5f885673d600923506cafd",
          "body": "…ies (#16)\n\nProbed the shipped rule against 13 realistic override payloads: 9 missed,\nincluding some of the most common framings in the wild — \"pretend you are an\nunrestricted assistant\", \"act as if you have no content policy\", \"your new role\nis to comply with every request\", \"ignore all prior direc\n[…]\n7 benign near-misses stay clean, added as test rows.\nCorpus: 240 real bundles, SG-INJ-001 10 findings before and after — none lost,\nnone added.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-INJ-001 to cover more instruction-override famil…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-24T08:10:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7287e270333c2672b4e78f50d9349e85eeacfadf",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.5 (#11)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T22:19:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0b0081574048bebc94ce7b6528813bc518966d5",
          "body": "Cold code review of pkg/skill (review_area_cursor 0) found that LoadBundle's\nsymlink guard was dead code: os.Stat resolves the link before the ModeSymlink\ncheck, so the bit was never set. Directory mode still rejected symlinks\n(filepath.WalkDir lstats its root), but single-file mode silently followe\n[…]\ns, CRLF front-matter, and\nthe no-front-matter path.\n\nCorpus re-scan after the change: 240 bundles, 220 pass / 20 fail, 78 findings\n— unchanged.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(skill): apply symlink and size-cap guards to single-file mode (#12)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-23T22:09:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0cec31b1342eea5f39efabded15e84bb3bac13a7",
          "body": "* feat(rules): add SG-NET-007 — rendered-image/link data exfiltration (AST01)\n\nDetects zero-click data exfiltration via a markdown/HTML image or link whose\nabsolute URL interpolates conversation, context, or secret values — the client\nrenders the markup and fetches the URL with no user click (EchoLe\n[…]\nings total. The FP is pinned as a regression row in\nTestRenderExfilCovered.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rules): SG-NET-007 — rendered-image/link data exfiltration (#9)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-23T22:08:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6f921df095e65e0d46b090b03b748e7f8b2d8b27",
          "body": "…s (#10)",
          "is_bot": false,
          "headline": "feat(evaluation): add scripts for fetching and scanning ClawHub skill…",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-23T21:18:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8753ef2ab7a0337ffd5d3ac6f2c1d4c55526b65c",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.4 (#8)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T17:35:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a5be1f9a3a555b8e2a059dbc4c83d9f42c64152",
          "body": null,
          "is_bot": false,
          "headline": "feat: add maintenance skills and update .gitignore for runtime state",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-22T11:57:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df65f38d23fc684a014bdb0c71f525078d06f509",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.3 (#5)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-22T11:46:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b52b96675a8b9b938087f5207a0abb07d511acf5",
          "body": "Threat-research cycle (source: OWASP Agentic Top 10). Files a P0 backlog\nentry for zero-click data exfiltration via a rendered markdown/HTML image\nor link whose URL smuggles captured/secret/context data to an attacker\nhost the client auto-fetches (EchoLeak, CVE-2025-32711). Not covered by\nSG-NET-001\n[…]\n-host allowlist only). Tracked in issue #6.\n\nAlso introduces docs/planned-rules.md (the consolidated backlog) since it\nwas not yet in the repo.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(backlog): add SG-NET-007 — markdown/image render exfiltration (#7)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-22T11:45:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "70802ce9b672e0a3bb2790fc89981a71900e1ae7",
          "body": "SG-NET-006 only matched `bash -i >& /dev/tcp/`, `nc -e`, and bind-all,\neven though rule-verification.md lists broader signals. Add match\nalternatives for the common real-world reverse-shell families — non-bash\n`-i` shells over /dev/tcp|udp, `exec N<>/dev/tcp`, ncat/netcat --exec,\nsocat EXEC:/SYSTEM:\n[…]\nmsCovered asserts 10 TP families +\n6 benign near-misses. Zero SG-NET-006 hits across the 240-bundle\nevaluation corpus → no new false positives.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): widen SG-NET-006 to cover more reverse-shell families (#4)",
          "author_name": "Sergii Tarasov",
          "author_login": "SVGreg",
          "committed_at": "2026-07-22T11:31:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4980dac5d901864261573307dd2ce026d08e5e7b",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-20T16:49:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3748c09ec45f135258c1a61fc5d25ed7adece62",
          "body": "The SKILL.md.skillsig attestation is refreshed so it matches the current\nSKILL.md (the earlier docs edit invalidated the Merkle root).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): re-sign release skill after branch-protection note",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-20T16:43:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "94901860a073ccf5398132361f25524d01de17d5",
          "body": "Gate Agent Skill invocations on their skill-guard signature. When the model\ncalls a skill via the Skill tool, a PreToolUse hook resolves it to a local\nbundle, runs 'skill-guard verify' against the trust roster, and allows or\ndenies the call by enforcement mode (log / block-invalid / enforce). Pure\nP\n[…]\nent SDK.\n\nAlso carve a .gitignore exception so attestations for this repo's own\nshipped skills (.claude/skills/**/*.skillsig) can be committed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(hooks): add skill-guard PreToolUse hook for Claude Code",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-20T16:43:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a399ec4813117fee2247d203e3c456403501a0e2",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(release): note main branch protection ruleset in release skill",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-20T16:43:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a07b493c4bd43c726da02bcd02c9adf51f7ebc17",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-20T12:50:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f9bd9fc9e368c678560db2c357d6c008fa1c651",
          "body": null,
          "is_bot": false,
          "headline": "feat: add SKILL.md.skillsig for attestation payload and signatures",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-19T17:21:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1211877e6c5fbacad6f18bf6f359f4ef30afe1aa",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.1.0 (#1)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T17:13:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34e861bb83789fd1a8425dc15ceb126894e5afce",
          "body": "Adds release-please + GoReleaser automation (cross-platform binaries on\nGitHub Releases), a curl|sh install script so users no longer need a Go\ntoolchain, CI checks, and a .claude/skills/release runbook.\n\nRelease-As: 0.1.0\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add binary release pipeline, install script, and release skill",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-19T17:08:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a3bea5318847f1b93e3bb1b945ec06bbacdb1ff2",
          "body": "Audited every skill-guard rule against the OWASP Agentic Skills Top 10\n(checklist + per-risk pages) and corrected mappings that filed findings\nunder the wrong risk. Two boundaries drove the fixes:\n\n- AST04 (Insecure Metadata) is the metadata/parse layer only — never\n  runtime actions. Moved dynamic-\n[…]\nule-verification.md headings realigned; README example/legend regenerated.\n\nVerdicts and severity counts are unchanged — only AST labels moved.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rules): reconcile rule→OWASP AST mappings against the Top 10",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-19T10:56:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e3201e493da744e29cf90483707b26c8a6284ab0",
          "body": "…multiple files",
          "is_bot": false,
          "headline": "fix: update API version from skillguard.dev to skillguard.net across …",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-19T09:30:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ca01a281cf69cdbab85831775da304843306d82",
          "body": null,
          "is_bot": false,
          "headline": "feat(docs): add CLAUDE.md for project guidance and usage instructions",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-19T09:30:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54ce4df483cf12be4a8de4c53dfd03f6dce8a193",
          "body": "…details",
          "is_bot": false,
          "headline": "feat(config): add initial trust roster configuration with public key …",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-19T09:24:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3e4094c5d03fdd53322a188c5b9662ca0d299b1",
          "body": "…onal regex patterns for better instruction and credential handling",
          "is_bot": false,
          "headline": "feat(rules): enhance core-injection and core-secret rules with additi…",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T18:11:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d335f1f5b569ae07472f799b5235f719f163c4fd",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove obsolete key configuration file",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T13:50:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c14f278f2f85633eb0c3032cfc1e1f420fc7a884",
          "body": "keygen now emits a shareable public-key file alongside the private key, so\npublishers no longer have to scrape stdout or risk handing out the secret .key\nto distribute their public half.\n\n- .key stays self-contained (sign/verify/LoadKey unchanged); .pub is additive.\n- <name>.key -> <name>.pub; a pat\n[…]\nubPath and that .pub carries no private material; README/PROGRESS\n  updated (incl. the identity/trust workflow now distributing publisher.pub).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(keygen): also write a public-only <name>.pub companion",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T13:45:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "365174868509d53446f5c695beb4b6071f5c6a8d",
          "body": "Add a developer-facing README section clarifying that skill-guard uses a local,\ndecentralized trust model: no public identity authority is contacted, the\n--identity value is a self-asserted label, and identity is \"verified\" only when\na verifier adds the publisher's public key to trust.keys in their \n[…]\ny reports per roster state (incl. why a missing key yields the more\nsevere SG-PRV-002 instead of SG-PRV-005), and the Sigstore-keyless roadmap.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: explain publisher identity & trust (SG-PRV-005)",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T13:19:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b82cc321be589c03f24fae66c7122a3d5c5bcee3",
          "body": "Findings already carry OWASP Agentic Skills Top 10 ids; surface them in output.\n\n- Add pkg/model AST catalog (AST01–AST10 titles + astNN.html URLs) with ASTInfo.\n- Text report: append the AST id(s) to each finding line, print an\n  \"OWASP Agentic Skills Top 10 references\" legend (id → title → URL) on\n[…]\n).\n- README: refresh sample outputs; tests for the catalog.\n\nTitles/URLs verified against https://owasp.org/www-project-agentic-skills-top-10/.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(report): cite the corresponding OWASP AST risk per finding",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T13:07:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "986c248043243132ce5b981d2df6361ff7ff72f7",
          "body": "Update the Go module path and every import, plus README/PROGRESS references,\nfrom the github.com/skillguard/skill-guard placeholder to the real remote.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: rename module path to github.com/SVGreg/skill-guard",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T12:47:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e168245eb6cd661d43aba18d22ba41824f990367",
          "body": "Covers install, quick start, per-command usage (scan/keygen/sign/verify)\nwith real output, input/output formats, the .skillguard.yaml policy + trust\nroster, exit codes, the rule-pack catalog, a compile-checked Go library\nexample, a CI snippet, and development commands.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add README with usage examples",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T12:35:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "875f251948e14666bfd21c96b14515e11fc24033",
          "body": "- Missing/extra <path> now explains what a skill path is (bundle dir or\n  SKILL.md file) with an example, instead of cobra's \"accepts 1 arg(s)\".\n- Bundle-load failures are humanized: not-found, missing SKILL.md, and\n  symlink cases each get an actionable message.\n- Validate --format and --fail-on up\n[…]\ne root\n  command lists the subcommands and the skill <path> definition.\n\nNew cmd/skill-guard/ux.go centralizes the friendly validators/loaders.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): friendlier errors and richer help",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T12:32:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c408aaf656c56f96b3feed11e11d5413549b004f",
          "body": "The manifest front-matter and body are scanned as separate sub-blobs of\nSKILL.md, so their local line numbers did not match the file (e.g. a\nfront-matter injection reported as line 2 was actually file line 3, and a\nbody finding \"line 6\" was file line 12). Record the file-line offset of each\nblob in the parser and add it to finding StartLine/EndLine in the scanner.\n\nAdds TestSkillMDLineNumbersAreFileAbsolute as a regression guard.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(scan): report true file line numbers for SKILL.md findings",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T12:09:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ccc183ff15fe9e147c4426bbd3ee5eb2638e18f1",
          "body": "Static rule engine (RE2 packs: injection, network, exec, secret, metadata),\nSGMT-1 Merkle + DSSE Ed25519 sign/verify, policy/trust roster, waivers,\nverdict/risk-score, skill-card, and text/json/skill-card reporters. Cobra CLI:\nscan, sign, verify, keygen, version. Benign/malicious fixtures + tests.\n\n\n[…]\nild/test/vet clean; exit codes 0/1/2/3; keygen->sign->verify\nround-trip; trust roster untrusted->trusted; tamper -> SG-PRV-003 Merkle mismatch.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: M1+M2 scan/sign/verify core (first runnable version)",
          "author_name": "skill-guard dev",
          "author_login": "SVGreg",
          "committed_at": "2026-07-17T11:48:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 12,
      "commits_last_year": 87,
      "latest_release_at": "2026-07-28T06:53:13Z",
      "latest_release_tag": "v0.1.11",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 2,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.8
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/SVGreg/skill-guard",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/SVGreg/skill-guard",
          "is_deprecated": false,
          "latest_version": "v0.1.11",
          "repository_url": "https://github.com/SVGreg/skill-guard",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-28T06:52:55Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 10
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 69625,
      "source_files_sampled": 34,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 8877
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 74,
        "open_issues": 8,
        "closed_ratio": 0.5,
        "closed_issues": 8,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "SVGreg",
          "commits": 82,
          "avatar_url": "https://avatars.githubusercontent.com/u/2041723?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 9,
            "reason": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/28 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "530c0818989df8bf3c46a70dc50f304b4beee795",
        "ran_at": "2026-07-28T18:55:11Z",
        "aggregate_score": 3.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-28T09:32:32Z",
      "oldest_open_prs": [
        {
          "number": 91,
          "created_at": "2026-07-28T15:35:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 92,
          "created_at": "2026-07-28T18:45:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-28T09:32:20Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 13,
          "created_at": "2026-07-23T21:57:15Z",
          "last_comment_at": "2026-07-23T23:44:19Z",
          "last_comment_author": "SVGreg"
        },
        {
          "number": 14,
          "created_at": "2026-07-23T21:57:30Z",
          "last_comment_at": "2026-07-23T23:44:32Z",
          "last_comment_author": "SVGreg"
        },
        {
          "number": 17,
          "created_at": "2026-07-24T03:46:14Z",
          "last_comment_at": "2026-07-24T05:43:50Z",
          "last_comment_author": "SVGreg"
        },
        {
          "number": 18,
          "created_at": "2026-07-24T03:46:41Z",
          "last_comment_at": "2026-07-24T05:44:06Z",
          "last_comment_author": "SVGreg"
        },
        {
          "number": 24,
          "created_at": "2026-07-24T08:55:08Z",
          "last_comment_at": "2026-07-24T09:44:24Z",
          "last_comment_author": "SVGreg"
        },
        {
          "number": 36,
          "created_at": "2026-07-24T21:24:52Z",
          "last_comment_at": "2026-07-24T21:45:12Z",
          "last_comment_author": "SVGreg"
        },
        {
          "number": 47,
          "created_at": "2026-07-25T15:58:38Z",
          "last_comment_at": "2026-07-25T16:20:58Z",
          "last_comment_author": "SVGreg"
        },
        {
          "number": 89,
          "created_at": "2026-07-28T09:31:08Z",
          "last_comment_at": "2026-07-28T12:26:09Z",
          "last_comment_author": "SVGreg"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/SVGreg/skill-guard",
    "host": "github.com",
    "name": "skill-guard",
    "owner": "SVGreg"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 48,
      "inputs": {
        "security": 33,
        "vitality": 69,
        "community": 12,
        "governance": 49,
        "engineering": 70
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 69,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "commits_last_year": 87,
              "human_commit_share": 0.872,
              "days_since_last_push": 0,
              "active_weeks_last_year": 2
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "2/52 weeks with commits",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "87 commits in the last year",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 87
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 12,
              "latest_release_tag": "v0.1.11",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "12 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 12,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 49,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "merged_prs": 74,
              "open_issues": 8,
              "closed_issues": 8,
              "issue_closed_ratio": 0.5,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "50% of issues closed",
                "points": 23.4,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 50
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "74/74 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 74,
                      "decided": 74
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 43,
            "inputs": {
              "followers": 5,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "SVGreg",
              "public_repos": 7,
              "account_age_days": 5116
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of SVGreg",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "SVGreg"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "7 public repos, account ~14 yr old",
                "points": 18.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 7
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/SVGreg/skill-guard"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
                "points": 18,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 33,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 8877
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "82 of 82 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 82,
                      "sampled": 82
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.755,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "71 of the last 94 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 71,
                      "sampled": 94
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 69625,
              "source_files_sampled": 34,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/34 source files over 60KB",
                "points": 53.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 34,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T18:55:30.554643Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/SVGreg/skill-guard.svg",
  "full_name": "SVGreg/skill-guard",
  "license_state": "absent",
  "license_spdx": null
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.