Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 15:20 UTC

VelixarAi / velixar-mcp-server

MCP server for persistent AI memory — give any AI assistant long-term recall. Works with Claude, Kiro, Cursor, Windsurf.

TypeScript · JavaScriptMIT★ 1 star⑂ 0 forkssince Feb 2026View on GitHub ↗

VelixarAi/velixar-mcp-server holds a health index of 56 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (86/100) and lowest on Security (28/100). It was last updated 5 days ago. A single contributor accounts for most of its recent work.

56
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

56
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

VelixarAiPersonal account
2 followers14 public repossince Apr 2025

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npmvelixar-mcp-server1.5.02,839245 days agomcpmodel-context-protocolaimemoryllmpersistent-memorycognitive-contextknowledge-graphidentityvector-search

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

77Good · 22% of overall
How it's scored
36/36Push recency — last push 5 days ago
6.2/36Commit cadence — 9/52 weeks with commits
16.8/18Commit volume — 74 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year74
human_commit_share1
days_since_last_push5
active_weeks_last_year9
How it's scored
16.2/27Ships releases — 16 version tags (no GitHub releases)
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~0.5 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count16
latest_release_tagv1.5.0
releases_from_tagsyes
days_since_latest_release5
mean_days_between_releases0.5
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

32At risk · 18% of overall
How it's scored
0/60Stars — 1 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
46/80Monthly downloads — 2,839 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesvelixar-mcp-server
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,839
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

49At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
38.2/38.3PR acceptance — 2/2 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/22 approved changesets -- score normalized to 0
Inputs used
merged_prs2
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
3.4/25Owner reach — 2 followers of VelixarAi
11.2/25Track record — 14 public repos, account ~1 yr old
Inputs used
followers2
owner_typeUser
is_verified
owner_loginVelixarAi
public_repos14
account_age_days476
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 24 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesvelixar-mcp-server
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

86Excellent · 20% of overall
How it's scored
24/24CI workflows — 5 workflow(s)
24/24Tests present
16/16Linter config
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://velixarai.com
10/10Repository description
10/10Topics — 8 topics
10/10Wiki
Inputs used
topicsai-agents, ai-memory, claude, cursor, llm, mcp, model-context-protocol, persistent-memory
has_wikiyes
homepagehttps://velixarai.com
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

28Critical · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/22 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
0/10Dangerous-Workflow — dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
2.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 11 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate2.8
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

61Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 70 of 74 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.946
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config
11/11Static type checking — tsconfig.json
10/10Reproducible environment — lockfile
2.7/10Demonstrated agent practice — 1 of the last 74 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
5/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configstsconfig.json
agent_commit_share0.014
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
55/55Manageable file sizes — 0/52 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes51,481
source_files_sampled52
oversized_source_files0
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — openapi.json
20/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalyes
api_schema_filesopenapi.json

Key facts

1GitHub stars
1contributors
74commits, last 12 months
5days since last push
16releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:velixar-mcp-server@1.5.0; advisories assessed against the repository dependency graph instead

More detail

OpenSSF Scorecard 2.8 / 10
2.8aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 15:20 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/22 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
0Dangerous-Workflowdangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
5Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 5
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities11 existing vulnerabilities detected
Direct dependencies 1
RegistryPackageVersion constraintManifest
npm@modelcontextprotocol/sdk1.21.0package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "ai-memory",
        "claude",
        "cursor",
        "llm",
        "mcp",
        "model-context-protocol",
        "persistent-memory"
      ],
      "is_fork": false,
      "size_kb": 457,
      "has_wiki": true,
      "homepage": "https://velixarai.com",
      "languages": {
        "JavaScript": 102630,
        "TypeScript": 361372
      },
      "pushed_at": "2026-07-18T07:36:54Z",
      "created_at": "2026-02-15T07:13:38Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T07:37:00Z",
      "description": "MCP server for persistent AI memory — give any AI assistant long-term recall. Works with Claude, Kiro, Cursor, Windsurf.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "VelixarAi",
      "company": null,
      "location": null,
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/206012560?v=4",
      "created_at": "2025-04-03T01:56:38Z",
      "is_verified": null,
      "public_repos": 14,
      "account_age_days": 476
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-07-18T07:36:52Z"
        },
        {
          "tag": "v1.4.3",
          "kind": "patch",
          "published_at": "2026-07-18T02:01:02Z"
        },
        {
          "tag": "v1.4.2",
          "kind": "patch",
          "published_at": "2026-07-18T01:19:06Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-07-18T00:37:59Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-07-17T23:57:35Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2026-07-17T16:18:26Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2026-07-16T03:10:14Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-07-15T03:19:50Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-07-14T02:38:53Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-07-13T19:14:37Z"
        },
        {
          "tag": "v1.2.4",
          "kind": "patch",
          "published_at": "2026-07-13T18:40:55Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-07-13T03:14:40Z"
        },
        {
          "tag": "v1.2.2",
          "kind": "patch",
          "published_at": "2026-07-13T01:58:34Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-07-13T01:29:30Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-07-11T22:52:59Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-03-16T02:48:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "49dc4e3b0186637cbaaf6c765ba54875a6e6bdcc",
          "body": "…d back to branch org-entitlement-caps",
          "is_bot": false,
          "headline": "v1.5.0 — manifest handshake update system; org entitlement caps walke…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T07:36:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81d01847e6e59ba8e7354e7d05aaa80a7f56fece",
          "body": "…orkspace's real ceiling\"\n\nThis reverts commit 03448f17c18eb1a3f341244469ed3e8c58a14a93.",
          "is_bot": false,
          "headline": "Revert \"Entitlement-aware tool schema (F2v2b): cap tier enum at the w…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T07:35:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "689af4674864ed49f12153aaa4b0b6eea117810f",
          "body": "Real stdio MCP session: store -> search -> delete -> verify-gone under a hard\nwatchdog timeout — the only vantage point that sees the cold-start wedge class\n(backend health cannot, by construction). REFUSES to run without a dedicated\nVELIXAR_CANARY_KEY (never falls back to the broad key; equality-ch\n[…]\nlow_dispatch ONLY (public repo — no PR triggers, so\nforks can never reach the secret); secret absent = neutral skip, honestly\nlogged. timeout-minutes bounds a wedged run; its failure IS the detection.",
          "is_bot": false,
          "headline": "MCP-external synthetic probe (F1 layer 3, off-box by construction)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T03:28:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e523619f856dfe2657e9d0c59398aac8dafab06",
          "body": "…g channels\n\nDetection: A' GET /v1/mcp/manifest at startup (backend-authoritative status,\nseverity/reason/action computed server-side); A the X-Velixar-Mcp-Latest header\n(mid-session, re-arms once when latest moves); B npm poll (fallback).\nSurfacing: (1) MCP initialize `instructions` — server constr\n[…]\ngrity/\nbelow_minimum repeat on EVERY response with a results-may-be-affected warning —\nonce-per-session discipline otherwise (a notice on every call trains the model\nto skim past it). 12 notice tests.",
          "is_bot": false,
          "headline": "feat(manifest): update nudge v2 — manifest handshake + three surfacin…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T03:16:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "03448f17c18eb1a3f341244469ed3e8c58a14a93",
          "body": "…'s real ceiling\n\nFetch GET /v1/entitlements at startup; ListTools re-caps from pristine defs each\ncall (tier maximum 2 + honest description when org memory is not provisioned).\nvelixar_capabilities: toolset_tier (tool_tier deprecated alias), plan,\norg_memory_entitled, max_memory_tier. Fetch failure = no cap; server-side checks\nstay authoritative. 58/0 tests.",
          "is_bot": false,
          "headline": "Entitlement-aware tool schema (F2v2b): cap tier enum at the workspace…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T02:50:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e96ad9ed4640d1f8cfa5222aa140e55094b47c42",
          "body": "…atches 2-4)\n\n- #10: read X-Velixar-Volume and surface meta.volume_id — the agent can confirm which\n  volume it read/wrote (cross-volume contamination guard on the API surface).\n- #2: velixar_store declares the 50,000-char ceiling in the schema (maxLength + desc),\n  so a client never bisects to find\n[…]\nth passes through the backend's honest `probed` coverage\n  (write_path/embedding NOT probed) and labels capabilities_verified + tool_tier so a\n  green health can't be misread as 'writes work'. v1.4.3.",
          "is_bot": false,
          "headline": "feat(dx): surface volume_id + declared store limit + honest health (b…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T02:01:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27e6324f44d0363f297f7be60a56c50cd2642b8a",
          "body": "…ate_effect)\n\nFix-batch #1 client half. The backend now emits retryable/subsystem/state_effect/\nretry_after in the error body. The client:\n- honors the SERVER's retryable for the retry decision instead of guessing by status\n  (guessing is what hammered a systemic-fault path and tripped the breaker);\n- folds subsystem + state_effect + retry_after into the surfaced error message so the\n  agent knows which layer broke and whether a failed write left residue.\nv1.4.2.",
          "is_bot": false,
          "headline": "feat(dx): honor server-emitted error metadata (retryable/subsystem/st…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T01:19:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f6f01c291ff8cabb00afa6f45a67f1f7808e658",
          "body": "Two independent signals of 'a newer velixar-mcp-server exists', both funnelled\ninto ONE session-scoped notice on the next tool response's meta.update_available:\n- A (backend-driven): every API response carries X-Velixar-Mcp-Latest (server-\n  controlled via VELIXAR_MCP_LATEST env). api.ts reads it li\n[…]\nnever break a tool call); shown once, no nagging;\nsemver-ish compare ignores pre-release/garbage so it never nags on noise.\nAlso sends X-Velixar-Client-Version for backend staleness telemetry. v1.4.1.",
          "is_bot": false,
          "headline": "feat(nudge): A+B update notice — stale clients learn they're behind",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-18T00:37:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc9d667be40b97fbe381fbbc017bc078e61ab7db",
          "body": "The prompt-freshness guard requires every tool have a matrix entry. Empty array\n(no workflow prompt references it, same as velixar_search_neighborhood).",
          "is_bot": false,
          "headline": "test(lineage): register velixar_lineage in tool-prompt-matrix",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-17T23:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "560bb42c13b2dba36dd63491b86db4ac2445563b",
          "body": "- velixar_lineage: trace the DERIVATION graph (what a memory was built on / what\n  was built on it). N-hop DAG walk, both directions. Explicitly contrasted with\n  velixar_search_neighborhood in its description — reasoning provenance, not similarity.\n- velixar_store: source_ids now map to the backend\n[…]\nevious_memory_id[0], dropping every id past the first and conflating 'built on'\n  with 'came after' — the exact previous/parent/derived confusion this untangles.\n- v1.4.0 (package.json + server.json).",
          "is_bot": false,
          "headline": "feat(lineage): velixar_lineage tool + fix source_ids conflation",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-17T23:33:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acce2ebac041d2f52b79b1f2f7c728e2a17c0575",
          "body": "The backend fix made 0/0 read as UNKNOWN on the main path, but the\nclient-side fallback (coverage endpoint unreachable -> broad search + set\ndifference) kept the inversion: zero relevant memories returned\ncoverage_ratio 1 / confidence high — a hallucination trap. Found by an\nexternal pressure test r\n[…]\n, confidence 'unknown'. The validator no longer\ncoerces null->0, and the main path surfaces 'unknown' instead of\ncomparing null against thresholds. Falsifier-proven (2 tests red on the\nunfixed build).",
          "is_bot": false,
          "headline": "fix(coverage): the fallback branch must not invert at zero data (v1.3.4)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-17T16:18:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2c93d10c67d46a718ee92e8883d217c4219b6719",
          "body": "The 60s TTL cache was write-and-read only — nothing ever invalidated it.\nLive repro: inspect after update returned the pre-update row at 1ms;\ninspect after delete returned the full deleted row instead of the\ntombstone. Backend correct both times; the client cache lied.\n\nAny non-GET/HEAD request now \n[…]\nd retries too, since a timed-out mutation may still have landed\nserver-side. Falsifier-proven: the new tests fail 3/4 on the unfixed\nbuild (the passing one is the control proving the cache is active).",
          "is_bot": false,
          "headline": "fix(cache): invalidate the response cache on every mutation (v1.3.3)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-16T03:10:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df758fb920cd558e4e16b815d5cb4ef37359e43e",
          "body": null,
          "is_bot": false,
          "headline": "release: server.json 1.3.2 (the version-agreement pin caught the drift)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-15T03:19:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb42f49c62738b9f4f532e0d9538f065b0ed91f9",
          "body": "…3.2)\n\n- X-Velixar-Channel: mcp on every request — the channel is declared, not\n  inferred: this process IS the MCP server. (Backend still labels ≤1.3.1\n  correctly via the client-header fallback.)\n- origin{client,channel,stamped} from the backend now survives validation and\n  normalizeMemory, so hosts can show where a memory was written from.",
          "is_bot": false,
          "headline": "feat: declare the mcp channel + pass through the origin envelope (v1.…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-15T02:34:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a8080a8db2338109bd3ff1d926fb31a2680af71",
          "body": "NOT a fix for the 2026-07-14 zombie incident, and this commit will not pretend it\nis. The falsifier proved the current SDK already exits on clean stdin EOF — and the\nseventeen stale servers found on one machine were not orphans anyway: their host\nsessions were ALIVE, just idle for days, so no stdin \n[…]\nt, unconditional exit paths are worth pinning rather\nthan inheriting from SDK internals that may change. Behaviour verified: stdin-EOF,\nSIGTERM and SIGINT each exit 0 within ~10ms of the event. 45/45.",
          "is_bot": false,
          "headline": "hygiene: exit explicitly on stdin close and signals",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-14T13:46:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d0be07c426431c8519c970f117d970d8ff2b4c3f",
          "body": "- meta.request_ms: real elapsed time stamped at dispatch (was hardcoded 0)\n- meta.workspace_id: '(scoped by API key)' instead of '' — the empty string\n  read as 'workspace isolation is not active'; enforcement is server-side\n- velixar_list count_only: asks the store for a real count (new backend\n  p\n[…]\nr_contradictions: empty result no longer presented as 'beliefs are\n  consistent' — the contradictions store currently has no producer, and\n  absence of evidence must not present as evidence of absence",
          "is_bot": false,
          "headline": "fix: honesty batch from the probe review (v1.3.1)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-14T02:38:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6739de5fe69af07d3bd86b48a99a633b70e6724",
          "body": "loadConfig() defaulted userId to the literal 'mcp-user' and every read and\nwrite volunteered it. When the backend made user filters airtight (the 07-12\ncross-user leak fix), the placeholder became a fence: each MCP install lived\nin a parallel memory universe — 26 pinned memories visible where the\nda\n[…]\nites now flow through two helpers (userParams/withUser)\nin api.js; a test fails if a raw user_id: config.userId ever returns.\nAuthor stamps fall back to the MCP client slug instead of the placeholder.",
          "is_bot": false,
          "headline": "fix: stop inventing a user identity — the key decides scope (v1.3.0)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T19:14:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "295a29ac24e871c1652f33f7f1e1df2fa99144ae",
          "body": "….2.4)\n\nHand-editing claude_desktop_config.json was the worst step in onboarding. People\ndo not have the file, or they have it with other servers already in it and paste\nthe snippet over the top — silently deleting an MCP server they depend on. A\nconfig edit is a job for a program, not a copy-paste \n[…]\na\nrealistic config that already had filesystem + github servers: both survived, an\nunrelated top-level key survived, the key was written, and a second run rotated\nthe key without duplicating anything.",
          "is_bot": false,
          "headline": "feat: 'velixar-mcp-server install' — one command, no JSON editing (v1…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T18:40:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b3b94cb19dc47f5723b605c0154e5bc35cf16b5b",
          "body": "If client_id.ts reports a slug the backend does not recognise, it drops the\nX-Velixar-Client header and the tool's tile never turns 'connected' — the exact\nbug 1.2.3 fixed. And if the backend supports a host we cannot identify, that\nhost's users can never light up their tile either. Both directions \n[…]\n first falsifier appended a duplicate /zed/ rule AFTER the real\none, so it never matched and the test 'passed' — a falsifier that does not\nfalsify is worth nothing. Mutated the existing rule instead.)",
          "is_bot": false,
          "headline": "test: the slugs we emit must be slugs the backend knows",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T04:26:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f2d57105bec0bf9751aae6a72e56ba3b1c7c4f8",
          "body": "A tool using Velixar was invisible to the dashboard unless its key had been\nminted from that tool's own tile. Claude Code could call the API all day and its\nconnector tile stayed blank — because nothing in the request said who was calling.\n\nThe server already knew. It detects its host at startup and\n[…]\nc/server.ts      resolves identity at oninitialized.\n\nVerified over a real stdio handshake against a capture server: a client naming\nitself 'claude-code' causes X-Velixar-Client: claude_code upstream.",
          "is_bot": false,
          "headline": "feat: the server tells the API which host it is (v1.2.3)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T03:14:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24ec0959c5bb4fa779c25fb3ba725961a3d2f53d",
          "body": "The root cause of the version drift was not the hardcoded literals — it was that\nevery 1.2.x release was cut from a long-lived feature branch while main sat at\n1.1.0. Anyone reading main could not see what had actually shipped, so nobody\nnoticed the server was telling hosts it was 1.1.0.\n\nMerging PR #2 fixed today's gap. This stops it recurring: a tag can be cut from\nany commit, so being-on-main has to be checked, not assumed.",
          "is_bot": false,
          "headline": "ci: refuse to publish from a commit that is not on main",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T02:08:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e9089dc33de65b73e02d0070786af04d7ae9cbd",
          "body": "mcp: contract-gate (#3) + Stewardship/recall_first mode (#28)",
          "is_bot": false,
          "headline": "Merge pull request #2 from VelixarAi/mcp/contract-gate-and-stewardship",
          "author_name": "VelixarAi",
          "author_login": "VelixarAi",
          "committed_at": "2026-07-13T02:08:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2bd6d879dc7e3c7bacd8d1a6712ad38bf5802a96",
          "body": "…he workflow\n\nThe previous version used the secrets context inside setup-node's `with:`, which\nGitHub does not allow there. It did not just skip the step — it made the whole\nworkflow file INVALID, so tag pushes stopped producing runs at all. Being clever\nabout supporting both auth paths cost the pipeline entirely.\n\nWe have a token. Use it, plainly, and keep --provenance + id-token: write, which\nis what actually mints the attestation.",
          "is_bot": false,
          "headline": "ci: token publish with provenance — drop the conditional that broke t…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T01:58:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a732321774f6d9eb704978d4ab91ba8692f8597f",
          "body": "…attested\n\nnpm's OIDC exchange kept returning 404 (no matching trusted-publisher record),\nso releases were being cut by hand with NO provenance. GitHub's half was fine\nthroughout — it issued the id-token (200); npm simply never recognised us.\n\nThe key thing people conflate: PROVENANCE does not come \n[…]\nC when\nit does not. Either way the release is attested.\n\nAlso adds a post-publish check that the registry's version matches package.json\n— the exact drift that made 1.2.0 tell every host it was 1.1.0.",
          "is_bot": false,
          "headline": "ci: publish via automation token when present, OIDC otherwise — both …",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T01:53:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4e480965211b61eae3269b9e4387c9a768e5641",
          "body": "No code change from 1.2.1. This release exists to make the release path real:\n1.2.0 and 1.2.1 were both published BY HAND and carry no provenance\nattestation, because npm's trusted-publisher record did not match the workflow\n(OIDC exchange 404 -> ENEEDAUTH). The record has been recreated, so this tag\nproves the pipeline end to end — the only way to prove it, since npm forbids\nrepublishing a version.\n\nA product that sells auditable provenance should not ship an unattested\npackage.",
          "is_bot": false,
          "headline": "release: v1.2.2 — publish through the trusted-publishing pipeline",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T01:49:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a19f1867d9abc4d4cc8c202e446fcf36c9a15414",
          "body": "The guard checks the BUILT artifact (that is the point: what ships is what a host\nsees). But CI runs `npm ci && npm test && npm publish`, and the build lives in\nprepublishOnly — so tests ran with no dist/ and the guard died on\nERR_MODULE_NOT_FOUND. It caught a real gap on its first CI run: itself.",
          "is_bot": false,
          "headline": "ci: npm test must build first — the version guard inspects dist/",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T01:29:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87461857888130dbd81142f5ccbf2fa122c9a1d9",
          "body": "…ished\n\n1.2.0 shipped reporting itself as 1.1.0 (serverInfo) and 0.5.0\n(velixar_capabilities). npm forbids republishing 1.2.0, so the fix ships here.\n\nContent delta vs 1.2.0 is exactly the version derivation — no tool or behaviour\nchanges. server.json's two version fields bumped too, and now guarded\n[…]\nin the tarball and were the same hand-maintained drift trap.\n\nVerified on the built server over stdio: serverInfo 1.2.1, velixar_capabilities\n1.2.1, package.json 1.2.1, server.json 1.2.1. Suite 28/28.",
          "is_bot": false,
          "headline": "release: v1.2.1 — the version a host sees is now the version npm publ…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T01:27:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20e3ac0fa475fbb583d8870ae0bb6007fffcac77",
          "body": "The server told hosts it was 1.1.0 while npm shipped it as 1.2.0, and\nvelixar_capabilities/health reported 0.5.0. Three hand-typed literals, three\ndifferent answers to 'what version am I talking to?'. A version number that can\ndisagree with itself is worse than none, because it is trusted.\n\nBumping \n[…]\n= '0.5.0' fails the test. Suite 27/27.\n\nNOT PUBLISHED: npm forbids republishing 1.2.0, so the fix reaches users only on\nthe next release (1.2.1). Until then npx still serves the 1.1.0-reporting build.",
          "is_bot": false,
          "headline": "version: derive from package.json — three numbers had drifted apart",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-13T01:18:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec58c5213230cca6063a6660bfe469eabd31773f",
          "body": null,
          "is_bot": false,
          "headline": "ci: http loglevel to surface OIDC exchange errors",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-11T22:52:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d800239e4f8dcf67d5ceaa74a2e9b7be391fddca",
          "body": "…lishing",
          "is_bot": false,
          "headline": "ci: drop registry-url — its authToken line overrides OIDC trusted pub…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-11T22:49:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9534fe94b3e5e66b747b4595b500e48cd77460e6",
          "body": null,
          "is_bot": false,
          "headline": "ci: commit package-lock.json (npm ci requires it)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-11T22:44:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84d8eaa21dafc80cf4b6736913f6fae6ed522c8d",
          "body": null,
          "is_bot": false,
          "headline": "ci: npm trusted publishing via OIDC — no tokens, provenance included",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-11T22:42:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "194739fd2d53bf5d137acc52380c9793f392307b",
          "body": "…udit_log), recall_first playbook, /v1 API prefix",
          "is_bot": false,
          "headline": "release: v1.2.0 — 14 new tools (clairvoyance, retrieval, live-data, a…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-11T22:29:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2f686dd4e3d48a3a400b57565bb6d49cbadb72d",
          "body": "…1.2.0",
          "is_bot": false,
          "headline": "docs: verified counts (40 tools / 19 playbooks); sync server.json to …",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-07-11T22:29:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "540bc9af05fe01732302530f86ce0b5e5b5fdbdd",
          "body": null,
          "is_bot": false,
          "headline": "Fix: prefix API requests with /v1 to match live API",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-06-15T06:14:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c473ba6aa7abce0cd848e76655202ec666b02f3",
          "body": "…tract-gate branch",
          "is_bot": false,
          "headline": "Add Clairvoyance tools + simulation engine; fixes broken build on con…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-06-15T03:31:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be51bb6b5491b418f3189082c8d8d1db74f4fb4e",
          "body": "## Contract gate (#3)\n\nCloses #3. Prevents the silent-data-loss bug class where api.X<TypedShape>\ncasts compile but ignore real response shape (caused 19 silent-loss bugs\nacross 6 files in March 2026).\n\nsrc/api.ts:\n  + requestValidated<T>(path, opts, validate)\n  + getValidated<T>(path, validate, cac\n[…]\n fixed)\n  - Prompt size <4 KB (R4 token-cost guardrail)\n\n## Verification\n\nnpx tsc --noEmit clean\nnpm test → 24 passed, 0 failed across 7 suites\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "mcp: contract-gate (#3) + Stewardship/recall_first mode (#28)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-05-02T05:42:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d6ed674aac2160244aab5d988b361ab609c7cbc",
          "body": "…radictions/{id}",
          "is_bot": false,
          "headline": "fix: contradictions resolve calls correct backend URL /exocortex/cont…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-04-02T04:18:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31fe7a4cba94d891310c5690b72d30845077f254",
          "body": "… new tools\n\n- Replace batch_search references with multi_search in prompts\n- Remove batch_search from tool-prompt-matrix.json\n- Add graph_search, graph_stats, audit_log to matrix\n- Fix anti-pattern hint in server.ts\n- 12 passed, 0 failed",
          "is_bot": false,
          "headline": "fix: update prompts and tool-prompt-matrix for batch_search removal +…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-04-02T03:52:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8af1eb29519b062ae74db4f10966f2818d07c12",
          "body": "…rom Instance A",
          "is_bot": false,
          "headline": "fix: add missing error codes (QUARANTINE_VIOLATION, ARCHIVE_FAILED) f…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-04-02T03:26:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92111d0f2fa609286611199e31ead16b5f04f05e",
          "body": "Phase 2: multi_search transparency (matched_query_indices, query_weights, threshold),\n  batch_search merged as alias, search_neighborhood direction/min_similarity,\n  coverage_check auto_retrieve + structured gaps\nPhase 3: graph_search, graph_stats, graph_traverse filters + fuzzy matching,\n  graph_sa\n[…]\nistry), audit_log tool, tool tier system\nPhase 8: discover_data include_schema\n\n7 Whys mitigations: H3.1-H3.6, H4.1-H4.7, H7.1-H7.6\nCo-authored-by: Instance A (Phases 0, 1, 5, tool tiers in server.ts)",
          "is_bot": false,
          "headline": "feat: MCP tool improvements phases 2-8",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-04-02T03:22:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b582cd3aa21924b71803b6702d34dbaa5579dc1",
          "body": "New tool: velixar_upload\n- Reads local file, computes SHA-256\n- Presigns S3 URL, uploads, triggers ingestion pipeline\n- Supports PDF, MD, TXT, CSV, JSON, DOCX, code files\n- WAF detection with user-friendly error\n- 50MB limit, full provenance tracking\n\nPublished to npm as velixar-mcp-server@1.1.0",
          "is_bot": false,
          "headline": "feat: velixar_upload MCP tool — file upload with provenance (v1.1.0)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-22T04:20:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2349e6d12d40a063f38d2a9e6871edf97310ed11",
          "body": "Prompt Overhaul (10 issues):\n- cognitive_constitution prompt with full behavioral rules\n- KG-aware search docs in orient_then_narrow\n- Fixed template substitution bug (5 broken conditionals)\n- Error handling section in constitution\n- Part 2 chat agent updated (no more Memory Org LLM refs)\n- org_know\n[…]\n-5: Constitution reinforcement every N calls for hosts that\n  never read prompts (configurable via VELIXAR_CONSTITUTION_REINFORCE_INTERVAL)\n- AH-6: GetPrompt read logging with prompt name, host, count",
          "is_bot": false,
          "headline": "feat: prompt overhaul + architecture hardening (MCP-side)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-19T11:12:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3aa346bbb4da31322bffe3aa2f3b649570619ed9",
          "body": "H16: Model-aware distillation benchmarks — fixture with 5 extraction\n     prompts, 4 models, regression policy (block deploy on >10% drop).\nM1:  Messy data fixture — 1200 memories with duplicates, contradictions,\n     poor tags, ambiguous scope, low signal, stale data + gold tasks.\nM2:  Benchmark co\n[…]\nlation\n     rules covering latency, circuit breaker, rate limits, quality.\nM25: Alert enrichment spec — auto-attach CloudWatch logs and client\n     metrics to alerts with per-pattern enrichment rules.",
          "is_bot": false,
          "headline": "harden: Final batch — benchmarks, CI, observability (10 tasks)",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T06:37:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c46b86c02fffa3b94ec662dcb360352f9cea049",
          "body": "M4:  Aging grace period — distill response includes archival_policy with\n     min_age_days and require_completeness_check for backend to respect.\nM13: Graph traverse usage telemetry — tracks total calls and no-entity\n     calls, exports getGraphTelemetry() for monitoring.\nM15: Tool gap detection — b\n[…]\n>20 items) get rate_limit_hint\n     suggesting batch splitting.\nM27: Dual session storage — session_save stores both raw content and\n     compact summary (tagged session_summary) for efficient resume.",
          "is_bot": false,
          "headline": "harden: Medium batch 3 — runtime & lifecycle",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T06:28:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc452289fda8637d966cf157a98fcd22b672f355",
          "body": "M3:  Circular dependency check — script detects import cycles, found and\n     fixed api.ts↔validate.ts cycle (removed log import from validate.ts).\nM5:  Constitution compression — already done in H1 (compact ~400 tokens).\nM7:  Adaptive circuit breaker — exponential backoff for recovery timeout\n     \n[…]\ns/errors, postmortem→decisions).\nM28: Exact dedup fast path — content hash check before cosine similarity\n     in distill, records hash after successful store.\nM29: API timing always-on — same as M10.",
          "is_bot": false,
          "headline": "harden: Medium batch 1+2 — infrastructure & benchmarks",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T06:26:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb9733afa1297783f22715f19b829ffff5373ca9",
          "body": "H4:  Workspace change detection — detects workspace ID change mid-session,\n     warns on first tool call after switch.\nH5:  Stale env var detection — startup check compares VELIXAR_WORKSPACE_ID\n     against git root, logs warning on mismatch.\nH16: Rate limit budget tracking — captures X-RateLimit-* \n[…]\ng of supporting memories.\nH29: (Already done in H28) — all prompts include max tool call budgets.\nH32: Security mode verification — read-back after set, includes\n     verified: true/false in response.",
          "is_bot": false,
          "headline": "harden: Sprint 5 — integration hardening",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T06:19:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6063b563ad54c8365e6b39a87b95b387a3309467",
          "body": "H2:  Tool description A/B testing script — measures selection accuracy\n     for ambiguous pairs (search/context, inspect/search, timeline/\n     contradictions). Informational for CI.\nH10: Identity staleness detection — stale_identity flag when identity\n     hasn't been updated in >20 tool calls.\nH11\n[…]\n_answer computed in every\n     response meta (true when data present, confident, no contradictions).\nH31: Runtime debug toggle — velixar_debug(verbose=true/false) toggles\n     logging without restart.",
          "is_bot": false,
          "headline": "harden: Sprint 4 — cognitive layer hardening",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T06:15:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7aafb8921d5cdf61e2fa98dfbbbc353f2635b64a",
          "body": "H15: Distillation quality scoring — word count, specificity heuristic,\n     quality score (0-1) with issue flags in distill response.\nH17: Provenance validation on inspect — derived_from IDs checked for\n     existence, broken links marked as {status: 'deleted'}.\nH20: Adaptive duplicate detection — t\n[…]\nompleteness_unverified when\n     source_ids provided, included in quality scoring.\nH3/H6: Schema contract tests — CI script validates 7 Lambda endpoint\n     response shapes against expected contracts.",
          "is_bot": false,
          "headline": "harden: Sprint 3 — data quality & lifecycle",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T06:05:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89b99ea48dee83ce83e88ee2dbea2ead508f536f",
          "body": "H1:  Constitution fallback — compact constitution injected into first tool\n     response if host never reads the resource. One-shot per session.\nH7:  Response finalizer — wrapResponse now sets status='partial' when\n     partial_context is true, enforces absence_reason on data_absent.\nH8:  Absence se\n[…]\nisory workflow prompts — all 16 prompts rewritten with stop\n     conditions BEFORE tool sequences, 'Suggested approach' instead of\n     'Workflow', explicit max tool call budgets, early-exit guidance.",
          "is_bot": false,
          "headline": "harden: Sprint 2 — silent degradation prevention",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T04:21:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6af2cc4a9a9ebb4c9aa82964ffe2d3f09ac0d53",
          "body": "New tool: velixar_session_resume handles session reconstruction server-side.\nAccepts intent (continue_coding, write_postmortem, catch_up) and optional\nfocus entity. Internally: loads session memories, chunks by 15-min time\nwindows, selects chunks within token budget (recent=full detail, older=\nsumma\n[…]\ny), extracts decisions and open threads, returns chunk manifest\nfor drill-down via session_recall(chunk_id=...).\n\nLLM makes one call, gets one response, full session awareness. No\npagination required.",
          "is_bot": false,
          "headline": "harden: C8 velixar_session_resume — single-call session reconstruction",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T04:09:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d713c1947a688f4eeb9218319c3d13b80fbd968f",
          "body": "… gate, C6 bot scanning, C7 SDK parity\n\nC3: Contradictions now classified as 'contradiction' vs 'superseded' based\non memory timestamp gap (>7 days = temporal update, not conflict).\nResponse includes separate evidence and superseded arrays.\n\nC4: Content-hash idempotency cache (5min TTL) prevents dup\n[…]\nion of API keys, tokens, AWS keys, emails, IPs. Stripped before store.\n\nC7: SDK parity check script compares MCP tool list against JS and Python\nSDK methods. Designed for CI — exits non-zero on drift.",
          "is_bot": false,
          "headline": "harden: C3 temporal supersession, C4 batch idempotency, C5 CI quality…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T04:07:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6a6c99e739d373d0e41a0705793fc5c0ab23d100",
          "body": "C1: Added src/validate.ts with typed validators for all backend response\nshapes (store, search, list, graph, identity, overview, mutation).\nReplaced all 26 'as any' casts across tool handlers with validated\nresponses. Malformed backend data now throws SchemaError instead of\npassing undefined fields \n[…]\nt roots on initialize via listRoots().\nOn each tool call, validates resolved workspace ID against host roots.\nInjects _workspace_warning into responses on mismatch. Logs workspace\ndrift at warn level.",
          "is_bot": false,
          "headline": "harden: C1 runtime schema validation + C2 workspace cross-validation",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T04:04:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d32fcd0d2c73f9b8004632a631d93a9269a9682",
          "body": "…tation details",
          "is_bot": false,
          "headline": "docs: rewrite README for v1.0.0 — full cognitive surface, no implemen…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T03:25:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef3f9873ce11a9c6132187fcc4d70b8e881a58a1",
          "body": "Core cognitive context MCP server is feature-complete.\n\nSurface:\n- 25 tools (5 CRUD + 8 flagship + 2 session + 2 batch + 2 maintenance + 4 system + 2 import/export)\n- 5 resources (constitution, identity, recent, relevant, shadow graph)\n- 16 workflow prompts across 6 groups\n- 108 benchmark prompts, a\n[…]\n7 (97%) — remaining 10 are v2.0.0 external integrations\n\nv2.0.0 scope (separate repos):\n- VS Code extension\n- Slack/Teams bot\n- velixar-js / velixar-python SDK updates\n- HubSpot/Salesforce integration",
          "is_bot": false,
          "headline": "release: v1.0.0 — Velixar MCP Server",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:48:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8e6c2b9e2d42529c69ef8b86d1d85f31a070326b",
          "body": "…y docs\n\n- velixar://domains/{domain}/shadow_graph dynamic resource\n- evaluate_enterprise_fit workflow prompt (16 total)\n- Cursor/Windsurf compatibility verified (tools-only mode)\n- JetBrains feasibility assessed (Continue.dev recommended)\n- 5 resources, 16 prompts, 25 tools\n\n297/307 tasks complete (97%).",
          "is_bot": false,
          "headline": "feat: shadow graph resource, enterprise-fit prompt, host compatibilit…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:47:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b538e5450d457b300e79a79037d5fb86e79a80d7",
          "body": "- HTTP health check server (VELIXAR_HEALTH_PORT env var)\n- Alert-level structured logging for store failures\n- GitHub Action: velixar-memory-sync (PR merge → memory)\n- GitHub Action: velixar-decision-capture (issue close → decision memory)\n- CI webhook endpoint verified E2E\n\n25 tools, 4 resources, 15 prompts.\n293/307 tasks complete (95%).",
          "is_bot": false,
          "headline": "feat: health check server, GitHub Actions, CI webhook, alerting",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:45:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2894c183a038a1f427fa7ba3764275522071f597",
          "body": "- velixar_import: bulk import from JSON/Markdown with provenance tracking\n- velixar_export: enhanced with include_graph option for full backup\n- Structured JSON logging (VELIXAR_LOG_FORMAT=json) for Datadog/CloudWatch\n- Tool-level logging with duration and error tracking\n- Circuit breaker state change logging\n- OpenAPI 3.1 spec covering all API routes\n- 108 benchmark prompts covering all 25 tools\n\n25 tools, 4 resources, 15 prompts.\n287/307 tasks complete (94%).",
          "is_bot": false,
          "headline": "feat: import/export tools, structured logging, OpenAPI spec",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:37:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de72ccd2eaa0e990f465b2bfb9d6ea083efd6610",
          "body": "…l degradation\n\n- velixar_export: JSON and Markdown export with optional query filter\n- HOST-COMPATIBILITY.md: 6 verified hosts, degradation behavior documented\n- Graceful degradation: tools work without resources/prompts support\n\n24 tools, 4 resources, 15 prompts.\n276/307 tasks complete (90%).",
          "is_bot": false,
          "headline": "feat: Phase 7 partial — export tool, host compatibility docs, gracefu…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:28:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57f71cf98197dbb8ff30ddb20d8398e0ca247355",
          "body": "…breaker\n\nPhase 5.2: Parallel fetch with Promise.allSettled for time-to-first-context.\nPartial results returned when some endpoints fail. Timing tracked in response meta.\n\nPhase 5.5: Full benchmark suite:\n- 102 tool selection prompts covering all 23 tools\n- 4 benchmark fixtures (solo-dev, research, \n[…]\neria\n- 7 metrics with baseline/excellence thresholds\n- 2 needle-in-haystack test designs\n- Benchmark runner: node benchmarks/run.js (all pass)\n\n23 tools, 4 resources, 15 prompts, 4 benchmark fixtures.",
          "is_bot": false,
          "headline": "feat: Phase 5 complete — benchmarks, streaming optimization, circuit …",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:26:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccc628a1a1d5b2eff11d286d43be7e28155c096c",
          "body": "…elemetry\n\nPhase 5.1: Circuit breaker (5 failures → open, 30s reset, half-open probe).\nIntegrated into API client request path. Cache fallback when circuit open.\n\nPhase 5.3: Debug tool now shows circuit breaker state, retry/fallback counts.\nHealth tool shows circuit state. VELIXAR_DEBUG=true enables\n[…]\nnning mode (standard/strict/off).\nMode surfaced in capabilities output.\n\nCapabilities tool now lists prompts alongside tools and resources.\nVersion bumped to 0.6.0.\n\n23 tools, 4 resources, 15 prompts.",
          "is_bot": false,
          "headline": "feat: v0.6.0 — Phase 5 reliability, circuit breaker, security tool, t…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:22:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "98840ab05e81d194e80594c5769ffa4a42cdb5f5",
          "body": "…verified\n\nLayer 1: Constitution resource already shipping (6 cognitive modes, orient-then-narrow,\nanti-patterns, justification rules, response classes, episodic aging).\n\nLayer 2: 15 workflow prompts across 5 groups:\n- Orientation (4): recall_prior_reasoning, build_project_context, profile_entity, o\n[…]\nnes: purpose, trigger, tool order, reasoning rules, output form, stop conditions.\nPrompts capability registered in server, ListPrompts and GetPrompt handlers wired.\n\n22 tools, 4 resources, 15 prompts.",
          "is_bot": false,
          "headline": "feat: Phase 4 complete — 15 cognitive workflow prompts, constitution …",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:20:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6c5488773d997b1f3e2b8b0f0d1f6967eee69b2a",
          "body": "…g rules\n\nPhase 3.3: velixar_batch_store (up to 20 items, parallel, per-item status),\nvelixar_batch_search (up to 10 queries, parallel, per-query results)\n\nPhase 3.4: velixar_consolidate (merge episodic → semantic, preserves provenance,\nbefore/after summaries), velixar_retag (add/remove/replace tags\n[…]\nsodic eligible\nfor archival after semantic extraction, semantic persists indefinitely, archived\nepisodic accessible via timeline/inspect but excluded from active context.\n\n22 tools total, 4 resources.",
          "is_bot": false,
          "headline": "feat: Phase 3 complete — batch ops, consolidate, retag, episodic agin…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:17:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6eb2bf7749581f2d362d28fa5f81ebb18c378d09",
          "body": "…ve/recall, proactive relevant recall resource\n\nPhase 3.1: velixar_distill now detects near-duplicates (>0.92 similarity) and flags\nactive contradictions before storing. Skips storage on duplicate detection.\n\nPhase 3.2: velixar_session_save and velixar_session_recall — save session summaries\nwith se\n[…]\ndology defined for all 4 remaining metrics.\nRelease gate checklist template created.\n\n18 tools total (5 CRUD + 8 flagship + 2 session + 3 system)\n4 resources (constitution, identity, recent, relevant)",
          "is_bot": false,
          "headline": "feat: Phase 3 — distill duplicate/contradiction detection, session sa…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:06:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7eb0ec30b4e34ec5e03f115b77d7d69ebf38e52d",
          "body": "…sodic preference",
          "is_bot": false,
          "headline": "feat: contradictions Resolution form, timeline Timeline form with epi…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-16T02:02:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "370aadad05d88351df3a57c500011c9485818f28",
          "body": "…xt semantic preference, distill provenance\n\n- velixar_identity: get/store/update flows, workspace_scope enforcement\n- velixar_graph_traverse: normalize output to GraphEntity/GraphRelation schema\n- velixar_context: prefer semantic memories for injection, episodic for evidence\n- velixar_distill: auto-tag generation, source_ids provenance (derived_from)\n- All schemas complete in types.ts (Phase 0.3 done)",
          "is_bot": false,
          "headline": "feat: Phase 2 refinements — identity CRUD, graph normalization, conte…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-15T23:32:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b6208d7697c9b9d0b0a45f4bf759a714c51b212",
          "body": "…bsence semantics, inspect justification\n\nResources per strategy memo:\n- velixar://system/constitution — cognitive behavioral constitution (6 modes, anti-patterns, justification rules)\n- velixar://identity/current — user identity profile with 24h staleness tracking\n- velixar://memories/recent — comp\n[…]\nn\n\nSchema:\n- AbsenceReason enum (no_data, low_confidence, partial, conflict, stale, backend_error)\n- absence_reason field on ResponseMeta\n\nTools:\n- velixar_inspect now carries full justification chain",
          "is_bot": false,
          "headline": "feat: v0.5.0 — resources (constitution, identity, improved recall), a…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-15T23:29:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "42064b51dd562be8662bbaade4a804e9409e42e7",
          "body": "…red responses\n\n- New src/justify.ts: evidence classification, confidence computation,\n  presentation policy matrix per MCP-SERVER-STRATEGY.md\n- Wired into velixar_context, velixar_identity, velixar_contradictions,\n  velixar_patterns — all inferred responses now carry JustificationResult\n- Enforces:\n[…]\nule 1)\n- Confidence bands: high/medium/low/unstable/conflicting\n- Presentation modes: assertive → do_not_assert based on claim type + confidence\n- Evidence freshness: recent (<24h), aging (<7d), stale",
          "is_bot": false,
          "headline": "feat: justification pipeline — epistemic accountability for all infer…",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-15T21:40:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d901250bfba2a2193c41ae9a9d0d41adbd3f4f00",
          "body": "- Graph traverse: handle 404 gracefully (data_absent, not error)\n- System tools: wrap in VelixarResponse<T> envelope\n- Update version to 0.4.0, feature flags reflect live state\n- Capabilities: 16 tools, 7 features enabled\n\nBackend fixes (deployed as Lambda v115):\n- update_memory: use memory agent for existence check, not org_memories\n- graph routes: add missing _get_memory_agent() calls (was UnboundLocalError)",
          "is_bot": false,
          "headline": "fix: E2E verification pass — all 16 tools wired and working",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-15T20:37:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec8ed75d11a90d862ee5ffc8b7f1b53211c93662",
          "body": "Implemented:\n- velixar_context: synthesized workspace brief (4 parallel API calls)\n- velixar_identity: user profile, preferences, expertise, goals\n- velixar_contradictions: conflicting beliefs/facts\n- velixar_timeline: temporal evolution of topics\n- velixar_patterns: recurring problem/solution motif\n[…]\nrk once backend is fixed.\n\nAlso: added /exocortex/contradictions and /exocortex/overview routes\nto API Gateway, added /v1/memory/identity endpoint to Lambda.\n\nServer now at v0.4.0 with 15 tools total.",
          "is_bot": false,
          "headline": "feat: Phase 2 flagship tools — 7 of 8 cognitive tools live",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-15T20:18:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc3801f89fe1b38116a2373c9bbb82e1c9f2d033",
          "body": "- TypeScript migration: 11 modules, strict mode, zero errors\n- Response normalization: all CRUD tools return VelixarResponse<T> envelope\n- Tool contracts: 13-tool disambiguation matrix (TOOL-CONTRACTS.md)\n- memory_type filter on search/list, author field on store\n- README rewritten with workspace config docs, all tools, response format\n- System tools: health, debug, capabilities\n\nPhase 1 tasks: 39/39 complete (except workspace bleed tests — deferred to Phase 2.11)",
          "is_bot": false,
          "headline": "feat: Phase 1 complete — TypeScript, normalization, tool contracts",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-03-15T19:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8cfac0e4a142622a9e77538691bc4104267ed11",
          "body": "* ci: add shared CI workflows\n\n- Wire up VelixarAi/velixar-ci-workflows node-ci reusable workflow\n- Add .pre-commit-config.yaml (gitleaks + eslint)\n\n* ci: retrigger after making shared workflows repo public\n\n* fix: add secrets: inherit to CI caller workflow\n\n* ci: retrigger after node-ci.yml YAML fi\n[…]\nprovements\n\n* ci: retrigger after workflow improvements\n\n* ci: retrigger\n\n* ci: retrigger after pytest continue-on-error fix\n\n* ci: retrigger\n\n---------\n\nCo-authored-by: Velixar AI <dev@velixarai.com>",
          "is_bot": false,
          "headline": "ci: add shared CI workflows (#1)",
          "author_name": "VelixarAi",
          "author_login": "VelixarAi",
          "committed_at": "2026-03-07T13:19:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71ac422087a0981a767f3de3207907ded6f3a98b",
          "body": null,
          "is_bot": false,
          "headline": "v0.2.4: add mcpName for MCP Registry, publish to official registry",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-02-28T03:21:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3180d0ed96200c8c23fd5d22b07a2291d7ef66b9",
          "body": "- 5 tools: store, search, list, update, delete\n- Auto-recall via MCP resources\n- Works with Claude Desktop, Kiro, Cursor, Windsurf, Continue\n- 30s timeout for Lambda cold starts\n- MIT licensed",
          "is_bot": false,
          "headline": "feat: velixar MCP server v0.2.2 — persistent memory for any AI assistant",
          "author_name": "Velixar AI",
          "author_login": null,
          "committed_at": "2026-02-28T02:50:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 16,
      "commits_last_year": 74,
      "latest_release_at": "2026-07-18T07:36:52Z",
      "latest_release_tag": "v1.5.0",
      "releases_from_tags": true,
      "days_since_last_push": 5,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "velixar-mcp-server",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "mcp",
            "model-context-protocol",
            "ai",
            "memory",
            "llm",
            "persistent-memory",
            "cognitive-context",
            "knowledge-graph",
            "identity",
            "vector-search"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/velixar-mcp-server",
          "is_deprecated": false,
          "latest_version": "1.5.0",
          "repository_url": "https://github.com/VelixarAi/velixar-mcp-server",
          "versions_count": 24,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2839,
          "first_published_at": "2026-02-15T23:07:07.366000Z",
          "latest_published_at": "2026-07-18T07:37:16.305000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [
        "openapi.json"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 51481,
      "source_files_sampled": 52,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.21.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 2,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "VelixarAi",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/206012560?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "host-compat.yml",
        "memory-summarize.yml",
        "publish.yml",
        "synthetic-probe.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/22 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 5,
            "reason": "dependency not pinned by hash detected -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "11 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "49dc4e3b0186637cbaaf6c765ba54875a6e6bdcc",
        "ran_at": "2026-07-23T15:20:05Z",
        "aggregate_score": 2.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T13:50:41Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-13T02:08:16Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/VelixarAi/velixar-mcp-server",
    "host": "github.com",
    "name": "velixar-mcp-server",
    "owner": "VelixarAi"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 56,
      "inputs": {
        "security": 28,
        "vitality": 77,
        "community": 32,
        "governance": 49,
        "engineering": 86
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 77,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "commits_last_year": 74,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "74 commits in the last year",
                "points": 16.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 74
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 16,
              "latest_release_tag": "v1.5.0",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "16 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 32,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "packages": [
                "velixar-mcp-server"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2839
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,839 downloads/month across npm",
                "points": 46,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2839,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 49,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 2,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2/2 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2,
                      "decided": 2
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 31,
            "inputs": {
              "followers": 2,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "VelixarAi",
              "public_repos": 14,
              "account_age_days": 476
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of VelixarAi",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "VelixarAi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "14 public repos, account ~1 yr old",
                "points": 11.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 14
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "velixar-mcp-server"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "24 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 24
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 86,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "ai-agents",
                "ai-memory",
                "claude",
                "cursor",
                "llm",
                "mcp",
                "model-context-protocol",
                "persistent-memory"
              ],
              "has_wiki": true,
              "homepage": "https://velixarai.com",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://velixarai.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 28,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 28,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 2.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 2.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "11 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 61,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.946,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "70 of 74 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 70,
                      "sampled": 74
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.014,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 74 commits agent-authored or agent-credited",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 74
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 5,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 51481,
              "source_files_sampled": 52,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/52 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 52,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": [
                "openapi.json"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "openapi.json",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "openapi.json"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:velixar-mcp-server@1.5.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T15:20:15.687130Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/v/VelixarAi/velixar-mcp-server.svg",
  "full_name": "VelixarAi/velixar-mcp-server",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.