Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 10:40 UTC

YosefHayim / ebay-mcp

Local MCP server that exposes eBay Sell APIs to AI assistants with OAuth, tool gating, and stdio/HTTP transports.

TypeScriptMIT★ 105 stars⑂ 48 forkssince Nov 2025View on GitHub ↗

YosefHayim/ebay-mcp holds a health index of 70 out of 100, placing it in the Good band. It scores highest on Vitality (92/100) and lowest on Sustainability & Governance (54/100). It was last updated 5 days ago. A single contributor accounts for most of its recent work.

70
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

70
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

YosefHayimPersonal account
16 followers12 public repossince Aug 2024

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npmebay-mcp1.14.12,316345 days agomcpebayebay-apimodel-context-protocolai-toolsaillmdocumentationapiserverbackend

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

92Excellent · 22% of overall
How it's scored
36/36Push recency — last push 5 days ago
22.2/36Commit cadence — 32/52 weeks with commits
18/18Commit volume — 697 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year697
human_commit_share0.73
days_since_last_push5
active_weeks_last_year32

Release discipline

100Excellent
How it's scored
27/27Ships releases — 51 releases published
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~3.8 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count51
latest_release_tagv1.14.1
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases3.8
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

65Moderate · 18% of overall
How it's scored
32.7/60Stars — 105 stars
13.9/25Forks — 48 forks
0/15Watchers — 2 watchers
Inputs used
forks48
stars105
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
44.9/80Monthly downloads — 2,316 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesebay-mcp
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,316
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

54Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
2.4/22.5Commit distribution — top contributor authored 89% of commits
9.5/13.5Contributor breadth — 7 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled7
top_contributor_share0.892
How it's scored
44/46.8Issue resolution — 94% of issues closed
26.2/38.3PR acceptance — 85/124 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs85
open_issues1
closed_issues16
issue_closed_ratio0.941
closed_unmerged_prs39
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
8.8/25Owner reach — 16 followers of YosefHayim
11.9/25Track record — 12 public repos, account ~1 yr old
Inputs used
followers16
owner_typeUser
is_verified
owner_loginYosefHayim
public_repos12
account_age_days701
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 34 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesebay-mcp
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

82Good · 20% of overall
How it's scored
24/24CI workflows — 11 workflow(s)
24/24Tests present
16/16Linter config — biome.json
0/9.6Pre-commit hooks
6.4/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configyes
has_precommit_configno

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://www.npmjs.com/package/ebay-mcp
10/10Repository description
10/10Topics — 16 topics
10/10Wiki
Inputs used
topicschatgpt, claude, ebay, mcp-server, typescript, api-wrapper, ebay-api, mcp, model-context-protocol, npm, oauth2, ai-agents, cursor, local-first, nodejs, tool-gating
has_wikiyes
homepagehttps://www.npmjs.com/package/ebay-mcp
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

56Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0/2.5CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 10 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.8
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
13.2/25Indirect dependencies free of known advisories — 1 affected: @hono/node-server 1.19.15 (moderate 5.9)
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages194
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Matched the npm:ebay-mcp@1.14.1 runtime dependency closure — what installing the published package pulls in — 194 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

76Good · 0% of overall
How it's scored
45/45Agent instructions — .github/copilot-instructions.md, AGENTS.md, CLAUDE.md
15/15Machine-readable docs (llms.txt) — llms.txt present
40/40Legible commit history — 72 of 73 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtyes
legible_history_share0.986
agent_instruction_files.github/copilot-instructions.md, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes12,152
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — biome.json
11/11Static type checking — tsconfig.json, ui/tsconfig.json
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 29 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 2 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilespnpm-lock.yaml
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configstsconfig.json, ui/tsconfig.json
agent_commit_share0.29
toolchain_manifests
dependency_bot_commit_share0.02
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
53.2/55Manageable file sizes — 8/245 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes507,840
source_files_sampled245
oversized_source_files8
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalyes
api_schema_files

Key facts

105GitHub stars
7contributors
697commits, last 12 months
5days since last push
51releases
1bus factor
1open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 48 ⇿
0Stars
48Forks
51Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

010203040504722025-112026-032026-07
Major 1Minor 13Patch 37
OpenSSF Scorecard 4.8 / 10
4.8aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 10:39 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
0CI-Tests0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities10 existing vulnerabilities detected
Direct dependencies 17
RegistryPackageVersion constraintManifest
npm@modelcontextprotocol/ext-apps1.7.4package.json
npm@modelcontextprotocol/sdk1.29.0package.json
npmchalk^5.6.2package.json
npmcors^2.8.6package.json
npmdotenv^17.4.2package.json
npmdotenv-stringify^3.0.1package.json
npmeffect^3.21.4package.json
npmexpress^5.2.1package.json
npmfast-xml-builder1.2.0package.json
npmfast-xml-parser^5.9.0package.json
npmhelmet^8.2.0package.json
npmjose^6.2.3package.json
npmprompts^2.4.2package.json
npmupdate-notifier^7.3.1package.json
npmwinston^3.19.0package.json
npmzod^3.25.76package.json
npmzod-to-json-schema^3.25.2package.json
All dependencies 442

Full resolved dependency set from the GitHub dependency graph: 17 direct and 425 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npm@modelcontextprotocol/ext-apps1.7.4direct
npm@modelcontextprotocol/sdk1.29.0direct
npmchalk5.6.2direct
npmcors2.8.6direct
npmdotenv17.4.2direct
npmdotenv-stringify3.0.1direct
npmeffect3.21.4direct
npmexpress5.2.1direct
npmfast-xml-builder1.2.0direct
npmfast-xml-parser5.9.0direct
npmhelmet8.2.0direct
npmjose6.2.3direct
npmprompts2.4.2direct
npmupdate-notifier7.3.1direct
npmwinston3.19.0direct
npmzod3.25.76direct
npmzod-to-json-schema3.25.2direct
npm@babel/code-frame7.29.7indirect
npm@babel/helper-string-parser7.29.7indirect
npm@babel/helper-validator-identifier7.29.7indirect
npm@babel/parser7.29.7indirect
npm@babel/types7.29.7indirect
npm@bcoe/v8-coverage1.0.2indirect
npm@biomejs/biome2.5.1indirect
npm@biomejs/cli-darwin-arm642.5.1indirect
npm@biomejs/cli-darwin-x642.5.1indirect
npm@biomejs/cli-linux-arm642.5.1indirect
npm@biomejs/cli-linux-arm64-musl2.5.1indirect
npm@biomejs/cli-linux-x642.5.1indirect
npm@biomejs/cli-linux-x64-musl2.5.1indirect
npm@biomejs/cli-win32-arm642.5.1indirect
npm@biomejs/cli-win32-x642.5.1indirect
npm@colors/colors1.6.0indirect
npm@dabh/diagnostics2.0.8indirect
npm@esbuild/aix-ppc640.28.1indirect
npm@esbuild/android-arm0.28.1indirect
npm@esbuild/android-arm640.28.1indirect
npm@esbuild/android-x640.28.1indirect
npm@esbuild/darwin-arm640.28.1indirect
npm@esbuild/darwin-x640.28.1indirect
npm@esbuild/freebsd-arm640.28.1indirect
npm@esbuild/freebsd-x640.28.1indirect
npm@esbuild/linux-arm0.28.1indirect
npm@esbuild/linux-arm640.28.1indirect
npm@esbuild/linux-ia320.28.1indirect
npm@esbuild/linux-loong640.28.1indirect
npm@esbuild/linux-mips64el0.28.1indirect
npm@esbuild/linux-ppc640.28.1indirect
npm@esbuild/linux-riscv640.28.1indirect
npm@esbuild/linux-s390x0.28.1indirect
npm@esbuild/linux-x640.28.1indirect
npm@esbuild/netbsd-arm640.28.1indirect
npm@esbuild/netbsd-x640.28.1indirect
npm@esbuild/openbsd-arm640.28.1indirect
npm@esbuild/openbsd-x640.28.1indirect
npm@esbuild/openharmony-arm640.28.1indirect
npm@esbuild/sunos-x640.28.1indirect
npm@esbuild/win32-arm640.28.1indirect
npm@esbuild/win32-ia320.28.1indirect
npm@esbuild/win32-x640.28.1indirect
npm@hono/node-server1.19.14indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/sourcemap-codec1.5.5indirect
npm@jridgewell/trace-mapping0.3.31indirect
npm@mswjs/interceptors0.41.9indirect
npm@noble/hashes1.8.0indirect
npm@nodable/entities2.2.0indirect
npm@nodelib/fs.scandir2.1.5indirect
npm@nodelib/fs.stat2.0.5indirect
npm@nodelib/fs.walk1.2.8indirect
npm@open-draft/deferred-promise2.2.0indirect
npm@open-draft/logger0.3.0indirect
npm@open-draft/until2.1.0indirect
npm@paralleldrive/cuid22.3.1indirect
npm@pnpm/config.env-replace1.1.0indirect
npm@pnpm/network.ca-file1.0.2indirect
npm@pnpm/npm-conf3.0.3indirect
npm@polka/url1.0.0-next.29indirect
npm@redocly/ajv8.11.2indirect
npm@redocly/config0.22.0indirect
npm@redocly/openapi-core1.34.15indirect
npm@rollup/rollup-android-arm-eabi4.62.0indirect
npm@rollup/rollup-android-arm644.62.0indirect
npm@rollup/rollup-darwin-arm644.62.0indirect
npm@rollup/rollup-darwin-x644.62.0indirect
npm@rollup/rollup-freebsd-arm644.62.0indirect
npm@rollup/rollup-freebsd-x644.62.0indirect
npm@rollup/rollup-linux-arm-gnueabihf4.62.0indirect
npm@rollup/rollup-linux-arm-musleabihf4.62.0indirect
npm@rollup/rollup-linux-arm64-gnu4.62.0indirect
npm@rollup/rollup-linux-arm64-musl4.62.0indirect
npm@rollup/rollup-linux-loong64-gnu4.62.0indirect
npm@rollup/rollup-linux-loong64-musl4.62.0indirect
npm@rollup/rollup-linux-ppc64-gnu4.62.0indirect
npm@rollup/rollup-linux-ppc64-musl4.62.0indirect
npm@rollup/rollup-linux-riscv64-gnu4.62.0indirect
npm@rollup/rollup-linux-riscv64-musl4.62.0indirect
npm@rollup/rollup-linux-s390x-gnu4.62.0indirect
npm@rollup/rollup-linux-x64-gnu4.62.0indirect
npm@rollup/rollup-linux-x64-musl4.62.0indirect
npm@rollup/rollup-openbsd-x644.62.0indirect
npm@rollup/rollup-openharmony-arm644.62.0indirect
npm@rollup/rollup-win32-arm64-msvc4.62.0indirect
npm@rollup/rollup-win32-ia32-msvc4.62.0indirect
npm@rollup/rollup-win32-x64-gnu4.62.0indirect
npm@rollup/rollup-win32-x64-msvc4.62.0indirect
npm@so-ric/colorspace1.1.6indirect
npm@standard-schema/spec1.1.0indirect
npm@types/body-parser1.19.6indirect
npm@types/chai5.2.3indirect
npm@types/configstore6.0.2indirect
npm@types/connect3.4.38indirect
npm@types/cookiejar2.1.5indirect
npm@types/cors2.8.19indirect
npm@types/deep-eql4.0.2indirect
npm@types/estree1.0.9indirect
npm@types/express5.0.6indirect
npm@types/express-serve-static-core5.1.1indirect
npm@types/http-errors2.0.5indirect
npm@types/methods1.1.4indirect
npm@types/node25.9.3indirect
npm@types/prompts2.4.9indirect
npm@types/qs6.15.1indirect
npm@types/range-parser1.2.7indirect
npm@types/react19.2.17indirect
npm@types/react-dom19.2.3indirect
npm@types/send1.2.1indirect
npm@types/serve-static2.2.0indirect
npm@types/superagent8.1.10indirect
npm@types/supertest7.2.0indirect
npm@types/triple-beam1.3.5indirect
npm@types/update-notifier6.0.8indirect
npm@vitest/coverage-v84.1.9indirect
npm@vitest/expect4.1.9indirect
npm@vitest/mocker4.1.9indirect
npm@vitest/pretty-format4.1.9indirect
npm@vitest/runner4.1.9indirect
npm@vitest/snapshot4.1.9indirect
npm@vitest/spy4.1.9indirect
npm@vitest/ui4.1.9indirect
npm@vitest/utils4.1.9indirect
npmaccepts2.0.0indirect
npmagent-base7.1.4indirect
npmajv8.20.0indirect
npmajv-formats3.0.1indirect
npmansi-align3.0.1indirect
npmansi-colors4.1.3indirect
npmansi-regex5.0.1indirect
npmansi-regex6.2.2indirect
npmansi-styles6.2.3indirect
npmanymatch3.1.3indirect
npmanynum1.0.0indirect
npmargparse2.0.1indirect
npmarray-union2.1.0indirect
npmasap2.0.6indirect
npmassertion-error2.0.1indirect
npmast-v8-to-istanbul1.0.4indirect
npmasync3.2.6indirect
npmasynckit0.4.0indirect
npmatomically2.1.1indirect
npmbalanced-match1.0.2indirect
npmbinary-extensions2.3.0indirect
npmbody-parser2.3.0indirect
npmboxen7.1.1indirect
npmboxen8.0.1indirect
npmbrace-expansion2.1.1indirect
npmbraces3.0.3indirect
npmbytes3.1.2indirect
npmcall-bind-apply-helpers1.0.2indirect
npmcall-bound1.0.4indirect
npmcamelcase7.0.1indirect
npmcamelcase8.0.0indirect
npmchai6.2.2indirect
npmchange-case5.4.4indirect
npmchokidar3.6.0indirect
npmcli-boxes3.0.0indirect
npmcolor5.0.3indirect
npmcolor-convert3.1.3indirect
npmcolor-name2.1.0indirect
npmcolor-string2.1.4indirect
npmcolorette1.4.0indirect
npmcombined-stream1.0.8indirect
npmcommander9.5.0indirect
npmcomponent-emitter1.3.1indirect
npmconfig-chain1.1.13indirect
npmconfigstore7.1.0indirect
npmcontent-disposition1.1.0indirect
npmcontent-type1.0.5indirect
npmcontent-type2.0.0indirect
npmconvert-source-map2.0.0indirect
npmcookie0.7.2indirect
npmcookie-signature1.2.2indirect
npmcookiejar2.1.4indirect
npmcross-spawn7.0.6indirect
npmcsstype3.2.3indirect
npmdebug4.4.3indirect
npmdeep-extend0.6.0indirect
npmdelayed-stream1.0.0indirect
npmdepd2.0.0indirect
npmdezalgo1.0.4indirect
npmdir-glob3.0.1indirect
npmdot-prop9.0.0indirect
npmdunder-proto1.0.1indirect
npmeastasianwidth0.2.0indirect
npmee-first1.1.1indirect
npmemoji-regex10.6.0indirect
npmemoji-regex8.0.0indirect
npmemoji-regex9.2.2indirect
npmenabled2.0.0indirect
npmencodeurl2.0.0indirect
npmes-define-property1.0.1indirect
npmes-errors1.3.0indirect
npmes-module-lexer2.1.0indirect
npmes-object-atoms1.1.2indirect
npmes-set-tostringtag2.1.0indirect
npmesbuild0.28.1indirect
npmescape-goat4.0.0indirect
npmescape-html1.0.3indirect
npmestree-walker3.0.3indirect
npmetag1.8.1indirect
npmeventsource3.0.7indirect
npmeventsource-parser3.1.0indirect
npmexpect-type1.3.0indirect
npmexpress-rate-limit8.5.2indirect
npmfast-check3.23.2indirect
npmfast-deep-equal3.1.3indirect
npmfast-glob3.3.3indirect
npmfast-safe-stringify2.1.1indirect
npmfast-uri3.1.2indirect
npmfastq1.20.1indirect
npmfdir6.5.0indirect
npmfecha4.2.3indirect
npmfflate0.8.3indirect
npmfill-range7.1.1indirect
npmfinalhandler2.1.1indirect
npmflatted3.4.2indirect
npmfn.name1.1.0indirect
npmform-data4.0.6indirect
npmformidable3.5.4indirect
npmforwarded0.2.0indirect
npmfresh2.0.0indirect
npmfsevents2.3.3indirect
npmfunction-bind1.1.2indirect
npmget-east-asian-width1.6.0indirect
npmget-intrinsic1.3.0indirect
npmget-proto1.0.1indirect
npmget-tsconfig4.14.0indirect
npmglob-parent5.1.2indirect
npmglobal-directory4.0.1indirect
npmglobby11.1.0indirect
npmgopd1.2.0indirect
npmgraceful-fs4.2.10indirect
npmgraceful-fs4.2.11indirect
npmhas-flag4.0.0indirect
npmhas-symbols1.1.0indirect
npmhas-tostringtag1.0.2indirect
npmhasown2.0.4indirect
npmhono4.12.25indirect
npmhtml-escaper2.0.2indirect
npmhttp-errors2.0.1indirect
npmhttps-proxy-agent7.0.6indirect
npmhusky9.1.7indirect
npmiconv-lite0.7.2indirect
npmignore5.3.2indirect
npmindex-to-position1.2.0indirect
npminherits2.0.4indirect
npmini1.3.8indirect
npmini4.1.1indirect
npmip-address10.2.0indirect
npmipaddr.js1.9.1indirect
npmis-binary-path2.1.0indirect
npmis-extglob2.1.1indirect
npmis-fullwidth-code-point3.0.0indirect
npmis-glob4.0.3indirect
npmis-in-ci1.0.0indirect
npmis-installed-globally1.0.0indirect
npmis-node-process1.2.0indirect
npmis-npm6.1.0indirect
npmis-number7.0.0indirect
npmis-path-inside4.0.0indirect
npmis-promise4.0.0indirect
npmis-stream2.0.1indirect
npmis-unsafe1.0.1indirect
npmisexe2.0.0indirect
npmistanbul-lib-coverage3.2.2indirect
npmistanbul-lib-report3.0.1indirect
npmistanbul-reports3.2.0indirect
npmjs-levenshtein1.1.6indirect
npmjs-tokens10.0.0indirect
npmjs-tokens4.0.0indirect
npmjs-yaml4.2.0indirect
npmjson-schema-traverse1.0.0indirect
npmjson-schema-typed8.0.2indirect
npmjson-stringify-safe5.0.1indirect
npmkleur3.0.3indirect
npmkuler2.0.0indirect
npmky1.14.3indirect
npmlatest-version9.0.0indirect
npmlogform2.7.0indirect
npmmagic-string0.30.21indirect
npmmagicast0.5.3indirect
npmmake-dir4.0.0indirect
npmmath-intrinsics1.1.0indirect
npmmedia-typer1.1.0indirect
npmmerge-descriptors2.0.0indirect
npmmerge21.4.1indirect
npmmethods1.1.2indirect
npmmicromatch4.0.8indirect
npmmime2.6.0indirect
npmmime-db1.52.0indirect
npmmime-db1.54.0indirect
npmmime-types2.1.35indirect
npmmime-types3.0.2indirect
npmminimatch5.1.9indirect
npmminimist1.2.8indirect
npmmrmime2.0.1indirect
npmms2.1.3indirect
npmmylas2.1.14indirect
npmnanoid3.3.12indirect
npmnegotiator1.0.0indirect
npmnock14.0.15indirect
npmnormalize-path3.0.0indirect
npmobject-assign4.1.1indirect
npmobject-inspect1.13.4indirect
npmobug2.1.3indirect
npmon-finished2.4.1indirect
npmonce1.4.0indirect
npmone-time1.0.0indirect
npmopenapi-typescript7.13.0indirect
npmoutvariant1.4.3indirect
npmpackage-json10.0.1indirect
npmparse-json8.3.0indirect
npmparseurl1.3.3indirect
npmpath-expression-matcher1.5.0indirect
npmpath-key3.1.1indirect
npmpath-to-regexp8.4.2indirect
npmpath-type4.0.0indirect
npmpathe2.0.3indirect
npmpicocolors1.1.1indirect
npmpicomatch2.3.2indirect
npmpicomatch4.0.4indirect
npmpkce-challenge5.0.1indirect
npmplimit-lit1.6.1indirect
npmpluralize8.0.0indirect
npmpostcss8.5.15indirect
npmpropagate2.0.1indirect
npmproto-list1.2.4indirect
npmproxy-addr2.0.7indirect
npmpupa3.3.0indirect
npmpure-rand6.1.0indirect
npmqs6.15.2indirect
npmqueue-lit1.5.2indirect
npmqueue-microtask1.2.3indirect
npmrange-parser1.2.1indirect
npmraw-body3.0.2indirect
npmrc1.2.8indirect
npmreact19.2.7indirect
npmreact-dom19.2.7indirect
npmreadable-stream3.6.2indirect
npmreaddirp3.6.0indirect
npmregistry-auth-token5.1.1indirect
npmregistry-url6.0.1indirect
npmrequire-from-string2.0.2indirect
npmresolve-pkg-maps1.0.0indirect
npmreusify1.1.0indirect
npmrollup4.62.0indirect
npmrouter2.2.0indirect
npmrun-parallel1.2.0indirect
npmsafe-buffer5.2.1indirect
npmsafe-stable-stringify2.5.0indirect
npmsafer-buffer2.1.2indirect
npmscheduler0.27.0indirect
npmsemver7.8.4indirect
npmsend1.2.1indirect
npmserve-static2.2.1indirect
npmsetprototypeof1.2.0indirect
npmshebang-command2.0.0indirect
npmshebang-regex3.0.0indirect
npmside-channel1.1.1indirect
npmside-channel-list1.0.1indirect
npmside-channel-map1.0.1indirect
npmside-channel-weakmap1.0.2indirect
npmsiginfo2.0.0indirect
npmsirv3.0.2indirect
npmsisteransi1.0.5indirect
npmslash3.0.0indirect
npmsource-map-js1.2.1indirect
npmstack-trace0.0.10indirect
npmstackback0.0.2indirect
npmstatuses2.0.2indirect
npmstd-env4.1.0indirect
npmstrict-event-emitter0.5.1indirect
npmstring-width4.2.3indirect
npmstring-width5.1.2indirect
npmstring-width7.2.0indirect
npmstring_decoder1.3.0indirect
npmstrip-ansi6.0.1indirect
npmstrip-ansi7.2.0indirect
npmstrip-json-comments2.0.1indirect
npmstrnum2.4.0indirect
npmstubborn-fs2.0.0indirect
npmstubborn-utils1.0.2indirect
npmsuperagent10.3.0indirect
npmsupertest7.2.2indirect
npmsupports-color10.2.2indirect
npmsupports-color7.2.0indirect
npmtext-hex1.0.0indirect
npmtinybench2.9.0indirect
npmtinyexec1.2.4indirect
npmtinyglobby0.2.17indirect
npmtinyrainbow3.1.0indirect
npmto-regex-range5.0.1indirect
npmtoidentifier1.0.1indirect
npmtotalist3.0.1indirect
npmtriple-beam1.4.1indirect
npmtsc-alias1.8.17indirect
npmtsx4.22.4indirect
npmtype-fest2.19.0indirect
npmtype-fest4.41.0indirect
npmtype-is2.1.0indirect
npmtypescript5.9.3indirect
npmundici-types7.24.6indirect
npmunpipe1.0.0indirect
npmuri-js-replace1.0.1indirect
npmutil-deprecate1.0.2indirect
npmvary1.1.2indirect
npmvite7.3.5indirect
npmvite-plugin-singlefile2.3.3indirect
npmvitest4.1.9indirect
npmwhen-exit2.1.5indirect
npmwhich2.0.2indirect
npmwhy-is-node-running2.3.0indirect
npmwidest-line4.0.1indirect
npmwidest-line5.0.0indirect
npmwinston-transport4.9.0indirect
npmwrap-ansi8.1.0indirect
npmwrap-ansi9.0.2indirect
npmwrappy1.0.2indirect
npmxdg-basedir5.1.0indirect
npmxml-naming0.1.0indirect
npmyaml-ast-parser0.0.43indirect
npmyargs-parser21.1.1indirect
Dependency advisories 1

Installing npm:ebay-mcp@1.14.1 pulls in 194 packages, direct and transitive: 1 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
@hono/node-server1.19.15indirectmoderate12.0.5

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "chatgpt",
        "claude",
        "ebay",
        "mcp-server",
        "typescript",
        "api-wrapper",
        "ebay-api",
        "mcp",
        "model-context-protocol",
        "npm",
        "oauth2",
        "ai-agents",
        "cursor",
        "local-first",
        "nodejs",
        "tool-gating"
      ],
      "is_fork": false,
      "size_kb": 13761,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/ebay-mcp",
      "languages": {
        "CSS": 4837,
        "HTML": 1195,
        "Shell": 6826,
        "Dockerfile": 1193,
        "JavaScript": 92316,
        "TypeScript": 4178261
      },
      "pushed_at": "2026-07-19T13:51:13Z",
      "created_at": "2025-11-09T06:05:17Z",
      "owner_type": "User",
      "updated_at": "2026-07-23T13:06:30Z",
      "description": "Local MCP server that exposes eBay Sell APIs to AI assistants with OAuth, tool gating, and stdio/HTTP transports.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://yosefhayimsabag.com",
      "name": null,
      "type": "User",
      "login": "YosefHayim",
      "company": null,
      "location": "Israel, HaMarkeZ, Tel Aviv",
      "followers": 16,
      "avatar_url": "https://avatars.githubusercontent.com/u/179159376?v=4",
      "created_at": "2024-08-22T17:23:42Z",
      "is_verified": null,
      "public_repos": 12,
      "account_age_days": 701
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.14.1",
          "kind": "patch",
          "published_at": "2026-07-19T13:07:45Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2026-07-19T11:57:14Z"
        },
        {
          "tag": "v1.13.3",
          "kind": "patch",
          "published_at": "2026-07-04T01:27:09Z"
        },
        {
          "tag": "v1.13.2",
          "kind": "patch",
          "published_at": "2026-07-01T23:59:57Z"
        },
        {
          "tag": "v1.13.1",
          "kind": "patch",
          "published_at": "2026-06-25T18:25:43Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2026-06-25T18:13:31Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-06-16T16:56:55Z"
        },
        {
          "tag": "v1.11.1",
          "kind": "patch",
          "published_at": "2026-06-15T18:22:33Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2026-06-15T16:04:00Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2026-06-15T15:36:29Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-06-15T15:04:09Z"
        },
        {
          "tag": "v1.8.10",
          "kind": "patch",
          "published_at": "2026-05-23T10:54:34Z"
        },
        {
          "tag": "v1.8.9",
          "kind": "patch",
          "published_at": "2026-05-09T17:52:28Z"
        },
        {
          "tag": "v1.8.8",
          "kind": "patch",
          "published_at": "2026-04-26T10:08:28Z"
        },
        {
          "tag": "v1.8.6",
          "kind": "patch",
          "published_at": "2026-04-23T14:44:23Z"
        },
        {
          "tag": "v1.8.5",
          "kind": "patch",
          "published_at": "2026-03-21T02:43:50Z"
        },
        {
          "tag": "v1.8.4",
          "kind": "patch",
          "published_at": "2026-03-16T15:36:12Z"
        },
        {
          "tag": "v1.8.3",
          "kind": "patch",
          "published_at": "2026-03-16T14:00:02Z"
        },
        {
          "tag": "v1.8.2",
          "kind": "patch",
          "published_at": "2026-03-16T13:45:50Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2026-03-16T13:42:06Z"
        },
        {
          "tag": "v1.7.9",
          "kind": "patch",
          "published_at": "2026-03-16T07:22:13Z"
        },
        {
          "tag": "v1.7.8",
          "kind": "patch",
          "published_at": "2026-03-16T07:19:42Z"
        },
        {
          "tag": "v1.7.7",
          "kind": "patch",
          "published_at": "2026-03-16T06:51:48Z"
        },
        {
          "tag": "v1.7.6",
          "kind": "patch",
          "published_at": "2026-03-16T06:44:42Z"
        },
        {
          "tag": "v1.7.5",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:26Z"
        },
        {
          "tag": "v1.7.4",
          "kind": "patch",
          "published_at": "2026-03-04T23:11:03Z"
        },
        {
          "tag": "v1.7.3",
          "kind": "patch",
          "published_at": "2026-02-28T15:12:09Z"
        },
        {
          "tag": "v1.7.2",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:59Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2026-02-04T22:10:45Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-02-04T22:01:07Z"
        },
        {
          "tag": "v1.6.4",
          "kind": "patch",
          "published_at": "2026-02-04T21:51:30Z"
        },
        {
          "tag": "v1.6.3",
          "kind": "patch",
          "published_at": "2026-02-04T21:41:37Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-01-09T12:09:45Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-01-08T01:52:30Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:25Z"
        },
        {
          "tag": "v1.4.6",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:24Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:22Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:21Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:21Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:21Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-03-16T06:47:19Z"
        },
        {
          "tag": "v1.1.8",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:18Z"
        },
        {
          "tag": "v1.1.7",
          "kind": "patch",
          "published_at": "2025-11-12T19:56:16Z"
        },
        {
          "tag": "v1.1.6",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:17Z"
        },
        {
          "tag": "v1.1.5",
          "kind": "patch",
          "published_at": "2026-03-16T06:47:17Z"
        },
        {
          "tag": "v1.1.4",
          "kind": "patch",
          "published_at": "2025-11-12T14:37:20Z"
        },
        {
          "tag": "v1.1.3",
          "kind": "patch",
          "published_at": "2025-11-12T14:36:53Z"
        },
        {
          "tag": "v1.1.2",
          "kind": "patch",
          "published_at": "2025-11-12T14:36:40Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2025-11-12T14:36:29Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2025-11-12T14:36:21Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2025-11-12T14:36:08Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "0a23f966e50695e7bb1087ee4e71ae9a03a85da5",
          "body": "Record marketing/inventory splits, setup re-home, OpenAPI path fix,\nand docs truth-up for the 1.14.1 patch release.",
          "is_bot": false,
          "headline": "docs(changelog): backfill v1.14.1 structure cleanup notes",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T13:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47d95fd139affcae71510969c7dfc26c91eba5b9",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.14.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-19T13:05:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eda16bd5851ef4c14c47d2a3cd0242be6e22ca2a",
          "body": "…x typo (#138 #139 #140)\n\n- Split Marketing API/schemas into campaigns/ads/promotions/reports (+ facade/barrel)\n- Split Inventory API into items/offers/locations (+ facade)\n- Re-home setup wizard/validator/security/scope helpers into scripts/; oauthHelper into auth/\n- Rename generated markeitng-and-promotions → marketing-and-promotions (sync maps already correct)\n\nPublic MCP tool names and api.marketing.*/api.inventory.* method names stay stable.",
          "is_bot": false,
          "headline": "chore: close structure backlog — split god modules, re-home setup, fi…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T12:54:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f5f1af7479e805d99b248a43b1ef92a335a9252",
          "body": "…locales\n\nCollapse definitions/tool-handlers husks into tools/types.ts, archive stale\narchitecture notes and plans, drop the one-off trading smoke script, document\nfamily/schema ownership, and align locale READMEs with Compliance decommission\nclaims. Large module splits tracked in #138–#140.",
          "is_bot": false,
          "headline": "chore: structure cleanup — collocate tool types, truth-up docs, sync …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T12:37:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "653718a8f1be7f8172045b01ea90ee4f4251d364",
          "body": "Ship unreleased work since v1.13.3: fork-inspired deploy/read-only/finding/CS\nfeatures, Effect schema migration, and dead Negotiation/Compliance tool fixes.",
          "is_bot": false,
          "headline": "chore(release): v1.14.0",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T11:56:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f38980616ff29fbd5cb6b05a5728d4bb56d332e",
          "body": "Confirm ebay_get_offers_to_buyers stays off the registry (nonexistent\nNegotiation endpoint) and make Compliance listing-violation tools fail\nfast with a clear decommission message instead of a bare eBay 404.",
          "is_bot": false,
          "headline": "fix: handle dead Negotiation and Compliance tools (#136, #137)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-19T11:56:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f4627d0957c2a5d5deae3b520dc930fdca03b29",
          "body": "Adopt high-value patterns from community forks without taking their\nproduct-specific shortcuts: container-friendly HTTP (PORT, 0.0.0.0,\nMCP_AUTH_TOKEN), Accept-Language + richer eBay error bodies, EBAY_READ_ONLY\ntool filtering, Basic-auth token introspection, Finding sold comps via\nbrowse, and Fulfillment cancellation/refund scans for seller CS.\n\nVerified locally with act (biome, typecheck, unit+integration, build).",
          "is_bot": false,
          "headline": "feat: fork-inspired deploy, locale, read-only, finding, and CS tools",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-18T18:08:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bbcdc7c7c5b44401933b6bf0113ea20d86c07a6",
          "body": null,
          "is_bot": false,
          "headline": "refactor: migrate tool schemas to effect adapter",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T05:45:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "884e108d4b3cafb9637a8f9b37e9c1738bc64148",
          "body": null,
          "is_bot": false,
          "headline": "refactor: align code with style guide",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T04:24:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecb39f1b8ce34c0aa8a872e44d3b3c4d7d0f76de",
          "body": null,
          "is_bot": false,
          "headline": "refactor: extract eBay rate limit tracker",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:22:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e859a6ddd897b2cac9b937ef04b1f5b8b6c19bea",
          "body": null,
          "is_bot": false,
          "headline": "fix: wire typed API error modules",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:21:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c4b129557b28d418bcde19120b466236160d27d",
          "body": null,
          "is_bot": false,
          "headline": "fix: add typed API error modules",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:20:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb09d0560d7f472e41f76f44e5d13fe959217ed6",
          "body": null,
          "is_bot": false,
          "headline": "docs: clarify trading schema docs",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:19:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3824fa487543abb96ae0588c87f044bc26d0491",
          "body": null,
          "is_bot": false,
          "headline": "fix: align eBay API Effect call sites",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:17:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd9280d522fb0b3d75c075c59cf6ba83bbd7554a",
          "body": null,
          "is_bot": false,
          "headline": "fix: align auth and trading tests",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:14:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "147edbda4910898ce067db6fd2e7575982ed9960",
          "body": null,
          "is_bot": false,
          "headline": "fix: type eBay API auth failures",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:11:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27e0d8feb905945a411d1f43ee35080bf348149d",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README hero and polish structure",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-07T01:07:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94c1ab69c0f0b0940366d81415abaaa87561a631",
          "body": null,
          "is_bot": false,
          "headline": "fix: correct ppnpm typo in CI workflows",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T21:07:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3aef79c50f75cdb6faf7acfe553ad6c9796a06c",
          "body": "- Replace npm/package-lock.json with pnpm/pnpm-lock.yaml\n- Add packageManager field to package.json\n- Update scripts: npm run → pnpm, npx → pnpm exec\n- Workflows: add pnpm/action-setup@v4, cache: pnpm, pnpm install --frozen-lockfile",
          "is_bot": false,
          "headline": "chore: migrate to pnpm, update CI workflows",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T21:01:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f2fc1f1cc97d1de9660f2b76da5fd0bc38f3ee7",
          "body": "…k, report-failure, ci)\n\nSynced from the canonical dufflebag/alg workflow set. Each workflow is\nsingle-purpose and reusable (workflow_call). ci.yml orchestrates them and\ngates merges via the CI Gate job.",
          "is_bot": false,
          "headline": "ci: add missing workflow templates (biome, build, e2e, test, typechec…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T19:47:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1c633da2d21ac8adfff8e7b403de86f197722fd",
          "body": "- Document scripts/dev/ convention in CODE-STYLE.md\n- Add scripts/dev/ to .gitignore so local dev scripts stay local",
          "is_bot": false,
          "headline": "chore: organize dev scripts into scripts/dev/ (gitignored)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T14:00:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e2d600cfefd8b8f262b297e14af4b581042be1d",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.3",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-04T01:26:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aaf9c269985e2141e44dd5382a99df3fd834e17",
          "body": "…d code (#133)\n\n* chore: close the style backlog — @/ imports, ui in the gate, drop dead code\n\nFollow-up burndown of the backlog #132 deferred (recorded in ADR 0006):\n\n- Codemod all 66 `../` parent imports to the `@/` alias, path-resolved and\n  typecheck-verified (Rule 1 → 0 violations)\n- Delete orp\n[…]\n\ntests pass, build ok (emits build/ui/stat.html).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: close the style backlog — @/ imports, ui in the gate, drop dea…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-04T01:25:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5a6a1f380ad2d24f4017b90af71ddb212db4e317",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: add verify script chaining the full check + build gate",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-02T20:47:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "18ca39ed6dde17e38050d8d698a413f97e3bbbd4",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-01T23:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "296fe19d0b43033d6a0b06a11740c04ecde99859",
          "body": "…as a reusable gate (#132)\n\nCodifies how the repo is built (docs + config) and replaces the ad-hoc GitHub\nActions with a reusable single-purpose gate. Docs record the desired end-state;\nexisting code is evidence. No runtime code moves.\n\nDocs\n- Add CODE-STYLE.md (style SSOT), CONTEXT.md, LANGUAGE.md,\n[…]\nte weekly-unit-tests.yml.\n\nValidated green: typecheck, biome ci (0 errors / ~1226 warnings), unit (1120),\nintegration (33), build.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: add code-style + structure docs, fix Biome config, rebuild CI …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-07-01T23:57:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "741517fdf75e714dd40e9e600d9eb79a530f2c9b",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: apply biome format and lint fixes",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-27T21:29:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "92c8fc81d7cb44b6beec5f107258a2a1a2cc475c",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-25T18:24:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e969e0a93aec811a4161659a71607be9f60a7d09",
          "body": "@redocly/openapi-core (transitive via openapi-typescript, dev-scope) pinned\njs-yaml 4.1.1, vulnerable to a quadratic-complexity DoS in merge-key handling\nvia repeated aliases (GHSA-h67p-54hq-rp68, Dependabot alert #171). Adds a pnpm\noverride forcing js-yaml >=4.2.0, matching the existing esbuild/yaml override\npattern, and extends the supply-chain guard test to pin it.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): force js-yaml >=4.2.0 to patch GHSA-h67p-54hq-rp68 DoS (#131)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-25T18:23:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2583be9eb0e3ebbcaee8714fb3cf670763cbd1cd",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.13.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-25T18:12:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f26464ffc37e1305323a27202ff33bfbcfac972e",
          "body": "…ontext (#130)\n\n* feat(tools): gate tool exposure via EBAY_MCP_TOOLS to control agent context\n\nPreviously all ~187 tools were advertised in a single tools/list on every\nconnect, loading the full catalogue (descriptions + Zod schemas) into every\nagent's context window. This adds an opt-in EBAY_MCP_TO\n[…]\n rather than hard-coding its opaque '2' encoding.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(tools): gate tool exposure via EBAY_MCP_TOOLS to control agent c…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-25T18:11:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2da9b717f766368df0bbeb908c7fdc71bbad0b61",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.12.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-16T16:56:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8dc5619240903d08928ecbf33acdcb75504ea586",
          "body": "… (#129)\n\n* feat(ui): add opt-in interactive MCP Apps UI layer\n\nRender 13 core read tools as interactive table / card / chart views via\nself-contained `ui://` HTML resources, gated by host capability and an\n`EBAY_MCP_UI=off` kill-switch. Hosts without MCP Apps support (e.g. Cursor)\nfall back to the \n[…]\nnt the EBAY_MCP_UI on/off toggle in .env.example.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ui): opt-in interactive MCP Apps UI layer (table / card / chart)…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-16T16:54:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c4fafd1b567a3d2bf85a2d4758a6d608586810a",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.11.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T18:21:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01377bdb6237c2fb61ce2dce1befe0908282ec9e",
          "body": "…8n (#128)\n\nRestructure the English README into a launch-style landing page: centered\nhero banner, drift-free shields badges (npm version/downloads, CI, MIT,\nNode, TypeScript + 322-tools / 100%-coverage / MCP stat badges), feature\nlist, an \"eBay MCP vs. raw eBay REST API\" comparison table, an anchor\n[…]\nhe real\nsrc/tools/categories/* paths, and add comparison/translation context.\n\nAdd public/ebay-mcp-hero.png (optimized to 1400px).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): overhaul landing docs with hero, badges, and tracked i1…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T18:20:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eff2b8575809ba240138d64b3639cbbff83b1e7e",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.11.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T16:03:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "810e3c79af8cdc31ac70329638f9a2dac8a8151a",
          "body": "…Cursor (#125)\n\nGenerate 'using' (drive-the-tools) and 'contributing' (work-on-the-repo)\nskills from one canonical source into each tool's native format — Claude\nCode SKILL.md, Cursor .cursor/rules/*.mdc, and a Codex AGENTS.md managed\nblock — with the live tool registry (322 tools, 13 families) inje\n[…]\nion, registry snapshot, and\n  the write-safety invariants (idempotency, preservation, foreign-skip,\n  dry-run, two-layer compose).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(skills): add agent-skills installer for Codex, Claude Code, and …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T16:02:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "df868268770e7c96eac69342f1e069ae8e971310",
          "body": "GitHub will force Node 24 on Actions runners starting 2026-06-16 and\nwarns that the Node 20-based actions may stop working. Bump every\naffected action to its current Node 24-based major across all workflows:\n\n- actions/checkout            v4 -> v6\n- pnpm/action-setup           v4 -> v6  (version sti\n[…]\nnput changes are required — all `with:` keys used here are still\nsupported. checkout@v6 was already in use by weekly-api-sync.yml.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: upgrade GitHub Actions to Node 24 runtimes (#127)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T15:50:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25d23191df7fab06e386ff32abe241e468665048",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.10.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T15:35:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e65e984e72417d959bcbd8355d62a18e7816e4",
          "body": "The update-notifier dependency was wired but dormant: notices never\nappeared because the check was silenced in npm-script contexts (the\ncommon launch path for the CLIs), getUpdateInfo() was unused, and the\nserver has no TTY for a box.\n\n- version.ts: opt into npm-script contexts via shouldNotifyInNpm\n[…]\n  registry check (installed vs latest), failing soft when offline.\n- tests: cover the notifier wiring with update-notifier mocked.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): surface available update notices to users (#126)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T15:34:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c46f4c0ccb8c808e750e00a42696de9beef8c924",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.9.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-15T15:03:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e9d04da2544a66a8bfc39b8b188a0fd25ed0f4",
          "body": "…ardening (#124)\n\nMerge dev → main: authenticating-proxy support (#122) + API/tooling hardening",
          "is_bot": false,
          "headline": "Merge dev → main: authenticating-proxy support (#122) + API/tooling h…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T15:02:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69291af718fe8ef7c09904acb9cea912e8d8aab4",
          "body": "…ted XSS\n\nThe auto-capture callback page (renderCallbackPage in oauth-helper.ts) wrote\neBay's `error` / `error_description` query params straight into HTML, so a\ncrafted `…/oauth/callback?error=<script>…` reflected unescaped into the\nresponse — CodeQL js/reflected-xss (high), new in PR #124's feat(s\n[…]\n payload in error_description is encoded, not reflected.\n\nnpm run check: 0 errors · npm test: 1035 passing · npm run build: clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): HTML-escape OAuth callback error detail to stop reflec…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:53:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f29ea5de48fe9f4341906add0acd8eed674516f5",
          "body": "Root cause of \"the provided authorization refresh token is invalid or was\nissued to another client\" at server start: the wizard's saveConfig wrote tokens\nunquoted (EBAY_USER_REFRESH_TOKEN=v^1.1#i^1#...). eBay tokens contain '#', which\ndotenv treats as the start of an inline comment for UNQUOTED valu\n[…]\n;\ncredit the developer in eBay-blue bold with a LinkedIn contact line. Both banner\nsites now share one printWizardBanner() helper.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(setup): quote .env values so #-bearing OAuth tokens survive dotenv",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:44:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2886acf962283153529f8c3f640a4fdadd501021",
          "body": "Auto-capture only works when the RuName redirect points at the local callback\nserver (via an HTTPS tunnel). Defaulting to it lured users into a dead end: eBay\nredirects to the RuName's real accepted URL (a hosted app, the old redirect,\netc.), so localhost never receives the code and nothing is captu\n[…]\ns a public HTTPS tunnel)\" so its\nprerequisite is explicit. No behavior change; the switch handles every value\nregardless of order.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(setup): default to paste-code OAuth, demote auto-capture to advanced",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:26:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c827c369804cda9bcc48a306928e672da4f1a5c2",
          "body": "eBay rejects http:// and localhost as a RuName auth-accepted URL (HTTPS is\nmandatory, confirmed in eBay's OAuth docs and developer console). The shipped\nwizard note and .env.example wrongly framed an HTTPS tunnel as an optional\nfallback \"if it rejects this URL\"; in reality the loopback port must alw\n[…]\n registered on the RuName.\n\nBehavior unchanged — only on-screen guidance, the .env.example comment, and the\ngetCallbackPort JSDoc.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(setup): correct OAuth auto-capture guidance — eBay requires HTTPS",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:16:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5f67997c80e45ebff1f2fa0870b26c0f6fd2301",
          "body": "Replace the copy-paste step in `npm run setup` with a one-click\n\"Auto-capture\" option: a loopback server catches eBay's redirect,\nvalidates a CSRF `state`, and exchanges the code automatically — the\nmanual paste flow stays as a fallback.\n\n- Harden src/utils/oauth-helper.ts startCallbackServer: CSRF \n[…]\n\n- 9 new tests: code capture, URL-decoding, error redirect, state\n  match/mismatch, stray path, custom path, timeout, port-in-use.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(setup): add OAuth auto-capture via local callback server",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T14:04:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c0a937bde5df179b976519912a936e33f228b9b2",
          "body": "…s → 0)\n\nBring the dependency tree to a clean security baseline. `pnpm audit` now\nreports no known vulnerabilities, including the lone critical (Vitest UI\nserver arbitrary file read/exec) and all runtime advisories.\n\nStructural\n- Delete the stale, committed package-lock.json. It was unused (all CI u\n[…]\n 0 errors / 593 warnings · `npm test` 1019 passing\n· `npm run build` clean · `pnpm audit` 0 vulnerabilities · 322 tools unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): remediate all Dependabot advisories (61 unique / 117 alert…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T13:35:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e98eb3016f06641b8abd77da858a150e75f99e7",
          "body": "Add two optional, independent EBAY_MCP_* environment variables so the server\ncan run behind a proxy that injects eBay authentication. Both default off, so\nexisting behavior is unchanged.\n\n- EBAY_MCP_DISABLE_AUTH_HEADER=true enables credential-less \"proxy auth\" mode:\n  the client attaches no eBay aut\n[…]\ng/normalizing/validating); getBaseUrl and\ngetIdentityBaseUrl gain an optional override parameter. Adds 19 unit tests.\n\nCloses #122\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(config): support running behind an authenticating proxy (#122)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-15T12:59:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0979da1528594193f70655ed14e4d441162d5b49",
          "body": "The negative-keyword API methods built paths eBay does not expose\n(`/ad_campaign/{id}/negative_keyword*`, `/ad_group/{id}/negative_keyword*`),\nso all ~24 negative-keyword tools would 404. eBay's spec exposes a single\nflat resource: GET/POST `/negative_keyword`, GET/PUT `/negative_keyword/{id}`,\nand \n[…]\n Advertised tool count 332 → 322 (README, AGENTS.md, llms.txt).\n\nnpm run check: 0 errors; npm test: 997 passed; npm run build: OK.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(marketing): map negative-keyword tools to eBay's real flat API",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T15:46:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0b5d21e5d1a09f3f4f5be046f1a948401430f434",
          "body": "Several tools advertised an inputSchema that did not match what their\nhandler actually accepts, making them effectively uncallable by MCP\nclients (rawTool / array-paired tools self-validate, so the advertised\nschema is the only contract a client sees but it was never enforced or\nkept in sync).\n\nComm\n[…]\n 8 ad-group negative-keyword defs (handlers use only adGroupId).\n\nnpm run check: 0 errors. npm test: 1006/1006. npm run build: OK.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tools): align advertised tool schemas with their real contracts",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T15:14:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a05163f7249b70985e9e8c74a636d188eeaa353f",
          "body": "This commit refactors several API methods across the AccountApi, InventoryApi, and DisputeApi classes to utilize generic Record types for request bodies instead of specific schema types. This change enhances flexibility and reduces the need for strict type definitions, allowing for a broader range o\n[…]\ne`, and `uploadEvidenceFile` methods in DisputeApi to accept Record types for their request bodies.\n\nThese adjustments aim to simplify method signatures and improve the adaptability of the API client.",
          "is_bot": false,
          "headline": "refactor(api): update API method signatures to use generic Record types",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T14:23:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b345d7424c56faa6e8a59feec5abac8f9d8bbfb",
          "body": "This commit introduces a consistent error handling mechanism across multiple API classes by utilizing the `withApiError` utility. This change improves the robustness of error reporting for API calls, ensuring that users receive clear and descriptive error messages when requests fail.\n\nKey updates in\n[…]\ni`.\n- Removed redundant try-catch blocks, simplifying the code and enhancing readability.\n\nThese enhancements aim to provide better user feedback and streamline error management across the API client.",
          "is_bot": false,
          "headline": "feat(api): enhance error handling across various APIs",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T11:07:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "163eab7f4fb857b827ed9db3e0523835425bcaea",
          "body": "This commit introduces a check in the EbayApiClient to throw an error if the access token is missing, providing a clear message to the user about the required credentials. Additionally, it refactors imports across various files to streamline the codebase, including the reorganization of tool definit\n[…]\ns to use the new `types.ts`.\n- Consolidated tool definitions into a new `connector.ts` file for better organization.\n\nThese changes aim to enhance the robustness and maintainability of the API client.",
          "is_bot": false,
          "headline": "fix(api): add error handling for missing access token in EbayApiClient",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T10:25:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b73ff0b219a69db7450c19a3e0762aeb9182945",
          "body": "This commit replaces all instances of axios with a custom HTTP client built on the native fetch API. The new implementation centralizes error handling, request/response parsing, and timeout management, reducing dependencies and improving performance. Key changes include:\n\n- Introduced `httpRequest` \n[…]\nutility functions to use the new HTTP client.\n- Removed axios from dependencies in package.json and updated related tests.\n\nThis transition aims to streamline the codebase and enhance maintainability.",
          "is_bot": false,
          "headline": "refactor: migrate from axios to native fetch for HTTP requests",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T10:18:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59fc60da5529d7e5539c6d4abeca87ba15a75aed",
          "body": "The registry exposes 332 tools (getToolEntries().length) and the suite has\n1005 tests, but the docs still advertised 325 tools / 958 tests. Sync up\nREADME, package.json, llms.txt, and AGENTS.md.\n\nVerified against a spec diff with the public eBay OAS mirror (hendt/ebay-api):\nour committed specs are a\n[…]\n eBay reorganizations (location endpoints live under\nthe Inventory API, already covered) — i.e. no new eBay endpoints are missing.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: correct advertised tool/test counts to match reality",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T09:51:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e011771d09b7ace3ca71ab59042a3baafc9d9a1d",
          "body": "The sync scraper has been blind since the spec-URL manifest\n(docs/sell-apps/README.md) was deleted in 41c5d1a: downloadSpecs() returns\n0 and the run still prints \"100% coverage\", so eBay API changes have gone\nundetected for ~6 months.\n\n- Restore docs/sell-apps/README.md (Sell-scoped spec URLs); Buy \n[…]\nreturns HTTP 403 to scripted spec fetches, so a\nreal spec refresh still needs a browser/authenticated source — tracked\nseparately.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sync): restore spec manifest and stop silent stale-coverage reports",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T09:11:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ec8f5e2c12514a343cae8f134914405bc80c7741",
          "body": "Redistribute depth without losing content:\n- README 661 -> 245 lines: collapse disclaimer wall, drop manual TOC,\n  table-ize rate limits, fix broken BUG_REPORT.md link\n- AGENTS.md: real agent guide (entry points, validation commands,\n  module map, add-an-endpoint workflow, conventions)\n- CLAUDE.md: \n[…]\nort AGENTS.md to keep a single source of truth\n- Move Logging + Troubleshooting into docs/logging.md and\n  docs/troubleshooting.md\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: trim README to a landing page, build out AGENTS.md",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-06-02T08:52:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a7b04816e574561958d28da0a97aa4db4d872b9",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.10",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-05-23T10:53:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "414642c1a4e0bd5a8a4cd0b04f3bb8d453b8e30c",
          "body": "fix(packaging): include build/mcp/**/*.js in published tarball",
          "is_bot": false,
          "headline": "Merge pull request #121 from YosefHayim/dev",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-23T10:52:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78804b01c08ab4d87d6a298127e28dde8fe3e957",
          "body": "The architecture refactor in v1.8.9 introduced src/mcp/runtime.ts and\nsrc/mcp/http-transport.ts, but the files whitelist in package.json was\nnot updated. As a result, npm install -g ebay-mcp@1.8.9 produced\nERR_MODULE_NOT_FOUND for build/mcp/runtime.js at startup.\n\nFixes #120\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(packaging): include build/mcp/**/*.js in published tarball",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-23T10:51:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0549b754a829e792817782739c1e4bb041eae9ea",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.9",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-05-09T17:51:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "296fc960faffb4077beca5b06b4bd1abe5312549",
          "body": "Improve architecture and add JSDoc coverage",
          "is_bot": false,
          "headline": "Merge pull request #119 from YosefHayim/architecture-deepening",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-09T17:50:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8b8aceb9318699522a24d9ce913b5e166c63593",
          "body": null,
          "is_bot": false,
          "headline": "Improve architecture and add JSDoc coverage",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-09T17:41:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a22d1cc21e9329a27cae6f30eef38b8da0988ad",
          "body": "Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: improve package.json description and keywords",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-05-03T00:16:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bd8e085f5520fdb8900bb63eaffd1aaeb8db64c8",
          "body": "The npm Trusted Publisher configuration for ebay-mcp is bound to\nworkflow filename `publish.yml` (matching the OIDC `job_workflow_ref`\nclaim). Commit 24b17b3 (\"unify release and publish workflows\") moved\npublishing into release.yml, which broke the match — npm rejected the\nPUT with 404 once OIDC aut\n[…]\n user-controlled inputs.\n- release.yml: drops the inline `Publish to npm` and verify-npm steps;\n  pushing the tag now hands off to publish.yml.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: split publish into publish.yml to fix OIDC trusted publisher match",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T10:06:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e2048d999fa4ad1285ddd18c85bca4406ef4ac8",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.8",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-26T10:00:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5e501df6587278dcd181a122e8557c0c71ecc63",
          "body": "Node 22 ships with npm 10.x, and `npm install -g npm@latest` to upgrade\nin-place fails on the runner with `Cannot find module 'promise-retry'`\n(known npm CLI issue when upgrading 10→11 over an in-place install).\n\nNode 24 ships with npm 11.5+ pre-installed, so trusted publishing works\nwithout an upgr\n[…]\n publish.yml. The verify step is kept as a\nguard so future Node downgrades fail loudly instead of silently\nfalling back to anonymous publishes.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: bump runner to Node 24 for OIDC trusted publishing",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T09:59:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e0656b93c31e63825a4ad71bc58af3f2a9c6909e",
          "body": "Releases since 1.8.5 (2026-03-21) silently failed at the npm publish\nstep because commit 24b17b3 (\"ci: unify release and publish workflows\")\ndropped the `npm install -g npm@latest` step that the previous\npublish.yml had. Node 22 ships with npm 10.x, which signs the\nprovenance statement but cannot co\n[…]\nestores the working configuration used before\nthe unification, plus a guard that fails fast if the runner ever ends\nup with npm < 11.5.1 again.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: restore npm upgrade step for OIDC trusted publishing",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T09:57:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d73fe07fdb47b764d599575eb612063901dbff04",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.7",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-26T09:51:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "578743db172d04287837b44e9c47b551c8127396",
          "body": "Closes #113 and #114.\n\n- exchangeCodeForToken now writes EBAY_USER_ACCESS_TOKEN and\n  EBAY_USER_REFRESH_TOKEN to .env immediately after a successful\n  authorization-code exchange (#113). The misleading JSDoc and\n  comment claiming automatic persistence are corrected; persistence\n  is now actually pe\n[…]\nin tests/unit/auth/oauth.test.ts covering both\n  bugs, including the no-rotation case and the matching-env case to\n  guard against regressions.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(auth): persist OAuth tokens to .env on code exchange and refresh",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-26T09:24:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5685c32ab003b0d9d5305fabdd55d71df2be4f2",
          "body": "…tion and update dependencies\n\n- Removed grimoire-wizard dependency from package.json and pnpm-lock.yaml.\n- Introduced a new setup-wizard module utilizing prompts for interactive setup.\n- Updated README to reflect changes in the setup wizard branding and description.\n- Adjusted setup script to integrate the new wizard implementation.",
          "is_bot": false,
          "headline": "refactor: replace grimoire-wizard with custom setup-wizard implementa…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T16:18:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b4bcbbed354d679dd3ce5902a42e2ca381d0770",
          "body": "…time",
          "is_bot": false,
          "headline": "refactor(setup): replace grimoire-wizard with prompts-based setup run…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T15:14:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24b17b3f03b83673d66c5966acbe07daf4564853",
          "body": null,
          "is_bot": false,
          "headline": "ci: unify release and publish workflows",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T15:11:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca5cb551a863e7f1b53f6b7a751a505cc16662fd",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.6",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-23T14:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "182673717b5858fc47fe89e3e5104cae6fbbc571",
          "body": "refactor: continue dedup cleanup and enforce pre-push checks",
          "is_bot": false,
          "headline": "Merge pull request #110 from YosefHayim/cloud/main",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T14:39:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61ab3dfba7324bf2c052d3b03b2321d995baeaa3",
          "body": "…ck, test, and build steps",
          "is_bot": false,
          "headline": "chore(husky): update pre-push script to include installation, typeche…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T14:36:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff04ed390f6c0d47d738ba4fb3a642eda89dcb8e",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): sync pnpm lockfile for husky dependency",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T14:20:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43fbe1cb8d63b3761ce94640647e4144224b47a8",
          "body": null,
          "is_bot": false,
          "headline": "refactor: continue dedup cleanup and enforce pre-push checks",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-04-23T13:56:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26708a2398b2184450c2e9de7e094d61c443f244",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-22T09:12:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66427cfc4d61d8659e15c0b1d0731a8e7834771d",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-13T18:38:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79d1f967bda9be5bdb8b8208288ba539a7999de5",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-01T08:55:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f21b32e3fb00d08531a0ddb56ceb2693babc0927",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-22T08:25:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea38d20b590f704c36692d9f8208b57ff31ba51f",
          "body": null,
          "is_bot": true,
          "headline": "docs: update API status snapshot [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-21T16:53:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8cfd7da377d8dd14ecaf2297f4f06a055b17723",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.5",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-21T02:43:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "839bd793eb7fed890c00f07539eb72c3a4bef29d",
          "body": "…d_yarn-e78c89ff38\n\nchore(deps): bump fast-xml-parser from 5.4.2 to 5.5.6 in the npm_and_yarn group across 1 directory",
          "is_bot": false,
          "headline": "Merge pull request #95 from YosefHayim/dependabot/npm_and_yarn/npm_an…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-21T02:42:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f09148d510cd0b6ff78fba198e9aad80769a1a1",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser).\n\n\nUpdates `fast-xml-parser` from 5.4.2 to 5.5.6\n- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)\n- [Changelog](https://github.co\n[…]\nendencies:\n- dependency-name: fast-xml-parser\n  dependency-version: 5.5.6\n  dependency-type: direct:production\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump fast-xml-parser",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-18T02:00:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "819c8f7e689ac21d8e847ea8cf68fcb5c96c2a5b",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.4",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T15:36:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e885a1aedfb67bb6007444ffe6c5938016114ef",
          "body": "…d_yarn-926779f9d1\n\nchore(deps): bump the npm_and_yarn group across 1 directory with 2 updates",
          "is_bot": false,
          "headline": "Merge pull request #93 from YosefHayim/dependabot/npm_and_yarn/npm_an…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T15:35:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c28a91e6cdae33e959556795ee3193323ffa9d0",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.3",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T13:59:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e8fbe4afbcf1f95be1651aab48921cb70bd6a25",
          "body": null,
          "is_bot": false,
          "headline": "ci: skip CI on dependabot PRs",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:58:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25ee0f45fe9fe979671933b0a081e64df6a2c797",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T13:45:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db972ee001a7084e2757d8f311f3cda8cb7e7907",
          "body": "Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>",
          "is_bot": false,
          "headline": "fix: update pnpm-lock.yaml for grimoire-wizard dep (replaces prompts)",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:44:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "442f35d30b742cc09d7f2b7e0205d8003c953c47",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): v1.8.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-16T13:42:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "155f29d97b78333516cc8df74379dd78ff573b0f",
          "body": "…integration)\n\nCo-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>",
          "is_bot": false,
          "headline": "ci: add automated release workflow + bump to v1.8.0 (grimoire wizard …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:41:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "376f71dd950147a93a53d61573a7ec96612df497",
          "body": null,
          "is_bot": false,
          "headline": "feat: add 'Powered by grimoire-wizard' subtitle in eBay blue",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:37:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3be0e9c4ab98cddd85735639efc0b36b440b6f25",
          "body": "…l back to existingConfig when password left empty",
          "is_bot": false,
          "headline": "fix: spinner no longer spams inside clack frame; credential hooks fal…",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:32:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9c035243c2c8303ce25c78c948266f011606fde",
          "body": "…mode, completion summary",
          "is_bot": false,
          "headline": "fix: restore full original UI — logo, welcome screen, showBox, quick …",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:22:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fad4ffcaab48246b80b5ecffe3a3800af1ec69d",
          "body": "…dates\n\nBumps the npm_and_yarn group with 2 updates in the / directory: [flatted](https://github.com/WebReflection/flatted) and [hono](https://github.com/honojs/hono).\n\n\nUpdates `flatted` from 3.3.4 to 3.4.1\n- [Commits](https://github.com/WebReflection/flatted/compare/v3.3.4...v3.4.1)\n\nUpdates `hono\n[…]\nependency-group: npm_and_yarn\n- dependency-name: hono\n  dependency-version: 4.12.8\n  dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the npm_and_yarn group across 1 directory with 2 up…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-16T13:11:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "781cc467497b75f6297148e48e66d19058d27631",
          "body": "- Replace prompts library with grimoire-wizard for the full setup flow\n- Wizard uses ClackRenderer for polished framed terminal UI\n- eBay brand theme (red/blue/yellow/green) via grimoire theme tokens\n- All 6 steps mapped: environment, marketplace, language, credentials, OAuth, MCP clients\n- OAuth fl\n[…]\ned\n- asyncValidate enforces v^1.1# format for refresh tokens\n- Reduces setup.ts from 1858 to ~560 lines while preserving all behavior\n- README: grimoire-wizard badge in header and setup wizard section",
          "is_bot": false,
          "headline": "feat: replace setup wizard with grimoire-wizard v0.6.0",
          "author_name": "YosefHayim",
          "author_login": "YosefHayim",
          "committed_at": "2026-03-16T13:09:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 51,
      "commits_last_year": 697,
      "latest_release_at": "2026-07-19T13:07:45Z",
      "latest_release_tag": "v1.14.1",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 32,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 3.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "ebay-mcp",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "mcp",
            "ebay",
            "ebay-api",
            "model-context-protocol",
            "ai-tools",
            "ai",
            "llm",
            "documentation",
            "api",
            "server",
            "backend"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/ebay-mcp",
          "is_deprecated": false,
          "latest_version": "1.14.1",
          "repository_url": "https://github.com/YosefHayim/ebay-mcp",
          "versions_count": 34,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2316,
          "first_published_at": "2025-11-16T23:59:14.059000Z",
          "latest_published_at": "2026-07-19T13:10:06.025000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 48,
      "stars": 105,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2025-11-12",
            "count": 1
          },
          {
            "date": "2025-11-14",
            "count": 1
          },
          {
            "date": "2025-12-05",
            "count": 1
          },
          {
            "date": "2025-12-07",
            "count": 1
          },
          {
            "date": "2025-12-28",
            "count": 1
          },
          {
            "date": "2025-12-31",
            "count": 1
          },
          {
            "date": "2026-01-23",
            "count": 1
          },
          {
            "date": "2026-01-28",
            "count": 1
          },
          {
            "date": "2026-01-30",
            "count": 1
          },
          {
            "date": "2026-02-05",
            "count": 1
          },
          {
            "date": "2026-02-14",
            "count": 1
          },
          {
            "date": "2026-02-16",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-02-18",
            "count": 1
          },
          {
            "date": "2026-02-22",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 2
          },
          {
            "date": "2026-03-24",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 2
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-04-13",
            "count": 1
          },
          {
            "date": "2026-04-15",
            "count": 1
          },
          {
            "date": "2026-04-17",
            "count": 1
          },
          {
            "date": "2026-04-20",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-05-10",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          },
          {
            "date": "2026-05-15",
            "count": 1
          },
          {
            "date": "2026-05-17",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-06-10",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 1
          },
          {
            "date": "2026-06-27",
            "count": 1
          },
          {
            "date": "2026-07-05",
            "count": 2
          },
          {
            "date": "2026-07-09",
            "count": 1
          },
          {
            "date": "2026-07-10",
            "count": 1
          },
          {
            "date": "2026-07-12",
            "count": 1
          },
          {
            "date": "2026-07-13",
            "count": 1
          },
          {
            "date": "2026-07-15",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 2
          },
          {
            "date": "2026-07-25",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 47,
        "total_forks": 48
      },
      "star_history": null,
      "open_issues_and_prs": 2
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json",
        "ui/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 507840,
      "source_files_sampled": 245,
      "oversized_source_files": 8,
      "agent_instruction_files": [
        ".github/copilot-instructions.md",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 12152
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 194,
        "malicious_count": 0,
        "assessed_package": "npm:ebay-mcp@1.14.1",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/ext-apps",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.7.4"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.29.0"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.6.2"
        },
        {
          "name": "cors",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.6"
        },
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "dotenv-stringify",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.1"
        },
        {
          "name": "effect",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.21.4"
        },
        {
          "name": "express",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        },
        {
          "name": "fast-xml-builder",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.2.0"
        },
        {
          "name": "fast-xml-parser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.9.0"
        },
        {
          "name": "helmet",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.2.0"
        },
        {
          "name": "jose",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.3"
        },
        {
          "name": "prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.2"
        },
        {
          "name": "update-notifier",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.3.1"
        },
        {
          "name": "winston",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.19.0"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        },
        {
          "name": "zod-to-json-schema",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.2"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@modelcontextprotocol/ext-apps",
            "direct": true,
            "version": "1.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": true,
            "version": "5.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "cors",
            "direct": true,
            "version": "2.8.6",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "17.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv-stringify",
            "direct": true,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "effect",
            "direct": true,
            "version": "3.21.4",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": true,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-builder",
            "direct": true,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-parser",
            "direct": true,
            "version": "5.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "helmet",
            "direct": true,
            "version": "8.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": true,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "prompts",
            "direct": true,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "update-notifier",
            "direct": true,
            "version": "7.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "winston",
            "direct": true,
            "version": "3.19.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "3.25.76",
            "ecosystem": "npm"
          },
          {
            "name": "zod-to-json-schema",
            "direct": true,
            "version": "3.25.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/biome",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-darwin-arm64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-darwin-x64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-arm64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-arm64-musl",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-x64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-linux-x64-musl",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-win32-arm64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/cli-win32-x64",
            "direct": false,
            "version": "2.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "@colors/colors",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@dabh/diagnostics",
            "direct": false,
            "version": "2.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@mswjs/interceptors",
            "direct": false,
            "version": "0.41.9",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@nodable/entities",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.scandir",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.stat",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.walk",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/deferred-promise",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/logger",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/until",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@paralleldrive/cuid2",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@pnpm/config.env-replace",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@pnpm/network.ca-file",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@pnpm/npm-conf",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@polka/url",
            "direct": false,
            "version": "1.0.0-next.29",
            "ecosystem": "npm"
          },
          {
            "name": "@redocly/ajv",
            "direct": false,
            "version": "8.11.2",
            "ecosystem": "npm"
          },
          {
            "name": "@redocly/config",
            "direct": false,
            "version": "0.22.0",
            "ecosystem": "npm"
          },
          {
            "name": "@redocly/openapi-core",
            "direct": false,
            "version": "1.34.15",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm-eabi",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-x64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-x64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-gnueabihf",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-musleabihf",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-s390x-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-musl",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openbsd-x64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openharmony-arm64",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-arm64-msvc",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-ia32-msvc",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-gnu",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-msvc",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "@so-ric/colorspace",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@standard-schema/spec",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/body-parser",
            "direct": false,
            "version": "1.19.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/configstore",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/connect",
            "direct": false,
            "version": "3.4.38",
            "ecosystem": "npm"
          },
          {
            "name": "@types/cookiejar",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/cors",
            "direct": false,
            "version": "2.8.19",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/express",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/express-serve-static-core",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/http-errors",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/methods",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/prompts",
            "direct": false,
            "version": "2.4.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/qs",
            "direct": false,
            "version": "6.15.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/range-parser",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "19.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "19.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/serve-static",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/superagent",
            "direct": false,
            "version": "8.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/supertest",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/triple-beam",
            "direct": false,
            "version": "1.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/update-notifier",
            "direct": false,
            "version": "6.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/ui",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "agent-base",
            "direct": false,
            "version": "7.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv-formats",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-align",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-colors",
            "direct": false,
            "version": "4.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "anymatch",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "anynum",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-union",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "asap",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ast-v8-to-istanbul",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "async",
            "direct": false,
            "version": "3.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "asynckit",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "atomically",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "binary-extensions",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "boxen",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "boxen",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "braces",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "change-case",
            "direct": false,
            "version": "5.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "chokidar",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-boxes",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "color",
            "direct": false,
            "version": "5.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "color-string",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "colorette",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "combined-stream",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "9.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "component-emitter",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "config-chain",
            "direct": false,
            "version": "1.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "configstore",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookiejar",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "csstype",
            "direct": false,
            "version": "3.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "deep-extend",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "delayed-stream",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dezalgo",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "dir-glob",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "dot-prop",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "enabled",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-set-tostringtag",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escape-goat",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource-parser",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "express-rate-limit",
            "direct": false,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "3.23.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-glob",
            "direct": false,
            "version": "3.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-safe-stringify",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "fastq",
            "direct": false,
            "version": "1.20.1",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fecha",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "fflate",
            "direct": false,
            "version": "0.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "fill-range",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "fn.name",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "form-data",
            "direct": false,
            "version": "4.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "formidable",
            "direct": false,
            "version": "3.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-tsconfig",
            "direct": false,
            "version": "4.14.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "global-directory",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "globby",
            "direct": false,
            "version": "11.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-tostringtag",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.25",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "https-proxy-agent",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "husky",
            "direct": false,
            "version": "9.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "index-to-position",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "ip-address",
            "direct": false,
            "version": "10.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-binary-path",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-in-ci",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-installed-globally",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-node-process",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-npm",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-number",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-inside",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-promise",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-unsafe",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-levenshtein",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-typed",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json-stringify-safe",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "kleur",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "kuler",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ky",
            "direct": false,
            "version": "1.14.3",
            "ecosystem": "npm"
          },
          {
            "name": "latest-version",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "logform",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "magicast",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge2",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "methods",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "micromatch",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "mime",
            "direct": false,
            "version": "2.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.52.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.54.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "2.1.35",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "5.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimist",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "mrmime",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mylas",
            "direct": false,
            "version": "2.1.14",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.12",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "nock",
            "direct": false,
            "version": "14.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "obug",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "one-time",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "openapi-typescript",
            "direct": false,
            "version": "7.13.0",
            "ecosystem": "npm"
          },
          {
            "name": "outvariant",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "package-json",
            "direct": false,
            "version": "10.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "path-expression-matcher",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "path-type",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pkce-challenge",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "plimit-lit",
            "direct": false,
            "version": "1.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "pluralize",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.15",
            "ecosystem": "npm"
          },
          {
            "name": "propagate",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "proto-list",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pupa",
            "direct": false,
            "version": "3.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.2",
            "ecosystem": "npm"
          },
          {
            "name": "queue-lit",
            "direct": false,
            "version": "1.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "queue-microtask",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rc",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "readable-stream",
            "direct": false,
            "version": "3.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "readdirp",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "registry-auth-token",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "registry-url",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-pkg-maps",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "reusify",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "rollup",
            "direct": false,
            "version": "4.62.0",
            "ecosystem": "npm"
          },
          {
            "name": "router",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "run-parallel",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-buffer",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "safe-stable-stringify",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "sirv",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "sisteransi",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "slash",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "stack-trace",
            "direct": false,
            "version": "0.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "strict-event-emitter",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "string_decoder",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strnum",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "stubborn-fs",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "stubborn-utils",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "superagent",
            "direct": false,
            "version": "10.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "supertest",
            "direct": false,
            "version": "7.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "10.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "text-hex",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "to-regex-range",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "totalist",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "triple-beam",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "1.8.17",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.22.4",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "2.19.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "4.41.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.24.6",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js-replace",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "util-deprecate",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "7.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "vite-plugin-singlefile",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "when-exit",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "widest-line",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "widest-line",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "winston-transport",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "xdg-basedir",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "xml-naming",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml-ast-parser",
            "direct": false,
            "version": "0.0.43",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 442,
        "direct_count": 17,
        "indirect_count": 425
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 85,
        "open_issues": 1,
        "closed_ratio": 0.941,
        "closed_issues": 16,
        "closed_unmerged_prs": 39
      },
      "bus_factor": 1,
      "bot_contributors": 3,
      "top_contributors": [
        {
          "type": "User",
          "login": "YosefHayim",
          "commits": 536,
          "avatar_url": "https://avatars.githubusercontent.com/u/179159376?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 50,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        },
        {
          "type": "User",
          "login": "longrackslabs",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/1175466?v=4"
        },
        {
          "type": "User",
          "login": "nedlir",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/66902031?v=4"
        },
        {
          "type": "User",
          "login": "jdbhartley",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/24490599?v=4"
        },
        {
          "type": "User",
          "login": "lwsinclair",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/2829939?v=4"
        },
        {
          "type": "User",
          "login": "michelbragaguimaraes",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/8365866?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.892
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "api-sync.yml",
        "biome.yml",
        "build.yml",
        "ci.yml",
        "e2e.yml",
        "publish.yml",
        "release.yml",
        "report-failure.yml",
        "test.yml",
        "typecheck.yml",
        "weekly-cleanup.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "10 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "0a23f966e50695e7bb1087ee4e71ae9a03a85da5",
        "ran_at": "2026-07-25T10:39:56Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T05:25:19Z",
      "oldest_open_prs": [
        {
          "number": 141,
          "created_at": "2026-07-20T19:40:26Z",
          "last_comment_at": "2026-07-20T19:40:52Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-07-04T01:25:04Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 142,
          "created_at": "2026-07-22T10:27:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/YosefHayim/ebay-mcp",
    "host": "github.com",
    "name": "ebay-mcp",
    "owner": "YosefHayim"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 70,
      "inputs": {
        "security": 56,
        "vitality": 92,
        "community": 65,
        "governance": 54,
        "engineering": 82
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 92,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "commits_last_year": 697,
              "human_commit_share": 0.73,
              "days_since_last_push": 5,
              "active_weeks_last_year": 32
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "32/52 weeks with commits",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 32
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "697 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 697
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 51,
              "latest_release_tag": "v1.14.1",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 3.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "51 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 5,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 5 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 65,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "forks": 48,
              "stars": 105,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "105 stars",
                "points": 32.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 105
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "48 forks",
                "points": 13.9,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 48
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "ebay-mcp"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2316
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,316 downloads/month across npm",
                "points": 44.9,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2316,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 24,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.892
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 89% of commits",
                "points": 2.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 89
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "merged_prs": 85,
              "open_issues": 1,
              "closed_issues": 16,
              "issue_closed_ratio": 0.941,
              "closed_unmerged_prs": 39
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "94% of issues closed",
                "points": 44,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 94
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "85/124 decided PRs merged",
                "points": 26.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 85,
                      "decided": 124
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "followers": 16,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "YosefHayim",
              "public_repos": 12,
              "account_age_days": 701
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "16 followers of YosefHayim",
                "points": 8.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 16,
                      "login": "YosefHayim"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "12 public repos, account ~1 yr old",
                "points": 11.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 12
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "ebay-mcp"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 82,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "11 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "chatgpt",
                "claude",
                "ebay",
                "mcp-server",
                "typescript",
                "api-wrapper",
                "ebay-api",
                "mcp",
                "model-context-protocol",
                "npm",
                "oauth2",
                "ai-agents",
                "cursor",
                "local-first",
                "nodejs",
                "tool-gating"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/ebay-mcp",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/ebay-mcp",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "16 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "10 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:ebay-mcp@1.14.1 runtime dependency closure — what installing the published package pulls in — 194 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:ebay-mcp@1.14.1",
                  "assessed": 194
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 194,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 194,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 76,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 0.986,
              "agent_instruction_files": [
                ".github/copilot-instructions.md",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 12152
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".github/copilot-instructions.md, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".github/copilot-instructions.md, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "72 of 73 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 72,
                      "sampled": 73
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json",
                "ui/tsconfig.json"
              ],
              "agent_commit_share": 0.29,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json, ui/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json, ui/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "29 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 29,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 507840,
              "source_files_sampled": 245,
              "oversized_source_files": 8
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "8/245 source files over 60KB",
                "points": 53.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 245,
                      "oversized": 8
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T10:40:08.372521Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/y/YosefHayim/ebay-mcp.svg",
  "full_name": "YosefHayim/ebay-mcp",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.