Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-27 14:58 UTC

agents-inc / cli

An agent composition framework that builds stacks and compiles specialized subagents for Claude Code

TypeScriptMIT★ 5 stars⑂ 0 forkssince Jan 2026View on GitHub ↗

agents-inc/cli holds a health index of 45 out of 100, placing it in the At risk band. It scores highest on AI Readiness (70/100) and lowest on Community & Adoption (36/100). It was last updated 3 days ago. A single contributor accounts for most of its recent work.

45
overall / 100
At risk

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

45
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

agents-incOrganization
1 follower5 public repossince Jan 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

45At risk · 22% of overall
How it's scored
36/36Push recency — last push 3 days ago
11.1/36Commit cadence — 16/52 weeks with commits
18/18Commit volume — 1,220 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year1,220
human_commit_share1
days_since_last_push3
active_weeks_last_year16
How it's scored
0/27Ships releases — no releases published
0/36Release recency — no releases
0/27Release cadence — no releases
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count0
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

36At risk · 18% of overall
How it's scored
9.8/60Stars — 5 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars5
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
44.8/80Monthly downloads — 2,275 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@agents-inc/cli
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,275
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

53Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
2.7/13.5Contributor breadth — 2 contributors
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.999
How it's scored
0/46.8Issue resolution — no issues or no data
38.2/38.3PR acceptance — 3/3 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs3
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
2.2/25Owner reach — 1 followers of agents-inc
6.8/25Track record — 5 public repos, account ~0 yr old
Inputs used
followers1
owner_typeOrganization
is_verified
owner_loginagents-inc
public_repos5
account_age_days201
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 6 days ago
20/20Version history — 118 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@agents-inc/cli
ecosystemsnpm
any_deprecatedno
min_days_since_publish6

Engineering Quality

Are baseline engineering and documentation practices in place?

52Moderate · 20% of overall
How it's scored
0/24CI workflows
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_cino
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.

Documentation

85Excellent
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 20 topics
10/10Wiki
Inputs used
topicsagent-composition, agent-framework, agent-stack, agentic-ai, ai-agents, ai-tools, anthropic, claude, claude-code, claude-code-plugin, claude-skills, cli, developer-tools, skill-stacks, subagents, typescript, agent-compiler, agents-as-code, claude-code-framework, composable-agents
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

37At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — no data
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
0/10Dangerous-Workflow — no data
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — no data
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — no data
0/7.5Vulnerabilities — 61 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate2.8
Excluded from scoring (no data or not applicable): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
6.2/25Indirect dependencies free of known advisories — 2 affected: brace-expansion 2.1.2 (high 7.5), tar 6.2.1 (high 8.8)
32.8/40No advisories left outstanding — 1 advisory-carrying package(s) unaddressed past 90 days; oldest published 191 days ago
Inputs used
sourceosv
advisories13
affected_packages2
assessed_packages227
unassessed_packages0
affected_by_severityhigh 2
direct_affected_packages0
Matched the npm:@agents-inc/cli@0.144.1 runtime dependency closure — what installing the published package pulls in — 227 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

70Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md, src/cli/lib/__tests__/fixtures/stacks/default/CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 97 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.97
agent_instruction_filesCLAUDE.md, src/cli/lib/__tests__/fixtures/stacks/default/CLAUDE.md
agent_instruction_max_bytes14,772
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking — e2e/tsconfig.json, tsconfig.json
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — no data
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configse2e/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.4/55Manageable file sizes — 6/521 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes163,822
source_files_sampled521
oversized_source_files6

Key facts

5GitHub stars
2contributors
1,220commits, last 12 months
3days since last push
0releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 2.8 / 10
2.8aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-27 14:58 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/aCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
n/aDangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
n/aPinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
n/aToken-PermissionsNo tokens found
0Vulnerabilities61 existing vulnerabilities detected
Direct dependencies 20
RegistryPackageVersion constraintManifest
npm@inkjs/ui^2.0.0package.json
npm@oclif/core^4.0.0package.json
npm@oclif/plugin-autocomplete^3.0.0package.json
npm@oclif/plugin-help^6.0.0package.json
npm@oclif/plugin-not-found^3.0.0package.json
npm@oclif/plugin-warn-if-update-available^3.0.0package.json
npm@oclif/table^0.5.0package.json
npmexeca^9.0.0package.json
npmfast-glob^3.3.0package.json
npmfs-extra^11.2.0package.json
npmgiget^1.2.0package.json
npmgray-matter^4.0.3package.json
npmink^5.0.0package.json
npmjiti2.4.2package.json
npmliquidjs^10.24.0package.json
npmreact^18.2.0package.json
npmremeda^2.33.6package.json
npmyaml^2.8.2package.json
npmzod^4.3.6package.json
npmzustand^5.0.0package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 2

Installing npm:@agents-inc/cli@0.144.1 pulls in 227 packages, direct and transitive: 2 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
brace-expansion2.1.2indirecthigh15.0.8
tar6.2.1indirecthigh127.5.21

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "agent-composition",
        "agent-framework",
        "agent-stack",
        "agentic-ai",
        "ai-agents",
        "ai-tools",
        "anthropic",
        "claude",
        "claude-code",
        "claude-code-plugin",
        "claude-skills",
        "cli",
        "developer-tools",
        "skill-stacks",
        "subagents",
        "typescript",
        "agent-compiler",
        "agents-as-code",
        "claude-code-framework",
        "composable-agents"
      ],
      "is_fork": false,
      "size_kb": 17371,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Liquid": 21753,
        "JavaScript": 608,
        "TypeScript": 5257224
      },
      "pushed_at": "2026-07-23T21:04:00Z",
      "created_at": "2026-01-28T21:42:32Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T21:04:13Z",
      "description": "An agent composition framework that builds stacks and compiles specialized subagents for Claude Code",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "agents-inc",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/253355797?v=4",
      "created_at": "2026-01-06T19:12:27Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 201
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "d01b95aef96ca486468c0bcc20d53b605871f552",
          "body": "Two-pass codex-keeper validation across all 41 reference docs plus the\ndocumentation map, correcting ~3 months of drift since the 2026-04-21\nvalidation (product 0.141 -> 0.144.1).\n\n- Correct 227 stale claims (paths, symbol names, behaviour) against current code\n- Document new source-of-truth modules\n[…]\nncile DOCUMENTATION_MAP: file counts (203->181 prod, 140->174 e2e),\n  version, dates, staleness dashboard; 5-invariant self-consistency audit passes\n- Fix one broken related-doc link in wizard-flow.md",
          "is_bot": false,
          "headline": "docs: refresh AI reference documentation to match v0.144.1",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-23T20:59:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80c92de513634a9dd3200f864cb73d27d54990ee",
          "body": "…3–0.144 fixes",
          "is_bot": false,
          "headline": "chore(release): 0.144.1 — E2E coverage and documentation for the 0.14…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:24:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6a601ed7ee6c42f0c0c4dc4a8848af4a6b8fce8",
          "body": "… wait helper\n\nUpdates the standards and reference docs that named waitForStableRender, and\nremoves documentation of methods deleted in this pass. Each doc that explains\nthe keypress guard now carries its precondition rather than just the new\nidentifier — a rename alone would have preserved the trap.\n\nCLAUDE.md's keypress rule is updated the same way. Consolidates the parked\nowner decisions at the top of the refactor ledger, deliberately without\ncheckboxes so the loop rule cannot pick them up.",
          "is_bot": false,
          "headline": "docs(standards): update e2e standards and conventions for the renamed…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:23:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18a073621abb3284c7ce36db69ca01ab24405a04",
          "body": "…eview passes\n\nPoint-in-time records from this work, including several that correct the\nrecord on their own subject matter: the aliasing in the shared-constant finding\npredated the refactor that was blamed for it; a structural config load cannot\nreplace the raw-text stack extractors because it erases the writer's\nbare-string compaction; and waitForStableRender is a wizard-footer sentinel\nrather than a generic primitive.",
          "is_bot": false,
          "headline": "docs(findings): record the findings from the refactor, bug-hunt and r…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:23:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "048d25e5d6661843f3cfae7b4eb15a4a3a2b6923",
          "body": "One spec per defect, each written to fail against the pre-fix code for the right\nreason before the fix landed. Covers the global-skill lock on the f hotkey,\ndeselect/re-select scope preservation, generated-union narrowing (via a tsc\nprobe), marketplace naming for local sources, the global config's m\n[…]\nl handling, and the doctor blind spots.\n\nEach spec asserts config AND filesystem state rather than exit codes: a wizard\ncan exit 0 having silently refused the mutation, so an exit code proves nothing.",
          "is_bot": false,
          "headline": "test(e2e): cover the fixes shipped in 0.143.0 and 0.144.0",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:22:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33e0e8082d68d86a607513963d58691b8f089d7b",
          "body": "Mechanical sweep: replaces the finalize/abort rituals, inline terminal geometry,\nduplicated timeout expressions, hardcoded step text and inline path joins with\nthe shared helpers and constants. Retires local parser helpers in favour of\nstructural config loads, and replaces two specs' raw Interactive\n[…]\nan\nthe behaviour under test — those are re-pinned more strictly: snapshot the\nproject config after setup and assert byte-identity after the guarded edit,\nrather than merely asserting a file is absent.",
          "is_bot": false,
          "headline": "test(e2e): adopt the shared infra across the existing specs",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:22:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db0adc2a61475d237b1611ad7104d86bafb52c3d",
          "body": "Extracts the rituals repeated across the suite into shared infra: finishWizard\nand abortAndDestroy for wizard teardown, readSkillBadgesViaEdit, a TestEnvironment\ntype, completeWithLocalSources, asserting config readers, and path helpers.\nReplaces inline literals with TERMINAL_SIZE, TIMEOUTS.SETUP_DU\n[…]\nplace, so xterm's processed\nbuffer can lose it; raw output is append-only and is now the surface asserted\nagainst, anchored to a pre-action cursor so a stale earlier toast cannot produce\na false pass.",
          "is_bot": false,
          "headline": "test(e2e): share page objects, fixtures and constants across the suite",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:22:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "396c9ed9e22c06f53d8ed56233819040677c9ed8",
          "body": "…ns on dropped skills (D-253, D-254)",
          "is_bot": false,
          "headline": "chore(release): 0.144.0 — doctor detects broken installs; compile war…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c32cc3c14cc04ea988c77da416e4cc730b225b7d",
          "body": "Applies the expressive-TypeScript pass to uninstall, update, validate, eject,\nsearch, build and new: shared constants, asserting lookups and extracted named\nhelpers in place of inline logic. Behaviour-preserving.",
          "is_bot": false,
          "headline": "refactor(commands): adopt shared helpers across the remaining commands",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:19:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8d25ad6dd40d6bbefaa24716c6381bef5a32dd8",
          "body": "A stack-referenced skill absent from disk was dropped from the recompiled agent\nwith only a verbose-level log, so the default output claimed a clean recompile\nof an agent that no longer matched config.ts. The drop is now a visible\nwarning. (D-254)",
          "is_bot": false,
          "headline": "fix(compile): warn when a configured skill is missing from disk",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:19:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be96864a18c04516f8b4e2ccad9ef76048fa9dbd",
          "body": "…cope-aware\n\ndoctor reported a clean bill of health after a plugin-mode skill was\nuninstalled: config.ts still declared it, enabledPlugins was empty, and the\noutput was byte-identical to the healthy state. Eject mode warned correctly in\nthe same situation, so plugin-sourced skills had no verificatio\n[…]\nhas no\nskill-installation path and silently drops the skill instead — following the\nadvice made the problem worse. It now states the diagnosis without prescribing a\ncommand that cannot fix it. (D-253)",
          "is_bot": false,
          "headline": "fix(doctor): detect uninstalled plugin skills and make scope checks s…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:19:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac801c33825305dc83ba6c07c0831e92c8501587",
          "body": "…integrity fixes (D-218, D-242, D-243, D-244, D-245, D-246, D-247, D-248, D-249, D-250, D-251, D-252)",
          "is_bot": false,
          "headline": "chore(release): 0.143.0 — install, config-generation and wizard data-…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:16:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d460d71311180b282a4663d6b6ca0ccd6062516",
          "body": "Replaces inline test data with factories, retires local parser helpers in favour\nof structural loads, and adds coverage for the fixes above.",
          "is_bot": false,
          "headline": "test(unit): adopt shared factories, helpers and asserting config loaders",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:14:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15a2cb9caccaf2f1ca6c2202a0e84f447ca2f4b3",
          "body": "…tup from a bare edit\n\nA project-context edit performed the disk and plugin-registry work for\nglobal-scoped skills but never recorded it: executeMigration honours each\nskill's own scope, while writeConfigAndCompile passed authoritativeScope\n\"owned\", so mergeConfigs preserved the old entries verbatim\n[…]\noject paths for skills and agents written to the\nhome directory, and printed skill display titles where the directories are ids.\nIt now reports per scope, with names that match the filesystem. (D-251)",
          "is_bot": false,
          "headline": "fix(edit,init): record global source switches and distinguish init se…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:14:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c15c6b5290349571a93946640ecade4fa839e993",
          "body": "…eserve scope on re-select\n\ntoggleTechnology (spacebar) guards globally-installed skills during a\nproject-scope edit; toggleFilterIncompatible (the `f` hotkey) did not. Pressing\n`f` removed the skill with no toast, and the resulting removal deleted the\nskill directory from the user's home while the \n[…]\nt in the snapshot is now a restore. (D-243)\n\nThe sources grid rendered marketplace owner.name — a person — where a source\nlabel belongs; the field is removed and the grid uses the source name. (D-247)",
          "is_bot": false,
          "headline": "fix(wizard): honour the global-skill lock on the filter hotkey and pr…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:13:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90bcffe35dcf011aa08d2aa7d6a641191d2ccbc8",
          "body": "…arketplace into global config\n\nTwo data-integrity fixes in the install layer.\n\nexecuteMigration's eject->plugin branch deleted the ejected skill copies before\nchecking that a marketplace existed, then demoted the failure to a warning and\nexited 0 — so config.ts claimed a plugin source for a skill w\n[…]\not silently skipped every\nplugin before deleting the config that recorded them. Both fields now carry\nthrough, fill-only, so an existing global value is never repointed from a\nproject context. (D-246)",
          "is_bot": false,
          "headline": "fix(install): hard-error before destructive plugin migration; carry m…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:13:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "551444e71bb9c3e7f29b1159d49a2166e2186250",
          "body": "loadFromLocal never read the source's .claude-plugin/marketplace.json, so\nconfig.ts recorded source: \"agents-inc\" for every skill while the plugin\nregistry, settings.json and the install output all named the real marketplace.\nloadFromRemote already read it; that asymmetry was the defect. Local-direc\n[…]\nce producing two identically-named entries in the\nsources grid, and guards local skill discovery so one malformed metadata.yaml\nreports against that skill instead of failing the whole command. (D-245)",
          "is_bot": false,
          "headline": "fix(loading): resolve marketplace name from local source manifests",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:13:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1af69b5f435b7d6eeacf4ec5d017eaa4fb9f7b14",
          "body": "An install that placed every skill at project scope left the global config\nempty, and the generated config-types.ts then collapsed SkillId, AgentName,\nDomain and Category to `string` — silently disabling all type checking in the\nuser's config.ts. A tsc probe with bogus literals for all four aliases \n[…]\niour\ngenerateBlankGlobalConfigTypesSource already had for the identical state.\n\nAlso consolidates the configuration layer: scope predicates, config merging and\nthe config/config-types writers. (D-244)",
          "is_bot": false,
          "headline": "fix(config): emit never for empty generated unions instead of string",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:13:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf4d357189cf11b7046276932ea210bdcf3dfe91",
          "body": "Collapses duplicated type aliases into Pick/Partial/intersection forms, adds\ntype guards for runtime narrowing, and extracts terminal and YAML-schema\nhelpers out of ad-hoc call sites.",
          "is_bot": false,
          "headline": "refactor(types): consolidate type definitions and shared utilities",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-20T21:13:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3cba36f1c62566685c2ba78c6b41e56b274a2176",
          "body": "Fixes the build-step `s` scope-toggle race (focusedSkillId now seeded\nsynchronously at hydrate and every domain transition) and caps the E2E\nsuite at 16 workers. No task tickets — root-caused from the dual-scope\nE2E flake investigation, recorded in the two findings shipped with this\nrelease.\n\nGates: wizard-store suite 218/218 green; release tree builds; full unit\nsuite validated green on the identical tree pre-0.142.4.",
          "is_bot": false,
          "headline": "chore(release): 0.142.5 — wizard focus-seed fix + E2E stability",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-19T16:01:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c18575e0ab70317524a04b3bb2c16030dd3f65f9",
          "body": "…tion\n\nPTY-driven wizard tests are load-sensitive at full parallelism (one worker\nper core, 21+ on dev machines): dropped keystrokes and slow installs\nproduce flaky failures that never reproduce solo. Cap maxWorkers at 16 —\nwall-clock cost is ~nil (309s vs 295s uncapped) since the suite is not\nparal\n[…]\nypress retry was tried and reverted\n(toggles revert on re-press when renders lag past the verification\nwindow), and the deferred footer-gating fix as the remaining path to a\nfully deterministic suite.",
          "is_bot": false,
          "headline": "test(e2e): cap suite at 16 workers; record dual-scope flake investiga…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-19T16:01:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "06458270c1d8db74eebe0d1cb1eed211c442ea11",
          "body": "…transitions\n\nThe build-step grid's focusedSkillId was seeded by a fire-once post-mount\nuseEffect in CategoryGrid, while the `s` scope-toggle hotkey in wizard.tsx\nreads it synchronously. A keystroke arriving between first paint and the\neffect flush acted on stale/null state — under parallel E2E load\n[…]\nvering the seed at hydrate, build entry, domain\nadvance/retreat, and the no-focusable-skill null case, plus the\nREACT_HONO_WEB_API_DOMAINS_MATRIX fixture with complete per-domain\ncategory definitions.",
          "is_bot": false,
          "headline": "fix(wizard): seed focusedSkillId synchronously at hydrate and domain …",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-19T16:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49b9b1a0a334fecd04768c1f5c24122a5de379f8",
          "body": "…y hardening\n\nExpressive-TypeScript refactor of the production codebase (~165 files) and\nthe full test suite (~250 files), plus a type-safety hardening pass. No\ntask tickets — Passes 6-7 of the expressive-TS effort.\n\nHighlights:\n- production refactor: orchestrators, guard clauses, extracted modules\n\n[…]\n replace hand-rolled parsers;\n  shared E2E drivers; deterministic E2E config (16 workers, suite retry)\n\nGates: tsc baseline-clean (both tsconfigs); full unit suite 5101/5101\ngreen on the release tree.",
          "is_bot": false,
          "headline": "chore(release): 0.142.4 — expressive-TypeScript refactor + type-safet…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-19T15:49:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b355c2e682681fb2895ca113417fdbda16519b10",
          "body": "Full-suite survey and refactor (252 spec files + 68 infra files) against\nthe expressive-TypeScript standard and CLAUDE.md test rules:\n\n- structural config loads replace hand-rolled parsers: YAML state\n  machines in matchers/assertions -> real yaml parser; config-text regex\n  extractors (incl. a 55-l\n[…]\n (scratch file, all\n  assertions were expect(true).toBe(true))\n- refactor ledger (todo/refactor-expressive-ts.md) updated with the\n  Pass 7 boundary note; findings recorded in .ai-docs/agent-findings/",
          "is_bot": false,
          "headline": "test: expressive-TS test-suite pass + E2E stability",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-19T15:49:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f499811f084c0f49b4f2de3d460c8efd565209b6",
          "body": "Expressive-TypeScript refactor across the production codebase (two-tier\norchestrators, guard clauses, named predicates/transforms, extracted\nmodules: scope-predicates, install-base-dir, is-home-directory,\nwrite-compiled-agents, compile-agents-all-scopes, require-marketplace,\nplugin-ref, validate-keb\n[…]\n on all remaining deliberate casts, including the\n  documented out-of-union placeholder categories in metadata-keys\n\nGates run manually pre-commit: tsc baseline-clean, full unit suite\n5101/5101 green.",
          "is_bot": false,
          "headline": "refactor(cli): expressive-TS production pass + type-safety hardening",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-19T15:49:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2d6161265a13029e5919ff645af41268ed48246",
          "body": "…241)\n\ntest: init-dashboard-edit-plugin-install.e2e.test.ts never set an explicit\nHOME, so the E2E sandbox collapsed it into a global edit (D-226), silently\ntesting global-edit semantics under a project-scope label. Rewritten to use\nan explicit, separate HOME so it genuinely exercises project scope,\n[…]\n store's already-correct behavior: selecting a conflicting\nexclusive-category skill at project scope is blocked with a toast, not\nsilently allowed to evict the global install. No product code changed.",
          "is_bot": false,
          "headline": "chore(release): 0.142.3 — fix vacuous project-scope test coverage (D-…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T21:45:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bbaaf345dd5063094bd5389ad575f35815bd0db2",
          "body": "…cond-spacebar global removal\n\nfix(wizard): a dual-scope skill/agent collapsed via spacebar now correctly\nstays selected in the same session (still active via global), instead of\nlosing its active styling. A second spacebar on that collapsed row is now\ncorrectly blocked instead of silently removing \n[…]\nkills and\nagents.\n\nD-241 filed as backlog: a pre-existing test never exercised genuine\nproject-scope editing due to the already-tracked D-226 sandbox gap;\nconfirmed not a regression from this release.",
          "is_bot": false,
          "headline": "chore(release): 0.142.2 — fix dual-scope collapse live-selection + se…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T21:27:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aaa1ceea25b1d24228b92f01f4dc6e5c9f3e3c60",
          "body": "The linked D-220 through D-225 plan files were pruned as resolved\nwork; their completion summaries in TODO-completed.md already\ncontain the relevant detail.",
          "is_bot": false,
          "headline": "docs: drop dead plan links from completed D-22x entries",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T19:23:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e5ce6ed1a9f69dc240f6d4815e36c345ce170eb",
          "body": "Zero usages anywhere in src/, scripts/, e2e/, or bin/.",
          "is_bot": false,
          "headline": "chore: remove unused terminal-image dependency",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T19:23:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa7b51a95053d87651be7abf2bffbcbb351ba916",
          "body": "docs/index.md and docs/guides/install-modes.md still described a\n\"Local Mode\" distinct from eject mode, but that mode was renamed to\n\"Eject Mode\" in code. .ai-docs/reference/commands/index.md listed\n--version/--description/--owner-name/--owner-email flags for\n`build marketplace` that no longer exist on the command.",
          "is_bot": false,
          "headline": "docs: fix stale local-mode terminology and marketplace flags table",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T19:23:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf44eceb83a9fb0acf21fe4b500785542ed3428a",
          "body": "launch-strategy.md is a pre-launch checklist for a launch that has\nalready shipped. screenshots/ and assets/logo.png are unreferenced\nsince the README moved to assets/demo.gif. .cache/agents-inc/version\nwas a stale committed runtime cache artifact; .cache is now gitignored.",
          "is_bot": false,
          "headline": "chore: remove stale planning docs and orphaned assets",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T19:23:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68056faed87e826d375aef22fd9908588f58ea17",
          "body": "99 findings marked resolved/superseded and 2 absorbed suggestions,\nall already incorporated into standards/code. Also renamed\nerror-swallowing-systemic-gap.md to add its missing date prefix.",
          "is_bot": false,
          "headline": "docs(agent-findings): prune resolved and superseded findings",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T19:23:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "652d1056ee94d7abf04a167f037af5b78a6374dd",
          "body": "Only caller was its own test; zero production call sites.",
          "is_bot": false,
          "headline": "refactor(wizard): remove dead getDomainsFromStack util",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T19:23:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5520575a4ba7205c88a930d44a9349ef2de5dab",
          "body": "docs: file two standards-gap findings from this cycle (recurring task-ID\nlint gap, e2e-helper-tests-never-run-under-either-vitest-project), plus\ncarry over formatting-only cleanup (README.md, todo/TODO-completed.md) left\nover from prior releases.",
          "is_bot": false,
          "headline": "chore(release): 0.142.1 — standards-gap findings and formatting cleanup",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T15:40:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f4cef5a2cdaede462b49fd873268ca4d29ed14e",
          "body": "…-to-end (D-233, D-227)\n\nfeat(wizard): spacebar on a persisted dual-scope [P][G] skill/agent now\ncollapses cleanly to inherited-global instead of leaving an orphan tombstone\n(applySkillRemoval + toggleAgent), and spacebar again restores the full pair.\ns (scope-toggle) is now a guarded no-op on a per\n[…]\nsurvive domain/stack re-preselection on the agent path (D-227).\n\nA low-severity, E2E-unreachable same-scope duplicate case remains open as\nbacklog (D-227 follow-up, unit-level it.fails coverage only).",
          "is_bot": false,
          "headline": "chore(release): 0.142.0 — dual-scope scope-toggle semantics fixed end…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T15:36:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e5076de94a6401a08700f13a05077660edce810",
          "body": "todo/ is now gitignored except the two files actively synced with the release\nprocess. Everything else in that directory (per-ticket investigation notes,\nscratch plans, the skill-olympics arena) stays on disk but is no longer\ntracked or shown in git status.",
          "is_bot": false,
          "headline": "chore: untrack todo/ working files except TODO.md and TODO-completed.md",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T15:33:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11e883342a05953857756794df4e40aa8d1dfa52",
          "body": "…ting global changes (D-240 backlog)\n\nfix(propagation): propagateGlobalChangesToProjects now prunes stale stack\nreferences to a removed global skill (computeRemovedGlobalSkillIds +\nretainReconciledStack) and reconciles selectedAgents symmetrically with\nagents[] (retainReconciledSelectedAgents) when pushing a global change out to\nother registered projects. Agent-file recompilation during propagation is\nfiled as backlog (D-240), deliberately deferred as a larger, separate change.",
          "is_bot": false,
          "headline": "chore(release): 0.141.8 — reconcile stack/selectedAgents when propaga…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T15:26:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8120ef2d36ff37a91f1de73862a545ac40d2219a",
          "body": "…ntry\n\nfix(config): buildStackForSelection now returns an authoritative {} instead of\nundefined when agents are selected but nothing preloads, so mergeConfigs no\nlonger mistakes \"genuinely empty\" for \"untouched\" and resurrects the removed\nskill's stale stack reference.",
          "is_bot": false,
          "headline": "chore(release): 0.141.7 — stop resurrecting a removed skill's stack e…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T15:21:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b40a3d37dee1725df123ff2e29445b9b001bff8",
          "body": "…ries (D-238)\n\nAlso removes the dead todo/ gitignore rule (every .md under todo/ was already\ntracked, so the rule excluded nothing and only broke lint-staged's re-stage\nstep).",
          "is_bot": false,
          "headline": "chore(release): 0.141.6 — build plugins prunes stale dist/plugins ent…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-18T15:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a731a20074fb6dbb771d6dc5d453cb796419d4c7",
          "body": "Updated README to include a skills table and progress status for commands.",
          "is_bot": false,
          "headline": "Enhance README with skills table and command updates",
          "author_name": "Vincent",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-10T18:12:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd5412399b08d0f6c30aa0eb37592b13ae585515",
          "body": "package.json's name field was written verbatim into marketplace.json,\nbreaking consumers with npm scoped names (e.g. @agents-inc/skills) since\nClaude Code's marketplace schema forbids path separators in name. --name\noverrides it, validated fail-fast with the same kebab-case rule new\nmarketplace already enforces. Omitting the flag keeps prior default\nbehavior unchanged.",
          "is_bot": false,
          "headline": "feat(build): add --name override flag to build marketplace",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T20:59:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e400fe2d16fb5e4f2f7cc010d5faf2b950604eb0",
          "body": "Ran generate:types and generate:schemas to catch metadata.schema.json's\ncategory/slug enums up to the skills source repo. Adds ~30 new category\nslugs from newly-added skills and replaces the stale nextjs-app-router\nand nextjs-server-actions slugs with nextjs, following a prior skills-repo\nmerge those slugs into a single skill.",
          "is_bot": false,
          "headline": "chore(release): 0.141.4 — regenerate skill matrix and metadata schema",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T20:53:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af8a00e4869eab1b8244c15244549db92270ed17",
          "body": "GitHub doesn't render <video> tags pointing at relative repo paths, only its\nown asset CDN. Switched to a gif embedded via <img>, which renders inline\neverywhere. demo.tape updated to output and capture the gif with tuned\ndimensions that keep the terminal above the wizard's 80-column minimum.",
          "is_bot": false,
          "headline": "chore(release): 0.141.3 — switch README demo from mp4 to gif",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T15:05:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "021731e059150027124e5ec3b730fee8f6b84a4b",
          "body": "…ed npx usage\n\nRenamed CLI_BIN_NAME to CLI_INVOKE_COMMAND (\"agentsinc\" -> \"npx @agents-inc/cli\")\nso warnings, errors, and generated snippets recommend the same invocation the\nREADME promotes. Also fixes a hardcoded \"agentsinc init\" literal in\nsource-manager.ts that bypassed the constant entirely.",
          "is_bot": false,
          "headline": "chore(release): 0.141.2 — runtime CLI invocation strings match promot…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T14:15:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd594c0e38c1193caaa93a104928a2fb4bce95b9",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'temp' into main",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T13:33:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96e96f765cd0a0d338f21d6007e954cbdd4b5f25",
          "body": "Hoisted domain-nav variant duplicated an absolute-positioning reserve\nmargin onto an in-flow element, producing 4 blank lines above the\nskills grid instead of 1.",
          "is_bot": false,
          "headline": "chore(release): 0.141.1 — wizard tab-bar spacing fix",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T13:24:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b62748c0de57966375c71e9392211636c6788539",
          "body": "Temp",
          "is_bot": false,
          "headline": "Merge pull request #3 from agents-inc/temp",
          "author_name": "Vincent",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T11:59:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e558c4671cd37b7f0af8a3bdde881898227a36f5",
          "body": "…lt-in theme",
          "is_bot": false,
          "headline": "chore(demo): regenerate demo recording with larger vhs output and bui…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T11:43:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a753874dd4e18d1c73ed57b4156018f598e4d220",
          "body": null,
          "is_bot": false,
          "headline": "docs: link readme intro steps to install-modes and editing-config guides",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-07-09T11:43:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1870762f39fc3dd59ed37f5a75a5c1f2440a9b89",
          "body": null,
          "is_bot": false,
          "headline": "temp",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-22T12:00:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a8aae13025c75e469d86bd59e429a7636d2bf16",
          "body": "…217)\n\nPer-skill source-based pluginRef in compiled agents.\nFixes mixed-mode agents emitting all-or-nothing formats.\nSee changelogs/0.140.0.md for full details.",
          "is_bot": false,
          "headline": "chore(release): 0.140.0 — per-skill plugin skill reference format (D-…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T21:43:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee1d82709e8216afe90333a314842a42f79ebdad",
          "body": "- Move D-217 row from TODO.md → TODO-completed.md with full landed-state\n  summary (per-skill pluginRef, derivePluginRef helper, source threading,\n  tests, E2E)\n- Update todo/D-217-plugin-skill-reference-format.md status block from\n  \"NOT STARTED. Plan substantially wrong — rewrite required.\" to DON\n[…]\nrom D-224 Fix B)\n- TODO.md already carried the D-233 row + Active Tasks detail section\n  from the earlier backlog-grooming pass; just removes the stale D-217\n  row and picks up the new D-233 plan link",
          "is_bot": false,
          "headline": "docs(todo): file D-233 plan; mark D-217 done",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T21:42:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f595e5ab45302beb720fe3347aa66fdadacabac8",
          "body": "Tests (all green):\n- stack-plugin-compiler.test.ts: 5 new per-skill ref-format tests\n  (pure plugin, pure eject, mixed, undefined source/user-authored local,\n  dual-scope same id)\n- resolver.test.ts: 2 new tests verifying source propagates through\n  resolveSkillReference onto the resolved Skill; 2 p\n[…]\nes until the template bug was fixed and the\n  fixture trimmed to match reality.\n\nFindings:\n- 2026-04-20-d217-test-prereq-already-satisfied.md\n- 2026-04-20-e2e-fixture-preload-drift-from-real-stacks.md",
          "is_bot": false,
          "headline": "test: D-217 coverage + E2E fixture template + realism trim",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T21:41:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5fa39c3ffaf46810ee2fdf688e7253acbe6ab0e0",
          "body": "Compiled agents now reference each skill in the format dictated by that\nskill's own `source`, not by a whole-agent `installMode` flag. Mixed-mode\nagents (some plugin-source skills + some eject-source skills) now emit\nper-skill refs correctly.\n\nContract:\n- skill.source === \"eject\" (or undefined) → ba\n[…]\nAgentsOptions`,\n`CompileAndWriteParams`, `compileAndWriteAgents`) to preserve caller\ncontracts; tracked as follow-up in\n.ai-docs/agent-findings/2026-04-20-d217-installmode-plumbing-dead-in-wrappers.md",
          "is_bot": false,
          "headline": "fix(compile): per-skill source-based plugin reference format (D-217)",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T21:41:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b51142198f7b0ec286bdb7a40fb10c76747727cb",
          "body": "Plan files for D-218 and D-226, 6 new backlog tickets, demo assets.\nNo product code changes.\nSee changelogs/0.139.0.md for full details.",
          "is_bot": false,
          "headline": "chore(release): 0.139.0 — backlog grooming + demo assets",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:33:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20cd0276aad09610483cad50cf2b07b7ddbbd74e",
          "body": "- assets/demo.tape: VHS (charmbracelet/vhs) script that records a full\n  `npx @agents-inc/cli init` wizard walkthrough to demo.mp4\n  (1000x1000, Monaspace Neon font, custom One Dark-ish theme)\n- assets/theme.json: 24-bit ANSI color palette used for the recording",
          "is_bot": false,
          "headline": "chore(assets): add README demo tape and terminal theme",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:32:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87dad99ac917dc9d95a8ae1d3bdb4f6ecfb66001",
          "body": "…lans\n\nBacklog grooming after the D-220–D-225 cluster landed.\n\nNew plan files:\n- D-218: plugin-install hardening follow-ups (mode-migrator data-loss +\n  ensure-marketplace error wrapping; item 2 landed 2026-04-17)\n- D-226: E2E sandbox collapses HOME into projectDir, making\n  isEditingFromGlobalScope\n[…]\nasks sections for D-228–D-232 follow the D-213/D-214/D-215\n  detail convention\n\nAlso includes prettier/linter fixes on already-committed files in this\nsession's earlier releases (no semantic changes).",
          "is_bot": false,
          "headline": "docs(todo): file D-227–D-232, add D-218/D-226 plans, update related p…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:32:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ea866b60f75bf04bde1f56df73797362c85e0f5f",
          "body": "…D-225)\n\nDual-scope badge, tombstone cleanup, symmetric info-panel diff.\nSee changelogs/0.138.0.md for full details.",
          "is_bot": false,
          "headline": "chore(release): 0.138.0 — scope toggle UX correctness (D-223, D-224, …",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:29:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "afaffb4b70dcd7ae89e6863f5e1ee91809043c15",
          "body": "The info panel rendered `+` next to the new-scope row on a P→G toggle\nbut never rendered `-` next to the removed project-scope row, because\n`removedSkills`/`removedAgents` filtered by id/name only while\n`prevSkillKeySet`/`prevAgentKeySet` were keyed on `(id, scope)`/\n`(name, scope)`. Asymmetric keys\n[…]\nnel overlay all assert\nsymmetric `{project: -, global: +}` / `{global: -, project: +}` entries\nwith `getSummaryDiffEntries`.\n\nPlan: todo/D-225-info-panel-asymmetric-scope-toggle-diff.md (status: done)",
          "is_bot": false,
          "headline": "fix(wizard): symmetric info-panel diff on scope toggle (D-225)",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:29:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc766ffedfe1440d3aaf64377fe3e46a0ac93bdb",
          "body": "After a G→P→G cycle on a skill with a prior global tombstone, the wizard\nsilently persisted a corrupt `{global} + {global, excluded:true}` pair —\n`toggleSkillScope`'s P→G branch only cleaned up the tombstone when\n`wasInstalledGlobally` returned true, but that predicate filters\n`!sc.excluded` so a to\n[…]\n\n- 2026-04-17-d224-rebuild-required-for-e2e.md (E2E runs against dist/;\n  ensureBinaryExists doesn't stamp-check staleness)\n\nPlan: todo/D-224-wizard-hides-global-after-PtoG-tombstone.md (status: done)",
          "is_bot": false,
          "headline": "fix(wizard): clean P→G tombstone unconditionally (D-224)",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:28:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70f775b9fff6a6172d68c9ed8b006d312646391a",
          "body": "`populateFromSkillIds` dropped excluded-global tombstones whenever an\nactive entry shared the same skill id, so the wizard-store couldn't\nrepresent a skill that had been toggled from G→P (project-active +\nglobal-tombstone). The render layer was already dual-scope capable\n(`CategoryOption.secondarySc\n[…]\ntombstone loss in `preselectAgentsFromDomains` +\n`stack-selection.tsx` is symmetric but separate — tracked as D-227.\n\nPlan: todo/D-223-wizard-scope-indicator-tombstoned-global-skills.md (status: done)",
          "is_bot": false,
          "headline": "fix(wizard): preserve dual-scope tombstone on hydration (D-223)",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:28:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1551cd5de01dc234eae368dc7a4b2527399c6d04",
          "body": "Stack preservation, agent dedup, propagation type lockstep.\nSee changelogs/0.137.0.md for full details.",
          "is_bot": false,
          "headline": "chore(release): 0.137.0 — config correctness (D-220, D-221, D-222)",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:25:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fe50dad959d536bb736c98684fd597359bd22b5",
          "body": "… (D-222)\n\nWhen a global agent toggle propagated to other registered projects, the\nvalue-side writer (`generateProjectConfigWithInlinedGlobal`) merged\n`global.selectedAgents ∪ project.selectedAgents` correctly, but the type-\nside writer (`generateConfigTypesSource`) received a `combinedConfig`\nthat \n[…]\n2026-04-18-mergeConfigs-drops-projects-field.md (distinct but\nadjacent bug in the same propagation path; worth tracking)\nPlan: todo/D-222-agent-propagation-selected-agents-type-drift.md (status: done)",
          "is_bot": false,
          "headline": "fix(config): dedup-merge selectedAgents in global→project propagation…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:24:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14a3697ee8d88f16b7c28b64e8f92b80307b3cee",
          "body": "Agent scope toggle (project→global) was leaving the old project-scope row\nin the `agents` array while adding the new global-scope row, producing\nduplicates across repeated edits (observed: 5× `web-researcher` at project\nscope after N edit cycles).\n\n`mergeConfigs` now uses compound keys `name:scope[:\n[…]\n second edit is idempotent, G→P produces the expected\ntombstone.\n\nFinding: 2026-04-17-merger-authoritative-for-names-semantic.md\nPlan: todo/D-221-agent-scope-toggle-duplicate-entries.md (status: done)",
          "is_bot": false,
          "headline": "fix(config): dedup agents array on scope migration (D-221)",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:23:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "408e48d66cc92c52922f2d2a1fa0c9ffbd1e8fd1",
          "body": "User-authored per-agent stack curation was being silently overwritten on\nevery save. `buildAgentStack` regenerated membership from ownership + scope\ndefaults and only consulted `existingStack` for the `preloaded` flag.\n\n`config-generator.ts` gains a `shouldIncludeTriple` predicate that:\n  - keeps pr\n[…]\n220 Scenario C\n  interaction with agent-scope default)\n- 2026-04-20-newly-toggled-agent-defaults-global-breaks-project-scope-stack.md\n\nPlan: todo/D-220-agent-skill-removal-regression.md (status: done)",
          "is_bot": false,
          "headline": "fix(config): preserve per-agent stack curation across edits (D-220)",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:23:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0586300680e3bd6b2ce9f36cc0d27391face1aa8",
          "body": "Infrastructure for the new scope-toggle and info-panel E2E tests landing\nin this release and the next.\n\n- base-step.ts: getSummaryDiffEntries(displayName) parses the\n  SkillAgentSummary diff panel into {prefix, scope} tuples (handles\n  column-aware Project/Global tracking via │-delimited segments)\n-\n[…]\nstep.ts: waitForStableRender() between navigateCursorToItem\n  and pressSpace in toggleAgent, matching the convention already used\n  by acceptDefaults and toggleScopeOnFocusedAgent (CLAUDE.md E2E rule)",
          "is_bot": false,
          "headline": "test(e2e): add shared page-object helpers for scope/diff assertions",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-20T19:22:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25848f7e425b2ccb404a895b31eb536426d3b7a6",
          "body": "7 new E2E lifecycle tests guarding previously-undercovered user journeys.\nNo production code changes.\n\nNew tests:\n- compile-after-scope-change — compiled agent .md files reflect the\n  post-edit stack across scope changes\n- doctor-dual-scope — cc doctor correctly surfaces state across\n  dual-scope in\n[…]\nLWAYS additions from 0.133.0–0.135.0\n  findings\n- DOCUMENTATION_MAP.md — detectProjectInstallation → detectInstallation\n  sync + message-count fixes\n- changelogs/0.134.0.md — minor formatting touch-up",
          "is_bot": false,
          "headline": "chore(release): 0.136.0 — E2E lifecycle coverage expansion + docs",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-17T19:35:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bce7c73651dd789da164d84181081801289e2063",
          "body": "Rewrites E2E fixtures, page objects, and matchers for reliability.\nUpdates all 40 existing E2E tests to consume the new APIs.\nNo production code changes.\n\nInfrastructure:\n- dual-scope-helpers.ts rewritten — initProject / initProjectAllGlobal\n  drive dashboard → Edit flow when a prior global install \n[…]\n, scope-change,\n  cross-scope, re-edit, etc.\n- e2e/integration/custom-agents.e2e.test.ts\n- e2e/smoke/pom-framework.e2e.test.ts\n\nNew E2E coverage (7 lifecycle files) + doc updates ship next in 0.136.0.",
          "is_bot": false,
          "headline": "chore(release): 0.135.0 — E2E infrastructure refactor",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-17T19:32:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed3111afe540d39f0210e5c9d644adfae3ff35c2",
          "body": "…s overhaul\n\nThree correctness fixes in the config pipeline:\n\n- mergeGlobalConfigs now uses deep-additive merge per (agent, category, skill).\n  Project-context edits never remove or overwrite existing global state.\n  Fixes silent data loss where per-agent stack updates were dropped on write\n  when n\n[…]\n D-220 (in-memory stack regeneration reverts\nuser hand-curation; additive merge limits but doesn't fix this), D-222\n(selectedAgents propagation type drift), D-221 (not reproducible from\ncurrent code).",
          "is_bot": false,
          "headline": "chore(release): 0.134.0 — config generation + global-merge correctnes…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-17T19:18:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e7976f3be8fbc89c7bb374c632f76f6ea7bd9e1a",
          "body": "Hardens `cc init` and `cc edit` plugin-install paths against silent no-ops\nand partial-state installs.\n\n- `cc init` resolves marketplace BEFORE `copyEjectSkillsStep` via new\n  `requireMarketplace` helper. Pre-fix, mixed-mode plugin failures left\n  orphaned eject copies on disk with no `config.ts`, c\n[…]\nkip\n  (2026-04-16) and init-partial-state-on-plugin-hard-error (2026-04-17).\n- D-218 item (2) marked fixed; items (1) and (3) remain open.\n- D-223, D-224, D-225 logged for wizard scope-indicator bugs.",
          "is_bot": false,
          "headline": "chore(release): 0.133.0 — plugin install pipeline hardening",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-17T19:13:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e3ba4a37d2fdc202aaeafd208ed4cb17261e8d0b",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.132.0 — wizard first-frame flash fix + escape nav",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T07:45:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "631c195ff84573a78b57f68465d018c3510b9aae",
          "body": null,
          "is_bot": false,
          "headline": "style: prettier formatting on scaffolding commands and README table",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T07:44:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db4eeab503d776db54e53e43703f0a5446db415e",
          "body": "10-agent investigation synthesized. Proposal: emit singular for exclusive\ncategories, array for multi-select; drop `preloaded: false` as default; drop\nredundant `selectedAgents` field (derivable from `agents` array); rename\n`domains` → `selectedDomains` to match wizard store field. Rejected dropping\ndomain prefix from category keys (5-way `framework` collision,\n`populateFromStack` relies on direct `matrix.categories[key]` lookup).",
          "is_bot": false,
          "headline": "docs(todo): log D-215 config shape simplification task",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T07:44:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b428d50fb72987b5d9c0a54b732a7e9f97066a85",
          "body": "`cc edit` briefly rendered the stack-selection screen for one commit cycle before\nshowing the build step. Root cause: `Wizard` subscribed to the store via\n`useWizardStore()` BEFORE `useWizardInitialization()` ran, so the first-render\nsnapshot captured `step: \"stack\"`. The hook's render-phase setStat\n[…]\ntime props\" regression tests pin\ndown the `installedSkillIds` and `initialAgents` prop semantics so a future\nrefactor can't re-introduce the bugs where they were removed and re-derived\nfrom the store.",
          "is_bot": false,
          "headline": "refactor(wizard): eliminate first-frame flash + fix edit-mode escape nav",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T07:44:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe40f2185cf23256cae41081147a7475254eeac3",
          "body": "… fixes\n\nNo user-facing command removals. Three scaffolding commands (new skill,\nnew agent, new marketplace) now exit non-zero with a clear message when\ninvoked — flipped back on once D-212/D-213/D-214 land.\n\nAlso: 5 new tasks logged covering the matrix-composition hardening\nbacklog, the custom-skil\n[…]\n-selection UX, and a validate/doctor merge\ninvestigation. R-01 refactor proposes env-var override for feature\nflags so gated-command tests can be re-enabled.\n\nSee changelogs/0.131.0.md for full notes.",
          "is_bot": false,
          "headline": "chore(release): 0.131.0 — gate scaffolding commands pending lifecycle…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T06:12:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "390b56e8b04f15ccbafe2c4194e358d8c4ebd160",
          "body": "Tasks added to todo/TODO.md (in order of insertion at the top):\n  * D-214 — Matrix composition hardening (prereq to re-enabling\n    new marketplace). 22-item fix list across must-fix (7 items),\n    should-fix (9 items), and nice-to-have (6 items) surfaced by\n    a 10-agent parallel investigation of \n[…]\nault) helper reading AGENTSINC_FLAG_* so\n    tests can re-enable features via env vars without editing\n    source. Migration plan + priority (low until a second gated\n    command needs test coverage).",
          "is_bot": false,
          "headline": "chore: log D-210..D-214 tasks + R-01 refactor for flag testability",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T06:12:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8f6ea649db53614315bfc2c9cddb805690964e9",
          "body": "README.md:\n  * Drop new skill, new agent, new marketplace rows from the\n    Customization commands table — users shouldn't see commands\n    that exit with a disabled message\n\ndocs/reference/commands.md:\n  * Matrix rows for the three gated commands marked with ⚠️ and\n    a \"currently disabled (featur\n[…]\nd stale\n    \"skills-matrix.yaml\" reference with the accurate list of\n    what the command actually writes (config TS files +\n    package.json + README + starter skill + auto-run build\n    marketplace)",
          "is_bot": false,
          "headline": "docs: mark gated scaffolding commands; remove skills-matrix.yaml mention",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T06:11:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "579a471a67321947f0d01b28bacbfec6012d4cb8",
          "body": "tsup inlines FEATURE_FLAGS constants into ./dist/commands/*.js at build\ntime, so vi.mock can't re-enable gated code paths from tests (see\ntodo/TODO-refactor.md R-01). Command-level tests that exercise the\ngated run() are moved to describe.skip with D-212 / D-213 / D-214\nreferences; helper tests stay\n[…]\nce.e2e.test.ts — 14 tests\n\nsearch.test.ts receives a one-line prettier formatting tweak (arg\narray unwrapped to single line) — unrelated to the gates.\n\nFull suite: 4981 passed / 50 skipped / 0 failed.",
          "is_bot": false,
          "headline": "test: skip scaffolding command tests behind feature flags",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T06:11:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1ca3b98f564b051860278cc0c02bd620ba44f7a",
          "body": "Each command's run() now exits non-zero with a disabled-message referencing\nthe tracking task when its flag is off (default). Library helpers\n(scaffoldSkillFiles, scaffoldAgentFiles internal flows, createMarketplaceFiles)\nare NOT gated — new marketplace still uses scaffoldSkillFiles internally.\n\nFla\n[…]\nsabled...\", { exit: EXIT_CODES.ERROR });\n    }\n    // ... rest unchanged\n  }\n\nload-agent-defs.ts also receives a prettier formatting pass (options\nobject destructure inlined) — unrelated to the gates.",
          "is_bot": false,
          "headline": "feat(feature-flags): gate new skill, new agent, new marketplace commands",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T06:11:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f819a1d9c95b24ddb18dd2517ceb38ad11f4d442",
          "body": "BREAKING — removes 8 flags across 5 commands:\n  * search --interactive/-i, --category/-c, --refresh, --json\n  * validate --verbose/-v\n  * edit --agent-source\n  * new marketplace --output/-o\n  * update --no-recompile\n\nsearch is now a zero-flag required-query catalog browse — no more\ninteractive multi\n[…]\nKEY_COPY_LINK, IMPORT_COMPLETE\n\nUnresolved-slug matrix diagnostic promoted verbose() → warn() so\nsource authoring bugs surface on stderr with --verbose gone.\n\nSee changelogs/0.130.0.md for full notes.",
          "is_bot": false,
          "headline": "chore(release): 0.130.0 — CLI simplification round 3",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:51:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0284016218570f7f07a8e3aa1bd76ff93ced1ad",
          "body": "validate and doctor answer the same question from different layers:\ncontent bugs validate catches cascade directly into operational\nfailures doctor surfaces. Same root cause, two signals — users\nguess which to run.\n\nProposal: drop validate, extend doctor with validate's six sub-passes.\nLayered outpu\n[…]\nt doctor checks) — tips via\n     formatTips() keyed to CheckKind.\n  3. One aggregated exit code.\n\nInvestigation-status task with open questions on naming and CI-focused\nmode. Logged at top of TODO.md.",
          "is_bot": false,
          "headline": "chore: add D-210 task — merge validate into doctor",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:51:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fb56039f1bc69e7fe95c128f9094277f65a44bb",
          "body": "docs/reference/commands.md:\n  * Command matrix updated — search zero-flag, validate zero-flag,\n    edit without --agent-source, new marketplace without --output,\n    update without --no-recompile\n  * baseFlags override list now lists 7 commands (adds search, validate)\n  * Per-command sections rewrit\n[…]\n\ne2e/FINDINGS.md:\n  * Finding 19 (new marketplace --output) rewritten to mark the flag\n    as removed in 0.129.0+\n\ne2e/TODO-E2E.md:\n  * Dropped bullet referencing --output flag coverage (flag is gone)",
          "is_bot": false,
          "headline": "docs: sync commands reference and findings for 0.130.0 simplification",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:51:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e94b2f795a6d1caeca94a2c99ffde38cdfe2eeea",
          "body": "Unit tests:\n  * search.test.ts — drop --category/-c/--source/-s/--json/-i tests;\n    add required-query and positional-query tests; migrate source\n    plumbing to writeTestTsConfig\n  * validate.test.ts — drop --verbose/-v acceptance tests\n  * edit.test.ts — drop --agent-source flag-acceptance tests\n\n[…]\nons still verify scope routing via CLI built-ins\n  * pages/wizards/edit-wizard.ts — comment example updated from\n    --agent-source to --refresh\n\nTotal: ~40 tests deleted or rewritten across 19 files.",
          "is_bot": false,
          "headline": "test: update for 0.130.0 flag and helper removals",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:51:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6775325263a00ed9b5dd8d2deb69b12d106c583",
          "body": "…fs first param\n\nWith --agent-source removed from every command, the helpers that\nserviced it are dead:\n\n  * resolveAgentsSource — zero non-test callers after --agent-source\n    removal; deleted along with ResolvedAgentsSource type and the\n    \"--agent-source flag cannot be empty\" error message\n  * \n[…]\ne-exports pruned from configuration/index.ts.\ngetAgentDefinitions keeps its remoteSource first param — still used\nby new/agent.tsx to locate a custom agent-summoner meta-agent via the\nuser's --source.",
          "is_bot": false,
          "headline": "refactor: delete resolveAgentsSource + formatOrigin; drop loadAgentDe…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:50:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d20ca2d69b837e5dbcbf7234e7d01ad3b00fdaef",
          "body": "BREAKING removals:\n  * edit --agent-source — last --agent-source on any command\n  * new marketplace --output/-o — marketplace always created under cwd\n    (matches new skill / new agent convention)\n  * update --no-recompile — auto-recompile after update is the right\n    default; users who want finer\n[…]\nptions object to loadAgentDefs\n(the first agentSource param is removed separately in the next commit).\n\nnew marketplace keeps --force and inherited --source.\nupdate keeps --yes and inherited --source.",
          "is_bot": false,
          "headline": "refactor: prune --agent-source, --output, --no-recompile from 3 commands",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:50:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1ac20974206c1ecb772fe723c80e12466c0be24",
          "body": "…c to warn\n\nBREAKING: validate no longer accepts --verbose/-v. Diagnostic commands\nshouldn't have a \"hide detail\" toggle. The four-pass summary table is\nalways emitted.\n\nChanges:\n  * static flags = {} (plus baseFlags = {} override)\n  * verbose parameter removed from validateAllRegistered,\n    valida\n[…]\nng integrity — does not fire on install state, scope splits,\nor partial installs. The matrix is per-source, so cross-refs resolve\nwithin a single source's full catalog, not against the user's install.",
          "is_bot": false,
          "headline": "refactor(validate): drop --verbose; promote unresolved-slug diagnosti…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:50:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "682af937df7d5b56d41abe96d711a1ded46e23b7",
          "body": "…earch component\n\nBREAKING: search no longer has --interactive, --json, --category, --refresh,\nor --source. The Ink multi-select UI and implicit import-on-select side\neffect are gone. Use `import skill` to install.\n\nsearch is now a read-only browse across primary source + every registered\nextra (fet\n[…]\ns.ts (MAX_VISIBLE_RESULTS, DESCRIPTION_WIDTH,\n    COPIED_MESSAGE_TIMEOUT_MS, FALLBACK_MESSAGE_TIMEOUT_MS)\n  * HOTKEY_COPY_LINK in hotkeys.ts\n  * SUCCESS_MESSAGES.IMPORT_COMPLETE\n\nNet ~450 LOC removed.",
          "is_bot": false,
          "headline": "refactor(search): collapse to zero-flag catalog browse; remove SkillS…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T04:50:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82695d23c73b64c0d09317a37982ace6e90a1795",
          "body": "BREAKING — removes:\n  * doctor --verbose/-v\n  * build plugins --skills-dir/-s\n  * build marketplace --name/--version/--description/--owner-name/--owner-email\n  * new skill --output/-o\n  * new agent --non-interactive/-n, --refresh/-r\n  * import skill --subdir, --refresh\n\nPlus --source inheritance dro\n[…]\nd and now covers the plugins pass.\nShared test helpers extracted: setupIsolatedHome (9 files),\nwriteTestPackageJson (4 sites), readMarketplaceJson (3 sites).\n\nSee changelogs/0.129.0.md for full notes.",
          "is_bot": false,
          "headline": "chore(release): 0.129.0 — CLI simplification continued",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T03:25:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "888479f80d8bc6e4024f3b70bf3e2d0b88c7294f",
          "body": "docs/reference/commands.md updated for all flag removals and the\nbuild marketplace package.json behavior. Introduction names the 5\ncommands that override baseFlags. Per-command sections rewritten\nfor doctor (CheckKind, safeCheck, source ordering), build marketplace\n(package.json read + parseAuthor f\n[…]\netplace-uses-removed-output-flag.md — now\n    resolved via scaffoldSkillFiles direct call.\n  * 2026-04-14-unit-test-home-isolation.md — proposes the helper\n    shape that was subsequently implemented.",
          "is_bot": false,
          "headline": "docs: sync commands reference to current flag set; add review findings",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T03:24:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ac083eb1c1c3b0620d234b3e4a5b5d3013e86ea",
          "body": "Unit tests (12 files): removed assertions on flags that no longer exist\n(--verbose on doctor, --skills-dir on build plugins, 5 metadata flags\non build marketplace, --output on new skill, --non-interactive/--refresh\non new agent, --subdir/--refresh on import skill). Migrated 9 files\nto setupIsolatedH\n[…]\n.\n\nintegration/import-skill.integration.test.ts: `--subdir` test suite\nremoved with the flag.\n\nAdded: 5 author-parsing edge-case unit tests covering name-only,\nemail-only, URL suffix, and object form.",
          "is_bot": false,
          "headline": "test: update tests for flag cleanup; migrate to setupIsolatedHome",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T03:24:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "455da65839ba78ea0124ba8deee6dcfa96e8fc88",
          "body": "…helper\n\nNew shared helpers:\n  * setupIsolatedHome(prefix) in __tests__/helpers/isolated-home.ts —\n    returns { tempDir, projectDir, fakeHome, cleanup }. Replaces the\n    ~13-line beforeEach/afterEach boilerplate that had been copied to\n    9 unit-test files. HOME + cwd + tempDir state is managed c\n[…]\n--name\nto `build marketplace`, which 0.129.0 removed. 13 E2E test suites\ncascaded to failure via beforeAll. Helper now writes package.json\nvia writeTestPackageJson before invoking `build marketplace`.",
          "is_bot": false,
          "headline": "test: extract shared helpers; purge dead fixtures; fix plugin-source …",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T03:24:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad317fa92b15845229722083b6c431c348596528",
          "body": "…etadata\n\nschemas.ts exported formatZodErrors(issues): string. schema-validator.ts\nexports a different-signature formatZodErrors(error): string[]. The\ncollision forced grep confusion. schemas.ts version is renamed to\nformatZodIssues; schema-validator.ts keeps its original name.\n\n7 consumer files upd\n[…]\nr was duplicated between validate.ts and source-validator.ts.\n\nskill-plugin-compiler.ts: unused `metadata` variable (orphaned by an\nearlier edit) removed from generateReadme's signature and call site.",
          "is_bot": false,
          "headline": "refactor: rename formatZodErrors → formatZodIssues; extract isCustomM…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T03:24:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4dbcf326327221a6eec13533d4ff9d4129f696bd",
          "body": "…S config\n\nvalidate.ts cwd === $HOME dedup now uses fs.realpathSync on both\nsides — fixes macOS where $HOME is commonly symlinked and string\nequality silently misses the collision. The plugins pass gets the\nsame dedup (was previously missing, causing double-listing when\nrun from home).\n\nsource-valid\n[…]\n128.0 was over-eager and falsely flagged valid\n    `export default { ... }` files as \"no default export\".\n    Detection simplified to trust loadConfig's null return (jiti\n    already unwraps default).",
          "is_bot": false,
          "headline": "refactor(validate): realpath dedup, split metadata conventions, fix T…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T03:23:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7d06dadf79e9e3a1d31df209529d541c7baeb56",
          "body": "…ds package.json\n\nBREAKING removals:\n  * doctor --verbose (always verbose)\n  * build plugins --skills-dir (hardcoded src/skills)\n  * build marketplace --name/--version/--description/--owner-name/--owner-email\n    (reads package.json at cwd)\n  * new skill --output (auto-detects marketplace)\n  * new a\n[…]\nverwrite existing {noun}\"). Examples format standardized\non {description, command} object form.\n\nUI_SYMBOLS.CHECK and UI_SYMBOLS.CROSS added for doctor's status\nglyphs (replaced raw Unicode literals).",
          "is_bot": false,
          "headline": "refactor: prune 13 CLI flags across 6 commands; build marketplace rea…",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-15T03:23:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "252dc07a67c2885d1798b596fdf22e50a844633b",
          "body": "BREAKING — removes:\n  * build stack command\n  * compile --agent-source flag\n  * doctor --source flag\n  * all validate positional args and flags\n\nvalidate is now a zero-arg four-pass command covering every registered\nsource, installed plugin, installed skill, and installed agent.\nvalidateSource extended with stack, source-agent, and TS-config passes\nfor marketplace authors.\n\nSee changelogs/0.128.0.md for full notes.",
          "is_bot": false,
          "headline": "chore(release): 0.128.0 — CLI surface cleanup and validate rewrite",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-14T18:23:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6071308ca85a923c263d1c626a4fafa26970ff7",
          "body": "- New docs/reference/commands.md — full surface reference for every\n  command including the four-pass validate, conventions, known gaps,\n  and an .ai-docs drift log\n- README: polyglot-setup hint on the scope bullet (D-178); remove the\n  stale info entry (never existed) and the build stack row; link \n[…]\nOLO toggle: add implementation plan and link from TODO\n- Move D-178 to completed\n- Finding on source-file-shapes inline duplication flags three more\n  files that should migrate to mock-source-files.ts",
          "is_bot": false,
          "headline": "docs: commands reference, README polyglot hint, TODO updates",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-14T18:22:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc98fba72e3a87097a1c51ea17b1ded24a28e9b5",
          "body": "Extends validateSource with three additional passes so marketplace\nauthors running validate from a source repo get coverage the old\nvalidateAllSchemas used to provide:\n\n  Phase 4 — src/stacks/*/config.yaml and src/stacks/**/skills/**/\n            metadata.yaml\n  Phase 5 — src/agents/**/metadata.yaml\n[…]\nlidateSource.\n\nAdds renderAgentMd helper (distinct from renderAgentYaml) and a new\nshared fixture file mock-source-files.ts with canonical file-shape\nconstants for the five published source artifacts.",
          "is_bot": false,
          "headline": "feat(source-validator): validate stacks, source agents, TS configs",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-14T18:22:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c66c6a46504c15d5330ebc60694aa47616c4a0a",
          "body": "Old validate had three polymorphic modes (schemas / plugins / source)\nbehind --source, --plugins, --all, and a positional [path]. The bare\nmode validated loose YAML files in cwd — useful for nobody.\n\nNew shape is validate [--verbose], with zero positional args. Runs\nfour passes over everything the C\n[…]\nolds only formatZodErrors.\nObsolete schema-validator.test.ts removed.\n\nE2E tests rewritten to drive validate through cc init-registered\nsources; relationships.e2e uses InitWizard + validate --verbose.",
          "is_bot": false,
          "headline": "refactor(validate): collapse to 4-pass no-arg command",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-14T18:22:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "10222c7cbf39b3128a4139f1fabafc01c16f5145",
          "body": "The hybrid interactive/non-interactive model didn't match the rest of\nthe build * family and the use case is covered by build plugins or by\nrebuilding via init with a stack preset.\n\nRemoves the command file, its unit + E2E tests, the inline\nStackSelector Ink component (used nowhere else), and the associated\nSTEP_TEXT / interactive-prompt references. Stack concept itself\nremains — only the dedicated CLI command is gone.",
          "is_bot": false,
          "headline": "refactor: remove build stack command",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-14T18:22:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a06f3ee6405b82b45898bb1c9da93a6ef843cf88",
          "body": "Both flags were undocumented and not surfaced to users. compile's flag\nthreaded an optional remote agent-partials source; doctor's flag ran\na source-reachability check that now lives elsewhere.\n\nRemoving the compile flag leaves STATUS_MESSAGES.FETCHING_AGENT_PARTIALS\norphaned, so that constant is deleted with the flag. doctor no longer\nspreads BaseCommand.baseFlags — matches its current actual behavior.\n\nE2E tests updated to pass source via CC_SOURCE env var instead.",
          "is_bot": false,
          "headline": "refactor: remove compile --agent-source and doctor --source flags",
          "author_name": "Vincent Bollaert",
          "author_login": "vincentbollaert",
          "committed_at": "2026-04-14T18:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 0,
      "commits_last_year": 1220,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 16,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@agents-inc/cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "cli",
            "claude",
            "claude-code",
            "skills",
            "composable skills",
            "agents",
            "stacks",
            "plugins",
            "ai",
            "anthropic",
            "developer-tools",
            "productivity",
            "prompt-engineering",
            "ai-tools"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@agents-inc/cli",
          "is_deprecated": false,
          "latest_version": "0.144.1",
          "repository_url": "https://github.com/agents-inc/cli",
          "versions_count": 118,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2275,
          "first_published_at": "2026-02-16T21:34:43.511000Z",
          "latest_published_at": "2026-07-20T21:26:27.182000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 5,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "e2e/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 163822,
      "source_files_sampled": 521,
      "oversized_source_files": 6,
      "agent_instruction_files": [
        "CLAUDE.md",
        "src/cli/lib/__tests__/fixtures/stacks/default/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 14772
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 1,
            "oldest_advisory_days": 2
          },
          {
            "name": "tar",
            "direct": false,
            "version": "6.2.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-23hp-3jrh-7fpw",
              "GHSA-34x7-hfp2-rc4v",
              "GHSA-83g3-92jg-28cx",
              "GHSA-8qq5-rm4j-mr97",
              "GHSA-8x88-c5mf-7j5w",
              "GHSA-9ppj-qmqm-q256",
              "GHSA-gvwx-54wh-qm9j",
              "GHSA-qffp-2rhf-9h96",
              "GHSA-r292-9mhp-454m",
              "GHSA-r6q2-hw4h-h46w"
            ],
            "fixed_version": "7.5.21",
            "advisory_count": 12,
            "oldest_advisory_days": 191
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 2
        },
        "advisory_count": 13,
        "affected_count": 2,
        "assessed_count": 227,
        "malicious_count": 0,
        "assessed_package": "npm:@agents-inc/cli@0.144.1",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@inkjs/ui",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.0"
        },
        {
          "name": "@oclif/core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.0"
        },
        {
          "name": "@oclif/plugin-autocomplete",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "@oclif/plugin-help",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "@oclif/plugin-not-found",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "@oclif/plugin-warn-if-update-available",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "@oclif/table",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.5.0"
        },
        {
          "name": "execa",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "fast-glob",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.0"
        },
        {
          "name": "fs-extra",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.2.0"
        },
        {
          "name": "giget",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.0"
        },
        {
          "name": "gray-matter",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.3"
        },
        {
          "name": "ink",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        },
        {
          "name": "jiti",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "2.4.2"
        },
        {
          "name": "liquidjs",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.24.0"
        },
        {
          "name": "react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.2.0"
        },
        {
          "name": "remeda",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.33.6"
        },
        {
          "name": "yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.2"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "zustand",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 3,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "vincentbollaert",
          "commits": 1218,
          "avatar_url": "https://avatars.githubusercontent.com/u/5147672?v=4"
        },
        {
          "type": "User",
          "login": "ext-gurgengasparyan",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/254417189?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.999
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "61 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d01b95aef96ca486468c0bcc20d53b605871f552",
        "ran_at": "2026-07-27T14:58:40Z",
        "aggregate_score": 2.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T21:04:02Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-09T11:59:18Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/agents-inc/cli",
    "host": "github.com",
    "name": "cli",
    "owner": "agents-inc"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 45,
      "inputs": {
        "security": 37,
        "vitality": 45,
        "community": 36,
        "governance": 53,
        "engineering": 52
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 45,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "commits_last_year": 1220,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 16
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "16/52 weeks with commits",
                "points": 11.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 16
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1220 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1220
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 36,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "forks": 0,
              "stars": 5,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "@agents-inc/cli"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2275
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,275 downloads/month across npm",
                "points": 44.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2275,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 53,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.999
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 3,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "3/3 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 3,
                      "decided": 3
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 39,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "agents-inc",
              "public_repos": 5,
              "account_age_days": 201
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of agents-inc",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "agents-inc"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~0 yr old",
                "points": 6.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@agents-inc/cli"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "118 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 118
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 52,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "agent-composition",
                "agent-framework",
                "agent-stack",
                "agentic-ai",
                "ai-agents",
                "ai-tools",
                "anthropic",
                "claude",
                "claude-code",
                "claude-code-plugin",
                "claude-skills",
                "cli",
                "developer-tools",
                "skill-stacks",
                "subagents",
                "typescript",
                "agent-compiler",
                "agents-as-code",
                "claude-code-framework",
                "composable-agents"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 37,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 28,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 2.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "61 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the npm:@agents-inc/cli@0.144.1 runtime dependency closure — what installing the published package pulls in — 227 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@agents-inc/cli@0.144.1",
                  "assessed": 227
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 74,
            "inputs": {
              "source": "osv",
              "advisories": 13,
              "affected_packages": 2,
              "assessed_packages": 227,
              "unassessed_packages": 0,
              "affected_by_severity": "high 2",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "2 affected: brace-expansion 2.1.2 (high 7.5), tar 6.2.1 (high 8.8)",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 2,
                      "packages": "brace-expansion 2.1.2 (high 7.5), tar 6.2.1 (high 8.8)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 191 days ago",
                "points": 32.8,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 1,
                      "oldest": 191
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 227,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.97,
              "agent_instruction_files": [
                "CLAUDE.md",
                "src/cli/lib/__tests__/fixtures/stacks/default/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 14772
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md, src/cli/lib/__tests__/fixtures/stacks/default/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md, src/cli/lib/__tests__/fixtures/stacks/default/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "e2e/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "e2e/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "e2e/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 163822,
              "source_files_sampled": 521,
              "oversized_source_files": 6
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "6/521 source files over 60KB",
                "points": 54.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 521,
                      "oversized": 6
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T14:58:46.658873Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/agents-inc/cli.svg",
  "full_name": "agents-inc/cli",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.