Public record
Software health reportschema 0.27.0 · metrics 2.3.2 · 2026-07-29 11:40 UTC

chanceryhq / chancery

The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.

Go · HTMLApache-2.0★ 25 stars⑂ 1 forksince Jul 2026View on GitHub ↗
KindMCP serverCommand-line toolhow this is determined

chanceryhq/chancery holds a health index of 59 out of 100, placing it in the Moderate band. It scores highest on Vitality (67/100) and lowest on Community & Adoption (44/100). It was last updated 8 days ago. A single contributor accounts for most of its recent work.

59
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.

59
Exceptional93-100The record's top tier (≈ top 5%); essentially all checked criteria met
Excellent80-92Strong across the board; minor gaps
Good65-79Healthy; gaps are limited and manageable
Moderate50-64Acceptable with notable gaps; review recommended
Weak35-49Material weaknesses across several areas
At Risk20-34Significant weaknesses; adoption warrants caution
Critical1-19Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

The weighted overall 56 is calibrated to 59 on the published index scale (record calibration 2026-08-02).

Ownership

chanceryhqOrganization
0 followers2 public repossince Jul 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/chanceryhq/chanceryv0.2.0-38 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

67Good · 21% of overall
How it's scored
28.8/36Push recency — last push 8 days ago
2.1/36Commit cadence — 3/52 weeks with commits
15.4/18Commit volume — 51 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year51
human_commit_share1
days_since_last_push8
active_weeks_last_year3

Release discipline

98Exceptional
How it's scored
27/27Ships releases — 2 releases published
36/36Release recency — latest release 8 days ago
27/27Release cadence — a release every ~8.7 days
8/10OpenSSF Scorecard: Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
Inputs used
releases_count2
latest_release_tagv0.2.0
releases_from_tagsno
days_since_latest_release8
mean_days_between_releases8.7

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

44Weak · 17% of overall
How it's scored
22.4/60Stars — 25 stars
0/25Forks — 1 forks
0/15Watchers — 0 watchers
Inputs used
forks1
stars25
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
readme_badges
has_contributingyes
has_issue_templateno
has_code_of_conductno
readme_badge_services
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

48Weak · 23% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
42/42Issue resolution — 100% of issues closed
0/30PR acceptance — no decided pull requests or no data
0/13Newcomer PR acceptance — no first-time contributor's PR decided in 30d
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs0
open_issues0
closed_issues6
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs0
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Excluded from scoring (no data or not applicable): PR acceptance, newcomer_pr_acceptance. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
0/25Owner reach — 0 followers of chanceryhq
3.6/25Track record — 2 public repos, account ~0 yr old
Inputs used
followers0
owner_typeOrganization
is_verified
owner_loginchanceryhq
public_repos2
account_age_days24
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 8 days ago
12/20Version history — 3 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/chanceryhq/chancery
ecosystemsgo
any_deprecatedno
min_days_since_publish8

Engineering Quality

Are baseline engineering and documentation practices in place?

66Good · 19% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 20 topics
0/10Wiki
Inputs used
topicsai-agents, iam, identity, mcp, security, agents, credentials, tools, multi-agent, spawn, browser, browser-automation, hierarchy, cookies, password, mcp-client, mcp-server, mcp-tools, audit, audit-log
has_wikino
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

52Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — no data
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
2/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4
Excluded from scoring (no data or not applicable): ci_tests. Remaining weights renormalized.

Dependency advisories

100Exceptional
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages15
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 15 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.

57Moderate · 4% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 49 of 51 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.961
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 51
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileyes
typed_languageyes
bootstrap_filesMakefile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
55/55Manageable file sizes — 0/43 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes54,882
source_files_sampled43
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

25GitHub stars
1contributors
51commits, last 12 months
8days since last push
2releases
1bus factor
0open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

OpenSSF Scorecard 4.0 / 10
4.0aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-29 11:40 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/aCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
4Security-Policysecurity policy file detected
8Signed-Releases2 out of the last 2 releases have a total of 2 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 4
RegistryPackageVersion constraintManifest
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/oklog/ulid/v2v2.1.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gomodernc.org/sqlitev1.53.0go.mod
All dependencies 15

Full resolved dependency set from the GitHub dependency graph: 4 direct and 11 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/golang-jwt/jwt/v5v5.3.1direct
Gogithub.com/oklog/ulid/v2v2.1.1direct
Gogithub.com/spf13/cobrav1.10.2direct
Gomodernc.org/sqlitev1.53.0direct
Gogithub.com/dustin/go-humanizev1.0.1indirect
Gogithub.com/google/uuidv1.6.0indirect
Gogithub.com/inconshreveable/mousetrapv1.1.0indirect
Gogithub.com/mattn/go-isattyv0.0.20indirect
Gogithub.com/ncruces/go-strftimev1.0.0indirect
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daecindirect
Gogithub.com/spf13/pflagv1.0.9indirect
Gogolang.org/x/sysv0.44.0indirect
Gomodernc.org/libcv1.73.4indirect
Gomodernc.org/mathutilv1.7.1indirect
Gomodernc.org/memoryv1.11.0indirect
Dependency advisories 0

This repository publishes no package the index resolves, so its own dependency graph was assessed — 15 packages, which also include development and test pins that never ship: 0 carry known advisories, of which 0 are direct.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "iam",
        "identity",
        "mcp",
        "security",
        "agents",
        "credentials",
        "tools",
        "multi-agent",
        "spawn",
        "browser",
        "browser-automation",
        "hierarchy",
        "cookies",
        "password",
        "mcp-client",
        "mcp-server",
        "mcp-tools",
        "audit",
        "audit-log"
      ],
      "is_fork": false,
      "size_kb": 3499,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 334383,
        "CSS": 13532,
        "HTML": 44856,
        "Shell": 2180,
        "Makefile": 194,
        "Dockerfile": 367,
        "JavaScript": 8009
      },
      "pushed_at": "2026-07-21T07:39:20Z",
      "created_at": "2026-07-04T12:50:16Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T07:40:02Z",
      "description": "The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "HTML"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "chanceryhq",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/299839401?v=4",
      "created_at": "2026-07-04T12:48:19Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 24
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-20T13:47:41Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T22:04:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
          "body": "A broken ring forming a C, holding two bars that narrow. A chancery is\nthe office that keeps the seal, and the narrowing bars are the property\nthe whole product rests on: delegated authority can only shrink. The\nold mark was a generic pillar that said nothing specific and tied to\nthe name not at all\n[…]\nnly variant because the inner bars merge below\nabout 20px. Site favicon links move from an inline data URI to real\nPNGs, versioned so the old cached icon is replaced. README gets a\ntheme-aware lockup.",
          "is_bot": false,
          "headline": "brand: new mark, the seal",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-21T07:39:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80d9cd58cbe2238b0e143453390862dd1d5a9b6c",
          "body": "A different UID is the only boundary that actually holds here: ptrace\nchecks credentials, so being an ancestor stops helping. --run-as <user>\nspawns the server under its own UID, and the sealed-file run dir and\nits contents are chowned to that user so --secret-file keeps working.\n\nApproaches that lo\n[…]\n--confine).\n\nTightens the SECURITY.md invariant: 'agents never hold credentials' is\nprecise about the model's context and the agent's environment, not\nOS-level isolation from same-UID code. 109 tests.",
          "is_bot": false,
          "headline": "G17: ship --run-as privilege separation for the tool server",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:49:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a138f5c9f7ea2e54965fc7ef98452a9410a33f8",
          "body": "…bounded\n\nSealed secrets are injected into the tool server's environment, so\n/proc/<pid>/environ exposes them to any same-UID process — and to\nancestors under the default yama ptrace_scope=1. Since the agent\nruntime typically spawns the wrap, a hostile runtime (distinct from a\nprompt-injected model)\n[…]\nsolation from hostile code sharing the UID, and the tables now say so.\nDeployment guidance gains the mitigation: separate OS user, or\nptrace_scope>=2.\n\nReported by u/Psychological_Arm645 on r/AutoGPT.",
          "is_bot": false,
          "headline": "SECURITY: add G17 — credential isolation is UID-bounded, not process-…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:43:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d32ccacf283db6071737e282c3084043d1b30983",
          "body": "Anyone who loaded the page while /assets/* still carried\n'immutable, max-age=31536000' holds that CSS for a year and would never\nsee the aspect-ratio fix. A changed URL is a different cache entry, so\n?v=2 forces one clean refetch; the corrected Cache-Control keeps future\nedits reachable without this.",
          "is_bot": false,
          "headline": "site: version asset URLs to break the poisoned immutable cache",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:34:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c01ee77b008d9ce94938268146645d33d5fcb2e",
          "body": "/assets/* was pinned for a year with immutable, which covers style.css\nand app.js — filenames that never change. Any returning visitor would\nhave been stuck with stale CSS indefinitely (exactly how the squashed\n-image fix failed to appear). Images keep the year; CSS/JS revalidate\nwith ETag.",
          "is_bot": false,
          "headline": "site: don't immutably cache un-hashed CSS/JS",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:31:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4c1fb76583a8920460165fbc050caca3b950ae7",
          "body": "Images declared width/height 1600x1000 against real 2880x1720 assets,\nand the img rule lacked height:auto — so max-width squashed both\ndashboard shots. Corrected the declarations and added height:auto.\n\nCopy moves from personal-project voice to product voice: drops the\nfooter byline, 'Talk to me' becomes 'Get in touch', and the mailto\ntemplate loses its first-name salutation.\n\nPages is disabled (Vercel is canonical at chanceryai.vercel.app), so\nits deploy workflow goes with it.",
          "is_bot": false,
          "headline": "site: fix squashed screenshots, product voice, drop GitHub Pages",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:30:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8793fe7416176ba919088a83e052b1bd7572148f",
          "body": "Above-the-fold content was gated behind IntersectionObserver plus a\nstagger, so the hero sat blank for ~1s on load — bad on slow connections\nand worse for link-preview crawlers (Product Hunt, LinkedIn) that\nscreenshot early. You don't animate what's already on screen at load.",
          "is_bot": false,
          "headline": "site: render the hero immediately, animate only below the fold",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:25:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aa3eecf5267789b3dbcef3f1d937c0846ec2250",
          "body": "…rprise CTA\n\nReplaces the static brochure with a real page: a typed terminal replaying\nthe enforcement story (grant → allow → deny → revoke → deny), scroll\nreveals, a flow diagram of the gate, tabbed workflows, dashboard shots,\nand an enterprise section with a prefilled mailto.\n\nAccessibility/robust\n[…]\nmotion renders everything static.\n\nZero third-party requests: system fonts, no CDN, no analytics — which\nlets the CSP be default-src 'none' with 'self' for script and style, no\nunsafe-inline anywhere.",
          "is_bot": false,
          "headline": "site: proper landing page — animated terminal, interactive tabs, ente…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:24:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a994cad55be9fa2f2df015fb43a2dc34f68a3626",
          "body": "The README had grown into a manual — 280 lines, five inlined feature\nwalkthroughs, and a 19-row RFC table. Now 126 lines: what it is, why,\ninstall, one real end-to-end example, a compact capability list, and a\ndocs table pointing at the material that already exists elsewhere.\n\nrfcs/README.md is a ge\n[…]\nthem.\n\nAdds vercel.json (static site/ deploy, security headers, immutable\nasset caching) and puts the dashboard screenshots on the landing page,\nwhere they earn their space, rather than in the README.",
          "is_bot": false,
          "headline": "README: cut to essentials; RFC index moves to rfcs/README.md",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:53:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2951e92fed8107967433eb31976ade7c7abaee81",
          "body": "Drops the pre-alpha label. Every design RFC moves from In Review to\nLocked (design settled and implemented); README gains a Status section\nstating what beta does and doesn't promise — the security model is\nsettled and gaps are published, but CLI/REST may still break before\n1.0.\n\nAdds CHANGELOG.md (v\n[…]\ne landing page from\nRFC-010's MVP item 8, deployed to Pages by a workflow. Assets are\nlocal to site/ because raw.githubusercontent serves a sandbox CSP that\nblocks embedding.\n\n105 tests, go vet clean.",
          "is_bot": false,
          "headline": "v0.2.0: beta — lock all 19 RFCs, add changelog and landing page",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:44:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f8ae24a4e62376dc098647d28a20b9ffff852df",
          "body": "POST /v1/leases/verify accepts optional xref=<system>:<opaque-id>\n(shape-checked, 400 on malformed). On a VALID lease it is recorded as\nmcp.call_xref carrying the lease's writ, agent, and resource plus the\nopaque foreign id — the one moment two audit chains describe the same\nevent. Invalid leases re\n[…]\n cooperating servers read wid/blk from the lease they\nalready hold.\n\nVerifyLease now returns full LeaseInfo claims. Dashboard event map,\nverify.md walkthrough, RFC-015 amendment; 105 tests. Closes #6.",
          "is_bot": false,
          "headline": "RFC-015 §10: audit cross-references at lease-verify (xref)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T11:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2af06ebc129d9273eb227fc369b2c2514041c525",
          "body": "What-you-get bullet list up top (one line per RFC arc); the RFC-015-018\nmechanisms broken out of the dense paragraph into two sections with\nrunnable commands (callee trust: install/pin/confine/dry-run; per-call:\ntask/intent/lease); matching subheadings for the spawn, wrap, browser,\nand control-plane blocks so 'Try it' reads as one tour.",
          "is_bot": false,
          "headline": "README: capability summary + structured tour",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T10:04:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "571e1a2963ada4a3f5575395681b03daea3a0dc0",
          "body": "chancery mcp install <pkg>@<exact-version>: one-time npm install\n(scripts disabled, local paths copied not symlinked) into\n$CHANCERY_DATA/servers/<ns>, Merkle tree-pinned automatically;\nmutable specs refused — a mutable reference is not an identity. A\ntree pin now follows its namespace: plain wraps \n[…]\n), G16 added (host-granular\negress; Linux egress cooperative until netns). 104 tests / 11\npackages, including confinement against the real OS sandbox and the\ninstall→pin→poison→refusal arc. Closes #5.",
          "is_bot": false,
          "headline": "RFC-018: frozen installs and manifest-bounded confinement",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T18:02:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17188a83ae5cb093f26c31dd322055bde05a5bc3",
          "body": "Pins are now (kind, identity) pairs — strongest applicable tier wins:\n\nT3 digest: a container image reference pinned by digest in the server\nargs (image@sha256:...) becomes the identity automatically; mutable\ntags are never identities. Chancery verifies the reference, the\ncontainer runtime verifies \n[…]\ndence, poisoned-dependency e2e).\nG13 narrowed in SECURITY.md/RFC-009: the gap is now the DEFAULT's,\nwith shipped opt-in mitigations; RFC-016 rewritten around the tiers;\nREADME/concepts/verify updated.",
          "is_bot": false,
          "headline": "RFC-016 T2/T3: tree pinning and image-digest pinning",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T17:32:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f58fa4dabcd50b6d276d4b45c78b96dd81c2397",
          "body": "Closes three roadmap issues born from practitioner review:\n\nRFC-015 (#2): the audit trail now distinguishes admitted from happened\n(mcp.call_result committed/failed), and 'mcp wrap --lease' stamps each\nadmitted call with a 30s signed lease in params._meta that cooperating\nservers verify via POST /v1\n[…]\ns only. Arguments pass through transiently and are\nnever stored.\n\n89 tests across 10 packages; gaps G13-G15 added to SECURITY.md and\nRFC-009; RFC-000/005/008 amended; concepts/verify/playbook updated.",
          "is_bot": false,
          "headline": "RFC-015/016/017: call lifecycle + leases, server pinning, intent socket",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T13:40:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c5b18a698b73f9996d4ec7da119e81c678d0227",
          "body": null,
          "is_bot": false,
          "headline": "README: dashboard screenshots (audit timeline, writ delegation tree)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T09:10:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f6dda69f002ff36396e2bde4ed36b6eeef33258",
          "body": "asciinema cast + GIF (embedded in README) recorded against the\nbrew-installed v0.1.0 binary in an isolated CHANCERY_DATA dir;\ndemo/demo-driver.sh regenerates it.",
          "is_bot": false,
          "headline": "Demo recording: 40-second grant/allow/revoke/deny/audit arc",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T08:27:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da257f750e929f7481066130ac5b328b88b08935",
          "body": "Without it, macOS quarantines the un-notarized binary and newer\nreleases delete it from the Caskroom seconds after install, leaving\na dangling /opt/homebrew/bin/chancery symlink.",
          "is_bot": false,
          "headline": "Cask post-install hook: strip Gatekeeper quarantine from the binary",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T22:01:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21d06772e4ede9099ee70fa1feb02c98dc9fe0b0",
          "body": null,
          "is_bot": false,
          "headline": "Ignore local Stitch design exports",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:53:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae937837791311f5b3b92ffdf7314571a14fe9d1",
          "body": "Void background, seal-purple accent, dual-font ledger (Inter UI /\nmono identity data), per-tab stat cards, uppercase mono table\nheaders, writ cards with boxed delegation-tree nodes and right-angle\nconnectors. Same read-only data plumbing: token gate, 4s polling,\nintegrity pill, text-node-only rendering.",
          "is_bot": false,
          "headline": "Dashboard visual redesign from the Stitch design system",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:40:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bda521f3cb7340b4090aa36ff1290bd46d259e6",
          "body": "…ty chips\n\n- timeline speaks human: 'Authority granted to deploy-bot', 'Agent\n  spawned: worker-1', 'Spawn refused' — raw event name demoted to a\n  small mono subline; category dots (grant/action/security/lifecycle)\n- times are relative ('12m ago', 'in 2h') with the full timestamp on\n  hover; templa\n[…]\nnt/caveats\n  (display only, unverified) so narrowing is visible at a glance\n- owners shown as emails (user: prefix stripped); writ ids demoted to\n  hover/sublines; agents show 'spawned by orch' origin",
          "is_bot": false,
          "headline": "Dashboard readability: plain-English events, relative times, capabili…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:38:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e87f007d2020e4c69ada4cae36aefb66db9246b3",
          "body": "The product's proof is visual — the timeline and the delegation tree —\nso chancery serve now ships a dependency-free, go:embed'd dashboard:\n\n- live audit timeline (filterable, ALLOW/DENY pills, agent names\n  resolved) with a permanent integrity badge backed by audit verify\n- agent roster with state \n[…]\nee, JWS omitted) — the\n  route RFC-008 documented but the MVP never implemented\n- verified live in a browser across all four views; 79 tests; docs,\n  playbook step 8, SECURITY G12, RFC-000/009 updated",
          "is_bot": false,
          "headline": "RFC-014: embedded read-only dashboard at /ui",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:32:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba10d2e3f466d755936ce507a950853210337b51",
          "body": "Denials are answered immediately by the proxy while allowed calls\nround-trip through the server, so the deny usually prints first; the\nsh stub always replies with id 0. Show the exact expected lines and\nadd a troubleshooting row so neither reads as a failure.",
          "is_bot": false,
          "headline": "Playbook step 5: document response ordering and the stub's id:0",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T07:43:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db1a4e2b7c469a7fcbf5a8160cd04a963bbd345b",
          "body": "One ~20-minute sitting: identity/versioning, delegation-only-narrows,\nsealed secrets (grep-for-plaintext), layered policy (allowlist\nsubtracts at the ACTING agent's block, never adds), in-path MCP\nenforcement as the delegated agent, audit tamper detection, lifecycle\nterminality, DENY-as-200 over HTT\n[…]\n the real pitfalls hit\nduring Vantage dogfooding (zsh comments, split heredocs, lost env\nvars, silenced stderr, wrap-awaits-client, exact host matching).\nLinked from README, docs index, and verify.md.",
          "is_bot": false,
          "headline": "Add docs/testing-playbook.md: guided run of every feature (001-013)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-06T04:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33a6c83780c65f4d56f517e94f71b26057ff2c12",
          "body": "Browser agents inherit human sessions — bearer, unscoped, invisible to\nIAM. This makes the session a credential and the navigation an action:\n\n- session custody: mcp wrap --secret-file materializes sealed storage\n  state (cookies) as a 0600 file in a private run dir the SERVER reads\n  (chancery-file\n[…]\naywright MCP recipe\n  (--isolated --storage-state=chancery-file:STATE)\n- 6 new tests incl. full browser e2e (78 total); RFC-000/005/009\n  amended; SECURITY.md gap G11; concepts + verify guides updated",
          "is_bot": false,
          "headline": "RFC-013: browser sessions and tokens as governed credentials",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T18:15:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d19a05fa20aaa000337c5f2a8aeabff8bf4d683",
          "body": "Orchestrators that create agents at runtime (the common multi-agent\npattern) no longer need the admin token. Spawning is itself a\nwrit-governed action:\n\n- admin verb joins the capability grammar (RFC-004 amended);\n  Cap.Implies subsumption for template ceilings\n- templates: human-approved max caps +\n[…]\nly (ActiveErr everywhere);\n  chancery agent sweep retires; agent list shows expired state\n- 10 new tests (72 total); RFC-000/004/007/008/009 amended;\n  SECURITY.md gap G10; docs + verify guide updated",
          "is_bot": false,
          "headline": "RFC-012: dynamic agent creation — writ-gated runtime spawn",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T17:49:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a125b8f2e82d63681ac9488bdd1e5fcd3753809",
          "body": "All four surfaced by testing against a real multi-agent system:\n\n#1 (footgun) mcp wrap --agent X now evaluates X's own writ block, not\n   the writ's latest block (which may belong to a delegated sub-agent).\n   New store.BlockForSubject; explicit --block is verified against\n   --agent. Previously a r\n[…]\n\n   check) — no more granting writs to revoked agents.\n\nTests: block-for-subject selection + narrowing, grant-refuses-inactive,\nno-block-for-agent is ErrNotFound. All 10 packages green; verified live.",
          "is_bot": false,
          "headline": "Fix 4 findings from live Vantage dogfooding",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T10:14:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a9575a3e62c91ef3c30492e55890a1e0a6bbb9b",
          "body": "User-facing verification guide: hands-on, CLI-only, copy-paste checks\nthat each RFC 001-009 does what it claims, with real expected output,\nseparate from the go test suite. Every block was run to capture real\noutput before documenting (caught and fixed an allow-list usage error\nin the draft).\n\nAlso \n[…]\nCLI surface (re-register errored). Added\n'chancery agent version <name>' + service.AddVersion (immutable, keeps\nhistory, emits shadow-agent event on unknown agent), tested. README\nlinks the new guide.",
          "is_bot": false,
          "headline": "Add docs/verify.md (verify each RFC by hand) + agent version command",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T09:04:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6ed6e38b6b0299014391a47ef9d9bd860bd1951",
          "body": "Adds the honest general-purpose story and a non-MCP setup+test\nwalkthrough. Distinguishes the two governance modes: in-path/enforced\n(MCP today, unbypassable) vs advisory/check (any agent, any language,\ntoday via POST /v1/writs/{id}/check + SDK Guard). Shows a plain DB ETL\nagent governed by read:/write: writs with instant revocation and\ntamper-evident audit — verified working via CLI and HTTP before\ndocumenting. README gains the MCP-first-not-MCP-only framing up top.",
          "is_bot": false,
          "headline": "docs: governing any agent (MCP-first, not MCP-only)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:52:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0588ee17c51534a86b5a27062c72789de75c121e",
          "body": "Fills the developer-setup gap: prerequisites (Go 1.26+, no CGO), build,\nrunning tests (incl. -short to skip the subprocess integration test and\nmake demo), a table mapping all 10 packages' tests to the RFC each\nproves, the repo layout, conventions (RFC discipline, the two non-\nnegotiable invariants), and the DCO (no CLA) contribution flow. README\ngains a 'Build & test from source' section linking it.",
          "is_bot": false,
          "headline": "Add CONTRIBUTING.md: build, test, repo layout, RFC-to-test map",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:13:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f131570e62cce1866e03039cecac971fcda80039",
          "body": "Captures the launch checklist durably (out of chat): pre-tag gates\n(3 real users, demo cast, quickstart re-verified), one-time org/repo\nsettings (public packages, chancery.dev, Pages, vuln reporting), the\nrelease cut + verify steps, announce channels, and known non-blocking\nfollow-ups. Release pipeline proven via a private v0.0.1 dry-run.",
          "is_bot": false,
          "headline": "Add LAUNCH.md — go-live runbook and gates",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:48:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bf60180aa7a9f2008e5b24bb637e5c867287537",
          "body": "The homebrew_casks repository block had no token, so goreleaser used\nthe default Actions token (cannot write cross-repo) and the tap push\n403'd. Point it at HOMEBREW_TAP_GITHUB_TOKEN (set from the\nTAP_GITHUB_TOKEN secret in release.yml).",
          "is_bot": false,
          "headline": "release: use the tap PAT for the Homebrew cask push",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:36:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ca5aa7ac8534a2d1a534cea9644079b27dde453",
          "body": "… docs\n\nWeek 4 (quickstart): QUICKSTART.md walks governing the real official\nfilesystem MCP server; a permanent CI-safe end-to-end test\n(cmd/chancery/wrap_integration_test.go) spawns a real child MCP server\nprocess and proves list-filter/allow/deny/mid-session-revoke + audit\nintegrity. Verified manu\n[…]\nd against a real\nhttptest control plane.\n\nWeek 8 (docs): docs/ for GitHub Pages (native Jekyll from /docs, no CI),\nindex + concepts; README gains a Guides section.\n\nAll 10 packages green; gofmt clean.",
          "is_bot": false,
          "headline": "weeks4-8: real-server quickstart, examples, shadow-agent obs, Go SDK,…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T19:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac965281b9e04516f8498cf2b57a0ad9eac2f3fe",
          "body": "Cross-platform static binaries (linux/darwin x amd64/arm64), multi-arch\ndistroless image to ghcr.io (dockers_v2 + buildx), Homebrew cask on\nchanceryhq/homebrew-tap, per-archive SBOM (syft), keyless cosign signing\nof checksums via GitHub OIDC. Version/commit/date injected via ldflags;\nchancery --vers\n[…]\n+ generated cask). Image cosign signing is a noted\nfast-follow pending dockers_v2 signing surface.\n\nPrereqs for first real release: create chanceryhq/homebrew-tap repo and\nset TAP_GITHUB_TOKEN secret.",
          "is_bot": false,
          "headline": "weeks2-3: release packaging — goreleaser, cosign, SBOM, Docker, brew",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:16:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7129083f873f8c9dda21496e9220f945bb4aa81",
          "body": "CLI register/instance-start/grant/delegate/check now call\ninternal/service (RFC-008 §4: one implementation shared with the HTTP\nAPI) instead of duplicating store+writ+policy logic; the mcp wrap\ndecider reuses service.Decide, keeping only the PEP-specific instance-\nliveness gate. Removes ~120 lines o\n[…]\ndecision for PEPs) and\nstore.AuditSince (tail cursor). New: chancery audit --follow streams\nevents live for the demo (ALLOW scrolls, DENY appears on revoke).\nAll tests green; demo and follow verified.",
          "is_bot": false,
          "headline": "week1: route CLI through the service layer; add audit --follow",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:11:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7d2dbe68328369e5898d40acc5173c09c95a0668",
          "body": null,
          "is_bot": false,
          "headline": "gitignore: exclude local tooling state",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57463e9fcc76f52877e402045bfae85b02943f79",
          "body": "Founder decision: defer chancery.dev (~$12/yr) until revenue; docs on\nchanceryhq.github.io; vulnerability reporting via GitHub private\nreporting (an improvement regardless — no email infra, built-in CVE\nworkflow). Squatting risk on the public name recorded in RFC-010.",
          "is_bot": false,
          "headline": "Free-domain path: GitHub Pages + private vulnerability reporting",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a86663237e5e0dcac9a95dde22c09690298bcf2",
          "body": "Locks: boundary test (single-trust-domain security/operability = OSS;\norg-scale value = enterprise); two published promises (no license\nflip ever; security never paywalled — all G1-G9 close in OSS); locked\nledger (Cedar/approvals/Postgres/all PEPs OSS; SSO/SCIM, multi-\ntenancy, SIEM exporters, compl\n[…]\nin OSS schema;\nchancery-ee orchestrates per-tenant cores over the public API); DCO\nno CLA (relicensing door welded shut); lockstep releases. Apache-2.0\nLICENSE at root. This closes RFC series 000-011.",
          "is_bot": false,
          "headline": "RFC-011: open-core boundary — the test, the ledger, the two promises",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c006c9542f6a94614e552c3a0316192d49a409ca",
          "body": "Locks: MVP = v0.1.0 with the enforcement wedge (registry inside it);\n12-week plan (CLI->service migration, packaging w/ cosign+SBOM, real-\nserver quickstart, Claude Code + LangGraph examples, shadow-agent\nobservation v0, Go SDK, docs, 3 external users before tag); demo\nscript locked word-for-word; c\n[…]\nadmap, HTTP/shell/browser PEPs, PoP, Cedar, Postgres to v1).\nShips: SECURITY.md (gap table G1-G9, invariants you can hold us to),\nMakefile, scripts/demo.sh (the 60-second arc, CI-runnable — verified).",
          "is_bot": false,
          "headline": "RFC-010: MVP scope — the 90-day build, demo locked, cutlines named",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a1385a3340e2cf8d1a5984481726a8e65a04dce",
          "body": "Research at series close (OWASP ASI, CSA MAESTRO/agentic IAM, Gartner\nguardian agents + agent sprawl): the five defining questions were all\noutbound and known-population. Added Q6 (inbound/agent-to-agent trust\n- ASI07, ~24% org visibility) and Q7 (unregistered agents - discovery\nas a byproduct of en\n[…]\nis\nthe product, ASI06 memory poisoning is the argued scope line) and\nadopts MAESTRO as process reference. Positioning notes: deterministic\nguardian layer, proportional governance as writ policy packs.",
          "is_bot": false,
          "headline": "RFC-000/009 addenda: extended question set and agentic Top 10 mapping",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61d1ed6a95da0469e2c2d6b28e33841d2ab8c1c2",
          "body": "…table\n\nLocks: trust boundaries (model untrusted, operator trusted in MVP,\nserver semi-trusted); STRIDE walk per component; OWASP LLM Top 10\nmapping (LLM06 excessive agency is the product); abuse cases walked;\npublished MVP gap table G1-G9 each with owner and phase (bearer docs,\nsingle admin token, \n[…]\nI-gated:\nalg:none rejection for both token types, HS256 key-confusion rejection,\ncross-writ block substitution, unsigned delegation block on signed\nchain, exp-required, capability-free grants refused.",
          "is_bot": false,
          "headline": "RFC-009: threat model — STRIDE, OWASP LLM Top 10, and the honest gap …",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:39:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb12309ebc1cdce1d65b1576e9eea3c738328596",
          "body": "… serve\n\nLocks: Vault-style REST/JSON under /v1 mirroring the principal model;\nDDL as the data contract (SQLite->Postgres behind the store seam);\ndigests-only registration (D6 extended to the wire); admin bearer token\n(hashed at rest, constant-time compare, failures audited) with v1 path\nto identity\n[…]\ntest full flow (register->instance->grant->ALLOW->revoke->\nDENY-at-registry->resurrection-blocked), auth rejection + audit, DENY-as-\n200, delegation+attenuation over HTTP, token never in audit stream.",
          "is_bot": false,
          "headline": "RFC-008: data model and APIs — REST/JSON /v1, service layer, chancery…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:36:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2779517ee71678f960df1621d7b87ff7e38acf4",
          "body": "…eans terminal\n\nLocks: per-layer state machines (agent active⇄suspended→retired/revoked,\norphaned exits only via ownership transfer); terminality enforced at the\ndata layer (no client can resurrect); suspend/revoke/retire/orphan as\ndistinct audited verbs; nothing ever deleted; cascade-by-check (one\n\n[…]\n TTL.\nchancery agent retire/orphan/transfer + terminality warnings.\nTests: full transition matrix, no-resurrection property, orphan blocks\nissuance until transfer, retired names not silently reusable.",
          "is_bot": false,
          "headline": "RFC-007: lifecycle and revocation — locked state machines, terminal m…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:32:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05f6f7fa1748ecce37a4f252c617a6cc2e1c7cff",
          "body": "Locks: fixed metadata-only schema (no payload columns — D6 by DDL),\nhash-chained events (prev_hash + SHA-256 over canonical encoding,\ngenesis sentinel), single-writer chain append, locked event taxonomy,\nattribution embedded per row (agent/instance/writ/lineage), NDJSON\nexport, deny-on-audit-failure\n[…]\nappen). chancery audit verify walks the chain and names the first\nbreak. Tests: clean verify, edit/deletion detection with prefix\nproperty, attribution round-trip, allowed-but-unauditable call denied.",
          "is_bot": false,
          "headline": "RFC-006: audit and attribution — hash-chained, metadata-only evidence",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:29:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26b52f631392dc52407f3bb27ba87663fad8672a",
          "body": "Locks: protocol-aware stdio proxy that owns the server process; per-call\nPDP with fresh registry state (revocation = next call, not next TTL);\ntools/list filtered, tools/call enforced (filtering is UX, the call path\nis the boundary); JSON-RPC -32001 denials naming the layer; sealed\nsecrets injected \n[…]\nrnal/mcp +\nchancery mcp wrap. Unit tests: forward/deny/filter/malformed/no-name/\npassthrough. Live integration test passed: mid-session agent revocation\nblocked the next call with attributed timeline.",
          "is_bot": false,
          "headline": "RFC-005: runtime enforcement — the MCP proxy, in-path and unbypassable",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:19:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44e030d20c5683cf7b0f700a0c5bfaadf9169242",
          "body": "Locks: conjunction of layers where only the writ grants (L1) and every\nother layer only denies — allow-lists (L2, MVP), Cedar org policy (L3,\nv1), approvals with reserved 'hold' effect (L4, v1); default-deny;\ncapability grammar locked (verb registry, /-segmented resources,\ntrailing-* with subtree-vs\n[…]\n delegates to it;\nper-agent tool_allowlists + 'chancery agent allow'. Tests: grammar\nvalidity table, match semantics table, layer attribution, empty-list vs\n!none sentinel, nil-authority default deny.",
          "is_bot": false,
          "headline": "RFC-004: policy and authorization — layered PDP, locked grammar",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:14:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d739d54d8f43991617a8e6d367280dc4f6d0090c",
          "body": "Locks: one sealed store (AES-256-GCM, per-entry nonces, name-bound AEAD),\ninjection at the enforcement point per action after writ+policy checks,\ncredential classes sequenced static->OAuth->STS->mTLS, rotation as one\nre-seal. internal/seal + chancery secret put/list/rm. Tests: roundtrip,\nno plaintext on disk, cross-name swap rejected, wrong-key fail-closed,\ntamper rejection, metadata-only listing.",
          "is_bot": false,
          "headline": "RFC-003: credential broker — sealed store, agents never hold secrets",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:10:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1b9e5f2e6a094aff9140db2df398e17803c83b",
          "body": "RFC-001/002 running code: SQLite registry (agents/versions/instances,\nthree-layer revocation, fail-closed CheckIssuable), ES256 identity\ndocuments (5-min TTL, WIMSE-style claims, cnf reserved), writ grant/\ndelegate/verify/check with structural attenuation, delegation trees in\nthe registry, metadata-only audit timeline, cobra CLI, CI. Tests cover\nthe RFC invariants: widening unrepresentable, TTL monotonic, depth\nbounded, null-authority refused, tamper detection, revocation at every\nlayer.",
          "is_bot": false,
          "headline": "chancery: registry, identity documents, and writs — first working slice",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ca61e7fb9b250f0bcc376c0e4d25e0e20510b20",
          "body": "Locks: authority as a JWS grant-chain where block 0 grants capabilities\nand later blocks may only add caveats (widening unrepresentable);\neffective authority = grant ∩ caveats; TTL monotonicity; bounded depth;\nthe chain IS the lineage (user -> agent -> sub-agent), embedded in the\ncredential; subtree revocation at any block. Central append in MVP,\nBiscuit-style offline attenuation reserved for v1 (dk field).",
          "is_bot": false,
          "headline": "RFC-002: lineage and delegation — the writ",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "779f3c58a1fd64915b7b6cd1588118b4a7699240",
          "body": "Locks: agent as third principal class; three-layer identity\n(Agent -> Version -> Instance) with content-addressed versions;\nSPIFFE-compatible naming, WIMSE-compatible identity documents (ES256,\n5-min TTL, cnf slot from day one); registry-born, attestation-confirmed\nbirth model; three-layer revocation. Also: Chancery confirmed as final\nproduct name (RFC-000 D7 updated).",
          "is_bot": false,
          "headline": "RFC-001: agent identity model",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:52:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a70c3367294cced7170e4fb6e8dc20ce9f577091",
          "body": "…gents\n\nLocks: positioning (neutral self-hosted system of record), open-core\nApache-2.0, Go, MCP-first wedge, control-plane-first with own minimal\nbroker, metadata-only audit invariant, codename Chancery.",
          "is_bot": false,
          "headline": "RFC-000: vision and plan for Chancery, the identity provider for AI a…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 2,
      "commits_last_year": 51,
      "latest_release_at": "2026-07-20T13:47:41Z",
      "latest_release_tag": "v0.2.0",
      "releases_from_tags": false,
      "days_since_last_push": 8,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 8.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/chanceryhq/chancery",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/chanceryhq/chancery",
          "is_deprecated": false,
          "latest_version": "v0.2.0",
          "repository_url": "https://github.com/chanceryhq/chancery",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T13:44:37Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 25,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-17",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 54882,
      "source_files_sampled": 43,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 15,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/oklog/ulid/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": true,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.53.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.73.4",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 15,
        "direct_count": 4,
        "indirect_count": 11
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 6,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "anee769",
          "commits": 51,
          "avatar_url": "https://avatars.githubusercontent.com/u/67168113?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "2 out of the last 2 releases have a total of 2 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
        "ran_at": "2026-07-29T11:40:42Z",
        "aggregate_score": 4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T07:40:02Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/chanceryhq/chancery",
    "host": "github.com",
    "name": "chancery",
    "owner": "chanceryhq"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 56 is calibrated to 59 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 56,
            "calibrated": 59,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 59,
      "inputs": {
        "security": 52,
        "vitality": 67,
        "community": 44,
        "governance": 48,
        "calibration": "2026-08-02",
        "engineering": 66,
        "ai_readiness": 57,
        "weighted_overall_raw": 56
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 67,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "weak",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "commits_last_year": 51,
              "human_commit_share": 1,
              "days_since_last_push": 8,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "51 commits in the last year",
                "points": 15.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v0.2.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 8.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "weak",
        "name": "Community & Adoption",
        "value": 44,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "forks": 1,
              "stars": 25,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "25 stars",
                "points": 22.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "weak",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): PR acceptance, Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "pr_acceptance",
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 74,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 6,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 0,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "chanceryhq",
              "public_repos": 2,
              "account_age_days": 24
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of chanceryhq",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "chanceryhq"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 3.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/chanceryhq/chancery"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "3 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "ai-agents",
                "iam",
                "identity",
                "mcp",
                "security",
                "agents",
                "credentials",
                "tools",
                "multi-agent",
                "spawn",
                "browser",
                "browser-automation",
                "hierarchy",
                "cookies",
                "password",
                "mcp-client",
                "mcp-server",
                "mcp-tools",
                "audit",
                "audit-log"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 52,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 15 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 15
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 15,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 15,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.961,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "49 of 51 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 49,
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 51",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 54882,
              "source_files_sampled": 43,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/43 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 43,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "weak",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "mcp-server",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "library": 3,
        "mcp-server": 4
      },
      "primary": "mcp-server",
      "evidence": [
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:github.com/spf13/cobra",
          "weight": 4
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:go",
          "weight": 3
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-server",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-tools",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "low",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": false
    },
    "metrics_version": "2.3.2"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T11:40:48.003499Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chanceryhq/chancery.svg",
  "full_name": "chanceryhq/chancery",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v2.3.2, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.