Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-28 07:43 UTC

gkoreli / ghx

Agent-first GitHub code exploration. GraphQL batching, code maps (~92% token reduction), AND search, repo discovery with README previews. Codemode TypeScript sandbox, MCP server. Go.

GoMIT★ 0 stars⑂ 0 forkssince Mar 2026View on GitHub ↗

gkoreli/ghx holds a health index of 55 out of 100, placing it in the Moderate band. It scores highest on AI Readiness (81/100) and lowest on Community & Adoption (32/100). It was last updated 8 days ago. A single contributor accounts for most of its recent work.

55
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

55
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Goga KoreliPersonal account
0 followers5 public repossince Nov 2025

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
Gogithub.com/gkoreli/ghx/v2v2.9.0-3420 days ago
npm@gkoreli/ghx2.9.02,1372920 days agogithubclicode-explorationagentgraphqlcode-map

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

75Good · 22% of overall
How it's scored
28.8/36Push recency — last push 8 days ago
8.3/36Commit cadence — 12/52 weeks with commits
18/18Commit volume — 598 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year598
human_commit_share1
days_since_last_push8
active_weeks_last_year12
How it's scored
27/27Ships releases — 37 releases published
36/36Release recency — latest release 20 days ago
27/27Release cadence — a release every ~0.2 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count37
latest_release_tagv2.9.0
releases_from_tagsno
days_since_latest_release20
mean_days_between_releases0.2

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

32At risk · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
44.4/80Monthly downloads — 2,137 downloads/month across go, npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesgithub.com/gkoreli/ghx/v2, @gkoreli/ghx
dependents
ecosystemsgo, npm
total_downloads
monthly_downloads2,137
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

46At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
38.2/38.3PR acceptance — 6/6 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/29 approved changesets -- score normalized to 0
Inputs used
merged_prs6
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
0/25Owner reach — 0 followers of gkoreli
7.1/25Track record — 5 public repos, account ~0 yr old
Inputs used
followers0
owner_typeUser
is_verified
owner_logingkoreli
public_repos5
account_age_days259
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 2 package(s) on go, npm
35/35Publish recency — latest publish 20 days ago
20/20Version history — 34 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/gkoreli/ghx/v2, @gkoreli/ghx
ecosystemsgo, npm
any_deprecatedno
min_days_since_publish20

Engineering Quality

Are baseline engineering and documentation practices in place?

69Moderate · 20% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://www.npmjs.com/package/@gkoreli/ghx
10/10Repository description
10/10Topics — 7 topics
10/10Wiki
Inputs used
topicsai-agents, cli, code-search, developer-tools, github, golang, mcp
has_wikiyes
homepagehttps://www.npmjs.com/package/@gkoreli/ghx
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

48At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3.5
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages6
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@gkoreli/ghx@2.9.0 runtime dependency closure — what installing the published package pulls in — 6 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

81Good · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md, CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes19,522
How it's scored
18/18One-command bootstrap — .mise.toml
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 94 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum, pnpm-lock.yaml
has_dockerfileno
typed_languageyes
bootstrap_files.mise.toml
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.94
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
55/55Manageable file sizes — 0/245 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes35,342
source_files_sampled245
oversized_source_files0

Key facts

0GitHub stars
1contributors
598commits, last 12 months
8days since last push
37releases
1bus factor
0open issues
Go, npmpackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 3.5 / 10
3.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-28 07:43 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
Direct dependencies 15
RegistryPackageVersion constraintManifest
Gogithub.com/bmatcuk/doublestar/v4v4.10.0go.mod
Gogithub.com/cli/go-gh/v2v2.13.0go.mod
Gogithub.com/coder/acp-go-sdkv0.13.5go.mod
Gogithub.com/dop251/gojav0.0.0-20260311135729-065cd970411cgo.mod
Gogithub.com/evanw/esbuildv0.27.4go.mod
Gogithub.com/mark3labs/mcp-gov0.45.0go.mod
Gogithub.com/odvcencio/gotreesitterv0.13.4go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogo.opentelemetry.io/proto/otlpv1.10.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 0

Installing npm:@gkoreli/ghx@2.9.0 pulls in 6 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "cli",
        "code-search",
        "developer-tools",
        "github",
        "golang",
        "mcp"
      ],
      "is_fork": false,
      "size_kb": 8080,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/@gkoreli/ghx",
      "languages": {
        "Go": 1986731,
        "Shell": 4575,
        "JavaScript": 1460
      },
      "pushed_at": "2026-07-19T16:16:33Z",
      "created_at": "2026-03-08T04:08:37Z",
      "owner_type": "User",
      "updated_at": "2026-07-19T16:16:37Z",
      "description": "Agent-first GitHub code exploration. GraphQL batching, code maps (~92% token reduction), AND search, repo discovery with README previews. Codemode TypeScript sandbox, MCP server. Go.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "mainline",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "gkoreli.com",
      "name": "Goga Koreli",
      "type": "User",
      "login": "gkoreli",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/243085293?v=4",
      "created_at": "2025-11-10T08:36:47Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 259
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.9.0",
          "kind": "minor",
          "published_at": "2026-07-08T02:49:04Z"
        },
        {
          "tag": "v2.8.0",
          "kind": "minor",
          "published_at": "2026-07-07T18:25:34Z"
        },
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2026-07-07T14:10:39Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-07-07T06:41:57Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-07-07T00:09:18Z"
        },
        {
          "tag": "v2.4.2",
          "kind": "patch",
          "published_at": "2026-07-06T21:47:37Z"
        },
        {
          "tag": "v2.4.1",
          "kind": "patch",
          "published_at": "2026-07-06T20:58:28Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-07-06T20:27:01Z"
        },
        {
          "tag": "v2.3.2",
          "kind": "patch",
          "published_at": "2026-07-06T16:37:37Z"
        },
        {
          "tag": "v2.3.1",
          "kind": "patch",
          "published_at": "2026-07-06T16:31:37Z"
        },
        {
          "tag": "v2.1.19",
          "kind": "patch",
          "published_at": "2026-07-02T18:23:33Z"
        },
        {
          "tag": "v2.1.18",
          "kind": "patch",
          "published_at": "2026-07-02T17:49:23Z"
        },
        {
          "tag": "v2.1.17",
          "kind": "patch",
          "published_at": "2026-06-09T21:04:34Z"
        },
        {
          "tag": "v2.1.16",
          "kind": "patch",
          "published_at": "2026-04-15T06:57:19Z"
        },
        {
          "tag": "v2.1.15",
          "kind": "patch",
          "published_at": "2026-04-15T06:50:57Z"
        },
        {
          "tag": "v2.1.14",
          "kind": "patch",
          "published_at": "2026-04-15T06:39:11Z"
        },
        {
          "tag": "v2.1.13",
          "kind": "patch",
          "published_at": "2026-04-01T22:20:15Z"
        },
        {
          "tag": "v2.1.12",
          "kind": "patch",
          "published_at": "2026-04-01T18:50:18Z"
        },
        {
          "tag": "v2.1.11",
          "kind": "patch",
          "published_at": "2026-04-01T18:36:09Z"
        },
        {
          "tag": "v2.1.10",
          "kind": "patch",
          "published_at": "2026-04-01T18:23:42Z"
        },
        {
          "tag": "v2.1.9",
          "kind": "patch",
          "published_at": "2026-04-01T18:19:27Z"
        },
        {
          "tag": "v2.1.8",
          "kind": "patch",
          "published_at": "2026-04-01T17:53:42Z"
        },
        {
          "tag": "v2.1.7",
          "kind": "patch",
          "published_at": "2026-03-30T23:58:07Z"
        },
        {
          "tag": "v2.1.6",
          "kind": "patch",
          "published_at": "2026-03-29T19:16:21Z"
        },
        {
          "tag": "v2.1.5",
          "kind": "patch",
          "published_at": "2026-03-29T18:41:54Z"
        },
        {
          "tag": "v2.1.4",
          "kind": "patch",
          "published_at": "2026-03-21T03:27:17Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2026-03-21T03:24:47Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2026-03-21T03:23:27Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2026-03-21T03:19:00Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-03-21T03:11:36Z"
        },
        {
          "tag": "v2.0.2",
          "kind": "patch",
          "published_at": "2026-03-21T02:59:30Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-03-21T02:55:07Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-03-20T23:50:16Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-03-08T20:59:43Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-03-08T17:10:19Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-03-08T17:08:23Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-03-08T17:06:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "719cb293a61532b9db6771e631ecf16e687f495b",
          "body": null,
          "is_bot": false,
          "headline": "docs: normalize engineering record spacing",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-19T16:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbf57fbc4d33e8363a435f8d91740423e335d721",
          "body": null,
          "is_bot": false,
          "headline": "docs: add ghx engineering record links",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-19T16:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78b97544d859f0fadf59d6cb0a756aa1b2263904",
          "body": "Agent-experience hardening from the v2.8.0 dogfood:\n- CLI failure exit codes classified in core (ADR-0034 ph1-2): read 404 0->3,\n  read-missing 0->1, explore/read/tree/grep malformed slug ->2, 401/403 name\n  the gh auth login fix; substring matcher deleted.\n- Resolved commit SHA surfaced to agents (\n[…]\nghx-sidecar profile (ADR-0032.2): type\n  unified, drop fixed, argv-derived path-scope; byte-identical dedup, measured\n  0 host-verdict changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.9.0",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:47:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "78b51e7dc87334abdb43ef18e21c4b6aaceb4447",
          "body": "…A-0001 cross-family DISCHARGED\n\nShips the product audit's #1-ranked, cheapest, zero-measurement-dependency\nfinding, in the cross-family-cleared SAFE form.\n\nH1 (default adoption surface inverts the north star): .claude-plugin/plugin.json\nshipped only skills/ghx + skills/ghx-mcp (the heavy power-user\n[…]\n, doesn't kill it.\n\nBoth PA threads (0001, 0002) now carry an independent cross-family second opinion;\nthe last owed adjudication debt is paid.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(plugin): ship PA-0001 H1 — recon skill in the default install; P…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:47:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c59dda14855b039c1f12eaf7e882273544aeebd2",
          "body": "Landed as 3a61b63 (worker a3ae99b), verified before merge. Records the\n[]string-only scoping decision, eval-runner (not denyClient) placement, the\ntrace-array-scoped byte-identical proof, and the no-live-smoke caveat.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0032.2 implementation record (as-built + honest caveats)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:44:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e41613c276d2e2f8405c6d1a2dbc731e703d933",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record ADR-0032.2 sidecar-profile Locations fix",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:42:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3a61b635cc60ab08c8d46881d3b7fb9b4dc9b188",
          "body": "…ecar profile (ADR-0032.2)\n\nImplements ADR-0032.2 (ACCEPTED, full scope). Closes TRUST hole H9: the\nghx-sidecar eval profile silently persisted empty tool-call Locations.\n\nD1 — depend-not-copy. Delete the byte-identical evals copy of\nToolCallTrace/ToolStatusTransition; SAFE now uses the SAF runtime'\n[…]\nuteClassification). Delta\nacross the committed corpus: 1682 execute traces gain path scope, 0 ACP\nlocations overridden, 0 host verdicts change.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sidecar): unify ToolCallTrace + trustworthy Locations for the sid…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:41:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "62b4d995eb3c5b903de90bcd95e2f13b72cdf15d",
          "body": "…elog + friction dispositions\n\nMark ADR-0034 accepted and record what phases 1-2 actually built (core\nFailureClass/ghx.Error/ClassifyUpstream reading structured HTTP/GraphQL\nsignals; CLI class->exit-code mapping with the substring table deleted;\nthe three friction fixes with the byte-identical + no-\n[…]\npendency\nevidence). Add the [Unreleased] Fixed/Changed entries. Update the three\n2026-07-07 exit-code friction dispositions from open to fixed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0034 ACCEPTED + phases 1-2 implementation notes; chang…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:40:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae532a6d42bbed81fab70c22734ed73e4dcc931a",
          "body": "…rictions (ADR-0034 phase 2)\n\nThe CLI now maps FailureClass -> exit code + affordance by reading the\nghx.Error that core attached at the source (errors.As), instead of\nre-parsing English error strings. Deleted the duplicated upstreamRules /\nupstreamAffordance / upstreamError / ghxCoreError substring\n[…]\ny the two F2 cases (exit 0 -> 3 and 0 -> 1) change. No eval anomaly\ndetector or scorer depends on ghx CLI exit codes. Full suite + -race green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): source exit-code class from core; fix 3 dogfood exit-code f…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:37:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "64cedae193babc73ce6a6436ff8ec0d61b6007da",
          "body": "…(ADR-0034 phase 1)\n\nLift failure-classification into core so every frontend maps one shared\ndomain class to its own idiom instead of re-deriving it from English error\nstrings (ADR-0034 M2; W2's flagged fragility).\n\n- Add FailureClass (ClassNone/ClassNoResults/ClassBadInput/ClassUpstream)\n  mirrorin\n[…]\nor. Full suite green; the three friction commands render identically to\npre-change HEAD. Table-driven classifier tests added (failure_test.go).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ghx): core owns the FailureClass taxonomy + upstream classifier …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:36:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8828ff8c5a3e003562fd263c5418620a5b692b6",
          "body": "…conflation, not one number\n\nFollow-up to 9cc1c6f. Goga pointed at skills/ghx/SKILL.md as \"what I meant by\n400\" — which exposed that my previous edit fixed the NUMBER but not the\nartifact/level mapping, and I then briefly over-corrected the other way.\nGround truth, recomputed per file:\n\n- Level 1 (m\n[…]\n (this whole thread took ~4 recompute iterations to land one number —\nexactly why \"recompute the exact quantity, name the artifact\" is a rule).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skills): fix the persona-tax scope line — \"~400\" is a THREE-way …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:31:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9cc1c6fd4c321f2c4acf0a0759debd1a160f7526",
          "body": "…-forge\n\nRevisit both skills against the PA-0002 run we just executed (synthesis →\ncross-family OWED → discharged later → corrections folded → governing ADR).\nEarned tightenings, folded into existing sections (no new sections):\n\n- CORRECT a debunked figure the skill still carried: the \"~400-line\n  p\n[…]\nready covered), persona-count changes (5-persona scoped run worked),\nremovals for their own sake (density is progressive-disclosure reference).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skills): fold PA-0002 process lessons into product-audit + skill…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:23:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b5f5070ade2c16daeaf121503589d92dcd47e632",
          "body": "Sibling to the --path grammar-teaching fix; both surfaced dogfooding the\nPA-0002 competitive recon. Code landed in 75579aa.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record ghx grep -i + tree --path (v2.8.0 dogfood AX)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:12:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "75579aac12ec1f6a8c9cc0819e4a78410349ce71",
          "body": "…or subtree\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): ghx grep -i (no-op, grep-parity) + ghx tree --path alias f…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:10:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "63e75280337177088085170c709f80dfff48b80a",
          "body": "…ases 1-2)\n\nGoga accepted both 2026-07-07:\n- 0032.2 at full scope — Layer A (type unification + drop-fix) AND Layer B\n  (D4: argv-derived path-scope), since D2 alone leaves Locations empty at the\n  source for the sidecar's execute-driven recon (dogfood FRICTION.md finding 2).\n  Still measurement-tou\n[…]\nources class from core, fixes the 3 dogfooded exit-code frictions,\n  deletes the substring matcher). Phases 3-4 (MCP, sidecar) sequenced later.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): accept ADR-0032.2 (full: +D4 argv-derive) and ADR-0034 (ph…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:09:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "102f0ccec9116c7b90014bf24935a1ce7c0718e6",
          "body": "…off; PA-0002 cross-family DISCHARGED\n\nExecutes the PA-0002 decision (absorb codebase-memory-mcp's ENGINE, gated —\nnot the product; the EVAL precedes the integration) as a governing ADR, and\ndischarges the OWED cross-family adjudication debt.\n\nADR-0024.3 (pre-registered, NOT accepted):\n- local:cbm =\n[…]\ntus.go:41, tool_registry.go:132,\n  report.go:45) + tests; effort M, not trivial.\n- vendor headline is 120x fewer tokens (5 queries), not \"99%\".\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0024.3 local:cbm tier-2 backend + pre-registered bake-…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:07:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a78bcc37a16b0cc88644708d45404744570fc20",
          "body": "…ode-mode + --depth exit codes)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record v2.8.0 dogfood AX fixes (Snapshot surfaced, c…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T19:26:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7dd74e0c03396d793632b95d14fb3294bb0a1b71",
          "body": "…de fixes (v2.8.0 dogfood)\n\nThree clean agent-experience fixes from the v2.8.0 dogfood run\n(docs/dogfood/FRICTION.md, 2026-07-07 section). None touches the\nmeasurement-bearing sidecar report or internal/sidecar/evals.\n\n1. Surface Snapshot{Repo,SHA} to agents (ADR-0036 B2, agent-facing half).\n   read\n[…]\nnal/codemode);\nTestCodeTranspileErrorExitsBadInvocation, TestAskDepthValidationRejectsBogus,\nTestAskDepthValidationAcceptsValid (internal/cli).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): surface Snapshot SHA to agents; code-mode + --depth exit-co…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T19:25:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73fe6130b189d747e02074d1a4132d4018e2328b",
          "body": "… ask exits 0 on BLOCKED, etc.)\n\nLive dogfood of v2.8.0 on gjson/p-queue/attrs: depth dial, ADR-0036 B2 Snapshot\nSHA, and the ghx tree panic fix all confirmed working (resolves the prior\nexplore->exit-3 friction). 8 soft frictions, 0 breaking.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(dogfood): v2.8.0 friction log — 8 soft (Snapshot under-surfaced,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T19:04:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9d66038b39e3a624afdfc6819af79fb32dd43d1f",
          "body": "…ST H9\n\nJudge's synthesis of the reusable-core arch-audit (first run of the arch-audit\nskill). Verdict: DO NOTHING structural — the SAF<->SAFE core is a genuine,\ncorrectly-sized shared kernel (telemetry), no framework extraction warranted\n(north-star filter, one product). The one real finding — veri\n[…]\nnd-not-copy + flow Locations), recorded as TRUST H9, NOT fixed as a\ndrive-by. Advances C7 (trust ledger). Everything else watch-list or frozen.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): AA-0002 distillation + ADR-0032.2 pre-registration + TRU…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:45:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd2e63915bde087fcf8253b91b05723c222ad78b",
          "body": "… gated\n\nJudge-reconciled verdict on absorbing DeusData/codebase-memory-mcp. Distiller\ncross-validated every load-bearing fact (MIT license; arXiv 83%-vs-92%;\nshell-out seam at tier2/toolrun.go:53 + target src/main.c:9; existing tier-2\nbackends) and discarded the over-reaches as bones.\n\nDECISION: ab\n[…]\nrammar, code-search rate limit, GitHub-only blindness) -> A.\n\nCross-family (Codex) adjudication OWED (capped twice) before any go/no-go or ADR.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0002 synthesis + distillation — absorb cbm ENGINE,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:45:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "384742572b571d8547c88644a7a3aa6f53043568",
          "body": "Reusable-core extraction (.1), Go architecture & boundaries (.2), domain\nmodeling (.3), YAGNI skeptic (.4, adversary), duplication/coupling metrics\n(.5, opus fallback — GPT usage-capped). Convergent verdict: the SAF<->SAFE\ncore is a GENUINE shared kernel (telemetry), correctly sized — no framework\ne\n[…]\nction warranted (north-star filter). One real bug found: ToolCallTrace\nduplicated + convertSidecarTrace drops Locations (measurement-touching).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): AA-0002 persona artifacts (5) — reusable-core boundary run",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:41:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "abc56653454ef692e8490c1e67f419ab46af9c4a",
          "body": "…p? (5 lenses)\n\nScoped PA-2 audit (focus: should ghx absorb DeusData/codebase-memory-mcp\nentirely). Five read-only persona-agents, each dogfooding ghx to recon the\ntarget, converging from different angles:\n\n- .1 Competitive (generative): ABSORB-PARTS — the engine as a brain-gated\n  shell-out tier-2 \n[…]\nO; \"entirely\" rejected; absorb the ENGINE\nnarrowly as a gated tier-2 backend, MEASURED by a ghx bake-off first.\nCross-family adjudication owed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0002 persona artifacts — absorb codebase-memory-mc…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:37:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf39223adb04b8f0dfcb1d6fe5310159f84c920f",
          "body": "… evals<->product shared kernel)\n\nFirst arch-audit run under the new skill. Scope: internal/sidecar (SAF) <->\ninternal/sidecar/evals (SAFE) shared kernel + telemetry substrate. Trigger: the\nframework half of the north star + ADR-0036's runner port. Utility tree:\nreal-shared-kernel-vs-duplication > context-tax reduction > replaceability. Frozen\nmeasurement stack respected; YAGNI adversary mandatory; do-nothing is valid.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): AA-0002 charter — reusable-core boundary (SAF-as-infra &…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:27:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0a7ac7f06d88fddf08700dec040bc323c7fa16d1",
          "body": "Architecture hardening (ADR-0035 cleanup + ADR-0036 target architecture with the\nconfig-selectable Runner port) + main-agent ergonomics. User-facing: daemon\nconfig tunables, read --line-range alias, --path affordance, Snapshot{Repo,SHA}\nin read/explore, supervisor-hardened daemon, ghx tree malformed\n[…]\nonsolidated turn engine behind the Runner port, typed Depth/Tier/Backend, tool\nregistry) synthesized from the docs/audits/ architecture audits.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.8.0",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:24:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "606248ab068913b5212dd349c9632288b977ea0b",
          "body": "…rrections\n\nInternal evidence agent rendered BuildPersonaSystemPrompt() = 141 lines / 6,858 B\n/ ~1,714 tokens (exact), and caught two uncorrected judge errors. Fixed:\n\n- Judge-step provenance bullet no longer claims \"wc -l=350 contradicts 141\" —\n  the persona's 141 was RIGHT; 350 was my non-comparab\n[…]\nructurally blind to\n  the native Explore rival's own docs (needed a curl fallback).\n\nCross-family adjudication still owed on the High findings.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001.8 evidence ledger + decision-grade merge + co…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:23:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ef0b6ac2951f2904e2fb6c109cce1e1dc663455",
          "body": "…ews shipped)\n\nSkill-forge loop complete: Round-0 research (5 canons incl. the mandatory Wave-2\nre-pricing) -> Round-1 draft -> Round-2 adversarial review (craft / completeness+fit\n/ meta-redteam) -> Round-3 judge reconciliation (this commit) + provenance shipped.\n\nACCEPTED (verified against the rep\n[…]\nng security/CLI-versioning/supply-chain/observability lenses (R2 — anti-fit or\nalready-owned); FM-4/5 folded into FM-3, not separate additions.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill): arch-audit Round-3 reconcile + finalize (research + revi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:22:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9eab3e6f7173e7f85da547aa76539b5b365b1df1",
          "body": "Decision-grade external cross-refs for PA-0001: competitors, the native\nalternative, and absorption/OSS-inspiration — all deep hyperlinks verified\n(14 repos, 9 file paths, 3 external URLs resolve).\n\nCorrections fed forward:\n- Claude Code Explore is NO LONGER Haiku-by-default (v2.1.198 inherits main\n\n[…]\ns the one ghx can't reconnoiter.\n\nTop absorption anchors: codebase-memory-mcp knowledge graph, repomix --compress,\naider repomap.py (PageRank).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001.7 external & OSS-inspiration cross-references",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:18:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "332d0e3cbd9a528062038ec28efe746a82346c55",
          "body": "…avior-identical (ADR-0036 C1)\n\nDefine the harness-neutral Runner port in package sidecar (runner.go: Runner/\nSession/TurnRequest/SteeringSpec/EventSink/Outcome/FailureClass) and make the\nclaude-agent-acp path implement it (acprunner.go): the string-matchers become an\nadapter-internal Outcome mappin\n[…]\nsidecar suite\npasses UNMODIFIED incl. -race (byte-identical proof); the agent that wrote this\ndied pre-commit and Fable salvaged + verified it.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): introduce Runner port; ACP path implements it, beh…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:16:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "004489e8b138a01e49ed0e342132ee6b7491f3bb",
          "body": "The reusable kernel from product-audit's evidence-ledger lesson: sourcing\ndiscipline was strong on the research INPUTS but never reached the OUTPUT, so a\nconclusion could ship as evidence-free prose.\n\n- Guardrail: conclusions aren't decision-ready without consolidated receipts —\n  the same sourcing \n[…]\ndence\n  ledger.\n\nLeft in product-audit (not copied): the specific evidence classes\n(source/strategy/experiment) and the OSS-absorption framing.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-forge): generalize \"decision-ready = consolidated receipts\"",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:16:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "412b151197782f950ffbed009022b7f9459868d9",
          "body": "…nce ledger\n\nFindings were decision-shaped but not decision-READY — conclusions without the\nreceipts. Fix the workflow so evidence spans every class and is consolidated:\n\n- New synthesis output: \"Evidence & cross-reference ledger (decision-grade)\" —\n  per top finding, consolidate SOURCE (file:line +\n[…]\na was inspired or\n  absorbed, as a SPECIFIC deep hyperlink (never a bare homepage), verified.\n- Delegation template updated to demand the same.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): require a decision-grade evidence & cross-refere…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:12:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7dcfc789dc3d94bf4ff6ffe2d9d79dcf189ee189",
          "body": "…anon\n\nAuthoring pass (skill-forge Round 1) on the fork's draft, folding in the sourced\nresearch: an ATAM utility-tree front-end to the charter (rank quality attributes\nper scope); complexity x git-churn hotspots + gocognit for the metrics persona\n(not just gocyclo); adversaries run as premortem/Tea\n[…]\nESS FUNCTIONS (committed CI checks)\nso boundaries don't drift back between audits (anti-shelfware). Provenance now\npoints to research/ ledgers.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill): arch-audit Round-1 revision — fold in Round-0 research c…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:04:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf1882ed646a19f942262322b429194bf10e1bf6",
          "body": "…(4 canons)\n\nskill-forge Round 0 for the arch-audit skill: idiomatic-Go architecture (R1),\nclean-architecture/DDD/reusable-core (R2, Shared-Kernel framing for evals<->product),\ntech-debt detection & metrics (R3, complexity x git-churn hotspots + Go tooling),\narchitecture-audit methodology (R4, ATAM \n[…]\nLM self-preference judge guardrail). 66 deep-URL sources total, degradations\ndisclosed per Source Ledger. Provenance for the SKILL.md revision.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-research): arch-audit Round-0 sourced research provenance …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:01:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d047dff48418b820b75d907cb7157d7d538eabf",
          "body": "…tech-debt audit loop\n\nA repeatable loop for raising ghx's maintainability -> engineering velocity:\npick a scope (whole codebase / module / reusable capability like the Agent\nSidecar Framework or the evals<->ghx shared core / a cross-cutting mindset),\nfan out 4-6 background personas (>=1 adversarial\n[…]\nstack\nrespect, north-star filter / no cathedrals, forward-looking agentic-first lens,\nff-only integration (never --amend on a shared mainline).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(skill): arch-audit — scoped multi-persona architecture/codebase/…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:49:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1bcf73bcfb58db5b7b2e43d5ce4a4a8281e44215",
          "body": "…-picture rule\n\nPort the reusable parts of the founder's audit-workflow guidance into the meta-\nskill (leaving product-audit-specific bits in product-audit):\n\n- Convergence & distillation is now a first-class step: a loop-table row\n  \"Distil (conditional)\" + a dedicated section. When the deliverable\n[…]\nncile: \"no\" outcomes extend to concluding the premise is wrong or that a\n  canonical source has gone stale and should be flagged for evolution.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-forge): generalize the convergence/distillation pass + big…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:40:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ae128db9cbb634f697afdb2a949411822129cfe",
          "body": "Convergence & distillation pass (Process step 8) mined the intersection and\ncross-validated against the codebase; orchestrator judged it.\n\n- Convergence re-scored by the shared-prior rule: H2's \"two personas agree\" is\n  shared-prior (both read corpus-discrimination) — its signal comes from the\n  dis\n[…]\n.\n- Bones vetoed: Explore-commoditizes over-reach; SPT \"value-free\" label; SPT\n  non-load-bearing; L2 M8. Cross-family adjudication still owed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001.9 distillation + judge verdicts; close the loop",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:31:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d31efb8a8e1b1402938e0636d6ee246bd270ab2",
          "body": "…(dogfood F3)\n\nDogfood friction F3 (docs/dogfood/FRICTION.md, 2026-07-07) reported a live\n401 on `ghx search` printing the bare \"search failed: HTTP 401: Bad\ncredentials (...)\" with no fix-it affordance. That was a stale-binary\nartifact: the friction binary was v2.6.0 (e8816ec), which predated the A\n[…]\nto 2 and fails the test.\n\nExit codes 0/1/2/3 unchanged. No errors.go change was needed (the 401 rule\nalready exists). Scope: internal/cli only.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): live upstream 401/auth errors name the 'gh auth login' fix …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:29:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d2d2858513aa30eadab03a5bfc9b1193159c903",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(review): independent review of ADR-0035/0036 refactors",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:28:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3ae3c6b9d42fb434499aed7210fae7a2919e08b4",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): runner-adapters integration spec (codex-acp + claude-sdk)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:28:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "98492fb7940ab066d6a3bd2cd3b9c95fecbc917c",
          "body": "The process retrospective caught the judge (me) comparing prompt.go's 350\nwhole-file lines against the persona's ~141-line RENDERED doctrine — two\nnon-comparable quantities. Re-derived: the recon doctrine is\nBuildPersonaSystemPrompt() (prompt.go:37), ~130-141 lines; the file also holds\nBuildDiscover\n[…]\nd; my dismissal\nwas itself the evidence-drift the new PF1 rule (recompute the exact quantity via\nthe finding's own command) now guards against.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): correct PA-0001 L1 — self-caught evidence-drift (PF1)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:27:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6ca4267f4692bc1ae0e96c51e29073ecbcfa609",
          "body": "…eword by specific id, ff-only landings\n\nGoga 2026-07-07 after the amend incident: parallel engineers may be committing\nto mainline in the same tree. Appends are safe; history rewrites are the danger.\nRules: never `git commit --amend` on mainline (it rewrites whatever HEAD points\nat, which may be an\n[…]\n CAS update-ref (never rebase a shared tree holding others'\nuncommitted files); land worker branches by ff-only (retry on race, never\ncorrupt).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(claude): git hygiene on a shared mainline — never blind-amend, r…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:27:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1c3037bef62b67f61757397a66fdb3620e57794",
          "body": "…posture, PF1/2/3\n\nFounder guidance + the PA-0001 process retrospective, folded in:\n\n- Process step 8 — Convergence & distillation (final pass): a fresh no-stake\n  agent mines the intersection of the fan-out; GENUINE cross-persona convergence\n  = high signal, shared-prior convergence discounted; dis\n[…]\ne-drift), order accepted findings by\n  leverage not severity alone.\n- skill-forge: convergence/distillation pass noted for multi-agent outputs.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): convergence pass, north-star-is-auditable, 2026 …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:27:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee62a610d950ac1d8554b0ca405b9b2176feff97",
          "body": "…e live run)\n\nIndependent review of the audit PROCESS as executed. Caught the orchestrator's\nown judge-step error (compared whole-file 350 lines vs the ~141-line rendered\npersona doctrine — non-comparable) and proposes: PF1 recompute the finding's\nexact quantity via its own command + cite by symbol/\n[…]\nred citability-gated field. Credits what the process did well (genuine\nre-derivation, named shared-prior caution, blocking cross-family state).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): PA-0001 process retrospective (meta-review of th…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:24:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dec217df201fac52af476689ed8cb63e51dec50f",
          "body": "…1.6)\n\nCodex (cross-family) was usage-capped, so per directive 5 a fresh no-stake\nClaude adjudicator re-derived C1-C5 from raw files (partial mitigation;\ncross-family still owed). It confirmed the spine of all three High findings and\nsharpened four, folded into an \"Adjudication outcome\" section:\n\n- \n[…]\nt).\n- M3 severity -> Medium.\n\nStatus: High findings self-verified + same-family-adjudicated; cross-family\ncheck still owed before any go/no-go.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001 judge step — same-family adjudication (PA-000…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:19:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03601262243b2e208e34aff7074a4084bf1acf10",
          "body": "…judicator fallback\n\nFounder guidance (2026-07-07): an audit needs a declared focus, not a\nfrom-inception sweep every run — but scoped != narrow-minded.\n\n- New Prime Directive 6: every audit declares a focus/attack surface (a\n  milestone/feature/goal/vision/surface); do NOT re-audit the whole produc\n[…]\nmitigation (removes stake/shared-context bias, not same-family bias);\n  flag findings checked only same-family. Same note added to skill-forge.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): require a scoped focus/attack-surface; Claude ad…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:13:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14660c8aa9a20cf7882540ead366971c0028113b",
          "body": "Orchestrator synthesis over the 5 persona artifacts. Judge step: Fable\nre-derived every load-bearing fact from raw artifacts (plugin.json,\ncorpus-discrimination table, report.go schemaVersion, handleRecon, prompt.go\nsize — which contradicted a persona's \"141 lines\" claim, rejected); competitor\nrepos\n[…]\nlus M1-M4, L1-L2, a strong \"what is actually fine\" (eval honesty; brain works\nlive, HIC 0), absorption candidates, and adjacent-idea proposals.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001 synthesis — judge-reconciled ghx product audit",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:33:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "18f6170f9138f44f45824a1149758af374b0b2ae",
          "body": "First real run of the product-audit skill on ghx. Five read-only adversarial\npersona-agents (opus), each a threaded PA-0001.k artifact under docs/product-audit/:\n\n- PA-0001.1 Agent Experience — default install ships the heavy CLI skill,\n  inverting \"zero ghx knowledge\"; read-of-missing-repo returns \n[…]\nalready say.\n\nSynthesis (PA-0001) follows after orchestrator judge step: self re-derivation\n(done) + Codex cross-family adjudication (running).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001 persona artifacts (live product-audit skill run)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:29:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03e24be20e5a2eba0ecaa7ba0c95a48e9a0be903",
          "body": "… ADR-threaded\n\nProduct audits now live in docs/product-audit/ (kept separate from the code\naudits in docs/audits/), numbered and threaded like ADRs: a round is PA-000N\nwith per-persona artifacts PA-000N.k-<persona>.md and a PA-000N-<focus>.md\nsynthesis. Establishes the convention the first live run (PA-0001) uses.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): output convention — docs/product-audit/ PA-000N,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:16:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e0a37499198097586782c90f33ae20579ba49613",
          "body": "Captures Goga's steering (2026-07-07) in the two places asked:\n\nAGENTS.md (Open Source Leverage tenet) — two binding rules:\n- Competitive analysis is generative, not defensive: study of OSS/real-world\n  competitors never triggers retreat; it doubles down on our advantages and\n  surfaces things to AB\n[…]\nlement, not just threat lists); the delegation template + process now dogfood\nghx for any GitHub/OSS exploration and log friction as a finding.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: competitive analysis is generative; dogfood ghx for exploration",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:10:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "acd5fb1e7cb27e42e7f892a92e858cfb8da4abf1",
          "body": "…ct 07)\n\nRound-4 steals (Picasso, with attribution), the one bounded change the recon\njustified — convert two umbrella scopes into checklists:\n\n- Phase 6 gains axprobe's AX report contract (goal_reached, human-intervention\n  count, false_errors, a 5-class friction taxonomy) and its weak-driver metho\n[…]\nmiss trace-mining; Evals\n  scope gains deepeval's agentic sub-metrics.\n\nDeclined: a third (DX) consumer axis and ax-audit's web-crawler rubric.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): absorb AX-tooling rubrics from OSS recon (artifa…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:09:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "321e2f9857be3a92b3ad326944ab3632dd96d99f",
          "body": "… recon",
          "is_bot": false,
          "headline": "docs(product-audit): research artifact 07 — OSS PM-agent / AX-tooling…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:08:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "230882b70499214602e8ada6eeee7b08cc35d980",
          "body": "…ctions\n\nUpdate TRUST.md hole H7 (ceiling effects) with the workstream-C7 corpus-\ndiscrimination finding: the corpus's discrimination power rests on only 2 of\nits 6 tasks (express-router-location, openai-node-streaming); gin/hono/flask\nsit at ceiling and ghx-mapengine is contamination-confounded, wi\n[…]\nDR-0032.1 (S2 fix is on HEAD; the execute-kind nuance remains).\n- F5 (token metric undercounts) = OPEN, folds into ADR-0036 Phase D real-token.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(trust): update H7 from corpus-discrimination; triage dogfood fri…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:07:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cdb81ae65da59cae31de4bcf6236dbf2c3335d19",
          "body": "…le validators (ADR-0036 B3)\n\nReplace stringly-typed Depth/Tier/Backend usage in the sidecar with value\ntypes (depth.go/tier_value.go/backend.go), each with one canonical parser/valid\nset, consumed by session_options/tier/reportsink/tool_registry and the CLI/MCP\ndepth boundary. Each frontend's curre\n[…]\ntity untouched: the\npersona, backend-ID, and TierUsed goldens pass unmodified. AskRequest keeps\nstring/[]string at the public boundary for now.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): introduce Depth/Tier/Backend value types with sing…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:02:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e4d7a1f6d2033a16daab7c9cec14ad42d349fde2",
          "body": "…(ADR-0036 B2)\n\nAdd ghx.Snapshot{Repo,SHA} and record the commit oid a core read actually\nresolved (defaultBranchRef.target.oid) as an additive field on read/explore\nresults, so evidence surfaces which commit was read and two reads in one\ninvestigation can be checked against a moving HEAD. Phase 1 is\nobservability-only — additive, behavior-preserving; pinning reads to the SHA is\ndeferred to an ADR-gated Phase 2.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ghx): capture the resolved commit SHA into read/explore results …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:00:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c0381bdc32bfdbaf7e5cfb41dd515cc357146a57",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record daemon supervisor hardening (ADR-0036 A1)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:55:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2870137cf40f600e2a51f518f6cbf073c53afdd",
          "body": "… propagation, graceful drain (ADR-0036 A1)\n\nThree reliability fixes to the resident daemon (resilience audit H2/H3/M1):\nper-request recover() so one turn's panic returns a JSON-RPC error to that\ncaller instead of killing the daemon and all warm sessions; request-scoped\ncontext + connection-closed w\n[…]\norker); signal-aware graceful drain implementing ADR-0030 D6.\nBehavior changes only on failure/shutdown paths; +181 lines of tests; race green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sidecar): daemon supervisor hardening — panic isolation, context…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:53:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "396e7912f08d1aefdd800cdfaa45dc1d89fe8d19",
          "body": "…t the edge (ADR-0036 B1)\n\nCore recon ops (Explore/Read/Tree/Repos/Glob/Search) now RECEIVE a typed\nghx.Repo instead of re-parsing an owner/repo string internally; ParseRepo runs\nonce at the CLI (ghx.go) and MCP (serve.go) edges. \"Parse at the boundary,\nflow the type inward.\" Behavior-preserving for\n[…]\nll surfaces the \"invalid repo\" substring so a bad slug maps to exit 2.\nCodemode wrappers keep string parsing (they are the JS string boundary).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(ghx): thread ghx.Repo across the core boundary; parse once a…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:51:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bec5b3af1662221817ccf659843c4636cce971e2",
          "body": "…-0 step\n\nEncodes the run's own top lesson: the contrarian \"does this wisdom hold in OUR\ncontext?\" lens must be a standing default, not an angle you hope to notice.\nRound 0 is now two waves — wave 1 maps the canon, wave 2 is a mandatory agent\nthat reads the wave-1 artifacts and audits them (HOLDS/AD\n[…]\n the worked example this pass\n(the agentic-first lens) was the single highest-leverage step and only happened\nbecause it was caught mid-flight.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-forge): make the context re-pricing pass a mandatory Round…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:48:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aacb58b40c02a815ae943afac9c08ee92e510920",
          "body": "…ewed skill creation\n\nCodifies the loop that produced .claude/skills/product-audit: Round 0 wide\ndelegated research (distinct angles incl. a contrarian/\"does the wisdom hold in\nour context\" lens) -> Round 1 orchestrator authors the draft (authorship not\ndelegated) -> Round 2 adversarial review on di\n[…]\n76) by verifying\nload-bearing claims and cross-family-checking the highest stakes. Owns the loop;\ndefers command mechanics to fable-delegation.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(skill-forge): meta-skill for research-driven, adversarially-revi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:31:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0ac85f2a7fce45c45fc88766177f385c53388532",
          "body": "… reviews\n\nCritically reconciled R1-R4 (accepted the verified/high-value subset; declined\ncargo-cult and scope-creep). Changes:\n\n- Judge independence (R4-F1): directive 5 + Process step 5 now require, for\n  High/thesis-invalidating findings, self re-derivation + an independent\n  cross-family check (\n[…]\nd: reliability-as-its-own-lens (covered by AX/token-econ; SRE-adjacent)\nand full Tier-B->AX-pillar collapse (kept distinct as more actionable).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): round-3 revision — incorporate the 4 adversarial…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:30:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f17053982ec72fcac82f07af4eac6e4c0c04ea44",
          "body": "Four independent critiques of the draft skill, each a ranked, DH5/DH6,\nseverity-tagged review with an honesty guard and specific-URL sourcing:\n\n- R1 skill-craft: run-spine buried past the token-retention line; ship a\n  copyable persona-delegation template; cut the anti-pattern self-tax.\n- R2 pm-comp\n[…]\nvals.\n  Cap scopes/surfaces, route dispositions to ADRs/workstreams. Net: keep.\n\nRound-3 revision incorporating the accepted subset lands next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): round-2 adversarial review artifacts (4 reviewers)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:28:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1de230b981a6750ff95c4d7781b31903a448db4",
          "body": "…ot, domain flow (synthesis of 5 vision audits)\n\nStrategic architecture ADR (ADR-0035 was tactical). Four decisions: (D1) a\nconsumer-defined Runner port in a leaf internal/sidecar/runner package so the\nagentic runtime is a config-selected adapter — claude-acp / codex-acp /\nclaude-sdk (in-process ant\n[…]\non-rewrite: A foundations, B domain, C runner port (supersedes ADR-0035 item\n5), D the SDK runtime (ADR-gated, changes token source). PROPOSED.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0036 target architecture — Runner port, composition ro…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:26:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8bdbe482af1dff1d4c921e40fd8dd8bceb3674a1",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): runner port & pluggable runtimes — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:23:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "479749e684812f91a0ec0d18a7df2aaf07ee1d6d",
          "body": "Idiomatic-Go package-architecture audit (Ben Johnson Standard Package\nLayout, Go Proverbs, Kat Zien) building on ADR-0035 and the five\n2026-07-07 audits. Answers Goga's singletons-vs-services question,\nidentifies the missing composition root (H1) and the core->codemode\ndependency-direction edge (H2), and proposes a concrete non-rewrite\ntarget layout + phased sequence toward P3/P4. Read-only; no code changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): Go architecture & boundaries — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:22:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "167d20d6c5ef3b3821e074f5e87ae3381cc3ce73",
          "body": "Read-only reliability/runtime audit of ghx under failure. Maps the current\nresilience architecture (ADR-0027 wrap-up/watchdog/stale-session/peer-closed/\nreport-retry, the acp.go marker strings, the ADR-0034 proposed failure-class\nmodel, and the B4 eval-anomaly derivation from persisted error strings\n[…]\n-layer target that preserves the frozen marker contract, and\ngives a phased non-rewrite sequence. No code changed; measurement stack untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): resilience & runtime robustness — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:20:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a54fba38a708f841460f9670798e67456a04c46a",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): domain model & ubiquitous language — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:18:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "778b2aea9d26427daee2a6744bedd5168161daa3",
          "body": "Adds .claude/skills/product-audit/SKILL.md — an orchestrator playbook for\nauditing ghx from the product-manager lens: adversarial PM personalities ×\nscopes × surfaces, grounded in the north star, agentic-first (primary consumer\nis an AI agent, so classic PM advice is re-priced HOLDS/ADAPT/INVERTED b\n[…]\nope boundary (defers code/security/eval-mechanics to their homes);\ncargo-cult anti-patterns; report output contract matching docs/audits style.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): draft the product-audit skill (round 1)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:15:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a2a8d462ffeea39e42751d93483a61b148bfca4",
          "body": "…tique [AA5]\n\nCounterweight persona (GPT-5.5): argues against over-engineering ghx as a solo\nGo product. Thesis: keep the bug/testability fixes, add only a narrow runner\nseam, reject core/shared/domain layering and framework extraction until a\nsecond runner implementation proves the shape. Grounded in Go Proverbs / Go\nCode Review Comments / Ben Johnson standard package layout.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): adversarial YAGNI skeptic — minimal-path architecture cri…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:12:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "65e0695b170ca2378b5b0f54ac58cf7b36cbccfd",
          "body": "… pivotal]\n\nAudits the classic-PM corpus (01-05) for a product whose primary consumer is\nan AI agent, not a human. Labels each load-bearing framework HOLDS / ADAPT /\nOUTDATED-OR-INVERTED, grounded in 13 agentic-first sources (5 Anthropic\nengineering posts, the MCP spec, OpenAI function-calling, Biil\n[…]\niability)\n- what still HOLDS: outcomes-over-output, JTBD, 7-Powers, red-team stack,\n  four-big-risks, PM craft/personas, market/business scopes\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): research artifact — the agentic-first lens [6th,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:12:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "67ae414131bbe8b45295996c77ff699681299ad2",
          "body": "…stry (ADR-0035 T2.4)\n\nDefaultToolRegistry() is now the single source of truth for the sidecar's\ntool set; the persona menu (prompt.go), backend vocabulary/local-backend\nchecks (tier.go, reportsink.go), and CLI backend IDs (cli/tier2.go) all derive\nfrom it instead of scattered hardcoded lists. Perso\n[…]\nPersonaByteStable, golden unchanged); backend\nidentity string pinned additively. P3 tool absorption's identity surface is\nnow one registration.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): centralize the sidecar tool set in a ToolSpec regi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:10:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1bda8848e7e5469c32ac3d413c94fa7c30a2a9f5",
          "body": "…ial red-team [5/5]\n\nCompletes the Round-0 research corpus for the product-audit skill.\n\n- 02-pm-personalities.md: 15 audit-persona blocks (worldview / optimizes-for /\n  signature questions / blind spots / what-good-looks-like), each grounded in a\n  named authority (Perri, Torres, Verna, Chu, Fourni\n[…]\n\nAn agentic-first lens artifact (06) — auditing this classic-PM advice for a\nproduct whose primary consumer is an AI agent — is in flight next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): research artifacts — PM personalities & adversar…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:02:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "43ea6e9f03c9ef87eca1a094b77c7ddf58bb7048",
          "body": "…s, strategic scopes [3/5]\n\nSourced provenance for the forthcoming product-audit skill. Each artifact\ncarries specific deep-URL citations with per-claim rationale; degradations\n(paywalls, 403s, unOCR'd scans) are disclosed in-document, not smoothed over.\n\n- 01-pm-excellence.md: PM competency models,\n[…]\n,\n  north-star alignment, gaps, adjacency, monetization, moat); 31 refs.\n\nPersonalities (02) and adversarial red-team (05) artifacts land next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): research artifacts — PM excellence, audit method…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:57:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26ae9ef442509838e0ca416a0a7b041e0224cfd7",
          "body": "…thTurnRunner (ADR-0035 T1.3)\n\nThe one-shot (acp.go RunTurnWithOptions) and warm (daemon_worker.go\nAgentWorker.RunTurn) paths duplicated the liveness watchdog, the four-way\nprompt select, and NewSession/LoadSession meta re-assertion. Extract one shared\nturn primitive (turn.go: startACPWatchdog/confi\n[…]\ntural refactor — ~244 lines of duplication removed; the full sidecar test\nsuite passes UNMODIFIED, incl. -race (byte-identical behavior proof).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): extract shared ACP turn primitive; decompose askWi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:54:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b972c4b157bcdcc34fcb21add786c6018a0c44a5",
          "body": "…e core recon (ADR-0035 T1.2)\n\nCore ops (explore/read/repos/glob/search) newed up api.DefaultGraphQLClient()/\nNewRESTClient() inline, so no test could exercise a network path. Introduce\nminimal graphQLDoer/restGetter interfaces + a package-level githubClients\nprovider (defaults to the real go-gh clients) that tests override. Public\nsignatures and CLI/MCP behavior unchanged; adds an offline fake-client test\ndriving Explore with no network.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(ghx): inject GitHub client behind a seam for offline-testabl…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fc889fe7cc6eacd6c6abee9e2376a19a9cc90ccf",
          "body": "…-0035 T1.1)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record ghx tree/explore/read malformed-slug fix (ADR…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:46:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9e4a10e427488d38bd7e3df43eaab15e06497a4c",
          "body": "…formed slug (ADR-0035 T1.1)\n\nUnify the three divergent owner/repo validators (explore/read/inspect/glob)\ninto a single ghx.ParseRepo. Fixes a real crash: `ghx tree noslash` panicked\nvia an unchecked slice index (glob.go); it now returns a clean bad-input error\n(exit 2). explore/read/tree route core\n[…]\nrepo maps to exit 2 instead of exit 3 (also fixes dogfood friction F1).\nBehavior-preserving for valid inputs; ParseRepo + no-panic tests added.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(ghx): introduce Repo value object; fix ghx tree panic on mal…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:45:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e92633d13d77a364900c3fff2660dc3dee2dd63",
          "body": "…uence (synthesis of 5 audits)\n\nConsolidates the original architecture audit + 4 new adversarial audits\n(design-patterns, complexity-metrics via GPT-5.5, coupling/testability,\nroadmap red-team) into one ranked, tiered refactor sequence. Ranks by\ncross-auditor convergence x impact x tractability. Eva\n[…]\nots\ndeferred behind a pre-registered eval ADR (frozen-measurement rule);\nframework extraction rejected now per the north-star filter. PROPOSED.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0035 architecture hardening — prioritized refactor seq…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:38:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b39ffa542a5302617ccade0d4c86c46054bf1bb4",
          "body": "Read-only contrarian audit ranking tech debt by velocity-cost against the\nP3/P4 roadmap. Companion to architecture-2026-07-07.md; does not repeat its\nactioned findings (acp.go split; ADR-0034 failure taxonomy).\n\nFindings (ranked by 1-3 month velocity-cost):\n- V1 (High): no sidecar tool registry — P3\n[…]\n won't move; domain models are portable), a recommended sequence,\nand a Method/auditability section. Every file:line verified; no code changed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): adversarial velocity red-team — roadmap-blocking tech debt",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:35:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf3428c69d5dae7132d73d9330bbc3fbb21f19db",
          "body": "Read-only audit through the coupling/cohesion/testability lens. Two High\nfindings: core recon has no GitHub-client injection seam (Explore/Search/\nRepos/Read/Tree untestable without live network), and the ACP turn engine is\nduplicated across acp.go + daemon_worker.go (plus two eval copies). Mediums:\n[…]\nDigest + dropped request context in daemon dispatch. Matches the\narchitecture-2026-07-07 audit format; cross-references rather than repeats it.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): coupling / cohesion / testability audit — ranked refactors",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:34:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b1051861ed9db486658dbd3373e3857ec52c144",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): design-patterns & domain-modeling audit — ranked refactors",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:34:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5b731289b1f1879fa046e5f3ebe4561caa676df0",
          "body": "…near history)\n\nGoga 2026-07-07: the per-worker `git merge --no-ff` left a merge bubble per\nephemeral branch, making the log noisy. New rule (AGENTS.md \"Integrating\nDelegated Work\" + fable-delegation skill): workers commit-and-stop on their\nbranch; the orchestrator lands each branch by rebasing onto mainline and\nfast-forwarding — no squash (each worker commit preserved), no merge commit.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agents): land delegated work by rebase+ff, not merge commits (li…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:34:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4d521467e486d500b2174aeb99e0a865e81aefda",
          "body": "…efactors [AUD2/codex]\n\ngocyclo/wc/fmt.Errorf pass. Top new debt: askWithTurnRunner cyclo 40\n(runtime.go:273); CLI inline RunE god-files; repeated MCP handler plumbing;\nRead control-density; repomap buildEdges. Eval hotspots flagged ADR-gated.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): complexity & maintainability metrics hotspots — ranked r…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a13187f0b15aa85141161ae25255775e188fb6fd",
          "body": "…ocations\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(dogfood): friction log 2026-07-07 — depth dial + affordances + L…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ff43a4d6824bc091543da943c5441f0e8bdf4ca1",
          "body": "…--path affordances (W1/W2); fix stray XML in failure-class audit\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record daemon config tunables + read --line-range / …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "262e7764201ed330bac36f38ddc058495e84d6e1",
          "body": "… directly, never a parking sub-agent\n\nIncident 2026-07-07: a Claude sub-agent (isolation: worktree) that launched\ncodex as a background job then parked raced the worktree GC — the harness\nauto-cleaned the \"unchanged\" worktree out from under the running codex, losing\ntwo delegations. Rule: run `codex exec` directly from Fable's own session into\na hand-created (non-harness) git worktree; Fable verifies/commits/merges.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill): capture background-codex delegation rule — run the shell…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6d4d9873f83f6c5a6eb865a928066cdd457a01e6",
          "body": "… explore/search (A2/A4)\n\nMined from production/eval traces: agents type `ghx read --line-range` (real\n`unknown flag` failure in ~/.ghx/sessions/letta-ai-letta/logs.jsonl) and\n`--path` on explore/search. Add --line-range as a hidden alias of --lines\n(byte-identical output, conflict-checked), and teach the unknown-flag\naffordance to name the correct invocation for --path on explore and search.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): read --line-range alias for --lines; --path affordance for…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c2bf8df98c9f7c858428a6c03f2540cf2cb05cd5",
          "body": "…d config (ADR-0030 follow-up)\n\nTwo daemon runtime tunables that were hardcoded (30m warm-worker idle TTL,\ncross-session concurrency 4) become optional ~/.ghx/config.json fields:\ndaemonWorkerIdleTTLMinutes and daemonMaxConcurrent. Nil preserves today's\ndefaults byte-identically; <=0 is rejected with a field-named error; both\nparticipate in ConfigDigest so a running daemon stale-replaces on change (D6).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sidecar): expose daemon idle-TTL and max-concurrency as validate…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f6134a44aec3318d57f9aeabc8c0ada2910d0def",
          "body": "…DR-0034)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): failure-class inventory across frontends (evidence for A…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b5364fabfffc2750f6aa7f29b64396ee8a95d7ae",
          "body": "… (C7)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(evals): corpus discrimination analysis toward H7 ceiling refresh…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2cda8a3553dfe379f33dd60c72baf1daa97ca57",
          "body": "Main-agent ergonomics + architecture/eval-trust hardening: MCP recon depth\ndial, CLI error affordances, host-task eval corpus (ADR-0032.1 S1-S4),\nToolCallTrace.Locations populated from ACP notifications, acp.go god-file\ndecomposition, ADR-0034 failure-class model (proposed).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.7.0",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:09:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4d9a3e1103e5b7414e065893b4e5be4406f653a5",
          "body": "…on on release\n\nGoga: maintain a changelog for each version — captured as a standing rule in\nAGENTS.md (Changelog section + Release Flow step 1).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agents): require a changelog entry per user-facing change; versi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:08:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "47e2b7cce522a589c56fd405cd3d41672504841d",
          "body": "…affordances, host-task corpus, Locations fix, acp.go/callTool cleanup, ADR-0034)\n\nMakes the 20 commits staged since v2.6.0 reviewable ahead of the next release.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): document staged Unreleased changes (depth dial, CLI …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:31:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5aec071e22dede01633a4455d090ed1564ec6ecc",
          "body": "…ifications (ADR-0032.1 S2)\n\nToolCallTrace.Locations was declared and JSON-tagged but never written, yet\nthe host-task attribution classifier reads it for rule R6 (path-scope of\nread/edit/delete/move/search tools). The R6 detector ran on always-empty data\nand reported false-clean — a visibility/trut\n[…]\n it now lives in denyclient.go after\nthe acp.go decomposition, so the change was re-applied there rather than\nmerged from the stale-base branch.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sidecar): populate ToolCallTrace.Locations from ACP tool-call not…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:15:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "de3f7ad117f5ec4f52c8e20b9e63c928f9dd94d7",
          "body": "…POSED; audit M2)\n\nLift failure-class from the CLI frontend into core internal/ghx so MCP\n(16 opaque NewToolResultError flattenings) and the sidecar report (83\nad-hoc fmt.Errorf) can map from one taxonomy — makes the A4 recovery\naffordances universal, not CLI-only. Proposed autonomously; cross-frontend\nrefactor awaits Goga acceptance before build (phased migration registered).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0034 unified failure-class model across frontends (PRO…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:11:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a49ce76fd4cdcc7e77300e93ecca11c1f5471ebb",
          "body": "…dit H2; pure relocation, byte-identical)",
          "is_bot": false,
          "headline": "merge: decompose acp.go god-file into cohesive sibling files (arch au…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:03:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d3294820980f3915cec8fc2ab1bc80bd8e1f9c5",
          "body": "…(audit H2)\n\nPure code-organization refactor of the 1012-line internal/sidecar/acp.go\ninto intent-revealing sibling files in the same `sidecar` package. Moves\ndeclarations verbatim — no renames, no signature/logic changes. Verified\nbyte-identical: every meaningful code line in the original appears e\n[…]\nd ShutdownAgent.\n\ngo build ./..., go vet ./internal/sidecar, go test ./internal/sidecar/...,\nand go test -race ./internal/sidecar/... all green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): decompose acp.go god-file along its concern seams …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:03:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73d092deb9ea1f6421e57971884696a7d0264d87",
          "body": "…pability-3]\n\n# Conflicts:\n#\tinternal/sidecar/recontool.go",
          "is_bot": false,
          "headline": "merge: expose depth dial (cheap|normal|deep) on MCP recon tool [B2/ca…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:01:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3765cd44de59cd7a9015e3ab31bc0f1297b193a6",
          "body": "…TAR cap 3)\n\nThe CLI has `--depth cheap|normal|deep` but the MCP recon tool hardcoded\ndepth=\"normal\", leaving the main-agent consumer path unable to steer recon\nbudget. Add a `depth` param to ReconMCPTool and forward it through the same\nAskRequest.Depth field the CLI uses (session_options.go depthBu\n[…]\nr.ReconMCPTool())). The eval tests\nassert hash recomputability + shape, not a frozen value, so they stay green\n(TestMockHostTrialArmB verified).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sidecar): expose recon depth dial on the MCP recon tool (NORTH_S…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T06:59:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45d4ee2c51524aacf1a28a8ebd0a8f06e827e2c9",
          "body": "…lices complete; docker grader + ≤5-ep smoke owed on a docker machine\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0032.1 S4 implementation note — corpus landed, all 4 s…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "66e0e67261b2d985d872ed71b9979cb35c85af00",
          "body": "…ement (ADR-0032.1 S4)",
          "is_bot": false,
          "headline": "merge: host-task eval corpus S4 — 6 verified fixtures + canary enforc…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T06:55:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 37,
      "commits_last_year": 598,
      "latest_release_at": "2026-07-08T02:49:04Z",
      "latest_release_tag": "v2.9.0",
      "releases_from_tags": false,
      "days_since_last_push": 8,
      "active_weeks_last_year": 12,
      "days_since_latest_release": 20,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/gkoreli/ghx/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/gkoreli/ghx/v2",
          "is_deprecated": false,
          "latest_version": "v2.9.0",
          "repository_url": "https://github.com/gkoreli/ghx",
          "versions_count": 34,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-08T02:47:49Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 20
        },
        {
          "name": "@gkoreli/ghx",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "github",
            "cli",
            "code-exploration",
            "agent",
            "graphql",
            "code-map"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@gkoreli/ghx",
          "is_deprecated": false,
          "latest_version": "2.9.0",
          "repository_url": "https://github.com/gkoreli/ghx",
          "versions_count": 29,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2137,
          "first_published_at": "2026-03-08T16:51:39.704000Z",
          "latest_published_at": "2026-07-08T02:50:31.403000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 20
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        ".mise.toml"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 35342,
      "source_files_sampled": 245,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 19522
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 6,
        "malicious_count": 0,
        "assessed_package": "npm:@gkoreli/ghx@2.9.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/bmatcuk/doublestar/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.10.0"
        },
        {
          "name": "github.com/cli/go-gh/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.13.0"
        },
        {
          "name": "github.com/coder/acp-go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.5"
        },
        {
          "name": "github.com/dop251/goja",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260311135729-065cd970411c"
        },
        {
          "name": "github.com/evanw/esbuild",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.27.4"
        },
        {
          "name": "github.com/mark3labs/mcp-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "github.com/odvcencio/gotreesitter",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.4"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/proto/otlp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 6,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "gkoreli",
          "commits": 598,
          "avatar_url": "https://avatars.githubusercontent.com/u/243085293?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "auto-tag.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "719cb293a61532b9db6771e631ecf16e687f495b",
        "ran_at": "2026-07-28T07:43:35Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T16:16:35Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-19T16:16:34Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/gkoreli/ghx",
    "host": "github.com",
    "name": "ghx",
    "owner": "gkoreli"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 48,
        "vitality": 75,
        "community": 32,
        "governance": 46,
        "engineering": 69
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "commits_last_year": 598,
              "human_commit_share": 1,
              "days_since_last_push": 8,
              "active_weeks_last_year": 12
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "12/52 weeks with commits",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 12
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "598 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 598
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 37,
              "latest_release_tag": "v2.9.0",
              "releases_from_tags": false,
              "days_since_latest_release": 20,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "37 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 37
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 20 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 32,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "github.com/gkoreli/ghx/v2",
                "@gkoreli/ghx"
              ],
              "dependents": null,
              "ecosystems": "go, npm",
              "total_downloads": null,
              "monthly_downloads": 2137
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,137 downloads/month across go, npm",
                "points": 44.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2137,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 46,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 6,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "6/6 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 6,
                      "decided": 6
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "critical",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 21,
            "inputs": {
              "followers": 0,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "gkoreli",
              "public_repos": 5,
              "account_age_days": 259
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of gkoreli",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "gkoreli"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~0 yr old",
                "points": 7.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/gkoreli/ghx/v2",
                "@gkoreli/ghx"
              ],
              "ecosystems": "go, npm",
              "any_deprecated": false,
              "min_days_since_publish": 20
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 20 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 69,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "ai-agents",
                "cli",
                "code-search",
                "developer-tools",
                "github",
                "golang",
                "mcp"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/@gkoreli/ghx",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@gkoreli/ghx",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 48,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@gkoreli/ghx@2.9.0 runtime dependency closure — what installing the published package pulls in — 6 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@gkoreli/ghx@2.9.0",
                  "assessed": 6
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 6,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 6,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 81,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 19522
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                ".mise.toml"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.94,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": ".mise.toml",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".mise.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "94 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 94,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 35342,
              "source_files_sampled": 245,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/245 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 245,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T07:43:44.484985Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/gkoreli/ghx.svg",
  "full_name": "gkoreli/ghx",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo, npm.