Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 01:22 UTC

kernel / cua

computer use cli / sdk for agent builders

TypeScriptNo license detected★ 4 stars⑂ 0 forkssince Apr 2026View on GitHub ↗

kernel/cua holds a health index of 49 out of 100, placing it in the At risk band. It scores highest on Engineering Quality (74/100) and lowest on Community & Adoption (29/100). It was last updated 5 days ago. A single contributor accounts for most of its recent work.

49
overall / 100
At risk

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

49
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

KERNELOrganization
236 followers73 public repossince Jan 2025

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
npm@onkernel/cua-ai0.7.04,961145 days ago
npm@onkernel/cua-cli0.5.01,552105 days ago
npm@onkernel/cua-agent0.7.04,951135 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

44At risk · 22% of overall
How it's scored
36/36Push recency — last push 5 days ago
9/36Commit cadence — 13/52 weeks with commits
17.5/18Commit volume — 88 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year88
human_commit_share1
days_since_last_push5
active_weeks_last_year13
How it's scored
0/27Ships releases — no releases published
0/36Release recency — no releases
0/27Release cadence — no releases
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count0
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

29Critical · 18% of overall
How it's scored
7.7/60Stars — 4 stars
0/25Forks — 0 forks
0/15Watchers — 1 watchers
Inputs used
forks0
stars4
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
0/22.5License — no license file detected
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
54.1/80Monthly downloads — 11,464 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@onkernel/cua-ai, @onkernel/cua-cli, @onkernel/cua-agent
dependents
ecosystemsnpm
total_downloads
monthly_downloads11,464
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

58Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
3.8/22.5Commit distribution — top contributor authored 83% of commits
4.1/13.5Contributor breadth — 3 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled3
top_contributor_share0.83
How it's scored
0/46.8Issue resolution — no issues or no data
34.8/38.3PR acceptance — 50/55 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 1/21 approved changesets -- score normalized to 0
Inputs used
merged_prs50
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs5
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
17.1/25Owner reach — 236 followers of kernel
16/25Track record — 73 public repos, account ~1 yr old
Inputs used
followers236
owner_typeOrganization
is_verified
owner_loginkernel
public_repos73
account_age_days557
How it's scored
25/25Published & resolvable — 3 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 14 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@onkernel/cua-ai, @onkernel/cua-cli, @onkernel/cua-agent
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

74Good · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
16/20OpenSSF Scorecard: CI-Tests — 17 out of 19 merged PRs checked by a CI test -- score normalized to 8
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://www.kernel.sh
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://www.kernel.sh
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

35At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2/2.5CI-Tests — 17 out of 19 merged PRs checked by a CI test -- score normalized to 8
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/21 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5License — license file not detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3.5
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

55Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 68 of 88 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.773
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking — packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 41 of the last 88 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
2/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configspackages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json
agent_commit_share0.466
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.6/55Manageable file sizes — 1/137 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes66,935
source_files_sampled137
oversized_source_files1
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

4GitHub stars
3contributors
88commits, last 12 months
5days since last push
0releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package '@onkernel/ptywright' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@onkernel/cua-ai@0.7.0; advisories assessed against the repository dependency graph instead

More detail

OpenSSF Scorecard 3.5 / 10
3.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 01:22 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
8CI-Tests17 out of 19 merged PRs checked by a CI test -- score normalized to 8
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/21 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
1Vulnerabilities9 existing vulnerabilities detected
Direct dependencies 15
RegistryPackageVersion constraintManifest
npm@earendil-works/pi-agent-core0.80.10packages/agent/package.json
npm@earendil-works/pi-ai0.80.10packages/agent/package.json
npm@onkernel/cua-ai0.7.0packages/agent/package.json
npm@onkernel/sdk0.49.0packages/agent/package.json
npmsharp^0.34.5packages/agent/package.json
npm@earendil-works/pi-ai0.80.10packages/ai/package.json
npm@tzafon/lightcone^0.7.0packages/ai/package.json
npmopenai^6.26.0packages/ai/package.json
npm@earendil-works/pi-coding-agent0.80.10packages/cli/package.json
npm@earendil-works/pi-tui0.80.10packages/cli/package.json
npm@onkernel/cua-agent0.7.0packages/cli/package.json
npm@onkernel/cua-ai0.7.0packages/cli/package.json
npm@onkernel/sdk0.49.0packages/cli/package.json
npmnode-addon-api^8.7.0packages/ptywright/package.json
npmnode-pty^1.1.0packages/ptywright/package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 8419,
      "has_wiki": true,
      "homepage": "https://www.kernel.sh",
      "languages": {
        "C": 12784,
        "C++": 7109,
        "Python": 1357,
        "JavaScript": 21577,
        "TypeScript": 831935
      },
      "pushed_at": "2026-07-17T18:44:32Z",
      "created_at": "2026-04-18T02:17:10Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T18:41:20Z",
      "description": "computer use cli / sdk for agent builders",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://www.kernel.sh",
      "name": "KERNEL",
      "type": "Organization",
      "login": "kernel",
      "company": null,
      "location": "United States of America",
      "followers": 236,
      "avatar_url": "https://avatars.githubusercontent.com/u/194616459?v=4",
      "created_at": "2025-01-11T15:49:38Z",
      "is_verified": null,
      "public_repos": 73,
      "account_age_days": 557
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "f1c91f7f784e6df6616bb443887701c3a8fde3ed",
          "body": "* Add Moonshot Kimi K3 computer-use provider\n\nExpose kimi-k3 as moonshotai:kimi-k3 (alias moonshot:), streaming through\npi-ai's builtin OpenAI-compatible chat completions transport with\nMOONSHOT_API_KEY. Kimi grounding emits 0-1 width/height fractions, so the\nprovider declares a fractional normalize\n[…]\nlevel in the CLI.\n\n* Trigger CI for ready-for-review run\n\n* Bump cua-ai/cua-agent to 0.7.0 and cua-cli to 0.5.0 for release\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Moonshot Kimi K3 computer-use provider (#66)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-17T18:41:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c94173d3e9561ee2b6fd02423c0d2b80a27deb16",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Unify CLI release and prerelease workflow (#62)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-14T00:59:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1d1f21e8b453f9dffa980453adc974b15301127",
          "body": "* Add Grok 4.5 computer-use provider\n\n* Map disabled Grok reasoning to low\n\n* Use pi-ai Grok model metadata\n\n* Document xAI tool contracts\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Grok 4.5 computer-use provider (#61)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-14T00:12:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52db49ee42ec36bcf3eead8929f0e153a2e79c79",
          "body": "Publish @onkernel/cua-cli from any branch under an npm dist-tag (never\n`latest`) as `<version>-<dist-tag>.<run-number>`, unique per run, so\nunmerged work can be tried via `npm install -g @onkernel/cua-cli@<tag>`.\nUnlike release-cua-cli.yml there is no \"tag on main\" gate; it publishes\nthrough OIDC trusted publishing the same way.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add workflow_dispatch prerelease publish for cua-cli (#58)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-13T23:46:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "98d013493690bd5e92c11e3e9420687ecc8ebad5",
          "body": "* Add Meta Muse Spark provider\n\n* Prefer scoped Meta API key name\n\n* Harden Meta live test setup\n\n* Address Meta provider review findings\n\n* Resolve Meta smoke fixture across workspaces\n\n* Simplify Meta provider integration\n\n* Drop Meta action alias normalization\n\n* Sanitize Meta payload after hooks\n[…]\nts after shared threading\n\n* Remove Meta-specific e2e gate\n\n* Document Meta response threading\n\n* Format exported API TSDoc\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Meta Muse Spark computer-use provider (#59)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-13T17:12:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a88952d62d80e8fc3d52eec41cd8d82bf43ad04",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Prepare CUA package releases (#57)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T18:53:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e53c87a01bc260e9498adb3015e3a0982f60dbb9",
          "body": "* Retry empty CUA responses once\n\n* Make empty response recovery explicit\n\n* Reset harness queue state between prompts\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add opt-in recovery for exact-empty CUA responses (#55)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T16:28:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5b01284158a94ccd42fe33e793bda0440b1229c",
          "body": "* Add --proxy flag to route the browser through a Kernel proxy\n\nAccepts a proxy id or name, resolved via proxies.retrieve with a\nlist-by-name fallback; ambiguous names and unknown selectors are errors\n(proxies are never auto-created, unlike --profile). Applies to one-shot\nsubcommands and session start; named sessions persist the resolved\nproxy_id in their metadata.\n\n* Bump cua-cli 0.3.1 for the --proxy flag release\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add --proxy flag for routing the browser through a Kernel proxy (#56)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T16:08:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03016f99ce09a2ef0442b73d380a1c0a35e0e3b1",
          "body": "* Bound retained tool result images\n\n* Configure tool result image replay\n\n* Document image replay limit type\n\n* Apply response threading policy to all model calls\n\n* Compose harness context hooks with image limits\n\n* Apply image limits to all model calls\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Configure CUA image context and response threading (#53)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T16:06:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88b101a801a3a17d3eb6547e77a0b08bbe4e30ab",
          "body": "* Retry transient provider errors\n\n* Make provider retries configurable\n\n* Preserve provider replay failures\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add configurable retries for transient provider errors (#54)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T14:21:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3caf6cc7f07117982184db043185480e2233b850",
          "body": "… computer/browser tools (#51)\n\n* Add action-plane modes (os/dom/hybrid) and Anthropic native computer/browser tools\n\n* Add setMode/getMode, /mode slash command, and live-API schema fix\n\n- CuaAgent.setMode / CuaAgentHarness.setMode switch action planes at\n  runtime (rejected when it conflicts with a\n[…]\nordinates); mode switches keep it. Drop the\ntranslator's dead mode option.\n\n---------\n\nCo-authored-by: hypeship <hypeship@onkernel.com>\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add action-plane modes (computer/browser/hybrid) and Anthropic native…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-09T19:25:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f3fe8d23f9f70c68f7911e8619028cfafc108aa",
          "body": "* Adopt pi 0.80's instance-based Models API across cua-ai, cua-agent, cua-cli\n\npi-ai 0.80 replaced the global api-registry and free-function catalog/stream\nsurface (getModel, getModels, streamSimple, registerApiProvider, ...) with an\ninstance-based Models API. Adopt it directly instead of the deprec\n[…]\nto resolve. Users pin\nthe family id; drop the snapshot rather than maintain it. The gpt-5.5 family\nannotation is unchanged.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Adopt pi 0.80's instance-based Models API (#50)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-08T14:35:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba6d43c2aa3a316686a902da2b07ec626738d34e",
          "body": "* packages/ai: adapt Sonnet 5 thinking payload\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* packages/ai: broaden adaptive thinking support\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* packages/agent: loosen payload hook assertion\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "packages/ai: adapt Anthropic thinking payloads (#49)",
          "author_name": "Mason Williams",
          "author_login": "masnwilliams",
          "committed_at": "2026-06-30T19:07:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a8b34fe76f9b5d1a41f779f27664c34ac972dbc4",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release CUA AI v0.3.3",
          "author_name": "Mason Williams",
          "author_login": "masnwilliams",
          "committed_at": "2026-06-30T18:31:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "53040a960f68a320b2cf351f65a56519ffeb3626",
          "body": "Annotate the claude-sonnet-5 family as CUA-supporting and register a\nCUA_MODEL_OVERRIDES entry so getCuaModel() resolves anthropic:claude-sonnet-5\nbefore pi-ai's registry carries it. Update the supported-models snapshot.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "packages/ai: add computer-use support for claude-sonnet-5 (#48)",
          "author_name": "Mason Williams",
          "author_login": "masnwilliams",
          "committed_at": "2026-06-30T18:30:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4a73fbd9f695806515611107d34abfe756fc0d17",
          "body": "…#46)\n\n* Thread Tzafon requests with previous_response_id + delta input\n\nAdd a shared response-threading capability (responseThreadingEnabled with\nCUA_DISABLE_RESPONSE_THREADING opt-out) and a pure responseThreadingDelta util\nthat finds the most recent assistant responseId and returns the messages a\n[…]\n's builtin\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Thread previous_response_id through Tzafon and OpenAI CUA providers (…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-29T14:03:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "79e1df44241d627bc50c35c5bdee43df0920262d",
          "body": "…h release\n\ncua-ai 0.3.2 adds computer-use support for gemini-3.5-flash. Bump the\ninter-package dependency pins so the release workflows can publish cua-ai,\nthen cua-agent, then cua-cli in dependency order.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump cua-ai 0.3.2, cua-agent 0.3.5, cua-cli 0.1.4 for gemini-3.5-flas…",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-24T19:39:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1d426c34d148dd4d88d835ea82f308014fc1ac90",
          "body": null,
          "is_bot": false,
          "headline": "Add gemini-3.5-flash to supported CUA models (#38)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-24T18:48:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f406ffb38b7bd1c9fba80e73e94f7e107211a16e",
          "body": "…ute release (#37)\n\nThe playwright_execute feature spans all three packages; none are published\nwith it yet. Bump versions (and inter-package dep pins) so the release\nworkflows can publish cua-ai, then cua-agent, then cua-cli in dependency order.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump cua-ai 0.3.1, cua-agent 0.3.4, cua-cli 0.1.3 for playwright_exec…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-23T22:11:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6c4740c800260f54c1d8425ee383c3dcb61263a1",
          "body": "Add opt-in playwright_execute tool to the CUA agent and CLI",
          "is_bot": false,
          "headline": "Merge pull request #33 from kernel/hypeship/cua-playwright-execute-tool",
          "author_name": "Daniel Prevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-23T21:18:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f855cf105d518990ac44ae821de1d8d15911c57c",
          "body": "…/stderr details\n\nplaywright_execute is frequently a pure read where forcing a screenshot wastes\nimage tokens and latency. Let the model request one on a follow-up turn. The\nexisting content.length === 0 → statusText fallback keeps content non-empty\nfor side-effect-only calls.\n\nAlso tighten the Play\n[…]\nl-exhaustiveness.test.ts: flip the trailing-image\n  assertions to assert no image is appended; drop the unused captureScreenshot\n  mocks; add a side-effect-only case that hits the statusText fallback.",
          "is_bot": false,
          "headline": "Drop auto-appended screenshot from playwright_execute; clarify stdout…",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-23T20:06:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1121e22170792922b421dacc36ed1c0efb8deece",
          "body": "The package now publishes to npm, so the install instructions should use a\nregistry install instead of running from source. Bump the version so the\nupdated README is republished.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Point cua-cli README install at the npm registry; bump to 0.1.2 (#34)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-22T22:19:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d746e8c6cd2abbe2fb3ee4b7a1b228190568fdc5",
          "body": "- executePlaywright: timeout_sec values below 1s previously truncated\n  to 0 and were forwarded to the SDK, which differs from omitting the\n  field. Floor the truncated value at 1s; anything sub-second falls\n  back to \"use server default\".\n- Document PlaywrightDetails fields so library consumers know what\n  each one means without reading the executor source.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bugbot fixes: sub-second timeout floor and PlaywrightDetails TSDoc",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T20:26:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "565fe015f5045f2f8b9888bbbdf5c1a086e065ac",
          "body": "Matches executeBatchTool's shape: the trailing translator.screenshot()\nlives inside the same try/catch as the underlying work, so any failure\nin the pipeline produces a single wrapped tool error rather than\ndiverging based on which step failed.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wrap playwright_execute screenshot in the same try as the execution",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T20:17:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "302fc14c424bc22f1362d25a6d08ef3e5ef548d2",
          "body": "Empirical results show CUA-specialized providers (Tzafon, Yutori) do\nemit playwright_execute calls — earlier docs were overly cautious.\nYutori in particular demonstrates the failure-as-content design well:\nit iterated through two wrong-API attempts (page.querySelector, bare\ndocument) before reading the stderr/error blocks and landing on\npage.evaluate(), which throwing would have prevented.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Update playwright_execute docs after Tzafon and Yutori e2e verification",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T19:00:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "11afbbfc9a03617bc4589605f6eebb00ec77ba63",
          "body": "formatPlaywrightResult's JSON.stringify try/catch guarded against\nnon-serializable values, but execution.result came from the SDK after\na JSON round trip through the wire — anything that survived that is\nalready JSON-safe, so the catch arm is unreachable.\n\nThe executePlaywright timeout chain checked\n[…]\n parameter is TS-typed number | undefined) and Number.isFinite\n(redundant — timeoutSec > 0 already rejects NaN, and Math.min handles\nInfinity).\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Deslop: drop dead defensive checks around playwright_execute",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T18:46:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "849f6a4cfc7e05f0a207114f2c6068ec6e2c77c6",
          "body": "- packages/agent: list playwright option alongside computerUseExtra and\n  add a paragraph explaining the tool's behavior and tested-models scope.\n- packages/ai: list the new tool-definition factory, schema, constants,\n  and CuaPlaywrightInput type in the API surface index.\n- packages/cli: document --playwright with a short explainer.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document playwright_execute in package READMEs",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T18:18:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5ddf0e50b9dbb6e47725d3af977403bc44586048",
          "body": "Schema description tells the model \"max 300\" but nothing enforced it.\nA model that ignored the bound would have hit a confusing SDK-level\nfailure depending on server behavior; this clamp keeps the client\nhonest to the documented contract.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Clamp playwright_execute timeout to the documented 300s server max",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:52:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e96be94b9962ad90c88c9cc0d98bc2be84cde9cb",
          "body": "Earlier review feedback dropped \"Defaults to 60\" out of a worry that the\ndefault lived in the SDK and could drift. The kernel.sh docs put both\nthe default (60s) and the cap (300s) on the server, so the description\nis the authoritative place to surface them — the model can't choose a\nsensible timeout without that anchor.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Restore documented timeout default and add the 300s max",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:47:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "49e6f155262283b9355fbbc002823dd394fd7605",
          "body": "Locals don't persist across calls but the browser session does. Without\nthis, a model could write code in call N assuming variables from call\nN-1 are still in scope.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document fresh-context-per-call in playwright_execute description",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:43:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9fa28705695ec289395f860c7811cfc89aa296f3",
          "body": "- Drop misleading \"Defaults to 60\" from timeout_sec description; the\n  actual default lives in the Kernel SDK, not here.\n- Expose result/stdout/stderr/error on PlaywrightDetails so library\n  consumers can branch on the structured execution result without\n  re-parsing tool content text.\n- Guard forma\n[…]\nr refs) so a successful Playwright run never\n  becomes a tool-level error.\n- Sync package-lock.json to match the cua-cli 0.1.1 bump in a7cdc07.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Address self-review feedback on playwright_execute",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:41:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b930ca1e2f22e73886cd059dca688109010a895c",
          "body": "Exposes a tool that runs Playwright/TypeScript directly against the\nbrowser session (via the Kernel SDK browsers.playwright.execute) for\nsteps that are awkward as raw pointer/keyboard actions. Modeled on the\nexisting computer_use_extra navigation tool: defined in cua-ai, executed\nthrough the transla\n[…]\nad. Enable with the\n`--playwright` CLI flag. Returns result/stdout/stderr and appends a fresh\nscreenshot so the screenshot loop stays coherent.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add opt-in playwright_execute tool to the CUA agent and CLI",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-19T21:51:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5f5612b505fc9e9b7a3caf0d7fc7c7dec5dd94cf",
          "body": "The extracted ghostty source has no .git, so ghostty's version detection\nwalks up into the host repo and panics on a non-vX.Y.Z tag (e.g. a\ncua-cli/vX.Y.Z release tag). Passing -Dversion-string short-circuits git\ndetection, making the native build independent of host git state.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Pin ghostty version-string so native build ignores host git tags",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-14T03:12:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a7cdc0719e317ebde43511d2ed7b3e8d57eeb0b3",
          "body": "Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump @onkernel/cua-cli to 0.1.1",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-14T03:04:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3712e73cc936cc8427d22e5bb3ae0278b65deccb",
          "body": "* Discover skills and context via pi resource loader\n\nReplace the hand-rolled skill scan in harness-skills.ts with pi's\nDefaultResourceLoader so installed-package skills load (the loader is a\nstrict superset of the old ~/.agents/skills discovery). Bridge pi's\nskill file paths back through cua-agent'\n[…]\nn field,\nand document that --no-skills leaves context files intact.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Load installed-plugin skills and align cua-cli startup with pi (#32)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-13T23:44:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae102c61f1e53ff8d5bb10d3276a113c24c615b4",
          "body": "npm 11.17 requires an explicit permission flag on npm trust; the release\nworkflows run a full npm publish, so --allow-publish is the right grant.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add required --allow-publish flag to npm trust commands (#31)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T20:04:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0da96b2fdf9efc7593e61804bd91578ec111342e",
          "body": "* Fix ESM import specifiers in cua-cli and smoke-test the bin in CI\n\npackages/cli used extensionless relative imports, which compile cleanly\nunder moduleResolution Bundler and work in vitest, but fail at runtime\nwith ERR_MODULE_NOT_FOUND when Node executes the published dist. Add .js\nextensions to a\n[…]\nclaration-only emit to dist-tsc for typechecking, tsdown owns dist/,\nand the root build bundles the cli after typechecking.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Bundle cua-cli with tsdown; smoke-test the bin in CI (#30)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T19:33:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16ac531aa6eb2eab80aae766bf4ac8ff5ca9a06e",
          "body": "The root build and typecheck scripts ran tsc -b before @onkernel/cua-agent's\ntsdown build, so packages/cli was type-checked against a missing (fresh\nclone) or stale (previously built checkout) dist/index.d.ts. Reorder the\nscripts so workspace dist artifacts exist before tsc -b runs, and add a\ntypech\n[…]\naned @mariozechner/* 0.67 entries and their unreferenced\ntransitive deps from package-lock.json (leftover from the pi 0.79 migration).\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Build agent dist before tsc -b and typecheck the workspace in CI (#29)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T18:15:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9258f47300dd360cd328d74b1818e69de5ab44d1",
          "body": "* Set up npm release workflow for @onkernel/cua-cli\n\n* Address review for cua-cli release setup\n\n- docs: add pre-publish smoke test step (npm pack + install + cua --help)\n  to the first-publish runbook, so a maintainer following it verbatim does\n  not ship a broken 0.1.0 to npm.\n- docs: list @earend\n[…]\nckages/ai and packages/agent entries by adding license MIT and engines\n  node >=22.19.0 to match the package.json metadata.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Set up npm release workflow for @onkernel/cua-cli (#28)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T16:11:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fec4254776e814eab4cf1e7fd484fd946669f11f",
          "body": "* Drop bin/cua, fold DESIGN.md into architecture.md, delete .cursor\n\n- Remove bin/cua wrapper and update install paths in README.md and\n  packages/cli/README.md to run the CLI via npx tsx from source. The\n  wrapper assumed a built dist/cli.js that's currently broken at runtime\n  in the workspace.\n- \n[…]\ned to npm.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Drop bin/cua, fold DESIGN.md into architecture.md, delete .cursor (#27)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T15:17:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c720368ca25024c0ea05a39d5279687158928abc",
          "body": "Move the CLI workspace directory to packages/cli. The npm package name\n(@onkernel/cua-cli), binary name (cua), and workspace identity are all\nunchanged. Updates root package.json workspaces, tsconfig project\nreferences, package-lock.json paths, bin/cua wrapper, README workspace\ntable and Mermaid dia\n[…]\n) keep\ntheir prose as-is. Tests under packages/cli still pass (29 passed, 4\nTUI fixture tests skipped without ptywright native build).\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Rename packages/cua-cli to packages/cli (#26)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T14:34:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1e89dd549d39aad6dd84f751150aa5ae60f8b6a",
          "body": "* PR 4: remove deprecated provider packages from workspace\n\nDeletes packages/cua-{translator,openai,anthropic,gemini,tzafon,yutori}\nnow that cua-cli is fully migrated to CuaAgentHarness + pi 0.79. Updates\nthe root package.json workspaces, root tsconfig references, README\n(workspace tree, mermaid, pa\n[…]\nen\n- add cli-harness.ts to the CLI runtime flow inventory in\n  docs/architecture.md and .agents/skills/update-docs/SKILL.md\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 4: remove deprecated provider packages from workspace (#25)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T06:25:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a5b61dce17d7a8007ba3ad28da8ffd8d555dd71",
          "body": "* PR 3: purge legacy pi 0.67 wiring from cua-cli\n\nDelete the dead pre-harness source files (agent.ts, agent-prompt.ts,\nold models.ts, config.ts, old sessions.ts, skills.ts, old named-sessions.ts,\nold action/runner.ts, old output/jsonl.ts) now that the harness paths from\nPR 1 and PR 2 cover every CLI\n[…]\nhe documented command would now\nfall through to interactive mode and start a TUI run with the literal\nprompt \"config init\".\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 3: purge legacy pi 0.67 wiring from cua-cli (#24)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T05:48:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2218ddddc75491887afed797f1c4ee2badd267bf",
          "body": "* PR 2: rebuild interactive TUI on CuaAgentHarness + pi-tui 0.79\n\nPer the migration plan (docs/cua-cli-harness-migration.md), the interactive\nTUI moves off the legacy provider-wiring stack and onto the harness:\n\n- tui/main.ts subscribes to harness.subscribe() and routes\n  AgentHarnessEvent into a pi\n[…]\nspawns 'zig ar -M' directly,\nso the cached zig binary must be discoverable on PATH for the\nnative binding build to succeed.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 2: rebuild interactive TUI on CuaAgentHarness + pi-tui 0.79 (#23)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T05:22:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a95e2d03906151976285f5fe49ef722151337cd",
          "body": "* Wire cua-cli non-interactive paths onto CuaAgentHarness\n\nPR 1 of the cua-cli → CuaAgentHarness migration plan\n(docs/cua-cli-harness-migration.md). Wires the non-interactive\nsurface of cua-cli onto CuaAgentHarness + pi 0.79 while leaving the\ninteractive TUI on the legacy stack for now.\n\nEngine:\n- h\n[…]\nt 2, the turn-cap abort path, jsonl tool steps,\n  the first-prompt screenshot, and --session <path> from a different\n  cwd.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 1: wire cua-cli non-interactive paths onto CuaAgentHarness (#22)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T04:05:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6ad0104d15d2824d7351f702327102e4e29d138",
          "body": "Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add cua-cli → CuaAgentHarness migration plan",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T02:52:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a3c606c191dad6a99f4561263c535276268f308",
          "body": "v4 of both actions runs on the Node.js 20 actions runtime, which GitHub\ndeprecates and force-switches to Node 24 on 2026-06-16; v5 targets the\nNode 24 runtime directly.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump checkout and setup-node actions to v5",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T01:55:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "efd8132084dece65045722a18c132ef7930d523f",
          "body": "…#21)\n\n* Tighten cua-agent design seams from review\n\n- The translator now consumes the canonical CuaAction union with an\n  exhaustive switch instead of re-parsing untyped records; malformed\n  shapes can no longer silently coerce to 0,0 clicks, and drift in the\n  canonical vocabulary becomes a compil\n[…]\ngent 0.3.3\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Tighten cua-agent design seams: typed translator, declared channels (…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T01:35:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "19ec1d21d81c7a256ac562496850c4f785f2fc07",
          "body": "PR CI previously ran only cua-ai unit tests and cua-agent's live e2e file, so\ncua-agent's unit suite ran solely in the release workflow and cross-package\nbreakage surfaced at release time. Add an agent-unit job that builds cua-ai and\nruns the cua-agent unit tests on every PR.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add cua-agent unit tests to CI",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T22:35:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "77af0f4b2e67adc25488ed7c3a61613c2efdd8c5",
          "body": "The google:gemini-3-pro-preview annotation was removed from cua-ai, leaving\nthis test resolving an unsupported model id and failing the cua-agent release\nworkflow's unit-test gate. Switch the model-change fixtures to the still-\nsupported google:gemini-3-flash-preview.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix cua-agent test referencing retired gemini-3-pro-preview model",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T22:19:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "33ee377c6c75addcc2ecc292afa3d553c45b4a3b",
          "body": "Add gpt-5.4-mini, gemini-3.1-flash-lite, and tzafon northstar-cua-fast 1.6/1.7 CUA annotations; remove retired gemini-3-pro-preview; bump cua-ai to 0.2.2 and cua-agent to 0.3.2.",
          "is_bot": false,
          "headline": "Add CUA model annotations and drop retired gemini-3-pro-preview (#20)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T22:11:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8881321f2f5401059b7c67e7de9989e3f51b9455",
          "body": null,
          "is_bot": false,
          "headline": "Release CUA AI v0.2.1 and CUA Agent v0.3.1",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T21:10:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df4799aa86d395cff86f0ba56e6ec30df28fa332",
          "body": "…(#19)\n\nThe update-models skill still pointed at the older cua-cli + cua-*\nadapter stack for the model list and adapter constants. Repoint it at\npackages/ai (@onkernel/cua-ai), which is the source of truth for\ncomputer-use model support: CUA_MODEL_ANNOTATIONS / CUA_MODEL_OVERRIDES,\nlistCuaModels()/g\n[…]\nt (and fable-5) to the discovery script's newer-tool/beta\n  runtime-pair list so they are not falsely flagged as runtime\n  mismatches.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Retarget update-models skill to packages/ai and add Fable 5 coverage …",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T20:58:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0bb4a875a974c8449a47ca0c1416136a68cd35be",
          "body": null,
          "is_bot": false,
          "headline": "De-vendor pi-agent-core and slim cua-agent to a light wrapper (#17)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-10T21:45:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd8043fb94c71e74e124c4cff45e0a6e765380d8",
          "body": "* Fix cua-ai ESM packaging and CI test coverage\n\nSwitch packages/ai to NodeNext module resolution and add explicit .js\nextensions to relative imports so the published dist loads in plain\nNode ESM (previously failed with ERR_UNSUPPORTED_DIR_IMPORT). Run the\nfull unit suite in CI and release instead o\n[…]\ne cleanly.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix cua-ai ESM packaging, error-handling docs, API consistency (#18)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-10T20:56:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d3beac2b81a6dec80ec1b5e166bf4cf36944991b",
          "body": "* Use explicit Anthropic computer tools\n\n* Introduce CuaProviderModule contract in cua-ai\n\nReplace the per-provider switch in resolveCuaRuntimeSpec with a registry\nlookup over provider modules that conform to a shared CuaProviderModule\ninterface. Adding a provider is now \"write the module, add one l\n[…]\n: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Use explicit Anthropic computer tools (#16)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-03T21:06:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "602e2a9cb6967c8c0a7fffc194fe533388dae4a0",
          "body": "* Use Yutori native tool sets\n\n* Address Yutori native tool review\n\n* Wire Yutori runtime hooks through CUA agent\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Use Yutori native tool sets (#15)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-20T18:22:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b737c5739b110f48f8d35e61d6c05a6df00fc07c",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release CUA Agent v0.2.0",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-14T03:04:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "18af410856394e58f1ffb0c57ae71a674a9a70d1",
          "body": "* Add CUA AgentHarness model switching\n\n* Fix CUA agent keypress shortcuts\n\n* Preserve harness active tools on model switch\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add provider-aware CUA AgentHarness (#12)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-14T03:01:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e5e122091aa19747a07101f4d1997fc1a1279fd",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Clarify cua-ai runtime spec docs (#13)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-14T02:01:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca12c0ef08a005dd2a6a5dd9cf4de008e09c3afb",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add npm release workflows (#11)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T21:07:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7df5044516d5ee199b1bf5fc6105bf4ee1e1f6be",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Clarify harness use in agent README (#10)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T19:24:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96047e8c982f4aef76f564dc001890184b30b436",
          "body": "* Add class-based CUA runtime surfaces and runtime spec plumbing\n\nSwitch cua-agent to class-first CuaAgent/CuaHarness constructors, centralize provider-specific defaults in cua-ai via resolveCuaRuntimeSpec, and add exhaustive tool coverage plus live e2e scenarios to validate browser execution across\n[…]\nnd runtime spec matching).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add class-based CUA agent surfaces and runtime spec (#8)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T19:20:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1740619ad497db1f4540eaad4fbc9e64a777db37",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Gemini 3 Pro CUA model (#9)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T19:05:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ba105afbf30fc16dbf05643ee90eda3e28fd82f",
          "body": "…s (#7)\n\n* ai: tighten public surface and document CuaProvider + supported models\n\n- Un-export parseCuaModelRef/formatCuaModelRef (internal helpers).\n- Add docs/supported-models.md enumerating CUA-supported models per\n  provider with source citations, linked from README.\n- Add a CuaProvider section \n[…]\n fails CI.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ai: tighten public surface and document CuaProvider + supported model…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T18:31:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3135a5dbe8c0c54fc3a25062d9f1ac10b2d6d8ee",
          "body": "* Test and harden batch_computer_actions across providers\n\n- Add provider-by-provider unit coverage for the batch tool schemas.\n- Add integration tests (env-gated) that hit each provider live and\n  verify the response contains a parsed batch_computer_actions call.\n- Tzafon: unwrap stringified nested\n[…]\nri: translate type, goto_url, mouse_down, mouse_up, hover, hold_key\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Test and harden batch_computer_actions across providers (#3)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T16:02:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8811f3b2cb41125d15edbbcad1104dcc42c3987",
          "body": "…upe typebox (#6)\n\nThree related cleanups in @onkernel/cua-ai.\n\n1. Provider re-registration. pi-ai's register-builtins module eagerly\n   registers openai-responses, anthropic-messages, and\n   google-generative-ai when the package is imported. The CUA layer was\n   re-registering them with the same la\n[…]\n all have stream/\nstreamSimple functions wired up after importing the package.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ai: drop redundant built-in re-registration, remove dynamicModel, ded…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T14:07:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "697319858d41ca6e3fd93a29645574ba1175e4d0",
          "body": null,
          "is_bot": false,
          "headline": "ai: replace CUA model regex allowlist with annotation table (#5)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T13:44:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e728095315511e5035a08304967109bd62bbfa0e",
          "body": null,
          "is_bot": false,
          "headline": "Document provider-native CUA action vocabularies (#4)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T13:17:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dea327387e02ad6e237b64f24c47720f4d8eab1",
          "body": "Migrate pi-ai/pi-agent-core to @earendil-works scope",
          "is_bot": false,
          "headline": "Merge pull request #2 from kernel/hypeship/migrate-pi-to-earendil-works",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T12:21:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c67b48e4fc41201c45180ff24644c8a55709fbe",
          "body": "The @mariozechner/pi-* packages are deprecated and the repo moved from\nbadlogic/pi-mono to earendil-works/pi. Updates packages/ai and\npackages/agent to the new @earendil-works/pi-* packages at 0.74.0, which\nalso renames @sinclair/typebox to typebox (v1, schemas are unchanged).\nREADME, doc, and skill\n[…]\ne new GitHub URL and\nnpm names; deprecated cua-* package READMEs are updated for users who\nfollow them, but their pinned npm deps are left alone since the packages\nare being absorbed into packages/ai.",
          "is_bot": false,
          "headline": "Migrate pi-ai/pi-agent-core to @earendil-works scope",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T12:11:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acd224870672902a6f46f0a4ce89cc9ef0752bc9",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Document CUA provider coordinate metadata",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-03T02:19:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e5584ae9883f030aeb2cc73822c63abb47ec3021",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Decouple CUA AI quickstart from CLI config",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T20:14:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f6864ec5f830836478f45cc1ac55da6ca3c14669",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add provider-scoped CUA tool definitions",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T19:55:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5ca68471f8fe805d73edb41a4ed9081bd4388254",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Simplify CUA model info",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T19:31:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "063bf8c81b2a6422df0176617a93d77dffd07914",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add CUA AI quickstart example",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T19:06:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "91621dcd5a48665a31e135a48b5dbb29a4700cd3",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Refine CUA AI package README",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T18:46:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "657b7c78bb87bea2550ce4ab0ed3a889f4c639eb",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add CUA AI and agent SDK packages",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T17:27:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2f7a2aeba4c28883ed85d326eda1534c5e3fa251",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Add Yutori provider support.",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-30T20:21:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4bfae4bc94c72ebdde8f87e56812dda141899f8",
          "body": null,
          "is_bot": false,
          "headline": "package.json tweaks",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-30T14:28:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25abde5b8bff4d31a77651b75e84e9cc02444919",
          "body": null,
          "is_bot": false,
          "headline": "compaction and previous response id for oai",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-30T14:27:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5099544a24c99aa2fe7552dabb39577aef8c4c91",
          "body": "Use Anthropic's model-compatible computer tool beta for Haiku and make update-model validation distinguish provider fallback support from the local runtime path.\n\nMade-with: Cursor",
          "is_bot": false,
          "headline": "Fix Haiku computer tool selection",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T02:04:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfb6c48939ce969ea8baaafd7166535290d1d5f0",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Document provider boundary invariant",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T02:03:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ff9199976f8f171d44b265fff7fe17123267525",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Document architecture invariants and docs workflow",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T01:56:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9d32cb90565c271895eb5dc30fa3b6165778e4c",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Remove unsupported GPT-5.5 Pro models",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T01:46:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea0c3578ece8999b9f2c5a27629dc49fad6277da",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Add supported model enumeration",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T01:39:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f78c9e95e59033803a0ee434aaa2059da0329bb",
          "body": null,
          "is_bot": false,
          "headline": "readme and skill tweaks",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-26T19:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "070f7bfde74a30a7bdf66ecc5674f96fbbed84e3",
          "body": "Establish the new Kernel computer-use monorepo with the CLI, shared translator, provider adapters, and docs so `kernel/cua` can become the canonical home of the TypeScript implementation.\n\nMade-with: Cursor",
          "is_bot": false,
          "headline": "Initialize the TypeScript cua rewrite.",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-18T02:17:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 0,
      "commits_last_year": 88,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 13,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 25,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@onkernel/cua-ai",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@onkernel/cua-ai",
          "is_deprecated": false,
          "latest_version": "0.7.0",
          "repository_url": "https://github.com/kernel/cua",
          "versions_count": 14,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 4961,
          "first_published_at": "2026-05-13T21:09:51.636000Z",
          "latest_published_at": "2026-07-17T18:42:27.070000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@onkernel/cua-cli",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@onkernel/cua-cli",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/kernel/cua",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 1552,
          "first_published_at": "2026-06-12T19:54:38.839000Z",
          "latest_published_at": "2026-07-17T18:46:27.323000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@onkernel/cua-agent",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@onkernel/cua-agent",
          "is_deprecated": false,
          "latest_version": "0.7.0",
          "repository_url": "https://github.com/kernel/cua",
          "versions_count": 13,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 4951,
          "first_published_at": "2026-05-13T21:10:05.608000Z",
          "latest_published_at": "2026-07-17T18:44:19.065000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 4,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 11
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/agent/tsconfig.json",
        "packages/ai/tsconfig.json",
        "packages/cli/tsconfig.json",
        "packages/ptywright/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 66935,
      "source_files_sampled": 137,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@earendil-works/pi-agent-core",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@earendil-works/pi-ai",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@onkernel/cua-ai",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.7.0"
        },
        {
          "name": "@onkernel/sdk",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.49.0"
        },
        {
          "name": "sharp",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.34.5"
        },
        {
          "name": "@earendil-works/pi-ai",
          "manifest": "packages/ai/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@tzafon/lightcone",
          "manifest": "packages/ai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.0"
        },
        {
          "name": "openai",
          "manifest": "packages/ai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.26.0"
        },
        {
          "name": "@earendil-works/pi-coding-agent",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@earendil-works/pi-tui",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@onkernel/cua-agent",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.7.0"
        },
        {
          "name": "@onkernel/cua-ai",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.7.0"
        },
        {
          "name": "@onkernel/sdk",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.49.0"
        },
        {
          "name": "node-addon-api",
          "manifest": "packages/ptywright/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.7.0"
        },
        {
          "name": "node-pty",
          "manifest": "packages/ptywright/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 11,
        "merged_prs": 50,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "rgarcia",
          "commits": 73,
          "avatar_url": "https://avatars.githubusercontent.com/u/72655?v=4"
        },
        {
          "type": "User",
          "login": "dprevoznik",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/58714078?v=4"
        },
        {
          "type": "User",
          "login": "masnwilliams",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/43387599?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.83
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release-cua-agent.yml",
        "release-cua-ai.yml",
        "release-cua-cli.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 8,
            "reason": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/21 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f1c91f7f784e6df6616bb443887701c3a8fde3ed",
        "ran_at": "2026-07-23T01:22:14Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T18:46:32Z",
      "oldest_open_prs": [
        {
          "number": 35,
          "created_at": "2026-06-23T21:43:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 36,
          "created_at": "2026-06-23T21:46:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 40,
          "created_at": "2026-06-26T14:59:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 41,
          "created_at": "2026-06-26T21:53:47Z",
          "last_comment_at": "2026-07-14T01:04:10Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 42,
          "created_at": "2026-06-27T11:26:16Z",
          "last_comment_at": "2026-06-27T15:52:27Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 43,
          "created_at": "2026-06-27T12:47:37Z",
          "last_comment_at": "2026-06-27T19:31:31Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 44,
          "created_at": "2026-06-27T12:47:49Z",
          "last_comment_at": "2026-06-27T15:52:30Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 45,
          "created_at": "2026-06-27T17:06:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 63,
          "created_at": "2026-07-14T02:49:52Z",
          "last_comment_at": "2026-07-14T03:08:50Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 64,
          "created_at": "2026-07-14T02:50:03Z",
          "last_comment_at": "2026-07-14T04:14:08Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 65,
          "created_at": "2026-07-14T02:50:18Z",
          "last_comment_at": "2026-07-14T04:14:08Z",
          "last_comment_author": "rgarcia"
        }
      ],
      "last_merged_pr_at": "2026-07-17T18:41:16Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/kernel/cua",
    "host": "github.com",
    "name": "cua",
    "owner": "kernel"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 49,
      "inputs": {
        "security": 35,
        "vitality": 44,
        "community": 29,
        "governance": 58,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 44,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 88,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "88 commits in the last year",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 88
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 29,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 8,
            "inputs": {
              "forks": 0,
              "stars": 4,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "4 stars",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "packages": [
                "@onkernel/cua-ai",
                "@onkernel/cua-cli",
                "@onkernel/cua-agent"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 11464
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "11,464 downloads/month across npm",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 11464,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.83
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 83% of commits",
                "points": 3.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 83
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 65,
            "inputs": {
              "merged_prs": 50,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 5
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "50/55 decided PRs merged",
                "points": 34.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 50,
                      "decided": 55
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/21 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "followers": 236,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "kernel",
              "public_repos": 73,
              "account_age_days": 557
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "236 followers of kernel",
                "points": 17.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 236,
                      "login": "kernel"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "73 public repos, account ~1 yr old",
                "points": 16,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 73
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@onkernel/cua-ai",
                "@onkernel/cua-cli",
                "@onkernel/cua-agent"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "3 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 3,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "14 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
                "points": 16,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://www.kernel.sh",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.kernel.sh",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 35,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/21 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 55,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.773,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "68 of 88 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 68,
                      "sampled": 88
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "packages/agent/tsconfig.json",
                "packages/ai/tsconfig.json",
                "packages/cli/tsconfig.json",
                "packages/ptywright/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.466,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "41 of the last 88 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 41,
                      "sampled": 88
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 66935,
              "source_files_sampled": 137,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/137 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 137,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package '@onkernel/ptywright' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@onkernel/cua-ai@0.7.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T01:22:31.219271Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kernel/cua.svg",
  "full_name": "kernel/cua",
  "license_state": "absent",
  "license_spdx": null
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.