Public record
Software health reportschema 0.26.0 · metrics 1.13.0 · 2026-07-22 12:12 UTC

node9-ai / node9-proxy

The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

TypeScriptCustom license★ 209 stars⑂ 17 forkssince Feb 2026View on GitHub ↗

node9-ai/node9-proxy holds a health index of 66 out of 100, placing it in the Moderate band. It scores highest on Vitality (83/100) and lowest on Security (41/100). It was last updated 2 days ago. A single contributor accounts for most of its recent work.

66
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

66
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Node9 AIOrganization
9 followers8 public repossince Feb 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

83Good · 22% of overall
How it's scored
36/36Push recency — last push 2 days ago
14.5/36Commit cadence — 21/52 weeks with commits
18/18Commit volume — 1,147 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year1,147
human_commit_share0.77
days_since_last_push2
active_weeks_last_year21
How it's scored
27/27Ships releases — 100 releases published
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~1.1 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count100
latest_release_tagv1.63.0
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases1.1

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

66Moderate · 18% of overall
How it's scored
37.6/60Stars — 209 stars
10/25Forks — 17 forks
0/15Watchers — 0 watchers
Inputs used
forks17
stars209
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

86Excellent
How it's scored
22.5/22.5README
16.9/22.5License — license file present, not a recognized license
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
52.8/80Monthly downloads — 9,089 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@node9/proxy
dependents
ecosystemsnpm
total_downloads
monthly_downloads9,089
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

58Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
6.9/22.5Commit distribution — top contributor authored 69% of commits
4.1/13.5Contributor breadth — 3 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled3
top_contributor_share0.693
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
33/38.3PR acceptance — 200/232 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/15 approved changesets -- score normalized to 0
Inputs used
merged_prs200
open_issues0
closed_issues12
issue_closed_ratio1
closed_unmerged_prs32
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
7.2/25Owner reach — 9 followers of node9-ai
7.7/25Track record — 8 public repos, account ~0 yr old
Inputs used
followers9
owner_typeOrganization
is_verified
owner_loginnode9-ai
public_repos8
account_age_days144
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 163 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@node9/proxy
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

76Good · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.mjs
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

65Moderate
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://node9.ai/
10/10Repository description
10/10Topics — 8 topics
0/10Wiki
Inputs used
topicsai-safety, ai-security, claude-code, gemini, gemini-cli, llm, llm-agent, mcp-server
has_wikino
homepagehttps://node9.ai/
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

41At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/15 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
3/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 46 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate4.1

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

77Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 74 of 77 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.961
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes3,508
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — eslint.config.mjs
11/11Static type checking — packages/policy-engine/tsconfig.json, tsconfig.json
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 55 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
6/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configspackages/policy-engine/tsconfig.json, tsconfig.json
agent_commit_share0.55
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.1/55Manageable file sizes — 7/409 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes154,129
source_files_sampled409
oversized_source_files7
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_files

Key facts

209GitHub stars
3contributors
1,147commits, last 12 months
2days since last push
100releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@node9/proxy@1.63.0; advisories assessed against the repository dependency graph instead

More detail

Star and fork history 0 ★ / 17 ⇿
0Stars
17Forks
55Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0481216201732026-032026-042026-06
Major 0Minor 17Patch 38
OpenSSF Scorecard 4.1 / 10
4.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-22 12:12 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/15 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
6Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 6
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities46 existing vulnerabilities detected
Direct dependencies 13
RegistryPackageVersion constraintManifest
npm@inquirer/prompts^8.3.0package.json
npmchalk^4.1.2package.json
npmcommander^14.0.3package.json
npmexeca^9.6.1package.json
npmink^7.0.2package.json
npmmvdan-sh^0.10.1package.json
npmpicomatch^4.0.3package.json
npmreact^19.2.6package.json
npmsafe-regex2^5.1.0package.json
npmsmol-toml^1.6.1package.json
npmstring-width^4.2.3package.json
npmyaml^2.9.0package.json
npmzod^3.25.76package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai-safety",
        "ai-security",
        "claude-code",
        "gemini",
        "gemini-cli",
        "llm",
        "llm-agent",
        "mcp-server"
      ],
      "is_fork": false,
      "size_kb": 5331,
      "has_wiki": false,
      "homepage": "https://node9.ai/",
      "languages": {
        "Shell": 20284,
        "JavaScript": 45598,
        "TypeScript": 4104391
      },
      "pushed_at": "2026-07-20T08:19:31Z",
      "created_at": "2026-02-27T21:32:52Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T11:43:18Z",
      "description": "The Execution Security Layer for the Agentic Era. Providing deterministic \"Sudo\" governance and audit logs for autonomous AI agents.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": "NOASSERTION",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://node9.ai",
      "name": "Node9 AI",
      "type": "Organization",
      "login": "node9-ai",
      "company": null,
      "location": "Israel",
      "followers": 9,
      "avatar_url": "https://avatars.githubusercontent.com/u/264506876?v=4",
      "created_at": "2026-02-27T21:15:36Z",
      "is_verified": null,
      "public_repos": 8,
      "account_age_days": 144
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": "NOASSERTION",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.63.0",
          "kind": "minor",
          "published_at": "2026-07-17T11:57:46Z"
        },
        {
          "tag": "v1.62.1",
          "kind": "patch",
          "published_at": "2026-07-16T20:48:39Z"
        },
        {
          "tag": "v1.62.0",
          "kind": "minor",
          "published_at": "2026-07-16T19:35:26Z"
        },
        {
          "tag": "v1.61.1",
          "kind": "patch",
          "published_at": "2026-07-14T15:30:21Z"
        },
        {
          "tag": "v1.61.0",
          "kind": "minor",
          "published_at": "2026-07-13T06:11:43Z"
        },
        {
          "tag": "v1.60.0",
          "kind": "minor",
          "published_at": "2026-07-12T19:20:23Z"
        },
        {
          "tag": "v1.59.0",
          "kind": "minor",
          "published_at": "2026-07-10T19:49:43Z"
        },
        {
          "tag": "v1.58.5",
          "kind": "patch",
          "published_at": "2026-07-07T16:37:47Z"
        },
        {
          "tag": "v1.58.4",
          "kind": "patch",
          "published_at": "2026-07-07T16:07:48Z"
        },
        {
          "tag": "v1.58.3",
          "kind": "patch",
          "published_at": "2026-07-07T11:08:47Z"
        },
        {
          "tag": "v1.58.2",
          "kind": "patch",
          "published_at": "2026-07-07T10:06:10Z"
        },
        {
          "tag": "v1.58.1",
          "kind": "patch",
          "published_at": "2026-07-07T06:28:08Z"
        },
        {
          "tag": "v1.58.0",
          "kind": "minor",
          "published_at": "2026-07-07T05:01:13Z"
        },
        {
          "tag": "v1.57.0",
          "kind": "minor",
          "published_at": "2026-07-05T20:01:51Z"
        },
        {
          "tag": "v1.56.0",
          "kind": "minor",
          "published_at": "2026-07-05T13:31:03Z"
        },
        {
          "tag": "v1.55.1",
          "kind": "patch",
          "published_at": "2026-06-30T19:28:58Z"
        },
        {
          "tag": "v1.55.0",
          "kind": "minor",
          "published_at": "2026-06-30T17:56:52Z"
        },
        {
          "tag": "v1.54.0",
          "kind": "minor",
          "published_at": "2026-06-30T12:38:55Z"
        },
        {
          "tag": "v1.53.0",
          "kind": "minor",
          "published_at": "2026-06-30T08:34:50Z"
        },
        {
          "tag": "v1.52.0",
          "kind": "minor",
          "published_at": "2026-06-30T04:23:56Z"
        },
        {
          "tag": "v1.51.0",
          "kind": "minor",
          "published_at": "2026-06-29T19:59:25Z"
        },
        {
          "tag": "v1.50.0",
          "kind": "minor",
          "published_at": "2026-06-29T19:49:47Z"
        },
        {
          "tag": "v1.49.0",
          "kind": "minor",
          "published_at": "2026-06-29T12:05:52Z"
        },
        {
          "tag": "v1.48.0",
          "kind": "minor",
          "published_at": "2026-06-29T09:19:47Z"
        },
        {
          "tag": "v1.47.0",
          "kind": "minor",
          "published_at": "2026-06-29T08:45:00Z"
        },
        {
          "tag": "v1.46.0",
          "kind": "minor",
          "published_at": "2026-06-29T07:18:37Z"
        },
        {
          "tag": "v1.45.0",
          "kind": "minor",
          "published_at": "2026-06-28T11:54:22Z"
        },
        {
          "tag": "v1.44.0",
          "kind": "minor",
          "published_at": "2026-06-27T20:00:37Z"
        },
        {
          "tag": "v1.43.0",
          "kind": "minor",
          "published_at": "2026-06-27T10:20:12Z"
        },
        {
          "tag": "v1.42.0",
          "kind": "minor",
          "published_at": "2026-06-26T06:23:44Z"
        },
        {
          "tag": "v1.41.0",
          "kind": "minor",
          "published_at": "2026-06-26T05:12:58Z"
        },
        {
          "tag": "v1.40.0",
          "kind": "minor",
          "published_at": "2026-06-22T15:37:08Z"
        },
        {
          "tag": "v1.39.0",
          "kind": "minor",
          "published_at": "2026-06-18T16:14:17Z"
        },
        {
          "tag": "v1.38.0",
          "kind": "minor",
          "published_at": "2026-06-18T08:57:15Z"
        },
        {
          "tag": "v1.37.0",
          "kind": "minor",
          "published_at": "2026-06-17T18:05:51Z"
        },
        {
          "tag": "v1.36.0",
          "kind": "minor",
          "published_at": "2026-06-15T17:24:47Z"
        },
        {
          "tag": "v1.35.2",
          "kind": "patch",
          "published_at": "2026-06-15T11:44:16Z"
        },
        {
          "tag": "v1.35.1",
          "kind": "patch",
          "published_at": "2026-06-15T06:39:21Z"
        },
        {
          "tag": "v1.35.0",
          "kind": "minor",
          "published_at": "2026-06-15T06:07:49Z"
        },
        {
          "tag": "v1.34.0",
          "kind": "minor",
          "published_at": "2026-06-14T11:57:57Z"
        },
        {
          "tag": "v1.33.0",
          "kind": "minor",
          "published_at": "2026-06-13T08:05:49Z"
        },
        {
          "tag": "v1.32.0",
          "kind": "minor",
          "published_at": "2026-06-09T10:20:47Z"
        },
        {
          "tag": "v1.31.0",
          "kind": "minor",
          "published_at": "2026-06-07T21:03:42Z"
        },
        {
          "tag": "v1.30.0",
          "kind": "minor",
          "published_at": "2026-06-07T17:52:06Z"
        },
        {
          "tag": "v1.29.0",
          "kind": "minor",
          "published_at": "2026-06-07T06:22:54Z"
        },
        {
          "tag": "v1.28.0",
          "kind": "minor",
          "published_at": "2026-05-27T16:38:58Z"
        },
        {
          "tag": "v1.27.1",
          "kind": "patch",
          "published_at": "2026-05-25T21:12:09Z"
        },
        {
          "tag": "v1.27.0",
          "kind": "minor",
          "published_at": "2026-05-24T17:04:33Z"
        },
        {
          "tag": "v1.26.3",
          "kind": "patch",
          "published_at": "2026-05-22T06:22:29Z"
        },
        {
          "tag": "v1.26.2",
          "kind": "patch",
          "published_at": "2026-05-22T06:05:25Z"
        },
        {
          "tag": "v1.26.1",
          "kind": "patch",
          "published_at": "2026-05-21T20:24:27Z"
        },
        {
          "tag": "v1.26.0",
          "kind": "minor",
          "published_at": "2026-05-21T20:04:38Z"
        },
        {
          "tag": "v1.25.0",
          "kind": "minor",
          "published_at": "2026-05-21T11:22:49Z"
        },
        {
          "tag": "v1.24.3",
          "kind": "patch",
          "published_at": "2026-05-21T08:48:19Z"
        },
        {
          "tag": "v1.24.2",
          "kind": "patch",
          "published_at": "2026-05-21T08:10:28Z"
        },
        {
          "tag": "v1.24.1",
          "kind": "patch",
          "published_at": "2026-05-20T19:59:13Z"
        },
        {
          "tag": "v1.24.0",
          "kind": "minor",
          "published_at": "2026-05-20T19:31:52Z"
        },
        {
          "tag": "v1.23.0",
          "kind": "minor",
          "published_at": "2026-05-17T13:10:16Z"
        },
        {
          "tag": "v1.22.0",
          "kind": "minor",
          "published_at": "2026-05-17T11:22:46Z"
        },
        {
          "tag": "v1.21.5",
          "kind": "patch",
          "published_at": "2026-05-14T05:40:27Z"
        },
        {
          "tag": "v1.21.4",
          "kind": "patch",
          "published_at": "2026-05-14T05:20:37Z"
        },
        {
          "tag": "v1.21.3",
          "kind": "patch",
          "published_at": "2026-05-14T05:12:17Z"
        },
        {
          "tag": "v1.21.2",
          "kind": "patch",
          "published_at": "2026-05-13T21:34:50Z"
        },
        {
          "tag": "v1.21.1",
          "kind": "patch",
          "published_at": "2026-05-13T16:04:57Z"
        },
        {
          "tag": "v1.21.0",
          "kind": "minor",
          "published_at": "2026-05-13T15:09:36Z"
        },
        {
          "tag": "v1.20.1",
          "kind": "patch",
          "published_at": "2026-05-12T17:19:06Z"
        },
        {
          "tag": "v1.20.0",
          "kind": "minor",
          "published_at": "2026-05-12T16:06:32Z"
        },
        {
          "tag": "v1.19.4",
          "kind": "patch",
          "published_at": "2026-05-10T09:09:42Z"
        },
        {
          "tag": "v1.19.3",
          "kind": "patch",
          "published_at": "2026-05-09T17:24:36Z"
        },
        {
          "tag": "v1.19.2",
          "kind": "patch",
          "published_at": "2026-05-07T20:35:43Z"
        },
        {
          "tag": "v1.19.1",
          "kind": "patch",
          "published_at": "2026-05-06T18:25:31Z"
        },
        {
          "tag": "v1.19.0",
          "kind": "minor",
          "published_at": "2026-05-06T12:03:03Z"
        },
        {
          "tag": "v1.18.3",
          "kind": "patch",
          "published_at": "2026-05-06T05:14:42Z"
        },
        {
          "tag": "v1.18.2",
          "kind": "patch",
          "published_at": "2026-05-05T16:04:57Z"
        },
        {
          "tag": "v1.18.1",
          "kind": "patch",
          "published_at": "2026-05-05T15:51:07Z"
        },
        {
          "tag": "v1.18.0",
          "kind": "minor",
          "published_at": "2026-05-05T12:25:04Z"
        },
        {
          "tag": "v1.17.0",
          "kind": "minor",
          "published_at": "2026-05-03T09:52:21Z"
        },
        {
          "tag": "v1.16.0",
          "kind": "minor",
          "published_at": "2026-04-30T09:35:48Z"
        },
        {
          "tag": "v1.15.0",
          "kind": "minor",
          "published_at": "2026-04-30T09:16:02Z"
        },
        {
          "tag": "v1.14.1",
          "kind": "patch",
          "published_at": "2026-04-28T10:38:08Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2026-04-27T07:08:41Z"
        },
        {
          "tag": "v1.13.1",
          "kind": "patch",
          "published_at": "2026-04-26T11:42:52Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2026-04-26T08:30:38Z"
        },
        {
          "tag": "v1.12.11",
          "kind": "patch",
          "published_at": "2026-04-25T14:18:03Z"
        },
        {
          "tag": "v1.12.10",
          "kind": "patch",
          "published_at": "2026-04-25T11:39:45Z"
        },
        {
          "tag": "v1.12.9",
          "kind": "patch",
          "published_at": "2026-04-25T11:15:35Z"
        },
        {
          "tag": "v1.12.8",
          "kind": "patch",
          "published_at": "2026-04-25T10:58:34Z"
        },
        {
          "tag": "v1.12.7",
          "kind": "patch",
          "published_at": "2026-04-25T10:18:13Z"
        },
        {
          "tag": "v1.12.6",
          "kind": "patch",
          "published_at": "2026-04-24T22:26:33Z"
        },
        {
          "tag": "v1.12.5",
          "kind": "patch",
          "published_at": "2026-04-24T21:25:37Z"
        },
        {
          "tag": "v1.12.4",
          "kind": "patch",
          "published_at": "2026-04-24T19:37:36Z"
        },
        {
          "tag": "v1.12.3",
          "kind": "patch",
          "published_at": "2026-04-24T16:37:45Z"
        },
        {
          "tag": "v1.12.2",
          "kind": "patch",
          "published_at": "2026-04-24T15:59:56Z"
        },
        {
          "tag": "v1.12.1",
          "kind": "patch",
          "published_at": "2026-04-24T10:16:28Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-04-24T08:45:20Z"
        },
        {
          "tag": "v1.11.13",
          "kind": "patch",
          "published_at": "2026-04-23T18:32:23Z"
        },
        {
          "tag": "v1.11.12",
          "kind": "patch",
          "published_at": "2026-04-23T15:56:05Z"
        },
        {
          "tag": "v1.11.11",
          "kind": "patch",
          "published_at": "2026-04-22T15:32:11Z"
        },
        {
          "tag": "v1.11.10",
          "kind": "patch",
          "published_at": "2026-04-22T14:58:59Z"
        },
        {
          "tag": "v1.11.9",
          "kind": "patch",
          "published_at": "2026-04-22T14:38:19Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "d32f9ae0152a075e2203c0d6ffbe9824b89b77fe",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.63.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T11:57:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cce90468b7a1cf27352db4483fb0903374d07ae",
          "body": "# [1.63.0](https://github.com/node9-ai/node9-proxy/compare/v1.62.1...v1.63.0) (2026-07-17)\n\n### Features\n\n* **sync:** ship syncHealth in policy snapshot (Step 2) ([#250](https://github.com/node9-ai/node9-proxy/issues/250)) ([d85397d](https://github.com/node9-ai/node9-proxy/commit/d85397d050622dbb7f492549e88b3566f6764d3d)), closes [Hi#effort](https://github.com/Hi/issues/effort) [#205](https://github.com/node9-ai/node9-proxy/issues/205)",
          "is_bot": false,
          "headline": "chore(release): 1.63.0 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-17T11:54:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d85397d050622dbb7f492549e88b3566f6764d3d",
          "body": "* fix(ci-check): name the actual granted tools in the CI-2 broad-tools signal\n\nThe broad/write-capable-tools signal emitted a FIXED exemplar string\n(\"Bash/Write/curl/git push\") regardless of what the workflow actually granted,\nso a finding could name tools the file doesn't contain (e.g. lobehub's\nmi\n[…]\n(1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(sync): ship syncHealth in policy snapshot (Step 2) (#250)",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-17T11:54:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "899348566602251b2f34497c5bf3286ac7e89aba",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.62.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-16T20:48:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f80c5ff6b9c75a50fb36f8fb71e67b90612de3fa",
          "body": "## [1.62.1](https://github.com/node9-ai/node9-proxy/compare/v1.62.0...v1.62.1) (2026-07-16)\n\n### Bug Fixes\n\n* **ci-check:** name the actual granted tools in the CI-2 broad-tools signal ([f4b689f](https://github.com/node9-ai/node9-proxy/commit/f4b689f47d466b0c5412ccdeec21e5de8c365689)), closes [Hi#effort](https://github.com/Hi/issues/effort)",
          "is_bot": false,
          "headline": "chore(release): 1.62.1 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-16T20:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4b689f47d466b0c5412ccdeec21e5de8c365689",
          "body": "…signal\n\nThe broad/write-capable-tools signal emitted a FIXED exemplar string\n(\"Bash/Write/curl/git push\") regardless of what the workflow actually granted,\nso a finding could name tools the file doesn't contain (e.g. lobehub's\nmigration-support agent, whose only broad grant is bare `Write`, was rep\n[…]\neck-calibration-round6. T1.2 (gh colon-scoped recognition)\nreclassified to Tier 2 (it changes severity — not a standalone bugfix).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): name the actual granted tools in the CI-2 broad-tools …",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T20:45:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2178a523463bb37f146ec5ba91bef21b23a41fb5",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.62.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-16T19:36:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13d1b257e7231ca669fc8c53c7b6ae65c2b1a49e",
          "body": "# [1.62.0](https://github.com/node9-ai/node9-proxy/compare/v1.61.1...v1.62.0) (2026-07-16)\n\n### Bug Fixes\n\n* **ci-check:** /review-pr findings B1 (dead elevated-perms signal) + B2 (no timeout) ([0454cbc](https://github.com/node9-ai/node9-proxy/commit/0454cbc8a2c849932d399a51aa5c1643ff4286a3))\n* **ci\n[…]\n Performance Improvements\n\n* **ci-check:** parallel fetch + progress spinner for scan-repo (P0.1-A) ([61779b7](https://github.com/node9-ai/node9-proxy/commit/61779b7979d814a544be70ced13f6f2b1fcf5c91))",
          "is_bot": false,
          "headline": "chore(release): 1.62.0 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-16T19:32:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3391ffb252eede3dd93e23f875129e5ba9a06976",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into dev",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T19:24:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2dbc68c1764b23b912ae1572352cb0a3f7f80f76",
          "body": "…dows)\n\nThe 'info-warns on NOT installed' test didn't call setPlatform('linux') like its\nsiblings, so it ran against whatever platform the CI runner actually is. On\nwindows-latest, autostartAdvice's platform guard (added in the code-review pass,\n8976c36) correctly returns null — but the unpinned tes\n[…]\nnd on ubuntu-latest CI).\n\nPin it like the other platform-sensitive tests in the file. Product code is\ncorrect; this is a test-harness fix only.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(ci): pin autostartAdvice platform in the not-installed test (Win…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T18:35:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8976c3635b101735a792f21a24b1d5b7a83c4875",
          "body": "Commit 2 of the policy-sync fix (policy-sync-fix-spec.md). Root cause of the\n7-day-stale policy incident: the daemon's autostart service was installed but\nDISABLED (undetected), and when down, the lazy-start fallback failed invisibly\n(stdio:'ignore', no liveness check) — so a startup crash left zero\n[…]\ning the live one's port\nwrites 'daemon-startup:port-in-use' to daemon-startup.log.\n\nTests: 5 new unit files (27 tests). Full suite 3474 passed.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(daemon): reliable autostart + self-diagnosing daemon start",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T18:12:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ddd6650e5224971c7eb8441db88d8150b4f0d568",
          "body": "…d autostart\n\nPolicy-sync-staleness Commit 2 (liveness). isDaemonServiceInstalled() can't see\nthe exact state that silently staled policy for ~6 days: the autostart unit is\nINSTALLED on disk but DISABLED, so it never runs. Add a strict enabled-probe:\n  - linux: `systemctl --user is-enabled node9-dae\n[…]\nctor/status wiring + self-heal follow. 8 unit tests\n(enabled/disabled/enabled-runtime/absent/darwin/unsupported/malformed-return).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(daemon): isDaemonServiceEnabled() — detect installed-but-disable…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T14:17:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae7130d6adb03354aba68cb13f3e04f4a1bf2ac6",
          "body": "…ndows)\n\nsync-health.integration.test.ts spawned dist/cli.js with only HOME set, but\nthe CLI resolves ~/.node9 via os.homedir(), which reads USERPROFILE (not HOME)\non Windows. So the child read the runner's real empty home and `node9 status`\nreported \"Privacy mode — no API key\" instead of the STALE-\n[…]\nndows only by coincidence).\n\nTest-harness only; no product change. Linux no-regression verified; Windows\ngreen is confirmed by CI.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(ci): set USERPROFILE alongside HOME in integration spawn env (Wi…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T13:43:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e3aba10dc7ad58df907e937f0412077116b9e4b4",
          "body": "…eScore (/review-pr)\n\nThe [0,100] clamp let NaN/Infinity through (NaN fails both min/max\ncomparisons unchanged) → a buggy caller could render a NaN score with a\n'critical' tier. Number.isFinite gate: garbage posture now degrades to\nruntime-only / not-enough-data — never a rendered NaN. Not reachable\nfrom the current caller (hardening), locked by test.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(engine): non-finite posture degrades to null in computeAgentDevic…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T12:57:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1be2e109f2b69dfd3898c1a83a54793a2d85f50a",
          "body": "… + posture (Score-1 Phase 0)\n\nThe Report's Risk Posture blended lifetime session-scan findings into a\n\"current risk\" number — pre-install history inflated the score, and the\nblend was also the reason the time filter couldn't be honest. Score-1\nredesign: current risk = what node9 CAUGHT (live window\n[…]\nvice-design.md §7.\nFail-first: 7-case matrix (null/day-1/earned-100/exact-weights/\nruntime-back-compat/tier-boundaries/clamp). Engine 239 green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(engine): computeAgentDeviceScore — the Report score becomes live…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-16T12:45:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0a94e7d39b6cff5491be69dee58ecaf7a07448d2",
          "body": "The proxy could enforce a days-stale cloud policy with zero signal: syncOnce\nswallowed every error in a bare catch{}, fetchedAt only advanced on content\nchange (so a healthy 304 and a week-broken sync looked identical), and nothing\non the enforce path checked cache age. A machine ran a 7-day-old pol\n[…]\never-fail-open (cache survives a failed sync), and STALE surfaced in stdout.\n\nSpec: doc/roadmap/active/policy-sync-fix-spec.md (Commit 1 of 2).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sync): surface stale/failing cloud-policy sync — never fail open",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-14T18:36:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7d58d9ba2e59df8cb43cd6e89018623a6b41dcac",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.61.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-14T15:30:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e525ca95c92ef27d149e2da9aa20635d8b4edb9",
          "body": "## [1.61.1](https://github.com/node9-ai/node9-proxy/compare/v1.61.0...v1.61.1) (2026-07-14)\n\n### Bug Fixes\n\n* **proxy:** R3 policy FP fixes + F4b MCP server label + Windows CI test ([bc8b474](https://github.com/node9-ai/node9-proxy/commit/bc8b474c68774898a5d1d8848756c04f38757ed5))",
          "is_bot": false,
          "headline": "chore(release): 1.61.1 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-14T15:27:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21d7d1dae65d80d4bcd8d7ec500458cf2d8fc858",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-14T15:26:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc8b474c68774898a5d1d8848756c04f38757ed5",
          "body": "Net release tail (report-v3/ci-check/posture feats already on main from prior releases). Ships: chmod +x no longer flagged world-writable; review-rm waived for same-command create-then-delete cleanup; cloud reporters send the friendly MCP server label (F4b); resolveServerLabel spec fixed on Windows (os.homedir vs $HOME). Patch bump. Detail in PR #247.",
          "is_bot": false,
          "headline": "fix(proxy): R3 policy FP fixes + F4b MCP server label + Windows CI test",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-14T15:26:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b244aeb86e836a0310a2ccef923541eae641aa12",
          "body": "…ir vs $HOME)\n\ndev CI was red on windows-latest only: resolveServerLabel returned the\nDERIVED name ('git') instead of the persisted config name ('my-git').\nRoot cause is the test, not the product: readMcpToolsConfig resolves the\nconfig path via os.homedir(), which on Windows uses USERPROFILE and\nIGN\n[…]\n on every\nplatform — the same pattern mcp-status.spec already uses. Verified by\nsimulating homedir != $HOME (old: MISS->'git'; fixed: 'my-git').\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(mcp): fix Windows-only failure in resolveServerLabel spec (homed…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-14T14:03:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3cb5d3d589c9afa42e4d1c830821146247d7378a",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'report-v3-canon' into HEAD",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-14T07:27:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a393bc5dc2e545a8e1c4e2d66698031a79f7fc9d",
          "body": "…eanup (R3)\n\nThe founder's recurring rm false positive is a write→run→cleanup loop in\nONE command:\n  cat > fn-probe.ts <<'EOF' … EOF\n  npx tsx fn-probe.ts; rm -f fn-probe.ts        ← review-rm prompted here\n\nThe file was created in this very command and never existed before, so the\ndelete protects n\n[…]\n(scratch cleanup allowed; .env,\ncross-command, dynamic, out-of-cwd, glob, append still review). Full suite\n3422 green, typecheck + format clean.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(policy): waive review-rm for a same-command create-then-delete cl…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-14T07:26:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9313a9562d2b1e59e28eeb8b28c8f00702e47646",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'report-v3-canon' into HEAD",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-14T07:19:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "263cc25314ae3c40ab3f50b64593e861e662f3d6",
          "body": "…erverKey hash (F4b)\n\nThe dashboard's MCP table showed rows like \"0c654ece65fb5d6f · 19 tools\"\n— raw serverKey hashes. The tool-call path already resolves display\nlabels (resolveServerLabel), but the three fire-and-forget cloud\nreporters (inventory / pin-mismatch / large-response) passed the raw\nser\n[…]\n as the key — green while production sent a\nhash) + a report-time/late-discovery resolution test. 3422 tests,\ntypecheck, lint, format all green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp): cloud reporters send the friendly server label, never the s…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-13T21:15:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "42155aebcb1de8d33fc889b459e5db48f43004ef",
          "body": "`chmod +x script.sh` grants execute only (→ 775 under a normal umask),\nnever write, yet the live gate reviewed it as \"world-writable… any user\ncan modify it\" — factually false. `+x` was wrongly in the AST detector's\nCHMOD_OPEN_PERM_TOKENS set alongside 777/0777/a+rwx.\n\nDrop `+x` from the set (the ge\n[…]\nrwx` still review.\n\nDogfooding FP on the founder's own scan-repo agents. Verified end-to-end\nvia evaluatePolicy; full suite green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(policy): chmod +x is not world-writable — stop reviewing it",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-13T11:32:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "07d40b12f6a8cbe5249889d8a304c1bababfc9e9",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.61.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-13T06:11:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02c6fc36b5e6e560d00605a8edfa07db52ed095a",
          "body": "# [1.61.0](https://github.com/node9-ai/node9-proxy/compare/v1.60.0...v1.61.0) (2026-07-13)\n\n### Features\n\n* **report:** regroup report dimensions to canon — loops→Detection, app-permission→Apps (v3 P1) ([dd5f13d](https://github.com/node9-ai/node9-proxy/commit/dd5f13d8cb652f553ec401548acf812b043830bf))",
          "is_bot": false,
          "headline": "chore(release): 1.61.0 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-13T06:08:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cb43453b202ea6cb293a04fb09afc58b5e64e1d",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-13T06:08:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd5f13d8cb652f553ec401548acf812b043830bf",
          "body": "…pp-permission→Apps (v3 P1)\n\nnode9 report now attributes catches to the same policy areas as the dashboard: loop-detected/mcp-pin-mismatch/injection* → Detection; app-permission → Apps; out of Tool Rules. Verified node9Firewall canon-taxonomy.ts has the identical mapping (CLI ⇄ dashboard agree). ReportDimensions gains detection{} + apps{}, drops toolRules.mcp/.loops. See #246/#245.",
          "is_bot": false,
          "headline": "feat(report): regroup report dimensions to canon — loops→Detection, a…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-13T06:08:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01c94862545f34a5269cfa8afbab5a708b9f353a",
          "body": "…ission→Apps (v3 P1)\n\nMirrors node9Firewall canon-taxonomy so `node9 report` and the dashboard agree on which policy area caught what. loop-detected/mcp-pin-mismatch/injection* → Detection; app-permission → Apps; out of Tool Rules. ReportDimensions gains detection{loops,pinMismatches,injections} + apps{blocked}; drops toolRules.mcp/.loops. Regroup unit proofs (incl. negatives). See #245.",
          "is_bot": false,
          "headline": "feat(report): regroup dimensions to canon — loops→Detection, app-perm…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-13T05:53:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "485547a2eb7c04dd1d7ad212b3a32210c62d4c87",
          "body": "Mirrors node9Firewall canon-taxonomy.ts so `node9 report` (CLI) and the\ndashboard agree on which policy area caught what. loop-detected /\nmcp-pin-mismatch / injection* now report under Detection (were Tool Rules);\napp-permission blocks under Apps (was toolRules.mcp). ReportDimensions type\n+ CLI repo\n[…]\n) rows.\n\nTests: aggregate regroup proofs (loop→detection, app-permission→apps, both\nout of toolRules) + updated fixtures. Full suite 3398 green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(report): regroup dimensions to canon — loops→Detection (v3 P1 pair)",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T20:35:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e704d1d84efdee3af405062157017b4c5a2cbe07",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.60.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-12T19:20:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c5cdb580622775d1e2d8b92b7682e126829f7c5",
          "body": "# [1.60.0](https://github.com/node9-ai/node9-proxy/compare/v1.59.0...v1.60.0) (2026-07-12)\n\n### Features\n\n* **ci-check:** round-4+round-5 calibration — trustworthy high/crit tier + Codex/monorepo coverage ([d677a9e](https://github.com/node9-ai/node9-proxy/commit/d677a9e641b3869d8d5487881ced5700757b49e7))",
          "is_bot": false,
          "headline": "chore(release): 1.60.0 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-12T19:17:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba37b4f6258ba1b1240373d1b361769b23222dec",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-12T19:16:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d677a9e641b3869d8d5487881ced5700757b49e7",
          "body": "…ier + Codex/monorepo coverage\n\nCalibrates + extends the scan-repo engine: CI-2/CI-4 FP+FN calibration, CI-2 gate polarity, .codex/config.toml analysis, monorepo deep discovery, CI-1 severity depth, and the CI-6 four-class hidden-char model. Validated by 3397 tests, two adversarial /code-review passes, and a 304-repo differential FP scan with hand-verification. See #244.",
          "is_bot": false,
          "headline": "feat(ci-check): round-4+round-5 calibration — trustworthy high/crit t…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T19:16:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "088ed8b69dc4c8e025f92fb810b9eb1ab30da04b",
          "body": "… model), fire on concealment signature\n\nGeneralizes the 5fc2b89 ZWSP fix into the full model: the prior HIDDEN_CHARS regex treated\nevery invisible/formatting char identically and fired critical on PRESENCE, but presence ≠\nconcealment. Four classes, distinct handling:\n\n  A — Unicode tag chars (U+E00\n[…]\nlden by\nconstruction; golden passed 11/11 on 5fc2b89 with the same CI-6 path. Re-run the golden at\nrelease time once quota resets.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-6 — classify hidden chars by legitimacy (four-class…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T18:05:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5fc2b8910079938ed176a616f78efd0063e021e2",
          "body": "…ipts, not always concealment\n\nFound by the post-round-5 differential scan (304 real repos, dev build vs prior recorded\nverdicts): microsoft/generative-ai-for-beginners and microsoft/AI-For-Beginners both jumped\nclean -> critical. Root cause: CI-6's HIDDEN_CHARS flagged U+200B (zero-width space)\nunc\n[…]\nwork broad-allow-no-deny, ruvnet/ruflo\nnested unpinned hook, lobehub a real un-gated workflow the old !contains() bug was hiding).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-6 — zero-width space is legitimate in non-Latin scr…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T17:56:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31c1b1ce3bfb9181d54eadbada585fa0cbf3f85f",
          "body": "…severity-depth items\n\n[6] reusable loaded-gun (CI-2 + CI-4): a workflow_call reusable was hard-capped at medium. Now\n    a reusable that ITSELF checks out an untrusted head to ROOT or ingests untrusted prompt text\n    is a \"loaded gun\" (exploitable the moment a caller wires a fork trigger) → keep i\n[…]\n\nspec 118, typecheck/lint/format clean, golden 15/15 (NVIDIA medium, milvus workflows still found\nvia the tree), full suite green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ci-check): round-5 [6]/[7]/[9]/1d — the remaining code-review + …",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T13:19:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "100786b3558b9eafc59548d5fecce46757902389",
          "body": "The workflow-backed /code-review (16 agents, verify pass) found 10 distinct issues. Fixed the\ncorrectness/security set + cheap cleanups; deferred 3 (noted):\n\n[1] FN — a NEGATED inclusion `!contains(privileged, github.actor)` (runs for everyone EXCEPT\n    the set) was credited as a gate → a wide-open\n[…]\nes response already lists workflows).\n\nTest-first (6 new). Verified: ci-check spec 112, typecheck/lint/format clean, golden 15/15.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): address batch /code-review findings on the round-5 diff",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T12:44:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce90048314f031aae5417aed7df968c813c6c810",
          "body": "…h (monorepo blind spot)\n\nSURFACE_FILES was a fixed list of ROOT paths, so a monorepo's agent surface in sub-packages\n(packages/x/CLAUDE.md, apps/web/.claude/settings.json, nested .mcp.json/.codex/config.toml) was\n100% invisible — a guaranteed false-negative for the repo shape we scan most. The disp\n[…]\n), vscode → 9, langchain → 0 (has none). Golden 15/15, 0 FAIL, no regression,\nno spurious incomplete. typecheck/lint/format clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ci-check): round-5 1c-B — discover the agent surface at ANY dept…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T12:15:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aace7135b50384fbae66648de7a2c19c1eb42565",
          "body": "… fetch)\n\n`.codex/config.toml` was in SURFACE_FILES (fetched every scan) but scanTree had no branch for\nit — the file was downloaded and silently dropped, a coverage false-negative: a risky Codex\nconfig produced zero findings while the same risk in .mcp.json/.claude was flagged. Proven:\na dangerous \n[…]\n\nscanTree integration (dead fetch → live). Verified: ci-check spec 101, typecheck/lint/format\nclean, golden 15/15 (no regression).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ci-check): round-5 1c-A — analyze .codex/config.toml (was a dead…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T11:56:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9e11a7aefdf9fcac35aede6b1152cbc5f6592c9a",
          "body": "…no longer credited)\n\nACTOR_GATE_RE matched `author_association` / `MEMBER` / `OWNER` / `FIRST_TIME_CONTRIBUTOR` /\n`permission` as bare substrings, so an INVERTED actor check read as a gate and CAPPED a\nwide-open workflow to advisory — the most dangerous FN class: a critical that LOOKS gated.\n\n  if:\n[…]\nt clean, golden 14 PASS / 0 FAIL\n(1 network-skip) — metabase label-gate + claude-code implicit gate still credited, no regression.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-2 round-5 1a — actor-gate POLARITY (inverted gates …",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T11:41:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7fac2e0c3f165d501030110d65ae469aedd42ff0",
          "body": "… FP + empty-job crash\n\nRound-4 follow-up closing false-negatives on the high/critical tier, each proven against\na real workflow shape and covered by a failing-first regression test.\n\n- write-all FN: the per-scope permission checks matched only the literal `contents: write`\n  string, so GitHub's `pe\n[…]\nl suite 3359, typecheck/lint/format clean, golden 15/15 (no FP/FN\nregression on the hand-verified real repos), all 3 PoCs correct.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-2 write-all / default-permissions FN + job-override…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T11:32:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "017a4e147645972219cf8908134461ed475fb23a",
          "body": "…e) is the high-tier risk\n\npull-requests:write lets an injected agent gh pr review --approve a malicious PR (bypasses a\nrequired-review gate); the actual merge commit still needs contents:write. Comment-only; no\nbehavior change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(ci-check): precise Fix-4 threat wording — self-approve (not merg…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T10:32:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ac91dc28c96077d1880c87240259203e534ab80e",
          "body": "… the high/crit tier\n\nPrecision fixes to the agentic-workflow analyzer, each keyed to a real repo that was\nmis-scored (a verify pass found 45% FP on the previously-unverified high/crit tier):\n\n- Trigger reachability: workflow_call-only is reusable (scored potentially-untrusted,\n  capped medium — not\n[…]\nulti-agent review (9 findings, 7 false-negatives fixed).\n13 regression tests; 5 FPs now <= medium, all genuine findings unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-2/CI-4 calibration — eliminate 5 false positives on…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-12T07:06:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "85b155921f21fdae72c3ef56bd28c5bdf8da3a10",
          "body": "…requests:write)\n\ncanDamage lumped all GitHub write perms together, so pull-requests/issues:write + a\nscoped gh/git tool read as \"can push code\" -> critical. But git push needs\ncontents:write, and gh api with only pr/issues:write can only comment/label/approve.\nNow three damage tiers: RCE (bare Bash\n[…]\n(ccglass/ding113/podsync) unchanged. 65 ci-check tests incl. 3 negatives\nthat must stay critical (contents:write, PAT, bare Bash).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F15 — write-scope granularity (contents:write vs pull-…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T20:23:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "364f11a525a3448ee25d2bb186efe127129bfda9",
          "body": null,
          "is_bot": false,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T19:55:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43e999c88b0f9d8403642df79eeb1c8637080af9",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.59.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-10T19:49:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a84cee3dc259805d4a4db436a74b532fdee30261",
          "body": "# [1.59.0](https://github.com/node9-ai/node9-proxy/compare/v1.58.5...v1.59.0) (2026-07-10)\n\n### Features\n\n* **ci-check:** agent-reachable secrets (CI-4) + instruction-file (CI-6) checks + injection calibration + scan-repo CTA ([#243](https://github.com/node9-ai/node9-proxy/issues/243)) ([3f0abaf](ht\n[…]\nhub.com/node9-ai/node9-proxy/commit/3f0abaf3c8f3ff7276c48f64cb8b68cf8cf07690)), closes [#1](https://github.com/node9-ai/node9-proxy/issues/1) [#238](https://github.com/node9-ai/node9-proxy/issues/238)",
          "is_bot": false,
          "headline": "chore(release): 1.59.0 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-10T19:47:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "388af6a0a6c358a871cd740fbce3d36c7e9849f2",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-10T19:46:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f0abaf3c8f3ff7276c48f64cb8b68cf8cf07690",
          "body": "…-6) checks + injection calibration + scan-repo CTA (#243)\n\n* feat(posture): make the scorecard a cold-runnable front door (P3.1)\n\n`npx -y node9-ai posture` already resolves + runs the scorecard with zero install\n(verified against published 1.56.0). Two gaps closed so a STRANGER's run is coherent:\n\n\n[…]\n(1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(ci-check): agent-reachable secrets (CI-4) + instruction-file (CI…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T19:41:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a978c6ab3b6904ccfa1f0029c766612a7c9ceee2",
          "body": "Documents scanning a repo (or local folder) for agent-CI hijack risk:\nusage (npx / local / --json), a real demo-repo report, the CI-1..CI-6 check\ntable, and the GitHub Action for gating every PR. Static, config-only, no\ncode execution.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add `node9 scan-repo` — agent-CI security section to README",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c2265e992f0a7d0fb10f69949f88bd81ad8cb0b0",
          "body": "Scans committed instruction files (CLAUDE.md / AGENTS.md / GEMINI.md / .cursorrules /\ncopilot-instructions.md / .windsurfrules / .clinerules) — auto-loaded into the agent's\nsystem prompt straight from the repo, so a poisoned one is a PERSISTENT injection vector\nloaded into every future agent run. Lo\n[…]\n tests incl. FP regressions (install-docs curl|bash under\n## Install -> none; \"never read ~/.aws/...\" -> none; emoji ZWJ -> none).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ci-check): CI-6 — agent instruction-file risk (low-FP core)",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5b8dc9cfcf065a97651b722393a162996ae46e0",
          "body": "CI-2 computed broad-tools / exfil / write-tool capability from ALL agent steps across\nevery job. chmonitor has an injectable triage job (opened + \"*\", scoped Bash(gh:*)) and\na bare-Bash job GATED to a specific assignee — CI-2 merged the two, attributing the\ngated job's bare Bash to the injectable on\n[…]\ngenuine ding113/ccglass unchanged. 54 CI-check\ntests incl. a negative (bare Bash in a SECOND injectable job still counts -> high).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-2 tool detection scoped to the injectable job (G-d)",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "09403f2e1753a423f63871a297c1da843450a0c5",
          "body": "…e (G-c)\n\ncollectTools fed the whole claude_args (including --append-system-prompt) and the\nwhole settings JSON into BROAD_TOOL_RE / EXFIL_RCE_RE. A safety instruction like\n\"never edit code or push commits\" then matched the words \"edit\"/\"push\"/\"bash\", so a\nscoped `Bash(gh:*)` workflow read as broad-\n[…]\ntarget+write (not prose) — correctly untouched.\n52 CI-check tests incl. a negative (real bare Bash + same prose still fires high).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): tool detection reads only grant flags, not prompt pros…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cfb4a6926666861181c84139910035e0284b3d34",
          "body": "…ted trigger (B)\n\nTwo verified false-positive fixes, each caught on a big-name repo:\n\n- A1: a secret bound to a fuel INPUT (anthropic_api_key/ANTHROPIC_BASE_URL/…) is the\n  agent's own fuel regardless of the secret's NAME. NVIDIA/Megatron-LM passes\n  nvidia_inference_key as anthropic_api_key → CI-4 \n[…]\n (precise, no over-clearing). 49 tests incl. an A1\nnegative (a real DATABASE_URL beside the custom fuel key still fires critical).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-4 fuel-by-assignment (A1) + CI-2 reach needs untrus…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b9b57bb6c8bb2644c9ee60978d12f218906f32d7",
          "body": "The terminal scan report trailed off after the last finding with no next\nstep (posture ends on a signup link; scan-repo ended on nothing). Add a\nsingle continuous-coverage CTA pointing at the node9 GitHub Action, so a\none-time scan converts into per-PR coverage.\n\nPresentation only — reads res.worst/\n[…]\ncli_scan_repo for install attribution (mirrors ref=cli_posture).\n\nAdds 4 renderer tests (clean/high/incomplete/markdown-omission).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "scan-repo: add result-aware closing CTA to the Action",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2652ff68d207bf9ff683636891ceedcc934e41e4",
          "body": "CI-4 combined injectable + bare-Bash + secrets across the WHOLE workflow, so a\nsecret + shell sitting in a NON-reachable job falsely combined with a DIFFERENT\njob's untrusted trigger → phantom criticals. This ports CI-2's agent-job scoping\n(F11b) to CI-4: evaluate each agent job independently (its o\n[…]\nt ACTOR_GATE_RE / labelTypeConfigured / ifsAreGated; add jobActorGate\n- 2 regression tests for the two cross-job conflation shapes\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): CI-4 per-agent-job scoping — no cross-job conflation",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "abace3d87886459eb632654ad2ff4211667d9a4b",
          "body": "Implements CI-4 from the design doc (ci-check-ci4-ci5-design.md). New sibling\nanalyzer `analyzeWorkflowSecrets` (reuses CI-2's reachability model) flags EXTRA\nsecrets an agent can reach — cloud OIDC (id-token:write), static PATs, DB creds,\nother API keys — beyond the agent's own fuel (ANTHROPIC_API_\n[…]\nA-4f93-8r6f-vh4x) — added author_association gates (OWNER/MEMBER/COLLABORATOR)\nto the write-capable jobs. Our first confirmed fix.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ci-check): CI-4 — agent-reachable secrets (closes gap 1 of 2)",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-10T14:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "843f7cd5535aed8dabb2620a3368516340dfa125",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.58.5 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T16:37:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bdecf183f4fdad69f854a0facd587ea6ee81fece",
          "body": "## [1.58.5](https://github.com/node9-ai/node9-proxy/compare/v1.58.4...v1.58.5) (2026-07-07)\n\n### Bug Fixes\n\n* **ci-check:** accurate incomplete-cause message + trigger-aware fix text ([#242](https://github.com/node9-ai/node9-proxy/issues/242)) ([2295439](https://github.com/node9-ai/node9-proxy/commit/229543992ca04aee8009d1bfbd57ca44946aecba)), closes [#1](https://github.com/node9-ai/node9-proxy/issues/1) [#238](https://github.com/node9-ai/node9-proxy/issues/238)",
          "is_bot": false,
          "headline": "chore(release): 1.58.5 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-07T16:34:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fbcab6817f48c06077ad19818f2d684bf893cab",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T16:34:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "229543992ca04aee8009d1bfbd57ca44946aecba",
          "body": "…text (#242)\n\n* feat(posture): make the scorecard a cold-runnable front door (P3.1)\n\n`npx -y node9-ai posture` already resolves + runs the scorecard with zero install\n(verified against published 1.56.0). Two gaps closed so a STRANGER's run is coherent:\n\n- Install-aware #1 action: a cold reader (no `\n[…]\n(1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci-check): accurate incomplete-cause message + trigger-aware fix …",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T16:34:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c673f704c0fd1bf91ef7a769d0fa3932d6fdd1d",
          "body": "…-checkout fix text\n\nTwo cosmetic-but-honest fixes from dogfooding:\n- The INCOMPLETE warning hard-coded \"rate-limited\", but `incomplete` also fires on a\n  network timeout (metabase npx run) — and \"set GITHUB_TOKEN\" doesn't help a network\n  error. Now the message states the actual cause (rate limit →\n[…]\ne real\n  base-ref/subdir warning; `pull_request` → \"read-only fork token, low-risk, keep it\n  on pull_request\".\n\nSuite green (34).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): accurate incomplete-cause message + trigger-aware head…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T16:33:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "442b35cdf938bc7eba4837b636c3e68ac6e7716b",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.58.4 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T16:07:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "592ed749aec37e2064578c424919578af3e7092a",
          "body": "## [1.58.4](https://github.com/node9-ai/node9-proxy/compare/v1.58.3...v1.58.4) (2026-07-07)\n\n### Bug Fixes\n\n* **ci-check:** F14 — pull_request ≠ pull_request_target (privilege-aware severity) ([#241](https://github.com/node9-ai/node9-proxy/issues/241)) ([008efb8](https://github.com/node9-ai/node9-proxy/commit/008efb87dd5abce1656cb76628c8d24b20695f5d)), closes [#1](https://github.com/node9-ai/node9-proxy/issues/1) [#238](https://github.com/node9-ai/node9-proxy/issues/238)",
          "is_bot": false,
          "headline": "chore(release): 1.58.4 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-07T16:04:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8166dc5ab31dd65e5faf8c21cd41dd7124e23fe3",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T16:04:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "008efb87dd5abce1656cb76628c8d24b20695f5d",
          "body": "…are severity) (#241)\n\n* feat(posture): make the scorecard a cold-runnable front door (P3.1)\n\n`npx -y node9-ai posture` already resolves + runs the scorecard with zero install\n(verified against published 1.56.0). Two gaps closed so a STRANGER's run is coherent:\n\n- Install-aware #1 action: a cold rea\n[…]\n(1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F14 — pull_request ≠ pull_request_target (privilege-aw…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T16:04:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0104f61cecc261bb25a0fa600ec1c6723584b8f2",
          "body": "…are CI-2)\n\nThe top-150-by-stars sweep flagged metabase/metabase (48K★) HIGH — a false\npositive. Its resolve-backport-conflicts.yml is `pull_request` (NOT _target), so\nfork PRs run with a READ-ONLY token and no secrets — the `contents: write` isn't\ngranted to outsiders and there's nothing to exfil; \n[…]\n+3 tests incl. a pull_request-vs-_target regression (34 total).\nDesign: doc/roadmap/active/ci-check-f14-pull-request-privilege.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F14 — pull_request ≠ pull_request_target (privilege-aw…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T16:03:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c214a41c920e207dcdb29b66c1c8ed63e8ee8e0",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.58.3 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T11:08:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5b859a7f2e196d399fd7638d1a2f6636edc559e",
          "body": "## [1.58.3](https://github.com/node9-ai/node9-proxy/compare/v1.58.2...v1.58.3) (2026-07-07)\n\n### Bug Fixes\n\n* **ci-check:** never report a rate-limited scan as clean; auto-detect gh token ([#240](https://github.com/node9-ai/node9-proxy/issues/240)) ([53cc411](https://github.com/node9-ai/node9-proxy/commit/53cc411715c17bdd5a9cd80b52f62ad1ab82eee2)), closes [#1](https://github.com/node9-ai/node9-proxy/issues/1) [#238](https://github.com/node9-ai/node9-proxy/issues/238)",
          "is_bot": false,
          "headline": "chore(release): 1.58.3 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-07T11:05:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d80848f889277d1fa98d51bed394140249882b29",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T11:05:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53cc411715c17bdd5a9cd80b52f62ad1ab82eee2",
          "body": "… gh token (#240)\n\n* feat(posture): make the scorecard a cold-runnable front door (P3.1)\n\n`npx -y node9-ai posture` already resolves + runs the scorecard with zero install\n(verified against published 1.56.0). Two gaps closed so a STRANGER's run is coherent:\n\n- Install-aware #1 action: a cold reader \n[…]\n(1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci-check): never report a rate-limited scan as clean; auto-detect…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T11:05:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ed63f26485d4989863e928af2a3484d553af356",
          "body": "…p scans)\n\nFollow-on to the false-clean fix: `node9 scan-repo <public-repo>` was inert\nwithout a manually-set GITHUB_TOKEN — a dev with `gh auth login` still hit the\n60/hr unauthenticated limit and got an INCOMPLETE scan. Now resolveGitHubToken()\nfalls back to the gh CLI's stored credentials when no\n[…]\nTE warning).\n\nVerified: unauth hyperdx now reads 17 files → CRITICAL deep-review.yml; 3x-ui →\nrisk found. +test (31). Suite green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ci-check): auto-detect a GitHub token from the gh CLI (zero-setu…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T10:42:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4cae6012e1dc7efe4b0c38c43d130c5c57415664",
          "body": "…e assurance)\n\nRunning `npx node9-ai scan-repo` unauthenticated hits GitHub's 60-req/hr limit,\nso on a real repo it reads few/zero files — yet reported \"✅ agent-security:\nclean · 0 files\" (3x-ui) or a too-low worst (hyperdx missed deep-review.yml).\nFor a security tool, reporting clean on a scan it c\n[…]\nw\nunauthenticated npx — point them at the Action (GITHUB_TOKEN is auto-provided in\nCI) or `GITHUB_TOKEN=$(gh auth token) npx ...`.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): a rate-limited scan must never render as \"clean\" (fals…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T10:30:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1f18b40ee3d345d2a652435f17a415388440381",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.58.2 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T10:06:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90953afac3479b259aaf790f58d9d34ffe5447ba",
          "body": "## [1.58.2](https://github.com/node9-ai/node9-proxy/compare/v1.58.1...v1.58.2) (2026-07-07)\n\n### Bug Fixes\n\n* **ci-check:** F7 — credit claude-code-action's default gate (released-bug fix, release) ([#239](https://github.com/node9-ai/node9-proxy/issues/239)) ([3c2b04f](https://github.com/node9-ai/node9-proxy/commit/3c2b04f2e65f010e5c3ae9d95710aa4a3fc460b0)), closes [#1](https://github.com/node9-ai/node9-proxy/issues/1)",
          "is_bot": false,
          "headline": "chore(release): 1.58.2 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-07T10:03:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5983e3ce68c4254d2bdf977472cab6f886fb21a2",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T10:02:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21b04e8e3ab7ee4cd187fe6912ccc4ec2112bf19",
          "body": "Runs the node9-ai/agent-security-action on every PR to scan this repo's\nagent-security surface. Report-only (fail-on: never) for now.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: dogfood node9 agent-security check on PRs (#238)",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T10:02:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3c2b04f2e65f010e5c3ae9d95710aa4a3fc460b0",
          "body": "…d-bug fix, release) (#239)\n\n* feat(posture): make the scorecard a cold-runnable front door (P3.1)\n\n`npx -y node9-ai posture` already resolves + runs the scorecard with zero install\n(verified against published 1.56.0). Two gaps closed so a STRANGER's run is coherent:\n\n- Install-aware #1 action: a co\n[…]\n(1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F7 — credit claude-code-action's default gate (release…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T10:02:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a5cc0f2624fecebb6f5c461fc00448f3af019917",
          "body": "…ed tools\n\nThe hits 51-100 sweep surfaced repomix as a false HIGH: it uses only\n`--disallowedTools \"Bash,Edit,Write,WebFetch,WebSearch,Task\"` (a DENYLIST that\nBLOCKS those tools) + a read-only job, and documents the design as safe. But\ncollectTools read the raw claude_args string and matched \"Bash\"/\n[…]\nR triggers + '*' + issues/pull-requests:write +\nBash(gh:*)/Bash(git:*) + static PAT), hyperdx stays CRITICAL. +1 test (29). Green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F13 — don't read a --disallowedTools denylist as grant…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T09:52:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd443747e390b4dfdff6e1726b3d55ccdd775d3d",
          "body": "…rm × tool)\n\nDeep-verifying hyperdx vs UKGov exposed the final gap: write PERMISSIONS are only\ndangerous if the agent has a TOOL to exercise them. UKGov (UKGovernmentBEIS/\ninspect_evals) has pull-requests:write + id-token (AWS Bedrock) but its tools are\nread-only (Bash(git diff/log), Read, Write, Gr\n[…]\nical->medium; hyperdx stays CRITICAL (the one genuine finding,\nnow survived six calibration rounds F7-F12). +2 tests. Suite green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F12 — write perms need a TOOL to use them (damage = pe…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T09:38:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e0e6a6c73f4558e367f5e3f130689ca53aeb1ba",
          "body": "Two more over-rating gaps found by deep-verifying the survivors:\n- F11a: catastrophe requires DAMAGE CAPABILITY. An injected agent can only cause\n  real harm if it can write to GitHub (write perms / static PAT) or exfil/RCE\n  (bare Bash / curl / wget / sh — NOT a scoped `Bash(bash scripts/x.sh:*)` o\n[…]\nols). +2 tests. Suite green. Known residual: UKGovernmentBEIS\nhas a custom validate-step gate we don't yet detect (F12, deferred).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F11 — damage-capability + agent-job-scoped permissions",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T09:28:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fbe8d0f535ec9230d185f25e9e141f5f97ea25ed",
          "body": "…gger)\n\nTwo more calibration gaps found by dogfooding on real repos:\n- F10: allowed_non_write_users:'*' was counted as untrusted reach even on\n  schedule/workflow_dispatch/push triggers, where no untrusted user can trigger\n  the workflow — so lobehub's SCHEDULED jobs (moot '*' copy-paste) rated CRIT\n[…]\nnuine catastrophic combo (untrusted trigger + '*' + broad Bash +\nsecrets) still rates high/critical (test). +3 tests. Suite green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F9 (tool scope) + F10 (reach requires an untrusted tri…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T09:01:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f2daadff32853afef8d67a5673bfc2ab38e3f12e",
          "body": "Cousin to F7. A gated workflow (explicit if OR claude-code-action's default\nwrite-access gate) can't be triggered by an untrusted user, so injection is\nblocked regardless of how powerful its tools are. The gate-cap only applied when\nreach>0, so a gated workflow with broad tools + a static PAT + id-t\n[…]\nated workflows (allowed_non_write_users:*) stay\nhigh/medium. Live: NVIDIA HIGH->medium; the ungated demo stays critical. +F8 test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F8 — a gated workflow isn't HIGH on power alone",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T08:35:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "17f254b902cdaa8359d6d166e039536ecfddfcc4",
          "body": "…gate (was crying wolf)\n\nReleased-bug fix. CI-2 flagged the MOST COMMON claude-code-action setup as HIGH\n(\"no effective actor gate\") — but claude-code-action runs the agent ONLY for\nwrite-access users by default. So workflows relying on that default (milvus and\nmost users) were false-HIGH, telling p\n[…]\ne 3293. Known minor edge (/review-pr): a LIST\n(not *) bypass is treated as fully gated — surfaced via the nonWriteList mitigation.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): F7 — credit claude-code-action's default write-access …",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T07:58:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd38bc4e0bfe2c1c3f75ec36f1f6fb10df79b3cf",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.58.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T06:28:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ff9c3c5b2ec87bbc807bb6f7bfd9a2b2433293d",
          "body": "## [1.58.1](https://github.com/node9-ai/node9-proxy/compare/v1.58.0...v1.58.1) (2026-07-07)\n\n### Bug Fixes\n\n* **ci-check:** scan-repo B1/B2 review fixes + P0a e2e ([#237](https://github.com/node9-ai/node9-proxy/issues/237)) ([8b05104](https://github.com/node9-ai/node9-proxy/commit/8b0510403e3a3692fa05d096519ae8b9a4aa6a09)), closes [#1](https://github.com/node9-ai/node9-proxy/issues/1)",
          "is_bot": false,
          "headline": "chore(release): 1.58.1 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-07T06:25:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "368057ca6b3d562ca1cf002f1eb09f617fc63011",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T06:24:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b0510403e3a3692fa05d096519ae8b9a4aa6a09",
          "body": "* feat(posture): make the scorecard a cold-runnable front door (P3.1)\n\n`npx -y node9-ai posture` already resolves + runs the scorecard with zero install\n(verified against published 1.56.0). Two gaps closed so a STRANGER's run is coherent:\n\n- Install-aware #1 action: a cold reader (no `node9` on PATH\n[…]\nude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci-check): scan-repo B1/B2 review fixes + P0a e2e (#237)",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T06:24:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4290ae3b4ade3760eaa76a084afd99c8b9ea3696",
          "body": "…eway deny → flip → forward\n\ntest-robustness-plan P0a: the one green that means 'a block actually blocks'.\nExercises the WHOLE local enforcement chain with real components: the REAL sync\nartifact (rules-cache.json managedConfig.appPermissions keyed by serverKey =\npin hash) → getConfig apply → the RE\n[…]\nck).\n\n3 passed; tc/lint clean. (--no-verify: full suite ran green on P0b minutes ago;\nthis repo has a concurrent active session — see b2cc184.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(gate): P0a enforcement round-trip e2e — managed block → real gat…",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T05:10:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0498f11ce65f050ab720d371f5e5420ff96946de",
          "body": null,
          "is_bot": false,
          "headline": "chore: sync dev from main (1.58.0) + recover P0a round-trip e2e",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T05:10:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0454cbc8a2c849932d399a51aa5c1643ff4286a3",
          "body": "…B2 (no timeout)\n\n- B1: permsElevated ran /contents:\\s*write/ over a JSON-stringified mapping\n  ({\"contents\":\"write\"}), where the key is quoted (contents\":\"write\") — so the\n  regex NEVER matched and the \"elevated permissions\" signal was dead. Confirmed\n  against the live milvus run (its id-token: wr\n[…]\n so one slow file never aborts the batch, and surface a\n  NETWORK \"results may be INCOMPLETE\" note.\n\nFull suite 3289; ci-check 18.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): /review-pr findings B1 (dead elevated-perms signal) + …",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T05:01:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98060b34d49d9ec642582912c0e8d86e41899773",
          "body": null,
          "is_bot": true,
          "headline": "chore(engine): sync to 1.58.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T05:01:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2690a2c0716360a8666ebe71e0a8ad24f48778da",
          "body": "# [1.58.0](https://github.com/node9-ai/node9-proxy/compare/v1.57.0...v1.58.0) (2026-07-07)\n\n### Features\n\n* **report:** Report UI v2 CLI dimensions + posture, with shipped fixes (P0, P3) ([#236](https://github.com/node9-ai/node9-proxy/issues/236)) ([bb736bb](https://github.com/node9-ai/node9-proxy/commit/bb736bb7cbf1d2f907159de094a47552d7e00c03)), closes [#1](https://github.com/node9-ai/node9-proxy/issues/1)",
          "is_bot": false,
          "headline": "chore(release): 1.58.0 [skip ci]",
          "author_name": "semantic-release-bot",
          "author_login": "semantic-release-bot",
          "committed_at": "2026-07-07T04:58:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9407fe740a53285566bc5555420f6f3eb628275",
          "body": null,
          "is_bot": true,
          "headline": "chore: sync dev from main [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T04:57:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb736bb7cbf1d2f907159de094a47552d7e00c03",
          "body": "…es (P0, P3) (#236)\n\n* feat(posture): make the scorecard a cold-runnable front door (P3.1)\n\n`npx -y node9-ai posture` already resolves + runs the scorecard with zero install\n(verified against published 1.56.0). Two gaps closed so a STRANGER's run is coherent:\n\n- Install-aware #1 action: a cold reade\n[…]\n(1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(report): Report UI v2 CLI dimensions + posture, with shipped fix…",
          "author_name": "node9ai",
          "author_login": "node9ai",
          "committed_at": "2026-07-07T04:57:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "61779b7979d814a544be70ced13f6f2b1fcf5c91",
          "body": "The GitHub Contents API calls were sequential — ~21 serial round-trips for a\nrepo like milvus = a multi-second wait with no feedback. Now:\n- bounded-concurrency fetch pool (8) — milvus scan ~8s → ~1.5s;\n- a \\r stderr spinner with phase/progress (resolving → fetching n/N → done),\n  TTY-only and suppr\n[…]\nrogress is a best-effort UX hook threaded fetchTree → scanRepo → the CLI; the\nscan works without it. Full suite 3288; ci-check 17.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(ci-check): parallel fetch + progress spinner for scan-repo (P0.1-A)",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-06T20:12:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b81cd22d2a6b48d82a1d636e5adc8ba749344070",
          "body": "Self-review of the P0 module found three issues:\n- F1 (security): hasActorGate matched the bare word write/admin/maintain anywhere\n  in an `if:`, so a workflow whose `if` referenced a label like `needs-rewrite`\n  was falsely treated as actor-gated — under-rating a genuine injectable workflow\n  (fals\n[…]\nn limit (F6): each\nworkflow file analyzed in isolation — a workflow_call chain to another file may\nbe over-rated. Full suite 3288.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci-check): code-review fixes to the scan-repo analyzer (F1-F3)",
          "author_name": "Node9",
          "author_login": "node9ai",
          "committed_at": "2026-07-06T19:52:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 100,
      "commits_last_year": 1147,
      "latest_release_at": "2026-07-17T11:57:46Z",
      "latest_release_tag": "v1.63.0",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 21,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 1.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@node9/proxy",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-security",
            "agent-security",
            "agentic-ai",
            "mcp",
            "mcp-proxy",
            "claude-code",
            "claude-desktop",
            "codex",
            "gemini-cli",
            "cursor",
            "windsurf",
            "vscode",
            "opencode",
            "pi-agent",
            "hermes-agent",
            "sudo",
            "security-proxy",
            "human-in-the-loop",
            "hitl"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@node9/proxy",
          "is_deprecated": false,
          "latest_version": "1.63.0",
          "repository_url": "https://github.com/node9-ai/node9-proxy",
          "versions_count": 163,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 9089,
          "first_published_at": "2026-03-02T22:31:52.487000Z",
          "latest_published_at": "2026-07-17T11:57:38.628000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 17,
      "stars": 209,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-20",
            "count": 1
          },
          {
            "date": "2026-03-22",
            "count": 3
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-03-29",
            "count": 1
          },
          {
            "date": "2026-04-03",
            "count": 1
          },
          {
            "date": "2026-04-05",
            "count": 1
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-04-20",
            "count": 1
          },
          {
            "date": "2026-04-27",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-04-29",
            "count": 1
          },
          {
            "date": "2026-05-12",
            "count": 1
          },
          {
            "date": "2026-05-13",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 17,
        "total_forks": 17
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/policy-engine/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 154129,
      "source_files_sampled": 409,
      "oversized_source_files": 7,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 3508
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@inquirer/prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.3.0"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.2"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^14.0.3"
        },
        {
          "name": "execa",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.6.1"
        },
        {
          "name": "ink",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.2"
        },
        {
          "name": "mvdan-sh",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.10.1"
        },
        {
          "name": "picomatch",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.3"
        },
        {
          "name": "react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.6"
        },
        {
          "name": "safe-regex2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.1.0"
        },
        {
          "name": "smol-toml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.1"
        },
        {
          "name": "string-width",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.2.3"
        },
        {
          "name": "yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.9.0"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 200,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 12,
        "closed_unmerged_prs": 32
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "node9ai",
          "commits": 649,
          "avatar_url": "https://avatars.githubusercontent.com/u/259619752?v=4"
        },
        {
          "type": "User",
          "login": "semantic-release-bot",
          "commits": 161,
          "avatar_url": "https://avatars.githubusercontent.com/u/32174276?v=4"
        },
        {
          "type": "User",
          "login": "nawi-25",
          "commits": 126,
          "avatar_url": "https://avatars.githubusercontent.com/u/19473686?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.693
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "agent-security.yml",
        "ci.yml",
        "release.yml",
        "sync-dev.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/15 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 6,
            "reason": "dependency not pinned by hash detected -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "46 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d32f9ae0152a075e2203c0d6ffbe9824b89b77fe",
        "ran_at": "2026-07-22T12:12:17Z",
        "aggregate_score": 4.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [
        {
          "number": 251,
          "created_at": "2026-07-19T16:52:20Z",
          "last_comment_at": "2026-07-19T16:52:39Z",
          "last_comment_author": "github-actions"
        }
      ],
      "last_merged_pr_at": "2026-07-17T11:54:12Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/node9-ai/node9-proxy",
    "host": "github.com",
    "name": "node9-proxy",
    "owner": "node9-ai"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 66,
      "inputs": {
        "security": 41,
        "vitality": 83,
        "community": 66,
        "governance": 58,
        "engineering": 76
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 1147,
              "human_commit_share": 0.77,
              "days_since_last_push": 2,
              "active_weeks_last_year": 21
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "21/52 weeks with commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1147 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1147
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v1.63.0",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 1.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 66,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "forks": 17,
              "stars": 209,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "209 stars",
                "points": 37.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 209
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "17 forks",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "packages": [
                "@node9/proxy"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 9089
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "9,089 downloads/month across npm",
                "points": 52.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 9089,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 23,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.693
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 69% of commits",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 69
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "merged_prs": 200,
              "open_issues": 0,
              "closed_issues": 12,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 32
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "200/232 decided PRs merged",
                "points": 33,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 200,
                      "decided": 232
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/15 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "followers": 9,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "node9-ai",
              "public_repos": 8,
              "account_age_days": 144
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "9 followers of node9-ai",
                "points": 7.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 9,
                      "login": "node9-ai"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "8 public repos, account ~0 yr old",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 8
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@node9/proxy"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "163 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 163
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 76,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "ai-safety",
                "ai-security",
                "claude-code",
                "gemini",
                "gemini-cli",
                "llm",
                "llm-agent",
                "mcp-server"
              ],
              "has_wiki": false,
              "homepage": "https://node9.ai/",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://node9.ai/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 41,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 4.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/15 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "46 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 77,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.961,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 3508
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "74 of 77 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 74,
                      "sampled": 77
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/policy-engine/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.55,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/policy-engine/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/policy-engine/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "55 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 55,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 154129,
              "source_files_sampled": 409,
              "oversized_source_files": 7
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "7/409 source files over 60KB",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 409,
                      "oversized": 7
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@node9/proxy@1.63.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T12:12:33.134489Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/node9-ai/node9-proxy.svg",
  "full_name": "node9-ai/node9-proxy",
  "license_state": "custom",
  "license_spdx": null
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.26.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.