Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [],
"is_fork": true,
"size_kb": 71816,
"has_wiki": false,
"homepage": "https://penclip.ing",
"languages": {
"Go": 2459,
"CSS": 95456,
"HCL": 2195,
"HTML": 30991,
"Shell": 198993,
"PLpgSQL": 778,
"Dockerfile": 5593,
"JavaScript": 729163,
"TypeScript": 36824094
},
"pushed_at": "2026-07-18T16:38:12Z",
"created_at": "2026-03-26T16:56:28Z",
"owner_type": "User",
"updated_at": "2026-07-18T15:32:14Z",
"description": "Open-source orchestration for zero-human companies",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "master",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": null,
"type": "User",
"login": "penclipai",
"company": null,
"location": null,
"followers": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/18637088?v=4",
"created_at": "2016-04-24T01:27:10Z",
"is_verified": null,
"public_repos": 27,
"account_age_days": 3742
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": false
},
"activity": {
"releases": [
{
"tag": "v2026.716.0",
"kind": "minor",
"published_at": "2026-07-18T16:38:14Z"
},
{
"tag": "v2026.714.0",
"kind": "minor",
"published_at": "2026-07-15T09:56:30Z"
},
{
"tag": "v2026.704.0",
"kind": "minor",
"published_at": "2026-07-04T16:42:13Z"
},
{
"tag": "v2026.703.0",
"kind": "minor",
"published_at": "2026-07-03T23:58:40Z"
},
{
"tag": "v2026.608.0",
"kind": "minor",
"published_at": "2026-06-08T18:42:25Z"
},
{
"tag": "v2026.607.0",
"kind": "minor",
"published_at": "2026-06-07T14:23:05Z"
},
{
"tag": "v2026.606.0",
"kind": "minor",
"published_at": "2026-06-06T11:37:46Z"
},
{
"tag": "v2026.605.0",
"kind": "minor",
"published_at": "2026-06-05T15:51:52Z"
},
{
"tag": "v2026.602.3",
"kind": "patch",
"published_at": "2026-06-02T19:05:54Z"
},
{
"tag": "v2026.602.2",
"kind": "patch",
"published_at": "2026-06-02T12:52:35Z"
},
{
"tag": "v2026.602.1",
"kind": "patch",
"published_at": "2026-06-02T10:08:50Z"
},
{
"tag": "v2026.602.0",
"kind": "minor",
"published_at": "2026-06-02T06:43:06Z"
},
{
"tag": "v2026.531.0",
"kind": "minor",
"published_at": "2026-05-31T20:15:03Z"
},
{
"tag": "v2026.530.0",
"kind": "minor",
"published_at": "2026-05-30T18:43:33Z"
},
{
"tag": "v2026.522.0",
"kind": "minor",
"published_at": "2026-05-22T06:55:56Z"
},
{
"tag": "v2026.521.0",
"kind": "minor",
"published_at": "2026-05-21T16:28:18Z"
},
{
"tag": "v2026.519.0",
"kind": "minor",
"published_at": "2026-05-19T13:27:36Z"
},
{
"tag": "v2026.514.0",
"kind": "minor",
"published_at": "2026-05-14T16:38:21Z"
},
{
"tag": "v2026.512.0",
"kind": "minor",
"published_at": "2026-05-12T15:21:47Z"
},
{
"tag": "v2026.511.1",
"kind": "patch",
"published_at": "2026-05-11T17:03:48Z"
},
{
"tag": "v2026.511.0",
"kind": "minor",
"published_at": "2026-05-11T08:47:37Z"
},
{
"tag": "v2026.508.2",
"kind": "patch",
"published_at": "2026-05-08T19:22:34Z"
},
{
"tag": "v2026.508.1",
"kind": "patch",
"published_at": "2026-05-08T16:42:11Z"
},
{
"tag": "v2026.508.0",
"kind": "minor",
"published_at": "2026-05-08T07:11:28Z"
},
{
"tag": "v2026.507.0",
"kind": "minor",
"published_at": "2026-05-07T08:22:30Z"
},
{
"tag": "v2026.506.0",
"kind": "minor",
"published_at": "2026-05-06T09:16:28Z"
},
{
"tag": "v2026.505.0",
"kind": "minor",
"published_at": "2026-05-05T17:44:55Z"
},
{
"tag": "v2026.426.0",
"kind": "minor",
"published_at": "2026-04-26T16:53:17Z"
},
{
"tag": "v2026.424.0",
"kind": "minor",
"published_at": "2026-04-24T07:59:07Z"
},
{
"tag": "v2026.419.0",
"kind": "minor",
"published_at": "2026-04-19T06:42:37Z"
},
{
"tag": "v2026.414.2",
"kind": "patch",
"published_at": "2026-04-14T13:52:43Z"
},
{
"tag": "v2026.414.0",
"kind": "minor",
"published_at": "2026-04-14T06:58:04Z"
},
{
"tag": "v2026.413.0",
"kind": "minor",
"published_at": "2026-04-13T04:36:35Z"
},
{
"tag": "v2026.412.0",
"kind": "minor",
"published_at": "2026-04-12T06:53:43Z"
},
{
"tag": "v2026.411.0",
"kind": "minor",
"published_at": "2026-04-11T08:05:52Z"
},
{
"tag": "v2026.410.0",
"kind": "minor",
"published_at": "2026-04-10T09:11:53Z"
},
{
"tag": "v2026.406.0",
"kind": "minor",
"published_at": "2026-04-05T16:43:25Z"
},
{
"tag": "v2026.404.0",
"kind": "minor",
"published_at": "2026-04-04T14:56:33Z"
},
{
"tag": "v2026.401.0",
"kind": "minor",
"published_at": "2026-04-01T02:47:33Z"
}
],
"recent_commits": [
{
"oid": "047c4d51f8e53f32c1daca494e69460cf1695095",
"body": "Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(lockfile): refresh pnpm-lock.yaml (#157)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-18T15:32:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a444e253e0f3521f0dc435592289d41f87be8b4a",
"body": "…very-test\n\nStabilize heartbeat recovery audit assertions",
"is_bot": false,
"headline": "Merge pull request #162 from penclipai/codex/stabilize-heartbeat-reco…",
"author_name": "penclipai",
"author_login": "penclipai",
"committed_at": "2026-07-18T15:31:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "298a58a455440036d7f14538831020542c8079dd",
"body": "The release shard showed that the recovery comment can be visible just before the accepted interaction receives its resumeFailure metadata. Poll for that exact field so the test observes the completed asynchronous pipeline rather than an intermediate database state.\n\nConstraint: The heartbeat pipeli\n[…]\nmic boundary.\n\nConfidence: high\n\nScope-risk: narrow\n\nTested: Focused recovery test 10 consecutive passes; full heartbeat-process-recovery suite 89 passed, 2 skipped; server typecheck; git diff --check",
"is_bot": false,
"headline": "Wait for complete recovery audit state before asserting",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-18T15:17:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6758825c43834672d530d4ca00cbe842f711a744",
"body": "…n-test\n\nStabilize buffered sandbox session coverage",
"is_bot": false,
"headline": "Merge pull request #161 from penclipai/codex/stabilize-sandbox-sessio…",
"author_name": "penclipai",
"author_login": "penclipai",
"committed_at": "2026-07-18T14:37:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2027a0e478d1e30074f22d3a5798182b32d53735",
"body": "The recovery test observed the retry run before the heartbeat pipeline had finished recording its system comment. Wait for the comment using the suite's existing polling helper so the test asserts the completed behavior boundary.\n\nConstraint: Production schedules the retry run before recording follo\n[…]\ne observation.\n\nConfidence: high\n\nScope-risk: narrow\n\nTested: Focused recovery test 5 consecutive passes; full heartbeat-process-recovery suite 89 passed, 2 skipped; server typecheck; git diff --check",
"is_bot": false,
"headline": "Prevent recovery assertions from racing async side effects",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-18T14:24:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e619c2c7abf6143bc702360664754e44023b0d78",
"body": "The CN test harness waited for bridge authentication before ending proxy stdin. When the sandbox child had already exited, authentication flushed the buffered exit and half-closed the socket before the late stdinEnd, producing a repeatable Linux exit-code race.\n\nConstraint: Preserve the Windows dire\n[…]\ns\nTested: target test 20 consecutive passes; execution-target-sandbox.test.ts 26/26; @penclipai/adapter-utils typecheck; general-workspaces-b all projects passed\nNot-tested: Linux CI pending PR checks",
"is_bot": false,
"headline": "Keep buffered sandbox tests on the real proxy input path",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-18T14:08:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a747c317393905b8c9821dd9c78dc930e52bb2fe",
"body": "Merge upstream through decision training and summary slots",
"is_bot": false,
"headline": "Merge pull request #160 from penclipai/codex/upstream-sync-20260716",
"author_name": "penclipai",
"author_login": "penclipai",
"committed_at": "2026-07-18T13:17:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4b67de6c990cad45f26f88e6ac2d060fc7985d0",
"body": "The CN fork boots Playwright in zh-CN by default, so upstream Apps flows must accept both supported locales while keeping seeded names and protocol identifiers exact. Centralize those UI selectors and use structural action-group matching where container text includes tool details.\n\nConstraint: Prese\n[…]\nctor patterns\nTested: apps-prosumer-mcp-flow.spec.ts (3 passed); affected Playwright inventory (33 tests); git diff --check\nNot-tested: Full Playwright suite was not rerun after this selector-only fix",
"is_bot": false,
"headline": "Keep upstream browser coverage valid in the CN-first UI",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-18T13:03:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2c299e3d485c49fba06d5667c9b25d0a6407ec8d",
"body": "…k contracts\n\nMerge the latest upstream summary-slot and decision-training work while retaining the CN fork package namespace, bilingual UI behavior, Windows compatibility, and external-adapter boundaries.\n\nConstraint: Preserve upstream structure and the five durable CN fork concerns.\n\nRejected: Kee\n[…]\n gates; 53-test upstream merge harness; 88 summary/training tests; Windows adapter suites; i18n key parity audit.\n\nNot-tested: full repository typecheck and build will run on the committed merge head.",
"is_bot": false,
"headline": "Absorb upstream summaries and decision training without weakening for…",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-18T12:02:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "936215693cdbce22a3af1b26cbbc35ec846b3504",
"body": "…n predicate (#9787)\n\n## Thinking Path\n\n> - Paperclip runs Codex as a sandboxed agent with its own CODEX_HOME;\nat the start of each run Paperclip merges the sandbox's auth.json with\nthe host's so the agent can authenticate to the Codex API\n> - The merge uses `codex-auth-merge-decision.cjs`, a small \n[…]\nllow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Harold Kim <harold@paperclip.ing>\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(codex-local): add outbound direction to codex-auth-merge decisio…",
"author_name": "Nicky Leach",
"author_login": "nickyleach",
"committed_at": "2026-07-17T21:18:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7ffeafad1f562559db39ea08d98263e952fdc858",
"body": "…redicate into the adapter (#9785)\n\n## Thinking Path\n\n> - Paperclip is an open source platform for managing AI agent teams,\nwith adapter packages providing concrete runtime environments (e.g.\n`codex-local` runs a local OpenAI Codex sandbox)\n> - `adapter-utils` is the shared utilities package — it sh\n[…]\nions, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\nCo-authored-by: Harold Kim <harold@paperclip.ing>\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "refactor(codex-local): relocate Codex auth-merge scripts + decision p…",
"author_name": "Nicky Leach",
"author_login": "nickyleach",
"committed_at": "2026-07-17T19:45:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cf5ba4bbea9d9e21ced6e7e3e662cccee95249f4",
"body": "…9778)\n\n## Thinking Path\n\n> - Paperclip's sandbox managed runtime is responsible for provisioning\nthe agent's execution environment — it extracts a home directory asset\ninto the sandbox before the adapter runs.\n> - The sandbox runtime core was directly branching on the adapter key\n(`codex`) to decid\n[…]\nllow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Harold Kim <harold@paperclip.ing>",
"is_bot": false,
"headline": "feat(adapter-utils): generic per-asset lifecycle-contribution seam (#…",
"author_name": "Nicky Leach",
"author_login": "nickyleach",
"committed_at": "2026-07-17T19:18:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "051ae4d102d57214351b3666a1746f40f1292954",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies and supervise governed work.\n> - Decisions capture high-value operator judgment, and the\ndecision-training foundation merged in #9702 freezes that evidence for\nlater evaluation and learning.\n> - \n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat: restore decision training library and inspector (#9779)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-17T18:27:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7e511a3e525229ffcb3747344827a31d3f36bd4",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - The Inbox lists issues as rows; unread rows show a small blue\nmark-read dot at the leading edge\n> - The dot was rendered as an `order-first` flex column that existed\nonly on unread rows, so it changed \n[…]\n5/5 with no open P2s, recommendations, or follow-ups\n(pending review)\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(ui): stop the inbox unread dot from indenting rows (#9767)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-17T17:21:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a090c09ee567d6c6775a5fb0fa0710b190d5d00e",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies and their work\n> - Human approvals, issue interactions, and execution decisions already\ncapture high-value decision moments\n> - Those moments are currently transient and cannot be reused as stabl\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat: add decision training snapshot foundation (#9702)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-17T17:17:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f1f54523876481ab0011c3fdd0b842753cd511a",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to organize,\ngovern, and understand AI-agent work\n> - Operators need concise, current status views across projects and\nexecution workspaces without manually reading every issue and run\n> - Paperclip already has auditable iss\n[…]\nps\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: add built-in summarizer and summary slots (#9713)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-17T16:03:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a6712fba6b4feb915e6cb9cc4c0a51ab1d3bbe40",
"body": "The bundled workspace diff plugin exposes its slot label through the generic plugin contract. Translate only the known first-party slot at the presentation layer so third-party plugin labels remain untouched.\n\nConstraint: Plugin manifests and unknown third-party labels remain protocol-owned raw valu\n[…]\n high\n\nScope-risk: narrow\n\nTested: focused workspace page and helper tests; locale catalog and validation tests; UI typecheck; token gates; browser zh-CN tab verification; i18n key snapshot comparison",
"is_bot": false,
"headline": "Keep first-party workspace tab labels localized",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-17T15:19:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2101e7bded3d4f29c2596434239453a2d026444a",
"body": "The latest upstream increment moved unread controls into a shared desktop gutter. The merge keeps that structure while retaining the CN fork's catalog-backed accessible label.\n\nConstraint: Preserve upstream layout and CN zh-CN-first accessibility contracts\n\nConfidence: high\n\nScope-risk: narrow\n\nTested: pnpm exec vitest run ui/src/components/IssueRow.test.tsx ui/src/pages/Inbox.test.tsx; pnpm check:token-gates",
"is_bot": false,
"headline": "Preserve localized inbox controls while absorbing upstream alignment",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-17T15:12:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "009410164fc938f7df462d2780cf409a8bd6db90",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - The Inbox lets operators scan task state and distinguish unread\nactivity at a glance\n> - Read and unread rows should keep the same status-and-title alignment\nso the list remains easy to scan\n> - The ma\n[…]\n [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "Fix inbox unread badge alignment (#9685)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-17T14:20:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "36de6d483a429f4f4af29ad9c9e055c07d5bc2d1",
"body": "Merge upstream activity attribution and workspace service controls while preserving CN package identifiers, localized control copy, and token-gate compatibility.\n\nConstraint: The CN fork keeps @penclipai technical package names and zh-CN-first rendered copy.\n\nRejected: Keep upstream hardcoded Englis\n[…]\nparison (20 added, 0 removed/missing/duplicate/fallback); UI and locale suites 39/39; activity attribution 9/9; token gates clean.\n\nNot-tested: repository-wide verification follows on the merged head.",
"is_bot": false,
"headline": "Absorb the latest upstream audit and workspace controls safely",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-17T13:17:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e84f0177ab6969c31f4bfabb9ad9f3bdefa35df5",
"body": "Isolate Vitest temporary roots, avoid adopting the test worker as a runtime service, and make POSIX permission and shell assertions reflect Windows filesystem behavior while preserving the production contracts.\n\nConstraint: Windows path limits, Git shell paths, and permission semantics differ from P\n[…]\nard tests 15/15; workspace runtime 96/96; adapter-utils 7/7; codex-local 135 passed and 1 skipped.\n\nNot-tested: serialized and repository-wide gates are completed after the incremental upstream merge.",
"is_bot": false,
"headline": "Keep the full verification gate reliable on Windows",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-17T13:04:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cc30df85b7eabac46336fe47ca0d98e78e9a57b2",
"body": "The JavaScript fallback now streams pg_dump COPY blocks through postgres.js so embedded and tool-limited environments restore table data instead of failing on COPY FROM stdin.\n\nConstraint: Windows and packaged runtimes may not provide psql.\n\nRejected: Require psql for every restore | breaks the exis\n[…]\nvaScript fallback contract.\n\nConfidence: high\n\nScope-risk: narrow\n\nTested: packages/db/src/backup-lib.test.ts (6/6)\n\nNot-tested: repository-wide gate is completed after the incremental upstream merge.",
"is_bot": false,
"headline": "Keep database restore complete without psql",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-17T13:04:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d42382df4c5724085967027485fcd39b91b01ae",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to coordinate\nAI-agent work.\n> - Execution workspaces provide the local service loop where operators\nstart, stop, restart, inspect, and open workspace services.\n> - The existing header exposed those actions through separate \n[…]\nups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(ui): stabilize workspace service controls (#9705)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-17T02:07:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b07b2994cc57988ec22b4f22cf48415f15cb5ddb",
"body": "## Thinking Path\n\n> - Paperclip is the control plane people use to manage AI-agent\ncompanies and their work\n> - The activity log is the generic audit spine for mutations across the\ncontrol plane\n> - Activity rows identify agents and runs, but they do not persist the\nresponsible human upstream\n> - Re\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat: stamp responsible users on activity logs (#9731)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-17T01:54:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ab7d90105a6c194e67c97e8105da5c857b95e83",
"body": "Merge the newly fetched upstream folders, inbox-policy, recovery, and adapter updates while preserving the fork package scope and zh-CN-first UI. Bound the unsharded Windows general-server lane into deterministic worker lifetimes so the broad release gate can finish reliably.\n\nConstraint: Preserve u\n[…]\nows tests; 14 shard-plan tests; frozen install; i18n snapshot/compare; browser impact audit.\n\nNot-tested: Full test:run, production build, and desktop packaging remain for the post-merge release gate.",
"is_bot": false,
"headline": "Keep the latest upstream increment releasable on the CN fork",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-17T00:11:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53f09cb818b934beadc2a58897604c9ddca1d42e",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to coordinate\nAI-agent companies\n> - Agents, routines, productivity review, and recovery services can all\ncreate or re-trigger work\n> - Repeated heartbeats or catch-up cycles can produce duplicate tasks\nor repeat recovery ac\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix: prevent duplicate task creation and recovery loops (#9648)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T22:00:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a015ac7a57b2f60b074f59daf75b1663bd6d52e7",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - The issue detail chat lets operators send messages while an issue\nrun is live\n> - Messages sent during a live run are shown as queued and can expose\nan interrupt action\n> - The UI only treated running \n[…]\n [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(ui): allow interrupting queued issue runs (#9725)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T21:55:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "59fb27ff794ce60b81b859922112f3d658376918",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies and their work\n> - The inbox is a per-user attention view, so archiving an item must\nnot alter the underlying issue, assignment, or status\n> - Agents can help responsible users tidy resolved work\n[…]\nps\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(inbox): let agents safely tidy user inboxes (#9724)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T21:49:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "89af58b6dc9a7ff869d26ca61ffbd59bd7ed0510",
"body": "## Thinking Path\n\n> - Paperclip is the control plane where operators configure and inspect\nAI-agent work.\n> - An issue can override the assigned agent's primary model for that\ntask.\n> - The issue-properties UI labeled that per-task setting as `Custom ·\n<model>`, which could be read as a property of \n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "Clarify task-level model overrides in issue properties (#9710)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T20:53:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52aea902632fcdb9b3e689c60e3a148a2009358b",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to organize\nand govern AI-agent companies\n> - Company skills are durable resources that users browse, import,\nassign, and maintain over time\n> - A flat skill list plus tags does not provide a stable location or\nhierarchy for\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat: organize skills with nested folders and My Skills (#9633)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T20:50:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1d2b6af5ac4a2cee5d3167a0df22b03610da1bfa",
"body": "## Thinking Path\n\n> - Paperclip is an open-source platform for orchestrating AI agents,\nbuilt on an embedded-Postgres server running a heartbeat loop to advance\nagent work.\n> - The server test suite exercises heartbeat liveness escalation and\nretry scheduling logic against a real embedded database; \n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(tests): stabilize heartbeat cleanup for tsx update (#9573)",
"author_name": "Nicky Leach",
"author_login": "nickyleach",
"committed_at": "2026-07-16T19:02:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "db61cc97d3a369db6a3f54d9e6e97040fd6b4b90",
"body": "Bumps [tsx](https://github.com/privatenumber/tsx) from 4.22.4 to 4.23.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/privatenumber/tsx/releases\">tsx's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v4.23.1</h2>\n<h2><a\nhref=\"https://github.com/privatenumber/tsx\n[…]\n4.22.4...v4.23.1\">compare\nview</a></li>\n</ul>\n</details>\n<br />\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): bump tsx from 4.22.4 to 4.23.1 (#9480)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-16T18:59:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c4da1c925f0bc627d00d4f4da03dce71b7c91fde",
"body": "…o 0.59.0 (#9484)\n\nBumps\n[@agentclientprotocol/claude-agent-acp](https://github.com/agentclientprotocol/claude-agent-acp)\nfrom 0.52.0 to 0.59.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/agentclientprotocol/claude-agent-acp/releases\">@agentclientprot\n[…]\n0.52.0...v0.59.0\">compare\nview</a></li>\n</ul>\n</details>\n<br />\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump @agentclientprotocol/claude-agent-acp from 0.52.0 t…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-16T18:17:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d62c5adb7ab5941ec6aa3968ef69d6dbd075ab9d",
"body": "Fixes #3759\n\n## Thinking Path\n\n> - Paperclip orchestrates AI agents and issue workflows, so the comment\ncomposer has to stay stable under normal typing.\n> - The affected subsystem is the shared markdown comment editor used\nacross issue and workflow surfaces.\n> - That editor decorates mention links a\n[…]\n- [ ] I have updated relevant documentation to reflect my changes\n- [x] I have considered and documented any risks above\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge",
"is_bot": false,
"headline": "fix(ui): stop recreating markdown mention observers (#3809)",
"author_name": "LeonSGP",
"author_login": "LeonSGP43",
"committed_at": "2026-07-16T17:44:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8b04147ca42b29382d8038f43a62d605d9b0cacc",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Its web UI keeps live views fresh with a live-events websocket plus\nReact Query, and #9627 began replacing polling with event-sourcing\n(pushing data into the cache)\n> - After the churn fixes (#9624) an\n[…]\n is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "perf(ui): stop polling the event-sourced company live-runs list (#9701)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T16:42:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5a5c918705d8c9a8d87ef8e4b3dbcc1968f4a504",
"body": "Move Codex ACPX model, reasoning effort, and fast-mode settings into CODEX_CONFIG startup config so arbitrary model IDs avoid ACP session picker validation.\n\nCo-Authored-By: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(acpx): configure Codex models at startup (#9700)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T16:41:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a92124c63c1bf42bf6db58d91a154488435a460",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane for managing AI-agent\ncompanies.\n> - Agent adapters are responsible for launching, observing, and\nterminating provider processes safely.\n> - The local Codex adapter uses an output-inactivity monitor to stop\ngenuinely hung child process\n[…]\nnch is execution-workspace managed and cannot be renamed\nduring this run; the PR title and body intentionally contain no internal\ntracker references.\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(codex-local): raise default output-inactivity timeout to 30m (#9699)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T16:41:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6ec059ab4eb36faa3ad62c915095916c80829c1b",
"body": "…#9695)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - The control plane records a successful-run handoff when productive\nwork ends without a durable next-step disposition\n> - That handoff state was derived only from the latest activity event,\nwit\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): suppress stale handoff alarms during live continuation (…",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T15:49:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a04a77c9d3c665c3653e232ef2a0b4ed7d3b1d91",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies and their work\n> - The inbox subsystem must let agents act for a responsible user\nwithout silently granting access to every company user's tasks\n> - Existing authorization had no inbox-specific a\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(authz): govern agent inbox archive access (#9658)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T14:51:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c65ab09d9faf8c4675bc16957ccfd8a8b0bcfdf5",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies and keep assigned work moving safely.\n> - The recovery subsystem decides whether a failed agent run should\nretry, wait, block for configuration, or escalate to another owner.\n> - Provider usage-l\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(recovery): wait for provider quota resets (#9635)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T14:24:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "85404b46c54172c9801489d5737f422f9c6924f4",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to coordinate\nAI-agent companies.\n> - Its recovery services create productivity reviews and liveness\nescalations when work stops making progress.\n> - Existing uniqueness guards prevent concurrent duplicates, but\nterminal rec\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): throttle serial recovery repeats (#9651)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T14:22:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2a25271a14a3df18db2ceba52651acfc2f07e32e",
"body": "The upstream head advanced with auditable inbox archive policy foundations after the initial release range was drafted. Record that user-facing foundation so the stable artifact matches the exact candidate being promoted.\n\nConstraint: Stable release notes must describe the complete v2026.714.0..cand\n[…]\nange.\n\nConfidence: high\n\nScope-risk: narrow\n\nTested: Database migration test; database typecheck; upstream merge harness; Windows compatibility suite.\n\nNot-tested: Final repository-wide gates pending.",
"is_bot": false,
"headline": "Keep stable notes aligned with the final upstream candidate",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-16T14:09:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2def3c2f261cfce930b8abfdfc6c248fa1501743",
"body": "The upstream branch advanced with company-scoped database contracts for agent-attributed inbox archives after local verification began. Merge that audited increment without rewriting the existing sync history or fork-specific fixes.\n\nConstraint: Upstream synchronization uses merge commits and preser\n[…]\n and retain legacy archive attribution defaults.\nTested: Upstream diff and migration contract review; final database and repository gates follow this merge.\nNot-tested: Final post-merge gates pending.",
"is_bot": false,
"headline": "Preserve inbox policy foundations in the completed upstream sync",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-16T14:07:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "781ce85fb30a17e3394cc4d1a6cba64e447acea6",
"body": "The recovered upstream range exposed Windows-only command and path assumptions plus untranslated routine detail states. Bound the local full-suite invocation, normalize the path assertion, localize the affected routine surfaces, and prepare the stable changelog resolved for the explicit release date\n[…]\nunner tests 12/12; locale/navigation tests 15/15; Claude execute tests 24/24; browser impact audit; i18n snapshot comparison.\n\nNot-tested: Final full gate waits for the newest upstream database merge.",
"is_bot": false,
"headline": "Keep the final sync verifiable and localized on Windows",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-16T14:06:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "da549123cc05c82de452220b2b1d861441b84ada",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - The inbox tracks issue visibility separately for each responsible\nuser\n> - Existing inbox archive records only identify the user whose inbox\nchanged, not the actor that made the change\n> - Agent-manage\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(db): add inbox archive agent policies (#9654)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T13:48:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fa3064526fc6fec23f11082ec33ad23c9389917e",
"body": "The follow-up upstream range adds hot restart safety, recovery observability, search extraction, issue deduplication, and UI guidance. The merge retains those changes while preserving fork package scopes, external-only Hermes boundaries, and complete zh-CN presentation for the new surfaces.\n\nConstra\n[…]\ne-harness tests; 61 Windows tests; 65 release-registry tests; 35 locale tests; 6 i18n audit tests; i18n snapshot comparison\n\nNot-tested: Full repository test and build gates run on the committed merge",
"is_bot": false,
"headline": "Keep CN fork behavior intact as upstream recovery fixes land",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-16T13:13:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "51dd362037c7fe8f1d0af6896d425bb662006d47",
"body": "The upstream merge introduces the tools and MCP platform across shared contracts, server runtime, UI, and release surfaces. Conflict repair keeps the fork's long-lived localization and platform boundaries while retaining upstream structure.\n\nConstraint: Preserve zh-CN, Windows, Electron, external-ad\n[…]\ner upstream head\n\nTested: i18n audit, UI typecheck, focused UI tests, Windows compatibility, merge harness, release registry tests\n\nNot-tested: Full repository gates run after the final upstream merge",
"is_bot": false,
"headline": "Preserve CN fork contracts while absorbing the upstream tools platform",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-16T12:56:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "054b076b58c76847f2a860f1d735f6da494671fa",
"body": "…ist reshapes (#9680)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - The Inbox is the primary triage surface; it supports both mouse\nhover and `j`/`k` keyboard navigation over a flat, expandable list of\nrows\n> - Hover and keyboard selection are me\n[…]\nreptile is 5/5 with no open P2s, recommendations, or follow-ups\n- [ ] I will address all Greptile and reviewer comments before\nrequesting merge\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ui): keep inbox hover and j/k keyboard selection in sync across l…",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T12:50:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "263316609e09f6b4a2c956b9eab946eb70e55449",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage AI\nagents and their work\n> - The server coordinates agent heartbeats and preserves eligible live\nruns during a hot restart\n> - Shutdown previously waited for all heartbeat scheduler work before\ncapturing the hot-re\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): avoid hot restart shutdown deadlock (#9670)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T10:09:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "992389480a243b97bda214227e0767eb8c3672af",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork.\n> - The local heartbeat/runtime subsystem starts long-running local\nagent processes and records their run state.\n> - Operators sometimes need to rebuild and restart the Paperclip server\nwhile local agent \n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): restore hot-restart run adoption (#9647)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T07:46:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cf7711ecc5179a875dd61c02c9174943f32dc2fb",
"body": "…, PAP-13554) (#9417)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - When an agent's task is `blocked`, humans often comment on the issue\nthread expecting it to reopen and resume\n> - If the issue stays `blocked` because an unresolved (not-done)\nbl\n[…]\node execution in the Paperclip harness.\n\n---\n\n- [x] I searched the GitHub PR list for similar/duplicate PRs before\nopening this one.\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(ui): explain when a message won't reopen a blocked issue (Rule C…",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T07:34:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4f9894df4459fde964de91aee9ae09c73bf57efc",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Heartbeat recovery keeps assigned issues moving when a run or\ncontinuation path disappears\n> - Accepted issue-thread interactions can create a continuation wake\nafter an agent previously parked for rev\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): bound accepted-interaction continuation recovery (#9656)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T07:34:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3124dd0f1e65b95b6d7f1e7c236bc067e1c66646",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - When a run is stranded (process lost, adapter failure, a finished\nrun with no disposition, an over-eager inactivity kill), the harness\nopens a *recovery action* and wakes an owner to recover it\n> - Rec\n[…]\ne\nrequesting merge\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(server): recovery observability report and rate alert (#9644)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T07:34:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f44a002b8d3e3e9fbe5fb1c5ab24fa58af6aff4a",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Each company workspace in the web UI is mounted under a URL prefix\n(e.g. `/NEU/company/...`), and `Link` from `@/lib/router` applies that\nprefix automatically via `applyCompanyPrefix`\n> - Company Setti\n[…]\nd-by: Jakub Mikiciuk <jmikiciuk@igus.net>\nCo-authored-by: Cursor <cursoragent@cursor.com>\nCo-authored-by: Andrew Aymeloglu <aaymeloglu@gmail.com>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ui): restore prefix-aware company export/import links (#6648)",
"author_name": "Jakub Mikiciuk",
"author_login": "qbamca",
"committed_at": "2026-07-16T03:52:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "df2404d44377c795be56e0b78dbcfe5b0c1093e2",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane teams use to manage AI\nagents and their work\n> - The Codex local adapter supervises CLI child processes and\nterminates genuinely silent runs\n> - The existing inactivity timer only recognized parsed JSONL stdout\nevents as activity\n> - L\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(codex): count raw child output as activity (#9632)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T02:49:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8eff54bc4720549197e9106cbd253d38f38ac58c",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane operators use to manage\nAI-agent companies.\n> - Operators can store runtime secrets in provider vaults such as AWS\nSecrets Manager.\n> - The server already preserves sanitized AWS failure details,\nincluding the failed operation, require\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "[codex] Explain AWS secret creation failures in the UI (#9645)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T02:47:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8368fb30b01645838a1183666b83754aa8d7424f",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to run\nAI-agent companies.\n> - Scheduled routines support catch-up policies when the server resumes\nafter missed cron ticks.\n> - The existing capped replay policy dispatched once per missed tick,\nwhich can flood the board af\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(routines): coalesce sub-hourly catch-up runs (#9649)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T02:46:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd7c0d5f8340a04a4a340beedb8de56fc9edaf7b",
"body": "## Thinking Path\n\n> Paperclip already treats issue creation as a company-scoped mutation,\nbut retries and parallel agent heartbeats can submit the same create\nmore than once. Client instructions cannot provide at-most-once behavior\nunder concurrency, so the guard belongs in the server transaction. T\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(issues): deduplicate repeated creates (#9650)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T02:45:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea0e8999059b57d57858bec42309bdb0a135b661",
"body": "…te discovery (#9652)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - The `/pr-gardening` skill drives a bundled agent that scans a\ncompany's issues for those linked to open GitHub PRs, then reports on\ntheir state; it relies on the server's company\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(search): honor extract match limits + harden pr-gardening candida…",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T02:44:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5588ddf68175eea448f9d19677b97d7393c38c3d",
"body": "## Thinking Path\n\n> - Paperclip is the control plane operators use to run AI-agent\ncompanies and their isolated development workspaces.\n> - Worktree startup assigns each workspace a server port and an\nembedded PostgreSQL port.\n> - Existing collision detection depended on discovering sibling configs\n\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): prevent recurring worktree port conflicts (#9642)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T01:09:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f1508a79298a745174498d4d0bec8fee59b79e26",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies and review work that needs human attention.\n> - The Decisions page condenses approvals, failed runs, reviews, and\nissue interactions into a scannable attention queue.\n> - Some decision rows alrea\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(decisions): expand image rows into gallery (#9532)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T01:08:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d32ed8844356841e74398217a52746d60525e871",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to coordinate\nAI-agent companies and their work.\n> - Its recovery subsystem detects stranded issue execution and decides\nwhether to retry, escalate, or request operator intervention.\n> - The existing recovery path used a mos\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(recovery): route recovery by failure cause (#9634)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T01:04:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "16b95eece54ef95d9eb5ebfdac952f2bba51f269",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies\n> - Operators need to identify the exact source build running from the\npersistent account menu\n> - PR #9508 added linked source SHA metadata when the server can\ninspect its Git checkout\n> - Produ\n[…]\nks above\n- [x] All Paperclip CI gates pass\n- [x] Greptile review is 5/5 with no open P2-or-higher comments,\nrecommendations, or follow-ups\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): preserve source SHA without Git metadata (#9638)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T01:03:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b606869a6ad0c9531bf8a6745cc901fe076dc4a8",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Its skills layer gives agents repeatable operational workflows\nwithout embedding every procedure in core orchestration\n> - Pull requests referenced across active issue threads currently\nrequire expensi\n[…]\nups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(skills): add active PR gardening workflow (#9510)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T00:05:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ae7790861811323de7ffcedffa9f56cd88b98bc0",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to coordinate\nAI-agent companies\n> - Agents and operators need company-scoped search to discover relevant\nissue history safely\n> - The interactive search endpoint intentionally returns compact\nexcerpts and low pagination cap\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(search): add bulk extract endpoint (#9507)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-16T00:05:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ae2c30f2f48a53fec87c3da05ab63f1964785f1",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies.\n> - Company skills make reusable agent behavior discoverable and\neditable from one place.\n> - Projects already contain skill directories, but operators had to\nimport each skill path manually.\n> \n[…]\nps\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(skills): import skills from projects (#9620)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-15T23:01:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9af96461d53517edaa34153395dd400fc700b0db",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to coordinate\nAI agents and their work.\n> - Its server recovery layer classifies blocked issue graphs and\nrestores interrupted heartbeat execution.\n> - A dependent issue could remain dispatch-suppressed by a cancelled\nblocke\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(server): restore stranded recovery continuations (#9630)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-15T21:41:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bbb3e19c6f5694418f5705dac12cc875f8cccbb9",
"body": "## Thinking Path\n\n> - Parallel local agent experiments should not reuse the primary\nPaperclip instance.\n> - Paperclip already creates isolated worktree instances with generated\nnames and environment files.\n> - The local development guide lacked a complete bootstrap and recovery\npath.\n> - This pull r\n[…]\ndations, or follow-ups\non the latest commit\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: RobinALG87 <RobinALG87@users.noreply.github.com>",
"is_bot": false,
"headline": "docs: add safe local worktree bootstrap guidance (#9195)",
"author_name": "Granis87",
"author_login": "RobinALG87",
"committed_at": "2026-07-15T20:51:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02a4f52277129baea97438355cd343e28bc96084",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Its web UI keeps live views fresh with React Query, coordinated by a\nlive-events websocket (`/api/companies/:id/events/ws`) and cross-tab\npolling\n> - We already cut the worst live-update churn (#9569, \n[…]\nl address all Greptile and reviewer comments before\nrequesting merge\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "perf(ui): event-source the company live-runs list (Phase 1) (#9627)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-15T20:40:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3e348b96b99edcf41388799557274113449baa3b",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Its web UI keeps live views (issue threads, run transcripts,\ndashboard) fresh via React Query polling plus a live-events websocket,\ncoordinated across tabs with a `BroadcastChannel` layer\n> - Long-live\n[…]\nl address all Greptile and reviewer comments before\nrequesting merge\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "perf(ui): cut live-updates churn that inflates tab memory (#9624)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-15T19:17:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3a727bf78067f6c3643a94d8f19e0b32ea1f580d",
"body": null,
"is_bot": false,
"headline": "fix(codex): warn when sandbox auth is shadowed (#9259)",
"author_name": "Nicky Leach",
"author_login": "nickyleach",
"committed_at": "2026-07-15T17:02:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "89ce36d7afcb3b2920c45c47b55f210d635b9976",
"body": "## Thinking Path\n\n> - Paperclip uses company skills to make agent capabilities reusable\nacross an organization.\n> - Skill operations currently mix capability availability with\npermission checks, which creates avoidable setup friction and\ninconsistent denial handling.\n> - The policy contract needs to\n[…]\nquesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: Evyatar Bluzer <bluzername@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(skills): open-by-default company skill policy and core UX (#9564)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-15T16:42:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "24bd860280b5a51315a421ad773a9e2352c94ce3",
"body": "## Thinking Path\n\n> - Paperclip orchestrates AI agents for zero-human companies.\n> - Productivity review reconciliation creates manager-owned review\nissues when assigned work shows no-comment, long-active, or high-churn\npatterns.\n> - SplatImmo hit a loop because productivity-review issues were\nauto-\n[…]\ny risks above\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\nCo-authored-by: Yanis Ismail <yanis.ismail@emissive.fr>\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "Stop cancelled productivity review loops (#5210)",
"author_name": "yismail",
"author_login": "YanisThePie",
"committed_at": "2026-07-15T16:38:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0ecae2cd7efb1d09f2354c6904fd20f266834571",
"body": "…time env authoritative (#9617)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Local coding adapters (Claude, Codex) run each agent heartbeat in a\nspawned child process; Paperclip resolves adapter-configured env —\nincluding `secret_ref` bindings —\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(adapters): forward resolved adapter env to local agents, keep run…",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-15T16:26:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e68f1933f4180383a8d06b58e7ffcf8bdbed1023",
"body": "docs: make CN maintenance skill authoritative",
"is_bot": false,
"headline": "Merge pull request #159 from penclipai/codex/maintain-cn-fork-skill",
"author_name": "penclipai",
"author_login": "penclipai",
"committed_at": "2026-07-15T16:18:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8ab9650350bdd51d0f6c9fce789719921bf58908",
"body": "Condense the CN maintenance trigger description while retaining the sync, recovery, audit, platform, PR, and latest-release activation surfaces.\n\nConstraint: Shipped skill frontmatter descriptions are capped at 300 characters\n\nConfidence: high\n\nScope-risk: narrow\n\nTested: shipped-catalog.test.ts 9 tests; skill quick validation; git diff check\n\nNot-tested: Full CI reruns remotely after push",
"is_bot": false,
"headline": "Keep shipped skill metadata within its prompt budget",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-15T16:03:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b287281940bc1f5e639d5fe71a3f346878427d0d",
"body": "## Problem\n\nThe quickstart docker-compose file was recently moved to\n\\`docker/docker-compose.quickstart.yml\\` during the Docker\nreorganization but still have zero inline comments. When new user copy\nthis file for self-hosting, they see variables like:\n- \\`BETTER_AUTH_SECRET\\` - what is this? How to \n[…]\nvariable with valid values\n- Note about \\`BETTER_AUTH_SECRET\\` with openssl generation command\n- Comment on the volume explaining what data it persist\n\nNo functional change - only YAML comments added.",
"is_bot": false,
"headline": "docs: add inline comments to docker quickstart compose file (#2431)",
"author_name": "Evyatar Bluzer",
"author_login": "bluzername",
"committed_at": "2026-07-15T14:39:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f95efed9cd608760a2cc71755d9e87fd5d8cfded",
"body": "Move durable upstream-sync and UI-localization policy into the maintenance skill so interrupted work, browser audits, and release handoffs share one recoverable source of truth.\n\nConstraint: Preserve only long-lived CN fork contracts and remove the legacy docs without redirect stubs\n\nRejected: Modif\n[…]\nskill quick validation; i18n key audit 6 tests; locale tests; snapshot parity; Markdown links; git diff checks\n\nNot-tested: Product runtime behavior unchanged by this documentation and skill migration",
"is_bot": false,
"headline": "Keep CN fork maintenance guidance authoritative",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-15T14:38:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea66ea81e6cb7afe6ae99f81c4906291e64650fa",
"body": "## Thinking Path\n\n> - Paperclip is the open source control plane people use to manage\nAI-agent companies\n> - Company skills are governed resources, so board users and agents\nacting for responsible users must be authorized consistently before\nmutating skill configuration\n> - The responsible-user auth\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(auth): honor responsible-user grants for company skills (#9571)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-15T12:52:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "79473082762097e0622260229d52cad80ec2b3ec",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Paperclip supports the Codex local adapter, which runs OpenAI Codex\nCLI sessions on behalf of agents\n> - Codex uses OAuth refresh tokens to maintain long-running\nauthenticated sessions\n> - When a refre\n[…]\nle is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "fix(codex): classify refresh auth failures (#9598)",
"author_name": "Nicky Leach",
"author_login": "nickyleach",
"committed_at": "2026-07-15T05:40:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6c6b740e5183c7a542516269be16cf66f9615255",
"body": "…ion-20260715\n\nfix: complete CN localization release readiness",
"is_bot": false,
"headline": "Merge pull request #158 from penclipai/codex/latest-release-localizat…",
"author_name": "penclipai",
"author_login": "penclipai",
"committed_at": "2026-07-15T02:04:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7fb66aa871c91e94b7e84802e5816f83a27244a",
"body": "The browser audit found remaining English UI copy across dense operator surfaces after the upstream sync. This completes the zh-CN catalog coverage, routes shared status and issue interaction labels through translation helpers, and adds the stable release notes required by the release workflow.\n\nCon\n[…]\nrties.test.tsx ui/src/lib/locale-catalog.test.ts ui/src/i18n/locale-validation.test.ts (63 tests)\n\nNot-tested: full live release workflow before this commit; it runs after merge through GitHub Actions",
"is_bot": false,
"headline": "Make the CN latest release safe for localized operators",
"author_name": "chenjunchang",
"author_login": "penclipai",
"committed_at": "2026-07-15T01:49:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7f2ed0ad90d7186d108f65400e322bda08dcbfe2",
"body": "… 403) (#3967)\n\n## Thinking Path\n\n> - Paperclip orchestrates AI agents for zero-human companies\n> - In a multi-tenant deployment, route handlers that take a resource id\n(`issue`, `goal`, `project`, `approval`, etc.) look the resource up by\nid and then call `assertCompanyAccess` on its `companyId` — \n[…]\nf the multi-tenant hardening initiative — see also #5864\n(per-company JWT keys) and #5865 (plugin tables `company_id`).\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "security(server): close cross-tenant existence oracle (404 instead of…",
"author_name": "Jannes Stubbemann",
"author_login": "stubbi",
"committed_at": "2026-07-14T22:53:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b79f744a8d2694a0c8853c0367ec8b8664de0049",
"body": "## Thinking Path\n\n> - Paperclip is the open source platform people use to manage AI agents\nfor work\n> - The Codex adapter runs agent tasks in isolated sandbox environments\non the user's machine\n> - When a Codex sandbox is reused across agent runs, its home directory\n(including `~/.codex/auth.json`) \n[…]\nmments before\nrequesting merge\n\n---------\n\nCo-authored-by: Priya Raman <priya.raman@paperclip.local>\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Harold Kim <harold@paperclip.ing>",
"is_bot": false,
"headline": "Fix Codex auth merge host-unusable fail closed (#9276)",
"author_name": "Nicky Leach",
"author_login": "nickyleach",
"committed_at": "2026-07-14T22:49:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1cfed0c0ff05b27618f0d6f948e55d6dd2e779d5",
"body": "…nvite endpoints (#8979)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Companies onboard human members through shareable invite links; the\n`/api/invites/:token` endpoints are deliberately public so a recipient\ncan view the invite and accept it wi\n[…]\n2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\nSupersedes #8147.\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "security(invites): widen invite-token entropy and rate-limit public i…",
"author_name": "Jannes Stubbemann",
"author_login": "stubbi",
"committed_at": "2026-07-14T22:47:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b4e7ba51436cd437ec6bfc82f6f0f6fe42df6dc5",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Every agent run streams its stdout/stderr/system output into the\nrun-log store (`server/src/services/run-log-store.ts`), and the run-log\nAPI serves those logs back for review and debugging\n> - The only\n[…]\n 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(run-logs): durable run-log store via object-storage mirror (#8984)",
"author_name": "Jannes Stubbemann",
"author_login": "stubbi",
"committed_at": "2026-07-14T22:45:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "543de323f65abe7cbd6852a2546f8f989cf42e2a",
"body": "… (#8986)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Humans sign in through the auth layer; every authenticated request\nparses the session/user profile with `currentUserProfileSchema` in\n`packages/shared`\n> - The schema requires `name` to be `\n[…]\n 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(shared): tolerate empty-string user name in profile/session parse…",
"author_name": "Jannes Stubbemann",
"author_login": "stubbi",
"committed_at": "2026-07-14T22:40:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4f539625f7b63541d1beae1341220702638b7677",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Agents execute inside sandboxed runtime containers built from\n`docker/agent-runtime/Dockerfile.base`\n> - OpenCode's skill tooling shells out to ripgrep; when `rg` is not on\nPATH it tries to download a \n[…]\nll address all Greptile and reviewer comments before\nrequesting merge\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "build(agent-runtime): ship ripgrep in the base image (#8976)",
"author_name": "Jannes Stubbemann",
"author_login": "stubbi",
"committed_at": "2026-07-14T22:38:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "df0e5bd0212cf2f1c98cf2053a4bbb41c7f527b4",
"body": "… comments (#9015)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork.\n> - Agents and humans coordinate on issue threads, where\n`request_confirmation` cards capture pending decisions; a genuine human\ncomment on the thread is meant to supersede (cancel) a \n[…]\non\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>\nCo-authored-by: Andrew Aymeloglu <aaymeloglu@gmail.com>",
"is_bot": false,
"headline": "fix(interactions): don't supersede decision cards on machine-authored…",
"author_name": "Nicholas Sollazzo",
"author_login": "nsollazzo",
"committed_at": "2026-07-14T20:56:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3db2e6bdd2a30bf8860b54361c3b44af0da3cb75",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\n → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563\n- Merge bottom-up only after full-stack review and an empty parity diff\nat #9563.\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 8/8]: add e2e coverage and operator docs (#9563)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T20:48:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f712cedbc2e0c86ffa606018609831167641766a",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\nthubusercontent.com/paperclipai/paperclip/42512d030c96f678c379fbd97d8b7c1737d654fc/doc/screenshots/garden-mcp-split-stack/byo-connect.png)\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 7/8]: activate Apps and gateway UI (#9562)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T20:40:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a116713b9a74f22629df62f7caa3a9707d162b67",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\n.githubusercontent.com/paperclipai/paperclip/ac72de3ec85feb14c5ec1ed0a3d39b29baa0abff/doc/screenshots/garden-mcp-split-stack/policies.png)\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 6/8]: add Tools and Profiles UI foundation (#9561)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T20:31:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9c8adee48b15aa7d12becd767e461a83a306f552",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\n → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563\n- Merge bottom-up only after full-stack review and an empty parity diff\nat #9563.\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 5/8]: integrate adapters and deployment runtime (#9560)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T20:15:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "931eec3fbf83dc425b5381ba5823125162cd13e7",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\n → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563\n- Merge bottom-up only after full-stack review and an empty parity diff\nat #9563.\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 4/8]: wire gateway runtime and Smoke Lab (#9559)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T20:07:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cfa5e0704e6b04d4088edd9f3dc83987069282ef",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\n → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563\n- Merge bottom-up only after full-stack review and an empty parity diff\nat #9563.\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 3/8]: add tool access policy core (#9558)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T19:22:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c6d4ee10f7f009f8bfb93a4dee87fb076760f275",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Its server and UI test suites protect company-scoped plugin access\nand instance settings behavior\n> - Recent governed-access contracts intentionally added company\ninvocation scope and new experimental-\n[…]\nisks above\n- [x] All Paperclip CI gates are green\n- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge",
"is_bot": false,
"headline": "test: align current-master regression expectations (#9577)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T19:03:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b0e9e3664f7e1851771fd549d177be411cffbf9b",
"body": "Auto-generated lockfile refresh after dependencies changed on master.\nThis PR only updates pnpm-lock.yaml.\n\nCo-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(lockfile): refresh pnpm-lock.yaml (#9305)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-14T18:19:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1de0a3bb1e8ff888e911c2ff14394e925bd929c4",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\n → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563\n- Merge bottom-up only after full-stack review and an empty parity diff\nat #9563.\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 2/8]: add governed access contracts (#9557)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T17:57:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b35de65aaabbd53c2393cdf10c2223e36af1c23",
"body": "## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Governed MCP access spans contracts, runtime enforcement, adapters,\nUI surfaces, and operator verification\n> - The parity reference PR #9534 is too large for effective automated\nor human review\n> - The\n[…]\n → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563\n- Merge bottom-up only after full-stack review and an empty parity diff\nat #9563.\n\n---------\n\nCo-authored-by: Paperclip <noreply@paperclip.ing>",
"is_bot": false,
"headline": "feat(mcp) [split 1/8]: add fixture demo servers (#9556)",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T17:56:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f49a3f99243a11b154b22b88c2f0ede16bf66b48",
"body": "…9569)\n\n## Thinking Path\n\n> - Paperclip is the open source app people use to manage AI agents for\nwork\n> - Agents stream their run output live into the web UI, viewed per-run\nin the `AgentDetail` transcript viewer\n> - Browser tabs holding these views were sitting at 8–16 GB of memory\nfootprint while\n[…]\n- [x] I will address all Greptile and reviewer comments before\nrequesting merge\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ui): cap live agent-run transcript buffers to bound tab memory (#…",
"author_name": "Dotta",
"author_login": "cryppadotta",
"committed_at": "2026-07-14T17:43:05Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 39,
"commits_last_year": 3663,
"latest_release_at": "2026-07-18T16:38:14Z",
"latest_release_tag": "v2026.716.0",
"releases_from_tags": false,
"days_since_last_push": 4,
"active_weeks_last_year": 23,
"days_since_latest_release": 4,
"mean_days_between_releases": 5.1
},
"community": {
"has_readme": false,
"has_license": false,
"has_description": false,
"has_contributing": false,
"health_percentage": null,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@penclipai/ui",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@penclipai/ui",
"is_deprecated": false,
"latest_version": "2026.716.0",
"repository_url": "https://github.com/penclipai/paperclip-cn",
"versions_count": 179,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 4262,
"first_published_at": "2026-04-01T01:17:29.153000Z",
"latest_published_at": "2026-07-18T16:37:57.679000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
},
{
"name": "penclip",
"exists": true,
"license": "MIT",
"keywords": [
"paperclip",
"ai",
"agents",
"orchestration",
"cli"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/penclip",
"is_deprecated": false,
"latest_version": "2026.716.0",
"repository_url": "https://github.com/penclipai/paperclip-cn",
"versions_count": 179,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 4543,
"first_published_at": "2026-04-01T01:17:20.552000Z",
"latest_published_at": "2026-07-18T16:37:37.689000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
},
{
"name": "@penclipai/server",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@penclipai/server",
"is_deprecated": false,
"latest_version": "2026.716.0",
"repository_url": "https://github.com/penclipai/paperclip-cn",
"versions_count": 179,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 4744,
"first_published_at": "2026-04-01T01:17:17.196000Z",
"latest_published_at": "2026-07-18T16:37:34.083000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
}
]
},
"popularity": {
"forks": 8,
"stars": 64,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-05-05",
"count": 1
},
{
"date": "2026-05-08",
"count": 1
},
{
"date": "2026-05-10",
"count": 1
},
{
"date": "2026-05-12",
"count": 1
},
{
"date": "2026-05-26",
"count": 1
},
{
"date": "2026-05-28",
"count": 1
},
{
"date": "2026-06-16",
"count": 1
},
{
"date": "2026-07-07",
"count": 1
}
],
"complete": true,
"collected": 8,
"total_forks": 8
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"cli/tsconfig.json",
"packages/adapter-utils/tsconfig.json",
"packages/adapters/claude-local/tsconfig.json",
"packages/adapters/codebuddy-local/tsconfig.json",
"packages/adapters/codex-local/tsconfig.json",
"packages/adapters/cursor-cloud/tsconfig.json",
"packages/adapters/cursor-local/tsconfig.json",
"packages/adapters/gemini-local/tsconfig.json",
"packages/adapters/grok-local/tsconfig.json",
"packages/adapters/openclaw-gateway/tsconfig.json",
"packages/adapters/opencode-local/tsconfig.json",
"packages/adapters/pi-local/tsconfig.json",
"packages/adapters/qwen-local/tsconfig.json",
"packages/db/tsconfig.json",
"packages/desktop-electron/tsconfig.json",
"packages/google-sheets-mcp-server/tsconfig.json",
"packages/kv-demo-mcp-server/tsconfig.json",
"packages/mcp-server/tsconfig.json",
"packages/plugins/create-paperclip-plugin/tsconfig.json",
"packages/plugins/examples/plugin-authoring-smoke-example/tsconfig.json",
"packages/plugins/examples/plugin-file-browser-example/tsconfig.json",
"packages/plugins/examples/plugin-hello-world-example/tsconfig.json",
"packages/plugins/examples/plugin-kitchen-sink-example/tsconfig.json",
"packages/plugins/examples/plugin-orchestration-smoke-example/tsconfig.json",
"packages/plugins/paperclip-plugin-fake-sandbox/tsconfig.json",
"packages/plugins/plugin-llm-wiki/tsconfig.json",
"packages/plugins/plugin-workspace-diff/tsconfig.json",
"packages/plugins/sandbox-providers/cloudflare/bridge-template/tsconfig.json",
"packages/plugins/sandbox-providers/cloudflare/tsconfig.json",
"packages/plugins/sandbox-providers/daytona/tsconfig.json",
"packages/plugins/sandbox-providers/e2b/tsconfig.json",
"packages/plugins/sandbox-providers/exe-dev/tsconfig.json",
"packages/plugins/sandbox-providers/kubernetes/tsconfig.json",
"packages/plugins/sandbox-providers/modal/tsconfig.json",
"packages/plugins/sandbox-providers/novita/tsconfig.json",
"packages/plugins/sdk/tsconfig.json",
"packages/shared/tsconfig.json",
"packages/skills-catalog/tsconfig.json",
"packages/teams-catalog/tsconfig.json",
"server/tsconfig.json",
"tsconfig.json",
"ui/tsconfig.json"
],
"toolchain_manifests": [
"tools/agent-shim/go.mod"
],
"largest_source_bytes": 644995,
"source_files_sampled": 3046,
"oversized_source_files": 100,
"agent_instruction_files": [
"AGENTS.md",
"docs/api/agents.md",
"packages/plugins/plugin-llm-wiki/agents/wiki-maintainer/AGENTS.md",
"packages/plugins/plugin-llm-wiki/fixtures/basic-root/AGENTS.md",
"packages/plugins/plugin-llm-wiki/templates/AGENTS.md",
"packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/ceo/AGENTS.md",
"packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/cto/AGENTS.md",
"packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/qa/AGENTS.md",
"packages/teams-catalog/catalog/bundled/product/product-design/agents/ux-designer/AGENTS.md",
"packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/cto/AGENTS.md",
"packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/qa/AGENTS.md",
"packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/senior-coder/AGENTS.md",
"packages/teams-catalog/catalog/optional/content/content-machine/agents/content-lead/AGENTS.md",
"server/src/built-ins/agents/reflection-coach/AGENTS.md",
"server/src/built-ins/agents/summarizer/AGENTS.md",
"server/src/onboarding-assets/ceo/AGENTS.md",
"server/src/onboarding-assets/default/AGENTS.md"
],
"agent_instruction_max_bytes": 8542
},
"dependencies": {
"manifests": [
"cli/package.json",
"package.json",
"server/package.json",
"ui/package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@clack/prompts",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^0.11.0"
},
{
"name": "@penclipai/adapter-claude-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-codebuddy-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-codex-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-cursor-cloud",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-cursor-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-gemini-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-grok-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-opencode-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-pi-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-qwen-local",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-openclaw-gateway",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-utils",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/db",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/server",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/shared",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "commander",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^13.1.0"
},
{
"name": "dotenv",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^17.4.2"
},
{
"name": "drizzle-orm",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "0.45.2"
},
{
"name": "embedded-postgres",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^18.3.0-beta.17"
},
{
"name": "postgres",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^3.4.9"
},
{
"name": "picocolors",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.1"
},
{
"name": "ws",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^8.19.0"
},
{
"name": "zod",
"manifest": "cli/package.json",
"ecosystem": "npm",
"version_constraint": "^3.24.2"
},
{
"name": "@aws-sdk/client-s3",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^3.1075.0"
},
{
"name": "@penclipai/adapter-claude-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-codebuddy-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-codex-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-cursor-cloud",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-cursor-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-gemini-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-grok-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-openclaw-gateway",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-opencode-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-pi-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-qwen-local",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-utils",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/db",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/plugin-sdk",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/shared",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "ajv",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^8.20.0"
},
{
"name": "ajv-formats",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.1"
},
{
"name": "better-auth",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "1.6.23"
},
{
"name": "chokidar",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.3"
},
{
"name": "detect-port",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.0"
},
{
"name": "dompurify",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^3.4.12"
},
{
"name": "dotenv",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^17.4.2"
},
{
"name": "drizzle-orm",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^0.45.2"
},
{
"name": "embedded-postgres",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^18.3.0-beta.17"
},
{
"name": "express",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^5.1.0"
},
{
"name": "jsdom",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^28.1.0"
},
{
"name": "multer",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^2.2.0"
},
{
"name": "open",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^11.0.0"
},
{
"name": "pino",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^9.6.0"
},
{
"name": "pino-http",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^10.4.0"
},
{
"name": "pino-pretty",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^13.1.3"
},
{
"name": "sharp",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^0.35.3"
},
{
"name": "ssh2",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^1.17.0"
},
{
"name": "ws",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^8.19.0"
},
{
"name": "zod",
"manifest": "server/package.json",
"ecosystem": "npm",
"version_constraint": "^3.24.2"
},
{
"name": "@assistant-ui/react",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "0.14.14"
},
{
"name": "@dnd-kit/core",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^6.3.1"
},
{
"name": "@dnd-kit/sortable",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^10.0.0"
},
{
"name": "@dnd-kit/utilities",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^3.2.2"
},
{
"name": "@lexical/link",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "0.46.0"
},
{
"name": "@mdxeditor/editor",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^3.55.0"
},
{
"name": "@penclipai/adapter-claude-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-codebuddy-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-codex-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-cursor-cloud",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-cursor-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-gemini-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-grok-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-openclaw-gateway",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-opencode-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-pi-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-qwen-local",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/adapter-utils",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@penclipai/shared",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@radix-ui/react-slot",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.3.0"
},
{
"name": "@tailwindcss/typography",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^0.5.20"
},
{
"name": "@tanstack/react-query",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^5.101.2"
},
{
"name": "@xterm/addon-fit",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^0.11.0"
},
{
"name": "@xterm/xterm",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.0"
},
{
"name": "class-variance-authority",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^0.7.1"
},
{
"name": "clsx",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.1"
},
{
"name": "cmdk",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.1"
},
{
"name": "i18next",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^26.3.1"
},
{
"name": "i18next-browser-languagedetector",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^8.2.1"
},
{
"name": "i18next-http-backend",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.2"
},
{
"name": "lexical",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "0.47.0"
},
{
"name": "lucide-react",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^0.577.0"
},
{
"name": "mermaid",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^11.16.0"
},
{
"name": "radix-ui",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.0"
},
{
"name": "react",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.7"
},
{
"name": "react-dom",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.7"
},
{
"name": "react-i18next",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^17.0.9"
},
{
"name": "react-markdown",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^10.1.0"
},
{
"name": "react-resizable-panels",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^4.12.1"
},
{
"name": "react-router-dom",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^7.16.0"
},
{
"name": "remark-gfm",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.1"
},
{
"name": "tailwind-merge",
"manifest": "ui/package.json",
"ecosystem": "npm",
"version_constraint": "^3.6.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 159,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 3
},
"bus_factor": 1,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "cryppadotta",
"commits": 2267,
"avatar_url": "https://avatars.githubusercontent.com/u/34892728?v=4"
},
{
"type": "User",
"login": "penclipai",
"commits": 511,
"avatar_url": "https://avatars.githubusercontent.com/u/18637088?v=4"
},
{
"type": "User",
"login": "devinfoley",
"commits": 258,
"avatar_url": "https://avatars.githubusercontent.com/u/139239?v=4"
},
{
"type": "User",
"login": "nickyleach",
"commits": 51,
"avatar_url": "https://avatars.githubusercontent.com/u/331803?v=4"
},
{
"type": "User",
"login": "mvanhorn",
"commits": 30,
"avatar_url": "https://avatars.githubusercontent.com/u/455140?v=4"
},
{
"type": "User",
"login": "stubbi",
"commits": 28,
"avatar_url": "https://avatars.githubusercontent.com/u/24454679?v=4"
},
{
"type": "User",
"login": "zvictor",
"commits": 28,
"avatar_url": "https://avatars.githubusercontent.com/u/181076?v=4"
},
{
"type": "User",
"login": "HenkDz",
"commits": 25,
"avatar_url": "https://avatars.githubusercontent.com/u/17301927?v=4"
},
{
"type": "User",
"login": "aronprins",
"commits": 24,
"avatar_url": "https://avatars.githubusercontent.com/u/1126344?v=4"
},
{
"type": "User",
"login": "plind-junior",
"commits": 17,
"avatar_url": "https://avatars.githubusercontent.com/u/59729252?v=4"
}
],
"contributors_sampled": 98,
"top_contributor_share": 0.654
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"agent-runtime-images.yml",
"commitperclip-review.yml",
"desktop-release.yml",
"docker.yml",
"e2e.yml",
"pr.yml",
"refresh-lockfile.yml",
"release-smoke.yml",
"release-verify.yml",
"release.yml",
"storybook-visual.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 7,
"reason": "3 out of 4 merged PRs checked by a CI test -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/19 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 12 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "62 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "047c4d51f8e53f32c1daca494e69460cf1695095",
"ran_at": "2026-07-23T04:14:04Z",
"aggregate_score": 5.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-18T16:50:00Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-18T15:32:08Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/penclipai/paperclip-cn",
"host": "github.com",
"name": "paperclip-cn",
"owner": "penclipai"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"security": 51,
"vitality": 84,
"community": 40,
"governance": 61,
"engineering": 53
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 84,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"commits_last_year": 3663,
"human_commit_share": 0.96,
"days_since_last_push": 4,
"active_weeks_last_year": 23
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 4 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 4
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "23/52 weeks with commits",
"points": 15.9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 23
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "3663 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 3663
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 39,
"latest_release_tag": "v2026.716.0",
"releases_from_tags": false,
"days_since_latest_release": 4,
"mean_days_between_releases": 5.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "39 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 39
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 4 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 4
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~5.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 5.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 40,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 36,
"inputs": {
"forks": 8,
"stars": 64,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "64 stars",
"points": 29.2,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 64
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "8 forks",
"points": 7,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 8
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"has_readme": false,
"has_license": false,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 69,
"inputs": {
"packages": [
"@penclipai/ui",
"penclip",
"@penclipai/server"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 13549
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "13,549 downloads/month across npm",
"points": 55.1,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 13549,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 61,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 98,
"top_contributor_share": 0.654
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 65% of commits",
"points": 7.8,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 65
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "98 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 98
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 12 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 70,
"inputs": {
"merged_prs": 159,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 3
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "159/162 decided PRs merged",
"points": 37.5,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 159,
"decided": 162
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/19 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 45,
"inputs": {
"followers": 2,
"owner_type": "User",
"is_verified": null,
"owner_login": "penclipai",
"public_repos": 27,
"account_age_days": 3742
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "2 followers of penclipai",
"points": 3.4,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 2,
"login": "penclipai"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "27 public repos, account ~10 yr old",
"points": 22.5,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 27
}
},
{
"code": "account_age_years",
"params": {
"years": 10
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@penclipai/ui",
"penclip",
"@penclipai/server"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 4
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "3 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 3,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 4 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 4
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "179 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 179
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 53,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "11 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 11
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "3 out of 4 merged PRs checked by a CI test -- score normalized to 7",
"points": 14,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "at_risk",
"name": "Documentation",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": "https://penclip.ing",
"has_readme": false,
"has_docs_dir": true,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://penclip.ing",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 51,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 51,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 5.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "3 out of 4 merged PRs checked by a CI test -- score normalized to 7",
"points": 1.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/19 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 12 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "62 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 7
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 79,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"docs/api/agents.md",
"packages/plugins/plugin-llm-wiki/agents/wiki-maintainer/AGENTS.md",
"packages/plugins/plugin-llm-wiki/fixtures/basic-root/AGENTS.md",
"packages/plugins/plugin-llm-wiki/templates/AGENTS.md",
"packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/ceo/AGENTS.md",
"packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/cto/AGENTS.md",
"packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/qa/AGENTS.md",
"packages/teams-catalog/catalog/bundled/product/product-design/agents/ux-designer/AGENTS.md",
"packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/cto/AGENTS.md",
"packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/qa/AGENTS.md",
"packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/senior-coder/AGENTS.md",
"packages/teams-catalog/catalog/optional/content/content-machine/agents/content-lead/AGENTS.md",
"server/src/built-ins/agents/reflection-coach/AGENTS.md",
"server/src/built-ins/agents/summarizer/AGENTS.md",
"server/src/onboarding-assets/ceo/AGENTS.md",
"server/src/onboarding-assets/default/AGENTS.md"
],
"agent_instruction_max_bytes": 8542
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, docs/api/agents.md, packages/plugins/plugin-llm-wiki/agents/wiki-maintainer/AGENTS.md, packages/plugins/plugin-llm-wiki/fixtures/basic-root/AGENTS.md, packages/plugins/plugin-llm-wiki/templates/AGENTS.md, packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/ceo/AGENTS.md, packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/cto/AGENTS.md, packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/qa/AGENTS.md, packages/teams-catalog/catalog/bundled/product/product-design/agents/ux-designer/AGENTS.md, packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/cto/AGENTS.md, packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/qa/AGENTS.md, packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/senior-coder/AGENTS.md, packages/teams-catalog/catalog/optional/content/content-machine/agents/content-lead/AGENTS.md, server/src/built-ins/agents/reflection-coach/AGENTS.md, server/src/built-ins/agents/summarizer/AGENTS.md, server/src/onboarding-assets/ceo/AGENTS.md, server/src/onboarding-assets/default/AGENTS.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, docs/api/agents.md, packages/plugins/plugin-llm-wiki/agents/wiki-maintainer/AGENTS.md, packages/plugins/plugin-llm-wiki/fixtures/basic-root/AGENTS.md, packages/plugins/plugin-llm-wiki/templates/AGENTS.md, packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/ceo/AGENTS.md, packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/cto/AGENTS.md, packages/teams-catalog/catalog/bundled/company-defaults/core-exec-team/agents/qa/AGENTS.md, packages/teams-catalog/catalog/bundled/product/product-design/agents/ux-designer/AGENTS.md, packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/cto/AGENTS.md, packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/qa/AGENTS.md, packages/teams-catalog/catalog/bundled/software-development/product-engineering/agents/senior-coder/AGENTS.md, packages/teams-catalog/catalog/optional/content/content-machine/agents/content-lead/AGENTS.md, server/src/built-ins/agents/reflection-coach/AGENTS.md, server/src/built-ins/agents/summarizer/AGENTS.md, server/src/onboarding-assets/ceo/AGENTS.md, server/src/onboarding-assets/default/AGENTS.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "96 of 96 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 96,
"sampled": 96
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"pnpm-lock.yaml"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"cli/tsconfig.json",
"packages/adapter-utils/tsconfig.json",
"packages/adapters/claude-local/tsconfig.json",
"packages/adapters/codebuddy-local/tsconfig.json",
"packages/adapters/codex-local/tsconfig.json",
"packages/adapters/cursor-cloud/tsconfig.json",
"packages/adapters/cursor-local/tsconfig.json",
"packages/adapters/gemini-local/tsconfig.json",
"packages/adapters/grok-local/tsconfig.json",
"packages/adapters/openclaw-gateway/tsconfig.json",
"packages/adapters/opencode-local/tsconfig.json",
"packages/adapters/pi-local/tsconfig.json",
"packages/adapters/qwen-local/tsconfig.json",
"packages/db/tsconfig.json",
"packages/desktop-electron/tsconfig.json",
"packages/google-sheets-mcp-server/tsconfig.json",
"packages/kv-demo-mcp-server/tsconfig.json",
"packages/mcp-server/tsconfig.json",
"packages/plugins/create-paperclip-plugin/tsconfig.json",
"packages/plugins/examples/plugin-authoring-smoke-example/tsconfig.json",
"packages/plugins/examples/plugin-file-browser-example/tsconfig.json",
"packages/plugins/examples/plugin-hello-world-example/tsconfig.json",
"packages/plugins/examples/plugin-kitchen-sink-example/tsconfig.json",
"packages/plugins/examples/plugin-orchestration-smoke-example/tsconfig.json",
"packages/plugins/paperclip-plugin-fake-sandbox/tsconfig.json",
"packages/plugins/plugin-llm-wiki/tsconfig.json",
"packages/plugins/plugin-workspace-diff/tsconfig.json",
"packages/plugins/sandbox-providers/cloudflare/bridge-template/tsconfig.json",
"packages/plugins/sandbox-providers/cloudflare/tsconfig.json",
"packages/plugins/sandbox-providers/daytona/tsconfig.json",
"packages/plugins/sandbox-providers/e2b/tsconfig.json",
"packages/plugins/sandbox-providers/exe-dev/tsconfig.json",
"packages/plugins/sandbox-providers/kubernetes/tsconfig.json",
"packages/plugins/sandbox-providers/modal/tsconfig.json",
"packages/plugins/sandbox-providers/novita/tsconfig.json",
"packages/plugins/sdk/tsconfig.json",
"packages/shared/tsconfig.json",
"packages/skills-catalog/tsconfig.json",
"packages/teams-catalog/tsconfig.json",
"server/tsconfig.json",
"tsconfig.json",
"ui/tsconfig.json"
],
"agent_commit_share": 0.19,
"toolchain_manifests": [
"tools/agent-shim/go.mod"
],
"dependency_bot_commit_share": 0.02
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "tools/agent-shim/go.mod (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "tools/agent-shim/go.mod"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "cli/tsconfig.json, packages/adapter-utils/tsconfig.json, packages/adapters/claude-local/tsconfig.json, packages/adapters/codebuddy-local/tsconfig.json, packages/adapters/codex-local/tsconfig.json, packages/adapters/cursor-cloud/tsconfig.json, packages/adapters/cursor-local/tsconfig.json, packages/adapters/gemini-local/tsconfig.json, packages/adapters/grok-local/tsconfig.json, packages/adapters/openclaw-gateway/tsconfig.json, packages/adapters/opencode-local/tsconfig.json, packages/adapters/pi-local/tsconfig.json, packages/adapters/qwen-local/tsconfig.json, packages/db/tsconfig.json, packages/desktop-electron/tsconfig.json, packages/google-sheets-mcp-server/tsconfig.json, packages/kv-demo-mcp-server/tsconfig.json, packages/mcp-server/tsconfig.json, packages/plugins/create-paperclip-plugin/tsconfig.json, packages/plugins/examples/plugin-authoring-smoke-example/tsconfig.json, packages/plugins/examples/plugin-file-browser-example/tsconfig.json, packages/plugins/examples/plugin-hello-world-example/tsconfig.json, packages/plugins/examples/plugin-kitchen-sink-example/tsconfig.json, packages/plugins/examples/plugin-orchestration-smoke-example/tsconfig.json, packages/plugins/paperclip-plugin-fake-sandbox/tsconfig.json, packages/plugins/plugin-llm-wiki/tsconfig.json, packages/plugins/plugin-workspace-diff/tsconfig.json, packages/plugins/sandbox-providers/cloudflare/bridge-template/tsconfig.json, packages/plugins/sandbox-providers/cloudflare/tsconfig.json, packages/plugins/sandbox-providers/daytona/tsconfig.json, packages/plugins/sandbox-providers/e2b/tsconfig.json, packages/plugins/sandbox-providers/exe-dev/tsconfig.json, packages/plugins/sandbox-providers/kubernetes/tsconfig.json, packages/plugins/sandbox-providers/modal/tsconfig.json, packages/plugins/sandbox-providers/novita/tsconfig.json, packages/plugins/sdk/tsconfig.json, packages/shared/tsconfig.json, packages/skills-catalog/tsconfig.json, packages/teams-catalog/tsconfig.json, server/tsconfig.json, tsconfig.json, ui/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "cli/tsconfig.json, packages/adapter-utils/tsconfig.json, packages/adapters/claude-local/tsconfig.json, packages/adapters/codebuddy-local/tsconfig.json, packages/adapters/codex-local/tsconfig.json, packages/adapters/cursor-cloud/tsconfig.json, packages/adapters/cursor-local/tsconfig.json, packages/adapters/gemini-local/tsconfig.json, packages/adapters/grok-local/tsconfig.json, packages/adapters/openclaw-gateway/tsconfig.json, packages/adapters/opencode-local/tsconfig.json, packages/adapters/pi-local/tsconfig.json, packages/adapters/qwen-local/tsconfig.json, packages/db/tsconfig.json, packages/desktop-electron/tsconfig.json, packages/google-sheets-mcp-server/tsconfig.json, packages/kv-demo-mcp-server/tsconfig.json, packages/mcp-server/tsconfig.json, packages/plugins/create-paperclip-plugin/tsconfig.json, packages/plugins/examples/plugin-authoring-smoke-example/tsconfig.json, packages/plugins/examples/plugin-file-browser-example/tsconfig.json, packages/plugins/examples/plugin-hello-world-example/tsconfig.json, packages/plugins/examples/plugin-kitchen-sink-example/tsconfig.json, packages/plugins/examples/plugin-orchestration-smoke-example/tsconfig.json, packages/plugins/paperclip-plugin-fake-sandbox/tsconfig.json, packages/plugins/plugin-llm-wiki/tsconfig.json, packages/plugins/plugin-workspace-diff/tsconfig.json, packages/plugins/sandbox-providers/cloudflare/bridge-template/tsconfig.json, packages/plugins/sandbox-providers/cloudflare/tsconfig.json, packages/plugins/sandbox-providers/daytona/tsconfig.json, packages/plugins/sandbox-providers/e2b/tsconfig.json, packages/plugins/sandbox-providers/exe-dev/tsconfig.json, packages/plugins/sandbox-providers/kubernetes/tsconfig.json, packages/plugins/sandbox-providers/modal/tsconfig.json, packages/plugins/sandbox-providers/novita/tsconfig.json, packages/plugins/sdk/tsconfig.json, packages/shared/tsconfig.json, packages/skills-catalog/tsconfig.json, packages/teams-catalog/tsconfig.json, server/tsconfig.json, tsconfig.json, ui/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "19 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 19,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "2 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 2,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 644995,
"source_files_sampled": 3046,
"oversized_source_files": 100
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "100/3046 source files over 60KB",
"points": 53.2,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 3046,
"oversized": 100
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Community profile unavailable",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"deps.dev does not index npm:@penclipai/ui@2026.716.0; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-23T04:14:30.604438Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/penclipai/paperclip-cn.svg",
"full_name": "penclipai/paperclip-cn",
"license_state": "standard",
"license_spdx": "MIT"
}