Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-24 06:53 UTC

ArcadeAI / safeword

Personal AI agent guides, templates, and learnings

TypeScriptЛіцензію не виявлено★ 8 зірок⑂ 2 форкиз жовт. 2025 р.Переглянути на GitHub ↗

ArcadeAI/safeword має індекс здоров’я 62 зі 100, що відповідає смузі «Помірний». Найвищий показник — Vitality (88/100), найнижчий — Community & Adoption (30/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

62
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

62
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Arcade.devОрганізація
290 підписників82 публічні репозиторіїз груд. 2023 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npmsafeword0.69.07 0361585 днів томуclisafeworddeveloper-experiencelintingclaude-code

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

88Відмінний · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
24.2/36Ритм комітів — 35/52 тижнів із комітами
18/18Обсяг комітів — 2 371 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year2 371
human_commit_share0,94
days_since_last_push0
active_weeks_last_year35
Як обчислюється оцінка
16.2/27Випускає релізи — 48 тегів версій (без релізів GitHub)
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~2,6 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count48
latest_release_tagv0.69.0
releases_from_tagsтак
days_since_latest_release5
mean_days_between_releases2,6
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

30У зоні ризику · 18% загального індексу
Як обчислюється оцінка
13.7/60Зірки — 8 зірок
0/25Форки — 2 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks2
stars8
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
0/22.5Ліцензія — файлу ліцензії не виявлено
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseні
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
51.3/80Щомісячні завантаження — 7 036 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packagessafeword
dependents
ecosystemsnpm
total_downloads
monthly_downloads7 036
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

57Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
5.2/22.5Розподіл комітів — головний контриб’ютор — автор 77% комітів
4.1/13.5Широта контриб’юторів — 3 контриб’юторів
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Використані вхідні дані
bus_factor1
contributors_sampled3
top_contributor_share0,767
Як обчислюється оцінка
18.5/46.8Вирішення issue — закрито 40% issue
34/38.3Прийняття PR — злито 469/527 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 1/27 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs469
open_issues518
closed_issues340
issue_closed_ratio0,396
closed_unmerged_prs58
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
17.7/25Охоплення власника — 290 підписників у ArcadeAI
18.2/25Послужний список — 82 публічних репозиторіїв, вік облікового запису ~2 р.
Використані вхідні дані
followers290
owner_typeOrganization
is_verified
owner_loginArcadeAI
public_repos82
account_age_days957

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 158 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagessafeword
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

72Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 5 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — eslint.config.mjs, ruff.toml
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні

Документація

55Помірний
Як обчислюється оцінка
30/30README
0/25Каталог документації
15/15Сайт документації / домашня сторінка — https://arcadeai.github.io/safeword/
10/10Опис репозиторію
0/10Теми
0/10Wiki
Використані вхідні дані
topics
has_wikiні
homepagehttps://arcadeai.github.io/safeword/
has_readmeтак
has_docs_dirні
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

59Помірний · 16% загального індексу

Стан безпеки

49У зоні ризику
Як обчислюється оцінка
3/7.5Binary-Artifacts — binaries present in source code
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/27 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Ліцензія — license file not detected
7.5/7.5Maintained — 30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4,8
Виключено з оцінювання (немає даних або не застосовно): signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
25/25Непрямі залежності без відомих сповіщень — жодна непряма залежність не має відомих сповіщень
0/40Немає задавнених сповіщень — жодне сповіщення не має дати публікації
Використані вхідні дані
sourceosv
advisories0
affected_packages0
assessed_packages292
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Виключено з оцінювання (немає даних або не застосовно): Немає задавнених сповіщень. Залишкові ваги перенормовано. Звірено з runtime-замиканням залежностей npm:safeword@0.69.0 — тим, що тягне за собою встановлення опублікованого пакета, — 292 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

74Добрий · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — .cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 94 з 94 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share1
agent_instruction_files.cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md
agent_instruction_max_bytes11 149
Як обчислюється оцінка
12.6/18Розгортання однією командою — experiments/go-skill-directive/checker/go.mod (домовленість інструментарію, без раннера задач)
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — eslint.config.mjs, ruff.toml
11/11Статична перевірка типів — packages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json
0/10Відтворюване середовище
10/10Підтверджена практика роботи з агентами — 74 з останніх 100 комітів створено агентом або з його зазначенням
8/8Автоматизоване супроводження — 6 з останніх 100 комітів — автоматичні оновлення залежностей
1/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
Використані вхідні дані
has_nixні
has_testsтак
lockfiles
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configspackages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json
agent_commit_share0,74
toolchain_manifestsexperiments/go-skill-directive/checker/go.mod
dependency_bot_commit_share0,06
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
54.7/55Керовані розміри файлів — 4/855 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes74 384
source_files_sampled855
oversized_source_files4
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
0/40Придатні до запуску приклади
Використані вхідні дані
example_dirs
has_mcp_signalтак
api_schema_files

Ключові факти

8зірок GitHub
3контриб'юторів
2 371комітів за останні 12 місяців
0днів від останнього пушу
48релізів
1бас-фактор
518відкритих issue
npm, PyPIпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

Історія зірок і форків 0 ★ / 2 ⇿
0Зірки
2Форки
9Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

111222212026-062026-062026-06
Мажорні 0Мінорні 8Патчі 1
OpenSSF Scorecard 4.8 / 10
4.8сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-24 06:53 UTC

4Binary-Artifactsbinaries present in source code
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/27 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
1Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
Прямі залежності 34
РеєстрПакетОбмеження версіїМаніфест
npm@cucumber/gherkin^41.0.0packages/cli/package.json
npm@cucumber/messages^34.0.1packages/cli/package.json
npm@eslint-community/eslint-plugin-eslint-comments^4.7.2packages/cli/package.json
npm@eslint-react/eslint-plugin5.14.6packages/cli/package.json
npm@eslint/js^10.0.1packages/cli/package.json
npm@next/eslint-plugin-next16.2.10packages/cli/package.json
npm@secretlint/core^13.0.2packages/cli/package.json
npm@secretlint/secretlint-rule-preset-recommend^13.0.2packages/cli/package.json
npm@tanstack/eslint-plugin-query5.101.2packages/cli/package.json
npm@vitest/eslint-plugin1.6.23packages/cli/package.json
npmcommander15.0.0packages/cli/package.json
npmeslint-config-prettier^10.1.8packages/cli/package.json
npmeslint-import-resolver-typescript^4.4.5packages/cli/package.json
npmeslint-plugin-astro~2.1.1packages/cli/package.json
npmeslint-plugin-better-tailwindcss4.6.1packages/cli/package.json
npmeslint-plugin-import-x^4.17.1packages/cli/package.json
npmeslint-plugin-jsdoc^63.0.13packages/cli/package.json
npmeslint-plugin-playwright2.10.5packages/cli/package.json
npmeslint-plugin-promise^7.3.0packages/cli/package.json
npmeslint-plugin-react-hooks^7.1.1packages/cli/package.json
npmeslint-plugin-regexp3.1.1packages/cli/package.json
npmeslint-plugin-security4.0.1packages/cli/package.json
npmeslint-plugin-simple-import-sort^14.0.0packages/cli/package.json
npmeslint-plugin-sonarjs4.1.0packages/cli/package.json
npmeslint-plugin-storybook10.5.0packages/cli/package.json
npmeslint-plugin-turbo2.10.4packages/cli/package.json
npmeslint-plugin-unicorn72.0.0packages/cli/package.json
npmsmol-toml1.7.0packages/cli/package.json
npmtypescript-eslint8.63.0packages/cli/package.json
npmyaml^2.9.0packages/cli/package.json
npm@astrojs/starlight^0.41.1packages/website/package.json
npmastro^7.0.7packages/website/package.json
npmastro-mermaid^2.1.0packages/website/package.json
npmmermaid^11.16.0packages/website/package.json
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Сповіщення про залежності 0

Встановлення npm:safeword@0.69.0 тягне 292 пакетів, прямих і транзитивних: 0 мають відомі сповіщення, з них 0 — прямі залежності.

Жодне відоме сповіщення не стосується оцінених залежностей.

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 14739,
      "has_wiki": false,
      "homepage": "https://arcadeai.github.io/safeword/",
      "languages": {
        "Go": 710,
        "CSS": 14599,
        "MDX": 61935,
        "Shell": 35402,
        "Python": 12793,
        "Gherkin": 365477,
        "JavaScript": 42262,
        "TypeScript": 5860967,
        "Go Template": 605
      },
      "pushed_at": "2026-07-24T06:03:53Z",
      "created_at": "2025-10-27T03:36:25Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T05:43:07Z",
      "description": "Personal AI agent guides, templates, and learnings",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://docs.arcade.dev",
      "name": "Arcade.dev",
      "type": "Organization",
      "login": "ArcadeAI",
      "company": null,
      "location": "United States of America",
      "followers": 290,
      "avatar_url": "https://avatars.githubusercontent.com/u/153409375?v=4",
      "created_at": "2023-12-10T03:38:49Z",
      "is_verified": null,
      "public_repos": 82,
      "account_age_days": 957
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.69.0",
          "kind": "minor",
          "published_at": "2026-07-18T20:57:56Z"
        },
        {
          "tag": "v0.68.0",
          "kind": "minor",
          "published_at": "2026-07-07T21:47:32Z"
        },
        {
          "tag": "v0.67.0",
          "kind": "minor",
          "published_at": "2026-07-07T05:48:35Z"
        },
        {
          "tag": "v0.63.0",
          "kind": "minor",
          "published_at": "2026-07-04T06:17:29Z"
        },
        {
          "tag": "v0.62.0",
          "kind": "minor",
          "published_at": "2026-07-03T02:33:29Z"
        },
        {
          "tag": "v0.61.0",
          "kind": "minor",
          "published_at": "2026-07-02T19:18:23Z"
        },
        {
          "tag": "v0.60.0",
          "kind": "minor",
          "published_at": "2026-07-01T15:50:40Z"
        },
        {
          "tag": "v0.59.0",
          "kind": "minor",
          "published_at": "2026-07-01T01:09:06Z"
        },
        {
          "tag": "v0.58.0",
          "kind": "minor",
          "published_at": "2026-06-26T13:32:39Z"
        },
        {
          "tag": "v0.57.0",
          "kind": "minor",
          "published_at": "2026-06-25T00:51:17Z"
        },
        {
          "tag": "v0.56.0",
          "kind": "minor",
          "published_at": "2026-06-24T18:18:47Z"
        },
        {
          "tag": "v0.55.0",
          "kind": "minor",
          "published_at": "2026-06-23T00:46:41Z"
        },
        {
          "tag": "v0.54.0",
          "kind": "minor",
          "published_at": "2026-06-21T14:04:28Z"
        },
        {
          "tag": "v0.52.1",
          "kind": "patch",
          "published_at": "2026-06-18T19:31:24Z"
        },
        {
          "tag": "v0.52.0",
          "kind": "minor",
          "published_at": "2026-06-18T14:39:39Z"
        },
        {
          "tag": "v0.51.0",
          "kind": "minor",
          "published_at": "2026-06-18T01:51:32Z"
        },
        {
          "tag": "v0.49.0",
          "kind": "minor",
          "published_at": "2026-06-16T05:52:57Z"
        },
        {
          "tag": "v0.48.0",
          "kind": "minor",
          "published_at": "2026-06-15T23:53:12Z"
        },
        {
          "tag": "v0.47.0",
          "kind": "minor",
          "published_at": "2026-06-14T04:47:11Z"
        },
        {
          "tag": "v0.46.2",
          "kind": "patch",
          "published_at": "2026-06-13T17:27:28Z"
        },
        {
          "tag": "v0.46.1",
          "kind": "patch",
          "published_at": "2026-06-13T14:24:51Z"
        },
        {
          "tag": "v0.46.0",
          "kind": "minor",
          "published_at": "2026-06-13T01:24:00Z"
        },
        {
          "tag": "v0.45.0",
          "kind": "minor",
          "published_at": "2026-06-12T17:57:53Z"
        },
        {
          "tag": "v0.44.0",
          "kind": "minor",
          "published_at": "2026-06-12T13:31:44Z"
        },
        {
          "tag": "v0.43.0",
          "kind": "minor",
          "published_at": "2026-06-10T21:51:51Z"
        },
        {
          "tag": "v0.42.0",
          "kind": "minor",
          "published_at": "2026-06-05T18:24:38Z"
        },
        {
          "tag": "v0.41.0",
          "kind": "minor",
          "published_at": "2026-06-01T18:25:08Z"
        },
        {
          "tag": "v0.40.1",
          "kind": "patch",
          "published_at": "2026-06-01T16:56:13Z"
        },
        {
          "tag": "v0.40.0",
          "kind": "minor",
          "published_at": "2026-06-01T15:53:00Z"
        },
        {
          "tag": "v0.39.1",
          "kind": "patch",
          "published_at": "2026-05-28T04:44:41Z"
        },
        {
          "tag": "v0.39.0",
          "kind": "minor",
          "published_at": "2026-05-27T00:25:41Z"
        },
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2026-05-26T05:51:32Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2026-05-26T05:33:07Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2026-05-25T16:46:34Z"
        },
        {
          "tag": "v0.35.2",
          "kind": "patch",
          "published_at": "2026-05-24T15:01:15Z"
        },
        {
          "tag": "v0.35.1",
          "kind": "patch",
          "published_at": "2026-05-23T05:27:00Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2026-05-23T00:35:39Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2026-05-18T18:46:28Z"
        },
        {
          "tag": "v0.32.1",
          "kind": "patch",
          "published_at": "2026-05-18T01:50:06Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-05-18T01:18:52Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-05-15T19:17:55Z"
        },
        {
          "tag": "v0.30.3",
          "kind": "patch",
          "published_at": "2026-05-14T15:34:43Z"
        },
        {
          "tag": "v0.30.2",
          "kind": "patch",
          "published_at": "2026-05-13T19:51:03Z"
        },
        {
          "tag": "v0.30.1",
          "kind": "patch",
          "published_at": "2026-05-06T14:46:03Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2025-12-05T22:42:01Z"
        },
        {
          "tag": "v0.7.4",
          "kind": "patch",
          "published_at": "2025-12-05T22:07:08Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2025-12-05T21:41:21Z"
        },
        {
          "tag": "v0.0.1",
          "kind": "patch",
          "published_at": "2026-01-10T01:53:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "625c1d47ad5fa546cea7792ce976ec1208941a72",
          "body": "* chore(deps): bump eslint-plugin-unicorn from 71.1.0 to 72.0.0\n\nBumps [eslint-plugin-unicorn](https://github.com/sindresorhus/eslint-plugin-unicorn) from 71.1.0 to 72.0.0.\n- [Release notes](https://github.com/sindresorhus/eslint-plugin-unicorn/releases)\n- [Commits](https://github.com/sindresorhus/e\n[…]\nror opt-outs in base.ts.\n\n---------\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: T <t@t.com>",
          "is_bot": true,
          "headline": "chore(deps): bump eslint-plugin-unicorn from 71.1.0 to 72.0.0 (#1142)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T05:42:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58d966598b063efe4cc56d7af251fc02d9fd6cd2",
          "body": "* Record RED for invalid Codex marketplace scenario\n\n* GREEN classify invalid Codex marketplace installs\n\n* Record GREEN for invalid Codex marketplace scenario\n\n* Record refactor decision for invalid Codex marketplace scenario\n\n* RED expose Safe Word Codex plugin skills\n\n* Record RED for Codex plugi\n[…]\n: cover repeated plugin installs\n\n* chore: refresh audit tooling\n\n* docs: restore tracker integration reference\n\n* docs(architecture): refresh generated CLI map\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Let Codex users install Safe Word without a migration (#1368)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:48:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d158a836ff94cc8aaccb7388dec4f7d360237632",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore: close DDFA7X ticket (#1369)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:13:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9450465b8ad6123f0f5bb4e0e25e731571661a28",
          "body": "* feat(retro): dedupe cloud-spooled drafts canonically\n\n* test(retro): verify canonical spool dedupe\n\n* chore(retro): reconcile verification ledger\n\n* fix(retro): enforce canonical marker integrity\n\n* fix(retro): route Codex filer through packaged skill\n\n* chore(retro): record canonical dedupe evide\n[…]\n canonicalSignature is a hash of the normalized repro,\nnever raw finding text.\n\nFixes the sole failing test on this branch (360 files passed, 1 failed pre-fix).\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Keep cloud-spooled retro filing from bypassing duplicate checks (#1092)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:07:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c406c90b2490a31f362642e260c29ae1ade74557",
          "body": "* fix: recognize default BDD lanes\n\n* chore(8B4GVR): flip ticket to done — done-gate closure\n\nIndependent review confirmed all Done-When behaviors are covered by\npassing assertions and CI is green on node 22/24. Clears the\ndone-flip gate blocking PR #1365.\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Recognize default BDD lanes without configuration (#1365)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-24T04:00:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01e6553b4322ac93cdc55ab75f72b1daf322a59f",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "fix(cursor): record relative skill proof (#1343)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-23T23:40:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "659ed1cac9ab813af7982eec18a218f429fb36ce",
          "body": "* fix(audit): discover nested native manifests\n\n* fix(audit): honor workspace Knip configs\n\n* fix(audit): prune standard environment trees\n\n* refactor(audit): share file discovery traversal\n\n* fix(codex-plugin): refresh audit skill asset\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Fix native-stack discovery in audit skill (#1310)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-23T23:38:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25508117af8555e95559d3f4ab3087abfc01e663",
          "body": "* Fix E008 feature lane coverage\n\n* Harden E008 resolver fallback\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Scan all feature lanes for E008 drift (#1277)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T05:00:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1c4733287154801c39d83d44538786676e01ed3",
          "body": "… (KKNFZA) (#1086)\n\n* feat(DGH59K): tracker identity + join — off-board ticketing increment (KKNFZA)\n\nDeliver the done child DGH59K of epic KKNFZA (off-board local ticketing)\nonto current main as a focused, self-contained increment. Issue-first ticket\nidentity: with a GitHub/Linear tracker connected\n[…]\nerate after merging main (codex-plugin modules)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(DGH59K): tracker identity + join — off-board ticketing increment…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T04:36:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4e88ce7e58b178977dc31d565fcf76bbe99907ee",
          "body": "… (#1332)\n\nFollow-up to #1243. Two accuracy fixes in the Claude Code Cloud surface entry:\n\n- The `+ → Add from GitHub` repo picker belongs to the claude.ai\n  Projects/Chats GitHub knowledge-file integration, not claude.ai/code.\n  On Claude Code on the web, repos appear in a selector below the input\n\n[…]\n with' said 'reclaimed container' while this entry's own\n  Description says 'Anthropic-managed VM' — aligned to VM.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(surfaces): correct Claude Code Cloud repo-onboarding + VM wording…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T03:36:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "20a37f2eb45810c8dac5554311cf073be9558990",
          "body": "…ear E008 surface drift (#1243)\n\n* fix(surfaces): rename Claude Code on the Web to Claude Code Cloud\n\nThe cloud surface now covers both Anthropic-hosted cloud sessions and\nClaude Code GitHub Actions, so \"on the Web\" no longer describes it.\nRename the surface and retag its references.\n\nCorrect two wr\n[…]\nface-drift references in packages/cli/features.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(surfaces): rename Claude Code on the Web to Claude Code Cloud; cl…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T02:30:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a9f2d0ae27be3d3ab5e90f9f90fe66db45a61573",
          "body": "Follow-ups from the independent review of #1260, filed as #1284.\n\n**Coverage was attributed to every changed file, not the selecting ones**\n(#1284.1). A config ran if it covered *any* changed file, so a session\ntouching both `.safeword/hooks/` and `packages/cli/` let the root config\nride in on the p\n[…]\nten failing first), stop-typecheck-gate integration 3/3,\nlint clean, parity 190 pairs + 8 contracts, 22/22 release.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): judge each tsconfig by the files that selected it (#1289)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T01:58:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7bf1e827ed1037f2bed1ea8967624da493632137",
          "body": "* docs(WNMCH1): add §8 product-management + design role plugins\n\nFold Anthropic's knowledge-work role playbooks (product-management, design)\ninto the comparison: per-skill teardown, plus new borrow candidates G7\n(connector-agnostic ~~category pattern) and S6 (write-spec PM rigor →\nspec/self-review).\n[…]\nand PR #1290\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AkABNy1kurs3nAoX8PYCLL\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(WNMCH1): add product-management + design role plugins (§8) (#1290)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-22T01:57:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6426b6e82a5cfb603746d8d1640dcd02c70fabc4",
          "body": "…#1260)\n\n* fix(hooks): check the configs that actually cover the changed files\n\nThe implement-stop typecheck gate picked a tsconfig by proximity alone.\n`findTsconfigUp` returns the nearest `tsconfig.json` at or above a changed\nfile, and nothing asked whether that config covers the file it started\nfr\n[…]\n parity 190 pairs +\n8 contracts, 22/22 release.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): check the configs that actually cover the changed files (…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-21T13:50:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c72d8474f4199931ac8597c8231a4b0f42c95004",
          "body": "…ons (#1229)\n\nTwo follow-ups from the #1210 review.\n\n**The remedy command was wrong where it is read.** #1209 shipped\n`bun run --cwd packages/cli generate:codex-plugin`. That flag resolves\nagainst the caller's cwd, so it only works from the repo root — and fails\nwith `ENOENT: Could not change direct\n[…]\nrelease, lint clean, parity 190 pairs + 8 contracts in\nsync, corrected command confirmed working from packages/cli.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(codex-plugin): correct the drift remedy; pin out repo-only citati…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T18:47:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f40541401a9cffe0c343b2fc1cea3b2338c27ef",
          "body": "…needs (#1225)\n\n`tsc -p tsconfig.json` at the repo root reported 88 errors on a clean\ncheckout. Every one was a missing modern-lib member — `toSorted` /\n`toReversed` (ES2023), `Iterator.toArray` (ESNext.Iterator), and\n`Set.difference` (ESNext.Collection) — in files nobody had touched.\n\nThe root conf\n[…]\nrified: root `tsc -p tsconfig.json` 88 -> 0, root `eslint .` clean,\n`packages/cli` lint clean, 22/22 release tests.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tsconfig): give the root config the lib settings its own include …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T18:36:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b15ea0501e0f55af9d5afe6f5370442c2839e332",
          "body": "…rd's own churn against the user (#1228)\n\n* fix(hooks): stop the self-report Stop wake loop; exempt .agents/ + .codex/ from the LOC gate\n\nTwo compounding bugs observed live on 0.68.0 → 0.69.0: the LOC gate\nproduced a signal that the self-report Stop hook then looped on for\n~1h40m, the agent replying\n[…]\nan; 187 tests green across the affected suites.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): stop the self-report Stop wake loop; stop counting safewo…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T18:07:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03838402e16e6d5f549803b57d8e09365757a28c",
          "body": "All three catalogue assertions reported which asset was wrong but not what\nto do about it, so hitting one cost a full investigation to rediscover\n`generate:codex-plugin` — which is documented in README.md but not at the\npoint of failure.\n\nAppends a shared remedy line to the missing / unexpected / dr\n[…]\noper command is the right remedy to name.\n\nVerified: 22/22 release tests, 83 BDD scenarios / 986 steps, lint clean.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(codex-plugin): name the remedy in catalogue drift errors (#1209)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T17:08:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "42158544c7976ca4b7c1bda3cabd43443997883e",
          "body": "…s (#1210)\n\nPRINCIPLES.md lives only at the safeword repo root. It is not in\ntemplates/, has no entry in ConfiguredPathKey (personas | glossary |\nsurfaces | architecture), and is never installed into a customer project.\nSo `(PRINCIPLES.md §1)` in audit/ and verify/ pointed customers at a file\nthey d\n[…]\nrified: 170 tests across the 6 suites that read these files, 22/22\nrelease, parity 190 pairs + 8 contracts in sync.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(skills): drop dangling PRINCIPLES.md citations from shipped skill…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T17:07:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "498f49bbd067b57abf0fb7df5a33af96a0616ed9",
          "body": "Adds a fast, deterministic unit guard for the detection rule fixed in #993:\na fresh non-JS project whose only .sh files are vendored by safeword (its own\nscripts + an auto-installed language skill under .claude/.agents) must NOT be\ndetected as a shell project — otherwise the post-setup health check \n[…]\nd; this pins the detector contract\ndirectly (detectProjectType().shell) so a regression localizes fast and offline.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(setup): guard shell detection against vendored .sh files (#1123)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T05:43:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c84ba658b4ebf75b8ba047e2d9e8a5d630d04fba",
          "body": "* docs(quality-review): trim skill bloat (151→137 lines)\n\nRemove redundancy per Anthropic skill-authoring best-practices (concise-is-key).\nDedupe the hook-vs-skill explanation (3-4x -> 1), the fresh-reviewer\nindependence rule (4x -> 1), and the couple-of-passes cap (3x -> 1); tighten\ninvocation-log \n[…]\nn unrelated pre-existing #993 test-harness bug.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Trim skill bloat; generalize quality-review to any work-product (#1122)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-20T05:43:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bc822b0538eb135af4f151588e6f5dbd9aefd5e3",
          "body": "…NMCH1) (#1160)\n\n* docs(ticket): file Anthropic plugins vs safeword comparison (WNMCH1)\n\nCapture a thorough compare/contrast of Anthropic's 13 claude-code\nplugins against safeword's capability surface as ticket WNMCH1.\nResearch artifact only; no code changes.\n\nCo-Authored-By: Claude Opus 4.8 <norepl\n[…]\n candidates.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AkABNy1kurs3nAoX8PYCLL\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(ticket): Anthropic claude-code plugins vs safeword comparison (W…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-19T20:33:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f45e8c0a201fa84b14db6f764351c0189aba47ea",
          "body": "Bumps the github-actions group with 2 updates: [actions/setup-node](https://github.com/actions/setup-node) and [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-node` from 6 to 7\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://git\n[…]\nsion-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the github-actions group with 2 updates (#1139)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T11:47:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e423ef2bf7b20f27e06a99056140d7a3e0544d98",
          "body": "…0.0 (#1141)\n\nBumps [eslint-plugin-simple-import-sort](https://github.com/lydell/eslint-plugin-simple-import-sort) from 13.0.0 to 14.0.0.\n- [Changelog](https://github.com/lydell/eslint-plugin-simple-import-sort/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/lydell/eslint-plugin-simple-import\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump eslint-plugin-simple-import-sort from 13.0.0 to 14.…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T01:56:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ad671373ab0af668c88ef940cb4b027f9e8ad31",
          "body": "Bump to 0.69.0 across package.json, marketplace.json, codex plugin.json, and hooks.json. Ships #993 Codex packaged-plugin migration + #1128 hardening.",
          "is_bot": false,
          "headline": "chore(release): v0.69.0 (#1124)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-18T20:57:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a05b1433c8ea076352b6307b14b2b3517b57b20",
          "body": "…rministic BDD (#1128)\n\nVerify/audit/refactor hardening over the #993 Codex migration: document smol-toml dep, clean async-action error handling via parseAsync (fixes stack-trace errors + spurious self-reports), knip ignore hygiene, and a deterministic 'Bun is unavailable' BDD scenario (fixes a CI flake). CI green.",
          "is_bot": false,
          "headline": "chore: 0.69 release hardening — parseAsync errors, knip hygiene, dete…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-18T20:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a94d77846cb9eaabb42ee671394ba24d4c42cfc5",
          "body": "Migrates Codex Safe Word from repo-local skill/hook files to a packaged Codex plugin plus the `safeword hook codex` / `migrate codex-plugin` CLI entrypoints. Plugin hooks run pinned `bunx --bun safeword@<version>` commands; version-sync is guarded across manifests + hooks.json. Upgrade preserves legacy runtime files for an explicit, reviewed handoff (`--remove-legacy-hooks`). Reviewed across multiple passes; CI green (lint + test node 22/24).",
          "is_bot": false,
          "headline": "feat(codex): migrate Safe Word to packaged plugin hooks (#993)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-18T16:00:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "344667ebd04eef129977f11b41f6214cf6eee74a",
          "body": "Prevent duplicate upstream GitHub issues when a recurring retro finding's title\ndrifts across sessions.\n\n- Add a second hidden marker keyed only on the normalized repro\n  (`canonical:<hash>`) alongside the existing title-based signature marker.\n- triage dedupes legacy-signature-first, then falls bac\n[…]\nner (\"if it's good merge\"); review requirement\nbypassed at their explicit instruction. 1 behind main = the just-merged #1053\n(unrelated files).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(A8NNZV): dedupe recurring retro findings by canonical repro (#1065)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-16T20:23:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "954f37c0d72acbd714c10e9339a772ccac3e7723",
          "body": "…ity (#1053)\n\nDerive new persona codes as canonical 3-4 characters and carry them unchanged\nfrom personas.md through JTBD IDs and Gherkin Rule tags.\n\n- CLI policy (personas.ts): canonical derivation, bounded deterministic\n  collision suffixes, non-throwing `codeError` discriminator so `safeword\n  ch\n[…]\nw\nrequirement bypassed at their explicit instruction. All checks green on head\n631b4266 (lint, test node 22.22.3, test node 24); 0 behind main.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(FAJV19): canonical 3-4 char persona codes with legacy compatibil…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-15T14:10:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "589b262308d769447a96f663053cba77cff03678",
          "body": "* refactor(R4S85Y): rename DEV persona code to TB across the corpus\n\nEliminate the redundant DEV persona code (DEV and TB name the same technical-\ndeveloper persona; PR #1040 review). Mechanical, collision-free rename:\n- DEV<n> -> TB<n>: 828 occurrences (JTBD/rule ids, @slug feature tags, .ts test\n \n[…]\n (parity restored), test:bdd 407 / 0 undefined.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: rename DEV persona code to TB across the corpus (#1052)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T18:41:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7eb638f0e9c1ac7c3a57be7a3121398b95b3725d",
          "body": "…+ drift (#1038)\n\n* docs(N0W5KG): intake + scenarios + plan for audit domain-docs check\n\nFeature: /audit checks personas/surfaces/glossary for emptiness (W008),\nsurface drift (E008), persona drift (E009). Design via /figure-it-out\n(pure-prose bash block, no new CLI code). 15 scenarios, two rounds of\n[…]\nipped\nthe earlier verify — noted for the retro.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit: check personas/surfaces/glossary namespace docs for emptiness …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T18:29:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2139ad76be22159ee18fa25f1f2da8ca50a3c560",
          "body": "feature-surfaces-bdd.feature tags @surface.safeword-cli on 3 tag lines but\nsurfaces.md had no matching entry (E008 drift surfaced by the new audit check).\nThe safeword CLI is a distinct CLI-kind surface — its own setup/upgrade/check/\nreconcile behaviors, harness-agnostic — not an agent runtime. Slug resolves;\n121 surface/persona tests green.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(P9Z3P7): add Safeword CLI surface to surfaces.md (#1039)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T04:13:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9511dca4485588048882a1e75ef465c733acd630",
          "body": "…9S30R) (#1016)\n\n* test(retro): live-lane smoke for reconcile version-provenance path\n\nAdd a token-gated live test asserting createReconcileTransport(token)\n.resolveTagDate('v0.68.0') returns the tag's real commit date against the\nreal GitHub API. This is the one reconcile path that never runs in CI\n[…]\necorded in verify.md.\n\nRefs #791, ticket B9S30R\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(retro): live-lane smoke for reconcile version-provenance path (B…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-14T04:13:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0066461ad62b251394138662a99bde089f655b75",
          "body": "Bumps the bun-minor-patch group with 2 updates in the / directory: [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) and [@eslint-react/eslint-plugin](https://github.com/Rel1cx/eslint-react/tree/HEAD/plugins/eslint-plugin).\n\n\nUpdates `dependency-cruiser` from 18.0.0 to 18.1.0\n- [R\n[…]\nion-update:semver-patch\n  dependency-group: bun-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the bun-minor-patch group with 2 updates (#1010)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T04:28:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dcf735dee1764c3d928a2af713af65e370701d8",
          "body": "Claude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): close FG6V57 — session-token rule merged (#992) (#1011)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-13T04:28:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "11d868eb5edff63d609c42bd16146546ce57c4ea",
          "body": "* fix: repair Codex retro extraction\n\n* chore(ticket): mark codex retro runtime done\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Fix Codex retro extraction outside git worktrees (#960) (#994)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-13T04:21:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "198a8d35d6e78bf3062dc6f6aa7c7899bf6e96ae",
          "body": "Rebased #995 onto current main (which now carries #996 @cucumber/messages 34\nand #998 eslint-plugin-unicorn 71). The 12 minor/patch bumps apply cleanly;\nthe one dependencies-block conflict was resolved as the union — kept main's\neslint-plugin-unicorn 71.1.0, took the group's storybook/turbo/typescript-eslint\nbumps. bun.lock regenerated (--lockfile-only) from the merged manifests.\nReviewed SAFE (all 12 minor/patch, no hidden major, no Node-floor change).\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(deps): bump the bun-minor-patch group with 12 updates (#1009)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-13T02:12:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "446071eed24b5b11b71fb077b7572bb174d87aa1",
          "body": "Bumps [eslint-plugin-unicorn](https://github.com/sindresorhus/eslint-plugin-unicorn) from 70.0.0 to 71.1.0.\n- [Release notes](https://github.com/sindresorhus/eslint-plugin-unicorn/releases)\n- [Commits](https://github.com/sindresorhus/eslint-plugin-unicorn/compare/v70.0.0...v71.1.0)\n\n---\nupdated-depe\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump eslint-plugin-unicorn from 70.0.0 to 71.1.0 (#998)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T01:19:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d61b0b1c1a9c51a70ab80df7d4b9bfa5ca524de",
          "body": "Bumps [@cucumber/messages](https://github.com/cucumber/messages) from 33.0.4 to 34.0.1.\n- [Release notes](https://github.com/cucumber/messages/releases)\n- [Changelog](https://github.com/cucumber/messages/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/cucumber/messages/compare/v33.0.4...v34.0\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @cucumber/messages from 33.0.4 to 34.0.1 (#996)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T01:18:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b14e9e0c505c492095075057304a66dff8ba3dc4",
          "body": "* fix(retro): one session-token rule, pinned by parity contract (FG6V57)\n\nThree sanitizers had drifted (charset, strip-vs-substitute, missing cap).\nOne rule now: substitute non-[\\w.-] to _, cap 80, fallback 'unknown' —\ntriage's public ledger token and the spool filename gain the missing\nlength bound\n[…]\nee-stage pass\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro: one session-token rule, pinned by parity contract (FG6V57) (#992)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-12T23:55:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "876a4a290fc10c4f42e323f7a10c911ac1d1a60f",
          "body": "PR #990 merged; first workflow_dispatch run green in 49s with the done-when\nsummary line (89 issues swept, 0 failed). Daily cron armed on main.\n\n\nClaude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): close 4KP67A — reconcile sweep scheduled and live (#991)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T22:55:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "30cd3d6cdcaf02da7b4ce7d6fb97de71d34349a8",
          "body": "Documents the plan-implementation phase (#988/#480) across the flow docs:\nSAFEWORD.md + planning-guide (dogfood + template mirrors), the website\nworkflow flowchart/prose, and the config reference's review-gate section.\nRebuilt cleanly on main after #988's squash-merge; dogfood planning-guide\nsynced \n[…]\ny\nis prettier-ignored, so the table realign had to be copied over — the drift\nthe release-gate parity test caught).\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: seven-phase flow + four-gate inventory (#989)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T22:54:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8f11e9a935ff982b7b55b81d1e0ae56b6bced14b",
          "body": "…80) (#988)\n\n* ticket(TXRHMD): intake — spec for plan-implementation phase (#480)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* ticket(TXRHMD): intake — cold-start check gaps appended, goal + work log\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* ticket(TXRHMD): define-beha\n[…]\nprovenance+parity green; mirrors byte-identical.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add plan-implementation phase between scenario-gate and implement (#4…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T22:10:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90a0c7e04e93ce06e94a0faf33ce200f544440bb",
          "body": "* ci: schedule the retro-reconcile sweep daily (4KP67A, #791 follow-up)\n\nNew standalone workflow: daily 06:17 UTC cron + workflow_dispatch,\npermissions {issues:write, contents:read}, non-cancelling concurrency\ngroup, runs the CLI from source with the Actions token. Fails loudly on\nmissing/broken aut\n[…]\ner side textually conflicts. Regenerated via\ntree-source sync-tickets so the index reflects current ticket state.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "CI: schedule the retro-reconcile sweep daily (4KP67A) (#990)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T20:17:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8890cf51a7bb78b0331e556d4c5bd8118a6df002",
          "body": "… KQ3MRV, HRDN42) (#967)\n\n* ticket(EDDABK): behavioral diff + panel-verified unification decision\n\n45-command corpus diff (9 divergence classes), 3-lens adversarial panel:\nsingle superset tokenizer, zero pinned-test flips, two companion gate\nfixes required (kill-guard bareName backslash strip, class\n[…]\n-review APPROVE; branch-staleness basename added.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(hooks): unify shell tokenizers + harden Bash gates (EDDABK #948,…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:58:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9601aebc4f8b61c09760dc8ce2337f992794da3f",
          "body": "…t-SHA reachability (HGYGND) (#964)\n\n* docs(ticket): park artifact-content phase-anchor redesign at intake, blocked on #810\n\nDesign-session record for the phase-provenance primitive redesign\n(core cluster #813/#815/#814/#816, epic #808): audit table of the five\nforward transitions against their comm\n[…]\nrtifact pair.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01DvXuj3us862ZSZxqxfxJQs\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Artifact-content phase anchors: tree-verified evidence replaces commi…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:56:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "85f168334f2ab9b9c8637e6f4325c0562d56a438",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Close M8NNX0 ticket after #928 (#968)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:32:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69e5418b878ea7855e26f3a86e7ad7c265b0b479",
          "body": "* Single lint-staged config + deterministic shellcheck lane (#966)\n\nThe package.json lint-staged block was dead config — lint-staged resolves\nsame-directory configs alphabetically, so lint-staged.config.mjs always\nshadowed it — yet it alone carried the shellcheck guard. Deleted the dead\nblock; porte\n[…]\ng fix (#966).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01DvXuj3us862ZSZxqxfxJQs\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Single lint-staged config + deterministic shellcheck lane (#966) (#980)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-09T18:32:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6acf044d83b63ef2520dbebdbbdfb07947b797ab",
          "body": "…urfaces + drop reporting (#587) (#958)\n\n* Open intake for retro tickets PNZM3B (process surfaces) and G19QG7 (filing provenance)\n\nIntake briefs and JTBDs for upstream issues #587 and #791; both tickets\nat phase: intake pending the JTBD gate.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nC\n[…]\nnd\npremortem.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KhS3XhHkGXRzKPYKqCR85c\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro: filing provenance + reconcile sweep (#791) and process-level s…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-08T05:41:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "647d34ecd1838467e7a0c6007ccc5c57179d5e6a",
          "body": "… (#957)\n\nJ555B9 tracked GHSA-mp2f-45pm-3cg9 (shellcheck -> decompress@4.2.1). #927\nremoved the shellcheck npm wrapper + its decompress dep (relies on system\nShellCheck), shipped in v0.68.0 — the chain is gone from bun.lock, so the\nDone-When (advisory clean) is met. Ticket.md flip only; the ticket INDEX is\nseparately stale (388→404) and left for a dedicated regen.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): close J555B9 — decompress advisory resolved by v0.68.0…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T23:46:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "969d6d89db5f4cd38441c5f6d45f955e535941cf",
          "body": "* Document uncommittable RED evidence path\n\n* refactor: structure uncommittable RED guidance\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Document uncommittable RED evidence path (#928)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T23:23:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5905a721003e03c86b9a67b641dc14820c7911a",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(release): v0.68.0 (#955)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T21:47:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b0f5ae5b4a5707a40e527408a6f0e64dd702ff0",
          "body": "* Restore Node 22 support\n\n* Fix Cucumber source import on Node 22 branch\n\n* Add Node 22 CI coverage\n\n* Restore Node 22 boundary error handling\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "Restore Node 22 support (#927)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T21:06:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb6ad7ba04c4a2e7900f56295a43eab83024dddb",
          "body": "…tch cleanup) (#946)\n\n* refactor: extract boundaryShimCommand to single-source the boundary-gate shim\n\nThe armored '[ -x … ] && … boundary --at <tier> || true' invocation was\nhand-copied 5× across schema.ts (husky textPatch) and hook-nudge.ts\n(lefthook + pre-commit snippets). A change to the [ -x ] \n[…]\n/91 boundary + phase-provenance + parity green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: dedupe boundary-shim command + frontmatter helpers (post-ba…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:59:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7eeff13770dc006145967a0bde8b56a401597f5e",
          "body": "…W) (#949)\n\n* cleanup-zombies.sh kills only with explicit --yes (#773 rung 4, 2KG1JW)\n\nBare invocation now previews (today's --dry-run behavior); killing requires\n--yes/-y. The skill/command/guide \"run --dry-run first, then re-run\" ritual\nwas prose-only — an agent that skipped the guide went straigh\n[…]\nticket 2KG1JW\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cleanup-zombies.sh kills only with explicit --yes (#773 rung 4, 2KG1J…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:57:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9937df40c5a619aed5fe33247e430c2c0f284fcf",
          "body": "…import-linter) (#947)\n\n`safeword upgrade` hardcoded ['ruff', 'mypy'] for a Python project while\n`safeword setup` installs ruff + mypy + deadcode (+ import-linter when a\nconfig would be scaffolded). So a repo upgraded rather than freshly set up\nsilently missed deadcode and import-linter. Move getPyt\n[…]\nof truth; both setup and upgrade now call\nit. Unit test pins the set (incl. deadcode) so the two can't drift again.\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(python): upgrade installs the same tool set as setup (deadcode + …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:55:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "17f5caeef1909199577a49085839c4a53bb83870",
          "body": "…e) (#948)\n\n* chore(ticket): EDDABK — consolidate divergent shell tokenizers across security gates (intake)\n\nCold-start intake for the item-5 finding deferred from the post-v0.67.0\nrefactor scout. dependency-readiness.ts carries a private\nsplitShellSegments/tokenizeShellWords/stripExecutionPrefixes \n[…]\nmentation constraint confirmed sound by review.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: T <t@t.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ticket): EDDABK — consolidate divergent shell tokenizers (intak…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T19:52:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c1d0a00c510240311db9c1b91bcd0228713ce7e4",
          "body": "… (#773 rung 3, JDK0F0) (#933)\n\n* Seal retro draft bodies with a digest; filing refuses modified bodies (#773 rung 3, JDK0F0)\n\nbuildDraft seals the final body (signature marker included) with\nbodyDigest = shortHash(body). The spool round-trips the seal, and the\nfiling seam (fileSpooledDrafts) refuse\n[…]\nticket JDK0F0\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Seal retro draft bodies with a digest; filing refuses modified bodies…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:07:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "676c936bd03e601fa1197c23ba656dc1ca624768",
          "body": "Completes the spawn-plumbing dedup started in #878 — this was the third\nhand-rolled copy, deferred then as out of that PR's scope.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: switch ledger-gate integration suite to spawnHookScript (#925)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:07:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fa5f404d52a70dd8a65c013b7f50d798dd8b5268",
          "body": "…o the bun:test lane (#922)\n\n* fix(lint): harden the deferred-test marker + mirror integrity rules to the bun:test lane\n\nQuality-review hardening of the just-merged #906 (one verified critical, two\nsuggestions):\n\n- The custom deferred-marker selector missed chained modifiers —\n  it.concurrent.todo p\n[…]\nntegrity pins\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(lint): harden the deferred-test marker + mirror integrity rules t…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:06:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b773c0fd2642111843121f5e001ab3b10a33011",
          "body": "…all (#810 slices 1–2) (#938)\n\n* CDRJTW intake start: boundary-reconciliation-gate ticket scaffold (#810)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01P42UynqbDXvubkgtrYMVQx\n\n* CDRJTW intake: boundary reconciliation gate — engine + local ho\n[…]\nkin phrasings\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01P42UynqbDXvubkgtrYMVQx\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Boundary reconciliation gate: engine, local hooks, and host-repo inst…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T17:05:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "44963e54872c3f14239421f0ab6931bdda127536",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(release): v0.67.0 (#926)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T05:48:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cf4b3456b729fde506b3c02d8854cd969de3940",
          "body": "… (#891) (#908)\n\n* fix(coverage): honor @-tag lineage in ledger-only test-definitions.md (#891)\n\nThe test-definitions.md coverage fallback derived AC/Rule references solely\nfrom `### Scenario:` titles shaped `<jtbd>.AC#.<name>`. A ticket with no\n`.feature` file that instead carried lineage as an `@<\n[…]\nd and green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VD4JSsVzspnYxGrnSbSWRB\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(coverage): honor @-tag lineage in ledger-only test-definitions.md…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T04:36:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a93d315a7f14bb98668560f2cded846e2d91048",
          "body": "…g 2, VFD6X1) (#906)\n\n* feat(VFD6X1): graduate test-integrity + no-sleep rules from prose to lint (#773)\n\nSecond enforce-then-trim rung of #773. The vitest lane gains:\n\n- vitest/no-disabled-tests (error): unconditional skips (it.skip, xit,\n  xdescribe) now need an inline eslint-disable with a reason\n[…]\n the ready PR\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Graduate test-integrity + no-sleep rules from prose to lint (#773 run…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-07T04:26:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d0fbffb953245b680c57d3d675723ce51e436b7c",
          "body": "…heck runs out of the box (#895)\n\n* ticket(V4MATC): intake for Python import-linter scaffold feature (#847)\n\nFeature ticket + spec: JTBD, five Rules, engineering scope converged.\nScaffold a safeword-owned .importlinter (root package + acyclic-siblings)\nonly when the top-level package is unambiguous;\n[…]\ntract setUpAcyclicProject fixture in lint-imports teeth tests\n\n* refactor: complete fileContainsSection adoption in project-detector siblings\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(python): scaffold generic import-linter config — audit's cycle c…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:20:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bcf9d13f677ee0fa98c3897be42ef6879b0cf20a",
          "body": "* feat(K4STDR): deny broad killall/pkill runtime kills on the Bash channel (#773)\n\nGraduates the zombie-process-cleanup.md:34 prose invariant into code — the\nfirst enforce-then-trim rung of #773. New lib/process-kill-guard.ts predicate\n(shell-segments tokenization, same doctrine as bash-ledger-write\n[…]\nof PR\nscope).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bash process-kill denylist + real-time work-log stamps (#878)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:20:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d3535f9f2807380cbb79324026fd7f5319a2018",
          "body": "Independent post-merge review (both CLEAN, 0 must-fix) surfaced three\nworthwhile notes:\n\n- ARCHITECTURE.md retro/ one-liner misattributed transcript mining — the\n  LLM miner front-end lives in commands/retro.ts; src/retro/ is the\n  sanitize/draft/triage/transport pipeline.\n- ticket-sync/ line now us\n[…]\nommendedTypeScript rows can no longer be\n  satisfied by their longer siblings.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs+test: post-merge review notes for #886/#887 (#900)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:16:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "883d70231942c2a78eba6efcfdaf4b33091ac337",
          "body": "* fix(hooks): match ticket.md by exact basename, not suffix\n\nA file merely ending in ticket.md (e.g. sub-ticket.md) took the\ncanonical-ticket branch in pre/post-tool-quality, reading its own\nfrontmatter instead of the folder's ticket.md — silently skipping or\nstealing the session binding and misappl\n[…]\ntests green).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01S8gT3sN8HC5K4rMjCCsCGV\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro sweep: fix 9 issues from session retrospectives (#890)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T22:14:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9fe4953fb5ed5c6b01df1cc008a114980e9293e3",
          "body": "…#887)\n\n- golden-path graceful-handling tests assert the observable outcome (exit 0,\n  byte-identical unfixable content, surfaced error / silent no-op) instead of\n  bare not.toThrow — a hook that corrupted the file used to pass.\n- git.test no-op cases assert the index is unchanged against a seeded t\n[…]\nh contract table, with behavioral coverage explicitly routed\n  to golden-path.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: strengthen weak assertions flagged by the full audit (A7192X) (…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T14:23:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6a74f5dacaf2e4a3c1773375e147076dcb2b067e",
          "body": "… (25TJAR) (#886)\n\nFull-audit findings: the CLI Structure tree documented 5 of 13 real src/\nmodules — adds learning-sync, retro, skills, test-plan, ticket-sync,\ntracker-connect, tracker-sync, upstream-monitor with one-line purposes from\ntheir module docs. Runtime deps table gains @cucumber/gherkin +\n[…]\nude-plugin/plugin.json), not Cursor, and\ndeliberately not a workspace package.\n\n\nClaude-Session: https://claude.ai/code/session_01Ae2oEdbqL2xGgGzfo9JCAi\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(architecture): reconcile narrative with the generated module map…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T14:23:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d605a631311f11d6fc2e659ec4be1f083adce324",
          "body": "…nforcement is opted out (#868)\n\nFollow-up to #864. In `architecture --stage`, the drift advisory sat after the\n`architectureDocEnforcement: false` opt-out early-return, so an opted-out host\nmissed it there — inconsistent with --check and default mode, and with the\ncode's own 'coverage honesty is no\n[…]\ne, so it reads the doc as-is, matching\n--check). New integration test pins it.\n\n\nClaude-Session: https://claude.ai/code/session_01KmPeTtB72TjBWquzo8t3Eo\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(architecture): surface narrative-drift advisory in --stage when e…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-06T00:49:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e31b164c90b6ce758dafe74daf76350c4cc80b7",
          "body": "…+ surfaces pre-existing drift (#848) (#864)\n\n* ticket(BY7RNR): intake + scenarios for architecture narrative blind spots (#848)\n\nSpec, dimensions, feature source (20 scenarios / 7 rules), R/G/R ledger, and\nimpl plan for honoring paths.architecture in the reconcile nudge and surfacing\npre-existing n\n[…]\ndes (-8 LOC).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014cxsMsSmNgZ4MUgTcQ39M3\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: architecture narrative reconciliation honors paths.architecture …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T23:21:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "abd4abdfc14f74fffaa7e10da13cc057ac11d7fa",
          "body": "… (F9W3JP) (#865)\n\n* ticket(F9W3JP): intake — epic-child linker feature\n\nFeature: `ticket new --parent <epicId>` writes both ends of the epic↔child\nlink (child parent:, epic children[] append) and groups the child under its\nepic in INDEX. One JTBD (TB1), four ACs (link both ways / index grouping /\nf\n[…]\nicket closed\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NXdv6zZRRJdCGf7XkCqvkh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "`ticket new --parent`: link a child ticket to its epic in one command…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T22:46:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65516026a3bd5a593226bd434fd51c2037f20123",
          "body": "…chitecture check (#857)\n\n* Route verify's Gherkin + typecheck lanes through test-plan (polyglot)\n\nThe verify skill's Gherkin acceptance lane was hardcoded to package.json's\ntest:bdd script (cucumber-js only), and the typecheck lane was TS-only. Fold\nboth into `safeword test-plan` — the single polyg\n[…]\n in bd669ca.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_012X1PmAQ8j7tfAF12DzhXij\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Polyglot verify + audit: de-JS the Gherkin/typecheck lanes and the ar…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T21:46:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9cefee868e24e635e0e08dab1e06492e1f937c16",
          "body": "Behavior-preserving Tier-1 rename. #822 renamed the user-facing gate label\n\"AC gate\" → \"criteria gate\" (the gate accepts a numbered Rule or a legacy AC);\nthis brings the internal symbols in line with that concept:\n\n- evaluateAcGate    → evaluateCriteriaGate\n- parseAcsByJtbd    → parseCriteriaByJtbd\n\n[…]\nTypecheck + lint + parser-parity + cucumber (243) green; full suite verifying.\n\n\nClaude-Session: https://claude.ai/code/session_01AisW4aBoExfLcVDVkAWCKm\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: rename internal AC-gate symbols to Criteria (#850)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T21:07:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "159bd1599a91309b5b11177c381e4993c2747cde",
          "body": "…orkspace Go/Python/Rust services (#843, #844) (#858)\n\n* feat(architecture): recognize flat/lib JS layouts + orphan non-JS services (#843, #844)\n\n#843: broaden the JS/TS skeleton recognizer to match the Python/Rust\nextractors — a flat `src/` (files, no subdirs), a `lib/` root, and\ntop-level source f\n[…]\nxtracts once.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01Nfb4uXwwx5hvuiAo9BUoQj\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "architecture generator: recognize flat/lib JS layouts + surface non-w…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T21:07:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65358e08894cab1ec91b9b2461a202b9a69ac023",
          "body": "…advisory (#809, #824, #825) (#839)\n\n* RM84M8 intake: evidence-anchored phase transitions (#809)\n\nSpec + engineering scope for the deliverable-boundary epic's substrate\nchild: a per-phase SHA anchor on feature ticket phase transitions,\nmirroring the R/G/R ledger's SHA-per-tick, with a shared detecti\n[…]\n index regen\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01P42UynqbDXvubkgtrYMVQx\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Evidence-anchored phase transitions: phase_anchors substrate + check …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:59:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4fd6a7b4d379cb013f9baa2a38fb886e94615164",
          "body": "…hantom (#838)\n\nWeb/remote sessions sign every commit via the env-runner\n(commit.gpgsign=true + gpg.ssh.program), but local `git log\n--show-signature` / `verify-commit` / `gpg --list-secret-keys` report\nan allowedSignersFile error and %G?=N because there's no local\nallowed-signers file. That is a lo\n[…]\n so agents stop\nmisdiagnosing signed commits as unverified / \"no signing key\".\n\n\nClaude-Session: https://claude.ai/code/session_01PHJHmk3eBjWd63Vo2hks5A\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agents): note that \"unverified commit\" is a local-verification p…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:38:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1be7f64ca56e0902e14756d500237ee0f131b54c",
          "body": "* Soft-deprecate Acceptance Criteria in favor of numbered Rules\n\nThe intake authoring layer now leads with numbered Rules (`.R<n>`) as the\ndefault criteria rung; Acceptance Criteria (`.AC<n>`) become the documented,\nstill-accepted legacy alternative. Parser and gate behavior are unchanged — the\ncrit\n[…]\narity green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AisW4aBoExfLcVDVkAWCKm\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Soft-deprecate Acceptance Criteria in favor of numbered Rules (#822)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:31:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3e53918c211b3aca7b0da9d5c45a8405c00a248d",
          "body": "…er-error-is-error (#806)\n\n* chore!: raise Node engine floor to 24 (drop Node 22)\n\nDrops the Node 22 term from packages/cli engines.node\n(`^22.22.3 || ^24.16.0 || >=26.3.0` → `^24.16.0 || >=26.3.0`) and\nupdates the astro engine-contract assertion to match.\n\nBREAKING CHANGE: Node 22/23 are no longer \n[…]\n floor to 24 (drops Node 22/23) and the shipped\nESLint preset now requires Node 24 (unicorn/prefer-error-is-error →\nError.isError). See #806.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release)!: v0.66.0 — raise Node floor to 24 + unicorn 70 + pref…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T20:30:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f793b0e249149a8321fe57292344d704b0c8a7ec",
          "body": "Co-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.65.0 (#846)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T19:24:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "adc73efc2c7c3feeb19ea0893122c749b7e5e785",
          "body": "… + cargo-deny gates (#823)\n\n* feat(rust): add strict workspace clippy gate to the typecheck plan\n\nThe per-file lint hook runs `clippy -p <pkg> --fix` — package-scoped, no\n`-D warnings`, no `--all-targets --all-features` — so feature-gated code\nand test/bench targets never see clippy until CI. Nothi\n[…]\ncheck/deps).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NzXf5iJmGodwv1P4kSHJNY\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rust): evolve the Rust langpack quality stack — workspace clippy…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T19:05:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "939d63400115c76e6f226cf48049fe08cbe4f095",
          "body": "…tions (#835)\n\n* refactor(ticket-new): extract fail() helper for the stderr+exit pattern\n\nDRYs the four identical `process.stderr.write(msg); process.exit(1)` sites\n(invalid --type, --why-on-feature, SlugError, TicketIdCollisionError) into a\nsingle `fail(message): never`. Byte-identical output and e\n[…]\n (3/3 pass).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01KmPeTtB72TjBWquzo8t3Eo\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: post-48h cleanup — fail() helper + shared cucumber spawn op…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T18:27:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c1e2273cb4594153d51fabb696a81031a2c72f20",
          "body": "* fix: batch low-risk retro quick-wins (#793, #705, #634, #696)\n\n- #696: the AC intake gate no longer counts arbitrary level-4 headings;\n  only lineage headings (`<jtbd>.AC<n>` / `<jtbd>.R<n>`) satisfy the\n  \"≥1 AC per JTBD\" requirement, so `#### Notes` can't vacuously pass it.\n- #634: resolveGitHub\n[…]\ntests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NXdv6zZRRJdCGf7XkCqvkh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retro backlog: low-risk quick-wins + `ticket new` epic/goal/why (#817)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T17:21:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25116a85b04f5bf059a6344247262b562fd06964",
          "body": "…s (#765 follow-up) (#804)\n\nFollow-up to the merged de-prescription pass (#803). verify/audit/quality-review/\nrefactor over the merged result surfaced three prose fixes, all in\ncontext-files-guide.md:\n\n- audit (dedup): the auto-load/brevity point was stated twice — the Reliability\n  note (:79) and a\n[…]\n); remaining clones are the pre-existing per-skill\ninvocation-log boilerplate.\n\n\nClaude-Session: https://claude.ai/code/session_01RTCTEqXfKZvmMEDY12FfMT\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Post-merge quality sweep: dedup + scope two context-files-guide claim…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T16:24:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "073452f842af9b33eefa3303ac1e3c4f0abec7eb",
          "body": "…st ergonomics (#786)\n\n* test: give the Cucumber wiring child its own timeout/kill (#488)\n\nspawnSync blocks the event loop, so Vitest's outer TIMEOUT_ACCEPTANCE_LANE\ncannot interrupt a hung `bunx cucumber-js`. Pass a child-process timeout\n(90s, inside the outer budget) and SIGKILL on expiry; the std\n[…]\nClaude Code.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01BCiX1gTvpS1sH6tG3CWJqM\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Test-harness reliability: Cucumber spawn/flake + vitest/build-lock/di…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T10:21:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0e9c6473051902ca7803f8f9a9defa62c9e9e40c",
          "body": "…els (#769–779) (#803)\n\n* De-prescribe pass (#765): retire decision-trees, downgrade emphasis, cut recaps\n\nPart of #765 (Goal 10 model portability / Goal 3 unambiguous instructions).\nCanonical edits in packages/cli/templates/**, propagated to dogfood mirrors via\nparity:fix (212 pairs + 3 contracts i\n[…]\nining scope.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RTCTEqXfKZvmMEDY12FfMT\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "De-prescribe pass (#765): retune the instruction layer for modern mod…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T10:21:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "46f7097c8afdf0411d7a863f909d720b68fcfdd2",
          "body": "Prior audit-follow-up commit (#763) bumped root dev deps and four of the\nfive cli-workspace deps, but left packages/cli's tsx at ^4.22.4. Align it\nto ^4.23.0 (lockfile already resolved 4.23.0) to close #717's lockstep\nrequirement.\n\nThe eslint devDep was already aligned to ^10.6.0 by #763. The eslint\n[…]\n #718 (5 unused exports) were already\nresolved by #763; knip is clean on both.\n\n\nClaude-Session: https://claude.ai/code/session_01GFFMurbDa1ZmzEBHjBSDA9\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): finish #717 cli tsx bump (closes #305, #717, #718) (#795)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T04:31:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "636720a3ce1f98a17513076658304cd262a84409",
          "body": "Co-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.64.0 (#785)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-05T00:38:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7c636ec2c2a709f3ba554aca9d4c05e7a9483fe9",
          "body": "…ency (#763)\n\n* chore(audit): un-export dead symbols, bump deps, fix markdown lint\n\nAudit follow-ups from /audit run:\n\n- Un-export 5 symbols knip flagged as unused (used only within their own\n  file): CODEX_SESSION_START_HOOK_PATCH, OWNED_LABEL_PREFIXES,\n  MONITOR_SOURCES, normalizeMarkdown, SYNCTIC\n[…]\n tests (comment, single-quote, virtual-manifest-no-edition), 2 updated.\nRegexes narrowed to [ \\t] to avoid sonarjs super-linear backtracking.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Audit follow-ups: dep hygiene, dead-export cleanup, Rust/Go pack curr…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T20:21:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5c08461a7f2908327c762e9a9499b4435fb2c9a",
          "body": "…(#756)\n\n* 7CK2KP: BDD-lane adoption — bdd.conventions pointer + deferral prose\n\nAdds readBddConventionsPath (bdd.conventions in .safeword/config.json) and a\nstderr pointer in safeword codify, and de-hardcodes lane paths + the\nrun-and-expect-failure verify story in the installed BDD prose (templates\n[…]\nENARIOS/TDD).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LCXJRr67NFJTiuJEi9D8KN\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "BDD lane adoption: bdd.conventions pointer + deferral prose (7CK2KP) …",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T20:08:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f85c792747034d26d6105af8acefca50165c5da3",
          "body": "* test(cucumber): retry a CLI spawn once when killed with no output\n\nThe 'When I run' step spawns node dist/cli.js with a 30s timeout. A ~1s\ncommand starved past that timeout under concurrent test load (e.g. the vitest\nsuite co-running, or a contended CI runner) is SIGTERM-killed with empty\noutput —\n[…]\nlane 243/243.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01XaAFny6rSiwMbhbHTMqn3b\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Retry a cucumber CLI spawn once when killed with no output (#764)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T20:08:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d7f8b48eee042a1d28f5a48d68112ec48f45994",
          "body": "…ce roots (#755)\n\n* refactor: name SAFEWORD_LANE_CONFIG_FILE in project-detector\n\nReplace the 'cucumber.mjs' literal at the three own-scaffold identity sites\n(config-discovery list, self-exclusion guard, own-lane probe) with a named\nconst so a scaffold rename stays in lockstep. Behavior-identical.\n\n\n[…]\ne the same list. Hoist one WORKSPACE_ROOTS into workspaces.ts\nso a new root can't be added to one scanner and silently missed by the others.\nBehavior-identical.\n\n---------\n\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "refactor: post-36h cleanup — name lane-config literal + dedup workspa…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T08:01:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "09a2545b538cc98d7c8eff3cb622218a8cf39320",
          "body": "Co-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "chore(release): v0.63.0 (#753)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T06:17:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87342d50810241ec71e519b3b6fd16d7025962a4",
          "body": "…n-zero exits (#720) (#729)\n\n* fix(self-report): capture only genuine CLI crashes, not deliberate exits (#720)\n\nrecordCliExit fired on process.on('exit') for ANY non-zero code, so the ~12\ncommands that use process.exit(1) as normal control flow (check,\narchitecture --check, codify arg errors, …) flo\n[…]\ny: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017A57mMA4Jo1rHDu1n5SKjd\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>\nCo-authored-by: T <t@t.com>",
          "is_bot": false,
          "headline": "fix(self-report): capture only genuine CLI crashes, not deliberate no…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T05:52:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b961bad13fb010c80482260a8ae5e9ec0c324f53",
          "body": "* test(W42G34): RED - bulk-tick sed against a ticket ledger must be denied (#644 G3)\n\nFailing integration test: pre-tool-quality's Bash branch currently allows\nthe literal #644 command (sed -i ticking every R/G/R checkbox). Includes\nthe ticket's BDD artifacts (spec, dimensions, feature source, ledge\n[…]\n tests green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01XaAFny6rSiwMbhbHTMqn3b\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Gate Bash-channel writes to the R/G/R ledger (#644 G3) (#721)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T05:17:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "49121345e8d49ccffae872daccb8d04ab03a37c1",
          "body": "…) (#719)\n\n* chore(tickets): file audit follow-ups JCC69C + J2R9HY (#644 G8 verify)\n\nTwo maintenance tasks surfaced by the audit during the G8 verify pass,\nboth out of scope for the merged docs-cleanup PR:\n\n- JCC69C: bump 6 outdated dev-tool deps (@types/node, eslint, knip,\n  prettier, tsx, markdown\n[…]\nlready exact.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_018PVMS5fJ5R3a11JVWQd5vh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(tickets): file audit follow-ups JCC69C + J2R9HY (#644 G8 verify…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T04:52:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3994451b11816d24424536a08ce6d1e8d68ee582",
          "body": "Adds numbered Rules (`<jtbd-id>.R<n>`) as an optional per-JTBD substitute for Acceptance Criteria — the coexistence bridge toward a single Rule tier (#716). Closes #649.\n\nRule ref grammar with AC-wins precedence, rule uncovered/stale/orphan coverage advisories, zero-@rejection advisory, rule-name-tag-mismatch lint, gate denial naming Rules, plain-language actionable messages, and zero behavior change for repos with no Rules. Full suite + Gherkin acceptance lane green.",
          "is_bot": false,
          "headline": "Add a numbered Rule tier between JTBD and scenarios (#713)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-04T00:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2d51768f7658d4bd8f0ce883f10a66a070986d9",
          "body": "…44 G8) (#714)\n\n* docs(tickets): label retrospective R/G/R ledgers as non-precedent (#644 G8)\n\nAnnotate 26 test-definitions.md ledgers whose RED/GREEN/REFACTOR boxes\nwere bulk-ticked after the fact — each file entered git history already\nfully ticked, with no per-step commit SHAs — starting with CDX\n[…]\nedger markers\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_018PVMS5fJ5R3a11JVWQd5vh\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(tickets): label retrospective R/G/R ledgers as non-precedent (#6…",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-03T23:00:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "efa6eaf5bb3367086b5848316402ec1b0b2d47d0",
          "body": "* 7PG694: ticket for verify/audit skill refactor\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QsRxD44HSbzHsrhXLm3XEW\n\n* 7PG694: refactor verify and audit skills per quality-review plan\n\nFresh-review verdict REQUEST CHANGES; all 7 APPLY item\n[…]\n with PR #701\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QsRxD44HSbzHsrhXLm3XEW\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Refactor the verify and audit skills (7PG694) (#701)",
          "author_name": "Alex Salazar",
          "author_login": "TheMostlyGreat",
          "committed_at": "2026-07-03T22:59:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 48,
      "commits_last_year": 2371,
      "latest_release_at": "2026-07-18T20:57:56Z",
      "latest_release_tag": "v0.69.0",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 35,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 2.6
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 25,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "safeword",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "cli",
            "safeword",
            "developer-experience",
            "linting",
            "claude-code"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/safeword",
          "is_deprecated": false,
          "latest_version": "0.69.0",
          "repository_url": "https://github.com/ArcadeAI/safeword",
          "versions_count": 158,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 7036,
          "first_published_at": "2025-11-28T16:14:55.476000Z",
          "latest_published_at": "2026-07-18T20:59:14.958000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 8,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-27",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 527
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/cli/tsconfig.json",
        "packages/website/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "experiments/go-skill-directive/checker/go.mod"
      ],
      "largest_source_bytes": 74384,
      "source_files_sampled": 855,
      "oversized_source_files": 4,
      "agent_instruction_files": [
        ".cursor/rules/bdd-core.mdc",
        ".cursor/rules/bdd-discovery.mdc",
        ".cursor/rules/bdd-done.mdc",
        ".cursor/rules/bdd-plan-implementation.mdc",
        ".cursor/rules/bdd-scenarios.mdc",
        ".cursor/rules/bdd-splitting.mdc",
        ".cursor/rules/bdd-tdd.mdc",
        ".cursor/rules/bdd-verify.mdc",
        ".cursor/rules/safeword-brainstorming.mdc",
        ".cursor/rules/safeword-core.mdc",
        ".cursor/rules/safeword-debugging.mdc",
        ".cursor/rules/safeword-elicitation.mdc",
        ".cursor/rules/safeword-figure-it-out.mdc",
        ".cursor/rules/safeword-quality-reviewing.mdc",
        ".cursor/rules/safeword-refactoring.mdc",
        ".cursor/rules/safeword-retro-filer.mdc",
        ".cursor/rules/safeword-tdd-review.mdc",
        ".cursor/rules/safeword-testing.mdc",
        ".cursor/rules/safeword-ticket-system.mdc",
        ".safeword/AGENTS.md",
        "AGENTS.md",
        "CLAUDE.md",
        "packages/cli/templates/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 11149
    },
    "dependencies": {
      "manifests": [
        ".github/requirements-ci.txt",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 292,
        "malicious_count": 0,
        "assessed_package": "npm:safeword@0.69.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "@cucumber/gherkin",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^41.0.0"
        },
        {
          "name": "@cucumber/messages",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^34.0.1"
        },
        {
          "name": "@eslint-community/eslint-plugin-eslint-comments",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.7.2"
        },
        {
          "name": "@eslint-react/eslint-plugin",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "5.14.6"
        },
        {
          "name": "@eslint/js",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.0.1"
        },
        {
          "name": "@next/eslint-plugin-next",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "16.2.10"
        },
        {
          "name": "@secretlint/core",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.0.2"
        },
        {
          "name": "@secretlint/secretlint-rule-preset-recommend",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.0.2"
        },
        {
          "name": "@tanstack/eslint-plugin-query",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "5.101.2"
        },
        {
          "name": "@vitest/eslint-plugin",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.6.23"
        },
        {
          "name": "commander",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "15.0.0"
        },
        {
          "name": "eslint-config-prettier",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.1.8"
        },
        {
          "name": "eslint-import-resolver-typescript",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.5"
        },
        {
          "name": "eslint-plugin-astro",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "~2.1.1"
        },
        {
          "name": "eslint-plugin-better-tailwindcss",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.6.1"
        },
        {
          "name": "eslint-plugin-import-x",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.17.1"
        },
        {
          "name": "eslint-plugin-jsdoc",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^63.0.13"
        },
        {
          "name": "eslint-plugin-playwright",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.10.5"
        },
        {
          "name": "eslint-plugin-promise",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.3.0"
        },
        {
          "name": "eslint-plugin-react-hooks",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.1.1"
        },
        {
          "name": "eslint-plugin-regexp",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "3.1.1"
        },
        {
          "name": "eslint-plugin-security",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.0.1"
        },
        {
          "name": "eslint-plugin-simple-import-sort",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^14.0.0"
        },
        {
          "name": "eslint-plugin-sonarjs",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.1.0"
        },
        {
          "name": "eslint-plugin-storybook",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "10.5.0"
        },
        {
          "name": "eslint-plugin-turbo",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.10.4"
        },
        {
          "name": "eslint-plugin-unicorn",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "72.0.0"
        },
        {
          "name": "smol-toml",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.7.0"
        },
        {
          "name": "typescript-eslint",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "8.63.0"
        },
        {
          "name": "yaml",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.9.0"
        },
        {
          "name": "@astrojs/starlight",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.41.1"
        },
        {
          "name": "astro",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.7"
        },
        {
          "name": "astro-mermaid",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.0"
        },
        {
          "name": "mermaid",
          "manifest": "packages/website/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.16.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 9,
        "merged_prs": 469,
        "open_issues": 518,
        "closed_ratio": 0.396,
        "closed_issues": 340,
        "closed_unmerged_prs": 58
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "TheMostlyGreat",
          "commits": 1800,
          "avatar_url": "https://avatars.githubusercontent.com/u/70783618?v=4"
        },
        {
          "type": "User",
          "login": "TESTPERSONAL",
          "commits": 538,
          "avatar_url": "https://avatars.githubusercontent.com/u/6664588?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.767
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "deploy-website.yml",
        "release.yml",
        "retro-reconcile.yml",
        "upstream-changelog-monitor.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs",
        "ruff.toml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 4,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/27 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 1,
            "reason": "dependency not pinned by hash detected -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "625c1d47ad5fa546cea7792ce976ec1208941a72",
        "ran_at": "2026-07-24T06:53:28Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T05:47:20Z",
      "oldest_open_prs": [
        {
          "number": 548,
          "created_at": "2026-06-29T00:16:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1143,
          "created_at": "2026-07-18T22:24:52Z",
          "last_comment_at": "2026-07-21T05:24:27Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 1382,
          "created_at": "2026-07-24T04:52:21Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1383,
          "created_at": "2026-07-24T04:57:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1384,
          "created_at": "2026-07-24T05:03:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1385,
          "created_at": "2026-07-24T05:17:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1386,
          "created_at": "2026-07-24T05:43:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1392,
          "created_at": "2026-07-24T05:53:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1394,
          "created_at": "2026-07-24T06:04:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T05:42:54Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 3,
          "created_at": "2025-11-27T19:40:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 5,
          "created_at": "2025-11-27T19:45:30Z",
          "last_comment_at": "2026-06-18T02:48:23Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 6,
          "created_at": "2025-11-27T20:24:41Z",
          "last_comment_at": "2026-06-20T07:20:58Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 11,
          "created_at": "2025-11-29T20:41:40Z",
          "last_comment_at": "2026-06-18T02:47:47Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 13,
          "created_at": "2025-12-02T05:58:09Z",
          "last_comment_at": "2026-06-18T02:47:41Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 16,
          "created_at": "2025-12-02T05:58:49Z",
          "last_comment_at": "2026-06-18T02:47:38Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 17,
          "created_at": "2025-12-02T05:58:52Z",
          "last_comment_at": "2026-06-18T02:47:51Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 18,
          "created_at": "2025-12-02T05:59:21Z",
          "last_comment_at": "2026-06-18T02:47:54Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 19,
          "created_at": "2025-12-02T05:59:24Z",
          "last_comment_at": "2026-06-18T02:47:56Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 21,
          "created_at": "2025-12-02T06:23:29Z",
          "last_comment_at": "2026-06-18T02:47:24Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 22,
          "created_at": "2025-12-03T17:59:35Z",
          "last_comment_at": "2026-06-18T02:47:31Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 23,
          "created_at": "2025-12-03T17:59:51Z",
          "last_comment_at": "2026-06-18T02:47:35Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 24,
          "created_at": "2025-12-03T18:16:25Z",
          "last_comment_at": "2026-06-18T02:48:06Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 29,
          "created_at": "2025-12-08T06:40:25Z",
          "last_comment_at": "2026-06-18T02:48:14Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 119,
          "created_at": "2026-05-20T08:46:55Z",
          "last_comment_at": "2026-06-26T00:03:58Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 129,
          "created_at": "2026-05-22T13:09:41Z",
          "last_comment_at": "2026-06-18T02:46:52Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 191,
          "created_at": "2026-06-05T13:21:03Z",
          "last_comment_at": "2026-06-26T00:04:02Z",
          "last_comment_author": "TheMostlyGreat"
        },
        {
          "number": 292,
          "created_at": "2026-06-20T22:25:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 294,
          "created_at": "2026-06-20T22:32:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 307,
          "created_at": "2026-06-21T14:19:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ArcadeAI/safeword",
    "host": "github.com",
    "name": "safeword",
    "owner": "ArcadeAI"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 59,
        "vitality": 88,
        "community": 30,
        "governance": 57,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 88,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "commits_last_year": 2371,
              "human_commit_share": 0.94,
              "days_since_last_push": 0,
              "active_weeks_last_year": 35
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "35/52 weeks with commits",
                "points": 24.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 35
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "2371 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 2371
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 48,
              "latest_release_tag": "v0.69.0",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 2.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "48 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 48
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 30,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 14,
            "inputs": {
              "forks": 2,
              "stars": 8,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "8 stars",
                "points": 13.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "packages": [
                "safeword"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 7036
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "7,036 downloads/month across npm",
                "points": 51.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 7036,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 24,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.767
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 77% of commits",
                "points": 5.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 77
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "merged_prs": 469,
              "open_issues": 518,
              "closed_issues": 340,
              "issue_closed_ratio": 0.396,
              "closed_unmerged_prs": 58
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "40% of issues closed",
                "points": 18.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "469/527 decided PRs merged",
                "points": 34,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 469,
                      "decided": 527
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "followers": 290,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "ArcadeAI",
              "public_repos": 82,
              "account_age_days": 957
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "290 followers of ArcadeAI",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 290,
                      "login": "ArcadeAI"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "82 public repos, account ~2 yr old",
                "points": 18.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 82
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "safeword"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "158 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 158
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs, ruff.toml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs, ruff.toml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://arcadeai.github.io/safeword/",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://arcadeai.github.io/safeword/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 59,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 0.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:safeword@0.69.0 runtime dependency closure — what installing the published package pulls in — 292 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:safeword@0.69.0",
                  "assessed": 292
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 292,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 292,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                ".cursor/rules/bdd-core.mdc",
                ".cursor/rules/bdd-discovery.mdc",
                ".cursor/rules/bdd-done.mdc",
                ".cursor/rules/bdd-plan-implementation.mdc",
                ".cursor/rules/bdd-scenarios.mdc",
                ".cursor/rules/bdd-splitting.mdc",
                ".cursor/rules/bdd-tdd.mdc",
                ".cursor/rules/bdd-verify.mdc",
                ".cursor/rules/safeword-brainstorming.mdc",
                ".cursor/rules/safeword-core.mdc",
                ".cursor/rules/safeword-debugging.mdc",
                ".cursor/rules/safeword-elicitation.mdc",
                ".cursor/rules/safeword-figure-it-out.mdc",
                ".cursor/rules/safeword-quality-reviewing.mdc",
                ".cursor/rules/safeword-refactoring.mdc",
                ".cursor/rules/safeword-retro-filer.mdc",
                ".cursor/rules/safeword-tdd-review.mdc",
                ".cursor/rules/safeword-testing.mdc",
                ".cursor/rules/safeword-ticket-system.mdc",
                ".safeword/AGENTS.md",
                "AGENTS.md",
                "CLAUDE.md",
                "packages/cli/templates/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 11149
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".cursor/rules/bdd-core.mdc, .cursor/rules/bdd-discovery.mdc, .cursor/rules/bdd-done.mdc, .cursor/rules/bdd-plan-implementation.mdc, .cursor/rules/bdd-scenarios.mdc, .cursor/rules/bdd-splitting.mdc, .cursor/rules/bdd-tdd.mdc, .cursor/rules/bdd-verify.mdc, .cursor/rules/safeword-brainstorming.mdc, .cursor/rules/safeword-core.mdc, .cursor/rules/safeword-debugging.mdc, .cursor/rules/safeword-elicitation.mdc, .cursor/rules/safeword-figure-it-out.mdc, .cursor/rules/safeword-quality-reviewing.mdc, .cursor/rules/safeword-refactoring.mdc, .cursor/rules/safeword-retro-filer.mdc, .cursor/rules/safeword-tdd-review.mdc, .cursor/rules/safeword-testing.mdc, .cursor/rules/safeword-ticket-system.mdc, .safeword/AGENTS.md, AGENTS.md, CLAUDE.md, packages/cli/templates/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "94 of 94 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 94,
                      "sampled": 94
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/cli/tsconfig.json",
                "packages/website/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.74,
              "toolchain_manifests": [
                "experiments/go-skill-directive/checker/go.mod"
              ],
              "dependency_bot_commit_share": 0.06
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "experiments/go-skill-directive/checker/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "experiments/go-skill-directive/checker/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs, ruff.toml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs, ruff.toml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/cli/tsconfig.json, packages/website/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "74 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 74,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "6 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 6,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 74384,
              "source_files_sampled": 855,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/855 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 855,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T06:53:49.239530Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/ArcadeAI/safeword.svg",
  "full_name": "ArcadeAI/safeword",
  "license_state": "absent",
  "license_spdx": null
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.