Звіт у форматі JSON машиночитний
{
"data": {
"icon": {
"bytes": 44648,
"width": 600,
"height": 600,
"rejected": [],
"collected": true,
"media_type": "image/png",
"source_url": "https://raw.githubusercontent.com/agentgg-dev/agentgg-agents/main/static/logo.png",
"source_type": "readme",
"content_hash": "081e585962f5dc7fb641a09e0a36eca04e064ff8f2b32c0a0e7cac96f4be1a9f",
"candidates_considered": 1
},
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 1892,
"has_wiki": false,
"homepage": null,
"languages": {
"CSS": 2483,
"JavaScript": 15232,
"TypeScript": 880790
},
"pushed_at": "2026-08-05T04:12:45Z",
"created_at": "2026-05-13T02:04:55Z",
"owner_type": "Organization",
"updated_at": "2026-08-05T04:13:13Z",
"description": "agentgg cli",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "https://agentgg.dev/",
"name": "AgentGG",
"type": "Organization",
"login": "agentgg-dev",
"company": null,
"location": "United States of America",
"followers": 7,
"avatar_url": "https://avatars.githubusercontent.com/u/284173600?v=4",
"created_at": "2026-05-13T02:03:20Z",
"is_verified": null,
"public_repos": 2,
"account_age_days": 84
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.1.11",
"kind": "patch",
"published_at": "2026-07-25T01:59:43Z"
},
{
"tag": "v0.1.10",
"kind": "patch",
"published_at": "2026-07-09T02:56:33Z"
},
{
"tag": "v0.1.9",
"kind": "patch",
"published_at": "2026-06-27T21:23:40Z"
},
{
"tag": "v0.1.8",
"kind": "patch",
"published_at": "2026-06-17T09:23:05Z"
},
{
"tag": "v0.1.7",
"kind": "patch",
"published_at": "2026-06-11T06:17:54Z"
},
{
"tag": "v0.1.6",
"kind": "patch",
"published_at": "2026-06-04T08:05:08Z"
},
{
"tag": "v0.1.5",
"kind": "patch",
"published_at": "2026-06-02T22:11:34Z"
},
{
"tag": "v0.1.4",
"kind": "patch",
"published_at": "2026-06-02T02:25:57Z"
},
{
"tag": "v0.1.3",
"kind": "patch",
"published_at": "2026-05-24T19:47:50Z"
},
{
"tag": "v0.1.2",
"kind": "patch",
"published_at": "2026-05-19T20:19:55Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2026-05-19T20:01:25Z"
}
],
"recent_commits": [
{
"oid": "5eee2312864559d1acc4366367471766f73ecb70",
"body": null,
"is_bot": false,
"headline": "Add --source-id so resume identity survives a changed scan root",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-08-05T04:10:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce1c10ed725e97ad9ac6bd7ffbce2a4e44320e6c",
"body": null,
"is_bot": false,
"headline": "Fix biome formatting in recon-scan-flags test",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-29T22:09:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "622f92c63e75f12897e7af522d0fe5c61c64a57b",
"body": "…tches",
"is_bot": false,
"headline": "feat(scan): emit state/capped.json listing agents dropped by --max-ba…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-28T20:30:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7d9e50a640918b5e418080b418aed39c8c193cf0",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.11",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-25T01:59:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "da7013136f3c2410f9876e3665b5abba27653213",
"body": null,
"is_bot": false,
"headline": "Drop the hardcoded 'detection failed' prefix from detector error logs",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-19T06:46:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2aef1eb2efc4b38ce1545fa4f98d04bc920d49c9",
"body": null,
"is_bot": false,
"headline": "Treat model content refusals as empty results instead of agent failures",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-19T06:46:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b6a850d9cf61365ced18cf4870e9a0c94f95bef",
"body": "…, and concurrency",
"is_bot": false,
"headline": "docs(readme): add execution-model section on phase ordering, batching…",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-13T07:04:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6d5ce9a62822a1beabc962912db0ccb8f9a6e76",
"body": null,
"is_bot": false,
"headline": "ci: pin npm to 11.5.1 to fix provenance publish",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-09T02:56:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5045c92d7062f63dc4790c4a37f2da54a160e800",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.10",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-09T02:09:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a317524633ee1a48c4ddaa286f323367d4bc5de",
"body": null,
"is_bot": false,
"headline": "Add real-LLM provider smoke tests and fix the wiring gaps they surfaced",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-09T01:04:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "814cd234634499fbcd4965ea6b4a9d56273a267d",
"body": null,
"is_bot": false,
"headline": "recon: default --auto-exclude on to match scan, add --no-auto-exclude",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-04T07:23:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9131e8d50c1d3f3238140c22a17bd2276473d66a",
"body": "…the pass",
"is_bot": false,
"headline": "scan: reuse auto-excludes from recon plan.json instead of re-running …",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-04T02:16:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "74779287196ac634df4d375ac828dc782aaec7f2",
"body": "…le caps",
"is_bot": false,
"headline": "scan: default per-agent and batch caps, add --no-max-* flags to disab…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-04T00:58:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d67fa241bc458f1e84c2da8a4090bf5633c9ea6c",
"body": null,
"is_bot": false,
"headline": "Drop full-finding Copy button, keep only Copy GHSA",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-03T21:07:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "96a57c9eea789f5fd9ac9777f3670029c1825ee9",
"body": null,
"is_bot": false,
"headline": "Add Copy GHSA button to finding viewer",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-03T20:15:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73353a61f7a527e6ed1f60825ead0dc8f99217c5",
"body": null,
"is_bot": false,
"headline": "recon: add --auto-exclude pass that records chosen globs in plan.json",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-03T20:15:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "94428f92a15138f228256974e2742ceb6fb88506",
"body": "…d route real-but-misreported findings to uncertain",
"is_bot": false,
"headline": "validator: raise the confirmed bar to CVE/advisory-grade certainty an…",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-03T20:09:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b4a0dc1c2d168080c6558a744ef3918c72979c8",
"body": "…cross-file exploit chains, and thread --validate-max-turns through every provider (default 50)",
"is_bot": false,
"headline": "validator: give validateFinding repo tools (Read/Glob/Grep) to trace …",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-03T19:21:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e97e2968d507d0927f65ba6f98bff7f74bf4e20",
"body": null,
"is_bot": false,
"headline": "scan: default validate/score/dedup/auto-exclude on, add --no-* opt-outs",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-03T03:22:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "36dbc6c16d567a7fc293dedb5399fb5ac8bd69fe",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Document --auto-exclude flag in README and ARCHITECTURE",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-03T02:54:36Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7772ada70e5af4b097467d5de1874034fdbaa00d",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix biome formatting on auto-exclude changes",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-03T02:50:30Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e6f44cc90ceba29e5e04b11cb7da4ba59842fd2d",
"body": "…red, generated) to skip before a scan",
"is_bot": false,
"headline": "Add --auto-exclude: LLM picks non-runtime folders (tests, docs, vendo…",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-03T02:48:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3cebdcab98601024cdba9ef390fb5b9d4f492e66",
"body": "… curb critical inflation",
"is_bot": false,
"headline": "Feed recon brief into CVSS scoring and recalibrate metric guidance to…",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-07-03T01:29:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f2a0e64df601cceb13ae7e0d8d23f21f0a0229af",
"body": null,
"is_bot": false,
"headline": "add --max-batches flag to cap total agent batches per scan",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-02T19:44:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "231b20b99d00d23a566305b0c069b1400ba2c2c1",
"body": "…to disable",
"is_bot": false,
"headline": "Add a bundled default scope used when --scope is omitted; --no-scope …",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-02T03:13:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b51842e68e47dc5e196ad3ce2485c871ea0e7989",
"body": null,
"is_bot": false,
"headline": "Add --max-files-per-agent flag to cap candidate files per agent",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-07-01T21:18:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a173f89dc95e3c52d00949ab428d79a2efb6dfd1",
"body": "…and empty responses",
"is_bot": false,
"headline": "Harden GLM-5 scan agents against transient errors, context overflow, …",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-29T05:06:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a1001583048dc8d0fdd676972221aa64b774478",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.9",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-27T21:23:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d26a6dbe4cb467fb2a0f8aa9bedea6bf5360b8bc",
"body": null,
"is_bot": false,
"headline": "init: fetch live Bedrock model list from the AWS control plane",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-27T21:16:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a2173408cba014b4e59d4cb84444ac46159288d9",
"body": null,
"is_bot": false,
"headline": "init: fetch live model lists from the Anthropic and OpenAI Models APIs",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-27T20:59:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "74dc4dbde378a4f38c5600a3d2cd9835ac576181",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.8",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-17T09:23:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "58895c32ce62c83f4bf2a2929175ed6bff858803",
"body": "…r custom",
"is_bot": false,
"headline": "fix(cli): make create reruns idempotent and bucket custom agents unde…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-17T09:15:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b79a979b227345ea0e07f7ba1df230b0502c2fc7",
"body": "The first scan-touching test in a fresh CI runner pays the cost of the\nofficial agent catalog auto-install (downloads + unzips 156 agents from\nGitHub). On the GitHub Actions runner this can take ~12s, which trips\nvitest's 5s default and fails `scan-resume.test.ts:168` despite the test\nitself doing t\n[…]\ninstalled, so\nthe same test runs in ~600ms. Bump the global testTimeout to 30s so\nslower runners have room; real hangs still fail.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: raise vitest testTimeout to 30s for CI cold-start tolerance",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-06-17T06:18:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "272b282fa9622805c6b4845d2fd013818ef588f8",
"body": "Auto-fixable formatting (multi-line argument wraps, single-line throws)\nplus two manual fixes biome flagged as unsafe:\n\n- agent-spec.ts: collapse `p.prompt && p.prompt.trim()` to `p.prompt?.trim()`.\n- create.ts: drop unused `AgentSpec` type import (the spec flows through\n `detector.createAgent` return-type inference).\n\nNo behavior change; tests still pass.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "style(cli): biome lint + format pass on agentgg create",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-06-17T06:11:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c37b054b96fc7ed68f503d5dae8639e4697b37d1",
"body": "Reads a past security report (.md/.txt file, directory, or .txt list) and\na code path, runs a tool-enabled LLM session that explores the repo, and\nemits an AgentSpec rendered to a standard agent .md. The goal is to catch\nthe same code anti-pattern on recurrence, not to re-find the original bug.\n\n- N\n[…]\n`. No state/ dir, no scan resume.\n- Unit tests for AgentSpec render round-trip and report-loader.\n- README + ARCHITECTURE updated.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(cli): add `agentgg create` to distill past reports into agents",
"author_name": "Philip Garabandic",
"author_login": null,
"committed_at": "2026-06-17T06:06:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d669e55b5992dab0db15b66d3ab7f9e2690c16c4",
"body": null,
"is_bot": false,
"headline": "fix: only show update banner when remote version is strictly newer",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-11T06:36:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c6fd0448a58a6680f7ec4224db88c8befa55cd52",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.7",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-11T06:17:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8eff2c283fbc62708d8d6a604c79fc20e8840f78",
"body": null,
"is_bot": false,
"headline": "feat: add token usage",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-11T05:56:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52acc6945269481d5e444356646df601b74b9b8a",
"body": null,
"is_bot": false,
"headline": "Merge branch 'main' of https://github.com/agentgg-dev/agentgg",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-07T00:43:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "747e198e5d755daadc299112e60315a346adfa1c",
"body": "…ields",
"is_bot": false,
"headline": "fix(detect): instruct detection agent to avoid em-dashes in finding f…",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-07T00:40:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9253ec4ef306bc65657a1f9ac7ffdeffc7ad33e7",
"body": null,
"is_bot": false,
"headline": "feat(cli): log withTpmRetry rate-limit backoff events",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-06T22:45:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "30e027b4a9af84c6b24a733d6953e695720b5c61",
"body": null,
"is_bot": false,
"headline": "fix(cli): accept --project on dedup for Vertex (match scan/recon)",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-06T04:17:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "33e2c484c98e5b8b83e857dc5dc23294cf75e8a9",
"body": "… keep SIGTERM + dedup persist",
"is_bot": false,
"headline": "revert(cli): drop validate/score restructure + precondition sidecars;…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-06T02:44:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a24b1c55a1f3dc6e196831fd749f383f0e967ea",
"body": "…; handle SIGTERM",
"is_bot": false,
"headline": "fix(cli): per-task persistence for validate/score/dedup/preconditions…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-06T00:11:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0e735d5c1b5df6bd237c395fc456718b2574e37",
"body": "…f churning the queue",
"is_bot": false,
"headline": "fix(detect): fail-fast on Claude.ai plan usage-window limit instead o…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-05T04:43:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fc1afbbf6f6f8275b1f497d34b790290a7b485ed",
"body": "…h and vulnSlug from header",
"is_bot": false,
"headline": "feat(viewer): copy-as-markdown button on finding page; drop noisy has…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-05T04:31:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e06840bc78a0b3ef6f2760a053cd86adc55721f",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.6",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-04T08:05:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba558a1564b84d6519d827f69c65aaffe317eb0b",
"body": null,
"is_bot": false,
"headline": "polish(cli): use full agentgg-agents name in update banner",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-04T07:58:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "61998acb1a2bb7733b574ae8b1a49ea9bce4383e",
"body": "…koff",
"is_bot": false,
"headline": "fix(detectors): catch Vertex 429s in withTpmRetry, jitter default bac…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-04T07:55:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a01d61f48808718e41584f672ebf232e4731e548",
"body": null,
"is_bot": false,
"headline": "feat(cli): notify when a newer CLI or agents catalog is available",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-04T07:47:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "34b64762217cb5232a23887741f317669b36a8a9",
"body": "…izard",
"is_bot": false,
"headline": "docs: add dedup phase to README, drop stale file-mode label in init w…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-04T07:32:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "643f33a470764101b3bf43aad4dc4471ea6191f4",
"body": "… collapse duplicates in report and viewer",
"is_bot": false,
"headline": "feat(dedup): add de-duplication phase (agentgg dedup + scan --dedup),…",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-04T01:32:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d14befeb6cb44dae6e6c0756771c4582a7f6ed9",
"body": null,
"is_bot": false,
"headline": "fix lint",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-03T22:23:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e421caac6834794e6f43a2b19dc7ec527fcc20f2",
"body": null,
"is_bot": false,
"headline": "Lean recon: drop default turn budget 100->50, tighten summary cap",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-03T20:51:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a9fe7fbc093457ca6f98590586e1294c0ddced36",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.5",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-02T22:11:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b9098f79548ba7cf98541c6abb50522fdcf6687",
"body": "…hes, validation, and scoring",
"is_bot": false,
"headline": "docs: clarify --concurrency is one scan-wide pool spanning agent batc…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-02T21:29:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "038c6eff2699ef3ac5558bea4713d6c1eb6c703f",
"body": "…card; biome format",
"is_bot": false,
"headline": "fix(viewer): drop redundant analyzed/pending hint from Files scanned …",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-02T21:29:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8ba02f47fd7157533ffa9f1e918906de626ea06d",
"body": "…rency in scan, revalidate, and score",
"is_bot": false,
"headline": "perf(validate,score): parallelize validation and scoring via --concur…",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-02T09:29:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3f2673828801957573bb82dae3a20adb3f611ee",
"body": "…lace per-agent durationMs with filesReviewed/hitCount",
"is_bot": false,
"headline": "perf(scan): pool all agents' batches into one global worker pool; rep…",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-02T08:40:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "614e5e36bb08c2f8206f0d1c8b73796adae7383b",
"body": null,
"is_bot": false,
"headline": "Add durationMs to AgentRun to record per-agent run time in ms",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-02T05:45:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "222843aedb4117d33d65cb70a88bf457da73e629",
"body": null,
"is_bot": false,
"headline": "chore: release 0.1.4",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-02T02:25:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa5e1eb135366e5f24afcb93a5302080c7d3a944",
"body": null,
"is_bot": false,
"headline": "feat(vertex): region support + curated Llama 4 models",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-02T02:19:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "81cec9c6e90b6fddbc810f3f629276e574de0d11",
"body": "…fe scan state\n\nCo-Authored-By: Philip Garabandic <philipgarabandic@gmail.com>",
"is_bot": false,
"headline": "feat(cli): recon + summary commands with per-file resume and merge-sa…",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-06-02T01:25:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "68f067c6cab95076c404ceaae5b0031fc00da525",
"body": null,
"is_bot": false,
"headline": "system print run to queued",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-01T05:19:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85dd0d6901bdba7144c2bcf1a681f8caf8b3791b",
"body": null,
"is_bot": false,
"headline": "Lint update to support new template",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-01T04:53:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "43d85ed5fc618d50c952c53a174d5563da31371e",
"body": "…e, replacing file/walker/hunt/rule modes",
"is_bot": false,
"headline": "feat: unified tool-enabled agent — recon → precondition → run pipelin…",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-06-01T04:34:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1b3678dd629c8349dcfde4a4c759db00f93e1060",
"body": "…t-schema",
"is_bot": false,
"headline": "Merge remote-tracking branch 'origin/main' into refactor/unified-agen…",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-05-31T23:01:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c21aad23066719604c2ab5850f32cf0faa96a10e",
"body": "Collapse the file/walker/hunt/rule modes into one tool-enabled agent type:\n- Agent gains `precondition` (prompt + structured regex gate) and `where`\n (filePatterns/excludePatterns/preFilter/batch knobs).\n- Remove AgentMode and the top-level mode/tech/filePatterns/excludePatterns/\n preFilter/prefil\n[…]\nume scope gains\n reconHash + precondition outcome so resume invalidates correctly.\n\ncli dispatch is rewritten in later phases of the refactor.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Phase 1: unified agent schema (precondition / where / recon)",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-05-31T23:00:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0780c26948f69b31e6f98116be329cd5ed1dfd33",
"body": null,
"is_bot": false,
"headline": "feat: add vertex provider (GLM-5 on Vertex AI Model Garden)",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-31T22:32:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "efe7707b02314a0babcd5bd24cff8c26b8d0deb4",
"body": "…-false-positives to drop them",
"is_bot": false,
"headline": "Invert false-positive report flag: keep FPs by default, add --exclude…",
"author_name": "Philip G",
"author_login": null,
"committed_at": "2026-05-31T21:18:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "179578fdfc875699b898f8ba09018939a6f6ce42",
"body": null,
"is_bot": false,
"headline": "Release v0.1.3",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-24T19:47:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98cbd39e723b9bf6f4fae419e0f3b2841029f9e7",
"body": null,
"is_bot": false,
"headline": "chore: publish to npm via trusted publisher",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-24T19:45:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f8b991da27d1de3fed5901fc71b2130641688ca5",
"body": null,
"is_bot": false,
"headline": "chore: remove anthropic usage logs",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-24T19:35:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "14ac08c661526e8d1802b168b97cdedfe2a1dd11",
"body": null,
"is_bot": false,
"headline": "feat: tech-gated agent selection and rule mode",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-24T19:10:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a3d496a0dc6fc88786708b29a9dd4e814e136ce5",
"body": null,
"is_bot": false,
"headline": "fix: abort scan on quota exhaustion",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-23T06:01:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e62d41616177748d6e238aed1aab3b23932c652a",
"body": "docs: refresh ARCHITECTURE, add issue/PR templates, link bug reports …",
"is_bot": false,
"headline": "Merge pull request #8 from agentgg-dev/docs/architecture-refresh",
"author_name": "Gracia",
"author_login": "gracia-gu",
"committed_at": "2026-05-19T21:03:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "90ab34460dc1f4ea2a26b89010e31fb72ad627e2",
"body": "…from README",
"is_bot": false,
"headline": "docs: refresh ARCHITECTURE, add issue/PR templates, link bug reports …",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-19T20:57:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eccd46c47dbd26cdf4ba41078a36311441c3e69e",
"body": "Co-authored-by: Philip Garabandic <philipgarabandic@gmail.com>",
"is_bot": false,
"headline": "Initial public commit",
"author_name": "Gracia Gu",
"author_login": "gracia-gu",
"committed_at": "2026-05-19T20:19:55Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 11,
"commits_last_year": 77,
"latest_release_at": "2026-07-25T01:59:43Z",
"latest_release_tag": "v0.1.11",
"releases_from_tags": true,
"days_since_last_push": 0,
"active_weeks_last_year": 12,
"days_since_latest_release": 11,
"mean_days_between_releases": 7.4
},
"artifacts": {
"collected": true,
"structure": [],
"declarations": [
{
"name": null,
"path": "package.json",
"tokens": [
"npm.private",
"npm.workspaces"
],
"ecosystem": "npm"
},
{
"name": "agentgg",
"path": "packages/cli/package.json",
"tokens": [
"npm.bin",
"npm.entry"
],
"ecosystem": "npm"
},
{
"name": null,
"path": "packages/core/package.json",
"tokens": [
"npm.entry",
"npm.private"
],
"ecosystem": "npm"
},
{
"name": null,
"path": "packages/viewer/package.json",
"tokens": [
"npm.private"
],
"ecosystem": "npm"
}
]
},
"community": {
"has_readme": true,
"has_license": true,
"readme_badges": {
"hosts": [],
"total": 0,
"header": 0,
"collected": true,
"has_inspect_badge": false
},
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "agentgg",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"security",
"sast",
"vulnerability",
"scanner",
"ai",
"llm",
"agentic",
"static-analysis",
"cli",
"code-security",
"appsec"
],
"ecosystem": "npm",
"categories": [],
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/agentgg",
"declared_type": null,
"is_deprecated": false,
"latest_version": "0.1.11",
"repository_url": "https://github.com/agentgg-dev/agentgg",
"versions_count": 12,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2730,
"first_published_at": "2026-05-19T14:08:21.430000Z",
"latest_published_at": "2026-07-25T02:02:28.302000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 11
}
]
},
"popularity": {
"forks": 11,
"stars": 89,
"watchers": 4,
"fork_history": {
"days": [
{
"date": "2026-05-26",
"count": 2
},
{
"date": "2026-06-02",
"count": 1
},
{
"date": "2026-06-05",
"count": 1
},
{
"date": "2026-06-06",
"count": 2
},
{
"date": "2026-06-10",
"count": 1
},
{
"date": "2026-06-13",
"count": 1
},
{
"date": "2026-06-25",
"count": 1
},
{
"date": "2026-07-22",
"count": 1
},
{
"date": "2026-07-29",
"count": 1
}
],
"complete": true,
"collected": 11,
"total_forks": 11
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"packages/cli/tsconfig.json",
"packages/core/tsconfig.json",
"packages/viewer/tsconfig.json",
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 87345,
"source_files_sampled": 123,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [
{
"name": "adm-zip",
"direct": true,
"version": "0.5.18",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-xcpc-8h2w-3j85"
],
"fixed_version": "0.6.0",
"advisory_count": 1,
"oldest_advisory_days": 25
},
{
"name": "uuid",
"direct": false,
"version": "9.0.1",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-w5hq-g745-h8pq"
],
"fixed_version": "13.0.1",
"advisory_count": 1,
"oldest_advisory_days": 104
},
{
"name": "@ai-sdk/provider-utils",
"direct": false,
"version": "2.1.6",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 4.3,
"advisory_ids": [
"GHSA-866g-f22w-33x8"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 79
},
{
"name": "@ai-sdk/provider-utils",
"direct": false,
"version": "2.2.8",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 4.3,
"advisory_ids": [
"GHSA-866g-f22w-33x8"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 79
},
{
"name": "@anthropic-ai/sdk",
"direct": false,
"version": "0.81.0",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 4.4,
"advisory_ids": [
"GHSA-p7fg-763f-g4gf"
],
"fixed_version": "0.91.1",
"advisory_count": 1,
"oldest_advisory_days": 97
},
{
"name": "hono",
"direct": false,
"version": "4.12.33",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.3,
"advisory_ids": [
"GHSA-8j4g-w8fx-2239"
],
"fixed_version": "4.12.34",
"advisory_count": 1,
"oldest_advisory_days": 1
},
{
"name": "jsondiffpatch",
"direct": false,
"version": "0.6.0",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 4.7,
"advisory_ids": [
"GHSA-33vc-wfww-vjfv"
],
"fixed_version": "0.7.2",
"advisory_count": 1,
"oldest_advisory_days": 328
},
{
"name": "ai",
"direct": true,
"version": "4.3.19",
"severity": "low",
"ecosystem": "npm",
"cvss_score": 3.7,
"advisory_ids": [
"GHSA-rwvc-j5jr-mgvh"
],
"fixed_version": "5.1.0-beta.9",
"advisory_count": 1,
"oldest_advisory_days": 271
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"low": 1,
"high": 2,
"moderate": 5
},
"advisory_count": 8,
"affected_count": 8,
"assessed_count": 229,
"malicious_count": 0,
"assessed_package": "npm:agentgg@0.1.11",
"unassessed_count": 0,
"direct_affected_count": 2
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "adm-zip",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^0.5.16"
},
{
"name": "@ai-sdk/amazon-bedrock",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^1.0.0"
},
{
"name": "@ai-sdk/openai",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^1.0.0"
},
{
"name": "@anthropic-ai/claude-agent-sdk",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "0.2.119"
},
{
"name": "@aws-sdk/client-bedrock",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.0"
},
{
"name": "@aws-sdk/credential-providers",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.0"
},
{
"name": "@inquirer/prompts",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^7.0.0"
},
{
"name": "ai",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.0"
},
{
"name": "commander",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^13.0.0"
},
{
"name": "google-auth-library",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^9.0.0"
},
{
"name": "gray-matter",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.3"
},
{
"name": "minimatch",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^10.0.0"
},
{
"name": "ollama-ai-provider",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^1.0.0"
},
{
"name": "zod",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^3.23.0"
},
{
"name": "zod-to-json-schema",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "gray-matter",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.3"
},
{
"name": "zod",
"manifest": "packages/core/package.json",
"ecosystem": "npm",
"version_constraint": "^3.23.0"
},
{
"name": "@agentgg/core",
"manifest": "packages/viewer/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "lucide-react",
"manifest": "packages/viewer/package.json",
"ecosystem": "npm",
"version_constraint": "^0.460.0"
},
{
"name": "next",
"manifest": "packages/viewer/package.json",
"ecosystem": "npm",
"version_constraint": "^16.2.6"
},
{
"name": "react",
"manifest": "packages/viewer/package.json",
"ecosystem": "npm",
"version_constraint": "^18.3.1"
},
{
"name": "react-dom",
"manifest": "packages/viewer/package.json",
"ecosystem": "npm",
"version_constraint": "^18.3.1"
},
{
"name": "react-markdown",
"manifest": "packages/viewer/package.json",
"ecosystem": "npm",
"version_constraint": "^10.1.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 7,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 1,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "gracia-gu",
"commits": 53,
"avatar_url": "https://avatars.githubusercontent.com/u/46605720?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"release.yml"
],
"has_docs_dir": false,
"linter_configs": [
"biome.json"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 4,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "52 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "5eee2312864559d1acc4366367471766f73ecb70",
"ran_at": "2026-08-05T08:53:11Z",
"aggregate_score": 3.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"recent_prs": {
"merged_7d": 0,
"decided_7d": 0,
"merged_30d": 0,
"authors_30d": 0,
"decided_30d": 0,
"sample_size": 7,
"window_days": 30,
"sample_exhausted": false,
"authors_probed_30d": 0,
"newcomer_merged_30d": 0,
"bot_prs_excluded_30d": 0,
"newcomer_authors_30d": 0,
"newcomer_decided_30d": 0
},
"ci_last_run_at": "2026-08-05T04:14:00Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-05-19T21:03:14Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/agentgg-dev/agentgg",
"host": "github.com",
"name": "agentgg",
"owner": "agentgg-dev"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": "The weighted overall 59 is calibrated to 63 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 59,
"calibrated": 63,
"calibration": "2026-08-02"
}
}
],
"value": 63,
"inputs": {
"security": 37,
"vitality": 72,
"community": 63,
"governance": 54,
"calibration": "2026-08-02",
"engineering": 64,
"ai_readiness": 60,
"weighted_overall_raw": 59
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 72,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"commits_last_year": 77,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 12
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "12/52 weeks with commits",
"points": 8.3,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 12
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "77 commits in the last year",
"points": 17,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 77
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 88,
"inputs": {
"releases_count": 11,
"latest_release_tag": "v0.1.11",
"releases_from_tags": true,
"days_since_latest_release": 11,
"mean_days_between_releases": 7.4
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "11 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 11
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 11 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 11
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~7.4 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 7.4
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 63,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "weak",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 42,
"inputs": {
"forks": 11,
"stars": 89,
"watchers": 4,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "89 stars",
"points": 31.5,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 89
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "11 forks",
"points": 8.3,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 11
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "4 watchers",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 4
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": 0,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"readme_badge_services": [],
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 57,
"inputs": {
"packages": [
"agentgg"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 2730
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,730 downloads/month across npm",
"points": 45.8,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2730,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 54,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 83,
"inputs": {
"merged_prs": 7,
"open_issues": 0,
"closed_issues": 1,
"prs_merged_7d": 0,
"prs_decided_7d": 0,
"prs_merged_30d": 0,
"prs_decided_30d": 0,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 0,
"first_time_authors_30d": 0,
"first_time_prs_merged_30d": 0,
"first_time_prs_decided_30d": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 42,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "7/7 decided PRs merged",
"points": 30,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 7,
"decided": 7
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "weak",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"followers": 7,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "agentgg-dev",
"public_repos": 2,
"account_age_days": 84
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "7 followers of agentgg-dev",
"points": 6.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 7,
"login": "agentgg-dev"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "2 public repos, account ~0 yr old",
"points": 3.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 2
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"agentgg"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 11
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 11 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 11
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "12 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 12
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 64,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "biome.json",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "weak",
"name": "Documentation",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "weak",
"name": "Security",
"value": 37,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 35,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 3.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 3,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "52 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "weak",
"name": "Dependency advisories",
"note": "Matched the npm:agentgg@0.1.11 runtime dependency closure — what installing the published package pulls in — 229 packages. Reachability is not analyzed.",
"notes": [
{
"code": "advisories_scope_published",
"params": {
"package": "npm:agentgg@0.1.11",
"assessed": 229
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 46,
"inputs": {
"source": "osv",
"advisories": 8,
"affected_packages": 8,
"assessed_packages": 229,
"unassessed_packages": 0,
"affected_by_severity": "high 2, moderate 5, low 1",
"direct_affected_packages": 2
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "2 affected: adm-zip 0.5.18 (high 7.5), ai 4.3.19 (low 3.7)",
"points": 12.8,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 2,
"packages": "adm-zip 0.5.18 (high 7.5), ai 4.3.19 (low 3.7)"
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "6 affected: uuid 9.0.1 (high 7.5), @ai-sdk/provider-utils 2.1.6 (moderate 4.3), @ai-sdk/provider-utils 2.2.8 (moderate 4.3), +3 more",
"points": 6.3,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 6,
"packages": "uuid 9.0.1 (high 7.5), @ai-sdk/provider-utils 2.1.6 (moderate 4.3), @ai-sdk/provider-utils 2.2.8 (moderate 4.3)"
}
},
{
"code": "advisories_affected_more",
"params": {
"count": 3
}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "4 advisory-carrying package(s) unaddressed past 90 days; oldest published 328 days ago",
"points": 26.5,
"status": "partial",
"details": [
{
"code": "advisories_stale",
"params": {
"days": 90,
"count": 4,
"oldest": 328
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 229,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 1
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 60,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "weak",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 36,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.679,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "53 of 78 human commits state their intent (structured subject or explanatory body)",
"points": 36.2,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 53,
"sampled": 78
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"pnpm-lock.yaml"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"packages/cli/tsconfig.json",
"packages/core/tsconfig.json",
"packages/viewer/tsconfig.json",
"tsconfig.json"
],
"agent_commit_share": 0.077,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "biome.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/viewer/tsconfig.json, tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/viewer/tsconfig.json, tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "6 of the last 78 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 6,
"sampled": 78
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 87345,
"source_files_sampled": 123,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/123 source files over 60KB",
"points": 54.6,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 123,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [
"library",
"application"
],
"labels": [
"cli",
"web-ui",
"library"
],
"scores": {
"cli": 14,
"web-ui": 8,
"library": 4.8
},
"primary": "cli",
"evidence": [
{
"tier": "declared",
"label": "cli",
"source": "npm.bin",
"weight": 6
},
{
"tier": "declared",
"label": "library",
"source": "npm.private",
"weight": -6
},
{
"tier": "distribution",
"label": "library",
"source": "registry:npm",
"weight": 6
},
{
"tier": "declared",
"label": "library",
"source": "npm.entry",
"weight": 4.8
},
{
"tier": "dependencies",
"label": "cli",
"source": "dep:commander",
"weight": 4
},
{
"tier": "dependencies",
"label": "web-ui",
"source": "dep:next",
"weight": 4
},
{
"tier": "dependencies",
"label": "web-ui",
"source": "dep:react-dom",
"weight": 4
},
{
"tier": "description",
"label": "cli",
"source": "description:cli",
"weight": 2
},
{
"tier": "tags",
"label": "cli",
"source": "tag:cli",
"weight": 2
}
],
"artifacts": [
{
"path": "package.json",
"labels": [],
"ecosystem": "npm"
},
{
"path": "packages/cli/package.json",
"labels": [
"cli",
"library"
],
"ecosystem": "npm"
},
{
"path": "packages/core/package.json",
"labels": [],
"ecosystem": "npm"
},
{
"path": "packages/viewer/package.json",
"labels": [],
"ecosystem": "npm"
}
],
"confidence": "high",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": true
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-08-05T08:53:16.277904Z",
"schema_version": "0.31.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/agentgg-dev/agentgg.svg",
"full_name": "agentgg-dev/agentgg",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}