Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 28099,
"has_wiki": true,
"homepage": null,
"languages": {
"JavaScript": 17142
},
"pushed_at": "2026-07-29T05:27:48Z",
"created_at": "2026-06-12T16:41:48Z",
"owner_type": "Organization",
"updated_at": "2026-07-23T14:34:29Z",
"description": "Read-only mirror of MoonshotAI/kimi-code for Botiverse/Raft consumption. Synced daily via CI; consumers pin immutable mirror tags. See README for the maintenance SOP.",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": null,
"primary_language": "JavaScript",
"significant_languages": [
"JavaScript"
]
},
"owner": {
"blog": "https://botiverse.dev",
"name": "Botiverse",
"type": "Organization",
"login": "botiverse",
"company": null,
"location": "United States of America",
"followers": 109,
"avatar_url": "https://avatars.githubusercontent.com/u/132640357?v=4",
"created_at": "2023-05-05T05:00:50Z",
"is_verified": null,
"public_repos": 18,
"account_age_days": 1181
},
"license": {
"state": "absent",
"spdx_id": null,
"raw_spdx": null,
"file_present": false,
"scorecard_found": false,
"profile_has_license": false
},
"activity": {
"releases": [
{
"tag": "v0.20.1",
"kind": "patch",
"published_at": "2026-06-27T05:13:02Z"
},
{
"tag": "v0.20.0",
"kind": "minor",
"published_at": "2026-06-27T05:13:00Z"
},
{
"tag": "v0.19.2",
"kind": "patch",
"published_at": "2026-06-24T05:36:19Z"
},
{
"tag": "@moonshot-ai/kimi-code@0.18.0",
"kind": "other",
"published_at": "2026-06-19T05:12:19Z"
},
{
"tag": "@moonshot-ai/kimi-code@0.17.1",
"kind": "other",
"published_at": "2026-06-18T05:05:33Z"
},
{
"tag": "@moonshot-ai/kimi-code@0.17.0",
"kind": "other",
"published_at": "2026-06-18T05:05:31Z"
},
{
"tag": "@moonshot-ai/kimi-code@0.16.0",
"kind": "other",
"published_at": "2026-06-17T05:03:49Z"
},
{
"tag": "@moonshot-ai/kimi-code@0.15.0",
"kind": "other",
"published_at": "2026-06-16T05:03:20Z"
},
{
"tag": "@moonshot-ai/kimi-code@0.14.3",
"kind": "other",
"published_at": "2026-06-15T05:10:25Z"
},
{
"tag": "npm-v0.9.3",
"kind": "other",
"published_at": "2026-06-13T15:16:41Z"
},
{
"tag": "@moonshot-ai/kimi-code@0.14.2",
"kind": "other",
"published_at": "2026-06-12T17:02:47Z"
}
],
"recent_commits": [
{
"oid": "7d1f80143319b97f7921a52e381959a394f4762f",
"body": "…nch) for publish (#3)\n\nRegisters patch-branch `kai/0.20.1-botiverse-roleadditional` in the README §1\nlocal-patch table + RELEASES.md version-mapping + a release-notes section, so\npublish-sdk.yml can build @botiverse/kimi-code-sdk@0.20.1-botiverse.1 from the\nbranch source. Publish-form e2e (pack → clean install → live Kimi codeword\nsurvives session.compact()) verified locally.\n\nCo-authored-by: Kai <kai@mail.build>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(releases): register 0.20.1-botiverse.1 (roleAdditional patch-bra…",
"author_name": "stdrc",
"author_login": "stdrc",
"committed_at": "2026-07-07T04:18:56Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "26b1ab90ef6cc0759b2c38702df38e76a76695fc",
"body": "…) + 0.20.0 backfill",
"is_bot": false,
"headline": "docs: 0.20.1 release notes (additive KimiAuth feedback-upload surface…",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-27T05:12:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e4cc9bc80ba50494c2863eb7e58f07d03b1e29d",
"body": "…sdk surface unchanged vs 0.18.0\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nSigned-off-by: Kai <kai@mail.build>",
"is_bot": false,
"headline": "docs: 0.19.2 release notes (pure latest + 0.19.2-botiverse.0) — node-…",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-24T05:35:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "419e0341c276d25fbd458153fc61d376e7f5eba8",
"body": "…ersion)\n\nBefore PR #2 the LocalKaos/Kaos surface extension was unconditional, which made\nit impossible to cut a PURE mirror at `latest` (the default install target per\nRELEASES.md, which must match the upstream surface verbatim). Gate the extension\non the version suffix:\n - `X.Y.Z` -> p\n[…]\nepackage for one upstream release (tygg \"Pure mirror\n版本和repackage版本都发\", #proj-runtime:a2c38238 2026-06-24).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nSigned-off-by: Kai <kai@mail.build>",
"is_bot": false,
"headline": "feat(repackage): pure-mirror mode (skip LocalKaos unless -botiverse v…",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-24T05:28:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "44c96c04bcc1447d2f5427a924f16d02e7b7cdeb",
"body": "publish-sdk run 27861837338 failed with:\n\n npm error You must specify a tag using --tag when publishing a prerelease version.\n\nThe mirror's `0.18.0-botiverse.0` version triggered npm's pre-release\ndist-tag requirement. The previous publish step always used the implicit\n`latest` tag, which is fine\n[…]\n botiverse`. Other pre-release\nsuffixes fall back to `--tag pre`. Stable versions continue to publish\nto the default `latest` tag with no flag.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(publish): set npm dist-tag for pre-release versions",
"author_name": "Joy (Claude)",
"author_login": "claude",
"committed_at": "2026-06-20T05:45:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d479cc9ed521f5c1610430991bb596c7fe471a74",
"body": "…declaration\n\nPR #2 merged but the publish-sdk workflow run 27861604589 failed with:\n\n repackage: upstream dist/index.d.mts no longer declares LocalKaos\n\nThe assumption that upstream's bundled `dist/index.d.mts` declares\n`LocalKaos` as a top-level class was wrong. Upstream tree-shakes the\nclass t\n[…]\nclaration to return `LocalKaos` (not `Kaos`) for chain\ntype preservation.\n\nverify-mirror-surface.mjs still PASS 13/13 (source-level + runtime).\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(repackage): handle upstream dist/index.d.mts having no LocalKaos …",
"author_name": "Joy (Claude)",
"author_login": "claude",
"committed_at": "2026-06-20T05:40:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8943b09772bd2b0add990640d0bb08df47a0e0a0",
"body": "…0-botiverse.0) (#2)\n\n@tygg + @Hao routed via #proj-runtime:96f626f3 (6/20). Slock daemon's\nKimi-SDK driver needs `LocalKaos.create().withEnv({ PATH })` to inject\nper-agent CLI wrapper PATH into Kimi tool execution; without this, the\nin-process driver cannot use per-session env overlay and falls bac\n[…]\n to `@<tag>-botiverse.<n>`.\n Adds the `0.18.0-botiverse.0` entry.\n\nNo upstream node-sdk runtime behavior change; bundle implementation\nuntouched.\n\nCo-authored-by: Joy (Claude) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Re-export LocalKaos + Kaos type (mirror-side surface extension; 0.18.…",
"author_name": "stdrc",
"author_login": "stdrc",
"committed_at": "2026-06-20T05:30:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ed708cc5af92936a26156b316e2c39e5c23ab3ad",
"body": "…es) (#1)\n\nDrop-in additive minor from 0.17.1. New optional `sessionStartedProperties`\nfield on `KimiHarnessOptions` / `CreateSessionOptions` / `ResumeSessionInput`\nmerged into `session_started` telemetry; canonical harness fields always win.\nApp-side features (web search/lazy-load, guided goal authoring, AgentSwarm\nconcurrency env knob, host CLI version in /meta) don't affect SDK consumers.\n\nCo-authored-by: Joy (Claude) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: 0.18.0 release note (node-sdk additive — sessionStartedProperti…",
"author_name": "stdrc",
"author_login": "stdrc",
"committed_at": "2026-06-19T05:06:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4bed1b9068fd96d17038cdc762119728487d1c06",
"body": "…onfigSafe + resolveConfigPath); server/web UI not on Slock SDK path\n\nUpstream `@moonshot-ai/kimi-code@0.17.0` mirrored 6/18:\n- node-sdk public interface ADDITIVE: new exports `loadRuntimeConfigSafe`\n and `resolveConfigPath` (host-side safe config reader + sync path\n resolver, useful for hosts tha\n[…]\no daemon driver change\nrequired. `loadRuntimeConfigSafe` could simplify our\n`detectKimiSdkModels` regex scan (`packages/daemon/src/drivers/\nkimi-sdk.ts`) — flagged as optional follow-up, not required.",
"is_bot": false,
"headline": "docs: 0.17.0 + 0.17.1 release notes — node-sdk additive (loadRuntimeC…",
"author_name": "Joy (Claude)",
"author_login": "claude",
"committed_at": "2026-06-18T05:02:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5e717566cc05e52be2a664172e56a5721a47a689",
"body": "…aos refresh\n\nUpstream `@moonshot-ai/kimi-code@0.16.0` mirrored. node-sdk public\ninterface unchanged (no diff under packages/node-sdk/, package.json\nstays at 0.9.3). Bundled siblings shipped:\n\n- agent-core@0.13.1 — compaction repeat-handling fix, replay-range fix,\n session-shutdown-vs-resume fix, log-plumbing cleanup\n- kosong@0.4.6 — host-shell ANTHROPIC credential isolation\n- kaos@0.1.6 — stream-close on buffered-reader destroy\n\nDrop-in bump for Slock daemon consumers.",
"is_bot": false,
"headline": "docs: 0.16.0 release note — public API unchanged, agent-core/kosong/k…",
"author_name": "Joy (Claude)",
"author_login": "claude",
"committed_at": "2026-06-17T05:02:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "790c9ffb7c32da7814563f2c147091ca7a825773",
"body": "Per tygg in #proj-runtime:a2c38238 (msgs cb736b39 / 9cfb4824 / c1f01b13):\n'对齐上游对外版本' — npm version mirrors the upstream Kimi Code CLI release\ntag (0.15.0 → 0.15.0). Simpler than the internal node-sdk version + patch-\nbump scheme I cut 0.9.4 under earlier today. If upstream doesn't release,\nwe don't \n[…]\nfavor of 0.15.0.\n\nUpdated RELEASES.md mapping table + policy note + the 0.15.0 release\nnote's 'Slock consumer impact' to reflect the new shape.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: switch versioning policy to align with upstream CLI tag",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-16T07:23:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dea849162fe897ae176d93f788366a102a887728",
"body": "The push-tag trigger doesn't fire when the publish tag points at an\nupstream-source commit that doesn't have our workflow file (e.g. tagging\n@moonshot-ai/kimi-code@0.15.0 commit doesn't include our .github/\nworkflows/). So workflow_dispatch is the practical path. Add an\nnpm_version input so dispatch can request a Botiverse-side patch-bump\n(today: 0.9.4 from 0.15.0 source where upstream node-sdk stayed 0.9.3).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(publish): support npm_version input on workflow_dispatch",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-16T06:45:32Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "29b30e2746570bbdd0876d9bd2d4a63246fef2a7",
"body": "…or bundled-implementation refresh\n\nPer tygg directive in #proj-runtime:a2c38238 msg=dd0680ba: upstream\nnode-sdk's package.json version is theirs and may be lazy (private\ninternal package); our consumer cadence shouldn't be hostage to it.\n\nPolicy (codified in RELEASES.md): npm version maintained ind\n[…]\nnpm 0.9.4 (bundled refresh:\nagent-core system-prompt polish, MCP-over-SSE, resume close-interrupted-\ntoolcalls fix, Xcode 26.5 MCP schema fix).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(publish): independent npm versioning policy + override support f…",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-16T06:41:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4979f1c5ee0c2d8138438e53b461f3436282b3af",
"body": "…ion refresh\n\nnode-sdk public surface (src/index.ts) and package.json version (0.9.3) are\nunchanged 0.14.3 → 0.15.0. The interesting deltas are in bundled siblings\nthat tsdown inlines into the published dist: agent-core (system prompt\ncontext, same-language reasoning, model capability table, decoupl\n[…]\npin the\nmirror tag (github:botiverse/kimi-code-sdk#@moonshot-ai/kimi-code@0.15.0)\nor wait for upstream to bump node-sdk's package.json version.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: 0.15.0 release note — public API unchanged, bundled-implementat…",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-16T05:03:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d88c8d0e0e3635e03b841450fb31bc51113ccdd3",
"body": "Reorder README §2 'What consumers should pin' so npm install is the\nrecommended default and the mirror-tag pin is the less-common option\n(only when you actually need the full upstream monorepo source for\nvendoring or local patching).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: recommend npm install as the primary consumer path",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-15T12:18:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "92d2b9fcde877dfd5d9ddf9df2955eb8cb41f472",
"body": "Reframe away from any single-consumer wording: this mirror is for any\nproject wanting to embed Kimi Code's Node SDK against immutable, smoke-\nverified versions. Add a 'Why not ACP?' section explaining that ACP\ndoesn't expose steering — load-bearing for embedders that need real-time\nturn interaction \n[…]\nprovements, docs;\nnot welcome: edits to mirrored upstream code or to existing mirror tags).\nDrop slock-specific maintainer/escalation phrasing.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: rewrite README as a community open-source release pipeline",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-15T12:14:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5c2f9dbff8205dfa41a53575fed782f5572f0f12",
"body": "Diff scope: apps/kimi-code/ + docs/ only. packages/node-sdk/ and all\nbundled siblings (agent-core/kosong/kaos/oauth/protocol/acp-adapter/\ntelemetry) untouched. node-sdk package.json version stays 0.9.3.\n\nSingle feature: feat(kimi-code): refresh OAuth provider models before\nopening model picker (#713\n[…]\n CLI/TUI feature only.\n\nSlock consumer impact: no-action. Existing 0.9.3 npm pin or 0.14.2\nmirror-tag pin already covers this upstream release.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: 0.14.3 release note — CLI/TUI-only, no node-sdk surface change",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-15T05:10:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "adc836789cd6488b0b4464784fd04909a2580334",
"body": "….15.0\n\nDiscovered when the publish-sdk dry-run hit ERR_PNPM_UNSUPPORTED_ENGINE\n('Expected version: >=24.15.0, Got: v22.22.3') under 'pnpm install'. The same\nconstraint applies to sync-upstream's post-sync smoke build, which would hit\nthis on the first real new-release sync (today's runs were ff no-\n[…]\ne issue).\n\nBoth workflows now setup-node@v5 with node-version: 24 + package-manager-cache:\nfalse so corepack remains the single source of pnpm.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: bump Node to 24 — kimi-code's package.json sets engines.node >=24…",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-13T15:28:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "fb6c971f17dfb08f7759bd478bead540075cb16b",
"body": "…sion)\n\nsetup-node@v5 turned on package-manager-cache by default. It auto-detects the\npnpm in kimi-code's packageManager field and tries to resolve pnpm on PATH\nbefore our 'corepack enable' step does. Result: 'Unable to locate executable\nfile: pnpm' in publish-sdk.yml's setup-node step.\n\nDisable package-manager-cache so corepack remains the single source of truth\nfor pnpm in this workflow.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: disable setup-node@v5 package-manager-cache (corepack/pnpm regres…",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-13T15:26:33Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "caea1276439f07ec4ceed2288394b2a44c63d694",
"body": "…to upstream 0.14.2\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: record first npm publish — @botiverse/kimi-code-sdk@0.9.3 maps …",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-13T15:16:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "01c340376103e3135450d527723d27f20b571e7d",
"body": "GitHub forces Node 24 as the default actions runtime on 2026-06-16; v4 of\nthese actions runs on the deprecated Node 20. Bump to v5 so the unattended\ndaily sync + publish workflows don't break.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: bump actions/checkout + setup-node to v5 (Node 24 readiness)",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-13T05:06:31Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1a7ee37e16a5313cbf5ae9db9d088280045ced93",
"body": "Phase 2: publish-sdk.yml builds node-sdk at a chosen upstream mirror tag,\nrepackages to the dist-only @botiverse/kimi-code-sdk, and publishes to npm via\nOIDC trusted publishing (no long-lived token). Triggered by a deliberate\npublish-sdk/v* tag (maintainer in the loop), with version-match assertion and\noptional npm-publish approval environment. README §6 documents the SOP +\none-time npm trusted-publisher setup.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add OIDC tag-triggered publish pipeline for @botiverse/kimi-code-sdk",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-12T17:51:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7b601edf25d2a06ee18400503a6952292f3a4159",
"body": "Full `pnpm install` would pull apps/kimi-code (TUI) + apps/vis (web/server)\ndeps that node-sdk doesn't use. node-sdk is bundled (tsdown) with its siblings\nas devDeps; smoke only needs node-sdk + its dep closure.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci(sync): scope smoke install to node-sdk dependency closure",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-12T17:08:21Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "04c106d06783ce69b6551868028187761ecb232d",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(releases): seed RELEASES.md — interface note for 0.14.2",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-12T17:00:04Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5d2aac739f6485dd832b773ec1fd96998fc6477d",
"body": "botiverse/kimi-code-sdk is a read-only mirror of MoonshotAI/kimi-code.\n- main (this branch): docs + sync CI only, no upstream code.\n- upstream-main + release/* + @moonshot-ai/kimi-code@* tags: the mirror.\nConsumers pin immutable mirror tags. Daily CI ff's upstream-main, mirrors new\nrelease tags, smoke-builds node-sdk, opens an issue on upstream breakage.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: mirror scaffold — README/SOP + daily upstream sync CI",
"author_name": "Kai",
"author_login": null,
"committed_at": "2026-06-12T16:49:22Z",
"body_truncated": false,
"is_coding_agent": true
}
],
"releases_count": 11,
"commits_last_year": 25,
"latest_release_at": "2026-06-27T05:13:02Z",
"latest_release_tag": "v0.20.1",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 4,
"days_since_latest_release": 32,
"mean_days_between_releases": 1.5
},
"community": {
"has_readme": true,
"has_license": false,
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 0,
"stars": 4,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 2
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 11307,
"source_files_sampled": 2,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [],
"dependencies": [],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 2,
"merged_prs": 3,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "claude",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
},
{
"type": "User",
"login": "stdrc",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/5317095?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.571
},
"quality_signals": {
"has_ci": true,
"has_tests": false,
"ci_workflows": [
"publish-sdk.yml",
"sync-upstream.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 0,
"reason": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/25 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 0,
"reason": "license file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "7d1f80143319b97f7921a52e381959a394f4762f",
"ran_at": "2026-07-30T03:08:15Z",
"aggregate_score": 3.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-29T05:27:50Z",
"oldest_open_prs": [
{
"number": 4,
"created_at": "2026-07-20T09:19:20Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 5,
"created_at": "2026-07-21T14:26:37Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-07T04:18:57Z",
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/botiverse/kimi-code-sdk",
"host": "github.com",
"name": "kimi-code-sdk",
"owner": "botiverse"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 42,
"inputs": {
"security": 31,
"vitality": 71,
"community": 16,
"governance": 49,
"engineering": 34
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 71,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 52,
"inputs": {
"commits_last_year": 25,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 4
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "4/52 weeks with commits",
"points": 2.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 4
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "25 commits in the last year",
"points": 12.7,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 25
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 11,
"latest_release_tag": "v0.20.1",
"releases_from_tags": false,
"days_since_latest_release": 32,
"mean_days_between_releases": 1.5
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "11 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 11
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 32 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 32
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.5 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.5
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 16,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 8,
"inputs": {
"forks": 0,
"stars": 4,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "4 stars",
"points": 7.7,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 4
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"has_readme": true,
"has_license": false,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "no license file detected",
"points": 0,
"status": "missed",
"details": [
{
"code": "license_absent",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 49,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 21,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.571
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 57% of commits",
"points": 9.7,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 57
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 72,
"inputs": {
"merged_prs": 3,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "3/3 decided PRs merged",
"points": 38.2,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 3,
"decided": 3
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/25 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"followers": 109,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "botiverse",
"public_repos": 18,
"account_age_days": 1181
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "109 followers of botiverse",
"points": 14.7,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 109,
"login": "botiverse"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "18 public repos, account ~3 yr old",
"points": 15.8,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 18
}
},
{
"code": "account_age_years",
"params": {
"years": 3
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "at_risk",
"name": "Engineering Quality",
"value": 34,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "critical",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 24,
"inputs": {
"has_ci": true,
"has_tests": false,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 31,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 31,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 3.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/25 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 3
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "critical",
"name": "AI Readiness",
"value": 29,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "25 of 25 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 25,
"sampled": 25
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "critical",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"has_nix": false,
"has_tests": false,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.88,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "22 of the last 25 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 22,
"sampled": 25
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "JavaScript",
"largest_source_bytes": 11307,
"source_files_sampled": 2,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "JavaScript without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "JavaScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/2 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 2,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-30T03:08:22.789258Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/botiverse/kimi-code-sdk.svg",
"full_name": "botiverse/kimi-code-sdk",
"license_state": "absent",
"license_spdx": null
}