Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 2.5.0 · 2026-07-29 11:40 UTC

chanceryhq / chancery

The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.

Go · HTMLApache-2.0★ 25 зірок⑂ 1 форкз лип. 2026 р.Переглянути на GitHub ↗
ТипMCP-серверІнструмент командного рядкаяк це визначено

chanceryhq/chancery має індекс здоров’я 59 зі 100, що відповідає смузі «Помірний». Найвищий показник — Vitality (67/100), найнижчий — Community & Adoption (44/100). Останнє оновлення було 8 днів тому. Більшість нещодавньої роботи виконує один учасник.

59
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє зважене середнє, відкаліброване за розподілом публічного реєстру, тож діапазони мають перцентильний зміст; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 34 («У зоні ризику»).

59
Винятковий93-100Верхній щабель реєстру (≈ топ-5%); відповідає практично всім перевіреним критеріям
Відмінний80-92Сильний за всіма напрямами; незначні прогалини
Добрий65-79Здоровий; прогалини обмежені та керовані
Помірний50-64Прийнятний, але з помітними прогалинами; рекомендовано перевірку
Слабкий35-49Суттєві недоліки в кількох сферах
У зоні ризику20-34Суттєві слабкі місця; впровадження потребує обережності
Критичний1-19Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Зважений загальний бал 56 калібровано до 59 за шкалою опублікованого індексу (калібрування реєстру 2026-08-02).

Власність

chanceryhqОрганізація
0 підписників2 публічні репозиторіїз лип. 2026 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
Gogithub.com/chanceryhq/chanceryv0.2.0-38 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

67Добрий · 21% загального індексу
Як обчислюється оцінка
28.8/36Свіжість push — останній push 8 дн. тому
2.1/36Ритм комітів — 3/52 тижнів із комітами
15.4/18Обсяг комітів — 51 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year51
human_commit_share1
days_since_last_push8
active_weeks_last_year3
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 2 релізів
36/36Свіжість релізів — останній реліз 8 дн. тому
27/27Ритм релізів — реліз кожні ~8,7 дн.
8/10OpenSSF Scorecard: Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
Використані вхідні дані
releases_count2
latest_release_tagv0.2.0
releases_from_tagsні
days_since_latest_release8
mean_days_between_releases8,7

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

44Слабкий · 17% загального індексу
Як обчислюється оцінка
22.4/60Зірки — 25 зірок
0/25Форки — 1 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks1
stars25
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (Apache-2.0)
18/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
readme_badges
has_contributingтак
has_issue_templateні
has_code_of_conductні
readme_badge_services
has_pull_request_templateні

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

48Слабкий · 23% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
42/42Вирішення issue — закрито 100% issue
0/30Прийняття PR — немає вирішених pull request-ів або даних
0/13Newcomer PR acceptance — за 30 дн. не вирішено жодного PR від новачка
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues6
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs0
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Виключено з оцінювання (немає даних або не застосовно): Прийняття PR, newcomer_pr_acceptance. Залишкові ваги перенормовано.

Власність та опіка

34У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
0/25Охоплення власника — 0 підписників у chanceryhq
3.6/25Послужний список — 2 публічних репозиторіїв, вік облікового запису ~0 р.
Використані вхідні дані
followers0
owner_typeOrganization
is_verified
owner_loginchanceryhq
public_repos2
account_age_days24
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у go
35/35Свіжість публікацій — остання публікація 8 дн. тому
12/20Історія версій — 3 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesgithub.com/chanceryhq/chancery
ecosystemsgo
any_deprecatedні
min_days_since_publish8

Інженерна якість

Чи наявні базові інженерні практики та документація?

66Добрий · 19% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 2 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
10/10Теми — 20 тем
0/10Wiki
Використані вхідні дані
topicsai-agents, iam, identity, mcp, security, agents, credentials, tools, multi-agent, spawn, browser, browser-automation, hierarchy, cookies, password, mcp-client, mcp-server, mcp-tools, audit, audit-log
has_wikiні
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

52Помірний · 16% загального індексу

Стан безпеки

40Слабкий
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
2/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4
Виключено з оцінювання (немає даних або не застосовно): ci_tests. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
0/25Непрямі залежності без відомих сповіщень — транзитивний набір не відокремлюється від залежностей розробки й тестування в цьому обсязі
0/40Немає задавнених сповіщень — жодне сповіщення не має дати публікації
Використані вхідні дані
sourceosv
advisories0
affected_packages0
assessed_packages15
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Виключено з оцінювання (немає даних або не застосовно): Непрямі залежності без відомих сповіщень, Немає задавнених сповіщень. Залишкові ваги перенормовано. Звірено 15 резолвлених залежностей із OSV. Цей репозиторій не публікує пакета, який резолвить індекс, тож натомість оцінено граф залежностей репозиторію. Цей граф змішує закріплені версії для розробки й тестування зі справді постачаними залежностями, тож оцінюються лише задекларовані runtime-залежності; транзитивні знахідки подаються як контекст і в оцінку не входять. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Має свідомо малу вагу (4%): агентний інструментарій — реальний сигнал супроводу, але репозиторій без нього все одно може отримати 100/100.

57Помірний · 4% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 49 з 51 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,961
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
18/18Розгортання однією командою — Makefile
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — Go (статично типізована)
10/10Відтворюване середовище — Dockerfile, lockfile
0/10Підтверджена практика роботи з агентами — серед останніх 51 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsтак
lockfilesgo.sum
has_dockerfileтак
typed_languageтак
bootstrap_filesMakefile
has_devcontainerні
has_linter_configні
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — Go (статично типізована)
55/55Керовані розміри файлів — 0/43 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageGo
largest_source_bytes54 882
source_files_sampled43
oversized_source_files0
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
0/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalні
api_schema_files

Ключові факти

25зірок GitHub
1контриб'юторів
51комітів за останні 12 місяців
8днів від останнього пушу
2релізів
1бас-фактор
0відкритих issue
Goпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Докладніше

OpenSSF Scorecard 4.0 / 10
4.0сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-29 11:40 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
4Security-Policysecurity policy file detected
8Signed-Releases2 out of the last 2 releases have a total of 2 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Прямі залежності 4
РеєстрПакетОбмеження версіїМаніфест
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/oklog/ulid/v2v2.1.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gomodernc.org/sqlitev1.53.0go.mod
Усі залежності 15

Повний розв'язаний набір залежностей із графа залежностей GitHub: 4 прямих і 11 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
Gogithub.com/golang-jwt/jwt/v5v5.3.1пряма
Gogithub.com/oklog/ulid/v2v2.1.1пряма
Gogithub.com/spf13/cobrav1.10.2пряма
Gomodernc.org/sqlitev1.53.0пряма
Gogithub.com/dustin/go-humanizev1.0.1непряма
Gogithub.com/google/uuidv1.6.0непряма
Gogithub.com/inconshreveable/mousetrapv1.1.0непряма
Gogithub.com/mattn/go-isattyv0.0.20непряма
Gogithub.com/ncruces/go-strftimev1.0.0непряма
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daecнепряма
Gogithub.com/spf13/pflagv1.0.9непряма
Gogolang.org/x/sysv0.44.0непряма
Gomodernc.org/libcv1.73.4непряма
Gomodernc.org/mathutilv1.7.1непряма
Gomodernc.org/memoryv1.11.0непряма
Сповіщення про залежності 0

Цей репозиторій не публікує пакета, який розпізнає індекс, тож оцінено його власний граф залежностей — 15 пакетів, серед яких є й піниї розробки та тестування, що ніколи не постачаються: 0 мають відомі сповіщення, з них 0 прямі.

Жодне відоме сповіщення не стосується оцінених залежностей.

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "iam",
        "identity",
        "mcp",
        "security",
        "agents",
        "credentials",
        "tools",
        "multi-agent",
        "spawn",
        "browser",
        "browser-automation",
        "hierarchy",
        "cookies",
        "password",
        "mcp-client",
        "mcp-server",
        "mcp-tools",
        "audit",
        "audit-log"
      ],
      "is_fork": false,
      "size_kb": 3499,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 334383,
        "CSS": 13532,
        "HTML": 44856,
        "Shell": 2180,
        "Makefile": 194,
        "Dockerfile": 367,
        "JavaScript": 8009
      },
      "pushed_at": "2026-07-21T07:39:20Z",
      "created_at": "2026-07-04T12:50:16Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T07:40:02Z",
      "description": "The identity provider for AI agents — registry, scoped delegation, in-path MCP enforcement, instant revocation, tamper-evident audit.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "HTML"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "chanceryhq",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/299839401?v=4",
      "created_at": "2026-07-04T12:48:19Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 24
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-20T13:47:41Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T22:04:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
          "body": "A broken ring forming a C, holding two bars that narrow. A chancery is\nthe office that keeps the seal, and the narrowing bars are the property\nthe whole product rests on: delegated authority can only shrink. The\nold mark was a generic pillar that said nothing specific and tied to\nthe name not at all\n[…]\nnly variant because the inner bars merge below\nabout 20px. Site favicon links move from an inline data URI to real\nPNGs, versioned so the old cached icon is replaced. README gets a\ntheme-aware lockup.",
          "is_bot": false,
          "headline": "brand: new mark, the seal",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-21T07:39:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80d9cd58cbe2238b0e143453390862dd1d5a9b6c",
          "body": "A different UID is the only boundary that actually holds here: ptrace\nchecks credentials, so being an ancestor stops helping. --run-as <user>\nspawns the server under its own UID, and the sealed-file run dir and\nits contents are chowned to that user so --secret-file keeps working.\n\nApproaches that lo\n[…]\n--confine).\n\nTightens the SECURITY.md invariant: 'agents never hold credentials' is\nprecise about the model's context and the agent's environment, not\nOS-level isolation from same-UID code. 109 tests.",
          "is_bot": false,
          "headline": "G17: ship --run-as privilege separation for the tool server",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:49:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a138f5c9f7ea2e54965fc7ef98452a9410a33f8",
          "body": "…bounded\n\nSealed secrets are injected into the tool server's environment, so\n/proc/<pid>/environ exposes them to any same-UID process — and to\nancestors under the default yama ptrace_scope=1. Since the agent\nruntime typically spawns the wrap, a hostile runtime (distinct from a\nprompt-injected model)\n[…]\nsolation from hostile code sharing the UID, and the tables now say so.\nDeployment guidance gains the mitigation: separate OS user, or\nptrace_scope>=2.\n\nReported by u/Psychological_Arm645 on r/AutoGPT.",
          "is_bot": false,
          "headline": "SECURITY: add G17 — credential isolation is UID-bounded, not process-…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T17:43:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d32ccacf283db6071737e282c3084043d1b30983",
          "body": "Anyone who loaded the page while /assets/* still carried\n'immutable, max-age=31536000' holds that CSS for a year and would never\nsee the aspect-ratio fix. A changed URL is a different cache entry, so\n?v=2 forces one clean refetch; the corrected Cache-Control keeps future\nedits reachable without this.",
          "is_bot": false,
          "headline": "site: version asset URLs to break the poisoned immutable cache",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:34:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c01ee77b008d9ce94938268146645d33d5fcb2e",
          "body": "/assets/* was pinned for a year with immutable, which covers style.css\nand app.js — filenames that never change. Any returning visitor would\nhave been stuck with stale CSS indefinitely (exactly how the squashed\n-image fix failed to appear). Images keep the year; CSS/JS revalidate\nwith ETag.",
          "is_bot": false,
          "headline": "site: don't immutably cache un-hashed CSS/JS",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:31:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4c1fb76583a8920460165fbc050caca3b950ae7",
          "body": "Images declared width/height 1600x1000 against real 2880x1720 assets,\nand the img rule lacked height:auto — so max-width squashed both\ndashboard shots. Corrected the declarations and added height:auto.\n\nCopy moves from personal-project voice to product voice: drops the\nfooter byline, 'Talk to me' becomes 'Get in touch', and the mailto\ntemplate loses its first-name salutation.\n\nPages is disabled (Vercel is canonical at chanceryai.vercel.app), so\nits deploy workflow goes with it.",
          "is_bot": false,
          "headline": "site: fix squashed screenshots, product voice, drop GitHub Pages",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:30:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8793fe7416176ba919088a83e052b1bd7572148f",
          "body": "Above-the-fold content was gated behind IntersectionObserver plus a\nstagger, so the hero sat blank for ~1s on load — bad on slow connections\nand worse for link-preview crawlers (Product Hunt, LinkedIn) that\nscreenshot early. You don't animate what's already on screen at load.",
          "is_bot": false,
          "headline": "site: render the hero immediately, animate only below the fold",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:25:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aa3eecf5267789b3dbcef3f1d937c0846ec2250",
          "body": "…rprise CTA\n\nReplaces the static brochure with a real page: a typed terminal replaying\nthe enforcement story (grant → allow → deny → revoke → deny), scroll\nreveals, a flow diagram of the gate, tabbed workflows, dashboard shots,\nand an enterprise section with a prefilled mailto.\n\nAccessibility/robust\n[…]\nmotion renders everything static.\n\nZero third-party requests: system fonts, no CDN, no analytics — which\nlets the CSP be default-src 'none' with 'self' for script and style, no\nunsafe-inline anywhere.",
          "is_bot": false,
          "headline": "site: proper landing page — animated terminal, interactive tabs, ente…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T16:24:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a994cad55be9fa2f2df015fb43a2dc34f68a3626",
          "body": "The README had grown into a manual — 280 lines, five inlined feature\nwalkthroughs, and a 19-row RFC table. Now 126 lines: what it is, why,\ninstall, one real end-to-end example, a compact capability list, and a\ndocs table pointing at the material that already exists elsewhere.\n\nrfcs/README.md is a ge\n[…]\nthem.\n\nAdds vercel.json (static site/ deploy, security headers, immutable\nasset caching) and puts the dashboard screenshots on the landing page,\nwhere they earn their space, rather than in the README.",
          "is_bot": false,
          "headline": "README: cut to essentials; RFC index moves to rfcs/README.md",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:53:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2951e92fed8107967433eb31976ade7c7abaee81",
          "body": "Drops the pre-alpha label. Every design RFC moves from In Review to\nLocked (design settled and implemented); README gains a Status section\nstating what beta does and doesn't promise — the security model is\nsettled and gaps are published, but CLI/REST may still break before\n1.0.\n\nAdds CHANGELOG.md (v\n[…]\ne landing page from\nRFC-010's MVP item 8, deployed to Pages by a workflow. Assets are\nlocal to site/ because raw.githubusercontent serves a sandbox CSP that\nblocks embedding.\n\n105 tests, go vet clean.",
          "is_bot": false,
          "headline": "v0.2.0: beta — lock all 19 RFCs, add changelog and landing page",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-20T13:44:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f8ae24a4e62376dc098647d28a20b9ffff852df",
          "body": "POST /v1/leases/verify accepts optional xref=<system>:<opaque-id>\n(shape-checked, 400 on malformed). On a VALID lease it is recorded as\nmcp.call_xref carrying the lease's writ, agent, and resource plus the\nopaque foreign id — the one moment two audit chains describe the same\nevent. Invalid leases re\n[…]\n cooperating servers read wid/blk from the lease they\nalready hold.\n\nVerifyLease now returns full LeaseInfo claims. Dashboard event map,\nverify.md walkthrough, RFC-015 amendment; 105 tests. Closes #6.",
          "is_bot": false,
          "headline": "RFC-015 §10: audit cross-references at lease-verify (xref)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T11:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2af06ebc129d9273eb227fc369b2c2514041c525",
          "body": "What-you-get bullet list up top (one line per RFC arc); the RFC-015-018\nmechanisms broken out of the dense paragraph into two sections with\nrunnable commands (callee trust: install/pin/confine/dry-run; per-call:\ntask/intent/lease); matching subheadings for the spawn, wrap, browser,\nand control-plane blocks so 'Try it' reads as one tour.",
          "is_bot": false,
          "headline": "README: capability summary + structured tour",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-17T10:04:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "571e1a2963ada4a3f5575395681b03daea3a0dc0",
          "body": "chancery mcp install <pkg>@<exact-version>: one-time npm install\n(scripts disabled, local paths copied not symlinked) into\n$CHANCERY_DATA/servers/<ns>, Merkle tree-pinned automatically;\nmutable specs refused — a mutable reference is not an identity. A\ntree pin now follows its namespace: plain wraps \n[…]\n), G16 added (host-granular\negress; Linux egress cooperative until netns). 104 tests / 11\npackages, including confinement against the real OS sandbox and the\ninstall→pin→poison→refusal arc. Closes #5.",
          "is_bot": false,
          "headline": "RFC-018: frozen installs and manifest-bounded confinement",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T18:02:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17188a83ae5cb093f26c31dd322055bde05a5bc3",
          "body": "Pins are now (kind, identity) pairs — strongest applicable tier wins:\n\nT3 digest: a container image reference pinned by digest in the server\nargs (image@sha256:...) becomes the identity automatically; mutable\ntags are never identities. Chancery verifies the reference, the\ncontainer runtime verifies \n[…]\ndence, poisoned-dependency e2e).\nG13 narrowed in SECURITY.md/RFC-009: the gap is now the DEFAULT's,\nwith shipped opt-in mitigations; RFC-016 rewritten around the tiers;\nREADME/concepts/verify updated.",
          "is_bot": false,
          "headline": "RFC-016 T2/T3: tree pinning and image-digest pinning",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T17:32:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f58fa4dabcd50b6d276d4b45c78b96dd81c2397",
          "body": "Closes three roadmap issues born from practitioner review:\n\nRFC-015 (#2): the audit trail now distinguishes admitted from happened\n(mcp.call_result committed/failed), and 'mcp wrap --lease' stamps each\nadmitted call with a 30s signed lease in params._meta that cooperating\nservers verify via POST /v1\n[…]\ns only. Arguments pass through transiently and are\nnever stored.\n\n89 tests across 10 packages; gaps G13-G15 added to SECURITY.md and\nRFC-009; RFC-000/005/008 amended; concepts/verify/playbook updated.",
          "is_bot": false,
          "headline": "RFC-015/016/017: call lifecycle + leases, server pinning, intent socket",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-16T13:40:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c5b18a698b73f9996d4ec7da119e81c678d0227",
          "body": null,
          "is_bot": false,
          "headline": "README: dashboard screenshots (audit timeline, writ delegation tree)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T09:10:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f6dda69f002ff36396e2bde4ed36b6eeef33258",
          "body": "asciinema cast + GIF (embedded in README) recorded against the\nbrew-installed v0.1.0 binary in an isolated CHANCERY_DATA dir;\ndemo/demo-driver.sh regenerates it.",
          "is_bot": false,
          "headline": "Demo recording: 40-second grant/allow/revoke/deny/audit arc",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-12T08:27:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da257f750e929f7481066130ac5b328b88b08935",
          "body": "Without it, macOS quarantines the un-notarized binary and newer\nreleases delete it from the Caskroom seconds after install, leaving\na dangling /opt/homebrew/bin/chancery symlink.",
          "is_bot": false,
          "headline": "Cask post-install hook: strip Gatekeeper quarantine from the binary",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T22:01:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21d06772e4ede9099ee70fa1feb02c98dc9fe0b0",
          "body": null,
          "is_bot": false,
          "headline": "Ignore local Stitch design exports",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:53:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae937837791311f5b3b92ffdf7314571a14fe9d1",
          "body": "Void background, seal-purple accent, dual-font ledger (Inter UI /\nmono identity data), per-tab stat cards, uppercase mono table\nheaders, writ cards with boxed delegation-tree nodes and right-angle\nconnectors. Same read-only data plumbing: token gate, 4s polling,\nintegrity pill, text-node-only rendering.",
          "is_bot": false,
          "headline": "Dashboard visual redesign from the Stitch design system",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T21:40:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bda521f3cb7340b4090aa36ff1290bd46d259e6",
          "body": "…ty chips\n\n- timeline speaks human: 'Authority granted to deploy-bot', 'Agent\n  spawned: worker-1', 'Spawn refused' — raw event name demoted to a\n  small mono subline; category dots (grant/action/security/lifecycle)\n- times are relative ('12m ago', 'in 2h') with the full timestamp on\n  hover; templa\n[…]\nnt/caveats\n  (display only, unverified) so narrowing is visible at a glance\n- owners shown as emails (user: prefix stripped); writ ids demoted to\n  hover/sublines; agents show 'spawned by orch' origin",
          "is_bot": false,
          "headline": "Dashboard readability: plain-English events, relative times, capabili…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:38:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e87f007d2020e4c69ada4cae36aefb66db9246b3",
          "body": "The product's proof is visual — the timeline and the delegation tree —\nso chancery serve now ships a dependency-free, go:embed'd dashboard:\n\n- live audit timeline (filterable, ALLOW/DENY pills, agent names\n  resolved) with a permanent integrity badge backed by audit verify\n- agent roster with state \n[…]\nee, JWS omitted) — the\n  route RFC-008 documented but the MVP never implemented\n- verified live in a browser across all four views; 79 tests; docs,\n  playbook step 8, SECURITY G12, RFC-000/009 updated",
          "is_bot": false,
          "headline": "RFC-014: embedded read-only dashboard at /ui",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T12:32:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba10d2e3f466d755936ce507a950853210337b51",
          "body": "Denials are answered immediately by the proxy while allowed calls\nround-trip through the server, so the deny usually prints first; the\nsh stub always replies with id 0. Show the exact expected lines and\nadd a troubleshooting row so neither reads as a failure.",
          "is_bot": false,
          "headline": "Playbook step 5: document response ordering and the stub's id:0",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-11T07:43:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db1a4e2b7c469a7fcbf5a8160cd04a963bbd345b",
          "body": "One ~20-minute sitting: identity/versioning, delegation-only-narrows,\nsealed secrets (grep-for-plaintext), layered policy (allowlist\nsubtracts at the ACTING agent's block, never adds), in-path MCP\nenforcement as the delegated agent, audit tamper detection, lifecycle\nterminality, DENY-as-200 over HTT\n[…]\n the real pitfalls hit\nduring Vantage dogfooding (zsh comments, split heredocs, lost env\nvars, silenced stderr, wrap-awaits-client, exact host matching).\nLinked from README, docs index, and verify.md.",
          "is_bot": false,
          "headline": "Add docs/testing-playbook.md: guided run of every feature (001-013)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-06T04:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33a6c83780c65f4d56f517e94f71b26057ff2c12",
          "body": "Browser agents inherit human sessions — bearer, unscoped, invisible to\nIAM. This makes the session a credential and the navigation an action:\n\n- session custody: mcp wrap --secret-file materializes sealed storage\n  state (cookies) as a 0600 file in a private run dir the SERVER reads\n  (chancery-file\n[…]\naywright MCP recipe\n  (--isolated --storage-state=chancery-file:STATE)\n- 6 new tests incl. full browser e2e (78 total); RFC-000/005/009\n  amended; SECURITY.md gap G11; concepts + verify guides updated",
          "is_bot": false,
          "headline": "RFC-013: browser sessions and tokens as governed credentials",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T18:15:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d19a05fa20aaa000337c5f2a8aeabff8bf4d683",
          "body": "Orchestrators that create agents at runtime (the common multi-agent\npattern) no longer need the admin token. Spawning is itself a\nwrit-governed action:\n\n- admin verb joins the capability grammar (RFC-004 amended);\n  Cap.Implies subsumption for template ceilings\n- templates: human-approved max caps +\n[…]\nly (ActiveErr everywhere);\n  chancery agent sweep retires; agent list shows expired state\n- 10 new tests (72 total); RFC-000/004/007/008/009 amended;\n  SECURITY.md gap G10; docs + verify guide updated",
          "is_bot": false,
          "headline": "RFC-012: dynamic agent creation — writ-gated runtime spawn",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T17:49:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a125b8f2e82d63681ac9488bdd1e5fcd3753809",
          "body": "All four surfaced by testing against a real multi-agent system:\n\n#1 (footgun) mcp wrap --agent X now evaluates X's own writ block, not\n   the writ's latest block (which may belong to a delegated sub-agent).\n   New store.BlockForSubject; explicit --block is verified against\n   --agent. Previously a r\n[…]\n\n   check) — no more granting writs to revoked agents.\n\nTests: block-for-subject selection + narrowing, grant-refuses-inactive,\nno-block-for-agent is ErrNotFound. All 10 packages green; verified live.",
          "is_bot": false,
          "headline": "Fix 4 findings from live Vantage dogfooding",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T10:14:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a9575a3e62c91ef3c30492e55890a1e0a6bbb9b",
          "body": "User-facing verification guide: hands-on, CLI-only, copy-paste checks\nthat each RFC 001-009 does what it claims, with real expected output,\nseparate from the go test suite. Every block was run to capture real\noutput before documenting (caught and fixed an allow-list usage error\nin the draft).\n\nAlso \n[…]\nCLI surface (re-register errored). Added\n'chancery agent version <name>' + service.AddVersion (immutable, keeps\nhistory, emits shadow-agent event on unknown agent), tested. README\nlinks the new guide.",
          "is_bot": false,
          "headline": "Add docs/verify.md (verify each RFC by hand) + agent version command",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T09:04:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6ed6e38b6b0299014391a47ef9d9bd860bd1951",
          "body": "Adds the honest general-purpose story and a non-MCP setup+test\nwalkthrough. Distinguishes the two governance modes: in-path/enforced\n(MCP today, unbypassable) vs advisory/check (any agent, any language,\ntoday via POST /v1/writs/{id}/check + SDK Guard). Shows a plain DB ETL\nagent governed by read:/write: writs with instant revocation and\ntamper-evident audit — verified working via CLI and HTTP before\ndocumenting. README gains the MCP-first-not-MCP-only framing up top.",
          "is_bot": false,
          "headline": "docs: governing any agent (MCP-first, not MCP-only)",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:52:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0588ee17c51534a86b5a27062c72789de75c121e",
          "body": "Fills the developer-setup gap: prerequisites (Go 1.26+, no CGO), build,\nrunning tests (incl. -short to skip the subprocess integration test and\nmake demo), a table mapping all 10 packages' tests to the RFC each\nproves, the repo layout, conventions (RFC discipline, the two non-\nnegotiable invariants), and the DCO (no CLA) contribution flow. README\ngains a 'Build & test from source' section linking it.",
          "is_bot": false,
          "headline": "Add CONTRIBUTING.md: build, test, repo layout, RFC-to-test map",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T08:13:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f131570e62cce1866e03039cecac971fcda80039",
          "body": "Captures the launch checklist durably (out of chat): pre-tag gates\n(3 real users, demo cast, quickstart re-verified), one-time org/repo\nsettings (public packages, chancery.dev, Pages, vuln reporting), the\nrelease cut + verify steps, announce channels, and known non-blocking\nfollow-ups. Release pipeline proven via a private v0.0.1 dry-run.",
          "is_bot": false,
          "headline": "Add LAUNCH.md — go-live runbook and gates",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:48:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bf60180aa7a9f2008e5b24bb637e5c867287537",
          "body": "The homebrew_casks repository block had no token, so goreleaser used\nthe default Actions token (cannot write cross-repo) and the tap push\n403'd. Point it at HOMEBREW_TAP_GITHUB_TOKEN (set from the\nTAP_GITHUB_TOKEN secret in release.yml).",
          "is_bot": false,
          "headline": "release: use the tap PAT for the Homebrew cask push",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-05T07:36:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ca5aa7ac8534a2d1a534cea9644079b27dde453",
          "body": "… docs\n\nWeek 4 (quickstart): QUICKSTART.md walks governing the real official\nfilesystem MCP server; a permanent CI-safe end-to-end test\n(cmd/chancery/wrap_integration_test.go) spawns a real child MCP server\nprocess and proves list-filter/allow/deny/mid-session-revoke + audit\nintegrity. Verified manu\n[…]\nd against a real\nhttptest control plane.\n\nWeek 8 (docs): docs/ for GitHub Pages (native Jekyll from /docs, no CI),\nindex + concepts; README gains a Guides section.\n\nAll 10 packages green; gofmt clean.",
          "is_bot": false,
          "headline": "weeks4-8: real-server quickstart, examples, shadow-agent obs, Go SDK,…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T19:01:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac965281b9e04516f8498cf2b57a0ad9eac2f3fe",
          "body": "Cross-platform static binaries (linux/darwin x amd64/arm64), multi-arch\ndistroless image to ghcr.io (dockers_v2 + buildx), Homebrew cask on\nchanceryhq/homebrew-tap, per-archive SBOM (syft), keyless cosign signing\nof checksums via GitHub OIDC. Version/commit/date injected via ldflags;\nchancery --vers\n[…]\n+ generated cask). Image cosign signing is a noted\nfast-follow pending dockers_v2 signing surface.\n\nPrereqs for first real release: create chanceryhq/homebrew-tap repo and\nset TAP_GITHUB_TOKEN secret.",
          "is_bot": false,
          "headline": "weeks2-3: release packaging — goreleaser, cosign, SBOM, Docker, brew",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:16:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7129083f873f8c9dda21496e9220f945bb4aa81",
          "body": "CLI register/instance-start/grant/delegate/check now call\ninternal/service (RFC-008 §4: one implementation shared with the HTTP\nAPI) instead of duplicating store+writ+policy logic; the mcp wrap\ndecider reuses service.Decide, keeping only the PEP-specific instance-\nliveness gate. Removes ~120 lines o\n[…]\ndecision for PEPs) and\nstore.AuditSince (tail cursor). New: chancery audit --follow streams\nevents live for the demo (ALLOW scrolls, DENY appears on revoke).\nAll tests green; demo and follow verified.",
          "is_bot": false,
          "headline": "week1: route CLI through the service layer; add audit --follow",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T13:11:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7d2dbe68328369e5898d40acc5173c09c95a0668",
          "body": null,
          "is_bot": false,
          "headline": "gitignore: exclude local tooling state",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57463e9fcc76f52877e402045bfae85b02943f79",
          "body": "Founder decision: defer chancery.dev (~$12/yr) until revenue; docs on\nchanceryhq.github.io; vulnerability reporting via GitHub private\nreporting (an improvement regardless — no email infra, built-in CVE\nworkflow). Squatting risk on the public name recorded in RFC-010.",
          "is_bot": false,
          "headline": "Free-domain path: GitHub Pages + private vulnerability reporting",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a86663237e5e0dcac9a95dde22c09690298bcf2",
          "body": "Locks: boundary test (single-trust-domain security/operability = OSS;\norg-scale value = enterprise); two published promises (no license\nflip ever; security never paywalled — all G1-G9 close in OSS); locked\nledger (Cedar/approvals/Postgres/all PEPs OSS; SSO/SCIM, multi-\ntenancy, SIEM exporters, compl\n[…]\nin OSS schema;\nchancery-ee orchestrates per-tenant cores over the public API); DCO\nno CLA (relicensing door welded shut); lockstep releases. Apache-2.0\nLICENSE at root. This closes RFC series 000-011.",
          "is_bot": false,
          "headline": "RFC-011: open-core boundary — the test, the ledger, the two promises",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c006c9542f6a94614e552c3a0316192d49a409ca",
          "body": "Locks: MVP = v0.1.0 with the enforcement wedge (registry inside it);\n12-week plan (CLI->service migration, packaging w/ cosign+SBOM, real-\nserver quickstart, Claude Code + LangGraph examples, shadow-agent\nobservation v0, Go SDK, docs, 3 external users before tag); demo\nscript locked word-for-word; c\n[…]\nadmap, HTTP/shell/browser PEPs, PoP, Cedar, Postgres to v1).\nShips: SECURITY.md (gap table G1-G9, invariants you can hold us to),\nMakefile, scripts/demo.sh (the 60-second arc, CI-runnable — verified).",
          "is_bot": false,
          "headline": "RFC-010: MVP scope — the 90-day build, demo locked, cutlines named",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a1385a3340e2cf8d1a5984481726a8e65a04dce",
          "body": "Research at series close (OWASP ASI, CSA MAESTRO/agentic IAM, Gartner\nguardian agents + agent sprawl): the five defining questions were all\noutbound and known-population. Added Q6 (inbound/agent-to-agent trust\n- ASI07, ~24% org visibility) and Q7 (unregistered agents - discovery\nas a byproduct of en\n[…]\nis\nthe product, ASI06 memory poisoning is the argued scope line) and\nadopts MAESTRO as process reference. Positioning notes: deterministic\nguardian layer, proportional governance as writ policy packs.",
          "is_bot": false,
          "headline": "RFC-000/009 addenda: extended question set and agentic Top 10 mapping",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T12:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61d1ed6a95da0469e2c2d6b28e33841d2ab8c1c2",
          "body": "…table\n\nLocks: trust boundaries (model untrusted, operator trusted in MVP,\nserver semi-trusted); STRIDE walk per component; OWASP LLM Top 10\nmapping (LLM06 excessive agency is the product); abuse cases walked;\npublished MVP gap table G1-G9 each with owner and phase (bearer docs,\nsingle admin token, \n[…]\nI-gated:\nalg:none rejection for both token types, HS256 key-confusion rejection,\ncross-writ block substitution, unsigned delegation block on signed\nchain, exp-required, capability-free grants refused.",
          "is_bot": false,
          "headline": "RFC-009: threat model — STRIDE, OWASP LLM Top 10, and the honest gap …",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:39:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb12309ebc1cdce1d65b1576e9eea3c738328596",
          "body": "… serve\n\nLocks: Vault-style REST/JSON under /v1 mirroring the principal model;\nDDL as the data contract (SQLite->Postgres behind the store seam);\ndigests-only registration (D6 extended to the wire); admin bearer token\n(hashed at rest, constant-time compare, failures audited) with v1 path\nto identity\n[…]\ntest full flow (register->instance->grant->ALLOW->revoke->\nDENY-at-registry->resurrection-blocked), auth rejection + audit, DENY-as-\n200, delegation+attenuation over HTTP, token never in audit stream.",
          "is_bot": false,
          "headline": "RFC-008: data model and APIs — REST/JSON /v1, service layer, chancery…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:36:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2779517ee71678f960df1621d7b87ff7e38acf4",
          "body": "…eans terminal\n\nLocks: per-layer state machines (agent active⇄suspended→retired/revoked,\norphaned exits only via ownership transfer); terminality enforced at the\ndata layer (no client can resurrect); suspend/revoke/retire/orphan as\ndistinct audited verbs; nothing ever deleted; cascade-by-check (one\n\n[…]\n TTL.\nchancery agent retire/orphan/transfer + terminality warnings.\nTests: full transition matrix, no-resurrection property, orphan blocks\nissuance until transfer, retired names not silently reusable.",
          "is_bot": false,
          "headline": "RFC-007: lifecycle and revocation — locked state machines, terminal m…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:32:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05f6f7fa1748ecce37a4f252c617a6cc2e1c7cff",
          "body": "Locks: fixed metadata-only schema (no payload columns — D6 by DDL),\nhash-chained events (prev_hash + SHA-256 over canonical encoding,\ngenesis sentinel), single-writer chain append, locked event taxonomy,\nattribution embedded per row (agent/instance/writ/lineage), NDJSON\nexport, deny-on-audit-failure\n[…]\nappen). chancery audit verify walks the chain and names the first\nbreak. Tests: clean verify, edit/deletion detection with prefix\nproperty, attribution round-trip, allowed-but-unauditable call denied.",
          "is_bot": false,
          "headline": "RFC-006: audit and attribution — hash-chained, metadata-only evidence",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:29:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26b52f631392dc52407f3bb27ba87663fad8672a",
          "body": "Locks: protocol-aware stdio proxy that owns the server process; per-call\nPDP with fresh registry state (revocation = next call, not next TTL);\ntools/list filtered, tools/call enforced (filtering is UX, the call path\nis the boundary); JSON-RPC -32001 denials naming the layer; sealed\nsecrets injected \n[…]\nrnal/mcp +\nchancery mcp wrap. Unit tests: forward/deny/filter/malformed/no-name/\npassthrough. Live integration test passed: mid-session agent revocation\nblocked the next call with attributed timeline.",
          "is_bot": false,
          "headline": "RFC-005: runtime enforcement — the MCP proxy, in-path and unbypassable",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:19:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44e030d20c5683cf7b0f700a0c5bfaadf9169242",
          "body": "Locks: conjunction of layers where only the writ grants (L1) and every\nother layer only denies — allow-lists (L2, MVP), Cedar org policy (L3,\nv1), approvals with reserved 'hold' effect (L4, v1); default-deny;\ncapability grammar locked (verb registry, /-segmented resources,\ntrailing-* with subtree-vs\n[…]\n delegates to it;\nper-agent tool_allowlists + 'chancery agent allow'. Tests: grammar\nvalidity table, match semantics table, layer attribution, empty-list vs\n!none sentinel, nil-authority default deny.",
          "is_bot": false,
          "headline": "RFC-004: policy and authorization — layered PDP, locked grammar",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:14:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d739d54d8f43991617a8e6d367280dc4f6d0090c",
          "body": "Locks: one sealed store (AES-256-GCM, per-entry nonces, name-bound AEAD),\ninjection at the enforcement point per action after writ+policy checks,\ncredential classes sequenced static->OAuth->STS->mTLS, rotation as one\nre-seal. internal/seal + chancery secret put/list/rm. Tests: roundtrip,\nno plaintext on disk, cross-name swap rejected, wrong-key fail-closed,\ntamper rejection, metadata-only listing.",
          "is_bot": false,
          "headline": "RFC-003: credential broker — sealed store, agents never hold secrets",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T07:10:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1b9e5f2e6a094aff9140db2df398e17803c83b",
          "body": "RFC-001/002 running code: SQLite registry (agents/versions/instances,\nthree-layer revocation, fail-closed CheckIssuable), ES256 identity\ndocuments (5-min TTL, WIMSE-style claims, cnf reserved), writ grant/\ndelegate/verify/check with structural attenuation, delegation trees in\nthe registry, metadata-only audit timeline, cobra CLI, CI. Tests cover\nthe RFC invariants: widening unrepresentable, TTL monotonic, depth\nbounded, null-authority refused, tamper detection, revocation at every\nlayer.",
          "is_bot": false,
          "headline": "chancery: registry, identity documents, and writs — first working slice",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ca61e7fb9b250f0bcc376c0e4d25e0e20510b20",
          "body": "Locks: authority as a JWS grant-chain where block 0 grants capabilities\nand later blocks may only add caveats (widening unrepresentable);\neffective authority = grant ∩ caveats; TTL monotonicity; bounded depth;\nthe chain IS the lineage (user -> agent -> sub-agent), embedded in the\ncredential; subtree revocation at any block. Central append in MVP,\nBiscuit-style offline attenuation reserved for v1 (dk field).",
          "is_bot": false,
          "headline": "RFC-002: lineage and delegation — the writ",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-04T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "779f3c58a1fd64915b7b6cd1588118b4a7699240",
          "body": "Locks: agent as third principal class; three-layer identity\n(Agent -> Version -> Instance) with content-addressed versions;\nSPIFFE-compatible naming, WIMSE-compatible identity documents (ES256,\n5-min TTL, cnf slot from day one); registry-born, attestation-confirmed\nbirth model; three-layer revocation. Also: Chancery confirmed as final\nproduct name (RFC-000 D7 updated).",
          "is_bot": false,
          "headline": "RFC-001: agent identity model",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:52:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a70c3367294cced7170e4fb6e8dc20ce9f577091",
          "body": "…gents\n\nLocks: positioning (neutral self-hosted system of record), open-core\nApache-2.0, Go, MCP-first wedge, control-plane-first with own minimal\nbroker, metadata-only audit invariant, codename Chancery.",
          "is_bot": false,
          "headline": "RFC-000: vision and plan for Chancery, the identity provider for AI a…",
          "author_name": "Aneesh Gupta",
          "author_login": "anee769",
          "committed_at": "2026-07-03T17:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 2,
      "commits_last_year": 51,
      "latest_release_at": "2026-07-20T13:47:41Z",
      "latest_release_tag": "v0.2.0",
      "releases_from_tags": false,
      "days_since_last_push": 8,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 8.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/chanceryhq/chancery",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/chanceryhq/chancery",
          "is_deprecated": false,
          "latest_version": "v0.2.0",
          "repository_url": "https://github.com/chanceryhq/chancery",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T13:44:37Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 25,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-17",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 54882,
      "source_files_sampled": 43,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 15,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/oklog/ulid/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": true,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.53.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.73.4",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 15,
        "direct_count": 4,
        "indirect_count": 11
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 6,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "anee769",
          "commits": 51,
          "avatar_url": "https://avatars.githubusercontent.com/u/67168113?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "2 out of the last 2 releases have a total of 2 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3fe3621f705d676f5a3fd50a57ce4097cd3b1b48",
        "ran_at": "2026-07-29T11:40:42Z",
        "aggregate_score": 4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T07:40:02Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/chanceryhq/chancery",
    "host": "github.com",
    "name": "chancery",
    "owner": "chanceryhq"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 56 is calibrated to 59 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 56,
            "calibrated": 59,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 59,
      "inputs": {
        "security": 52,
        "vitality": 67,
        "community": 44,
        "governance": 48,
        "calibration": "2026-08-02",
        "engineering": 66,
        "ai_readiness": 57,
        "weighted_overall_raw": 56
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 67,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "weak",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "commits_last_year": 51,
              "human_commit_share": 1,
              "days_since_last_push": 8,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "51 commits in the last year",
                "points": 15.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v0.2.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 8.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "weak",
        "name": "Community & Adoption",
        "value": 44,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "forks": 1,
              "stars": 25,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "25 stars",
                "points": 22.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "weak",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): PR acceptance, Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "pr_acceptance",
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 74,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 6,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 0,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "chanceryhq",
              "public_repos": 2,
              "account_age_days": 24
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of chanceryhq",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "chanceryhq"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 3.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/chanceryhq/chancery"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "3 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "ai-agents",
                "iam",
                "identity",
                "mcp",
                "security",
                "agents",
                "credentials",
                "tools",
                "multi-agent",
                "spawn",
                "browser",
                "browser-automation",
                "hierarchy",
                "cookies",
                "password",
                "mcp-client",
                "mcp-server",
                "mcp-tools",
                "audit",
                "audit-log"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 52,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 15 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 15
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 15,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 15,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.961,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "49 of 51 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 49,
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 51",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 51
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 54882,
              "source_files_sampled": 43,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/43 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 43,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "weak",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "application"
      ],
      "labels": [
        "mcp-server",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "library": 3,
        "mcp-server": 4
      },
      "primary": "mcp-server",
      "evidence": [
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:github.com/spf13/cobra",
          "weight": 4
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:go",
          "weight": 3
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-server",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-tools",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "low",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": false
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T11:40:48.003499Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chanceryhq/chancery.svg",
  "full_name": "chanceryhq/chancery",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v2.5.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаGo.