公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-25 09:49 UTC

cyanheads / mcp-ts-core

Agent-native TypeScript framework for building MCP servers. Declarative definitions with auth, multi-backend storage, OpenTelemetry, and first-class support for Bun/Node/Cloudflare Workers.

TypeScriptApache-2.0★ 147 星标⑂ 29 复刻始于 2025年3月在 GitHub 上查看 ↗

cyanheads/mcp-ts-core 的健康指数为 100 分中的 65 分,处于「中等」区间。 其得分最高的类别是Vitality(93/100),最低的是Security(47/100)。 最近一次更新在 3 天前。 近期的大部分工作由 1 位贡献者完成。

65
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

65
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Casey Hand个人账户
175 关注者146 个公开仓库始于 2014年12月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

93优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 3 天前
23.5/36提交节奏 — 52 周中有 34 周有提交
18/18提交量 — 最近一年 1,289 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year1,289
human_commit_share1
days_since_last_push3
active_weeks_last_year34

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 33 个发布版本
36/36发布时效 — 最近一次发布版本于 5 天前
27/27发布节奏 — 约每 4.2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count33
latest_release_tagv0.10.15
releases_from_tags
days_since_latest_release5
mean_days_between_releases4.2
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

56中等 · 占总体的 18%

流行度与采用

47存在风险
评分方式
35.1/60星标 — 147 个星标
12.1/25复刻 — 29 个复刻
0/15关注者 — 2 位关注者
所用输入
forks29
stars147
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
62/80月度下载量 — npm 合计每月 44,618 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@cyanheads/mcp-ts-core
dependents
ecosystemsnpm
total_downloads
monthly_downloads44,618
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

55中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0.1/22.5提交分布 — 头号贡献者编写了 100% 的提交
2.7/13.5贡献者广度 — 2 位贡献者
6/10OpenSSF Scorecard:Contributors — project has 2 contributing companies or organizations -- score normalized to 6
所用输入
bus_factor1
contributors_sampled2
top_contributor_share0.995
评分方式
35.9/46.8议题解决 — 77% 的议题已关闭
19.1/38.3PR 接受 — 已裁定的 PR 中 13/26 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs13
open_issues59
closed_issues195
issue_closed_ratio0.768
closed_unmerged_prs13
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
16.1/25所有者影响力 — cyanheads 有 175 位关注者
25/25既往记录 — 146 个公开仓库,账户约 11 年
所用输入
followers175
owner_typeUser
is_verified
owner_logincyanheads
public_repos146
account_age_days4,225
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 142 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@cyanheads/mcp-ts-core
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

70良好 · 占总体的 20%

工程实践

50中等
评分方式
0/24CI 工作流
24/24存在测试
16/16Linter 配置 — biome.json
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

100优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://www.npmjs.com/package/@cyanheads/mcp-ts-core
10/10仓库描述
10/10主题标签 — 10 个主题标签
10/10Wiki
所用输入
topicsmcp, mcp-server, model-context-protocol, ai, opentelemetry, cloudflare-workers, agent-native, framework, typescript, cyanheads
has_wiki
homepagehttps://www.npmjs.com/package/@cyanheads/mcp-ts-core
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

47存在风险 · 占总体的 16%

安全态势

37存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
0/10Dangerous-Workflow — 无数据
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — 无数据
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — 无数据
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate3.7
已排除计分(无数据或不适用):ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
13.2/25间接依赖不含已知公告 — 1 个受影响:@hono/node-server 1.19.15 (moderate 5.9)
40/40没有长期未处理的公告 — 没有公告公开超过 90 天
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages115
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
比对的是 npm:@cyanheads/mcp-ts-core@0.10.15 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 115 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

74良好 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md
agent_instruction_max_bytes39,823
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — biome.json
11/11静态类型检查 — tsconfig.json
10/10可复现环境 — Dockerfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — 无数据
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
已排除计分(无数据或不适用):OpenSSF Scorecard:Pinned-Dependencies。 其余权重已重新归一化。
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
55/55可控的文件大小 — 采样的 445 个源文件中有 0 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes54,037
source_files_sampled445
oversized_source_files0
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
20/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

147GitHub 星标
2贡献者
1,289最近 12 个月提交数
3距最近推送天数
33发布版本数
1巴士系数(bus factor)
59开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package '{{PACKAGE_NAME}}' from its registry

更多细节

Star 与 Fork 历史 0 ★ / 29 ⇿
0Star
29Fork
28发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

0510152025302922025-042025-112026-07
主版本 0次版本 1修订 27

每个点涵盖 2 天。

OpenSSF Scorecard 3.7 / 10
3.7综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-25 09:49 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
不适用Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
不适用Pinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
不适用Token-PermissionsNo tokens found
1Vulnerabilities9 existing vulnerabilities detected
直接依赖 13
注册表软件包版本约束清单文件
npm@hono/mcp^0.3.1package.json
npm@hono/node-server^2.0.10package.json
npm@modelcontextprotocol/ext-apps^1.7.4package.json
npm@modelcontextprotocol/sdk^1.29.0package.json
npm@opentelemetry/api^1.9.1package.json
npmdotenv^17.4.2package.json
npmhono^4.12.30package.json
npmjose^6.2.3package.json
npmpino^10.3.1package.json
npmzod^4.4.3package.json
npm@cyanheads/mcp-ts-core^{{FRAMEWORK_VERSION}}templates/package.json
npmpino-pretty^13.1.3templates/package.json
npmzod{{ZOD_VERSION}}templates/package.json
全部依赖 66

来自 GitHub 依赖图的完整解析依赖集合:13 个直接依赖与 53 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npm@cyanheads/mcp-ts-core^{{FRAMEWORK_VERSION}}直接
npm@hono/mcp^0.3.1直接
npm@hono/node-server^2.0.10直接
npm@modelcontextprotocol/ext-apps^1.7.4直接
npm@modelcontextprotocol/sdk^1.29.0直接
npm@opentelemetry/api^1.9.1直接
npmdotenv^17.4.2直接
npmhono^4.12.30直接
npmjose^6.2.3直接
npmpino^10.3.1直接
npmpino-pretty^13.1.3直接
npmzod^4.4.3直接
npmzod{{ZOD_VERSION}}直接
npm@biomejs/biome2.5.4间接
npm@cloudflare/vitest-pool-workers^0.18.4间接
npm@cloudflare/workers-types5.20260706.1间接
npm@duckdb/node-api^1.5.4-r.1间接
npm@hono/otel^1.1.2间接
npm@opentelemetry/exporter-metrics-otlp-http^0.220.0间接
npm@opentelemetry/exporter-trace-otlp-http^0.220.0间接
npm@opentelemetry/instrumentation-http^0.220.0间接
npm@opentelemetry/instrumentation-pino^0.66.0间接
npm@opentelemetry/resources^2.9.0间接
npm@opentelemetry/sdk-metrics^2.9.0间接
npm@opentelemetry/sdk-node^0.220.0间接
npm@opentelemetry/sdk-trace-node^2.9.0间接
npm@opentelemetry/semantic-conventions^1.43.0间接
npm@socketsecurity/bun-security-scanner^1.1.2间接
npm@supabase/supabase-js^2.110.6间接
npm@types/bun^1.3.14间接
npm@types/node26.1.1间接
npm@types/papaparse^5.5.2间接
npm@types/sanitize-html^2.16.1间接
npm@types/validator^13.15.10间接
npm@vitest/coverage-istanbul4.1.10间接
npm@vitest/ui4.1.10间接
npmbetter-sqlite3^12.11.1间接
npmbun-types^1.3.14间接
npmchrono-node^2.10.0间接
npmclipboardy^5.3.1间接
npmdefuddle^0.19.1间接
npmdepcheck^1.4.7间接
npmdiff^9.0.0间接
npmexeca^9.6.1间接
npmfast-check^4.9.0间接
npmfast-xml-parser^5.10.1间接
npmignore^7.0.5间接
npmignore^7.0.6间接
npmjs-yaml^5.2.1间接
npmlinkedom^0.18.13间接
npmnode-cron^4.6.0间接
npmopenai^6.46.0间接
npmpapaparse^5.5.4间接
npmpartial-json^0.1.7间接
npmpdf-lib^1.17.1间接
npmrepomix^1.16.1间接
npmsanitize-html^2.17.6间接
npmtsc-alias^1.9.0间接
npmtsc-alias^1.9.1间接
npmtypedoc^0.28.20间接
npmtypescript^6.0.3间接
npmunpdf^1.6.2间接
npmvalidator^13.15.35间接
npmvite8.1.5间接
npmvitest^4.1.10间接
npmvitest^4.1.9间接
依赖安全公告 1

安装 npm:@cyanheads/mcp-ts-core@0.10.15 会引入 115 个包(直接与传递):其中 1 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
@hono/node-server1.19.15间接12.0.5

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "mcp",
        "mcp-server",
        "model-context-protocol",
        "ai",
        "opentelemetry",
        "cloudflare-workers",
        "agent-native",
        "framework",
        "typescript",
        "cyanheads"
      ],
      "is_fork": false,
      "size_kb": 8898,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
      "languages": {
        "Shell": 102,
        "Dockerfile": 9732,
        "JavaScript": 109642,
        "TypeScript": 3872892
      },
      "pushed_at": "2026-07-22T01:11:54Z",
      "created_at": "2025-03-20T05:07:04Z",
      "owner_type": "User",
      "updated_at": "2026-07-24T18:42:03Z",
      "description": "Agent-native TypeScript framework for building MCP servers. Declarative definitions with auth, multi-backend storage, OpenTelemetry, and first-class support for Bun/Node/Cloudflare Workers.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://caseyjhand.com",
      "name": "Casey Hand",
      "type": "User",
      "login": "cyanheads",
      "company": null,
      "location": "Seattle, WA",
      "followers": 175,
      "avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4",
      "created_at": "2014-12-29T13:01:12Z",
      "is_verified": null,
      "public_repos": 146,
      "account_age_days": 4225
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.15",
          "kind": "patch",
          "published_at": "2026-07-19T12:24:31Z"
        },
        {
          "tag": "v0.10.14",
          "kind": "patch",
          "published_at": "2026-07-06T08:08:16Z"
        },
        {
          "tag": "v0.10.13",
          "kind": "patch",
          "published_at": "2026-07-05T18:04:33Z"
        },
        {
          "tag": "v0.10.12",
          "kind": "patch",
          "published_at": "2026-07-05T08:45:52Z"
        },
        {
          "tag": "v0.10.11",
          "kind": "patch",
          "published_at": "2026-07-05T05:59:38Z"
        },
        {
          "tag": "v0.10.10",
          "kind": "patch",
          "published_at": "2026-06-30T09:19:32Z"
        },
        {
          "tag": "v0.10.9",
          "kind": "patch",
          "published_at": "2026-06-20T07:52:14Z"
        },
        {
          "tag": "v0.10.8",
          "kind": "patch",
          "published_at": "2026-06-19T23:56:33Z"
        },
        {
          "tag": "v0.10.7",
          "kind": "patch",
          "published_at": "2026-06-19T21:26:53Z"
        },
        {
          "tag": "v0.10.6",
          "kind": "patch",
          "published_at": "2026-06-11T20:27:22Z"
        },
        {
          "tag": "v0.10.5",
          "kind": "patch",
          "published_at": "2026-06-11T16:51:26Z"
        },
        {
          "tag": "v0.10.4",
          "kind": "patch",
          "published_at": "2026-06-11T01:20:20Z"
        },
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-06-10T23:14:46Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-06-10T17:48:09Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-06-08T14:46:42Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-06-05T12:16:41Z"
        },
        {
          "tag": "v0.9.21",
          "kind": "patch",
          "published_at": "2026-06-02T09:05:28Z"
        },
        {
          "tag": "v0.9.20",
          "kind": "patch",
          "published_at": "2026-06-02T03:44:02Z"
        },
        {
          "tag": "v0.9.19",
          "kind": "patch",
          "published_at": "2026-05-31T11:08:20Z"
        },
        {
          "tag": "v0.9.18",
          "kind": "patch",
          "published_at": "2026-05-31T10:18:08Z"
        },
        {
          "tag": "v0.9.17",
          "kind": "patch",
          "published_at": "2026-05-31T05:42:27Z"
        },
        {
          "tag": "v0.9.16",
          "kind": "patch",
          "published_at": "2026-05-30T03:28:09Z"
        },
        {
          "tag": "v0.9.15",
          "kind": "patch",
          "published_at": "2026-05-30T02:47:15Z"
        },
        {
          "tag": "v0.9.14",
          "kind": "patch",
          "published_at": "2026-05-29T11:58:20Z"
        },
        {
          "tag": "v0.9.13",
          "kind": "patch",
          "published_at": "2026-05-29T01:58:44Z"
        },
        {
          "tag": "v0.9.12",
          "kind": "patch",
          "published_at": "2026-05-29T00:42:33Z"
        },
        {
          "tag": "v0.9.11",
          "kind": "patch",
          "published_at": "2026-05-28T08:26:20Z"
        },
        {
          "tag": "v0.9.10",
          "kind": "patch",
          "published_at": "2026-05-27T04:33:29Z"
        },
        {
          "tag": "v0.9.9",
          "kind": "patch",
          "published_at": "2026-05-24T10:13:49Z"
        },
        {
          "tag": "v0.9.8",
          "kind": "patch",
          "published_at": "2026-05-24T09:30:02Z"
        },
        {
          "tag": "v0.9.7",
          "kind": "patch",
          "published_at": "2026-05-23T16:45:02Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2026-05-23T10:27:23Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-05-23T08:40:15Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
          "body": "…fields, expectedStatuses opt-out",
          "is_bot": false,
          "headline": "chore(release): 0.10.15 — Retry-After honoring, canonical HTTP error …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:20:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac3b9e5aee765fdbacc4415b997ab0f9925284d7",
          "body": "Dependency arrows of note: @biomejs/biome 2.5.2 -> 2.5.4 (biome.json\nschema migrated via 'bunx biome migrate'), @cloudflare/vitest-pool-workers\n^0.18.0 -> ^0.18.4, @opentelemetry/semantic-conventions ^1.41.1 -> ^1.43.0,\nhono ^4.12.27 -> ^4.12.30, vite 8.1.3 -> 8.1.5, vitest/@vitest/coverage-istanbul\n[…]\n'\ncasts; fixed across 7 test files by extracting the cast to a local\nbefore the property access (behavior-preserving). The remaining 2 test\nfiles carry only Biome's it.each argument-list reformatting.",
          "is_bot": false,
          "headline": "chore(deps): bun update; biome 2.5.4 migration; typescript 7 held",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:18:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53ed7cd01b96c3d45a6b9c81f4a0d6dd53f4009d",
          "body": "…l-defs-analysis 1.4\n\ngit-wrapup: tag-annotation format overhauled to a flat-bullet headline\ndigest — no Keep-a-Changelog section headers, no gates line, deps\ncapped at one line naming only what earns it; notable changes get\ntheir own bullet, minor/internal items share one grouped bullet.\norchestrat\n[…]\ns (naming taxonomy, parameter vocabulary, tool overlap,\ninstructions drift, length outliers).\n\nfield-test-fix.md, fix-wrapup-release.md, maintenance-release.md updated\nto reference the new tag format.",
          "is_bot": false,
          "headline": "docs(skills): field-test 2.7, git-wrapup 1.8, orchestrations 1.7, too…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c00f24e7bb63d33f562e0d701faacb162badcdb",
          "body": "The 0.10.13 agent-notes told downstream maintenance agents to add a\ntrustedDependencies entry alongside the @socketsecurity/bun-security-scanner\ndevDependency. No such entry exists in that release — the instruction\nwould send an adopting agent looking for something that isn't there.",
          "is_bot": false,
          "headline": "docs(changelog): drop trustedDependencies from 0.10.13 notes (#281)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "685203b8c8ab1c8be4e4df458fc9001295924de9",
          "body": "…ror fields (#256, #279)\n\nfetchWithTimeout gains options.expectedStatuses: number[] — a listed\nnon-2xx status logs at debug instead of error; the thrown, status-mapped\nMcpError is unchanged. Also stops double-logging: the catch block now\nre-throws a FetchHttpError-tagged McpError as-is instead of re\n[…]\nside the\npre-existing statusCode/responseBody aliases (kept, identical values) so\na consumer can read either helper's error the same way.\n\nskills/api-utils/SKILL.md documents both changes (2.4 → 2.5).",
          "is_bot": false,
          "headline": "feat(network): expectedStatuses log opt-out; canonical status/body er…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d6143cc8c91701025dbe292b8521de24244b1fd",
          "body": "Parses an upstream Retry-After hint (RFC 9110 §10.2.3 delta-seconds\nor HTTP-date) off McpError.data.retryAfter and waits that long instead\nof blind exponential backoff. The honored delay is not jittered. When\nthe requested wait exceeds maxDelayMs, the error is treated as\nnon-transient and fails fast with the original error rather than\nburning an attempt that can't succeed in time.",
          "is_bot": false,
          "headline": "feat(network): withRetry honors Retry-After (#285)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:16:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "352addd4d50a55cd73c04c64e7a86bad0fa0c671",
          "body": "Split the dense post-snippet block into shorter paragraphs, cut a redundant sentence, and tighten wording. Facts and code samples unchanged.",
          "is_bot": false,
          "headline": "docs: condense README intro prose",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T09:26:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6a6235c923aaabfd4b172cad81a919a38e6b482",
          "body": "…oc fixes\n\nVersion bumps across package.json, server.json, README, CLAUDE.md, AGENTS.md; changelog 0.10.14; regenerated CHANGELOG.md rollup and docs/tree.md.",
          "is_bot": false,
          "headline": "chore(release): 0.10.14 — Docker build, linter null guard, canvas + d…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "738a6bb9bd6431b49f012ddc504f7b23332011db",
          "body": "…262)\n\nA bare-token curl 404s on the multi-arch OCI indexes docker buildx pushes; the manifest-list Accept header is missing. docker manifest inspect resolves them and exits non-zero when the tag is genuinely absent.",
          "is_bot": false,
          "headline": "docs(release-and-publish): verify GHCR via docker manifest inspect (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f40d4383847f5ce21f3f9e67ee0a95b9c8bbbbe",
          "body": "…minated union (#249)\n\nOUTLINE_VARIANT and outlineOnOverflow JSDoc and the techniques, add-tool, and design-mcp-server skills advertised a z.discriminatedUnion output that tool() rejects (schema-is-object lint and enrichment .extend() are ZodObject-only). Document the flat z.object with a kind discriminator and presence-based optional arms, rendered per field presence in format(). Docs and JSDoc only; no runtime change.",
          "is_bot": false,
          "headline": "docs(overflow): correct outline output to a flat object, not a discri…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb9a6321d856dac49592da1511695db6f22eba19",
          "body": "…overy (#264)\n\nMirror the missing_table precedent from query(): the source-table-not-found throw in DuckdbProvider.importFrom now sets reason missing_table plus a recovery hint. The sibling import_same_canvas and import_view_clash throws gain recovery hints too.",
          "is_bot": false,
          "headline": "fix(canvas): importFrom missing-table NotFound carries reason and rec…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13dbdbdbefa7b7a87ec76640a328c5eb4787f58e",
          "body": "… entry (#265)\n\nA null or undefined entry in a tools/resources/prompts array threw a TypeError and aborted validateDefinitions; only the prompts path survived. Harden the three shared sub-linters (lintEnrichmentContract, lintCappedListTruncation, lintHandlerBody) to early-return on a non-object def, and guard each per-definition loop before dispatch, emitting one definition-invalid error per bad entry. Adds src/linter/rules/definition-rules.ts.",
          "is_bot": false,
          "headline": "fix(linter): surface definition-invalid instead of crashing on a null…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a546e8e4db6d71236bce5049dd938ebc38f5f13",
          "body": "The build stage ran every dependency lifecycle script; better-sqlite3 prebuild-install falls back to node-gyp (absent in oven/bun) and exits 127, failing the build. Match the production stage with --ignore-scripts: the build only runs tsc, which needs type declarations, not native bindings. templates/Dockerfile mirrors it.",
          "is_bot": false,
          "headline": "fix(build): install with --ignore-scripts in Docker build stage (#267)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:04:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e82602fdbf699318a63a740bca990d3ca0061e92",
          "body": "…ization",
          "is_bot": false,
          "headline": "chore(release): 0.10.13 — supply-chain guard, coverage, config modern…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:01:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29e3ceb99a7453a83f620f5e08e8f0e617566ed8",
          "body": "AGENTS.md and CLAUDE.md note that init now scaffolds bunfig.toml, LICENSE, and .gitattributes. .github/FUNDING.yml trims to the active github and buy_me_a_coffee entries; LICENSE copyright year 2025 → 2026 (still Apache-2.0).",
          "is_bot": false,
          "headline": "docs: sync consumer-path list; trim FUNDING; LICENSE year 2026",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53aca5fc19253a53c30aa365e3bac7c591b6f8c3",
          "body": "…lish-docs-meta 2.11\n\napi-workers documents the @duckdb/node-api Worker stub alias. git-wrapup and orchestrations add the changelog-link final line to tag bodies. polish-docs-meta covers manifest.json author identity plus author/packageManager/engines metadata guidance.",
          "is_bot": false,
          "headline": "docs(skills): api-workers 1.6, git-wrapup 1.7, orchestrations 1.6, po…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7940d011996224e29aaf1dc506352cbfb0cb9d87",
          "body": "init now copies an Apache-2.0 LICENSE and a .gitattributes (LF normalization, binary-asset and machine-generated markers) into newly scaffolded servers.",
          "is_bot": false,
          "headline": "feat(templates): scaffold LICENSE and .gitattributes",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5f5027b6404f6ef5fa4d3d16f2b36b73f8d34b2",
          "body": "tsconfig.json extends a deduped tsconfig.base.json; the base moves target/lib ESNext → ES2025 (plus ESNext.TypedArrays). Dockerfile and templates/Dockerfile pin oven/bun:1.3.14 and add BuildKit install-cache mounts. .gitattributes overhauls the lockfile and linguist-generated markers and the git-arc\n[…]\nommit gains a POSIX shebang. Stricter-tsconfig script fixes: devdocs.ts explicit return, lint-mcp.ts conditional packageJson spread, tree.ts entries() iteration. typedoc drops the scripts entry point.",
          "is_bot": false,
          "headline": "build: modernize tsconfig, Dockerfile, and tooling config",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e0fbfd49e4365027c17e8ae8e8623e47bddb49b",
          "body": null,
          "is_bot": false,
          "headline": "chore: drop Smithery deployment config",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69433f431c6e695df623a831b57561d1f34d1821",
          "body": "wrangler.toml becomes wrangler.jsonc (schema-referenced, inline comments). An alias maps @duckdb/node-api to examples/duckdb-stub.ts so wrangler's esbuild step stops failing on DuckDB's native bindings — the DataCanvas provider's lazy import() is statically reachable from the Worker entry but never executes there.",
          "is_bot": false,
          "headline": "build(workers): migrate wrangler config to JSONC; stub @duckdb/node-api",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "114edd0339601adcc4294ffab99e024c7ce236c0",
          "body": "bunfig.toml adds a 3-day minimumReleaseAge hold on fresh publishes and an [install.security] Socket scanner; package.json declares the @socketsecurity/bun-security-scanner devDependency and trusts it. devcheck's Outdated gate now skips versions bun holds by release age (Update == Current, marked *),\n[…]\n .github/SECURITY.md adds a disclosure policy.\n\npackage.json also drops the unused main/types fields, adds a prepare hook-path script, bumps packageManager to bun@1.3.14, and sets the author identity.",
          "is_bot": false,
          "headline": "chore(security): minimumReleaseAge hold + Socket install scanner",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e301d1fe4e54c48702db126410acbeedbcb99554",
          "body": "…/services",
          "is_bot": false,
          "headline": "test: expand unit coverage; move DuckDB smoke suite under tests/smoke…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:58:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebbb12bfe2a8e37cbbccface856c59a9ae758c98",
          "body": "…separator",
          "is_bot": false,
          "headline": "chore(release): 0.10.12 — canvas error contracts, enrichment trailer …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c415f70563ad2bef2ae6eda735f136151f24269",
          "body": "…h (#261, #254)\n\nCanvasRegistry's not-found throws (acquire, touchOrThrow, touchWithTable, touchWithSqlTables) and DuckdbProvider.requireCanvas() now carry data.reason 'canvas_not_found', the canvasId, and a default recovery.hint, so consumer-declared canvas_not_found error contracts populate on the\n[…]\ny-structured McpError unchanged instead of reclassifying it to DatabaseError, preserving register_as_clash and export_path_* ValidationError codes and data across all four provider catch sites (#254).",
          "is_bot": false,
          "headline": "fix(canvas): structured canvas_not_found errors, McpError pass-throug…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07928d739c5ab069b8ca38c5339a2517bb0906c3",
          "body": "Clients that concatenate adjacent content[] text blocks with no join (Claude Desktop, claude.ai) rendered the trailer glued onto the last domain line. Markdown collapses consecutive blank lines, so clients that insert their own separator render at most one blank line either way.",
          "is_bot": false,
          "headline": "fix(tools): lead enrichment trailer with a blank-line separator (#257)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0c35f0558e3375079acc9212ffb7937b7ece8c9",
          "body": "…ics, dep refresh",
          "is_bot": false,
          "headline": "chore(release): 0.10.11 — scaffold devcheck fix, security-flag semant…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:56:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf33b280dfaf83378157eafb3961dfbb3cfea0a3",
          "body": "…overy discipline\n\nAdds the Reference tool shape to the taxonomy (decoder ring for opaque domain vocabulary — codes, enums, identifier formats; the standing target of recovery routing; implement first) with its own subsection. API probing gains unknown-param and omission-semantics probes, and the st\n[…]\nfalse, guidance } instead of throwing, zero-hit behavior is specced at design time, and design docs settle verbatim recovery strings under a no-dead-ends rule (each names the concrete next tool call).",
          "is_bot": false,
          "headline": "docs(skills): design-mcp-server 2.19 — reference tools, probe and rec…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:51:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8199830341c44d465e6c02bbd98e7224ae512d2e",
          "body": "@biomejs/biome 2.5.1 → 2.5.2 (biome.json $schema follows), @cloudflare/vitest-pool-workers ^0.16.20 → ^0.18.0, @cloudflare/workers-types 4.20260630.1 → 5.20260705.1, @opentelemetry/* 0.219→0.220 and 2.8→2.9 sets, @opentelemetry/instrumentation-pino ^0.65.0 → ^0.66.0, @supabase/supabase-js ^2.109.0 →\n[…]\nte 8.1.0 → 8.1.3.\ntemplates/package.json pins @biomejs/biome 2.5.2 and @types/node 26.1.0 so a fresh scaffold's Biome CLI matches the shared config's $schema and devcheck passes out of the box (#260).",
          "is_bot": false,
          "headline": "chore(deps): bun update --latest; align template biome/types pins (#260)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:46:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8ff580bcbf7110eb5539d859339c768a02a657c",
          "body": "…263)\n\n0.9.0 removed the startup lint gate — createApp() no longer invokes validateDefinitions — but three comment sites still described it: the errors-contract and format-parity JSDoc in toolDefinition.ts and the startup-fatal error comment in app.ts. All three now state the current mechanism (bun run lint:mcp, gated in devcheck). These ship in the published .d.ts, so hover docs previously contradicted actual behavior.",
          "is_bot": false,
          "headline": "docs(src): stale startup-linter JSDoc corrected to build-time lint (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:46:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4fc2f05c948da905d86127aceadc95e6046ba11",
          "body": "… as-built\n\nRoot protocol: definition linting described as build-time (bun run lint:mcp / devcheck), not startup — schema-serializable and format-parity notes corrected; init copy list completed (devcheck.config.json, tests, scripts/, skills/, never-overwrite + in-place upgrade); ContentCollect/Cont\n[…]\n(devcheck removed; techniques and api-mirror added; bun run list-skills), commands table moved npm→bun and gains lint:mcp / lint:packaging / list-skills rows, security frontmatter scoped the same way.",
          "is_bot": false,
          "headline": "docs(protocol): sync CLAUDE.md/AGENTS.md and template counterparts to…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0736c339d407ed94df2c285971e2049f2da1260",
          "body": "git-wrapup 1.6: create annotated tags with --cleanup=whitespace (default strip deletes #-leading markdown lines; verbatim breaks SSH signature parsing and leaks the signature block into the release body), verify the tag reads as signed in the end-state check, and scope the changelog security flag to\n[…]\nruns the project gates, and three transformation rows corrected (TS 5.5 inferred type predicates, enum-value serialization caveat, walrus example).\napi-utils 2.4, polish-docs-meta 2.10: version bumps.",
          "is_bot": false,
          "headline": "docs(skills): tag-signature safeguards, code-simplifier corrections",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18abb9cd5b3312619179ee6186cb4d303b091b77",
          "body": "The security frontmatter field flags a vulnerability or hardening fix in this project's own code. A dependency or transitive CVE bump is routine maintenance: it stays under ## Dependencies with the flag false, so the Security badge answers \"does the shipped code have a vuln\" rather than tripping on every dep refresh. Tightened in both changelog templates and the build-changelog JSDoc.",
          "is_bot": false,
          "headline": "docs(changelog): scope security flag to source-code fixes only",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8373752be1f3395fb2f05c224bbd512b88b4165",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.10.10 — js-yaml v5 migration, dependency refresh",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-30T09:16:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c34bf3dc3b3dd43cfc68fc94448df9dc96eefc2",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): remove Contributing from readme reference",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-30T09:16:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a95a408dd2a77eff8501f3e4952bc65bcc1bae3d",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): remove Contributing section",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-28T08:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c5b9ccb6e01cc88a0064b2e94f5ab9b669bee85",
          "body": "…uards\n\n@cloudflare/workers-types 4.20260619.1 → 4.20260620.1",
          "is_bot": false,
          "headline": "chore(release): 0.10.9 — devcheck dep-specifier and plugin-manifest g…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-20T07:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af5d2643d70b08990fb3f292c74b579663da67ad",
          "body": "…manifests (#246, #240)\n\ncheck-dependency-specifiers (new ALL_CHECKS step, --no-dep-specifiers): hard-fails on latest/*/dist-tag specifiers in package.json's four dep sections and bun.lock's workspaces map, never the packages section. latest fails everywhere; */next/beta/canary/rc fail in dependenci\n[…]\nnstall arg (an unscoped arg for a scoped package 404s). Gated by devcheck.config.json packaging.pluginManifests (default on); the Packaging gate now also runs when a plugin manifest is present. (#240)",
          "is_bot": false,
          "headline": "feat(devcheck): guard floating dep specifiers and plugin marketplace …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-20T07:46:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3de075e7b090a669334e8e4378de9e5fcb20f98",
          "body": "…assification",
          "is_bot": false,
          "headline": "chore(release): 0.10.8 — ctx.content collector, canvas invalid_sql cl…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "669ae01e52082d23bf3417f2756b83d8aff9324d",
          "body": "…(#239)",
          "is_bot": false,
          "headline": "feat(context): add ctx.content collector for non-text content blocks …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1761990cd6080eab5d4c62421c9e6999b69953d2",
          "body": "…ith binder detail (#236)",
          "is_bot": false,
          "headline": "fix(canvas): classify SELECT-shaped prepare failures as invalid_sql w…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "267e6da839c3b7dddd0e50463019ada1a106a1c1",
          "body": "…eeds it (#233)",
          "is_bot": false,
          "headline": "docs(telemetry): correct OTEL_SERVICE_NAME default — createApp name s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa1faca2c84607ea2e53887a4cdee69c5f6dec49",
          "body": "…x, dep refresh\n\nFresh-scaffold devcheck fixes (#242 #243), check-skill-versions worktree-deletion guard (#237), and the DuckdbProvider.describe() Binder Error fix (#235); seven skill version bumps (#238). Dependency refresh: biome 2.4.16 -> 2.5.0 (biome migrate applied to biome.json), node-cron 4.2\n[…]\nuler test moved to vi.mock for the frozen ESM namespace), and the resolutions block trimmed to one js-yaml pin (bun audit clean). Version bumped across package.json, server.json, CLAUDE.md, AGENTS.md.",
          "is_bot": false,
          "headline": "chore(release): 0.10.7 — devcheck scaffold guards, canvas describe fi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7d73e49c18598a3db6a72d60d141a17c9a06edb",
          "body": "…244)\n\nThe #157 body-size tests assert only an eventual 413, which passes even when the whole over-limit body is buffered via arrayBuffer() first. This adds an instrumented-stream test asserting the cap bounds buffering — cancels the stream shortly after the limit on a no-Content-Length body. Marked test.fails: the current buffer-then-check code does not satisfy it, so the suite stays green while #244 is open; implementing the streaming cap flips it red as the signal to restore test.",
          "is_bot": false,
          "headline": "test(transport): stage streaming body-cap regression as test.fails (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5e164216ada101b985998c12fae3d023ca20079",
          "body": "…ver isolation note\n\ngit-wrapup v1.4: tag annotations may carry one concise context line under the subject (one or two lines, never paragraph blocks); restate the Bash-git rule without the obsolete git-mcp-server rationale. orchestrations v1.4: parallel sub-agents drive git through the shell against their own working directory.",
          "is_bot": false,
          "headline": "docs(skills): allow one tag-annotation context line; drop git-mcp-ser…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe9e8b48439374b5c9fc551eb8872009fc20e900",
          "body": "…y drift (#238)\n\nSeven external skills carried body changes that shipped pre-0.9.18 with no metadata.version bump, so the version-gated maintenance Phase A sync never propagated them to consumers. Bumped: api-auth 1.1->1.2, api-errors 1.6->1.7, api-services 1.3->1.4, api-telemetry 1.0->1.1, field-test 2.5->2.6, report-issue-local 1.5->1.6, tool-defs-analysis 1.2->1.3. Mirrors in .claude/skills and .agents/skills already match.",
          "is_bot": false,
          "headline": "chore(skills): bump metadata.version on seven skills with shipped bod…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "200454465ad226087acd70a71a5de9621a5ae2bf",
          "body": "…oin (#235)\n\ndescribe({ tableName }) pushed an unqualified table_name predicate into a query joining information_schema.tables t with duckdb_tables(), both exposing table_name — DuckDB raised a Binder Error (ambiguous column) on every filtered call. Qualified the pushed filters with the t alias (t.table_name, t.table_type, t.table_schema); the table_type arm was latent but qualified for consistency.",
          "is_bot": false,
          "headline": "fix(canvas): qualify describe() filters against the duckdb_tables() j…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecccb7e85cfe939574346987b110a8e4ae5f5de0",
          "body": "git diff --name-only HEAD lists a deleted skill and git show HEAD:<path> still returns the blob, so the loop reached readFileSync on a path no longer on disk and crashed with ENOENT — hit on every maintenance pass that prunes an upstream-removed skill. Added an existsSync guard before the read; a deleted file has no body to compare and cannot violate the policy.",
          "is_bot": false,
          "headline": "fix(scripts): skip worktree-deleted SKILL.md in the version gate (#237)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71f4c5818d574962a6f0c0a91273509cfa79dd69",
          "body": "TODOs/FIXMEs, Tracked Secrets, and Framework Antipatterns shell out to git grep / git ls-files, which exit 128 (not a finding) on a fresh scaffold before git init — devcheck reported it as a failure. Added a shared isGitRepo() helper that returns null from those getCommand()s when .git is absent; check-framework-antipatterns.ts also self-guards for direct invocation.",
          "is_bot": false,
          "headline": "fix(scripts): guard git-dependent devcheck checks outside a repo (#243)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e9b8a17d22f9a44bfe1a4207d077df4cc4179e2",
          "body": "build-changelog.ts --check exited via a thrown buildRollup() when changelog/ held only template.md and no <major.minor>.x/ version files — a fresh scaffold's own shipped state, surfacing as a stack trace on the first devcheck. Now exits 0 under --check when collectVersionFiles() is empty; a manual changelog:build still throws on an empty tree.",
          "is_bot": false,
          "headline": "fix(scripts): skip changelog sync cleanly on a fresh scaffold (#242)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d491a2789a3f20d0e3ea5496a8a84c53081f3da",
          "body": "…e preamble (git-wrapup v1.3)",
          "is_bot": false,
          "headline": "docs(skills): tag annotations are sections+bullets only — no narrativ…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:32:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c78d58aaafb9cacd17323633f93c09a1ea72f43f",
          "body": "…lated to #230; clean-mcpb ships by init copy/script sync, not node_modules reference",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.6 entry — orchestrations bullet is unre…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:30:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65ce31ab46f45575c2f09358acfe32f99bbbb1a8",
          "body": "…ity lint (#230, #231)",
          "is_bot": false,
          "headline": "feat(packaging): 0.10.6 — bundle cleaner, post-bundle content + ident…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:24:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3e3c7551f0f00e43f79e55272fe69989b23ae76",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): orchestrations v1.3 — Phase 4 close-loop wording",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b8955b8164ca51b09b787b79f5cde879ac6eb5a",
          "body": "…ndings attribution, linter-claim wording",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.5 entry — skill version 1.5, fixture/bi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:56:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f4222e37bd18d26b2f37c187a2e2d5f24c46e3a",
          "body": "New ./testing/vitest subpath exports mcpTest (test.extend with ctx + storage fixtures) and McpTestFixtures interface. vitest >=4.0.0 added as an optional peer dependency. packaging guards updated: export-map allowlist gains ./testing/vitest; optional-peer-deps test adds an integration-entrypoint exe\n[…]\nino ^0.64.0 → ^0.65.0; @opentelemetry/resources ^2.7.1 → ^2.8.0; @opentelemetry/sdk-metrics ^2.7.1 → ^2.8.0; @opentelemetry/sdk-node ^0.218.0 → ^0.219.0; @opentelemetry/sdk-trace-node ^2.7.1 → ^2.8.0.",
          "is_bot": false,
          "headline": "feat(testing): 0.10.5 — mcpTest fixture-based Vitest subpath (#227)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:50:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1362c22cc9038c1e1aef17c9d262ef6b7765cb2",
          "body": "lintCappedListTruncation checked allowlist.includes(name) without guarding against non-array truncationAllowlist values; guard added.",
          "is_bot": false,
          "headline": "chore(linter): Array.isArray guard for the truncation allowlist check",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d44bee496c12fdfdaa011f1efbcfd0fb5fe2c8e2",
          "body": "… cases (#229)\n\nFifth vitest project 'typecheck' over tests/types/**/*.test-d.ts, using tsc checker with ignoreSourceErrors. maxWorkers: 4 required by vitest's uniform-sequence-group rule. New test:typecheck script. Three .test-d.ts files: error-contract (ReasonOf, TypedFail, TypedRecoveryFor, createFail, createRecoveryFor, HandlerContext), handler-context (HandlerContext inference), and tool-builder (output type inference).",
          "is_bot": false,
          "headline": "chore(tests): vitest typecheck project with @ts-expect-error negative…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbbec769c5bd2baa13452419568870b3028458cd",
          "body": "r2Buckets and d1Databases miniflare bindings added to the worker-runtime fixture. Per-provider test files exercise set/get/delete/list/TTL through the worker handler. skills/api-workers v1.3 documents the binding pattern.",
          "is_bot": false,
          "headline": "chore(tests): R2/D1 emulated workerd storage suites (#228)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0760ea0a627008344836ffad7a27e185bfff40da",
          "body": "R2 rejects list() limits above 1000; limit+1 now clamped to R2_MAX_LIST_LIMIT=1000. At the cap, the response's truncated flag covers has-more detection instead of the +1 probe.",
          "is_bot": false,
          "headline": "fix(storage): clamp R2 list +1 page probe at the 1000-key cap (#228)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54fd2e650dbde7474c170947873d503376cb2619",
          "body": "….3 floors (#216)\n\nAbortSignal.any for fetchWithTimeout external-signal composition and retry sleep cancellation. Uint8Array.toBase64/fromBase64 replaces chunked string-based encoding in the workerd/browser branch; Buffer fast-path stays primary. globalThis.performance.now direct delegation in nowMs\n[…]\nre extends AsyncDisposable — custom backend implementations must add [Symbol.asyncDispose]. TextToSpeechResult.audio and SpeechToTextOptions.audio type changed from Buffer|string to Uint8Array|string.",
          "is_bot": false,
          "headline": "refactor(utils,services): platform-native sweep under Node>=24/Bun>=1…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:48:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffa740dda1ec7f793efe305e9cad953ae50b15d2",
          "body": "…rom peers",
          "is_bot": false,
          "headline": "docs(changelog): fast-check was added to devDependencies, not moved f…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:22:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95c4927058f500771a797617abf425b3193c824c",
          "body": "…ync (#217)\n\nPackaging (#217):\n\n- exports map: default condition added to all 18 JS entries\n\n- HEALTHCHECK in Dockerfile and templates/Dockerfile (bun-native fetch, no curl dep)\n\n- tsconfig.base.json, tsconfig.json: importHelpers removed (no-op at ESNext, tslib never declared)\n\n- tsconfig.test.json \n[…]\nerage thresholds raised (stmts 88->91, branches 79->83, fns 90->92, lines 89->92)\n\nSkills:\n\n- api-testing v1.4: output schema assertions via expect.schemaMatching\n\n- api-canvas v1.6: see canvas commit",
          "is_bot": false,
          "headline": "chore(build,test): 0.10.4 — packaging hygiene, test infra, template s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:19:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d0ad33f93e4241bf5a3f14da20b131f3f6b6000c",
          "body": "…Found, catalog deny layer, approxSizeBytes (#221, #222, #223, #224, #226)\n\n- inferSchemaFromRows: all inferred columns now nullable: true; sample cannot prove NOT NULL (#221)\n\n- query() non-registerAs path: streamAndReadUntil(rowLimit+1) replaces runAndReadAll+slice; adds truncated flag to QueryRes\n[…]\nSystemCatalogs: new export; opt-in QueryOptions/RegisterViewOptions.denySystemCatalogs flag (#224)\n\n- describe(): LEFT JOIN duckdb_tables() to populate TableInfo.approxSizeBytes for base tables (#226)",
          "is_bot": false,
          "headline": "feat(canvas): inferred-nullable fix, streaming cap, missing-table Not…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:18:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfeb9ff6de473a04837319999a718e7676b2a8bd",
          "body": "…on, sampling removed, server identity, completable args\n\nVersion: 0.10.2 → 0.10.3\nDependency: @types/node ^25.9.2 → 25.9.3 (pinned to patch)",
          "is_bot": false,
          "headline": "chore(release): 0.10.3 — elicit wired on the wire, URL-mode elicitati…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:12:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07d71331263b1db5ade50df0608912df8a83c110",
          "body": "…tures\n\ngit ls-files lists files deleted from the worktree but not yet staged. The audit\ncrashed when trying to read those paths. Added existsSync() filter so uncommitted\ndeletions don't break the audit during development.",
          "is_bot": false,
          "headline": "chore(scripts): skip worktree-deleted files in audit-open-index-signa…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44d6bda1e971ed14e89ddba0719f3137d0144e96",
          "body": "…#213, #218)\n\nCreateAppOptions gains optional title, websiteUrl, description, icons (typed against\nImplementation['icons']). All four are forwarded to the McpServer constructor's\nserverInfo and to buildServerManifest so initialize and /.well-known/mcp.json stay\nconsistent. Explicit description wins \n[…]\nervices and createMcpServerInstance\nbut the registerAll() call was a no-op. The roots/ directory and its test are gone.\nRoots is also deprecated by SEP-2577. RootsRegistry was never publicly exported.",
          "is_bot": false,
          "headline": "feat(app): server identity fields, remove RootsRegistry placeholder (…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc7e7b02e607eb1c7694fc8c049d5371e353dc71",
          "body": "…mpt title (#214)\n\nprompt() args fields may be wrapped with completable() — re-exported from the main\nentry so consumers don't need a direct SDK import. The SDK auto-installs\ncompletion/complete handling and advertises the completions capability when any\nregistered prompt has a completable argument.\n[…]\nResourceTemplate constructor second argument; triggers the\nsame automatic completions capability advertisement.\n\nresource-registration.ts also carries the #211 elicit notifier wiring (file atomicity).",
          "is_bot": false,
          "headline": "feat(prompts,resources): completable args, resource complete map, pro…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee720eb0c63cb25938796bf1dee3da15bc54521f",
          "body": "…, #212, #220)\n\nctx.elicit was never defined at runtime — the extra-sniffing approach misread the\nSDK's RequestHandlerExtra shape. Now wired via registration-time notifier closures:\nelicitInput and getClientCapabilities bound to the per-server Server instance in\nboth tool-registration.ts and resourc\n[…]\nicitFn with a default no-op .url()\nstub so tests exercising form-mode elicitation don't need to supply .url explicitly.\n\nsrc/core/index.ts also carries the #214 completion re-exports (file atomicity).",
          "is_bot": false,
          "headline": "feat(context): wire ctx.elicit, add URL-mode, remove ctx.sample (#211…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:10:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43b072e45ea9344b4a4dcf6de720959d8935a36e",
          "body": "…irror-CLI recipe description, cap-field list",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.2 entry — scaffold stanza paths/user, m…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:50:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75c2b0bc10d1f7efb44f40565d2ed14074864518",
          "body": "… rules, scaffold data dirs\n\nhono ^4.12.24 → ^4.12.25\n@cloudflare/vitest-pool-workers ^0.16.13 → ^0.16.14\n@cloudflare/workers-types 4.20260608.1 → 4.20260610.1\n@supabase/supabase-js ^2.108.0 → ^2.108.1\nsanitize-html ^2.17.4 → ^2.17.5",
          "is_bot": false,
          "headline": "chore(release): 0.10.2 — per-table canvas TTL, canvas/truncation lint…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6aa8b05262127d4b7ca429eb37307e447b780a96",
          "body": "…rror-CLI Docker recipe (#199, #195)",
          "is_bot": false,
          "headline": "feat(templates): writable SQLite data dirs in scaffold Dockerfile, mi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "772939b251f95fa23ddf4de2aef52d198b334eec",
          "body": "…rich.truncated (#209, #197)",
          "is_bot": false,
          "headline": "feat(linter): canvas-consumer and truncation-disclosure rules, ctx.en…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a058c5efbad6b7e63779510ad706434f987a8d5a",
          "body": "…pillover (#140)",
          "is_bot": false,
          "headline": "feat(canvas): per-table TTL on registerTable, query registerAs, and s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "158747a30ee6c82246925f2c55190e8223d2d8fc",
          "body": "…scaffold/packaging fixes",
          "is_bot": false,
          "headline": "chore(release): 0.10.1 — canvas SQL gate fail-closed, pragma_* deny, …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a641fe30dec6ebfb21cd919d74968e1ce2bf3dbc",
          "body": "…ons (#210)",
          "is_bot": false,
          "headline": "fix(canvas): fail closed on non-SELECT and deny pragma_* table functi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4fe4cc7ec1b5ef3b974f7c8418c867b860ee8d3",
          "body": null,
          "is_bot": false,
          "headline": "fix(scheduling): actionable error when node-cron peer is missing (#200)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bc402edbe765de8bdae29594baff47eb892e0cd",
          "body": "…uard (#207)",
          "is_bot": false,
          "headline": "fix(packaging): anchor .mcpbignore dev patterns, add bundle-content g…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2a055524862a95b1f015ecb05c9ba4db0dbfea2",
          "body": null,
          "is_bot": false,
          "headline": "fix(templates): ship repository object in manifest (#206)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a59dea547837af557f39d34a5b9c1b6e3741b951",
          "body": null,
          "is_bot": false,
          "headline": "fix(templates): run scaffold scripts via Bun, drop tsx (#205)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e6cd672ee25a8f9e24234b4bfb3dc93fd919e73",
          "body": "@cloudflare/vitest-pool-workers ^0.16.11 → ^0.16.13\n@cloudflare/workers-types 4.20260602.1 → 4.20260605.1\n@supabase/supabase-js ^2.106.2 → ^2.107.0\nopenai ^6.41.0 → ^6.42.0",
          "is_bot": false,
          "headline": "chore(release): 0.10.0 — outline-on-overflow, stringbool env booleans",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ac4cc9089157bdfb7f1065ca2994160e59e316d",
          "body": "…202)\n\ntemplates/Dockerfile now accepts an APP_VERSION build arg and stamps\norg.opencontainers.image.version in the OCI label block; also declares\norg.opencontainers.image.source (filled with the repo URL at scaffold\ntime). release-and-publish skill updated to pass --build-arg APP_VERSION\nto docker buildx for both amd64/arm64 platforms. Scaffolded servers only\n— existing servers pick this up on re-scaffold.",
          "is_bot": false,
          "headline": "fix(templates): stamp OCI image.version and source on built images (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15d8d2b7eea4e77301d5737d4b84e4ecd9f02b7d",
          "body": "New /utils exports: outlineOnOverflow(), OUTLINE_VARIANT, selectSections(),\nformatOutline(), DEFAULT_OUTLINE_BUDGET_BYTES. When a document-shaped\npayload exceeds a serialized-byte budget, returns a section outline\n(top-level keys + per-section size) and a re-call notice instead of\ntruncating. Agent \n[…]\nte cache, when to choose\nit over spillover() or capped-list disclosure).\n\ndesign-mcp-server and add-tool skills updated with overflow guidance.\nCLAUDE.md, AGENTS.md, docs/tree.md updated for new dirs.",
          "is_bot": false,
          "headline": "feat(utils): outline-on-overflow for oversized document payloads (#204)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63655562b73a7694d85c5cb6ce2564b40195453f",
          "body": "Replaces the hand-rolled envBoolean preprocess in src/config/index.ts\nwith Zod z.stringbool(). Accepts true/false/1/0/yes/no/on/off\n(case-insensitive); rejects unrecognized values at startup instead of\nsilently coercing them to false. Real booleans pass through (Workers\n[vars]). yes/on/y/enabled now\n[…]\nin src/, which coerces \"false\" to true. Scanner now\nskips comment lines to avoid false-positives on doc mentions. Server-\nconfig docs (api-config skill, templates) updated to recommend\nz.stringbool().",
          "is_bot": false,
          "headline": "feat(config): parse env booleans via Zod stringbool (#201)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:12:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db1bc01d26a51e50bd2a27342ccc7a695f85c110",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.9.21 — HTTP transport per-request log context fix",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18ddb7eb9322592f8af3d01f893e28b0d06cf3ee",
          "body": "…ions skill",
          "is_bot": false,
          "headline": "docs(templates): expand First Session onboarding, document orchestrat…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a367b9c7edfff97e419f834335912ed63eca6284",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): mark orchestrations workflows as audience: external",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fd7c11e126b727e120a847383015725f0ceb2c3",
          "body": null,
          "is_bot": false,
          "headline": "fix(transport): derive per-request context in HTTP handlers (#194)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b24ebb00efd4d556a310236a7631483c1c9d5408",
          "body": "…ication routing",
          "is_bot": false,
          "headline": "chore(release): 0.9.20 — query-string redaction, lint fix, HTTP notif…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "908cadf8a147f5a11c86abdf7134a1d3befb71cd",
          "body": "…anvas, design-mcp-server",
          "is_bot": false,
          "headline": "docs(skills): add MCP-side list-filtering guidance to add-tool, api-c…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "664e10f2bbd43d26535f305162b92940abc5fbde",
          "body": "…135)",
          "is_bot": false,
          "headline": "fix: route list-changed notifications via request scope under HTTP (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4ab379de4de2acfe1c4d30c4fd417f60afcce41",
          "body": "…ns (#191)",
          "is_bot": false,
          "headline": "fix(linter): scope error-contract rules to throw sites, not compariso…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:41:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3109bb5993ff1eb7d7627b4814bf086a4e7ff577",
          "body": "… and logs (#190)",
          "is_bot": false,
          "headline": "fix(security): redact query-string secrets in fetchWithTimeout errors…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:41:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f72213a81ba556d899d3ab112c99a537028ecad",
          "body": "…orkflow gate markers\n\nAdds scripts/release-github.ts (bun run release:github): reads package.json version, derives tag subject, runs gh release create with --verify-tag --notes-from-tag --title 'v<VERSION>: <subject>', attaches dist/*.mcpb when manifest.json exists, and handles the release-already-\n[…]\ny fail-fast on data.retryable === false (#174), ctx.fail auto-populates data.retryable from contract entry, Gate after column in workflow phase tables (#183), MirrorService design-mcp-server guidance.",
          "is_bot": false,
          "headline": "feat(scripts): 0.9.19 — release:github script, withRetry fail-fast, w…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:07:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa7601461e0ea4543c0b5fe8db5c5c8970a61b54",
          "body": "New bullet in the output-design section of design-mcp-server/SKILL.md: when to mirror a bulk upstream instead of paginating it live, with corpus-size thresholds (in-memory / MirrorService / external store) and a pointer to api-mirror.",
          "is_bot": false,
          "headline": "docs(design-mcp-server): add MirrorService bulk-upstream design guidance",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:07:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f625b576d2d0f79cd41dfabadb141559548fbf3",
          "body": "Every phase row in skills/orchestrations/workflows/*.md now has a Gate after column: barrier (with a terse reason) or gate-free. The orchestrator can derive spawn/round structure directly from the table without re-deriving the barrier positions each run.\n\nskills/orchestrations/SKILL.md adds a one-line pointer tying the new column back to the 'Barriers only where gates sit' principle.",
          "is_bot": false,
          "headline": "feat(orchestrations): Gate after column in workflow phase tables (#183)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:06:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f825f53b7b2f58d39bea80315c3b1a54c88a77b7",
          "body": "defaultIsTransient now checks error.data.retryable === false and returns non-transient immediately, even when the error code is in the transient set (Timeout, ServiceUnavailable, RateLimited). This closes the gap for deterministic upstream failures surfaced as HTTP 200 with an error body — they no l\n[…]\ncontract entry's retryable field as a base default. Caller-supplied data.retryable overrides per-occurrence; reason is always forced last. Contract entries that omit retryable inject no key onto data.",
          "is_bot": false,
          "headline": "feat(utils): withRetry fail-fast on data.retryable === false (#174)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:06:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a458781a006bf8d1909704cd504740c46fc972b9",
          "body": "… gate (#123)",
          "is_bot": false,
          "headline": "feat(devcheck): 0.9.18 — skill-version gate (#99), open-indexed-named…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T10:17:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72ec04223613586ac432f68c99947a6075725538",
          "body": "…e3 peer dep\n\nNew Tier 3 primitive: `defineMirror()` + `sqliteMirrorStore()` under\n`@cyanheads/mcp-ts-core/mirror`. Provides the source-agnostic machinery\nfor a persistent, self-refreshing local mirror of a bulk upstream dataset\n(embedded SQLite + FTS5): cross-runtime store, volatile cursor / durabl\n[…]\npply only the ingester (sync generator) and schema. Node/Bun only;\n`bun:sqlite` built-in on Bun, `better-sqlite3` optional peer on Node.\n\n`@cloudflare/workers-types` 4.20260530.1 → 4.20260531.1 (dev).",
          "is_bot": false,
          "headline": "feat(services): 0.9.17 — MirrorService, /mirror subpath, better-sqlit…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T05:41:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52a7122c5ba6def233f6e71900537e886a9d9c09",
          "body": "The httpError test built a Response with status 204 and an empty-string body; 204 is a null-body status that rejects any body, so the suite failed under current runtimes. Default the helper body to null.\n\nAdd behavior coverage for untested paths: a new resource-rules suite, landing-rules validation \n[…]\nraversal, sanitization security edge cases, scheduler lifecycle (listJobs/destroyAll/not-found), error factories, tokenCounter, and JSON/YAML error truncation. Branches 83.0% to 83.9%; no src changes.",
          "is_bot": false,
          "headline": "test: fix null-body httpError helper, expand suite coverage",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-30T14:16:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6002abf68947d859e1523e607fae3f6084e416bf",
          "body": "…tools\n\nenrichmentTrailer.render was an arrow property, so its parameter was\nvariance-strict under strictFunctionTypes — a concrete tool's narrow\nrender value no longer assigned to the type-erased AnyToolDefinition,\nbreaking createApp({ tools }) typecheck for every tool declaring an\nenrichment block (even with no trailer literal). Switch to method\nsyntax for bivariant params, matching format and handler.\n\nType-only; no runtime change. (#180)",
          "is_bot": false,
          "headline": "fix: 0.9.16 — restore AnyToolDefinition assignability for enrichment …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-30T03:27:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 33,
      "commits_last_year": 1289,
      "latest_release_at": "2026-07-19T12:24:31Z",
      "latest_release_tag": "v0.10.15",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 34,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 4.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@cyanheads/mcp-ts-core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "agent",
            "agent-native",
            "ai",
            "ai-agent",
            "bun",
            "cloudflare-workers",
            "declarative",
            "framework",
            "mcp",
            "mcp-server",
            "mcp-framework",
            "model-context-protocol",
            "observability",
            "opentelemetry",
            "tools",
            "typescript"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
          "is_deprecated": false,
          "latest_version": "0.10.15",
          "repository_url": "https://github.com/cyanheads/mcp-ts-core",
          "versions_count": 142,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 44618,
          "first_published_at": "2026-03-12T12:17:08.098000Z",
          "latest_published_at": "2026-07-19T12:24:09.144000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 29,
      "stars": 147,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2025-04-01",
            "count": 1
          },
          {
            "date": "2025-04-27",
            "count": 1
          },
          {
            "date": "2025-05-12",
            "count": 1
          },
          {
            "date": "2025-05-14",
            "count": 2
          },
          {
            "date": "2025-05-17",
            "count": 1
          },
          {
            "date": "2025-07-09",
            "count": 1
          },
          {
            "date": "2025-07-23",
            "count": 1
          },
          {
            "date": "2025-09-03",
            "count": 1
          },
          {
            "date": "2025-10-02",
            "count": 1
          },
          {
            "date": "2025-10-14",
            "count": 1
          },
          {
            "date": "2025-10-16",
            "count": 1
          },
          {
            "date": "2025-10-30",
            "count": 1
          },
          {
            "date": "2025-11-17",
            "count": 1
          },
          {
            "date": "2025-12-04",
            "count": 1
          },
          {
            "date": "2025-12-24",
            "count": 1
          },
          {
            "date": "2026-01-02",
            "count": 1
          },
          {
            "date": "2026-01-04",
            "count": 1
          },
          {
            "date": "2026-01-14",
            "count": 1
          },
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 2
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-28",
            "count": 1
          },
          {
            "date": "2026-07-03",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 29,
        "total_forks": 29
      },
      "star_history": null,
      "open_issues_and_prs": 59
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 54037,
      "source_files_sampled": 445,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "templates/AGENTS.md",
        "templates/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 39823
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "templates/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 115,
        "malicious_count": 0,
        "assessed_package": "npm:@cyanheads/mcp-ts-core@0.10.15",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@hono/mcp",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.1"
        },
        {
          "name": "@hono/node-server",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.10"
        },
        {
          "name": "@modelcontextprotocol/ext-apps",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.7.4"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@opentelemetry/api",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.9.1"
        },
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "hono",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.30"
        },
        {
          "name": "jose",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.3"
        },
        {
          "name": "pino",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.3.1"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "@cyanheads/mcp-ts-core",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "^{{FRAMEWORK_VERSION}}"
        },
        {
          "name": "pino-pretty",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.1.3"
        },
        {
          "name": "zod",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "{{ZOD_VERSION}}"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@cyanheads/mcp-ts-core",
            "direct": true,
            "version": "^{{FRAMEWORK_VERSION}}",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/mcp",
            "direct": true,
            "version": "^0.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": true,
            "version": "^2.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/ext-apps",
            "direct": true,
            "version": "^1.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "^1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api",
            "direct": true,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "^17.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": true,
            "version": "^4.12.30",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": true,
            "version": "^6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "pino",
            "direct": true,
            "version": "^10.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pino-pretty",
            "direct": true,
            "version": "^13.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "^4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "{{ZOD_VERSION}}",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/biome",
            "direct": false,
            "version": "2.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "@cloudflare/vitest-pool-workers",
            "direct": false,
            "version": "^0.18.4",
            "ecosystem": "npm"
          },
          {
            "name": "@cloudflare/workers-types",
            "direct": false,
            "version": "5.20260706.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-api",
            "direct": false,
            "version": "^1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/otel",
            "direct": false,
            "version": "^1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-metrics-otlp-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-pino",
            "direct": false,
            "version": "^0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resources",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-metrics",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-node",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-trace-node",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": false,
            "version": "^1.43.0",
            "ecosystem": "npm"
          },
          {
            "name": "@socketsecurity/bun-security-scanner",
            "direct": false,
            "version": "^1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/supabase-js",
            "direct": false,
            "version": "^2.110.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/bun",
            "direct": false,
            "version": "^1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/papaparse",
            "direct": false,
            "version": "^5.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/sanitize-html",
            "direct": false,
            "version": "^2.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/validator",
            "direct": false,
            "version": "^13.15.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-istanbul",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/ui",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "better-sqlite3",
            "direct": false,
            "version": "^12.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "bun-types",
            "direct": false,
            "version": "^1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "chrono-node",
            "direct": false,
            "version": "^2.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "clipboardy",
            "direct": false,
            "version": "^5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "defuddle",
            "direct": false,
            "version": "^0.19.1",
            "ecosystem": "npm"
          },
          {
            "name": "depcheck",
            "direct": false,
            "version": "^1.4.7",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "^9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "^4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-parser",
            "direct": false,
            "version": "^5.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "^7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "^7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "^5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "linkedom",
            "direct": false,
            "version": "^0.18.13",
            "ecosystem": "npm"
          },
          {
            "name": "node-cron",
            "direct": false,
            "version": "^4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "openai",
            "direct": false,
            "version": "^6.46.0",
            "ecosystem": "npm"
          },
          {
            "name": "papaparse",
            "direct": false,
            "version": "^5.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "partial-json",
            "direct": false,
            "version": "^0.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "pdf-lib",
            "direct": false,
            "version": "^1.17.1",
            "ecosystem": "npm"
          },
          {
            "name": "repomix",
            "direct": false,
            "version": "^1.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "sanitize-html",
            "direct": false,
            "version": "^2.17.6",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "^1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "typedoc",
            "direct": false,
            "version": "^0.28.20",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "unpdf",
            "direct": false,
            "version": "^1.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "validator",
            "direct": false,
            "version": "^13.15.35",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "8.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.9",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 66,
        "direct_count": 13,
        "indirect_count": 53
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 13,
        "open_issues": 59,
        "closed_ratio": 0.768,
        "closed_issues": 195,
        "closed_unmerged_prs": 13
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "cyanheads",
          "commits": 1544,
          "avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4"
        },
        {
          "type": "User",
          "login": "caseybreen",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/26234849?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.995
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
        "ran_at": "2026-07-25T09:49:09Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T12:23:34Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-05-23T02:12:04Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 66,
          "created_at": "2026-04-24T21:00:39Z",
          "last_comment_at": "2026-05-22T00:35:02Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 75,
          "created_at": "2026-04-28T04:08:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 77,
          "created_at": "2026-04-28T23:53:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 78,
          "created_at": "2026-04-28T23:53:33Z",
          "last_comment_at": "2026-06-07T18:16:07Z",
          "last_comment_author": "xlyoung"
        },
        {
          "number": 79,
          "created_at": "2026-04-28T23:53:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 94,
          "created_at": "2026-05-01T23:25:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 106,
          "created_at": "2026-05-03T07:02:02Z",
          "last_comment_at": "2026-05-03T08:11:29Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 107,
          "created_at": "2026-05-03T07:39:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 110,
          "created_at": "2026-05-03T22:45:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 139,
          "created_at": "2026-05-17T18:23:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 142,
          "created_at": "2026-05-21T15:01:15Z",
          "last_comment_at": "2026-06-11T22:37:44Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 151,
          "created_at": "2026-05-23T16:12:48Z",
          "last_comment_at": "2026-06-02T10:26:46Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 152,
          "created_at": "2026-05-23T18:12:07Z",
          "last_comment_at": "2026-05-23T18:18:18Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 162,
          "created_at": "2026-05-28T09:05:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 163,
          "created_at": "2026-05-28T10:14:45Z",
          "last_comment_at": "2026-05-28T12:41:51Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 164,
          "created_at": "2026-05-28T23:27:45Z",
          "last_comment_at": "2026-05-31T05:42:50Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 187,
          "created_at": "2026-06-01T06:12:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 188,
          "created_at": "2026-06-01T06:13:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 193,
          "created_at": "2026-06-02T03:33:33Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 196,
          "created_at": "2026-06-02T10:26:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/cyanheads/mcp-ts-core",
    "host": "github.com",
    "name": "mcp-ts-core",
    "owner": "cyanheads"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 47,
        "vitality": 93,
        "community": 56,
        "governance": 55,
        "engineering": 70
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 93,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "commits_last_year": 1289,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 34
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "34/52 weeks with commits",
                "points": 23.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 34
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1289 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1289
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 33,
              "latest_release_tag": "v0.10.15",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 4.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "33 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 33
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 5,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 5 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 56,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "forks": 29,
              "stars": 147,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "147 stars",
                "points": 35.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 147
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "29 forks",
                "points": 12.1,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 78,
            "inputs": {
              "packages": [
                "@cyanheads/mcp-ts-core"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 44618
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "44,618 downloads/month across npm",
                "points": 62,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 44618,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.995
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "merged_prs": 13,
              "open_issues": 59,
              "closed_issues": 195,
              "issue_closed_ratio": 0.768,
              "closed_unmerged_prs": 13
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "77% of issues closed",
                "points": 35.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 77
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "13/26 decided PRs merged",
                "points": 19.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 13,
                      "decided": 26
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "followers": 175,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "cyanheads",
              "public_repos": 146,
              "account_age_days": 4225
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "175 followers of cyanheads",
                "points": 16.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 175,
                      "login": "cyanheads"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "146 public repos, account ~11 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 146
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@cyanheads/mcp-ts-core"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "142 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 142
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "mcp",
                "mcp-server",
                "model-context-protocol",
                "ai",
                "opentelemetry",
                "cloudflare-workers",
                "agent-native",
                "framework",
                "typescript",
                "cyanheads"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 47,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@cyanheads/mcp-ts-core@0.10.15 runtime dependency closure — what installing the published package pulls in — 115 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@cyanheads/mcp-ts-core@0.10.15",
                  "assessed": 115
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 115,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 115,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "templates/AGENTS.md",
                "templates/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 39823
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 54037,
              "source_files_sampled": 445,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/445 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 445,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package '{{PACKAGE_NAME}}' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T09:49:14.556607Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cyanheads/mcp-ts-core.svg",
  "full_name": "cyanheads/mcp-ts-core",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.