原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 504,
"has_wiki": false,
"homepage": null,
"languages": {
"Go": 656908,
"CSS": 3884,
"Vue": 9269,
"HTML": 310,
"Shell": 1467,
"JavaScript": 3381
},
"pushed_at": "2026-07-21T15:52:16Z",
"created_at": "2026-06-22T19:01:50Z",
"owner_type": "User",
"updated_at": "2026-07-21T15:57:41Z",
"description": "Multi-provider agent harness / personal+business assistant in Go (pluggable identities, skills, sub-agents; HTTP API; Telegram + Vue web clients)",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "http://basecode.al",
"name": "Flakerim Ismani",
"type": "User",
"login": "flakerimi",
"company": "basecode LLC.",
"location": "Tirane, Albania",
"followers": 37,
"avatar_url": "https://avatars.githubusercontent.com/u/871482?v=4",
"created_at": "2011-06-23T18:19:21Z",
"is_verified": null,
"public_repos": 108,
"account_age_days": 5514
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-07-03T19:00:12Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-07-03T18:38:03Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-07-03T13:04:26Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-07-03T10:47:06Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-07-03T10:21:24Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-07-03T09:40:50Z"
},
{
"tag": "v0.5.3",
"kind": "patch",
"published_at": "2026-07-03T08:11:48Z"
},
{
"tag": "v0.5.2",
"kind": "patch",
"published_at": "2026-07-02T23:16:29Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2026-07-02T23:03:59Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-07-02T22:55:58Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2026-07-02T22:47:19Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-07-02T21:41:00Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-07-02T21:33:40Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-07-02T21:11:10Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-07-02T20:47:18Z"
}
],
"recent_commits": [
{
"oid": "c570fa86469f9be037794922bd291a6fc0cbc2f1",
"body": "…profile dir, not the public repo",
"is_bot": false,
"headline": "skills: omnius moves home — a personal skill lives in its identity's …",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-21T15:52:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf92bb3a2aec2f11b8a525e51172097400961651",
"body": "…s, generic integrations row, ignore *.p8",
"is_bot": false,
"headline": "oss: scrub personal branding — neutral launchd label, example fixture…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-21T15:52:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1360754a92f646fe91a144dda1b7ddc646bb99f7",
"body": "…register like providers, plugins stay the fallback",
"is_bot": false,
"headline": "channel: deliver kinds become a registry — telegram/webhook/apns/app …",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-21T15:52:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "307eab165cefee555a69042596baa371cd8a6dd9",
"body": "…r budget away; classify gets 64 tokens",
"is_bot": false,
"headline": "router: kimi fast tier is moonshot-v1-32k — k2.5 thinks its classifie…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-20T14:18:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76c79b7719c36cfea29a16b61a1dacbbec43cd37",
"body": "…es each turn, profile tier is the fallback",
"is_bot": false,
"headline": "routing: profiles no longer smother classification — the API classifi…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-20T14:15:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1334cf090d5936d93291e7263a0af45d63a7b8ee",
"body": "…pp's home screen",
"is_bot": false,
"headline": "server: GET /v1/schedules — the proactive clock, read-only, for the a…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-20T14:10:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4bcc3b3b8e1397b4bbc1fa9d0a4a9e41666dd00e",
"body": "…ted; DELETE endpoint\n\nThe list loads every session anyway, so each meta now carries the opening\nuser message as its title (the Claude-app convention), the newest text as\na preview, and the file mtime; the endpoint sorts newest-first. DELETE\n/v1/sessions/{id} backs swipe-to-delete.",
"is_bot": false,
"headline": "sessions: list metadata for a conversations UI — title, preview, upda…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-12T02:48:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e19ebce325d29551bc7c62ecdf34a41e50870d57",
"body": "…HTTP\n\nNew inbox package: per-identity deliveries.json (capped, read-state).\nDeliver kind app:<profile> persists to the feed then announces with a\nbest-effort push banner — the record outlives the notification, which is\nwhat lets the app replace a chat channel as the archive. Server gains\nGET /v1/deliveries, POST /v1/deliveries/read, and POST /v1/feedback\n(corrections → durable lessons, the loop the Telegram buttons ran).\nApp-queued background tasks deliver to app:<profile>.",
"is_bot": false,
"headline": "inbox: the app becomes home — durable deliveries, feedback loop over …",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-12T00:11:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b09f8efd819436c8590e36f947b0ec9c6bbcdbd",
"body": "…o the app\n\nGET /v1/connectors reports each integration's live status; POST\n/v1/connectors/google/connect mints a consent URL bound to the profile's\ncredential store using the same remote OAuth flow the chat surfaces use.\nThe app's Settings page replaces the /integration slash command.",
"is_bot": false,
"headline": "server: /v1/connectors + google connect-start — integrations move int…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T19:35:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0053e15c6e64f7e9b865c905c5ecd88e6bfe256",
"body": null,
"is_bot": false,
"headline": "gofmt",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T19:25:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "319d4c7d18b52f07a485719734300084e0ef8534",
"body": "POST to the Calendar v3 events endpoint; RFC3339-with-offset for timed\nevents, bare dates for all-day. Scope calendar.events joins the default\nset — accounts connected before it must reconnect, and the tool says so\nin its own error guidance.",
"is_bot": false,
"headline": "google: calendar_create_event — Donna shapes the day, not just reads it",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T19:23:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0639d0fc4b125f20946a3783de2c2d96136786eb",
"body": "… override\n\n'telegram:123|push:personal' reaches phone banner and chat archive both;\neach target is attempted, first error reported. schedule_add accepts an\noptional deliver field so an identity can retarget its own routines\ninstead of being bound to the asking surface forever.",
"is_bot": false,
"headline": "deliver: multiple |-separated targets; schedule_add: explicit deliver…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T19:11:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c675b7b91c15a64fe03746819b1223d189dc2a6f",
"body": "channel/apns: stdlib-only APNs client (ES256 provider JWT from the .p8,\nHTTP/2 to api.push.apple.com) plus a per-identity device-token store.\nPOST /v1/push/register binds an app install to an identity; deliver kind\npush:<profile> alerts every registered device and prunes tokens APNs\nreports dead. Unconfigured (no APNS_* env) stays a clean error, not a\nsilent drop.",
"is_bot": false,
"headline": "push: APNs delivery channel — the app becomes a deliver target",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T19:02:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "79cf3ffb315527d975ff12acc3cad572d0d8c0bd",
"body": "The daemon's -bash flag only reached the API surface — chat, scheduler,\nand task worker never saw it. HARNESS_BASH=1 enables the tool in\napp.Build for every surface at once (trusted deployments only; bash is\nunsandboxed in the daemon's container). The omnius skill documents the\nverified read endpoints of api.omnius.lol for curl+jq use and forbids\nunprompted mutations/admin calls.",
"is_bot": false,
"headline": "bash fleet-wide via HARNESS_BASH=1; skills: omnius",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T18:48:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7742e4ecdfad6086dc86a395550c89929a20c11",
"body": "The model has no clock — Donna dated a ledger entry six days into the\npast because 'today' was a guess. Day-granular stamp keeps prompt-cache\ninvalidation to once per day. The accountant skill records receipts\n(photo or typed) into workspace:accounting/ledger-<year>.csv and answers\nspending questions by re-reading the ledger, never from recollection.",
"is_bot": false,
"headline": "app: stamp today's date into the system prompt; skills: accountant",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T18:29:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3a4a31002232fd2f7a4a41da38e80ca01fe05b8",
"body": "chatRequest gains images[] (base64 + media_type, 5 MB cap, validated to\nclean 400s before the SSE stream opens); the turn drives ContinueWith so\nvision-capable models see the photo and blind ones get the placeholder.",
"is_bot": false,
"headline": "server: /v1/chat accepts images — photos ride the API, not just telegram",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T17:30:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9711065eb390b9bb0e1c2086ae70c8b4a05456d",
"body": "Red-square test against the live APIs (2026-07-11): moonshot k2.5/k2.6 and\nfireworks k2p6 all read the image; fireworks k2p5 500s on image input and\ndeepseek v4 rejects image parts outright, so both stay unlisted — blind\ndegrades to a placeholder, a wrong claim degrades to an API error.",
"is_bot": false,
"headline": "vision: kimi k2.5/k2.6 and fireworks kimi-k2p6 verified image-capable",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T15:56:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0985181958c970844e6e2600374ef437f2cf3b4f",
"body": "Extracted from the user's own working pattern: restate claims as numbers,\nre-derive from raw inputs, hunt the fatal constraint first, steelman then\nattack, deliver kill/proceed verdict before the analysis.",
"is_bot": false,
"headline": "skills: sanity-check — verdict-first stress-test for ideas and numbers",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T15:56:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84942a07c56ccfbea1751f45b28af8b1af80287e",
"body": "The neutral seam gains BlockImage + CapVision; adapters encode images\n(anthropic base64 source, openai data-url parts) and degrade them to an\nexplicit placeholder on blind models instead of a 400 or silence. The\nvision flag is reconciled per request against the model routing actually\npicked, not fro\n[…]\ns and image files\n(largest rendition, caption as text) and drives them through the new\nContinueWith; oversized files get a friendly refusal, failed downloads\nan apology instead of the old silent drop.",
"is_bot": false,
"headline": "vision: images flow end-to-end — telegram photos reach the model",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-11T10:10:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3cad1cb86dda6c82a82e9a7b12aa5add684fcdde",
"body": "doctor was the only package without tests, and couldn't have had them: doProbe\nbuilt its own http.Client and Run hardcoded api.telegram.org, so exercising Run\nwould have hit the real network — against the suite's no-network rule.\n\nHoist the client and the Telegram base into package vars (providerBas\n[…]\nmErr keeps the last clause and truncates at\n80, Run skips keyless providers and trims the public URL's trailing slash, and\nthe tool stays read-only, announcing PROBLEMS FOUND only when a wire is down.",
"is_bot": false,
"headline": "doctor: tests, and the seam that makes them possible",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-09T18:04:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5885abf39209a211ae69fec2fecd75c30b5497ba",
"body": "Tonight's outage: the container's outbound NAT wedged — inbound health checks\nkept passing while the Telegram poller and every model call hung, and a human\nhad to notice and restart. Three answers:\n\n- egress watchdog (daemon): probes an outbound URL every 90s; 3 consecutive\n failures flip /healthz \n[…]\nstory.\n It caught two real bugs on its first run, fixed here: empty-name tool calls\n were persisted at accumulation (poison at the source), and an empty model\n reply returned silence with no error.",
"is_bot": false,
"headline": "production hardening: egress watchdog, harness doctor, chaos suite",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T19:00:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d0ceedb2a0d1e3b43acf73fc952a6575575f7adf",
"body": "A DeepSeek timeout killed a background task permanently and would have made\nchat apologize — with five other vendors' keys sitting configured. Now:\n\n- task queue: transient failures (network, TLS, 429/5xx) re-queue with\n backoff (NotBefore) up to 3 attempts; the user only hears about the last\n- HAR\n[…]\ns\n every provider's own model, so no ids cross vendors\n- telegram chat + scheduled runs (pulse, briefs, watches): one transparent\n retry on the first fallback instead of an apology or a skipped beat",
"is_bot": false,
"headline": "resilience: retry transient failures, fail over across providers",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T18:37:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d1d094f46ff3aa64de35a54f4c0c69276f545bb3",
"body": "…il_get_attachment\n\n'Text only' left attachments invisible: the part walker ignored anything with\na filename. Now gmail_get_message lists attachments (name, type, size, id) and\ngmail_get_attachment fetches one — text-like files return inline (capped),\nbinaries land in the workspace under attachments/ for downstream tools (e.g.\na pdftotext exec plugin) to read. Parts learn filename/size/attachmentId.",
"is_bot": false,
"headline": "google: email attachments — list in gmail_get_message, fetch with gma…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T13:04:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8e5563ea4c16a0386a9ec3ec8e66987d26965d6c",
"body": null,
"is_bot": false,
"headline": "google test: 7 tools after login (gmail_mark_read joined)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T12:56:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6401dced0bf626befdac36c1a69e3e1f8216f78d",
"body": "Triage without cleanup is half a job: the assistant could read and report a\nmessage but not mark it read (or archive it), so the same unread mail kept\nresurfacing. gmail_mark_read removes UNREAD (optionally INBOX) via\nmessages/modify; needs the new gmail.modify scope, so previously connected\naccounts must reconnect (/integration google) to grant it.",
"is_bot": false,
"headline": "google: gmail_mark_read tool + gmail.modify scope",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T12:53:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0a253c025ddc20f8635a9ae93d9bbb56dd22c3fb",
"body": "Empty-output-means-no-delivery relied on models emitting literally nothing,\nwhich they hate: the 10-minute inbox watch spammed '*Nothing that needs you.*'\nevery cycle. Scheduled runs now treat a bare silence sentinel (NOTHING /\nSILENCE, markdown-wrapped or not) as no-op; the pulse skill/prompt and the\nschedule_add tool teach the convention. Real messages that merely start with\n'Nothing' still deliver.",
"is_bot": false,
"headline": "schedule: silence sentinel — watch runs can actually shut up",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T11:27:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e71ffea1646655ee2e1cd1d0769ceeadcac38952",
"body": "…ove tools\n\n'Brief me at 7 every day' required a human at a terminal: the agent could\nqueue one-shot background work but couldn't touch recurring schedules — it\ncouldn't even see them, so it proposed duplicating ones that already existed.\nNow schedule_add / schedule_list / schedule_remove are identity-scoped tools\n(own tasks only; deliver defaults to the surface's reply target; add/remove\nare gated writes), registered like the task tools whenever a profile is set.",
"is_bot": false,
"headline": "schedule: the identity manages its own duties — schedule_add/list/rem…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T10:47:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "709e74bcd091322e04336de0ec139ab2a27634f7",
"body": "Telegram's in-app browser has no Google session (and Google can refuse OAuth\nin embedded browsers), stranding the connect flow. The message now carries the\ncopyable link + the open-in-browser tip alongside the button.",
"is_bot": false,
"headline": "telegram: include the raw consent link under the connect button",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T10:23:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "934296e05376d8c473f2fedd7282a5cc9f505461",
"body": "Bare /integration now sends an inline-button menu of connectable services;\ntapping one swaps the menu message for the live connect button (URL buttons\ncan't be minted lazily, so the callback edits in a fresh consent link).\nShared googleConnectButton serves both the direct command and the menu tap.",
"is_bot": false,
"headline": "telegram: /integration shows a tappable menu",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T10:21:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f50d2f6b52aabf66bbf26c27a6e5238b8ed10fae",
"body": "The loopback connect flow needs a browser on the machine running harness —\nuseless for a daemon on a server and a user on a phone. Now: auth.GoogleRemote\nmints consent links (PKCE + one-time state bound to the identity's credential\nstore), the daemon serves the public /oauth/google/callback that exc\n[…]\nchat that started it gets a confirmation when the\ncallback lands. Needs a Web OAuth client (GOOGLE_CLIENT_ID/SECRET) with the\ncallback registered, plus HARNESS_PUBLIC_URL. Telegram buttons learn url:.",
"is_bot": false,
"headline": "connect: remote Google OAuth — /integration google from any chat",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T09:40:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8744f266633b1242335fa07be4b15147ea457a12",
"body": "A report-writing turn died repeatedly: the model streamed a big write_file\ncall, the output-token limit cut the arguments mid-JSON, the input parsed to\nnil, and the loop treated max_tokens as a final answer — leaving dangling\nhalf-calls and a user hearing 'my writes keep getting interrupted'. Now:\n\n\n[…]\nections\n- publish skill teaches section-writing for big pages\n- working surfaces raise MaxTokens 4096 → 8192\n- deliveries log proof (chars + target) so a sent-but-vanished message is\n never a mystery",
"is_bot": false,
"headline": "agent+tool: survive output-token truncation of tool calls",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-03T08:11:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "169d2ec8586e886833a6b74b10325706c59086a6",
"body": "… wedge a session\n\nA live session froze permanently: an assistant message carrying a malformed\ntool call (empty name) got persisted, and every subsequent request replayed it\nto the provider, which rejected the whole conversation. RepairHistory now runs\non any history entering Continue: it drops unreplayable tool_use blocks (and\nmessages left empty), and closes dangling tool calls (a turn clipped by a\nrestart) with synthetic error results so pairing always holds.",
"is_bot": false,
"headline": "agent: repair persisted histories before replay — one bad block can't…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T23:16:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f519051c4ac9fedbcee907e5d0a67d58b96272ee",
"body": "'agent: exceeded 16 turns' threw away everything a deep-research request had\ngathered. Now exhausting the budget triggers one final no-tools turn: the\nmodel is told the budget is spent and answers with what it has, noting what's\nunfinished — a degraded answer instead of no answer. Spec.MaxTurns plumbs the\nbudget per surface: telegram/API/scheduled runs get 40, background tasks 48\n(that's the place for deep work), CLI keeps the default 16.",
"is_bot": false,
"headline": "agent: wrap up at the turn budget instead of erroring away the work",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T23:03:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1b81abede82d81ecbfcc429b8f83a4d702f5676e",
"body": "Server.Public serves a directory at the server root (unauthenticated,\nhttp.Dir-confined); the cmd layer points it at the default identity's\nworkspace/pub. The assistant publishes by writing a file: write_file\npub/reports/foo.html → live at https://<host>/reports/foo.html — a link and a\nsummary in ch\n[…]\ntead of a wall of text. Ships a publish skill encoding the\nhabit (standalone styled HTML, public-internet warning, link + takeaways).\nUnmatched non-/ paths now 404 instead of echoing the service card.",
"is_bot": false,
"headline": "server: publish pages — workspace pub/ served at the root",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T22:55:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dfba63269c86fe5b2f039a935ca3feb981c39808",
"body": "Telegram rejects sendMessage over 4096 UTF-16 units with 400 'message is too\nlong', which silently ate long task deliveries (a 13k-char research result\nnever reached the user). sendMessage now splits into ≤4000-unit chunks,\nbreaking at line boundaries (then spaces), emoji counted as two units; the\ninline keyboard rides the last chunk. Covers chat replies, pulses, and\nbackground-task deliveries alike.",
"is_bot": false,
"headline": "telegram: chunk long messages — never drop a delivery",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T22:47:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8d8452c998af8d74e0d7b04b720848ffac2b7c10",
"body": "…w the user\n\nThe personal persona no longer just 'remembers what matters' when told: it\nquietly notices durable things during normal conversation (routines,\npreferences, people, style — tagged saves) and uses them to anticipate. Felt\nknown, not watched: it never recites the file back.",
"is_bot": false,
"headline": "profile: ambient learning — the identity makes it its business to kno…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:48:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ed4172f090870b8fd3da9302885ef8c85c772e48",
"body": "The identity's heartbeat: 'harness pulse -deliver telegram:<id>' installs a\nper-identity scheduled check-in (stable id, idempotent re-install, -off to\nstop). On each beat it looks around its own house — task_status (new tool: the\nagent can finally see its own background queue), calendar, one resurfa\n[…]\n so; NOTHING if not: an empty reply skips delivery, so silence is\nthe default, not a failure. The pulse skill defines the look-around procedure\nand can be refined by the identity like any other skill.",
"is_bot": false,
"headline": "pulse: presence, not just availability",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:40:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "82ce3cbe875cca250add4339364781435077e323",
"body": null,
"is_bot": false,
"headline": "docs: web README — tasks panel",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:33:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "22ea0b2dbc94f3bb0df3261f6144ec9ca1a78e0e",
"body": "Four seams (native connector / MCP / exec plugin / deliver target), the rule\nfor picking one (prefer the dumbest route that works), what's shipped, and\nthe planned candidates across channels, suites, dev tools, media, and infra.\nGround rules: writes declare themselves, per-identity scoping is the security\nmodel, everything testable offline.",
"is_bot": false,
"headline": "docs: INTEGRATIONS.md — the integration map and decision rule",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:32:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb5d32411807ae780b2c811da26b2652de6f7047",
"body": "GET/POST /v1/tasks and GET /v1/tasks/{id} on the API (injected task.Store,\nnil disables the routes; empty profile falls back to the server default), and\na Tasks panel in the Vue client — queue work for the current identity, watch\nstatuses update live (5s poll while open), expand a job to read its result.",
"is_bot": false,
"headline": "server+web: surface the background-task queue",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:31:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18fec174c23392d22bfba30370f061285be6e9c3",
"body": "Any executable dropped in plugins/ (project-local, per-identity, or shared)\nthat answers three verbs over stdio becomes an integration:\n\n <exe> spec → JSON manifest (tools + deliver kinds)\n <exe> run <tool> ← input JSON on stdin → output on stdout\n <exe> deliver <kind>\n[…]\nry is\nbest-effort (a broken plugin warns, never takes the harness down); first dir\nclaiming a name wins. Ships a complete one-file example (plugins.example/dice)\nand a shell-script-fixture test suite.",
"is_bot": false,
"headline": "plugin: exec plugins — the zero-framework extension seam",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:26:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "aaca339953cd5a7e51523d60c71d56157c181d84",
"body": "'webhook:<url>' POSTs the output as JSON with both 'text' (Slack/Mattermost/\nTeams) and 'content' (Discord) keys — each service reads its own and ignores\nthe other, so a single deliver kind covers every incoming-webhook service.\nWorks everywhere Deliver does: schedules, one-shot wake-ups, background tasks.",
"is_bot": false,
"headline": "deliver: webhook kind — one target for Slack, Discord, Mattermost, Teams",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:21:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93709ccc94dd2d6a2378cc6a2f56142d03475f2c",
"body": "True wake-ups: a task that fires once and retires (MarkRan disables it and\nclears NextRun instead of re-arming). 'in 2h' is the 'wake me in two hours'\ntimer; 'once 09:00' the next-occurrence alarm.",
"is_bot": false,
"headline": "schedule: one-shot specs — 'once HH:MM' and 'in <dur>'",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:20:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "406babb6e935929da793a9372bdf6bc4de2d785a",
"body": null,
"is_bot": false,
"headline": "docs: pillars table + status — hands, background work",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:11:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "60146ce56a69e5f3f01fea11f06b0aca69bcd399",
"body": "A shipped senior-engineer identity with real hands: orient from the project's\nown docs, surgical edits, verify with the project's checks before declaring\ndone, remember conventions between sessions, learn skills from worked-out\nprocedures. The dev-loop skill encodes the edit→verify→commit loop. Rooted in\nthis checkout, the harness can work on its own codebase — the dogfood capstone.",
"is_bot": false,
"headline": "profiles: developer identity + dev-loop skill — harness develops harness",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:09:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7153189d3975fbbe5e247e63e25681cd07e5f788",
"body": "Where schedule/ fires on a clock, task/ fires now, off the caller's critical\npath. A persistent JSON queue (profiles base, like schedule) + a daemon worker\nthat drains it sequentially and delivers results over the same channel wire.\n\n- task.Store: Enqueue/List/Get/NextQueued (claims durably)/Complet\n[…]\ne result lands back in that chat\n- harness task add|list|show|drain; daemon gains a task worker\n (-task-interval, -no-tasks); failures are delivered too — the asker is\n never left waiting on silence",
"is_bot": false,
"headline": "task: background work queue — 'do X, report when done'",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:08:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4f3f850bf1c47e0837cbd5afd71e4445d8605900",
"body": "…n gate\n\nThe agent could read, remember, and learn but not produce artifacts. Now:\n\n- write_file / edit_file / list_dir join read_file, all confined by a shared\n resolver; a workspace: path prefix addresses the identity's persistent home\n from any working root, and escape attempts are rejected, no\n[…]\n, chat) confirms writes on the terminal; -yes waives, piped runs\n deny; chat shares one stdin reader between REPL and gate\n- remote surfaces stay ungated — they're sandboxed in the identity workspace",
"is_bot": false,
"headline": "tool: real hands — write_file, edit_file, list_dir behind a permissio…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T21:02:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2230ae2dfa59a64aa981225911ce3126823424cd",
"body": "…files\n\nWorkspaceDir(name) = profiles/<name>/workspace. With no explicit Spec.Root,\napp.Build roots tool.Env in the profile's workspace (created on demand) and\nnotes it in the system prompt, so files persist across sessions and surfaces.\nRemote surfaces (daemon, serve, telegram, schedule, reflect, onboard) switch\nto the auto root — their cwd was meaningless; main and chat keep cwd via\n-root '.'. Env gains a Workspace field and Agent an Env() accessor.",
"is_bot": false,
"headline": "profile: per-identity workspace — the identity's persistent home for …",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T20:53:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac366edc9f62f0f455939df3e99998d50e77e763",
"body": "Now that the repo is public: a lean stdlib-only CI job, go install one-liner\nand badges in the README, and contributor ground rules (no deps, offline\ntests, vendor-neutral above the provider seam).",
"is_bot": false,
"headline": "ci: GitHub Actions (gofmt/build/vet/test) + install docs + CONTRIBUTING",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T20:46:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3881d944c1551f68159c056cad85ae7b1ba4829a",
"body": "- LICENSE: MIT\n- profiles/basecode.md → profiles/business.md, genericized (personal persona\n out of the shipped template; harness onboard generates real ones)\n- telegram: generic bot handle in test, generic /help + command examples\n- README: license section, generic identity examples, full provider list in\n Status, drop stale 'Gmail send next' line (it shipped)\n- remove HANDOFF.md (session-local notes, never belonged in the repo)",
"is_bot": false,
"headline": "prep for open source: MIT license, generic profile, README refresh",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T20:08:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b7084f6cc2a67f252fdde55aec8de04dd80819c5",
"body": "Alongside gmail_create_draft, add gmail_send: posts a Message to\nusers/me/messages/send (goes out immediately). Reuses buildRawMessage, so\nreply threading works via thread_id + in_reply_to. Covered by the existing\ngmail.compose scope (compose = manage drafts AND send), so no re-consent\nbeyond the initial connect. Draft is still the recommended path; the tool's\ndescription tells the model to send only when clearly asked.",
"is_bot": false,
"headline": "google: add gmail_send (direct send)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T00:20:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6dab659d2e980875f8e6b8bda6138b773b2a51d9",
"body": "Telegram HTML has no <table>, so pipe tables came through raw. Detect GFM\ntables (header + dash separator + rows) and render them as a column-aligned\n<pre> block — cells stripped of inline markdown, padded to the widest cell,\nwith a dashed header underline. Fenced code is protected first so code with\npipes isn't misread as a table.",
"is_bot": false,
"headline": "telegram: render markdown tables as aligned monospace blocks",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T00:12:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "742c293b4282f8ad201305961d2e275aa60d5e3f",
"body": "Reasoning models take several seconds; the chat looked dead meanwhile. Add\nSendChatAction and pulse 'typing' every 4s (Telegram clears it after ~5s)\naround the model call, so the bot looks alive until the reply lands.",
"is_bot": false,
"headline": "telegram: show 'typing…' while the model generates",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-02T00:04:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24a974e32bd603fcff04e629b8e864d210a7fd00",
"body": "Buttons under every message was noise. Attach them only when the reply is\n200+ chars, so short acknowledgements and one-liners stay clean while longer\nanswers stay ratable.",
"is_bot": false,
"headline": "telegram: show 👍/👎 only on substantial replies",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T23:56:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3a0422407e397077f6930985356a1ae90fec95ee",
"body": "Replies were sent as plain text, so the model's **bold**, `code`, tables and\nlinks showed up raw. Now the model's markdown is converted to the small HTML\nsubset Telegram renders (bold/italic/code/pre/links/headings/bullets), sent\nwith parse_mode=HTML. Everything else is HTML-escaped, and if Telegram rejects\nthe HTML the send falls back to plain text so a reply is never lost.",
"is_bot": false,
"headline": "telegram: render assistant markdown as HTML",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T23:51:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a619b8a46a2859b804b9f7e3990f8a8d414f7be",
"body": "More OpenAI-compatible providers, endpoints verified against each /models:\n- openrouter (aggregator), mistral, zai (Zhipu GLM) — verified working\n- xai (Grok), together — slugs + standard endpoints (keys need activation)\n- qwen (DashScope): real chat-model tiers (qwen3.7-max / -plus / qwen-flash),\n default qwen-plus — fixes it falling back to 'mock'\nSecrets load from .env (gitignored). mistral-medium-2508 / glm-4.7 defaults.",
"is_bot": false,
"headline": "provider: add OpenRouter, Mistral, Z.ai, xAI, Together; wire Qwen models",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T23:47:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df372b69739682f839c19828a4a52d7de2c85177",
"body": "Pulled the real model ids from each provider's /models endpoint and fixed the\ntables (DefaultModel had no case for fireworks/mimo — they fell back to 'mock').\n\n- deepseek → v4-pro / v4-flash (was deepseek-chat/reasoner, retired)\n- kimi → k2.6 default, k2.5 fast (was moonshot-v1-8k)\n- fireworks → kim\n[…]\n / sonnet-4.6 / haiku-4.5 / fable-5 in the menu\n- apple: on-device Foundation Models via a local OpenAI-compatible bridge\n- qwen: OpenAI-compatible (DashScope); endpoint + key from config, no defaults",
"is_bot": false,
"headline": "provider: refresh model catalogs; add apple + qwen providers",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T23:32:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2963acfe55c132c2786660330cbf989ba1522555",
"body": "Secrets like TELEGRAM_BOT_TOKEN / provider keys / the Google client can now\nlive in ./.env (or <user-config>/harness/.env), loaded before anything reads\nthe environment. Real env vars still win; missing files are fine. Std-lib\nparser handles export/quotes/comments.",
"is_bot": false,
"headline": "config: auto-load .env at startup",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T23:32:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4a75f4704c53ec559414ecabcb7accfff24aea4",
"body": "The third self-improvement loop: a correction the user gives now becomes a\ndurable lesson that shapes future behavior instead of evaporating.\n\n- record_feedback tool saves a lesson (a memory tagged 'lesson').\n- Digest surfaces lessons in their own 'apply these' section above facts, so\n they steer b\n[…]\nction and records the next message as a lesson for that identity.\n\nTogether with the critique and reflection loops, the assistant now improves\nwithin a task, across sessions, and from direct feedback.",
"is_bot": false,
"headline": "memory: feedback-to-lesson loop (record_feedback + Telegram 👍/👎)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T23:32:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "15f4e449097ce4e1143ab06fc2c92569e3a2a394",
"body": "The second self-improvement loop: the identity reviews its own recent\nconversations and distills durable lessons into memory and skills.\n\n- session.Transcript renders a conversation as plain dialogue (tool traffic\n omitted); Store.Recent returns the most-recently-touched non-empty sessions.\n- revie\n[…]\nrofile -provider -deliver -limit] is the entry point;\n because the tool + skill are in every profile run, a scheduled nightly\n task ('reflect on today') works the same way and can -deliver a digest.",
"is_bot": false,
"headline": "session: reflection loop (harness reflect + review_sessions + skill)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T23:04:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72a3e8ba7cf77a053a68bd5719b4cbb77cbf7dad",
"body": "The first of three self-improvement loops. When Options.Critique is set,\na final answer is reviewed by a critic pass (reasoning tier) before it's\nreturned; if the critic finds concrete problems, the loop feeds them back\nand revises once more, bounded by MaxCritique (default 1). Fails open — a\ncritic\n[…]\ntique and an\noptional CritiqueAware handler hook so surfaces can show 'revising…'.\n\nThis is the within-a-task quality loop; the cross-session reflection loop\nand the feedback-to-lesson loop come next.",
"is_bot": false,
"headline": "agent: in-task self-critique loop (opt-in)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T22:59:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ef38f71d7737669a018d745deab34cbe3df61ba6",
"body": "Builds the Morning Chief-of-Staff on the delivery seam from the last change.\n\nGmail draft (the missing write half): gmail_create_draft posts an RFC822\nmessage (base64url) to the drafts API — never sends, so replies wait in\nDrafts for one-tap review. Reply threading works: gmail_get_message now\nsurfa\n[…]\nrnight mail into one\nphone-readable digest, preps external meetings via meeting-prep, and queues\nreply drafts. Run it as a scheduled task with -deliver telegram:<chatID> for\na 7am brief on your phone.",
"is_bot": false,
"headline": "google: Gmail draft tool + chief-of-staff skill",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T22:15:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6f43b69bc84b0f0c1dcf4f90f530127733e48ee7",
"body": "Closes the second-brain loop on top of searchable recall.\n\nCapture: remember now takes optional tags (stored in the note body, so\nthey're searchable via recall with no format change); a capture skill\nteaches the identity to distill forwarded links/notes, dedupe via recall,\nand file them cleanly.\n\nRe\n[…]\n agent.\n\nDelivery: a scheduled Task gains a Deliver target (telegram:<chatID>);\nrunScheduledTask captures the assistant text and pushes it to the channel,\nso a daily resurface run lands on your phone.",
"is_bot": false,
"headline": "memory: capture tags + proactive resurfacing loop",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T22:05:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b24145417649f2b9344422babcbbb12bb0cae08",
"body": "Second-brain retrieval backbone. Memory was dumped whole into the system\nprompt every turn — fine at ten notes, unworkable at hundreds. Now:\n\n- Store.Search ranks memories by keyword overlap (name matches weighted\n higher, light prefix stemming); deterministic and offline, swappable for\n a vector \n[…]\nbounded, back-compat preserved).\n- harness memory search <q> to browse a profile's memory.\n\nFoundation for the capture -> resurface loop; capture ergonomics and a\nproactive resurfacing cron come next.",
"is_bot": false,
"headline": "memory: searchable recall + bounded context digest",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T21:53:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6aee2b67f926a330d2175393413ca3f6340d2192",
"body": null,
"is_bot": false,
"headline": "docs: CLAUDE.md for Claude Code",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T21:05:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5d57c4f107503b605ad2ba4cd7411638064566c9",
"body": "A registry is a git repo of skill folders. skill.Source is the install\nseam; GitSource shallow-clones into <config>/harness/registry/<hash> and\nserves from the checked-out tree (git-independent scan/copy in tree, so it\nunit-tests without git). Install copies a skill folder into a skills dir,\nwhere t\n[…]\nrs it — no agent-loop changes.\n\nCLI: harness skills search <q> / add <name> (-profile, -refresh).\nConfig: skills.registry (git URL) / $HARNESS_SKILLS_REGISTRY.\nPath-traversal skill names are rejected.",
"is_bot": false,
"headline": "skill: git-backed skills registry (search/add)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-07-01T21:05:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bde5ed9564e2729a3038916c6d772af2a9f7d1d2",
"body": "Render assistant replies as markdown via marked + DOMPurify (LLM output is\ninjected with v-html, so sanitizing is mandatory). User messages stay plain\ntext. Add markdown styles (code/pre, lists, links, blockquote, tables).",
"is_bot": false,
"headline": "web: render assistant markdown (sanitized)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-18T13:54:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "44ea2e6c9cf00c333ea17642601462d893151b81",
"body": null,
"is_bot": false,
"headline": "docs: README — Vue web client",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T20:19:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad99f4758797e07bfc18dc3ea5b14f433823ae06",
"body": "A decoupled Vue 3 + Vite single-page app (web/) that talks to the token-gated\n/v1 API: connect with URL + token, pick identity and provider/model, stream\nreplies over SSE, and load session history. Chat is a POST that streams SSE, so\nthe client uses fetch + ReadableStream (EventSource can't POST or set the auth\nheader) and parses frames in src/api.js. Reactive via Vue refs; same server-side\nconversation the CLI/Telegram see. node_modules/dist gitignored.",
"is_bot": false,
"headline": "web: separate Vue 3 SPA client for the API",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T20:19:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "faf45b33f3f09099000ca5d7277295639f21889d",
"body": null,
"is_bot": false,
"headline": "docs: README — harness daemon supervisor",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T20:11:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d2a58847788d8d7336f2c3e56564c2e5c02df62",
"body": "Add 'harness daemon' running the HTTP API, the scheduler, and (optionally) the\nTelegram bot as goroutines under one signal context with graceful shutdown —\nthe durable process to deploy on a VPS instead of three hand-managed ones.\nExtract reusable cores so it composes them without duplication: serve\n[…]\nldAPIServer (serve.go), runScheduler (schedule.go), runTelegramBot\n(telegram.go). -print-launchd emits a macOS launch-agent plist. Verified:\nAPI+scheduler up together, SIGTERM shuts both down cleanly.",
"is_bot": false,
"headline": "daemon: one supervisor process (API + scheduler + channels)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T20:11:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd1d8824db351171ab50072115bddd75b4c89bbe",
"body": null,
"is_bot": false,
"headline": "docs: README — token-gated HTTP API for local/VPS clients",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T19:09:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9dd3ee5ad6c8b11df98d742ecbd11437fa52b104",
"body": "Token auth on all /v1 routes (Bearer header or ?token= for EventSource;\nconstant-time compare), CORS so browser/desktop clients on other origins can\nconnect (safe under token gating), and a graceful OPTIONS preflight. New\nendpoints for clients: GET /v1/profiles, GET /v1/models, GET /v1/sessions/{id}\n[…]\nal provider/model to switch a session's model;\nFactory now takes provider+model. serve auto-generates+persists an API token\n(or -token/$HARNESS_API_TOKEN; -open for localhost dev). Healthz stays open.",
"is_bot": false,
"headline": "server: API hardening for remote/multi-client use",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T19:09:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d0def6b29119b4539d28ac27f700f8366da9ffa2",
"body": null,
"is_bot": false,
"headline": "docs: README — harness onboard",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T16:25:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb63416e235a853b955863e275229927dc58af9a",
"body": "Add a guided setup that turns the generic harness into a business-specific\nassistant: a short interview (business, what it does, role, tone, assistant\nname), then the model drafts a tailored persona (template fallback) and writes\nprofiles/<slug>.md, optionally setting it as the default identity. New onboard\npackage holds the pure pieces (slug, draft prompt, template persona, profile\nassembly); config gains Save + SetDefaultProfile; profile gains UserProfilesDir.",
"is_bot": false,
"headline": "onboard: AI-drafted identity setup (harness onboard)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T16:25:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "851bdb131235b3f77577a50a40b8a318a4ec1c84",
"body": null,
"is_bot": false,
"headline": "docs: README — the four pluggable layers (skills vs specialists)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T13:07:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18b946102553ff3d2032df6015c71609567c5c3b",
"body": "Make sub-agents pluggable like skills: declarative agents/<name>.md specs\n(persona + tier + tool allowlist), loaded shared + per-identity (subagent pkg).\nA generic agent.Dispatch tool routes dispatch(agent, task) to the named\nspecialist — its own persona, tier, and filtered toolset — with the roster\n[…]\nrchestrator's prompt. app.Build wires it; a starter\nresearcher spec ships in agents/. Add 'harness agents' to list the roster.\nSkills = procedures the agent follows; specialists = separate agent runs.",
"is_bot": false,
"headline": "subagent: pluggable specialist sub-agents (dispatch tool)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T13:07:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7d4e4b54f8f2daceb128ba078845171ea162118",
"body": "… cap\n\n- httpDoRetry: exponential backoff with Retry-After on network errors, 429,\n and 5xx; both the Anthropic and OpenAI adapters build a fresh request per\n attempt and retry transient failures instead of failing the turn.\n- Tests for the previously-untested SSE wire parsers (Anthropic + OpenAI)\n[…]\n gives-up-and-reports).\n- capToolResult: bound a single tool result (100k) so a huge file/fetch can't\n blow the context window.\n- Close the last untested packages: app (Build paths) and auth (store).",
"is_bot": false,
"headline": "provider/agent: reliability hardening — retry, SSE tests, tool-output…",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T11:58:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "320d5f344b9006456005608af2b9cdefd55636a0",
"body": "Each chat can switch identity in-chat (/profile basecode) and the choice\npersists per chat (chatIdentities store, outside any profile dir). Switching\nidentity swaps the whole context — that identity's account, memory, skills,\ntools, and its own conversation thread — while /model still switches the model\nwithin an identity. Register /profile + /profiles in the command menu; /status\nand /help now show the active identity.",
"is_bot": false,
"headline": "telegram: in-chat identity switching (/profile, /profiles)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T10:27:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5d06121adecab623cbc2bb26372cb9a3b1f73723",
"body": null,
"is_bot": false,
"headline": "docs: README — per-identity accounts/tools and the connect flow",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T10:11:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bcf62460b550edb07bfc546663cf76e6529692e1",
"body": "Layer each identity's own MCP servers (profiles/<name>/mcp.json via\nprofile.MCPFile) on top of the shared mcp.json, so a business profile can have\ntools a personal one doesn't — alongside the already per-profile accounts,\nmemory, skills, and sessions. Add a basecode business profile (Flak @ Basecode)\nas a concrete second identity.",
"is_bot": false,
"headline": "profiles: per-identity tools (profile-scoped MCP) + basecode identity",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T10:11:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb1986d63c39ce71747c8b4b2de8984bb4c7eeea",
"body": "Move each command group out of the monolithic main.go into its own file\n(introspect, connect, chat, schedule, serve, telegram). main.go is now just\ndispatch + the default run + the terminal handler. With the earlier app/\nextraction, main.go drops from ~1417 to 179 lines and the reusable logic lives\nin packages.",
"is_bot": false,
"headline": "cmd/harness: split the CLI into focused files",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T10:01:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e306dee36e7ae284969352599c47c527de174ac0",
"body": "Move buildAgent/defaultConnectors/path helpers into a new app package\n(app.Build, app.Connectors, app.Spec) so every surface composes its agent the\nsame way. Move the curated model catalog into provider.Models and the buffering\nhandler into agent.Collector. The cmd binary now calls into these instead of\ndefining them. Pure refactor — all tests green.",
"is_bot": false,
"headline": "app: extract agent composition into a package; thin the CLI",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T09:56:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5252ffe9ed9c347f3cf88beb8e7cfb6738fc50e4",
"body": "Add inline-keyboard support to the channel (Button, SendKeyboard, EditMessage,\nAnswerCallback, CallbackQuery parsing, Run callback dispatch). /model and\n/models now open a tap-through menu: pick a provider, then a model; the choice\npersists on the chat session. Curated per-provider model lists and a ready-\nprovider list drive the buttons.",
"is_bot": false,
"headline": "telegram: interactive provider→model menu (inline keyboards)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T09:46:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7bb1cd209006d14b0d6a80bc487c5f2ffa95d422",
"body": "Give the assistant a concrete identity (Morpheus) and assert it positively. The\nprevious fix mentioned the literal string 'Claude Code' to negate it, which\nprimed the model to surface the term — even on non-OAuth providers. Remove that\nstring entirely and lead with the name across personal + work profiles and the\nTelegram /help. Verified: identifies as Morpheus on both Claude (OAuth) and\nDeepSeek.",
"is_bot": false,
"headline": "profile: name the assistant Morpheus; fix Claude Code leak",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T09:38:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6022a78a3bad8da6c707d0c2ab59e9ed5c303a64",
"body": "Add -allow (and $HARNESS_TELEGRAM_ALLOW): a comma-separated set of permitted\nchat ids; non-allowed chats are blocked (logged + a private notice) before\nreaching the model. Warn at startup when the bot is left open. Also clarify in\nthe personal persona that 'Claude Code' / provider names are access details,\nnot the assistant's identity — so it stops introducing itself as Claude Code\non the Claude OAuth path (which had leaked into history across providers).",
"is_bot": false,
"headline": "telegram: chat allowlist; persona asserts own identity",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T09:29:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7d555263166246c282ca362c2c16486286081719",
"body": "Add Bot.SetCommands (setMyCommands) and call it at startup so /model, /models,\n/status, /reset, /help appear in the client's command menu and autocomplete\ninstead of having to be known in advance.",
"is_bot": false,
"headline": "telegram: register slash commands in Telegram's UI menu",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T09:21:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "21d88e78895c2ac8431a0efe727bad46dfd30aae",
"body": "Add /model <provider> [model], /models, /status, /reset, /help to the Telegram\nchannel. The choice persists per chat on the session (new Provider/Model fields)\nand the responder builds each turn's agent from it, falling back to the launch\ndefault. /model validates against provider.Slugs() and warns (via the real\nbuild path) when a provider has no key/endpoint configured.",
"is_bot": false,
"headline": "telegram: in-chat model switching via slash commands",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T09:15:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a573294ad2040bba9dfc670ae36de4bf6c184af2",
"body": "Add BuildWith(slug, BuildOptions) so credentials/endpoints can come from the\nconfig file (providers.<slug>.{api_key,base_url,model}), env still overriding.\nNew OpenAI-compatible providers: kimi|moonshot (api.moonshot.ai/v1), fireworks\n(api.fireworks.ai/inference/v1), and mimo (endpoint must be set i\n[…]\nconfig — no\ndefault assumed). buildAgent resolves the provider config and a config-pinned\nmodel. Upgrade the personal persona into a capable assistant identity used\nacross CLI, web, and chat surfaces.",
"is_bot": false,
"headline": "providers: add Kimi/Moonshot, Fireworks, MiMo + config-stored keys",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T09:09:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "47591872ce66446836c012a0065db2f32f777c22",
"body": null,
"is_bot": false,
"headline": "docs: README — Gmail connector + Telegram channel",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T08:26:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "adf420c11f6740ca8bfc297a46d68154c32dfd22",
"body": "Add a transport-only Telegram channel: long-poll getUpdates, route each\nmessage through an injected Responder, reply with sendMessage. The CLI wires\n'harness channel telegram' so each chat resumes its own per-identity session\n(tg-<chatid>) — the conversation has memory. Reply text is buffered via a new\nbufHandler. Needs a BotFather token (-token or $TELEGRAM_BOT_TOKEN).",
"is_bot": false,
"headline": "channel/telegram: reach the assistant from Telegram",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T08:26:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8101950a11a3af4cc652cd83feb3273e47fa3501",
"body": "Extend the Google connector with Gmail: search messages with Gmail query\nsyntax (sender/subject/date/snippet) and fetch one message's headers + decoded\nplain-text body. Reuses the connector's OAuth get + apiBase test seam; the\ngmail.readonly scope was already requested. Tools gate on being logged in.",
"is_bot": false,
"headline": "google: Gmail read tools (gmail_list_messages, gmail_get_message)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T08:22:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa6720f879c186b0f659d0ecd82ed82bd8603ae2",
"body": null,
"is_bot": false,
"headline": "docs: rewrite README for the full assistant — pillars, commands, layout",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:50:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "50f29f98e66ef22390b04a3aa876b2e159c5c91f",
"body": "Add a transport-only server package that streams a chat turn over Server-Sent\nEvents and persists it to the profile's session store. The agent build and\nsession resolution are injected, so the package stays decoupled and reusable.\nEndpoints: POST /v1/chat (SSE), GET /v1/sessions, GET /healthz, GET /. Wire\nharness serve with graceful shutdown. The same engine now backs CLI, chat,\nschedule, and HTTP clients.",
"is_bot": false,
"headline": "server: HTTP+SSE serve mode (harness serve)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:49:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3190331be0e57bd497ae913c027b5b591aca6b68",
"body": "Add the scheduling pillar: a task pairs an identity (profile + provider) with\na prompt and a schedule spec — 'every 30m', 'daily 08:00', or 'weekly mon\n09:00'. NextRun computes the next fire time; the store persists tasks as JSON\nand tracks last/next run. CLI: schedule add/list/remove/run/run-due/daemon.\nrun-due is meant for a system cron/launchd; daemon keeps a process checking on\nan interval. The assistant can now run on a clock, not only when prompted.",
"is_bot": false,
"headline": "schedule: proactive scheduled tasks (harness schedule)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:47:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e79fdc11a6dae1dcc1782b3272675de4107d574e",
"body": "When CompactTokens is set and the assembled history exceeds it, the oldest\ncomplete turns are summarized by a fast-tier call into a single user/assistant\nexchange, keeping the prompt within the context window without dropping facts.\nThe split is pairing-safe (tail starts on a user turn) and the summ\n[…]\nt re-summarizes only when its summarized prefix grows. The\npersisted session keeps full fidelity — only the prompt is compacted. Enabled\nin chat (-compact, default 120k tokens); off for one-shot runs.",
"is_bot": false,
"headline": "agent: summarizing context compaction for long conversations",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:42:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40b4402ad43de3306dbb990a95cc6f1cf2cce860",
"body": "Add agent.Continue, which resumes from prior history and returns the full\nupdated history so it can be persisted. Add a session package that stores a\nconversation as JSON under a profile's sessions dir, plus the chat REPL\n(/exit, /reset, -session, -new) and a sessions listing command. Refactor the\nagent-building wiring out of runAgent into a shared buildAgent so run and chat\nbehave identically. Conversations now survive across invocations.",
"is_bot": false,
"headline": "session: multi-turn persistent conversations (harness chat)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:38:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e06827463fd07d521ccb09b5a0ebcbf9fb1c5037",
"body": "Skills are now scoped per identity: an active profile's own skills dir is\nscanned first and wins on name conflicts. Add the learn_skill tool so an\nidentity can save a reusable workflow it worked out as a new SKILL.md under\nits own skills dir — the self-improvement loop. The skills command and agent\nruns are both profile-aware.",
"is_bot": false,
"headline": "skill: per-profile skills + self-improving learn_skill tool",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:33:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b7b4f1a8b68224150deeab2d1c23b1b952649d21",
"body": "- memory package: per-identity store (<profile>/memory/*.md), load/save,\n Context() injects 'what you remember about the user' + a remember nudge\n- remember tool persists a durable fact; wired into identity-profile runs\n- 'memory' command lists an identity's memories\n- tests: save/load, remember tool, context rendering\n\nThe assistant now carries facts across invocations (per identity).",
"is_bot": false,
"headline": "memory: per-profile persistent memory + remember tool",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:28:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fec7f76e1d3a6377a991d154940b1c3dd5eadf8e",
"body": "- profile.DataDir(name) / AuthFile(name): each identity gets its own\n <user-config>/harness/profiles/<name>/ store, so personal and work connect\n *different* Google accounts\n- connect: -profile flag (default from config); writes the account to that\n identity's auth.json (creating its data dir)\n- \n[…]\nhe Google connector reads the active\n identity's auth file; connectors/run thread the active profile through\n\nSwitching identity switches connected accounts — like Construct's profile-scoped\nstorage.",
"is_bot": false,
"headline": "profiles: per-identity data dir (Construct-style scoped accounts)",
"author_name": "Flakerim Ismani",
"author_login": "flakerimi",
"committed_at": "2026-06-17T02:24:46Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 15,
"commits_last_year": 117,
"latest_release_at": "2026-07-03T19:00:12Z",
"latest_release_tag": "v0.10.0",
"releases_from_tags": false,
"days_since_last_push": 7,
"active_weeks_last_year": 5,
"days_since_latest_release": 25,
"mean_days_between_releases": 0.1
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 57,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/flakerimi/harness",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/flakerimi/harness",
"is_deprecated": false,
"latest_version": "v0.19.2",
"repository_url": "https://github.com/flakerimi/harness",
"versions_count": 32,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-20T14:18:29Z",
"latest_version_yanked": null,
"days_since_latest_publish": 8
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 31391,
"source_files_sampled": 141,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 10160
},
"dependencies": {
"manifests": [
"go.mod",
"web/package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "dompurify",
"manifest": "web/package.json",
"ecosystem": "npm",
"version_constraint": "3.4.11"
},
{
"name": "marked",
"manifest": "web/package.json",
"ecosystem": "npm",
"version_constraint": "18.0.5"
},
{
"name": "vue",
"manifest": "web/package.json",
"ecosystem": "npm",
"version_constraint": "3.5.38"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "flakerimi",
"commits": 117,
"avatar_url": "https://avatars.githubusercontent.com/u/871482?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 8,
"reason": "2 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "c570fa86469f9be037794922bd291a6fc0cbc2f1",
"ran_at": "2026-07-29T13:14:11Z",
"aggregate_score": 3.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T15:52:54Z",
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/flakerimi/harness",
"host": "github.com",
"name": "harness",
"owner": "flakerimi"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 49,
"inputs": {
"security": 39,
"vitality": 75,
"community": 33,
"governance": 40,
"engineering": 52
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 75,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"commits_last_year": 117,
"human_commit_share": 1,
"days_since_last_push": 7,
"active_weeks_last_year": 5
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 7 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 7
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "5/52 weeks with commits",
"points": 3.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 5
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "117 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 117
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 15,
"latest_release_tag": "v0.10.0",
"releases_from_tags": false,
"days_since_latest_release": 25,
"mean_days_between_releases": 0.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "15 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 15
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 25 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 25
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 33,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 40,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 16,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution",
"pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"merged_prs": 0,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 58,
"inputs": {
"followers": 37,
"owner_type": "User",
"is_verified": null,
"owner_login": "flakerimi",
"public_repos": 108,
"account_age_days": 5514
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "37 followers of flakerimi",
"points": 11.4,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 37,
"login": "flakerimi"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "108 public repos, account ~15 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 108
}
},
{
"code": "account_age_years",
"params": {
"years": 15
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/flakerimi/harness"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 8
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 8 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 8
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "32 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 32
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 52,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "at_risk",
"name": "Documentation",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 39,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 39,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 3.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "2 existing vulnerabilities detected",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 3
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 74,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.98,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 10160
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "98 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 98,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 56,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "go.mod (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "go.mod"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 31391,
"source_files_sampled": 141,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/141 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 141,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-29T13:14:15.734846Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/flakerimi/harness.svg",
"full_name": "flakerimi/harness",
"license_state": "standard",
"license_spdx": "MIT"
}