公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-28 07:43 UTC

gkoreli / ghx

Agent-first GitHub code exploration. GraphQL batching, code maps (~92% token reduction), AND search, repo discovery with README previews. Codemode TypeScript sandbox, MCP server. Go.

GoMIT★ 0 星标⑂ 0 复刻始于 2026年3月在 GitHub 上查看 ↗

gkoreli/ghx 的健康指数为 100 分中的 55 分,处于「中等」区间。 其得分最高的类别是AI Readiness(81/100),最低的是Community & Adoption(32/100)。 最近一次更新在 8 天前。 近期的大部分工作由 1 位贡献者完成。

55
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

55
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Goga Koreli个人账户
0 关注者5 个公开仓库始于 2025年11月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
Gogithub.com/gkoreli/ghx/v2v2.9.0-3420 天前
npm@gkoreli/ghx2.9.02,1372920 天前githubclicode-explorationagentgraphqlcode-map

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

75良好 · 占总体的 22%
评分方式
28.8/36推送新近度 — 最近一次推送于 8 天前
8.3/36提交节奏 — 52 周中有 12 周有提交
18/18提交量 — 最近一年 598 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year598
human_commit_share1
days_since_last_push8
active_weeks_last_year12

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 37 个发布版本
36/36发布时效 — 最近一次发布版本于 20 天前
27/27发布节奏 — 约每 0.2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count37
latest_release_tagv2.9.0
releases_from_tags
days_since_latest_release20
mean_days_between_releases0.2

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

32存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
44.4/80月度下载量 — go, npm 合计每月 2,137 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesgithub.com/gkoreli/ghx/v2, @gkoreli/ghx
dependents
ecosystemsgo, npm
total_downloads
monthly_downloads2,137
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

46存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
38.2/38.3PR 接受 — 已裁定的 PR 中 6/6 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/29 approved changesets -- score normalized to 0
所用输入
merged_prs6
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
0/25所有者影响力 — gkoreli 有 0 位关注者
7.1/25既往记录 — 5 个公开仓库,账户约 0 年
所用输入
followers0
owner_typeUser
is_verified
owner_logingkoreli
public_repos5
account_age_days259
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go, npm 上有 2 个软件包
35/35发布时效 — 最近一次发布于 20 天前
20/20版本历史 — 34 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/gkoreli/ghx/v2, @gkoreli/ghx
ecosystemsgo, npm
any_deprecated
min_days_since_publish20

工程质量

基础的工程与文档实践是否到位?

69中等 · 占总体的 20%

工程实践

48存在风险
评分方式
24/24CI 工作流 — 1 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

100优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://www.npmjs.com/package/@gkoreli/ghx
10/10仓库描述
10/10主题标签 — 7 个主题标签
10/10Wiki
所用输入
topicsai-agents, cli, code-search, developer-tools, github, golang, mcp
has_wiki
homepagehttps://www.npmjs.com/package/@gkoreli/ghx
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

48存在风险 · 占总体的 16%

安全态势

35存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3.5
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
25/25间接依赖不含已知公告 — 没有间接依赖携带已知公告
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories0
affected_packages0
assessed_packages6
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
已排除计分(无数据或不适用):没有长期未处理的公告。 其余权重已重新归一化。 比对的是 npm:@gkoreli/ghx@2.9.0 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 6 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

81良好 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md, CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes19,522
评分方式
18/18一条命令的引导启动 — .mise.toml
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 94 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesgo.sum, pnpm-lock.yaml
has_dockerfile
typed_language
bootstrap_files.mise.toml
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.94
toolchain_manifestsgo.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
55/55可控的文件大小 — 采样的 245 个源文件中有 0 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes35,342
source_files_sampled245
oversized_source_files0

关键数据

0GitHub 星标
1贡献者
598最近 12 个月提交数
8距最近推送天数
37发布版本数
1巴士系数(bus factor)
0开放议题
Go, npm软件包生态系统数

数据采集警告

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 3.5 / 10
3.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-28 07:43 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
直接依赖 15
注册表软件包版本约束清单文件
Gogithub.com/bmatcuk/doublestar/v4v4.10.0go.mod
Gogithub.com/cli/go-gh/v2v2.13.0go.mod
Gogithub.com/coder/acp-go-sdkv0.13.5go.mod
Gogithub.com/dop251/gojav0.0.0-20260311135729-065cd970411cgo.mod
Gogithub.com/evanw/esbuildv0.27.4go.mod
Gogithub.com/mark3labs/mcp-gov0.45.0go.mod
Gogithub.com/odvcencio/gotreesitterv0.13.4go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogo.opentelemetry.io/proto/otlpv1.10.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

依赖安全公告 0

安装 npm:@gkoreli/ghx@2.9.0 会引入 6 个包(直接与传递):其中 0 个存在已知公告,0 个为直接依赖。

没有已知公告影响已评估的依赖。

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "cli",
        "code-search",
        "developer-tools",
        "github",
        "golang",
        "mcp"
      ],
      "is_fork": false,
      "size_kb": 8080,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/@gkoreli/ghx",
      "languages": {
        "Go": 1986731,
        "Shell": 4575,
        "JavaScript": 1460
      },
      "pushed_at": "2026-07-19T16:16:33Z",
      "created_at": "2026-03-08T04:08:37Z",
      "owner_type": "User",
      "updated_at": "2026-07-19T16:16:37Z",
      "description": "Agent-first GitHub code exploration. GraphQL batching, code maps (~92% token reduction), AND search, repo discovery with README previews. Codemode TypeScript sandbox, MCP server. Go.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "mainline",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "gkoreli.com",
      "name": "Goga Koreli",
      "type": "User",
      "login": "gkoreli",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/243085293?v=4",
      "created_at": "2025-11-10T08:36:47Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 259
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.9.0",
          "kind": "minor",
          "published_at": "2026-07-08T02:49:04Z"
        },
        {
          "tag": "v2.8.0",
          "kind": "minor",
          "published_at": "2026-07-07T18:25:34Z"
        },
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2026-07-07T14:10:39Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-07-07T06:41:57Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-07-07T00:09:18Z"
        },
        {
          "tag": "v2.4.2",
          "kind": "patch",
          "published_at": "2026-07-06T21:47:37Z"
        },
        {
          "tag": "v2.4.1",
          "kind": "patch",
          "published_at": "2026-07-06T20:58:28Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-07-06T20:27:01Z"
        },
        {
          "tag": "v2.3.2",
          "kind": "patch",
          "published_at": "2026-07-06T16:37:37Z"
        },
        {
          "tag": "v2.3.1",
          "kind": "patch",
          "published_at": "2026-07-06T16:31:37Z"
        },
        {
          "tag": "v2.1.19",
          "kind": "patch",
          "published_at": "2026-07-02T18:23:33Z"
        },
        {
          "tag": "v2.1.18",
          "kind": "patch",
          "published_at": "2026-07-02T17:49:23Z"
        },
        {
          "tag": "v2.1.17",
          "kind": "patch",
          "published_at": "2026-06-09T21:04:34Z"
        },
        {
          "tag": "v2.1.16",
          "kind": "patch",
          "published_at": "2026-04-15T06:57:19Z"
        },
        {
          "tag": "v2.1.15",
          "kind": "patch",
          "published_at": "2026-04-15T06:50:57Z"
        },
        {
          "tag": "v2.1.14",
          "kind": "patch",
          "published_at": "2026-04-15T06:39:11Z"
        },
        {
          "tag": "v2.1.13",
          "kind": "patch",
          "published_at": "2026-04-01T22:20:15Z"
        },
        {
          "tag": "v2.1.12",
          "kind": "patch",
          "published_at": "2026-04-01T18:50:18Z"
        },
        {
          "tag": "v2.1.11",
          "kind": "patch",
          "published_at": "2026-04-01T18:36:09Z"
        },
        {
          "tag": "v2.1.10",
          "kind": "patch",
          "published_at": "2026-04-01T18:23:42Z"
        },
        {
          "tag": "v2.1.9",
          "kind": "patch",
          "published_at": "2026-04-01T18:19:27Z"
        },
        {
          "tag": "v2.1.8",
          "kind": "patch",
          "published_at": "2026-04-01T17:53:42Z"
        },
        {
          "tag": "v2.1.7",
          "kind": "patch",
          "published_at": "2026-03-30T23:58:07Z"
        },
        {
          "tag": "v2.1.6",
          "kind": "patch",
          "published_at": "2026-03-29T19:16:21Z"
        },
        {
          "tag": "v2.1.5",
          "kind": "patch",
          "published_at": "2026-03-29T18:41:54Z"
        },
        {
          "tag": "v2.1.4",
          "kind": "patch",
          "published_at": "2026-03-21T03:27:17Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2026-03-21T03:24:47Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2026-03-21T03:23:27Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2026-03-21T03:19:00Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-03-21T03:11:36Z"
        },
        {
          "tag": "v2.0.2",
          "kind": "patch",
          "published_at": "2026-03-21T02:59:30Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-03-21T02:55:07Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-03-20T23:50:16Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-03-08T20:59:43Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-03-08T17:10:19Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-03-08T17:08:23Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-03-08T17:06:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "719cb293a61532b9db6771e631ecf16e687f495b",
          "body": null,
          "is_bot": false,
          "headline": "docs: normalize engineering record spacing",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-19T16:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbf57fbc4d33e8363a435f8d91740423e335d721",
          "body": null,
          "is_bot": false,
          "headline": "docs: add ghx engineering record links",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-19T16:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78b97544d859f0fadf59d6cb0a756aa1b2263904",
          "body": "Agent-experience hardening from the v2.8.0 dogfood:\n- CLI failure exit codes classified in core (ADR-0034 ph1-2): read 404 0->3,\n  read-missing 0->1, explore/read/tree/grep malformed slug ->2, 401/403 name\n  the gh auth login fix; substring matcher deleted.\n- Resolved commit SHA surfaced to agents (\n[…]\nghx-sidecar profile (ADR-0032.2): type\n  unified, drop fixed, argv-derived path-scope; byte-identical dedup, measured\n  0 host-verdict changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.9.0",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:47:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "78b51e7dc87334abdb43ef18e21c4b6aaceb4447",
          "body": "…A-0001 cross-family DISCHARGED\n\nShips the product audit's #1-ranked, cheapest, zero-measurement-dependency\nfinding, in the cross-family-cleared SAFE form.\n\nH1 (default adoption surface inverts the north star): .claude-plugin/plugin.json\nshipped only skills/ghx + skills/ghx-mcp (the heavy power-user\n[…]\n, doesn't kill it.\n\nBoth PA threads (0001, 0002) now carry an independent cross-family second opinion;\nthe last owed adjudication debt is paid.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(plugin): ship PA-0001 H1 — recon skill in the default install; P…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:47:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c59dda14855b039c1f12eaf7e882273544aeebd2",
          "body": "Landed as 3a61b63 (worker a3ae99b), verified before merge. Records the\n[]string-only scoping decision, eval-runner (not denyClient) placement, the\ntrace-array-scoped byte-identical proof, and the no-live-smoke caveat.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0032.2 implementation record (as-built + honest caveats)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:44:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e41613c276d2e2f8405c6d1a2dbc731e703d933",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record ADR-0032.2 sidecar-profile Locations fix",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:42:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3a61b635cc60ab08c8d46881d3b7fb9b4dc9b188",
          "body": "…ecar profile (ADR-0032.2)\n\nImplements ADR-0032.2 (ACCEPTED, full scope). Closes TRUST hole H9: the\nghx-sidecar eval profile silently persisted empty tool-call Locations.\n\nD1 — depend-not-copy. Delete the byte-identical evals copy of\nToolCallTrace/ToolStatusTransition; SAFE now uses the SAF runtime'\n[…]\nuteClassification). Delta\nacross the committed corpus: 1682 execute traces gain path scope, 0 ACP\nlocations overridden, 0 host verdicts change.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sidecar): unify ToolCallTrace + trustworthy Locations for the sid…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:41:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "62b4d995eb3c5b903de90bcd95e2f13b72cdf15d",
          "body": "…elog + friction dispositions\n\nMark ADR-0034 accepted and record what phases 1-2 actually built (core\nFailureClass/ghx.Error/ClassifyUpstream reading structured HTTP/GraphQL\nsignals; CLI class->exit-code mapping with the substring table deleted;\nthe three friction fixes with the byte-identical + no-\n[…]\npendency\nevidence). Add the [Unreleased] Fixed/Changed entries. Update the three\n2026-07-07 exit-code friction dispositions from open to fixed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0034 ACCEPTED + phases 1-2 implementation notes; chang…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:40:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae532a6d42bbed81fab70c22734ed73e4dcc931a",
          "body": "…rictions (ADR-0034 phase 2)\n\nThe CLI now maps FailureClass -> exit code + affordance by reading the\nghx.Error that core attached at the source (errors.As), instead of\nre-parsing English error strings. Deleted the duplicated upstreamRules /\nupstreamAffordance / upstreamError / ghxCoreError substring\n[…]\ny the two F2 cases (exit 0 -> 3 and 0 -> 1) change. No eval anomaly\ndetector or scorer depends on ghx CLI exit codes. Full suite + -race green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): source exit-code class from core; fix 3 dogfood exit-code f…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:37:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "64cedae193babc73ce6a6436ff8ec0d61b6007da",
          "body": "…(ADR-0034 phase 1)\n\nLift failure-classification into core so every frontend maps one shared\ndomain class to its own idiom instead of re-deriving it from English error\nstrings (ADR-0034 M2; W2's flagged fragility).\n\n- Add FailureClass (ClassNone/ClassNoResults/ClassBadInput/ClassUpstream)\n  mirrorin\n[…]\nor. Full suite green; the three friction commands render identically to\npre-change HEAD. Table-driven classifier tests added (failure_test.go).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ghx): core owns the FailureClass taxonomy + upstream classifier …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:36:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8828ff8c5a3e003562fd263c5418620a5b692b6",
          "body": "…conflation, not one number\n\nFollow-up to 9cc1c6f. Goga pointed at skills/ghx/SKILL.md as \"what I meant by\n400\" — which exposed that my previous edit fixed the NUMBER but not the\nartifact/level mapping, and I then briefly over-corrected the other way.\nGround truth, recomputed per file:\n\n- Level 1 (m\n[…]\n (this whole thread took ~4 recompute iterations to land one number —\nexactly why \"recompute the exact quantity, name the artifact\" is a rule).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skills): fix the persona-tax scope line — \"~400\" is a THREE-way …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:31:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9cc1c6fd4c321f2c4acf0a0759debd1a160f7526",
          "body": "…-forge\n\nRevisit both skills against the PA-0002 run we just executed (synthesis →\ncross-family OWED → discharged later → corrections folded → governing ADR).\nEarned tightenings, folded into existing sections (no new sections):\n\n- CORRECT a debunked figure the skill still carried: the \"~400-line\n  p\n[…]\nready covered), persona-count changes (5-persona scoped run worked),\nremovals for their own sake (density is progressive-disclosure reference).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skills): fold PA-0002 process lessons into product-audit + skill…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:23:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b5f5070ade2c16daeaf121503589d92dcd47e632",
          "body": "Sibling to the --path grammar-teaching fix; both surfaced dogfooding the\nPA-0002 competitive recon. Code landed in 75579aa.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record ghx grep -i + tree --path (v2.8.0 dogfood AX)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:12:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "75579aac12ec1f6a8c9cc0819e4a78410349ce71",
          "body": "…or subtree\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): ghx grep -i (no-op, grep-parity) + ghx tree --path alias f…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:10:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "63e75280337177088085170c709f80dfff48b80a",
          "body": "…ases 1-2)\n\nGoga accepted both 2026-07-07:\n- 0032.2 at full scope — Layer A (type unification + drop-fix) AND Layer B\n  (D4: argv-derived path-scope), since D2 alone leaves Locations empty at the\n  source for the sidecar's execute-driven recon (dogfood FRICTION.md finding 2).\n  Still measurement-tou\n[…]\nources class from core, fixes the 3 dogfooded exit-code frictions,\n  deletes the substring matcher). Phases 3-4 (MCP, sidecar) sequenced later.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): accept ADR-0032.2 (full: +D4 argv-derive) and ADR-0034 (ph…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:09:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "102f0ccec9116c7b90014bf24935a1ce7c0718e6",
          "body": "…off; PA-0002 cross-family DISCHARGED\n\nExecutes the PA-0002 decision (absorb codebase-memory-mcp's ENGINE, gated —\nnot the product; the EVAL precedes the integration) as a governing ADR, and\ndischarges the OWED cross-family adjudication debt.\n\nADR-0024.3 (pre-registered, NOT accepted):\n- local:cbm =\n[…]\ntus.go:41, tool_registry.go:132,\n  report.go:45) + tests; effort M, not trivial.\n- vendor headline is 120x fewer tokens (5 queries), not \"99%\".\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0024.3 local:cbm tier-2 backend + pre-registered bake-…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-08T02:07:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a78bcc37a16b0cc88644708d45404744570fc20",
          "body": "…ode-mode + --depth exit codes)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record v2.8.0 dogfood AX fixes (Snapshot surfaced, c…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T19:26:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7dd74e0c03396d793632b95d14fb3294bb0a1b71",
          "body": "…de fixes (v2.8.0 dogfood)\n\nThree clean agent-experience fixes from the v2.8.0 dogfood run\n(docs/dogfood/FRICTION.md, 2026-07-07 section). None touches the\nmeasurement-bearing sidecar report or internal/sidecar/evals.\n\n1. Surface Snapshot{Repo,SHA} to agents (ADR-0036 B2, agent-facing half).\n   read\n[…]\nnal/codemode);\nTestCodeTranspileErrorExitsBadInvocation, TestAskDepthValidationRejectsBogus,\nTestAskDepthValidationAcceptsValid (internal/cli).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): surface Snapshot SHA to agents; code-mode + --depth exit-co…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T19:25:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73fe6130b189d747e02074d1a4132d4018e2328b",
          "body": "… ask exits 0 on BLOCKED, etc.)\n\nLive dogfood of v2.8.0 on gjson/p-queue/attrs: depth dial, ADR-0036 B2 Snapshot\nSHA, and the ghx tree panic fix all confirmed working (resolves the prior\nexplore->exit-3 friction). 8 soft frictions, 0 breaking.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(dogfood): v2.8.0 friction log — 8 soft (Snapshot under-surfaced,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T19:04:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9d66038b39e3a624afdfc6819af79fb32dd43d1f",
          "body": "…ST H9\n\nJudge's synthesis of the reusable-core arch-audit (first run of the arch-audit\nskill). Verdict: DO NOTHING structural — the SAF<->SAFE core is a genuine,\ncorrectly-sized shared kernel (telemetry), no framework extraction warranted\n(north-star filter, one product). The one real finding — veri\n[…]\nnd-not-copy + flow Locations), recorded as TRUST H9, NOT fixed as a\ndrive-by. Advances C7 (trust ledger). Everything else watch-list or frozen.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): AA-0002 distillation + ADR-0032.2 pre-registration + TRU…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:45:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd2e63915bde087fcf8253b91b05723c222ad78b",
          "body": "… gated\n\nJudge-reconciled verdict on absorbing DeusData/codebase-memory-mcp. Distiller\ncross-validated every load-bearing fact (MIT license; arXiv 83%-vs-92%;\nshell-out seam at tier2/toolrun.go:53 + target src/main.c:9; existing tier-2\nbackends) and discarded the over-reaches as bones.\n\nDECISION: ab\n[…]\nrammar, code-search rate limit, GitHub-only blindness) -> A.\n\nCross-family (Codex) adjudication OWED (capped twice) before any go/no-go or ADR.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0002 synthesis + distillation — absorb cbm ENGINE,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:45:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "384742572b571d8547c88644a7a3aa6f53043568",
          "body": "Reusable-core extraction (.1), Go architecture & boundaries (.2), domain\nmodeling (.3), YAGNI skeptic (.4, adversary), duplication/coupling metrics\n(.5, opus fallback — GPT usage-capped). Convergent verdict: the SAF<->SAFE\ncore is a GENUINE shared kernel (telemetry), correctly sized — no framework\ne\n[…]\nction warranted (north-star filter). One real bug found: ToolCallTrace\nduplicated + convertSidecarTrace drops Locations (measurement-touching).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): AA-0002 persona artifacts (5) — reusable-core boundary run",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:41:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "abc56653454ef692e8490c1e67f419ab46af9c4a",
          "body": "…p? (5 lenses)\n\nScoped PA-2 audit (focus: should ghx absorb DeusData/codebase-memory-mcp\nentirely). Five read-only persona-agents, each dogfooding ghx to recon the\ntarget, converging from different angles:\n\n- .1 Competitive (generative): ABSORB-PARTS — the engine as a brain-gated\n  shell-out tier-2 \n[…]\nO; \"entirely\" rejected; absorb the ENGINE\nnarrowly as a gated tier-2 backend, MEASURED by a ghx bake-off first.\nCross-family adjudication owed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0002 persona artifacts — absorb codebase-memory-mc…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:37:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf39223adb04b8f0dfcb1d6fe5310159f84c920f",
          "body": "… evals<->product shared kernel)\n\nFirst arch-audit run under the new skill. Scope: internal/sidecar (SAF) <->\ninternal/sidecar/evals (SAFE) shared kernel + telemetry substrate. Trigger: the\nframework half of the north star + ADR-0036's runner port. Utility tree:\nreal-shared-kernel-vs-duplication > context-tax reduction > replaceability. Frozen\nmeasurement stack respected; YAGNI adversary mandatory; do-nothing is valid.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): AA-0002 charter — reusable-core boundary (SAF-as-infra &…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:27:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0a7ac7f06d88fddf08700dec040bc323c7fa16d1",
          "body": "Architecture hardening (ADR-0035 cleanup + ADR-0036 target architecture with the\nconfig-selectable Runner port) + main-agent ergonomics. User-facing: daemon\nconfig tunables, read --line-range alias, --path affordance, Snapshot{Repo,SHA}\nin read/explore, supervisor-hardened daemon, ghx tree malformed\n[…]\nonsolidated turn engine behind the Runner port, typed Depth/Tier/Backend, tool\nregistry) synthesized from the docs/audits/ architecture audits.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.8.0",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:24:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "606248ab068913b5212dd349c9632288b977ea0b",
          "body": "…rrections\n\nInternal evidence agent rendered BuildPersonaSystemPrompt() = 141 lines / 6,858 B\n/ ~1,714 tokens (exact), and caught two uncorrected judge errors. Fixed:\n\n- Judge-step provenance bullet no longer claims \"wc -l=350 contradicts 141\" —\n  the persona's 141 was RIGHT; 350 was my non-comparab\n[…]\nructurally blind to\n  the native Explore rival's own docs (needed a curl fallback).\n\nCross-family adjudication still owed on the High findings.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001.8 evidence ledger + decision-grade merge + co…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:23:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ef0b6ac2951f2904e2fb6c109cce1e1dc663455",
          "body": "…ews shipped)\n\nSkill-forge loop complete: Round-0 research (5 canons incl. the mandatory Wave-2\nre-pricing) -> Round-1 draft -> Round-2 adversarial review (craft / completeness+fit\n/ meta-redteam) -> Round-3 judge reconciliation (this commit) + provenance shipped.\n\nACCEPTED (verified against the rep\n[…]\nng security/CLI-versioning/supply-chain/observability lenses (R2 — anti-fit or\nalready-owned); FM-4/5 folded into FM-3, not separate additions.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill): arch-audit Round-3 reconcile + finalize (research + revi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:22:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9eab3e6f7173e7f85da547aa76539b5b365b1df1",
          "body": "Decision-grade external cross-refs for PA-0001: competitors, the native\nalternative, and absorption/OSS-inspiration — all deep hyperlinks verified\n(14 repos, 9 file paths, 3 external URLs resolve).\n\nCorrections fed forward:\n- Claude Code Explore is NO LONGER Haiku-by-default (v2.1.198 inherits main\n\n[…]\ns the one ghx can't reconnoiter.\n\nTop absorption anchors: codebase-memory-mcp knowledge graph, repomix --compress,\naider repomap.py (PageRank).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001.7 external & OSS-inspiration cross-references",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:18:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "332d0e3cbd9a528062038ec28efe746a82346c55",
          "body": "…avior-identical (ADR-0036 C1)\n\nDefine the harness-neutral Runner port in package sidecar (runner.go: Runner/\nSession/TurnRequest/SteeringSpec/EventSink/Outcome/FailureClass) and make the\nclaude-agent-acp path implement it (acprunner.go): the string-matchers become an\nadapter-internal Outcome mappin\n[…]\nsidecar suite\npasses UNMODIFIED incl. -race (byte-identical proof); the agent that wrote this\ndied pre-commit and Fable salvaged + verified it.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): introduce Runner port; ACP path implements it, beh…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:16:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "004489e8b138a01e49ed0e342132ee6b7491f3bb",
          "body": "The reusable kernel from product-audit's evidence-ledger lesson: sourcing\ndiscipline was strong on the research INPUTS but never reached the OUTPUT, so a\nconclusion could ship as evidence-free prose.\n\n- Guardrail: conclusions aren't decision-ready without consolidated receipts —\n  the same sourcing \n[…]\ndence\n  ledger.\n\nLeft in product-audit (not copied): the specific evidence classes\n(source/strategy/experiment) and the OSS-absorption framing.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-forge): generalize \"decision-ready = consolidated receipts\"",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:16:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "412b151197782f950ffbed009022b7f9459868d9",
          "body": "…nce ledger\n\nFindings were decision-shaped but not decision-READY — conclusions without the\nreceipts. Fix the workflow so evidence spans every class and is consolidated:\n\n- New synthesis output: \"Evidence & cross-reference ledger (decision-grade)\" —\n  per top finding, consolidate SOURCE (file:line +\n[…]\na was inspired or\n  absorbed, as a SPECIFIC deep hyperlink (never a bare homepage), verified.\n- Delegation template updated to demand the same.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): require a decision-grade evidence & cross-refere…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:12:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7dcfc789dc3d94bf4ff6ffe2d9d79dcf189ee189",
          "body": "…anon\n\nAuthoring pass (skill-forge Round 1) on the fork's draft, folding in the sourced\nresearch: an ATAM utility-tree front-end to the charter (rank quality attributes\nper scope); complexity x git-churn hotspots + gocognit for the metrics persona\n(not just gocyclo); adversaries run as premortem/Tea\n[…]\nESS FUNCTIONS (committed CI checks)\nso boundaries don't drift back between audits (anti-shelfware). Provenance now\npoints to research/ ledgers.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill): arch-audit Round-1 revision — fold in Round-0 research c…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:04:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf1882ed646a19f942262322b429194bf10e1bf6",
          "body": "…(4 canons)\n\nskill-forge Round 0 for the arch-audit skill: idiomatic-Go architecture (R1),\nclean-architecture/DDD/reusable-core (R2, Shared-Kernel framing for evals<->product),\ntech-debt detection & metrics (R3, complexity x git-churn hotspots + Go tooling),\narchitecture-audit methodology (R4, ATAM \n[…]\nLM self-preference judge guardrail). 66 deep-URL sources total, degradations\ndisclosed per Source Ledger. Provenance for the SKILL.md revision.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-research): arch-audit Round-0 sourced research provenance …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T18:01:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d047dff48418b820b75d907cb7157d7d538eabf",
          "body": "…tech-debt audit loop\n\nA repeatable loop for raising ghx's maintainability -> engineering velocity:\npick a scope (whole codebase / module / reusable capability like the Agent\nSidecar Framework or the evals<->ghx shared core / a cross-cutting mindset),\nfan out 4-6 background personas (>=1 adversarial\n[…]\nstack\nrespect, north-star filter / no cathedrals, forward-looking agentic-first lens,\nff-only integration (never --amend on a shared mainline).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(skill): arch-audit — scoped multi-persona architecture/codebase/…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:49:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1bcf73bcfb58db5b7b2e43d5ce4a4a8281e44215",
          "body": "…-picture rule\n\nPort the reusable parts of the founder's audit-workflow guidance into the meta-\nskill (leaving product-audit-specific bits in product-audit):\n\n- Convergence & distillation is now a first-class step: a loop-table row\n  \"Distil (conditional)\" + a dedicated section. When the deliverable\n[…]\nncile: \"no\" outcomes extend to concluding the premise is wrong or that a\n  canonical source has gone stale and should be flagged for evolution.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-forge): generalize the convergence/distillation pass + big…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:40:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ae128db9cbb634f697afdb2a949411822129cfe",
          "body": "Convergence & distillation pass (Process step 8) mined the intersection and\ncross-validated against the codebase; orchestrator judged it.\n\n- Convergence re-scored by the shared-prior rule: H2's \"two personas agree\" is\n  shared-prior (both read corpus-discrimination) — its signal comes from the\n  dis\n[…]\n.\n- Bones vetoed: Explore-commoditizes over-reach; SPT \"value-free\" label; SPT\n  non-load-bearing; L2 M8. Cross-family adjudication still owed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001.9 distillation + judge verdicts; close the loop",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:31:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d31efb8a8e1b1402938e0636d6ee246bd270ab2",
          "body": "…(dogfood F3)\n\nDogfood friction F3 (docs/dogfood/FRICTION.md, 2026-07-07) reported a live\n401 on `ghx search` printing the bare \"search failed: HTTP 401: Bad\ncredentials (...)\" with no fix-it affordance. That was a stale-binary\nartifact: the friction binary was v2.6.0 (e8816ec), which predated the A\n[…]\nto 2 and fails the test.\n\nExit codes 0/1/2/3 unchanged. No errors.go change was needed (the 401 rule\nalready exists). Scope: internal/cli only.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): live upstream 401/auth errors name the 'gh auth login' fix …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:29:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d2d2858513aa30eadab03a5bfc9b1193159c903",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(review): independent review of ADR-0035/0036 refactors",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:28:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3ae3c6b9d42fb434499aed7210fae7a2919e08b4",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): runner-adapters integration spec (codex-acp + claude-sdk)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:28:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "98492fb7940ab066d6a3bd2cd3b9c95fecbc917c",
          "body": "The process retrospective caught the judge (me) comparing prompt.go's 350\nwhole-file lines against the persona's ~141-line RENDERED doctrine — two\nnon-comparable quantities. Re-derived: the recon doctrine is\nBuildPersonaSystemPrompt() (prompt.go:37), ~130-141 lines; the file also holds\nBuildDiscover\n[…]\nd; my dismissal\nwas itself the evidence-drift the new PF1 rule (recompute the exact quantity via\nthe finding's own command) now guards against.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): correct PA-0001 L1 — self-caught evidence-drift (PF1)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:27:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6ca4267f4692bc1ae0e96c51e29073ecbcfa609",
          "body": "…eword by specific id, ff-only landings\n\nGoga 2026-07-07 after the amend incident: parallel engineers may be committing\nto mainline in the same tree. Appends are safe; history rewrites are the danger.\nRules: never `git commit --amend` on mainline (it rewrites whatever HEAD points\nat, which may be an\n[…]\n CAS update-ref (never rebase a shared tree holding others'\nuncommitted files); land worker branches by ff-only (retry on race, never\ncorrupt).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(claude): git hygiene on a shared mainline — never blind-amend, r…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:27:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1c3037bef62b67f61757397a66fdb3620e57794",
          "body": "…posture, PF1/2/3\n\nFounder guidance + the PA-0001 process retrospective, folded in:\n\n- Process step 8 — Convergence & distillation (final pass): a fresh no-stake\n  agent mines the intersection of the fan-out; GENUINE cross-persona convergence\n  = high signal, shared-prior convergence discounted; dis\n[…]\ne-drift), order accepted findings by\n  leverage not severity alone.\n- skill-forge: convergence/distillation pass noted for multi-agent outputs.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): convergence pass, north-star-is-auditable, 2026 …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:27:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee62a610d950ac1d8554b0ca405b9b2176feff97",
          "body": "…e live run)\n\nIndependent review of the audit PROCESS as executed. Caught the orchestrator's\nown judge-step error (compared whole-file 350 lines vs the ~141-line rendered\npersona doctrine — non-comparable) and proposes: PF1 recompute the finding's\nexact quantity via its own command + cite by symbol/\n[…]\nred citability-gated field. Credits what the process did well (genuine\nre-derivation, named shared-prior caution, blocking cross-family state).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): PA-0001 process retrospective (meta-review of th…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:24:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dec217df201fac52af476689ed8cb63e51dec50f",
          "body": "…1.6)\n\nCodex (cross-family) was usage-capped, so per directive 5 a fresh no-stake\nClaude adjudicator re-derived C1-C5 from raw files (partial mitigation;\ncross-family still owed). It confirmed the spine of all three High findings and\nsharpened four, folded into an \"Adjudication outcome\" section:\n\n- \n[…]\nt).\n- M3 severity -> Medium.\n\nStatus: High findings self-verified + same-family-adjudicated; cross-family\ncheck still owed before any go/no-go.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001 judge step — same-family adjudication (PA-000…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:19:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03601262243b2e208e34aff7074a4084bf1acf10",
          "body": "…judicator fallback\n\nFounder guidance (2026-07-07): an audit needs a declared focus, not a\nfrom-inception sweep every run — but scoped != narrow-minded.\n\n- New Prime Directive 6: every audit declares a focus/attack surface (a\n  milestone/feature/goal/vision/surface); do NOT re-audit the whole produc\n[…]\nmitigation (removes stake/shared-context bias, not same-family bias);\n  flag findings checked only same-family. Same note added to skill-forge.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): require a scoped focus/attack-surface; Claude ad…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T17:13:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14660c8aa9a20cf7882540ead366971c0028113b",
          "body": "Orchestrator synthesis over the 5 persona artifacts. Judge step: Fable\nre-derived every load-bearing fact from raw artifacts (plugin.json,\ncorpus-discrimination table, report.go schemaVersion, handleRecon, prompt.go\nsize — which contradicted a persona's \"141 lines\" claim, rejected); competitor\nrepos\n[…]\nlus M1-M4, L1-L2, a strong \"what is actually fine\" (eval honesty; brain works\nlive, HIC 0), absorption candidates, and adjacent-idea proposals.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001 synthesis — judge-reconciled ghx product audit",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:33:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "18f6170f9138f44f45824a1149758af374b0b2ae",
          "body": "First real run of the product-audit skill on ghx. Five read-only adversarial\npersona-agents (opus), each a threaded PA-0001.k artifact under docs/product-audit/:\n\n- PA-0001.1 Agent Experience — default install ships the heavy CLI skill,\n  inverting \"zero ghx knowledge\"; read-of-missing-repo returns \n[…]\nalready say.\n\nSynthesis (PA-0001) follows after orchestrator judge step: self re-derivation\n(done) + Codex cross-family adjudication (running).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit(product): PA-0001 persona artifacts (live product-audit skill run)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:29:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03e24be20e5a2eba0ecaa7ba0c95a48e9a0be903",
          "body": "… ADR-threaded\n\nProduct audits now live in docs/product-audit/ (kept separate from the code\naudits in docs/audits/), numbered and threaded like ADRs: a round is PA-000N\nwith per-persona artifacts PA-000N.k-<persona>.md and a PA-000N-<focus>.md\nsynthesis. Establishes the convention the first live run (PA-0001) uses.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): output convention — docs/product-audit/ PA-000N,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:16:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e0a37499198097586782c90f33ae20579ba49613",
          "body": "Captures Goga's steering (2026-07-07) in the two places asked:\n\nAGENTS.md (Open Source Leverage tenet) — two binding rules:\n- Competitive analysis is generative, not defensive: study of OSS/real-world\n  competitors never triggers retreat; it doubles down on our advantages and\n  surfaces things to AB\n[…]\nlement, not just threat lists); the delegation template + process now dogfood\nghx for any GitHub/OSS exploration and log friction as a finding.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: competitive analysis is generative; dogfood ghx for exploration",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:10:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "acd5fb1e7cb27e42e7f892a92e858cfb8da4abf1",
          "body": "…ct 07)\n\nRound-4 steals (Picasso, with attribution), the one bounded change the recon\njustified — convert two umbrella scopes into checklists:\n\n- Phase 6 gains axprobe's AX report contract (goal_reached, human-intervention\n  count, false_errors, a 5-class friction taxonomy) and its weak-driver metho\n[…]\nmiss trace-mining; Evals\n  scope gains deepeval's agentic sub-metrics.\n\nDeclined: a third (DX) consumer axis and ax-audit's web-crawler rubric.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): absorb AX-tooling rubrics from OSS recon (artifa…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:09:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "321e2f9857be3a92b3ad326944ab3632dd96d99f",
          "body": "… recon",
          "is_bot": false,
          "headline": "docs(product-audit): research artifact 07 — OSS PM-agent / AX-tooling…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:08:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "230882b70499214602e8ada6eeee7b08cc35d980",
          "body": "…ctions\n\nUpdate TRUST.md hole H7 (ceiling effects) with the workstream-C7 corpus-\ndiscrimination finding: the corpus's discrimination power rests on only 2 of\nits 6 tasks (express-router-location, openai-node-streaming); gin/hono/flask\nsit at ceiling and ghx-mapengine is contamination-confounded, wi\n[…]\nDR-0032.1 (S2 fix is on HEAD; the execute-kind nuance remains).\n- F5 (token metric undercounts) = OPEN, folds into ADR-0036 Phase D real-token.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(trust): update H7 from corpus-discrimination; triage dogfood fri…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:07:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cdb81ae65da59cae31de4bcf6236dbf2c3335d19",
          "body": "…le validators (ADR-0036 B3)\n\nReplace stringly-typed Depth/Tier/Backend usage in the sidecar with value\ntypes (depth.go/tier_value.go/backend.go), each with one canonical parser/valid\nset, consumed by session_options/tier/reportsink/tool_registry and the CLI/MCP\ndepth boundary. Each frontend's curre\n[…]\ntity untouched: the\npersona, backend-ID, and TierUsed goldens pass unmodified. AskRequest keeps\nstring/[]string at the public boundary for now.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): introduce Depth/Tier/Backend value types with sing…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:02:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e4d7a1f6d2033a16daab7c9cec14ad42d349fde2",
          "body": "…(ADR-0036 B2)\n\nAdd ghx.Snapshot{Repo,SHA} and record the commit oid a core read actually\nresolved (defaultBranchRef.target.oid) as an additive field on read/explore\nresults, so evidence surfaces which commit was read and two reads in one\ninvestigation can be checked against a moving HEAD. Phase 1 is\nobservability-only — additive, behavior-preserving; pinning reads to the SHA is\ndeferred to an ADR-gated Phase 2.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ghx): capture the resolved commit SHA into read/explore results …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T16:00:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c0381bdc32bfdbaf7e5cfb41dd515cc357146a57",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record daemon supervisor hardening (ADR-0036 A1)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:55:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2870137cf40f600e2a51f518f6cbf073c53afdd",
          "body": "… propagation, graceful drain (ADR-0036 A1)\n\nThree reliability fixes to the resident daemon (resilience audit H2/H3/M1):\nper-request recover() so one turn's panic returns a JSON-RPC error to that\ncaller instead of killing the daemon and all warm sessions; request-scoped\ncontext + connection-closed w\n[…]\norker); signal-aware graceful drain implementing ADR-0030 D6.\nBehavior changes only on failure/shutdown paths; +181 lines of tests; race green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sidecar): daemon supervisor hardening — panic isolation, context…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:53:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "396e7912f08d1aefdd800cdfaa45dc1d89fe8d19",
          "body": "…t the edge (ADR-0036 B1)\n\nCore recon ops (Explore/Read/Tree/Repos/Glob/Search) now RECEIVE a typed\nghx.Repo instead of re-parsing an owner/repo string internally; ParseRepo runs\nonce at the CLI (ghx.go) and MCP (serve.go) edges. \"Parse at the boundary,\nflow the type inward.\" Behavior-preserving for\n[…]\nll surfaces the \"invalid repo\" substring so a bad slug maps to exit 2.\nCodemode wrappers keep string parsing (they are the JS string boundary).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(ghx): thread ghx.Repo across the core boundary; parse once a…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:51:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bec5b3af1662221817ccf659843c4636cce971e2",
          "body": "…-0 step\n\nEncodes the run's own top lesson: the contrarian \"does this wisdom hold in OUR\ncontext?\" lens must be a standing default, not an angle you hope to notice.\nRound 0 is now two waves — wave 1 maps the canon, wave 2 is a mandatory agent\nthat reads the wave-1 artifacts and audits them (HOLDS/AD\n[…]\n the worked example this pass\n(the agentic-first lens) was the single highest-leverage step and only happened\nbecause it was caught mid-flight.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill-forge): make the context re-pricing pass a mandatory Round…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:48:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aacb58b40c02a815ae943afac9c08ee92e510920",
          "body": "…ewed skill creation\n\nCodifies the loop that produced .claude/skills/product-audit: Round 0 wide\ndelegated research (distinct angles incl. a contrarian/\"does the wisdom hold in\nour context\" lens) -> Round 1 orchestrator authors the draft (authorship not\ndelegated) -> Round 2 adversarial review on di\n[…]\n76) by verifying\nload-bearing claims and cross-family-checking the highest stakes. Owns the loop;\ndefers command mechanics to fable-delegation.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(skill-forge): meta-skill for research-driven, adversarially-revi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:31:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0ac85f2a7fce45c45fc88766177f385c53388532",
          "body": "… reviews\n\nCritically reconciled R1-R4 (accepted the verified/high-value subset; declined\ncargo-cult and scope-creep). Changes:\n\n- Judge independence (R4-F1): directive 5 + Process step 5 now require, for\n  High/thesis-invalidating findings, self re-derivation + an independent\n  cross-family check (\n[…]\nd: reliability-as-its-own-lens (covered by AX/token-econ; SRE-adjacent)\nand full Tier-B->AX-pillar collapse (kept distinct as more actionable).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): round-3 revision — incorporate the 4 adversarial…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:30:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f17053982ec72fcac82f07af4eac6e4c0c04ea44",
          "body": "Four independent critiques of the draft skill, each a ranked, DH5/DH6,\nseverity-tagged review with an honesty guard and specific-URL sourcing:\n\n- R1 skill-craft: run-spine buried past the token-retention line; ship a\n  copyable persona-delegation template; cut the anti-pattern self-tax.\n- R2 pm-comp\n[…]\nvals.\n  Cap scopes/surfaces, route dispositions to ADRs/workstreams. Net: keep.\n\nRound-3 revision incorporating the accepted subset lands next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): round-2 adversarial review artifacts (4 reviewers)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:28:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1de230b981a6750ff95c4d7781b31903a448db4",
          "body": "…ot, domain flow (synthesis of 5 vision audits)\n\nStrategic architecture ADR (ADR-0035 was tactical). Four decisions: (D1) a\nconsumer-defined Runner port in a leaf internal/sidecar/runner package so the\nagentic runtime is a config-selected adapter — claude-acp / codex-acp /\nclaude-sdk (in-process ant\n[…]\non-rewrite: A foundations, B domain, C runner port (supersedes ADR-0035 item\n5), D the SDK runtime (ADR-gated, changes token source). PROPOSED.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0036 target architecture — Runner port, composition ro…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:26:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8bdbe482af1dff1d4c921e40fd8dd8bceb3674a1",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): runner port & pluggable runtimes — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:23:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "479749e684812f91a0ec0d18a7df2aaf07ee1d6d",
          "body": "Idiomatic-Go package-architecture audit (Ben Johnson Standard Package\nLayout, Go Proverbs, Kat Zien) building on ADR-0035 and the five\n2026-07-07 audits. Answers Goga's singletons-vs-services question,\nidentifies the missing composition root (H1) and the core->codemode\ndependency-direction edge (H2), and proposes a concrete non-rewrite\ntarget layout + phased sequence toward P3/P4. Read-only; no code changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): Go architecture & boundaries — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:22:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "167d20d6c5ef3b3821e074f5e87ae3381cc3ce73",
          "body": "Read-only reliability/runtime audit of ghx under failure. Maps the current\nresilience architecture (ADR-0027 wrap-up/watchdog/stale-session/peer-closed/\nreport-retry, the acp.go marker strings, the ADR-0034 proposed failure-class\nmodel, and the B4 eval-anomaly derivation from persisted error strings\n[…]\n-layer target that preserves the frozen marker contract, and\ngives a phased non-rewrite sequence. No code changed; measurement stack untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): resilience & runtime robustness — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:20:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a54fba38a708f841460f9670798e67456a04c46a",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): domain model & ubiquitous language — target design",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:18:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "778b2aea9d26427daee2a6744bedd5168161daa3",
          "body": "Adds .claude/skills/product-audit/SKILL.md — an orchestrator playbook for\nauditing ghx from the product-manager lens: adversarial PM personalities ×\nscopes × surfaces, grounded in the north star, agentic-first (primary consumer\nis an AI agent, so classic PM advice is re-priced HOLDS/ADAPT/INVERTED b\n[…]\nope boundary (defers code/security/eval-mechanics to their homes);\ncargo-cult anti-patterns; report output contract matching docs/audits style.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(product-audit): draft the product-audit skill (round 1)",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:15:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a2a8d462ffeea39e42751d93483a61b148bfca4",
          "body": "…tique [AA5]\n\nCounterweight persona (GPT-5.5): argues against over-engineering ghx as a solo\nGo product. Thesis: keep the bug/testability fixes, add only a narrow runner\nseam, reject core/shared/domain layering and framework extraction until a\nsecond runner implementation proves the shape. Grounded in Go Proverbs / Go\nCode Review Comments / Ben Johnson standard package layout.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(arch): adversarial YAGNI skeptic — minimal-path architecture cri…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:12:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "65e0695b170ca2378b5b0f54ac58cf7b36cbccfd",
          "body": "… pivotal]\n\nAudits the classic-PM corpus (01-05) for a product whose primary consumer is\nan AI agent, not a human. Labels each load-bearing framework HOLDS / ADAPT /\nOUTDATED-OR-INVERTED, grounded in 13 agentic-first sources (5 Anthropic\nengineering posts, the MCP spec, OpenAI function-calling, Biil\n[…]\niability)\n- what still HOLDS: outcomes-over-output, JTBD, 7-Powers, red-team stack,\n  four-big-risks, PM craft/personas, market/business scopes\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): research artifact — the agentic-first lens [6th,…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:12:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "67ae414131bbe8b45295996c77ff699681299ad2",
          "body": "…stry (ADR-0035 T2.4)\n\nDefaultToolRegistry() is now the single source of truth for the sidecar's\ntool set; the persona menu (prompt.go), backend vocabulary/local-backend\nchecks (tier.go, reportsink.go), and CLI backend IDs (cli/tier2.go) all derive\nfrom it instead of scattered hardcoded lists. Perso\n[…]\nPersonaByteStable, golden unchanged); backend\nidentity string pinned additively. P3 tool absorption's identity surface is\nnow one registration.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): centralize the sidecar tool set in a ToolSpec regi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:10:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1bda8848e7e5469c32ac3d413c94fa7c30a2a9f5",
          "body": "…ial red-team [5/5]\n\nCompletes the Round-0 research corpus for the product-audit skill.\n\n- 02-pm-personalities.md: 15 audit-persona blocks (worldview / optimizes-for /\n  signature questions / blind spots / what-good-looks-like), each grounded in a\n  named authority (Perri, Torres, Verna, Chu, Fourni\n[…]\n\nAn agentic-first lens artifact (06) — auditing this classic-PM advice for a\nproduct whose primary consumer is an AI agent — is in flight next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): research artifacts — PM personalities & adversar…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T15:02:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "43ea6e9f03c9ef87eca1a094b77c7ddf58bb7048",
          "body": "…s, strategic scopes [3/5]\n\nSourced provenance for the forthcoming product-audit skill. Each artifact\ncarries specific deep-URL citations with per-claim rationale; degradations\n(paywalls, 403s, unOCR'd scans) are disclosed in-document, not smoothed over.\n\n- 01-pm-excellence.md: PM competency models,\n[…]\n,\n  north-star alignment, gaps, adjacency, monetization, moat); 31 refs.\n\nPersonalities (02) and adversarial red-team (05) artifacts land next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(product-audit): research artifacts — PM excellence, audit method…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:57:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26ae9ef442509838e0ca416a0a7b041e0224cfd7",
          "body": "…thTurnRunner (ADR-0035 T1.3)\n\nThe one-shot (acp.go RunTurnWithOptions) and warm (daemon_worker.go\nAgentWorker.RunTurn) paths duplicated the liveness watchdog, the four-way\nprompt select, and NewSession/LoadSession meta re-assertion. Extract one shared\nturn primitive (turn.go: startACPWatchdog/confi\n[…]\ntural refactor — ~244 lines of duplication removed; the full sidecar test\nsuite passes UNMODIFIED, incl. -race (byte-identical behavior proof).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): extract shared ACP turn primitive; decompose askWi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:54:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b972c4b157bcdcc34fcb21add786c6018a0c44a5",
          "body": "…e core recon (ADR-0035 T1.2)\n\nCore ops (explore/read/repos/glob/search) newed up api.DefaultGraphQLClient()/\nNewRESTClient() inline, so no test could exercise a network path. Introduce\nminimal graphQLDoer/restGetter interfaces + a package-level githubClients\nprovider (defaults to the real go-gh clients) that tests override. Public\nsignatures and CLI/MCP behavior unchanged; adds an offline fake-client test\ndriving Explore with no network.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(ghx): inject GitHub client behind a seam for offline-testabl…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fc889fe7cc6eacd6c6abee9e2376a19a9cc90ccf",
          "body": "…-0035 T1.1)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record ghx tree/explore/read malformed-slug fix (ADR…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:46:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9e4a10e427488d38bd7e3df43eaab15e06497a4c",
          "body": "…formed slug (ADR-0035 T1.1)\n\nUnify the three divergent owner/repo validators (explore/read/inspect/glob)\ninto a single ghx.ParseRepo. Fixes a real crash: `ghx tree noslash` panicked\nvia an unchecked slice index (glob.go); it now returns a clean bad-input error\n(exit 2). explore/read/tree route core\n[…]\nrepo maps to exit 2 instead of exit 3 (also fixes dogfood friction F1).\nBehavior-preserving for valid inputs; ParseRepo + no-panic tests added.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(ghx): introduce Repo value object; fix ghx tree panic on mal…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:45:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e92633d13d77a364900c3fff2660dc3dee2dd63",
          "body": "…uence (synthesis of 5 audits)\n\nConsolidates the original architecture audit + 4 new adversarial audits\n(design-patterns, complexity-metrics via GPT-5.5, coupling/testability,\nroadmap red-team) into one ranked, tiered refactor sequence. Ranks by\ncross-auditor convergence x impact x tractability. Eva\n[…]\nots\ndeferred behind a pre-registered eval ADR (frozen-measurement rule);\nframework extraction rejected now per the north-star filter. PROPOSED.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0035 architecture hardening — prioritized refactor seq…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:38:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b39ffa542a5302617ccade0d4c86c46054bf1bb4",
          "body": "Read-only contrarian audit ranking tech debt by velocity-cost against the\nP3/P4 roadmap. Companion to architecture-2026-07-07.md; does not repeat its\nactioned findings (acp.go split; ADR-0034 failure taxonomy).\n\nFindings (ranked by 1-3 month velocity-cost):\n- V1 (High): no sidecar tool registry — P3\n[…]\n won't move; domain models are portable), a recommended sequence,\nand a Method/auditability section. Every file:line verified; no code changed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): adversarial velocity red-team — roadmap-blocking tech debt",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:35:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf3428c69d5dae7132d73d9330bbc3fbb21f19db",
          "body": "Read-only audit through the coupling/cohesion/testability lens. Two High\nfindings: core recon has no GitHub-client injection seam (Explore/Search/\nRepos/Read/Tree untestable without live network), and the ACP turn engine is\nduplicated across acp.go + daemon_worker.go (plus two eval copies). Mediums:\n[…]\nDigest + dropped request context in daemon dispatch. Matches the\narchitecture-2026-07-07 audit format; cross-references rather than repeats it.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): coupling / cohesion / testability audit — ranked refactors",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:34:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b1051861ed9db486658dbd3373e3857ec52c144",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): design-patterns & domain-modeling audit — ranked refactors",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:34:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5b731289b1f1879fa046e5f3ebe4561caa676df0",
          "body": "…near history)\n\nGoga 2026-07-07: the per-worker `git merge --no-ff` left a merge bubble per\nephemeral branch, making the log noisy. New rule (AGENTS.md \"Integrating\nDelegated Work\" + fable-delegation skill): workers commit-and-stop on their\nbranch; the orchestrator lands each branch by rebasing onto mainline and\nfast-forwarding — no squash (each worker commit preserved), no merge commit.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agents): land delegated work by rebase+ff, not merge commits (li…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:34:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4d521467e486d500b2174aeb99e0a865e81aefda",
          "body": "…efactors [AUD2/codex]\n\ngocyclo/wc/fmt.Errorf pass. Top new debt: askWithTurnRunner cyclo 40\n(runtime.go:273); CLI inline RunE god-files; repeated MCP handler plumbing;\nRead control-density; repomap buildEdges. Eval hotspots flagged ADR-gated.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): complexity & maintainability metrics hotspots — ranked r…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a13187f0b15aa85141161ae25255775e188fb6fd",
          "body": "…ocations\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(dogfood): friction log 2026-07-07 — depth dial + affordances + L…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ff43a4d6824bc091543da943c5441f0e8bdf4ca1",
          "body": "…--path affordances (W1/W2); fix stray XML in failure-class audit\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): record daemon config tunables + read --line-range / …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "262e7764201ed330bac36f38ddc058495e84d6e1",
          "body": "… directly, never a parking sub-agent\n\nIncident 2026-07-07: a Claude sub-agent (isolation: worktree) that launched\ncodex as a background job then parked raced the worktree GC — the harness\nauto-cleaned the \"unchanged\" worktree out from under the running codex, losing\ntwo delegations. Rule: run `codex exec` directly from Fable's own session into\na hand-created (non-harness) git worktree; Fable verifies/commits/merges.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(skill): capture background-codex delegation rule — run the shell…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6d4d9873f83f6c5a6eb865a928066cdd457a01e6",
          "body": "… explore/search (A2/A4)\n\nMined from production/eval traces: agents type `ghx read --line-range` (real\n`unknown flag` failure in ~/.ghx/sessions/letta-ai-letta/logs.jsonl) and\n`--path` on explore/search. Add --line-range as a hidden alias of --lines\n(byte-identical output, conflict-checked), and teach the unknown-flag\naffordance to name the correct invocation for --path on explore and search.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): read --line-range alias for --lines; --path affordance for…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c2bf8df98c9f7c858428a6c03f2540cf2cb05cd5",
          "body": "…d config (ADR-0030 follow-up)\n\nTwo daemon runtime tunables that were hardcoded (30m warm-worker idle TTL,\ncross-session concurrency 4) become optional ~/.ghx/config.json fields:\ndaemonWorkerIdleTTLMinutes and daemonMaxConcurrent. Nil preserves today's\ndefaults byte-identically; <=0 is rejected with a field-named error; both\nparticipate in ConfigDigest so a running daemon stale-replaces on change (D6).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sidecar): expose daemon idle-TTL and max-concurrency as validate…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f6134a44aec3318d57f9aeabc8c0ada2910d0def",
          "body": "…DR-0034)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(audit): failure-class inventory across frontends (evidence for A…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b5364fabfffc2750f6aa7f29b64396ee8a95d7ae",
          "body": "… (C7)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(evals): corpus discrimination analysis toward H7 ceiling refresh…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:32:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2cda8a3553dfe379f33dd60c72baf1daa97ca57",
          "body": "Main-agent ergonomics + architecture/eval-trust hardening: MCP recon depth\ndial, CLI error affordances, host-task eval corpus (ADR-0032.1 S1-S4),\nToolCallTrace.Locations populated from ACP notifications, acp.go god-file\ndecomposition, ADR-0034 failure-class model (proposed).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.7.0",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:09:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4d9a3e1103e5b7414e065893b4e5be4406f653a5",
          "body": "…on on release\n\nGoga: maintain a changelog for each version — captured as a standing rule in\nAGENTS.md (Changelog section + Release Flow step 1).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agents): require a changelog entry per user-facing change; versi…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T14:08:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "47e2b7cce522a589c56fd405cd3d41672504841d",
          "body": "…affordances, host-task corpus, Locations fix, acp.go/callTool cleanup, ADR-0034)\n\nMakes the 20 commits staged since v2.6.0 reviewable ahead of the next release.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): document staged Unreleased changes (depth dial, CLI …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:31:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5aec071e22dede01633a4455d090ed1564ec6ecc",
          "body": "…ifications (ADR-0032.1 S2)\n\nToolCallTrace.Locations was declared and JSON-tagged but never written, yet\nthe host-task attribution classifier reads it for rule R6 (path-scope of\nread/edit/delete/move/search tools). The R6 detector ran on always-empty data\nand reported false-clean — a visibility/trut\n[…]\n it now lives in denyclient.go after\nthe acp.go decomposition, so the change was re-applied there rather than\nmerged from the stale-base branch.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sidecar): populate ToolCallTrace.Locations from ACP tool-call not…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:15:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "de3f7ad117f5ec4f52c8e20b9e63c928f9dd94d7",
          "body": "…POSED; audit M2)\n\nLift failure-class from the CLI frontend into core internal/ghx so MCP\n(16 opaque NewToolResultError flattenings) and the sidecar report (83\nad-hoc fmt.Errorf) can map from one taxonomy — makes the A4 recovery\naffordances universal, not CLI-only. Proposed autonomously; cross-frontend\nrefactor awaits Goga acceptance before build (phased migration registered).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0034 unified failure-class model across frontends (PRO…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:11:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a49ce76fd4cdcc7e77300e93ecca11c1f5471ebb",
          "body": "…dit H2; pure relocation, byte-identical)",
          "is_bot": false,
          "headline": "merge: decompose acp.go god-file into cohesive sibling files (arch au…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:03:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d3294820980f3915cec8fc2ab1bc80bd8e1f9c5",
          "body": "…(audit H2)\n\nPure code-organization refactor of the 1012-line internal/sidecar/acp.go\ninto intent-revealing sibling files in the same `sidecar` package. Moves\ndeclarations verbatim — no renames, no signature/logic changes. Verified\nbyte-identical: every meaningful code line in the original appears e\n[…]\nd ShutdownAgent.\n\ngo build ./..., go vet ./internal/sidecar, go test ./internal/sidecar/...,\nand go test -race ./internal/sidecar/... all green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(sidecar): decompose acp.go god-file along its concern seams …",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:03:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73d092deb9ea1f6421e57971884696a7d0264d87",
          "body": "…pability-3]\n\n# Conflicts:\n#\tinternal/sidecar/recontool.go",
          "is_bot": false,
          "headline": "merge: expose depth dial (cheap|normal|deep) on MCP recon tool [B2/ca…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T07:01:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3765cd44de59cd7a9015e3ab31bc0f1297b193a6",
          "body": "…TAR cap 3)\n\nThe CLI has `--depth cheap|normal|deep` but the MCP recon tool hardcoded\ndepth=\"normal\", leaving the main-agent consumer path unable to steer recon\nbudget. Add a `depth` param to ReconMCPTool and forward it through the same\nAskRequest.Depth field the CLI uses (session_options.go depthBu\n[…]\nr.ReconMCPTool())). The eval tests\nassert hash recomputability + shape, not a frozen value, so they stay green\n(TestMockHostTrialArmB verified).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sidecar): expose recon depth dial on the MCP recon tool (NORTH_S…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T06:59:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45d4ee2c51524aacf1a28a8ebd0a8f06e827e2c9",
          "body": "…lices complete; docker grader + ≤5-ep smoke owed on a docker machine\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(adr): ADR-0032.1 S4 implementation note — corpus landed, all 4 s…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T06:56:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "66e0e67261b2d985d872ed71b9979cb35c85af00",
          "body": "…ement (ADR-0032.1 S4)",
          "is_bot": false,
          "headline": "merge: host-task eval corpus S4 — 6 verified fixtures + canary enforc…",
          "author_name": "Goga Koreli",
          "author_login": "gkoreli",
          "committed_at": "2026-07-07T06:55:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 37,
      "commits_last_year": 598,
      "latest_release_at": "2026-07-08T02:49:04Z",
      "latest_release_tag": "v2.9.0",
      "releases_from_tags": false,
      "days_since_last_push": 8,
      "active_weeks_last_year": 12,
      "days_since_latest_release": 20,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/gkoreli/ghx/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/gkoreli/ghx/v2",
          "is_deprecated": false,
          "latest_version": "v2.9.0",
          "repository_url": "https://github.com/gkoreli/ghx",
          "versions_count": 34,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-08T02:47:49Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 20
        },
        {
          "name": "@gkoreli/ghx",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "github",
            "cli",
            "code-exploration",
            "agent",
            "graphql",
            "code-map"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@gkoreli/ghx",
          "is_deprecated": false,
          "latest_version": "2.9.0",
          "repository_url": "https://github.com/gkoreli/ghx",
          "versions_count": 29,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2137,
          "first_published_at": "2026-03-08T16:51:39.704000Z",
          "latest_published_at": "2026-07-08T02:50:31.403000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 20
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        ".mise.toml"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 35342,
      "source_files_sampled": 245,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 19522
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 6,
        "malicious_count": 0,
        "assessed_package": "npm:@gkoreli/ghx@2.9.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/bmatcuk/doublestar/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.10.0"
        },
        {
          "name": "github.com/cli/go-gh/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.13.0"
        },
        {
          "name": "github.com/coder/acp-go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.5"
        },
        {
          "name": "github.com/dop251/goja",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260311135729-065cd970411c"
        },
        {
          "name": "github.com/evanw/esbuild",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.27.4"
        },
        {
          "name": "github.com/mark3labs/mcp-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "github.com/odvcencio/gotreesitter",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.4"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/proto/otlp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 6,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "gkoreli",
          "commits": 598,
          "avatar_url": "https://avatars.githubusercontent.com/u/243085293?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "auto-tag.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "719cb293a61532b9db6771e631ecf16e687f495b",
        "ran_at": "2026-07-28T07:43:35Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T16:16:35Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-19T16:16:34Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/gkoreli/ghx",
    "host": "github.com",
    "name": "ghx",
    "owner": "gkoreli"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 48,
        "vitality": 75,
        "community": 32,
        "governance": 46,
        "engineering": 69
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "commits_last_year": 598,
              "human_commit_share": 1,
              "days_since_last_push": 8,
              "active_weeks_last_year": 12
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "12/52 weeks with commits",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 12
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "598 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 598
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 37,
              "latest_release_tag": "v2.9.0",
              "releases_from_tags": false,
              "days_since_latest_release": 20,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "37 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 37
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 20 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 32,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "github.com/gkoreli/ghx/v2",
                "@gkoreli/ghx"
              ],
              "dependents": null,
              "ecosystems": "go, npm",
              "total_downloads": null,
              "monthly_downloads": 2137
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,137 downloads/month across go, npm",
                "points": 44.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2137,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 46,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 6,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "6/6 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 6,
                      "decided": 6
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "critical",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 21,
            "inputs": {
              "followers": 0,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "gkoreli",
              "public_repos": 5,
              "account_age_days": 259
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of gkoreli",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "gkoreli"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~0 yr old",
                "points": 7.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/gkoreli/ghx/v2",
                "@gkoreli/ghx"
              ],
              "ecosystems": "go, npm",
              "any_deprecated": false,
              "min_days_since_publish": 20
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 20 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 69,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "ai-agents",
                "cli",
                "code-search",
                "developer-tools",
                "github",
                "golang",
                "mcp"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/@gkoreli/ghx",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@gkoreli/ghx",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 48,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@gkoreli/ghx@2.9.0 runtime dependency closure — what installing the published package pulls in — 6 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@gkoreli/ghx@2.9.0",
                  "assessed": 6
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 6,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 6,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 81,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 19522
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                ".mise.toml"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.94,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": ".mise.toml",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".mise.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "94 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 94,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 35342,
              "source_files_sampled": 245,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/245 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 245,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T07:43:44.484985Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/gkoreli/ghx.svg",
  "full_name": "gkoreli/ghx",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go, npm.