公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 01:22 UTC

kernel / cua

computer use cli / sdk for agent builders

TypeScript未检测到许可证★ 4 星标⑂ 0 复刻始于 2026年4月在 GitHub 上查看 ↗

kernel/cua 的健康指数为 100 分中的 49 分,处于「存在风险」区间。 其得分最高的类别是Engineering Quality(74/100),最低的是Community & Adoption(29/100)。 最近一次更新在 5 天前。 近期的大部分工作由 1 位贡献者完成。

49
总分 / 100
存在风险

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

49
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

KERNEL组织
236 关注者73 个公开仓库始于 2025年1月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
npm@onkernel/cua-ai0.7.04,961145 天前
npm@onkernel/cua-cli0.5.01,552105 天前
npm@onkernel/cua-agent0.7.04,951135 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

44存在风险 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 5 天前
9/36提交节奏 — 52 周中有 13 周有提交
17.5/18提交量 — 最近一年 88 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year88
human_commit_share1
days_since_last_push5
active_weeks_last_year13
评分方式
0/27有发布版本 — 未发布任何发布版本
0/36发布时效 — 没有发布版本
0/27发布节奏 — 没有发布版本
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count0
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

29危急 · 占总体的 18%
评分方式
7.7/60星标 — 4 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 1 位关注者
所用输入
forks0
stars4
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

25危急
评分方式
22.5/22.5README
0/22.5许可证 — 未检测到许可证文件
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
54.1/80月度下载量 — npm 合计每月 11,464 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@onkernel/cua-ai, @onkernel/cua-cli, @onkernel/cua-agent
dependents
ecosystemsnpm
total_downloads
monthly_downloads11,464
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

58中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
3.8/22.5提交分布 — 头号贡献者编写了 83% 的提交
4.1/13.5贡献者广度 — 3 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled3
top_contributor_share0.83
评分方式
0/46.8议题解决 — 没有议题或无数据
34.8/38.3PR 接受 — 已裁定的 PR 中 50/55 已合并
0/15OpenSSF Scorecard:Code-Review — Found 1/21 approved changesets -- score normalized to 0
所用输入
merged_prs50
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs5
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
17.1/25所有者影响力 — kernel 有 236 位关注者
16/25既往记录 — 73 个公开仓库,账户约 1 年
所用输入
followers236
owner_typeOrganization
is_verified
owner_loginkernel
public_repos73
account_age_days557
评分方式
25/25已发布且可解析 — npm 上有 3 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 14 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@onkernel/cua-ai, @onkernel/cua-cli, @onkernel/cua-agent
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

74良好 · 占总体的 20%

工程实践

64中等
评分方式
24/24CI 工作流 — 4 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
16/20OpenSSF Scorecard:CI-Tests — 17 out of 19 merged PRs checked by a CI test -- score normalized to 8
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

90优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://www.kernel.sh
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepagehttps://www.kernel.sh
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

35存在风险 · 占总体的 16%

安全态势

35存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2/2.5CI-Tests — 17 out of 19 merged PRs checked by a CI test -- score normalized to 8
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/21 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5许可证 — license file not detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3.5
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

55中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 88 次人类提交中有 68 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.773
agent_instruction_files
agent_instruction_max_bytes
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json
10/10可复现环境 — lockfile
10/10已体现的代理实践 — 最近 88 次提交中有 41 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
2/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
所用输入
has_nix
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configspackages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json
agent_commit_share0.466
toolchain_manifests
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
54.6/55可控的文件大小 — 采样的 137 个源文件中有 1 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes66,935
source_files_sampled137
oversized_source_files1

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

4GitHub 星标
3贡献者
88最近 12 个月提交数
5距最近推送天数
0发布版本数
1巴士系数(bus factor)
0开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package '@onkernel/ptywright' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@onkernel/cua-ai@0.7.0; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 3.5 / 10
3.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 01:22 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
8CI-Tests17 out of 19 merged PRs checked by a CI test -- score normalized to 8
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/21 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
1Vulnerabilities9 existing vulnerabilities detected
直接依赖 15
注册表软件包版本约束清单文件
npm@earendil-works/pi-agent-core0.80.10packages/agent/package.json
npm@earendil-works/pi-ai0.80.10packages/agent/package.json
npm@onkernel/cua-ai0.7.0packages/agent/package.json
npm@onkernel/sdk0.49.0packages/agent/package.json
npmsharp^0.34.5packages/agent/package.json
npm@earendil-works/pi-ai0.80.10packages/ai/package.json
npm@tzafon/lightcone^0.7.0packages/ai/package.json
npmopenai^6.26.0packages/ai/package.json
npm@earendil-works/pi-coding-agent0.80.10packages/cli/package.json
npm@earendil-works/pi-tui0.80.10packages/cli/package.json
npm@onkernel/cua-agent0.7.0packages/cli/package.json
npm@onkernel/cua-ai0.7.0packages/cli/package.json
npm@onkernel/sdk0.49.0packages/cli/package.json
npmnode-addon-api^8.7.0packages/ptywright/package.json
npmnode-pty^1.1.0packages/ptywright/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 8419,
      "has_wiki": true,
      "homepage": "https://www.kernel.sh",
      "languages": {
        "C": 12784,
        "C++": 7109,
        "Python": 1357,
        "JavaScript": 21577,
        "TypeScript": 831935
      },
      "pushed_at": "2026-07-17T18:44:32Z",
      "created_at": "2026-04-18T02:17:10Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T18:41:20Z",
      "description": "computer use cli / sdk for agent builders",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://www.kernel.sh",
      "name": "KERNEL",
      "type": "Organization",
      "login": "kernel",
      "company": null,
      "location": "United States of America",
      "followers": 236,
      "avatar_url": "https://avatars.githubusercontent.com/u/194616459?v=4",
      "created_at": "2025-01-11T15:49:38Z",
      "is_verified": null,
      "public_repos": 73,
      "account_age_days": 557
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "f1c91f7f784e6df6616bb443887701c3a8fde3ed",
          "body": "* Add Moonshot Kimi K3 computer-use provider\n\nExpose kimi-k3 as moonshotai:kimi-k3 (alias moonshot:), streaming through\npi-ai's builtin OpenAI-compatible chat completions transport with\nMOONSHOT_API_KEY. Kimi grounding emits 0-1 width/height fractions, so the\nprovider declares a fractional normalize\n[…]\nlevel in the CLI.\n\n* Trigger CI for ready-for-review run\n\n* Bump cua-ai/cua-agent to 0.7.0 and cua-cli to 0.5.0 for release\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Moonshot Kimi K3 computer-use provider (#66)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-17T18:41:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c94173d3e9561ee2b6fd02423c0d2b80a27deb16",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Unify CLI release and prerelease workflow (#62)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-14T00:59:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1d1f21e8b453f9dffa980453adc974b15301127",
          "body": "* Add Grok 4.5 computer-use provider\n\n* Map disabled Grok reasoning to low\n\n* Use pi-ai Grok model metadata\n\n* Document xAI tool contracts\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Grok 4.5 computer-use provider (#61)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-14T00:12:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52db49ee42ec36bcf3eead8929f0e153a2e79c79",
          "body": "Publish @onkernel/cua-cli from any branch under an npm dist-tag (never\n`latest`) as `<version>-<dist-tag>.<run-number>`, unique per run, so\nunmerged work can be tried via `npm install -g @onkernel/cua-cli@<tag>`.\nUnlike release-cua-cli.yml there is no \"tag on main\" gate; it publishes\nthrough OIDC trusted publishing the same way.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add workflow_dispatch prerelease publish for cua-cli (#58)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-13T23:46:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "98d013493690bd5e92c11e3e9420687ecc8ebad5",
          "body": "* Add Meta Muse Spark provider\n\n* Prefer scoped Meta API key name\n\n* Harden Meta live test setup\n\n* Address Meta provider review findings\n\n* Resolve Meta smoke fixture across workspaces\n\n* Simplify Meta provider integration\n\n* Drop Meta action alias normalization\n\n* Sanitize Meta payload after hooks\n[…]\nts after shared threading\n\n* Remove Meta-specific e2e gate\n\n* Document Meta response threading\n\n* Format exported API TSDoc\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Meta Muse Spark computer-use provider (#59)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-13T17:12:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a88952d62d80e8fc3d52eec41cd8d82bf43ad04",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Prepare CUA package releases (#57)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T18:53:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e53c87a01bc260e9498adb3015e3a0982f60dbb9",
          "body": "* Retry empty CUA responses once\n\n* Make empty response recovery explicit\n\n* Reset harness queue state between prompts\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add opt-in recovery for exact-empty CUA responses (#55)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T16:28:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5b01284158a94ccd42fe33e793bda0440b1229c",
          "body": "* Add --proxy flag to route the browser through a Kernel proxy\n\nAccepts a proxy id or name, resolved via proxies.retrieve with a\nlist-by-name fallback; ambiguous names and unknown selectors are errors\n(proxies are never auto-created, unlike --profile). Applies to one-shot\nsubcommands and session start; named sessions persist the resolved\nproxy_id in their metadata.\n\n* Bump cua-cli 0.3.1 for the --proxy flag release\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add --proxy flag for routing the browser through a Kernel proxy (#56)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T16:08:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03016f99ce09a2ef0442b73d380a1c0a35e0e3b1",
          "body": "* Bound retained tool result images\n\n* Configure tool result image replay\n\n* Document image replay limit type\n\n* Apply response threading policy to all model calls\n\n* Compose harness context hooks with image limits\n\n* Apply image limits to all model calls\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Configure CUA image context and response threading (#53)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T16:06:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88b101a801a3a17d3eb6547e77a0b08bbe4e30ab",
          "body": "* Retry transient provider errors\n\n* Make provider retries configurable\n\n* Preserve provider replay failures\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add configurable retries for transient provider errors (#54)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-10T14:21:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3caf6cc7f07117982184db043185480e2233b850",
          "body": "… computer/browser tools (#51)\n\n* Add action-plane modes (os/dom/hybrid) and Anthropic native computer/browser tools\n\n* Add setMode/getMode, /mode slash command, and live-API schema fix\n\n- CuaAgent.setMode / CuaAgentHarness.setMode switch action planes at\n  runtime (rejected when it conflicts with a\n[…]\nordinates); mode switches keep it. Drop the\ntranslator's dead mode option.\n\n---------\n\nCo-authored-by: hypeship <hypeship@onkernel.com>\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add action-plane modes (computer/browser/hybrid) and Anthropic native…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-09T19:25:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f3fe8d23f9f70c68f7911e8619028cfafc108aa",
          "body": "* Adopt pi 0.80's instance-based Models API across cua-ai, cua-agent, cua-cli\n\npi-ai 0.80 replaced the global api-registry and free-function catalog/stream\nsurface (getModel, getModels, streamSimple, registerApiProvider, ...) with an\ninstance-based Models API. Adopt it directly instead of the deprec\n[…]\nto resolve. Users pin\nthe family id; drop the snapshot rather than maintain it. The gpt-5.5 family\nannotation is unchanged.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Adopt pi 0.80's instance-based Models API (#50)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-07-08T14:35:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba6d43c2aa3a316686a902da2b07ec626738d34e",
          "body": "* packages/ai: adapt Sonnet 5 thinking payload\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* packages/ai: broaden adaptive thinking support\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* packages/agent: loosen payload hook assertion\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "packages/ai: adapt Anthropic thinking payloads (#49)",
          "author_name": "Mason Williams",
          "author_login": "masnwilliams",
          "committed_at": "2026-06-30T19:07:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a8b34fe76f9b5d1a41f779f27664c34ac972dbc4",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release CUA AI v0.3.3",
          "author_name": "Mason Williams",
          "author_login": "masnwilliams",
          "committed_at": "2026-06-30T18:31:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "53040a960f68a320b2cf351f65a56519ffeb3626",
          "body": "Annotate the claude-sonnet-5 family as CUA-supporting and register a\nCUA_MODEL_OVERRIDES entry so getCuaModel() resolves anthropic:claude-sonnet-5\nbefore pi-ai's registry carries it. Update the supported-models snapshot.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "packages/ai: add computer-use support for claude-sonnet-5 (#48)",
          "author_name": "Mason Williams",
          "author_login": "masnwilliams",
          "committed_at": "2026-06-30T18:30:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4a73fbd9f695806515611107d34abfe756fc0d17",
          "body": "…#46)\n\n* Thread Tzafon requests with previous_response_id + delta input\n\nAdd a shared response-threading capability (responseThreadingEnabled with\nCUA_DISABLE_RESPONSE_THREADING opt-out) and a pure responseThreadingDelta util\nthat finds the most recent assistant responseId and returns the messages a\n[…]\n's builtin\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Thread previous_response_id through Tzafon and OpenAI CUA providers (…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-29T14:03:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "79e1df44241d627bc50c35c5bdee43df0920262d",
          "body": "…h release\n\ncua-ai 0.3.2 adds computer-use support for gemini-3.5-flash. Bump the\ninter-package dependency pins so the release workflows can publish cua-ai,\nthen cua-agent, then cua-cli in dependency order.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump cua-ai 0.3.2, cua-agent 0.3.5, cua-cli 0.1.4 for gemini-3.5-flas…",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-24T19:39:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1d426c34d148dd4d88d835ea82f308014fc1ac90",
          "body": null,
          "is_bot": false,
          "headline": "Add gemini-3.5-flash to supported CUA models (#38)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-24T18:48:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f406ffb38b7bd1c9fba80e73e94f7e107211a16e",
          "body": "…ute release (#37)\n\nThe playwright_execute feature spans all three packages; none are published\nwith it yet. Bump versions (and inter-package dep pins) so the release\nworkflows can publish cua-ai, then cua-agent, then cua-cli in dependency order.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump cua-ai 0.3.1, cua-agent 0.3.4, cua-cli 0.1.3 for playwright_exec…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-23T22:11:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6c4740c800260f54c1d8425ee383c3dcb61263a1",
          "body": "Add opt-in playwright_execute tool to the CUA agent and CLI",
          "is_bot": false,
          "headline": "Merge pull request #33 from kernel/hypeship/cua-playwright-execute-tool",
          "author_name": "Daniel Prevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-23T21:18:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f855cf105d518990ac44ae821de1d8d15911c57c",
          "body": "…/stderr details\n\nplaywright_execute is frequently a pure read where forcing a screenshot wastes\nimage tokens and latency. Let the model request one on a follow-up turn. The\nexisting content.length === 0 → statusText fallback keeps content non-empty\nfor side-effect-only calls.\n\nAlso tighten the Play\n[…]\nl-exhaustiveness.test.ts: flip the trailing-image\n  assertions to assert no image is appended; drop the unused captureScreenshot\n  mocks; add a side-effect-only case that hits the statusText fallback.",
          "is_bot": false,
          "headline": "Drop auto-appended screenshot from playwright_execute; clarify stdout…",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-23T20:06:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1121e22170792922b421dacc36ed1c0efb8deece",
          "body": "The package now publishes to npm, so the install instructions should use a\nregistry install instead of running from source. Bump the version so the\nupdated README is republished.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Point cua-cli README install at the npm registry; bump to 0.1.2 (#34)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-22T22:19:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d746e8c6cd2abbe2fb3ee4b7a1b228190568fdc5",
          "body": "- executePlaywright: timeout_sec values below 1s previously truncated\n  to 0 and were forwarded to the SDK, which differs from omitting the\n  field. Floor the truncated value at 1s; anything sub-second falls\n  back to \"use server default\".\n- Document PlaywrightDetails fields so library consumers know what\n  each one means without reading the executor source.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bugbot fixes: sub-second timeout floor and PlaywrightDetails TSDoc",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T20:26:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "565fe015f5045f2f8b9888bbbdf5c1a086e065ac",
          "body": "Matches executeBatchTool's shape: the trailing translator.screenshot()\nlives inside the same try/catch as the underlying work, so any failure\nin the pipeline produces a single wrapped tool error rather than\ndiverging based on which step failed.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wrap playwright_execute screenshot in the same try as the execution",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T20:17:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "302fc14c424bc22f1362d25a6d08ef3e5ef548d2",
          "body": "Empirical results show CUA-specialized providers (Tzafon, Yutori) do\nemit playwright_execute calls — earlier docs were overly cautious.\nYutori in particular demonstrates the failure-as-content design well:\nit iterated through two wrong-API attempts (page.querySelector, bare\ndocument) before reading the stderr/error blocks and landing on\npage.evaluate(), which throwing would have prevented.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Update playwright_execute docs after Tzafon and Yutori e2e verification",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T19:00:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "11afbbfc9a03617bc4589605f6eebb00ec77ba63",
          "body": "formatPlaywrightResult's JSON.stringify try/catch guarded against\nnon-serializable values, but execution.result came from the SDK after\na JSON round trip through the wire — anything that survived that is\nalready JSON-safe, so the catch arm is unreachable.\n\nThe executePlaywright timeout chain checked\n[…]\n parameter is TS-typed number | undefined) and Number.isFinite\n(redundant — timeoutSec > 0 already rejects NaN, and Math.min handles\nInfinity).\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Deslop: drop dead defensive checks around playwright_execute",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T18:46:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "849f6a4cfc7e05f0a207114f2c6068ec6e2c77c6",
          "body": "- packages/agent: list playwright option alongside computerUseExtra and\n  add a paragraph explaining the tool's behavior and tested-models scope.\n- packages/ai: list the new tool-definition factory, schema, constants,\n  and CuaPlaywrightInput type in the API surface index.\n- packages/cli: document --playwright with a short explainer.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document playwright_execute in package READMEs",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T18:18:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5ddf0e50b9dbb6e47725d3af977403bc44586048",
          "body": "Schema description tells the model \"max 300\" but nothing enforced it.\nA model that ignored the bound would have hit a confusing SDK-level\nfailure depending on server behavior; this clamp keeps the client\nhonest to the documented contract.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Clamp playwright_execute timeout to the documented 300s server max",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:52:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e96be94b9962ad90c88c9cc0d98bc2be84cde9cb",
          "body": "Earlier review feedback dropped \"Defaults to 60\" out of a worry that the\ndefault lived in the SDK and could drift. The kernel.sh docs put both\nthe default (60s) and the cap (300s) on the server, so the description\nis the authoritative place to surface them — the model can't choose a\nsensible timeout without that anchor.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Restore documented timeout default and add the 300s max",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:47:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "49e6f155262283b9355fbbc002823dd394fd7605",
          "body": "Locals don't persist across calls but the browser session does. Without\nthis, a model could write code in call N assuming variables from call\nN-1 are still in scope.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document fresh-context-per-call in playwright_execute description",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:43:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9fa28705695ec289395f860c7811cfc89aa296f3",
          "body": "- Drop misleading \"Defaults to 60\" from timeout_sec description; the\n  actual default lives in the Kernel SDK, not here.\n- Expose result/stdout/stderr/error on PlaywrightDetails so library\n  consumers can branch on the structured execution result without\n  re-parsing tool content text.\n- Guard forma\n[…]\nr refs) so a successful Playwright run never\n  becomes a tool-level error.\n- Sync package-lock.json to match the cua-cli 0.1.1 bump in a7cdc07.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Address self-review feedback on playwright_execute",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-20T14:41:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b930ca1e2f22e73886cd059dca688109010a895c",
          "body": "Exposes a tool that runs Playwright/TypeScript directly against the\nbrowser session (via the Kernel SDK browsers.playwright.execute) for\nsteps that are awkward as raw pointer/keyboard actions. Modeled on the\nexisting computer_use_extra navigation tool: defined in cua-ai, executed\nthrough the transla\n[…]\nad. Enable with the\n`--playwright` CLI flag. Returns result/stdout/stderr and appends a fresh\nscreenshot so the screenshot loop stays coherent.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add opt-in playwright_execute tool to the CUA agent and CLI",
          "author_name": "dprevoznik",
          "author_login": "dprevoznik",
          "committed_at": "2026-06-19T21:51:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5f5612b505fc9e9b7a3caf0d7fc7c7dec5dd94cf",
          "body": "The extracted ghostty source has no .git, so ghostty's version detection\nwalks up into the host repo and panics on a non-vX.Y.Z tag (e.g. a\ncua-cli/vX.Y.Z release tag). Passing -Dversion-string short-circuits git\ndetection, making the native build independent of host git state.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Pin ghostty version-string so native build ignores host git tags",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-14T03:12:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a7cdc0719e317ebde43511d2ed7b3e8d57eeb0b3",
          "body": "Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump @onkernel/cua-cli to 0.1.1",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-14T03:04:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3712e73cc936cc8427d22e5bb3ae0278b65deccb",
          "body": "* Discover skills and context via pi resource loader\n\nReplace the hand-rolled skill scan in harness-skills.ts with pi's\nDefaultResourceLoader so installed-package skills load (the loader is a\nstrict superset of the old ~/.agents/skills discovery). Bridge pi's\nskill file paths back through cua-agent'\n[…]\nn field,\nand document that --no-skills leaves context files intact.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Load installed-plugin skills and align cua-cli startup with pi (#32)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-13T23:44:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae102c61f1e53ff8d5bb10d3276a113c24c615b4",
          "body": "npm 11.17 requires an explicit permission flag on npm trust; the release\nworkflows run a full npm publish, so --allow-publish is the right grant.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add required --allow-publish flag to npm trust commands (#31)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T20:04:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0da96b2fdf9efc7593e61804bd91578ec111342e",
          "body": "* Fix ESM import specifiers in cua-cli and smoke-test the bin in CI\n\npackages/cli used extensionless relative imports, which compile cleanly\nunder moduleResolution Bundler and work in vitest, but fail at runtime\nwith ERR_MODULE_NOT_FOUND when Node executes the published dist. Add .js\nextensions to a\n[…]\nclaration-only emit to dist-tsc for typechecking, tsdown owns dist/,\nand the root build bundles the cli after typechecking.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Bundle cua-cli with tsdown; smoke-test the bin in CI (#30)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T19:33:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16ac531aa6eb2eab80aae766bf4ac8ff5ca9a06e",
          "body": "The root build and typecheck scripts ran tsc -b before @onkernel/cua-agent's\ntsdown build, so packages/cli was type-checked against a missing (fresh\nclone) or stale (previously built checkout) dist/index.d.ts. Reorder the\nscripts so workspace dist artifacts exist before tsc -b runs, and add a\ntypech\n[…]\naned @mariozechner/* 0.67 entries and their unreferenced\ntransitive deps from package-lock.json (leftover from the pi 0.79 migration).\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Build agent dist before tsc -b and typecheck the workspace in CI (#29)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T18:15:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9258f47300dd360cd328d74b1818e69de5ab44d1",
          "body": "* Set up npm release workflow for @onkernel/cua-cli\n\n* Address review for cua-cli release setup\n\n- docs: add pre-publish smoke test step (npm pack + install + cua --help)\n  to the first-publish runbook, so a maintainer following it verbatim does\n  not ship a broken 0.1.0 to npm.\n- docs: list @earend\n[…]\nckages/ai and packages/agent entries by adding license MIT and engines\n  node >=22.19.0 to match the package.json metadata.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Set up npm release workflow for @onkernel/cua-cli (#28)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T16:11:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fec4254776e814eab4cf1e7fd484fd946669f11f",
          "body": "* Drop bin/cua, fold DESIGN.md into architecture.md, delete .cursor\n\n- Remove bin/cua wrapper and update install paths in README.md and\n  packages/cli/README.md to run the CLI via npx tsx from source. The\n  wrapper assumed a built dist/cli.js that's currently broken at runtime\n  in the workspace.\n- \n[…]\ned to npm.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Drop bin/cua, fold DESIGN.md into architecture.md, delete .cursor (#27)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T15:17:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c720368ca25024c0ea05a39d5279687158928abc",
          "body": "Move the CLI workspace directory to packages/cli. The npm package name\n(@onkernel/cua-cli), binary name (cua), and workspace identity are all\nunchanged. Updates root package.json workspaces, tsconfig project\nreferences, package-lock.json paths, bin/cua wrapper, README workspace\ntable and Mermaid dia\n[…]\n) keep\ntheir prose as-is. Tests under packages/cli still pass (29 passed, 4\nTUI fixture tests skipped without ptywright native build).\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Rename packages/cua-cli to packages/cli (#26)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T14:34:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1e89dd549d39aad6dd84f751150aa5ae60f8b6a",
          "body": "* PR 4: remove deprecated provider packages from workspace\n\nDeletes packages/cua-{translator,openai,anthropic,gemini,tzafon,yutori}\nnow that cua-cli is fully migrated to CuaAgentHarness + pi 0.79. Updates\nthe root package.json workspaces, root tsconfig references, README\n(workspace tree, mermaid, pa\n[…]\nen\n- add cli-harness.ts to the CLI runtime flow inventory in\n  docs/architecture.md and .agents/skills/update-docs/SKILL.md\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 4: remove deprecated provider packages from workspace (#25)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T06:25:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a5b61dce17d7a8007ba3ad28da8ffd8d555dd71",
          "body": "* PR 3: purge legacy pi 0.67 wiring from cua-cli\n\nDelete the dead pre-harness source files (agent.ts, agent-prompt.ts,\nold models.ts, config.ts, old sessions.ts, skills.ts, old named-sessions.ts,\nold action/runner.ts, old output/jsonl.ts) now that the harness paths from\nPR 1 and PR 2 cover every CLI\n[…]\nhe documented command would now\nfall through to interactive mode and start a TUI run with the literal\nprompt \"config init\".\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 3: purge legacy pi 0.67 wiring from cua-cli (#24)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T05:48:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2218ddddc75491887afed797f1c4ee2badd267bf",
          "body": "* PR 2: rebuild interactive TUI on CuaAgentHarness + pi-tui 0.79\n\nPer the migration plan (docs/cua-cli-harness-migration.md), the interactive\nTUI moves off the legacy provider-wiring stack and onto the harness:\n\n- tui/main.ts subscribes to harness.subscribe() and routes\n  AgentHarnessEvent into a pi\n[…]\nspawns 'zig ar -M' directly,\nso the cached zig binary must be discoverable on PATH for the\nnative binding build to succeed.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 2: rebuild interactive TUI on CuaAgentHarness + pi-tui 0.79 (#23)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T05:22:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a95e2d03906151976285f5fe49ef722151337cd",
          "body": "* Wire cua-cli non-interactive paths onto CuaAgentHarness\n\nPR 1 of the cua-cli → CuaAgentHarness migration plan\n(docs/cua-cli-harness-migration.md). Wires the non-interactive\nsurface of cua-cli onto CuaAgentHarness + pi 0.79 while leaving the\ninteractive TUI on the legacy stack for now.\n\nEngine:\n- h\n[…]\nt 2, the turn-cap abort path, jsonl tool steps,\n  the first-prompt screenshot, and --session <path> from a different\n  cwd.\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "PR 1: wire cua-cli non-interactive paths onto CuaAgentHarness (#22)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T04:05:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6ad0104d15d2824d7351f702327102e4e29d138",
          "body": "Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add cua-cli → CuaAgentHarness migration plan",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T02:52:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a3c606c191dad6a99f4561263c535276268f308",
          "body": "v4 of both actions runs on the Node.js 20 actions runtime, which GitHub\ndeprecates and force-switches to Node 24 on 2026-06-16; v5 targets the\nNode 24 runtime directly.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump checkout and setup-node actions to v5",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T01:55:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "efd8132084dece65045722a18c132ef7930d523f",
          "body": "…#21)\n\n* Tighten cua-agent design seams from review\n\n- The translator now consumes the canonical CuaAction union with an\n  exhaustive switch instead of re-parsing untyped records; malformed\n  shapes can no longer silently coerce to 0,0 clicks, and drift in the\n  canonical vocabulary becomes a compil\n[…]\ngent 0.3.3\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Tighten cua-agent design seams: typed translator, declared channels (…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-12T01:35:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "19ec1d21d81c7a256ac562496850c4f785f2fc07",
          "body": "PR CI previously ran only cua-ai unit tests and cua-agent's live e2e file, so\ncua-agent's unit suite ran solely in the release workflow and cross-package\nbreakage surfaced at release time. Add an agent-unit job that builds cua-ai and\nruns the cua-agent unit tests on every PR.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add cua-agent unit tests to CI",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T22:35:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "77af0f4b2e67adc25488ed7c3a61613c2efdd8c5",
          "body": "The google:gemini-3-pro-preview annotation was removed from cua-ai, leaving\nthis test resolving an unsupported model id and failing the cua-agent release\nworkflow's unit-test gate. Switch the model-change fixtures to the still-\nsupported google:gemini-3-flash-preview.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix cua-agent test referencing retired gemini-3-pro-preview model",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T22:19:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "33ee377c6c75addcc2ecc292afa3d553c45b4a3b",
          "body": "Add gpt-5.4-mini, gemini-3.1-flash-lite, and tzafon northstar-cua-fast 1.6/1.7 CUA annotations; remove retired gemini-3-pro-preview; bump cua-ai to 0.2.2 and cua-agent to 0.3.2.",
          "is_bot": false,
          "headline": "Add CUA model annotations and drop retired gemini-3-pro-preview (#20)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T22:11:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8881321f2f5401059b7c67e7de9989e3f51b9455",
          "body": null,
          "is_bot": false,
          "headline": "Release CUA AI v0.2.1 and CUA Agent v0.3.1",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T21:10:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df4799aa86d395cff86f0ba56e6ec30df28fa332",
          "body": "…(#19)\n\nThe update-models skill still pointed at the older cua-cli + cua-*\nadapter stack for the model list and adapter constants. Repoint it at\npackages/ai (@onkernel/cua-ai), which is the source of truth for\ncomputer-use model support: CUA_MODEL_ANNOTATIONS / CUA_MODEL_OVERRIDES,\nlistCuaModels()/g\n[…]\nt (and fable-5) to the discovery script's newer-tool/beta\n  runtime-pair list so they are not falsely flagged as runtime\n  mismatches.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Retarget update-models skill to packages/ai and add Fable 5 coverage …",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-11T20:58:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0bb4a875a974c8449a47ca0c1416136a68cd35be",
          "body": null,
          "is_bot": false,
          "headline": "De-vendor pi-agent-core and slim cua-agent to a light wrapper (#17)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-10T21:45:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd8043fb94c71e74e124c4cff45e0a6e765380d8",
          "body": "* Fix cua-ai ESM packaging and CI test coverage\n\nSwitch packages/ai to NodeNext module resolution and add explicit .js\nextensions to relative imports so the published dist loads in plain\nNode ESM (previously failed with ERR_UNSUPPORTED_DIR_IMPORT). Run the\nfull unit suite in CI and release instead o\n[…]\ne cleanly.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix cua-ai ESM packaging, error-handling docs, API consistency (#18)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-10T20:56:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d3beac2b81a6dec80ec1b5e166bf4cf36944991b",
          "body": "* Use explicit Anthropic computer tools\n\n* Introduce CuaProviderModule contract in cua-ai\n\nReplace the per-provider switch in resolveCuaRuntimeSpec with a registry\nlookup over provider modules that conform to a shared CuaProviderModule\ninterface. Adding a provider is now \"write the module, add one l\n[…]\n: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Use explicit Anthropic computer tools (#16)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-06-03T21:06:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "602e2a9cb6967c8c0a7fffc194fe533388dae4a0",
          "body": "* Use Yutori native tool sets\n\n* Address Yutori native tool review\n\n* Wire Yutori runtime hooks through CUA agent\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Use Yutori native tool sets (#15)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-20T18:22:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b737c5739b110f48f8d35e61d6c05a6df00fc07c",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release CUA Agent v0.2.0",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-14T03:04:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "18af410856394e58f1ffb0c57ae71a674a9a70d1",
          "body": "* Add CUA AgentHarness model switching\n\n* Fix CUA agent keypress shortcuts\n\n* Preserve harness active tools on model switch\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add provider-aware CUA AgentHarness (#12)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-14T03:01:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e5e122091aa19747a07101f4d1997fc1a1279fd",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Clarify cua-ai runtime spec docs (#13)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-14T02:01:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca12c0ef08a005dd2a6a5dd9cf4de008e09c3afb",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add npm release workflows (#11)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T21:07:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7df5044516d5ee199b1bf5fc6105bf4ee1e1f6be",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Clarify harness use in agent README (#10)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T19:24:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96047e8c982f4aef76f564dc001890184b30b436",
          "body": "* Add class-based CUA runtime surfaces and runtime spec plumbing\n\nSwitch cua-agent to class-first CuaAgent/CuaHarness constructors, centralize provider-specific defaults in cua-ai via resolveCuaRuntimeSpec, and add exhaustive tool coverage plus live e2e scenarios to validate browser execution across\n[…]\nnd runtime spec matching).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add class-based CUA agent surfaces and runtime spec (#8)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T19:20:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1740619ad497db1f4540eaad4fbc9e64a777db37",
          "body": "Co-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Gemini 3 Pro CUA model (#9)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T19:05:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ba105afbf30fc16dbf05643ee90eda3e28fd82f",
          "body": "…s (#7)\n\n* ai: tighten public surface and document CuaProvider + supported models\n\n- Un-export parseCuaModelRef/formatCuaModelRef (internal helpers).\n- Add docs/supported-models.md enumerating CUA-supported models per\n  provider with source citations, linked from README.\n- Add a CuaProvider section \n[…]\n fails CI.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ai: tighten public surface and document CuaProvider + supported model…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-13T18:31:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3135a5dbe8c0c54fc3a25062d9f1ac10b2d6d8ee",
          "body": "* Test and harden batch_computer_actions across providers\n\n- Add provider-by-provider unit coverage for the batch tool schemas.\n- Add integration tests (env-gated) that hit each provider live and\n  verify the response contains a parsed batch_computer_actions call.\n- Tzafon: unwrap stringified nested\n[…]\nri: translate type, goto_url, mouse_down, mouse_up, hover, hold_key\n\n---------\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Test and harden batch_computer_actions across providers (#3)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T16:02:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8811f3b2cb41125d15edbbcad1104dcc42c3987",
          "body": "…upe typebox (#6)\n\nThree related cleanups in @onkernel/cua-ai.\n\n1. Provider re-registration. pi-ai's register-builtins module eagerly\n   registers openai-responses, anthropic-messages, and\n   google-generative-ai when the package is imported. The CUA layer was\n   re-registering them with the same la\n[…]\n all have stream/\nstreamSimple functions wired up after importing the package.\n\nCo-authored-by: rgarcia <72655+rgarcia@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ai: drop redundant built-in re-registration, remove dynamicModel, ded…",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T14:07:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "697319858d41ca6e3fd93a29645574ba1175e4d0",
          "body": null,
          "is_bot": false,
          "headline": "ai: replace CUA model regex allowlist with annotation table (#5)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T13:44:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e728095315511e5035a08304967109bd62bbfa0e",
          "body": null,
          "is_bot": false,
          "headline": "Document provider-native CUA action vocabularies (#4)",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T13:17:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dea327387e02ad6e237b64f24c47720f4d8eab1",
          "body": "Migrate pi-ai/pi-agent-core to @earendil-works scope",
          "is_bot": false,
          "headline": "Merge pull request #2 from kernel/hypeship/migrate-pi-to-earendil-works",
          "author_name": "Rafael",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T12:21:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c67b48e4fc41201c45180ff24644c8a55709fbe",
          "body": "The @mariozechner/pi-* packages are deprecated and the repo moved from\nbadlogic/pi-mono to earendil-works/pi. Updates packages/ai and\npackages/agent to the new @earendil-works/pi-* packages at 0.74.0, which\nalso renames @sinclair/typebox to typebox (v1, schemas are unchanged).\nREADME, doc, and skill\n[…]\ne new GitHub URL and\nnpm names; deprecated cua-* package READMEs are updated for users who\nfollow them, but their pinned npm deps are left alone since the packages\nare being absorbed into packages/ai.",
          "is_bot": false,
          "headline": "Migrate pi-ai/pi-agent-core to @earendil-works scope",
          "author_name": "rgarcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-12T12:11:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acd224870672902a6f46f0a4ce89cc9ef0752bc9",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Document CUA provider coordinate metadata",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-03T02:19:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e5584ae9883f030aeb2cc73822c63abb47ec3021",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Decouple CUA AI quickstart from CLI config",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T20:14:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f6864ec5f830836478f45cc1ac55da6ca3c14669",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add provider-scoped CUA tool definitions",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T19:55:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5ca68471f8fe805d73edb41a4ed9081bd4388254",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Simplify CUA model info",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T19:31:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "063bf8c81b2a6422df0176617a93d77dffd07914",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add CUA AI quickstart example",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T19:06:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "91621dcd5a48665a31e135a48b5dbb29a4700cd3",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Refine CUA AI package README",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T18:46:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "657b7c78bb87bea2550ce4ab0ed3a889f4c639eb",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add CUA AI and agent SDK packages",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-05-01T17:27:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2f7a2aeba4c28883ed85d326eda1534c5e3fa251",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Add Yutori provider support.",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-30T20:21:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4bfae4bc94c72ebdde8f87e56812dda141899f8",
          "body": null,
          "is_bot": false,
          "headline": "package.json tweaks",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-30T14:28:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25abde5b8bff4d31a77651b75e84e9cc02444919",
          "body": null,
          "is_bot": false,
          "headline": "compaction and previous response id for oai",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-30T14:27:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5099544a24c99aa2fe7552dabb39577aef8c4c91",
          "body": "Use Anthropic's model-compatible computer tool beta for Haiku and make update-model validation distinguish provider fallback support from the local runtime path.\n\nMade-with: Cursor",
          "is_bot": false,
          "headline": "Fix Haiku computer tool selection",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T02:04:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfb6c48939ce969ea8baaafd7166535290d1d5f0",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Document provider boundary invariant",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T02:03:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ff9199976f8f171d44b265fff7fe17123267525",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Document architecture invariants and docs workflow",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T01:56:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9d32cb90565c271895eb5dc30fa3b6165778e4c",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Remove unsupported GPT-5.5 Pro models",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T01:46:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea0c3578ece8999b9f2c5a27629dc49fad6277da",
          "body": "Made-with: Cursor",
          "is_bot": false,
          "headline": "Add supported model enumeration",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-27T01:39:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f78c9e95e59033803a0ee434aaa2059da0329bb",
          "body": null,
          "is_bot": false,
          "headline": "readme and skill tweaks",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-26T19:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "070f7bfde74a30a7bdf66ecc5674f96fbbed84e3",
          "body": "Establish the new Kernel computer-use monorepo with the CLI, shared translator, provider adapters, and docs so `kernel/cua` can become the canonical home of the TypeScript implementation.\n\nMade-with: Cursor",
          "is_bot": false,
          "headline": "Initialize the TypeScript cua rewrite.",
          "author_name": "Rafael Garcia",
          "author_login": "rgarcia",
          "committed_at": "2026-04-18T02:17:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 0,
      "commits_last_year": 88,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 13,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 25,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@onkernel/cua-ai",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@onkernel/cua-ai",
          "is_deprecated": false,
          "latest_version": "0.7.0",
          "repository_url": "https://github.com/kernel/cua",
          "versions_count": 14,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 4961,
          "first_published_at": "2026-05-13T21:09:51.636000Z",
          "latest_published_at": "2026-07-17T18:42:27.070000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@onkernel/cua-cli",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@onkernel/cua-cli",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/kernel/cua",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 1552,
          "first_published_at": "2026-06-12T19:54:38.839000Z",
          "latest_published_at": "2026-07-17T18:46:27.323000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@onkernel/cua-agent",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@onkernel/cua-agent",
          "is_deprecated": false,
          "latest_version": "0.7.0",
          "repository_url": "https://github.com/kernel/cua",
          "versions_count": 13,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 4951,
          "first_published_at": "2026-05-13T21:10:05.608000Z",
          "latest_published_at": "2026-07-17T18:44:19.065000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 4,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 11
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/agent/tsconfig.json",
        "packages/ai/tsconfig.json",
        "packages/cli/tsconfig.json",
        "packages/ptywright/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 66935,
      "source_files_sampled": 137,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@earendil-works/pi-agent-core",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@earendil-works/pi-ai",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@onkernel/cua-ai",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.7.0"
        },
        {
          "name": "@onkernel/sdk",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.49.0"
        },
        {
          "name": "sharp",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.34.5"
        },
        {
          "name": "@earendil-works/pi-ai",
          "manifest": "packages/ai/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@tzafon/lightcone",
          "manifest": "packages/ai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.0"
        },
        {
          "name": "openai",
          "manifest": "packages/ai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.26.0"
        },
        {
          "name": "@earendil-works/pi-coding-agent",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@earendil-works/pi-tui",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.80.10"
        },
        {
          "name": "@onkernel/cua-agent",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.7.0"
        },
        {
          "name": "@onkernel/cua-ai",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.7.0"
        },
        {
          "name": "@onkernel/sdk",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.49.0"
        },
        {
          "name": "node-addon-api",
          "manifest": "packages/ptywright/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.7.0"
        },
        {
          "name": "node-pty",
          "manifest": "packages/ptywright/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 11,
        "merged_prs": 50,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "rgarcia",
          "commits": 73,
          "avatar_url": "https://avatars.githubusercontent.com/u/72655?v=4"
        },
        {
          "type": "User",
          "login": "dprevoznik",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/58714078?v=4"
        },
        {
          "type": "User",
          "login": "masnwilliams",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/43387599?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.83
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release-cua-agent.yml",
        "release-cua-ai.yml",
        "release-cua-cli.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 8,
            "reason": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/21 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f1c91f7f784e6df6616bb443887701c3a8fde3ed",
        "ran_at": "2026-07-23T01:22:14Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T18:46:32Z",
      "oldest_open_prs": [
        {
          "number": 35,
          "created_at": "2026-06-23T21:43:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 36,
          "created_at": "2026-06-23T21:46:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 40,
          "created_at": "2026-06-26T14:59:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 41,
          "created_at": "2026-06-26T21:53:47Z",
          "last_comment_at": "2026-07-14T01:04:10Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 42,
          "created_at": "2026-06-27T11:26:16Z",
          "last_comment_at": "2026-06-27T15:52:27Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 43,
          "created_at": "2026-06-27T12:47:37Z",
          "last_comment_at": "2026-06-27T19:31:31Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 44,
          "created_at": "2026-06-27T12:47:49Z",
          "last_comment_at": "2026-06-27T15:52:30Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 45,
          "created_at": "2026-06-27T17:06:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 63,
          "created_at": "2026-07-14T02:49:52Z",
          "last_comment_at": "2026-07-14T03:08:50Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 64,
          "created_at": "2026-07-14T02:50:03Z",
          "last_comment_at": "2026-07-14T04:14:08Z",
          "last_comment_author": "rgarcia"
        },
        {
          "number": 65,
          "created_at": "2026-07-14T02:50:18Z",
          "last_comment_at": "2026-07-14T04:14:08Z",
          "last_comment_author": "rgarcia"
        }
      ],
      "last_merged_pr_at": "2026-07-17T18:41:16Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/kernel/cua",
    "host": "github.com",
    "name": "cua",
    "owner": "kernel"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 49,
      "inputs": {
        "security": 35,
        "vitality": 44,
        "community": 29,
        "governance": 58,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 44,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 88,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "88 commits in the last year",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 88
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 29,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 8,
            "inputs": {
              "forks": 0,
              "stars": 4,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "4 stars",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "packages": [
                "@onkernel/cua-ai",
                "@onkernel/cua-cli",
                "@onkernel/cua-agent"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 11464
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "11,464 downloads/month across npm",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 11464,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.83
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 83% of commits",
                "points": 3.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 83
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 65,
            "inputs": {
              "merged_prs": 50,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 5
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "50/55 decided PRs merged",
                "points": 34.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 50,
                      "decided": 55
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/21 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "followers": 236,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "kernel",
              "public_repos": 73,
              "account_age_days": 557
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "236 followers of kernel",
                "points": 17.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 236,
                      "login": "kernel"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "73 public repos, account ~1 yr old",
                "points": 16,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 73
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@onkernel/cua-ai",
                "@onkernel/cua-cli",
                "@onkernel/cua-agent"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "3 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 3,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "14 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
                "points": 16,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://www.kernel.sh",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.kernel.sh",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 35,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/21 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 55,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.773,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "68 of 88 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 68,
                      "sampled": 88
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "packages/agent/tsconfig.json",
                "packages/ai/tsconfig.json",
                "packages/cli/tsconfig.json",
                "packages/ptywright/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.466,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/agent/tsconfig.json, packages/ai/tsconfig.json, packages/cli/tsconfig.json, packages/ptywright/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "41 of the last 88 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 41,
                      "sampled": 88
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 66935,
              "source_files_sampled": 137,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/137 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 137,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package '@onkernel/ptywright' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@onkernel/cua-ai@0.7.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T01:22:31.219271Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kernel/cua.svg",
  "full_name": "kernel/cua",
  "license_state": "absent",
  "license_spdx": null
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.