公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-24 02:25 UTC

lyraai-protocol / lyra

A Sui-native, policy-bound, non-custodial AI finance agent. Natural-language goals → policy-checked PTBs, executed only within approved on-chain scope, with auditable Walrus receipts.

TypeScriptMIT★ 0 星标⑂ 1 复刻始于 2026年6月在 GitHub 上查看 ↗

lyraai-protocol/lyra 的健康指数为 100 分中的 53 分,处于「中等」区间。 其得分最高的类别是Vitality(75/100),最低的是Security(24/100)。 最近一次更新在 3 天前。 近期的大部分工作由 1 位贡献者完成。

53
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

53
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Lyra AI组织
0 关注者3 个公开仓库始于 2026年7月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npmlyra-ai-agent0.4.32,124195 天前lyraaiagentclituisuiwalrusdeepbookdefi
npmlyra-core0.4.11,6431010 天前lyraaiagentsuitreasurydefipolicy
npmlyra-gateway0.4.11,2341110 天前lyraaiagentgatewaydaemonsui
npmlyra-plugin-system0.4.11,2271010 天前lyraaiagentfsshellbrowsersandboxtoolsplugin
npmlyra-plugin-onchain0.4.21,5021510 天前
npmlyra-plugin-telegram0.4.11,2451010 天前lyraaiagenttelegramgrammyplugin
npmlyra-plugin-onchain-one0.5.040325 天前lyraaiagentsuidefideepbookwalruspolicyplugin

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

75良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 3 天前
3.5/36提交节奏 — 52 周中有 5 周有提交
18/18提交量 — 最近一年 135 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year135
human_commit_share1
days_since_last_push3
active_weeks_last_year5

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 7 个发布版本
36/36发布时效 — 最近一次发布版本于 3 天前
27/27发布节奏 — 约每 5.4 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count7
latest_release_tagv0.5.0
releases_from_tags
days_since_latest_release3
mean_days_between_releases5.4
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

34存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 1 个复刻
0/15关注者 — 0 位关注者
所用输入
forks1
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
53/80月度下载量 — npm 合计每月 9,378 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packageslyra-ai-agent, lyra-core, lyra-gateway, lyra-plugin-system, lyra-plugin-onchain, lyra-plugin-telegram, lyra-plugin-onchain-one
dependents
ecosystemsnpm
total_downloads
monthly_downloads9,378
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

50中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
38.2/38.3PR 接受 — 已裁定的 PR 中 29/29 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/19 approved changesets -- score normalized to 0
所用输入
merged_prs29
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
0/25所有者影响力 — lyraai-protocol 有 0 位关注者
4.4/25既往记录 — 3 个公开仓库,账户约 0 年
所用输入
followers0
owner_typeOrganization
is_verified
owner_loginlyraai-protocol
public_repos3
account_age_days12
评分方式
25/25已发布且可解析 — npm 上有 7 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 19 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packageslyra-ai-agent, lyra-core, lyra-gateway, lyra-plugin-system, lyra-plugin-onchain, lyra-plugin-telegram, lyra-plugin-onchain-one
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

74良好 · 占总体的 20%

工程实践

80良好
评分方式
24/24CI 工作流 — 1 个工作流
24/24存在测试
16/16Linter 配置 — biome.json
0/9.6Pre-commit 钩子
0/6.4.editorconfig
16/20OpenSSF Scorecard:CI-Tests — 17 out of 19 merged PRs checked by a CI test -- score normalized to 8
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

65中等
评分方式
30/30README
0/25文档目录
15/15文档 / 主页站点 — https://lyraai.space
10/10仓库描述
10/10主题标签 — 10 个主题标签
0/10Wiki
所用输入
topicsai-agent, blockchain, deepbook, defi, move, non-custodial, sui, typescript, walrus, web3
has_wiki
homepagehttps://lyraai.space
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

24危急 · 占总体的 16%

安全态势

24危急
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2/2.5CI-Tests — 17 out of 19 merged PRs checked by a CI test -- score normalized to 8
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/19 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 38 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate2.4
已排除计分(无数据或不适用):packaging, signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

68中等 · 占总体的 0%
评分方式
45/45代理指令 — CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes1,784
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — biome.json
11/11静态类型检查 — packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/gateway/tsconfig.json, packages/plugin-onchain-one/tsconfig.json, packages/plugin-onchain-two/tsconfig.json, packages/plugin-onchain/tsconfig.json, packages/plugin-system/tsconfig.json, packages/plugin-telegram/tsconfig.json, tsconfig.json
0/10可复现环境
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configspackages/cli/tsconfig.json, packages/core/tsconfig.json, packages/gateway/tsconfig.json, packages/plugin-onchain-one/tsconfig.json, packages/plugin-onchain-two/tsconfig.json, packages/plugin-onchain/tsconfig.json, packages/plugin-system/tsconfig.json, packages/plugin-telegram/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
55/55可控的文件大小 — 采样的 352 个源文件中有 0 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes51,042
source_files_sampled352
oversized_source_files0

关键数据

0GitHub 星标
1贡献者
135最近 12 个月提交数
3距最近推送天数
7发布版本数
1巴士系数(bus factor)
0开放议题
npm软件包生态系统数

数据采集警告

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:lyra-ai-agent@0.4.3; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 2.4 / 10
2.4综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-24 02:25 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
8CI-Tests17 out of 19 merged PRs checked by a CI test -- score normalized to 8
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/19 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities38 existing vulnerabilities detected
直接依赖 56
注册表软件包版本约束清单文件
npmagent-browser^0.26.0package.json
npm@clack/prompts^0.8.2packages/cli/package.json
npm@mysten/sui^1.45.2packages/cli/package.json
npm@opentui/core^0.1.97packages/cli/package.json
npm@opentui/solid^0.1.97packages/cli/package.json
npmlyra-core^0.4.1packages/cli/package.json
npmlyra-gateway^0.4.1packages/cli/package.json
npmlyra-plugin-onchain^0.4.1packages/cli/package.json
npmlyra-plugin-system^0.4.1packages/cli/package.json
npmlyra-plugin-telegram^0.4.1packages/cli/package.json
npmpicocolors^1.1.1packages/cli/package.json
npmqrcode-terminal^0.12.0packages/cli/package.json
npmsolid-js^1.9.12packages/cli/package.json
npm@mysten/sui^1.40.0packages/core/package.json
npm@noble/curves^2.2.0packages/core/package.json
npm@noble/hashes^2.2.0packages/core/package.json
npmgray-matter^4.0.3packages/core/package.json
npmqrcode-terminal^0.12.0packages/core/package.json
npmzod^3.24.1packages/core/package.json
npm@mysten/sui^1.45.2packages/gateway/package.json
npm@noble/curves^2.2.0packages/gateway/package.json
npm@noble/hashes^2.2.0packages/gateway/package.json
npmlyra-core^0.4.1packages/gateway/package.json
npmlyra-plugin-onchain^0.4.1packages/gateway/package.json
npmlyra-plugin-system^0.4.1packages/gateway/package.json
npmlyra-plugin-telegram^0.4.1packages/gateway/package.json
npmzod^3.24.1packages/gateway/package.json
npm@7kprotocol/sdk-ts^4.0.0packages/plugin-onchain-one/package.json
npm@cetusprotocol/aggregator-sdk^1.6.1packages/plugin-onchain-one/package.json
npm@mysten/deepbook-v3^0.18.0packages/plugin-onchain-one/package.json
npm@mysten/sui^1.40.0packages/plugin-onchain-one/package.json
npm@mysten/walrus^0.6.4packages/plugin-onchain-one/package.json
npm@pythnetwork/pyth-sui-js2.2.0packages/plugin-onchain-one/package.json
npm@scallop-io/sui-scallop-sdk^2.4.5packages/plugin-onchain-one/package.json
npm@suilend/sdk1.1.99packages/plugin-onchain-one/package.json
npm@suilend/sui-fe0.3.49packages/plugin-onchain-one/package.json
npmlyra-core^0.4.0packages/plugin-onchain-one/package.json
npmnavi-sdk^1.7.3packages/plugin-onchain-one/package.json
npmzod^3.23.8packages/plugin-onchain-one/package.json
npm@mysten/sui^2.20.3packages/plugin-onchain-two/package.json
npm@wormhole-foundation/sdk^6.1.0packages/plugin-onchain-two/package.json
npm@wormhole-foundation/sdk-sui^6.1.0packages/plugin-onchain-two/package.json
npmlyra-coreworkspace:*packages/plugin-onchain-two/package.json
npm@wormhole-foundation/sdk-evm^6.1.0packages/plugin-onchain-two/package.json
npm@wormhole-foundation/sdk-sui-cctp^6.1.0packages/plugin-onchain-two/package.json
npm@wormhole-foundation/sdk-evm-cctp^6.1.0packages/plugin-onchain-two/package.json
npm@wormhole-foundation/sdk-base^6.1.0packages/plugin-onchain-two/package.json
npmlyra-coreworkspace:*packages/plugin-onchain/package.json
npmlyra-plugin-onchain-oneworkspace:*packages/plugin-onchain/package.json
npmlyra-core^0.4.1packages/plugin-system/package.json
npmagent-browser^0.26.0packages/plugin-system/package.json
npmzod^3.24.1packages/plugin-system/package.json
npm@mysten/sui^1.45.0packages/plugin-telegram/package.json
npmgrammy^1.42.0packages/plugin-telegram/package.json
npmlyra-core^0.4.1packages/plugin-telegram/package.json
npmzod^3.23.8packages/plugin-telegram/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "ai-agent",
        "blockchain",
        "deepbook",
        "defi",
        "move",
        "non-custodial",
        "sui",
        "typescript",
        "walrus",
        "web3"
      ],
      "is_fork": false,
      "size_kb": 3639,
      "has_wiki": false,
      "homepage": "https://lyraai.space",
      "languages": {
        "Shell": 2921,
        "TypeScript": 1603071
      },
      "pushed_at": "2026-07-20T09:13:16Z",
      "created_at": "2026-06-17T04:26:20Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-20T09:11:36Z",
      "description": "A Sui-native, policy-bound, non-custodial AI finance agent. Natural-language goals → policy-checked PTBs, executed only within approved on-chain scope, with auditable Walrus receipts.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Lyra AI",
      "type": "Organization",
      "login": "lyraai-protocol",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/302378094?v=4",
      "created_at": "2026-07-11T05:25:04Z",
      "is_verified": null,
      "public_repos": 3,
      "account_age_days": 12
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-20T09:13:16Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-18T10:33:20Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-17T10:50:40Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-07-11T13:29:57Z"
        },
        {
          "tag": "v0.1.10",
          "kind": "patch",
          "published_at": "2026-07-10T11:21:57Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-07-09T11:10:57Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-06-18T06:13:18Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "892f33455c3bf47fc8ff335e5b3cae35b69bcd5d",
          "body": "chore(deployments): refresh mainnet + testnet records",
          "is_bot": false,
          "headline": "Merge pull request #29 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-20T09:10:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "122d9cf762aade5dcb480e6f5e35045de61b0f9f",
          "body": "mainnet.json was two deploys stale (still on 0x1925bced from 07-11). Now records the\nlive lineage: original 0x8b2412e9 (07-13) upgraded to 0xcd6943c0 (07-18, cap setters),\nwith the upgrade history, UpgradeCap, and digests — all verified on-chain.\n\nAdds originalPackageId + a usage note to both, since\n[…]\n\n\ntestnet.json pointed at the June policy-only package; now the model-B deploy\n(0xf7658441). publishedBy omitted there — its publish tx is pruned from public testnet\nRPCs, so it could not be verified.",
          "is_bot": false,
          "headline": "chore(deployments): refresh mainnet + testnet records",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-20T09:09:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d0a8c7937b4f2176fc4a8cec9c474909af81a35",
          "body": "docs + cli 0.4.3: new package id, LP / editable caps in README",
          "is_bot": false,
          "headline": "Merge pull request #28 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T16:46:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34803a3f0b0d0d1c953d298ee05c97d557beb187",
          "body": "…ew in README; release cli 0.4.3",
          "is_bot": false,
          "headline": "docs: package id → 0xcd6943c0 (upgraded) + LP / editable caps / previ…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T16:43:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad65f9e668c588b5358a20f81d21c52187ea4ba4",
          "body": "chore(cli): default package id → upgraded 0xcd6943c0",
          "is_bot": false,
          "headline": "Merge pull request #27 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T16:29:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cb1c62cae6be0aaf7c81501cf240683835bf2c9",
          "body": "The mainnet package was upgraded (cap setters). Move the CLI's DEFAULT_PACKAGE_ID to\nthe new published id for its moveCall targets; the old id still works (backward-\ncompatible upgrade), so this is a consistency update, not a break.",
          "is_bot": false,
          "headline": "chore(cli): point default package id at the upgraded 0xcd6943c0",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T16:28:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d646ab58128356d0bda780d1e67b6664ae8569a",
          "body": null,
          "is_bot": false,
          "headline": "chore(cli): release lyra-ai-agent 0.4.2 (web-login domain fix)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T15:31:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c0a2c3d2363e0702a6f103d357ec8defb61dc09",
          "body": "fix(cli): web login points at app.lyraai.space (was 404 on bare domain)",
          "is_bot": false,
          "headline": "Merge pull request #26 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T15:30:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "560cf98bb2736f81aa4f7edaa247e6fd1990871b",
          "body": "`lyra login` / `lyra init` (Login with web) POST to {base}/api/cli/login/start, but\nthe default base was https://lyraai.space — the landing site, which has no /api routes\nand 404s every call. The API lives on the app subdomain. Default to\nhttps://app.lyraai.space (LYRA_WEB_URL still overrides). Verified:\napp.lyraai.space/api/cli/login/start → 200, bare domain → 404.",
          "is_bot": false,
          "headline": "fix(cli): point web login at app.lyraai.space, not the bare domain",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T15:28:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "880403e778069674274fefbacbe54d2c6316292f",
          "body": "style: fix biome lint (swap.ts + package.json formatting)",
          "is_bot": false,
          "headline": "Merge pull request #25 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T10:23:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f02a7087917cd4dbfaba7c92714b9afa6ba4279c",
          "body": "…age.json)\n\nThe hermes MetaAg block in swap.ts was over-indented and the 0.5.0 version bump\nreformatted package.json off biome's style — both tripped the monorepo lint on CI.\nFormatting only; no behavior change.",
          "is_bot": false,
          "headline": "style(onchain-one): fix biome formatting (swap.ts block indent + pack…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T10:21:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fe813f756be5e39c0ff0f54d0646c3c25b50f2e",
          "body": "feat(onchain-one): Cetus LP zap tool (plugin 0.5.0)",
          "is_bot": false,
          "headline": "Merge pull request #24 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T10:19:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "940e67a3f4fd355a4975310365776c0f1573dd33",
          "body": "… SUI (0.5.0)\n\nNew value-moving tool: provide full-range liquidity to a Cetus CLMM pool, funded\nentirely from the vault's SUI. In one PTB: draw SUI (policy-gated vault_spend_capped)\n→ keep part as one side, swap the rest to the pair coin via the 7k aggregator → open\nthe position via pool_script_v2::\n[…]\nthmetic,\namounts are computed on-chain).\n\nVerified: the exact open_position moveCall dry-ran clean on mainnet (created a Position\nNFT, zero funds moved). Also ships the pending hermes-swap oracle fix.",
          "is_bot": false,
          "headline": "feat(onchain-one): cetus.add_liquidity — full-range LP zap from vault…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T10:15:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6173365de5959e95c5f3fcfb2f77fac92e0cde58",
          "body": "The 7k aggregator's Cetus provider reads its Pyth feeds from hermesApi; unset, its\npythUrls is empty and oracle-gated routes fail on 'Failed to update Pyth price\nfeeds'. Defaults to https://hermes.pyth.network, LYRA_HERMES_API overrides. Matches\nthe web console's fix.",
          "is_bot": false,
          "headline": "fix(swap): pass Pyth Hermes URL to the aggregator (Cetus oracle routes)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-18T06:16:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9db124f3d2ef1d0123d47c0cf2cae39792449d69",
          "body": "docs: the README predates the bridge",
          "is_bot": false,
          "headline": "Merge pull request #23 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-17T10:55:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e44aee1c17fc70a4e1355de59f797bb6c6f9ffbc",
          "body": "The biggest feature since v0.2.1 wasn't in it at all — zero mentions of the bridge,\nthe deposit driver, or the waitlist. Added:\n\n  · A 'funding the vault from another chain' section under How it works: the six\n    source chains, the state machine each deposit walks, and why a restart resumes\n    a m\n[…]\nsits and the waitlist now, not just\n    articles).\n\nAlso gitignores testnet-plan/ (private launch planning), and lets bun.lock catch up\nto the 0.4.1 workspace versions it was still recording as 0.3.0.",
          "is_bot": false,
          "headline": "docs: the README predates the bridge",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-17T10:53:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50b1c5732de50dcde6c13a3a45ac5e1ea13b90f6",
          "body": "Bridge driver loop + entry point (durable deposit runtime)",
          "is_bot": false,
          "headline": "Merge pull request #22 from lyraai-protocol/dev",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T18:29:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76b1b12641eea2aa3610e40c9f6ca87c78722f0e",
          "body": "x is already covered by the a-z range, so the class is identical without it.",
          "is_bot": false,
          "headline": "fix(bridge): drop redundant x from [^a-z0-9x] character class",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T18:26:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c1fdb0d8c82feb9bf4bb76b73cc032390d1d533",
          "body": "The runtime that carries cross-chain deposits to the vault:\n- InMemoryDepositStore.fromRecords — seed the sync store from durable records, so\n  the tested sync spine can run over a batch loaded from the async store.\n- driveDurableTick (deposit-driver-loop) — one tick: load active → hydrate →\n  drive\n[…]\nem via relayer, vault deposit delegated back to the v1\n  app over /api/bridge/execute-deposit), polled on an interval.\n\n60/60 onchain-two tests pass; typecheck + biome clean. Node-only (Wormhole SDK).",
          "is_bot": false,
          "headline": "feat(bridge): durable driver loop + entry point (onchain-two)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T18:23:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a72fe77fdb1e388e55e3af8f6167e38e9fabdd68",
          "body": "Sui-native legs delegated; deposit PTB verified on testnet.",
          "is_bot": false,
          "headline": "feat(bridge): delegate CctpExecutor deposit/swap legs to config",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T15:48:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f285d0b6633bd1ba46474281359283bd2f617f61",
          "body": "Proven CCTP flow wired into DepositExecutors. 52 tests.",
          "is_bot": false,
          "headline": "feat(bridge): CctpExecutor — real DepositExecutors over Wormhole CCTP",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T15:32:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95808f591e036adf9c77c773aece4c20c01c9fab",
          "body": "Agent-facing deposit surface over the spine. 49 tests.",
          "is_bot": false,
          "headline": "feat(bridge): bridge.deposit + bridge.status agent tools",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T14:05:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78a6ce1306700edd3cb0769263b1f0e204cb5fde",
          "body": "validateDepositRequest completes the off-chain deposit spine. 42 tests.",
          "is_bot": false,
          "headline": "feat(bridge): deposit intent validation (entry point)",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T14:01:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d9d349c403281bb1e90ab3668dc12b94672f0f4",
          "body": "Runtime loop for #16 — driveOnce/driveTick + reapStale, 29 tests. Executors injectable for live cross-chain later.",
          "is_bot": false,
          "headline": "feat(bridge): deposit driver (advance via injected executors)",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T13:56:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76a033f38434d792fd241bc470b90d5d41535ef5",
          "body": "Testable orchestration core for #16 — state machine + store, 20 tests. Cross-chain execution stays scaffolded.",
          "is_bot": false,
          "headline": "feat(bridge): deposit lifecycle state machine + pending-transfer store",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T13:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9ea404b781e0bb9dd59807418984c2bbed6dabc",
          "body": "v1-only pass-through + files/publishConfig; deps resolve. CLI install fixed.",
          "is_bot": false,
          "headline": "fix(facade): republish lyra-plugin-onchain 0.4.2 with resolved deps",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T13:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d0eb7c94fdfd45f19b7d5d27b3ac333445913af",
          "body": "Reformat the changeset-written package.jsons to biome's style. Versions/content unchanged.",
          "is_bot": false,
          "headline": "chore(lint): biome-format changeset package.json (fix 0.4.0 CI)",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T12:56:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "723f75a7a664a1edf9c889f85e5a40bf431fa635",
          "body": "Published stack 0.4.0 to npm; remote-signer signBytes seam consumable by the app.",
          "is_bot": false,
          "headline": "chore(release): version packages 0.4.0 (remote-signer seam)",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T12:54:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a48698fddb929f06ab2bead7de0ed25e354f84ba",
          "body": "Single submit() choke point + optional signBytes hook so a remote signer covers all write tools. Local keypair path unchanged. 129 tests pass; changeset bundled.",
          "is_bot": false,
          "headline": "feat(plugin): remote-signer seam — submit() choke point + signBytes",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T12:45:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d4a55e338430502d712f12ed1e956c4aad72e3d",
          "body": "…ings)\n\nBehavior-preserving helper extraction across 59 functions in 6 packages. biome clean (0 errors, 0 warnings), tsc 0 errors, 1960 tests pass.",
          "is_bot": false,
          "headline": "Refactor: all functions under cognitive-complexity 15 (zero lint warn…",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T11:01:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1740cac0310aefed465e791cf47b13a993555888",
          "body": "plugin/cli default package id → 0x8b2412e9…; best-practice borrow/settle swap; shared write helpers; v2 CCTP bridge scaffold; READMEs + lint hygiene. 126 + 684 tests pass.",
          "is_bot": false,
          "headline": "Cutover: model-B mainnet package + bounded vault exits + docs",
          "author_name": "rifky",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-13T10:20:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb8ab57e2d020ed93423e47c60466a7946404bd0",
          "body": null,
          "is_bot": false,
          "headline": "chore: biome-format the tool catalog + registration test",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T13:21:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "465e9d7436a1d91cbb49a790b91e6a4bd2282966",
          "body": "…idance (0.2.1)\n\nAdding a tool is now one catalog entry (+ the tool file): the plugin registers by\niterating TOOLS, WEB_TOOL_NAMES is derived for the console, and the guidance's\ncapability list is generated from the catalog — no more editing index.ts, the web\nWEB_TOOLS set, and the guidance prose per integration.",
          "is_bot": false,
          "headline": "feat(catalog): single tool catalog drives registration + web set + gu…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T13:18:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4afb0256fbe8433cbc504fa74283a3f81a12ff21",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.2.0 (Walrus staking + single-source protocol registry)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T13:06:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8362f66785ee84d7a265c138269f97a9000d4450",
          "body": "… export\n\nAdding a protocol was ~3 edits in the plugin (PROTOCOL_IDS + PROTOCOL_LABELS +\nALLOWLISTABLE_PROTOCOLS) plus 2 hand-kept mirrors in the app + landing. Now ONE\nentry in a REGISTRY array derives all three, and a dependency-free ./protocol-ids\nsubpath export lets the browser import the allowlist directly — no more mirrors to\nkeep in sync.",
          "is_bot": false,
          "headline": "refactor(protocols): single-source protocol registry + client subpath…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T13:01:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43f49443c7b852c9333d0295248e78a89c5dc026",
          "body": "…ending suite\n\nThe on-chain guidance stopped at Scallop/NAVI lending + walrus.store; it never\nmentioned any staking. Add the staking section (native, Volo, Walrus WAL) + the\nSuilend/borrow/repay/swap tools so the model proactively knows it can list + do\nWAL staking, not just stumble into it via tool descriptions.",
          "is_bot": false,
          "headline": "docs(guidance): tell the agent about WAL staking + the full staking/l…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T12:53:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6eb614eba7ebd60121533e5f3adfdec606362a3c",
          "body": "Integrates https://stake-wal.wal.app: the agent can delegate WAL to a Walrus\nstorage node's pool to earn rewards + secure decentralized storage.\n\n- walrus.stake   → <walrus>::staking::stake_with_pool (min 1 WAL) → StakedWal\n- walrus.unstake → request_withdraw_stake (WAL returns next epoch)\n- walrus.\n[…]\nrom the\nagent's WAL balance (not the SUI vault) and bounded by the 'walrus' protocol\nallowlist. Added to the protocol registry + allowlist. Live mainnet dry-run test\npasses (1 WAL → node → StakedWal).",
          "is_bot": false,
          "headline": "feat(walrus): WAL staking — stake/unstake/read Walrus storage nodes",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T12:20:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "552207f1a86fad611048bff09f83ef34f501f3e5",
          "body": "…l/lyra\n\nThe changeset version bump rewrote the package manifests in a non-biome style\n(the CI lint gate rejected them); reformat + fix the stale rifkyeasy/lyra\nrepository/bugs/homepage URLs.",
          "is_bot": false,
          "headline": "chore: biome-format package.json + repoint metadata to lyraai-protoco…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T10:17:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5506877533b65f199325191cf077fef16f39d3e",
          "body": "- Root README: org repo layout (lyra/contracts/app/landing/api), 5-module Move\n  package + version guard, correct clone URL, Netlify deploy, 37 Move tests.\n- plugin-onchain: replace stale EVM-era tool list with the real Sui tools.\n- cli: real command set (login/whoami in, identity/drain out).\n- core: drop removed Trustless-Agents identity references.\n- Package READMEs repointed rifkyeasy/lyra -> lyraai-protocol/lyra.\n- npm 0.1.11 (plugin-onchain + cli repointed at the reworked v1 package).",
          "is_bot": false,
          "headline": "docs: refresh all READMEs + release 0.1.11",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T09:54:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab076faaacdaa51a9e18d77d2115e2254d6015e1",
          "body": "…ir own repo\n\nThe Move package was restructured into a professional multi-module layout and\nfreshly published on mainnet (new package id\n0x1925bced9aeb16ca8159be0a10d39a0778fe618404443a4b6149116ad9997617). This repoints\nevery off-chain consumer (plugin-onchain, cli) at the new id and updates the\nActionReceipt type path (policy -> receipt module).\n\nThe package source now lives in lyraai-protocol/contracts; move/ is gitignored here\nand checked out as a nested satellite repo.",
          "is_bot": false,
          "headline": "chore(onchain): repoint to reworked v1 package; move contracts to the…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T09:30:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81a79805661d79b59cd40060f6f47738fa3c01ad",
          "body": "The marketing site (lyraai.space) and console (app.lyraai.space) live in the\nlyraai-protocol/landing and /app repos. This repo is the core: Move contracts,\nCLI, packages, gateway.",
          "is_bot": false,
          "headline": "chore: core repo — web split out to landing + app",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T08:07:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94479efed99b2f4b336f7c3037b9a7dd285de61d",
          "body": "…ro copy\n\n- research: clicking a research card used to bounce to /docs/* or /safety.\n  Add dedicated Medium-style article pages at /research/[slug] (articles.ts +\n  a clean reading layout — byline, prose, pull-quotes, keep-reading), and point\n  the cards there. The \"Read the source\" card stays an ex\n[…]\nrk logo on a\n  dark tab. Removed the unreliable media-query PNG <link> tags; PNG/ico stay as\n  the Safari fallback.\n- hero: drop the leading \"Ask. \" → \"Do anything on-chain, / across the Sui network.\"",
          "is_bot": false,
          "headline": "feat(web): Medium-style research articles, theme-adaptive favicon, he…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-11T05:27:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41f0691c7bea4a7a81f8333fc6b4534cff1d5140",
          "body": "The fixed group referenced renamed packages (lyra-ai-cli, lyra-ai-harness,\nlyra-ai-plugin-comms) that no longer exist, breaking changeset publish. Point it\nat the current six so their versions stay aligned going forward.",
          "is_bot": false,
          "headline": "chore(changeset): fix fixed-group package names (Nebula-era → Lyra)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T11:18:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70df3169ce504d9275bf40825be4947e0254f2cf",
          "body": "Bump every published package (lyra-ai-agent, lyra-core, lyra-gateway,\nlyra-plugin-onchain, lyra-plugin-system, lyra-plugin-telegram) to a uniform\n0.1.10 and align interdependency ranges to ^0.1.10, so the vault-funded DeFi +\nupdatable-allowlist work ships to npm as one coherent version set.",
          "is_bot": false,
          "headline": "chore(release): align all packages to 0.1.10",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T11:18:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e309a51244304b2d324b116f3a083cc37a59d2c",
          "body": "Closes the two remaining gaps from the vault-funding work.\n\nScallop (was: stuck on agent EOA):\n- Scallop's `*Quick` helpers auto-select the agent's own coins, so they can't\n  be vault-funded. Switch supply to the non-quick `tx.deposit(coin, 'sui')` fed\n  a vault-drawn Coin<SUI> via fundSui; withdraw\n[…]\novisioned, with\n  the same gas fallback. Verified: resolves the test agent's vault; null for\n  agents without one.\n\ntsc -b + web tsc + biome clean; 125 pass (pre-existing 20 approval fails unchanged).",
          "is_bot": false,
          "headline": "feat(onchain): vault-fund Scallop + auto-wire the CLI/gateway vault",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T09:55:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0ea7a1d7c46864d495dbe5b8f2c96c1d37fb179",
          "body": "…browser bundle)\n\nImporting ALLOWLISTABLE_PROTOCOLS/NO_PROTOCOL from lyra-plugin-onchain into the\nAgentWalletBar client component pulled the plugin's Node-only graph into the\nbrowser bundle, breaking next build on node:crypto. Mirror the (client-safe)\nconstants in apps/web/lib/onchain-constants.ts instead; cross-referenced to the\nplugin's protocol-ids.ts. Verified with a clean next build.",
          "is_bot": false,
          "headline": "fix(web): mirror protocol registry client-side (avoid node:crypto in …",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T09:04:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d0024c654713aca9c8e0e12af88685151308f72",
          "body": "Make the vault_spend protocol allowlist actually gate the DeFi tools per\nprotocol, with an owner UI to manage it — closing the \"scalable: add/remove\nprotocols\" loop.\n\nContract (mainnet UPGRADED → v6\n0x8ffdbda0…; original id 0x250880a4… unchanged):\n- policy.move: @0x0 is now a reserved \"no specific p\n[…]\nicy's allowed_protocols.\n\nVerified LIVE on v6: under allowlist [NAVI, 0x0] → Suilend spend blocked\n(MoveAbort), 0x0 transfer + NAVI spend succeed; policy reset to open. tsc -b +\nweb tsc + biome clean.",
          "is_bot": false,
          "headline": "feat(onchain): granular per-protocol allowlist gating + owner UI",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T09:04:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b11e18e934ef59bec508884808c2760ba98a7c15",
          "body": "Rework lyra::policy + the agent tools so the treasury vault is the single\nfund source for agent actions, and make the coin/protocol allowlists\nextendable without a redeploy — new Sui protocols/assets slot in with one\nowner tx.\n\nContract (mainnet package UPGRADED in place → v5\n0x811bb37d…; original/t\n[…]\neFi tools are\n  vault-funded per signed-in owner.\n\nVerified: live vault_spend dry-run on v5 (VaultSpent + ActionRecorded events,\ncorrect budget accounting). tsc -b + biome clean; no new test failures.",
          "is_bot": false,
          "headline": "feat(onchain): vault-funded DeFi + owner-updatable policy allowlists",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T08:35:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6324745df4c0522a815bd387862ee47dc81dcc89",
          "body": null,
          "is_bot": false,
          "headline": "chore: biome-format package.json (workspaces edit)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T06:36:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "494a135178d0c0b7a7b61b6a8767154c1a4d8dc7",
          "body": "apps/automation is gitignored and its own standalone repo, but the `apps/*`\nworkspace glob pulled it into the root bun.lock (twitter-api-v2, prettier). CI\n(which never checks out apps/automation) then failed `bun install --frozen-lockfile`\nwith \"lockfile had changes\". Workspaces now list packages/* + apps/web explicitly.",
          "is_bot": false,
          "headline": "fix(build): drop apps/automation from workspaces so bun.lock matches CI",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T06:36:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bca5883da8869962b533a81a50668bb409a33d0e",
          "body": "…eposit QR\n\nConsole UX fixes from live testing:\n- get_balance now returns BOTH the Lyra agent (the wallet that holds funds +\n  executes) and the connected wallet, labeled — \"my balance\" was silently\n  showing only the owner wallet, hiding the agent's actual funds.\n- The system prompt now carries the\n[…]\nprompt.\n- AgentWalletBar: a \"deposit ⊞\" toggle shows a QR of the agent address (CSP-safe\n  SVG) + copy, so users can scan to fund the agent.\n- biome ignores apps/automation (its own prettier project).",
          "is_bot": false,
          "headline": "fix(web): agent-aware balance, agent-address, console-only sign-in, d…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T06:36:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e167f0312bb8c821ec0342eb891332f477a3a2d",
          "body": "…s fixtures\n\nThe test used two REAL, live Telegram bot tokens as \"realistic\" fixtures\n(validated live via getMe: @anima_enigma_bot / @anima_specter_bot). They were\ncommitted to the public repo and shipped in the npm tarball (test files leak in),\nso anyone could use them. Replaced with obviously-fake fixtures that still match\nthe token shape (so the looksLikeBotToken tests are unchanged). These tokens are\nthird-party — the repo just stops distributing them.",
          "is_bot": false,
          "headline": "security: scrub live Telegram bot tokens from telegram-secrets.test.t…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-10T06:36:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ceeb0f159709dd0c4754ac66be53e4fa064f7b25",
          "body": "The web agent merged plugin-onchain's dotted tool names (suilend.supply,\nnavi.borrow, …) straight into the OpenAI tools list, but the function-calling API\nrequires names to match ^[a-zA-Z0-9_-]+$ — so any chat that surfaced a DeFi tool\n400'd (\"tools[7].function.name does not match pattern\"). Now the schema name is\nsanitized (dot → underscore) and dispatch maps it back to the real tool, exactly\nlike lyra-core's brain does for the CLI. Verified all 22 web tools sanitize to\nvalid names.",
          "is_bot": false,
          "headline": "fix(web): sanitize plugin-onchain tool names for the OpenAI API",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T14:46:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6138e86efe7f4e07900647cc97bfa9171d56ba10",
          "body": "…card\n\nThe share image still showed \"Nebula AI\". Swapped the static /og-image.jpg for a\nNext-generated app/opengraph-image.tsx (1200×630, on-brand: lyra wordmark, \"Do\nanything on-chain, across Sui\", accent glow) and dropped the explicit metadata\nimage refs so both og:image and twitter:image use it. Deleted the stale jpg.\n\nVerified: next build renders a valid 1200×630 PNG; homepage og:image +\ntwitter:image resolve to https://lyraai.space/opengraph-image.",
          "is_bot": false,
          "headline": "fix(web): replace the old Nebula OG image with a code-generated Lyra …",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T12:26:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1d4fd022b62db438b0cfa178fab94930a4a7413",
          "body": null,
          "is_bot": false,
          "headline": "chore: gitignore local-only apps/automation workspace",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T12:26:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc3fe4f969b3433cc4c2bc0860ee171338a49fd6",
          "body": "Mobile fixes reported on device:\n- Navbar: standalone menu entries (Research/Pricing) were rendered at a giant\n  display size while grouped items were 22px — now all mobile-menu links share\n  the same 22px scale. Removed the now-unused MenuLink.\n- Navbar: the flat mobile strip that inherits the sect\n[…]\nge fades\nin FIRST, then the logos + title animate in; on the way out the logos + title\nleave first, then the image fades back to 0 last. Cream edge-fades stay static so\nsection boundaries still blend.",
          "is_bot": false,
          "headline": "fix(web): mobile responsive polish + staged protocol scroll animation",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T11:55:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74c9716b7d8436e4671479ba3b60f5254baf27b8",
          "body": "…k subpaths\n\nThe web (Node) couldn't import @suilend/sdk — its index re-exports strategies.js →\n@suilend/springsui-sdk, whose ESM does a directory import Node's resolver rejects.\nBut the lending path doesn't need springsui: import SuilendClient + the market\nconstants from `@suilend/sdk/client` and i\n[…]\nion), no longer CLI-only, and the earlier lazy-import\nworkaround is gone.\n\nVerified: tsc + full suite clean, next build (Node) passes with Suilend enabled,\nSuilend integration test still green on Bun.",
          "is_bot": false,
          "headline": "fix(onchain): make Suilend work on the web too (Node) via @suilend/sd…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T11:55:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3bbe95792c947f59be897958f5703fc0528895e",
          "body": "The web console could only read + propose transfer/swap. Now, when the owner is\nsigned in, the chat agent EXECUTES lending + staking inline through the SAME\nplugin-onchain tool registry the CLI uses (bound to the owner's derived agent,\nunder the on-chain policy gate): NAVI supply/withdraw/borrow/rep\n[…]\ns + serves on Node (home/health/chat 200),\nall SDKs except @suilend/sdk import under Node, Suilend still works on Bun\n(integration + handler), full suite 961 pass / 4 skip / 0 fail, biome + tsc clean.",
          "is_bot": false,
          "headline": "feat(web): execute DeFi in the web agent via the CLI's tool registry",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T11:30:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "037b96d0043facd390f9458200e0464bb2b96852",
          "body": "0.1.8 is already on npm; bump so the live-mainnet-verified fixes (Suilend\ncross-asset borrow, Scallop withdraw fix, LYRA_RPC_URL, findObligation retry)\npublish instead of being skipped.",
          "is_bot": false,
          "headline": "chore(release): plugin-onchain + cli 0.1.9",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T10:08:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "672476f85a26db81ebe31c1a963bc62957142899",
          "body": "…ow, RPC, Scallop)\n\nRan full round-trips on mainnet through the real tool handlers and fixed every\ngap the live tests surfaced:\n\n- Suilend borrow/repay are now CROSS-ASSET (default borrow USDC against SUI\n  collateral). Suilend forbids borrowing the same asset you post as collateral\n  (obligation::b\n[…]\nl round-trips (real digests): NAVI supply/borrow/repay/withdraw,\nSuilend supply/borrow(USDC)/repay/withdraw, Volo stake/unstake, Scallop\nsupply/withdraw. 961 pass / 4 skip / 0 fail; tsc + biome clean.",
          "is_bot": false,
          "headline": "fix(onchain): live-mainnet-verified lending/staking (cross-asset borr…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T09:58:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b35730dc2d14b5fcf2d22c95501da09a83f47c6b",
          "body": "… dev",
          "is_bot": false,
          "headline": "fix(ci): force-checkout on VPS deploy so a dirty bun.lock can't block…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T09:17:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6432a1bde5089acd7aa0afcda1fa1e57f6289eb6",
          "body": "Scale-up of the executable DeFi surface — the three biggest Sui money\nmarkets now support full supply/withdraw/borrow/repay, plus liquid staking.\n\n- Suilend: supply/withdraw/borrow/repay + position on MAIN_POOL. Uses\n  @suilend/sdk@1.1.x, whose @mysten/sui is a peerDependency (binds our v1\n  copy) —\n[…]\nrk guards) + gated live\nmainnet dry-run integration tests (native stake, Volo, Suilend supply all\nsimulate success). 961 pass / 4 skip / 0 fail; biome + tsc clean.\n\nBump plugin-onchain + cli to 0.1.8.",
          "is_bot": false,
          "headline": "feat(onchain): Suilend + Volo, borrow/repay, CI/CD on dev (0.1.8)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T09:16:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a4f6125970cd975d2a18fbfde446ef7ab6c165f",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): DeFi minimums + staking + borrow → 0.1.7 (dev)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T08:34:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93ebf61764c0a19e4580ba1a8d23730c5960934d",
          "body": null,
          "is_bot": false,
          "headline": "test(defaults): DEFAULT_ALLOWED_PROTOCOLS now includes stake + borrow",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T08:28:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "579f69333afb91daf16e1c1d0f973b286a3c0aac",
          "body": "Fix the \"reports success but the on-chain tx failed\" bug for too-small amounts:\nadd a per-action minimum guard (minimums.ts) that returns a clear \"amount too\nsmall\" error BEFORE building/simulating/executing — wired into sui.send, swap,\nnavi.supply, and scallop.supply. Sui native staking hard-requir\n[…]\nrrowCoin/repayDebt).\n- Allow 'stake' and 'borrow' protocols by default.\n\nAll go through the same guarded pipeline (min → policy → dry-run simulate →\nexecute → on-chain effects check). Pushed to `dev`.",
          "is_bot": false,
          "headline": "feat(defi): amount minimums + native staking + NAVI borrow/repay",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-07-09T08:27:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dfeab62000bc87ce44b8effc00d0f1270681d22",
          "body": "The local gateway daemon couldn't run the Telegram bot from `lyra telegram setup`:\n(1) it required LYRA_AGENT_KEY in env — now falls back to ~/.lyra/agent.key (the\nfile `lyra init`/`lyra login` writes); (2) it read LYRA_TELEGRAM_BOT_TOKEN but\nsetup sets TELEGRAM_BOT_TOKEN — now accepts both (and TEL\n[…]\n to ~/.lyra/.env (0600) so `lyra gateway\nstart` picks it up with no manual export. Verified: daemon binds with a file key\nand the telegram listener goes active. gateway + cli → 0.1.6 (cli dep ^0.1.6).",
          "is_bot": false,
          "headline": "fix(gateway): run the Telegram bot 24/7 from env-based setup (0.1.6)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-20T10:21:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "441fbc624f2e885b511864fe5bc59083ff00fa62",
          "body": "`lyra` chat (and the gateway) crashed at startup with \"First argument must be an\nError object\": navi-sdk → axios → follow-redirects calls Error.captureStackTrace\nat module-init in a way Bun rejects. Add a capture-shim (no-op on failure) as the\nfirst import in plugin-onchain (before ./tools/navi loads navi-sdk) and in the CLI\nentry. plugin-onchain → 0.1.5, lyra-ai-agent → 0.1.5 (dep ^0.1.5); the gateway\npicks up the fixed plugin-onchain transitively.",
          "is_bot": false,
          "headline": "fix: guard Error.captureStackTrace so navi-sdk doesn't crash Bun (0.1.5)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-19T09:35:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccd7e6a22a561a812b74da5a196b3ff1da8216cf",
          "body": "`lyra login` used to write only ~/.lyra/agent.key, leaving `lyra` (chat) with no\nconfig to load — it crashed with a mangled \"First argument must be an Error\nobject\". Factor the config-write + memory-seed out of `lyra init` into a shared\n`finalizeSetup`, and call it from `lyra login` (when no config exists) so the\ndevice-link is a complete setup. Only the CLI changed since 0.1.3.",
          "is_bot": false,
          "headline": "fix(cli): `lyra login` writes a runnable config (release 0.1.4)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-19T09:21:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ebb1ed66bbf1f3288098b80deb8fa87d8197cf9",
          "body": "…d versions)\n\nSo a single bumped package (e.g. cli 0.1.3 while the rest stay 0.1.2) can be\npublished without 403-ing on the unchanged packages — each is skipped if its\nexact version is already on npm.",
          "is_bot": false,
          "headline": "chore(release): make publish-npm.sh idempotent (skip already-publishe…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T09:49:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9781201108815d8f9f501bb2a12d460fd1d6ec19",
          "body": "`lyra login` now prints the public verify URL (it builds the link from the base it\ncalled instead of the server's reported origin). Only the CLI changed since 0.1.2;\nits internal deps stay ^0.1.2 (other packages remain at 0.1.2 on npm).",
          "is_bot": false,
          "headline": "chore(release): lyra-ai-agent 0.1.3 — cli-login public URL fix",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T09:47:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "684e0572231183cab9b01d9d5d3bf170bf132941",
          "body": "`lyra login` now builds the verify link from the base it called (e.g.\nhttps://lyraai.space), instead of the server-reported origin which resolved to\nthe internal reverse-proxy host (localhost:3220). The /start route also prefers\nthe forwarded host over req.url as a fallback. (VPS now sets LYRA_WEB_URL too.)",
          "is_bot": false,
          "headline": "fix(cli-login): show the public verify URL, not the internal proxy host",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T09:46:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ebd03a8cbd61bb4e934b3cfb877e89c22804df5",
          "body": "CLI now runs with no env vars. Bake defaults (mainnet package id, network,\nOpenAI/gpt-4o-mini, policy caps). `lyra init` is interactive: optional LLM key\n(blank → hosted demo proxy), then \"Create new\" (self-sovereign agent, key at\n~/.lyra/agent.key 0600) or \"Login with web\" (device-link → same agent\n[…]\nt,poll,approve} + the /cli-login page implement the\ndevice-link — the SIWS-gated approve derives and returns the owner's agent key\nonce (one-time poll).\n\nAll packages → 0.1.2. tsc + 947 TS tests pass.",
          "is_bot": false,
          "headline": "feat: zero-env CLI config + device-link login (release 0.1.2)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T09:37:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "570bedab475a25b3b16540017f7c739b0f5271c6",
          "body": "- Hero: new headline \"Ask. Do anything on-chain, across the Sui network.\"; fade\n  the LineWaves into the page at the bottom so it isn't hard-cut.\n- V1Opener / V3Brain: rewrite the scrollytelling copy Sui-native (Move, PTBs,\n  fullnode dry-run, vault, ActionReceipt, Walrus) — drop the EVM leftovers\n  (estimateGas / simulateContract) inherited from the Mantle port.\n- Navbar: slim the 7-item mega-nav to Product · Developers · Research · Pricing · More.",
          "is_bot": false,
          "headline": "feat(web): de-Nebula pass — hero, copy, navbar, edge mask",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T08:29:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c286b366b0b9b3302b59ab6a0e874ead233b4389",
          "body": "A scroll-driven section over the 5.avif portal: the Sui protocols Lyra executes\nwithin (real DefiLlama logos, self-hosted) sit on a semicircle that follows the\narc and zoom in from invisible as you scroll. Section edges fade into the cream\npage so the dark band blends with the sections around it. Placed after the hero.",
          "is_bot": false,
          "headline": "feat(web): \"Integrated across Sui DeFi\" cosmic section",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T08:29:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97eef237c038dbe87f88d1d0665d4f5aff08fd98",
          "body": "A dark starfield section where the Sui protocols Lyra's agent can execute within\n(DeepBook, Walrus, Cetus, FlowX, Bluefin, Turbos, Scallop, NAVI, Suilend, 7k,\nDefiLlama, Pyth, SuiNS, Sui) drift as nodes around a centered headline. Nodes ring\nthe centre so the copy stays readable; respects reduced-motion. Initials now,\nswappable for real logos.",
          "is_bot": false,
          "headline": "feat(web): \"Integrated protocols\" cosmic section (Morpho-style)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T07:25:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a4c8c9bd8e34d27550b707a8981376c0ccbd163",
          "body": "Add a TxResultDialog (modal) shown after every value-moving action in the console\n— provision / deposit / withdraw / gas top-up / payee allowlist (AgentWalletBar)\nand agent transfer / swap (ActionCard). Confirms success with the digest linked to\nthe explorer, or shows the error. Escape / backdrop / Done to dismiss.",
          "is_bot": false,
          "headline": "feat(web): success dialog after console transactions",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-18T06:53:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5eb6f4af2f6ef59a7ccf9dfb1c967588062fb71b",
          "body": "Add /apple-touch-icon.png (was 404) using the cream mark — iOS fills icon\ntransparency with black, so the dark mark would be invisible. Point metadata\napple icon at it.",
          "is_bot": false,
          "headline": "fix(web): root apple-touch-icon (cream mark, iOS-visible)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T13:08:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91f9b27ca4dc387cf2ca0298d52e4fc8099fc087",
          "body": "Replace the favicon / app-icon set with the new Lyra mark (radiating fan). Map by\ncontrast: dark mark → /icons/light (light browser chrome), light mark → /icons/dark\n(dark chrome); root favicon.ico = dark mark. Manifest theme/background → cool\npalette #f5f7fa.",
          "is_bot": false,
          "headline": "feat(web): new Lyra logo favicons (dark/light scheme-aware)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T13:04:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ef918739a4f096a87e59ef55abe5a4577851d88",
          "body": "Remove the old Nebula leftovers (LightfallBg, anima wordmark/demo-thumb assets —\nzero references) and update the hero space backdrops.",
          "is_bot": false,
          "headline": "chore(web): drop unused Nebula assets + refresh space imagery",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T12:52:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83d758930a7c74056ce48062b36d41d692202536",
          "body": "Headline now uses mix-blend-difference over white so it dynamically blends with\nthe moving LineWaves (dark over light areas, recolored over the aqua/violet\nwaves) — always readable, never a flat layer on top. Drop the inner z-index so\nthe headline and canvas share one stacking context (mix-blend needs a common\nbackdrop); paint order is kept by DOM order. Removed the now-redundant \"Sui\"\naccent (the blend supplies the color shift).",
          "is_bot": false,
          "headline": "fix(web): blend hero headline with the animated background",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T12:49:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0289672247d557fa231485ca8746dcf61b4b76f",
          "body": "Replace Nebula's Fraunces serif with Basik (a clean geometric sans) for the\ndisplay/headline role — a distinct, modern identity. Self-hosted via next/font\nlocal (otf → woff2, 20KB); --font-display → --font-basik; Fraunces kept as\n--font-serif. Headline drops the Fraunces variable axes and uses Basik's Book\nweight.",
          "is_bot": false,
          "headline": "feat(web): Basik W05 Book as the display typeface",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T12:41:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b1be70e46d5c1c26be9ae7bf3b790602a1873eb",
          "body": "… accent\n\nDifferentiate from Nebula's warm, accent-less cream/ink editorial look:\n- Cool the base palette (light + dark): warm cream/ink → clean cool off-white +\n  cool near-black, cooler shadows.\n- Add a Lyra brand accent (Sui-aligned aqua #2b8fff + cosmic violet #7c6bff) as\n  design tokens — applied to the hero LineWaves, the primary CTA, and the \"Sui\"\n  highlight in the headline.",
          "is_bot": false,
          "headline": "feat(web): distinct Lyra visual identity — cool palette + aqua/violet…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T12:35:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2387dffc1199b20bdb03f1ff44ae01d110691911",
          "body": "- LineWavesBg: 'use client', clamp DPR (≤2, fill-rate bound), pause render when\n  off-screen (IntersectionObserver) or tab hidden (visibilitychange), debounced\n  ResizeObserver, window-tracked mouse warp (works under overlapping content),\n  prefers-reduced-motion → single static frame. Proper WebGL teardown.\n- Hero: move the canvas out of the max-width container into a full-screen\n  `absolute inset-0 -z-10` layer behind the content (z-10); overflow-hidden.",
          "is_bot": false,
          "headline": "feat(web): full-screen optimized LineWaves hero background",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T12:26:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ddb8dde4a013cea455bb06591081374f99b5f22",
          "body": "Quick-start (install → configure → init/fund → use), the four interfaces, how the\nnon-custodial vault + policy work, dev/deploy, and honest security boundaries.",
          "is_bot": false,
          "headline": "docs: simple, professional README — setup flow, interfaces, architecture",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T12:14:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03e542df2a1f6ae4bc8eb8a5530d822fb786ef4f",
          "body": "GitHub Actions SSHes to the VPS (secrets VPS_HOST/USER/SSH_KEY), pulls latest,\nand runs scripts/deploy-vps.sh: bun install → build to .next-build → atomic swap\ninto .next → pm2 reload lyra-web (near-zero-downtime; a failed build leaves the\nrunning version untouched). Live at https://lyraai.space.",
          "is_bot": false,
          "headline": "ci: auto-deploy web console to VPS on push to main",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T12:01:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cc8e54d8aedbd29808425721c92d392f6aed983",
          "body": null,
          "is_bot": false,
          "headline": "chore: gitignore .npmrc (never commit registry tokens)",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T11:47:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0492b4dea0b7e9485f2c573597612603587e855",
          "body": "…oken)\n\nThe 0.1.0 publish resolved workspace:* against a stale bun.lock, pinning the CLI's\ninternal deps to the old Mantle versions (lyra-core@0.3.3, etc.) which don't exist\non npm — so `bun add lyra-ai-agent` failed to resolve. Replace workspace:* with an\nexplicit ^0.1.1 range across all 6 packages (deterministic on publish, still links\nlocally) and bump to 0.1.1. tsc + 930 tests pass.",
          "is_bot": false,
          "headline": "fix(release): 0.1.1 — pin internal deps to ^0.1.1 (0.1.0 published br…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T11:42:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5f9d8de89c77a4be862a6338133f10a861bb48e",
          "body": "scripts/publish-npm.sh publishes the 6 packages in dependency order via\n`bun publish` (resolves workspace:* → version). Documents the bun-native consumer\ninstall + the 2FA/OTP prereqs.",
          "is_bot": false,
          "headline": "chore(release): add ordered npm publish script",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T10:41:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bca447f7a0007f089b062f8c60a5c5a0a5a141b0",
          "body": "…, not Mantle's lineage\n\nThe 0.3.x/0.4.0 versions were inherited from the Mantle \"Nebula\" project. Lyra\n(Sui) is a distinct project with fresh, unpublished npm names, so versioning\nstarts from the initial 0.1.0 across lyra-core, lyra-plugin-{onchain,system,\ntelegram}, lyra-gateway, and lyra-ai-agent (the CLI).",
          "is_bot": false,
          "headline": "chore(release): reset all packages to 0.1.0 — Lyra is a fresh project…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T10:41:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8a9c0a1df83c59f55200b04d3105d4a11d84183",
          "body": "…cipients\n\nCompletes the recipient-allowlist feature's usability. AgentWalletBar now shows\nthe policy's recipient allowlist state (any/open vs restricted to N payees) and\nlets the owner set it (comma-separated addresses → set_allowed_recipients) or\nre-open it — all owner-signed via dapp-kit. resolveOwnerVault reads the recipients\ndynamic field; /api/agent returns it. Verified: reads the live allowlist.",
          "is_bot": false,
          "headline": "feat(web): payee allowlist UI — owner manages the agent's approved re…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T10:26:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "987ab0d7be352dd1ae5167887ce00008a0f974a0",
          "body": "- ops.ts: webSuiClient() reads LYRA_RPC_URL (point at a dedicated/paid node in\n  prod instead of the public fullnode); used by agent-exec, vault resolver, and\n  /api/agent.\n- Every value-moving action emits one structured JSON line (ts, owner, agent,\n  kind, amount, coin, recipient, route, ok, digest/error) for audit + alerting via\n  a log pipeline. Verified live.",
          "is_bot": false,
          "headline": "feat(web): production ops — configurable RPC + structured audit log",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T10:15:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea968c8bc829d8f625dccd26ec671ddd0fb6a2e",
          "body": "… AgentSigner\n\nTwo of the production blockers from the readiness review:\n\n1. Recipient allowlist (anti prompt-injection). The owner can pin which addresses\n   the agent may pay via policy::set_allowed_recipients (dynamic field, so it works\n   on existing policies — no struct change). vault::vault_tr\n[…]\n a VPS or on managed MPC.\n   +8 derivation unit tests.\n\nUpgraded package 0x8e984145d636037cebf5c402ac4b338567411ba6dd275948d7ff593b1ed01a04.\n930 TS + 21 Move tests pass; web build + tsc + biome clean.",
          "is_bot": false,
          "headline": "feat: production hardening — on-chain recipient allowlist + pluggable…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T10:13:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12358baace5e9a27438ac2d3d9c6d314761d6877",
          "body": "…ndaries",
          "is_bot": false,
          "headline": "docs(demo): Telegram /link identity + honest non-custodial design bou…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T09:53:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05a18b6e4cd870454e38a33918432c5e9bb3c158",
          "body": "…llet (SIWS-style)\n\nCompletes the unified identity model across web + CLI + Telegram. A Telegram user\nproves they own their Sui wallet by signing a one-time challenge (/link → sign →\n/verify <sig>); the bot recovers the signer via verifyPersonalMessageSignature and\nbinds Telegram-user → owner. It th\n[…]\nleLinkStore at\n  ~/.lyra/telegram-owners.json).\n- 8 unit tests (sign→verify→bind, tamper/replay rejection); 191 telegram tests\n  pass total; live round-trip + cross-surface derivation parity verified.",
          "is_bot": false,
          "headline": "feat(plugin-telegram): /link — bind a Telegram user to their owner wa…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T09:52:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c54345768b0ce8890f69eb392218eeae87ee7d50",
          "body": "…ovision\n\nComposable `policy::new_policy` (returns policy + cap) + `policy::share_policy`\nlet `vault::provision<T>` create the policy, open the vault, deposit funds, and\nhand the owner cap back — all in ONE owner-signed PTB. Upgraded on mainnet to\npackage 0xc7c4f8887150035058e70b981896e4f0f868f1d6c2951549398ab364bacb4f90\n(digest Bicqt49e…); full provision → vault_spend → withdraw verified live.",
          "is_bot": false,
          "headline": "feat(move): one-signature onboarding — policy::new_policy + vault::pr…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T09:36:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5990f7f6b70ef57f7aeb204f9cf739a69cbb50ae",
          "body": "…e id",
          "is_bot": false,
          "headline": "docs(demo): non-custodial vault + multi-tenant model, upgraded packag…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T09:34:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f9b4205d48e5da1f86753d9fea3cc45d2c196bd",
          "body": "…easury, not its EOA\n\nWires the non-custodial vault into every surface. The agent no longer spends its\nown EOA funds; it draws from the SIGNED-IN owner's on-chain Vault via vault_spend,\nbounded by the policy. Multi-tenant: each owner → derived agent → own vault.\n\n- contract: one-signature onboarding\n[…]\n provision (1 PTB) → vault-backed transfer 47LJ9qEu… +\n  swap via cetus Gy26vRpQ… (from the vault) → 5-SUI blocked by cap → owner\n  withdraw. Upgraded package 0xc7c4f888…; 914 TS + 18 Move tests pass.",
          "is_bot": false,
          "headline": "feat: vault-backed execution end-to-end — agent spends the owner's tr…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T09:33:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de1ae8df04a4212860921b19348137a6a241dd12",
          "body": "…pgraded on mainnet\n\nProduction direction: funds no longer sit in the agent's EOA. A `Vault<T>` holds\nthe treasury on-chain; the delegated agent can only draw funds via `vault_spend`,\nwhich re-runs the full lyra::policy gate (agent identity, budget, per-tx cap,\ncoin/protocol allowlists, expiry, revo\n[…]\n91bee89d02f6691590211 (digest\n  J7KQ6yZ1…). Full lifecycle verified live: create_policy → open vault → deposit\n  → agent vault_spend (bounded) → owner_withdraw, all in one mainnet PTB\n  (2GMQUiQe7A…).",
          "is_bot": false,
          "headline": "feat(move): non-custodial treasury vault (lyra::vault) — deployed + u…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T09:16:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "519436f55ad22af00a49c0185a039054fda7411b",
          "body": "…gram\n\nEach owner wallet gets ONE deterministically-derived agent (HMAC-SHA256 of a\nserver master secret + owner address → Ed25519), so the same user resolves to the\nsame policy-bound agent on every surface — no per-user key storage.\n\n- plugin-onchain/derive.ts: canonical deriveAgentKeypair/Address \n[…]\nthe web — verified: owner 0x46e3… → agent 0x514f68… on both).\n- Verified on mainnet: the derived agent for an owner executed a transfer\n  (8jpqrA5L…) + swap via bluefin7k (HduffnDr…) under the policy.",
          "is_bot": false,
          "headline": "feat: multi-tenant agents — one owner → one agent across web/CLI/Tele…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T08:59:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b5da3a347ccede8861b3df579335dac82e1172a3",
          "body": "…allet)\n\nReworks the web execution model per the thesis: instead of the user signing each\ntx with their own wallet, the web now drives the SAME policy-bound agent wallet\nthe CLI/gateway/Telegram use. The connected wallet's Sui sign-in (SIWS) only\nproves owner identity — it authorizes directing the a\n[…]\nagent.ts / Chat copy: \"your policy-bound agent executes\", sign-in authorizes.\n- Verified live on mainnet: agent transfer HePrDnRz…, swap via Cetus AsNRxUmg…,\n  5-SUI request blocked by the per-tx cap.",
          "is_bot": false,
          "headline": "feat(web): web drives the policy-bound agent wallet (not the user's w…",
          "author_name": "rifkyeasy",
          "author_login": "rifkyeasy",
          "committed_at": "2026-06-17T08:36:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 7,
      "commits_last_year": 135,
      "latest_release_at": "2026-07-20T09:13:16Z",
      "latest_release_tag": "v0.5.0",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 5,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 5.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "lyra-ai-agent",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lyra",
            "ai",
            "agent",
            "cli",
            "tui",
            "sui",
            "walrus",
            "deepbook",
            "defi"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/lyra-ai-agent",
          "is_deprecated": false,
          "latest_version": "0.4.3",
          "repository_url": "https://github.com/lyraai-protocol/lyra",
          "versions_count": 19,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2124,
          "first_published_at": "2026-06-17T11:38:28.952000Z",
          "latest_published_at": "2026-07-18T16:41:21.898000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "lyra-core",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lyra",
            "ai",
            "agent",
            "sui",
            "treasury",
            "defi",
            "policy"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/lyra-core",
          "is_deprecated": false,
          "latest_version": "0.4.1",
          "repository_url": "https://github.com/lyraai-protocol/lyra",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1643,
          "first_published_at": "2026-06-17T11:38:17.102000Z",
          "latest_published_at": "2026-07-13T13:19:35.403000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        },
        {
          "name": "lyra-gateway",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lyra",
            "ai",
            "agent",
            "gateway",
            "daemon",
            "sui"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/lyra-gateway",
          "is_deprecated": false,
          "latest_version": "0.4.1",
          "repository_url": "https://github.com/lyraai-protocol/lyra",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1234,
          "first_published_at": "2026-06-17T11:38:25.465000Z",
          "latest_published_at": "2026-07-13T13:19:35.552000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        },
        {
          "name": "lyra-plugin-system",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lyra",
            "ai",
            "agent",
            "fs",
            "shell",
            "browser",
            "sandbox",
            "tools",
            "plugin"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/lyra-plugin-system",
          "is_deprecated": false,
          "latest_version": "0.4.1",
          "repository_url": "https://github.com/lyraai-protocol/lyra",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1227,
          "first_published_at": "2026-06-17T11:38:20.831000Z",
          "latest_published_at": "2026-07-13T13:19:35.547000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        },
        {
          "name": "lyra-plugin-onchain",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": null,
          "registry_url": "https://www.npmjs.com/package/lyra-plugin-onchain",
          "is_deprecated": false,
          "latest_version": "0.4.2",
          "repository_url": null,
          "versions_count": 15,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1502,
          "first_published_at": "2026-06-17T11:38:18.848000Z",
          "latest_published_at": "2026-07-13T13:22:50.048000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        },
        {
          "name": "lyra-plugin-telegram",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lyra",
            "ai",
            "agent",
            "telegram",
            "grammy",
            "plugin"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/lyra-plugin-telegram",
          "is_deprecated": false,
          "latest_version": "0.4.1",
          "repository_url": "https://github.com/lyraai-protocol/lyra",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1245,
          "first_published_at": "2026-06-17T11:38:23.066000Z",
          "latest_published_at": "2026-07-13T13:19:35.430000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        },
        {
          "name": "lyra-plugin-onchain-one",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lyra",
            "ai",
            "agent",
            "sui",
            "defi",
            "deepbook",
            "walrus",
            "policy",
            "plugin"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/lyra-plugin-onchain-one",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/lyraai-protocol/lyra",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 403,
          "first_published_at": "2026-07-13T12:53:00.903000Z",
          "latest_published_at": "2026-07-18T10:12:22.327000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-09",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/cli/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/gateway/tsconfig.json",
        "packages/plugin-onchain-one/tsconfig.json",
        "packages/plugin-onchain-two/tsconfig.json",
        "packages/plugin-onchain/tsconfig.json",
        "packages/plugin-system/tsconfig.json",
        "packages/plugin-telegram/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 51042,
      "source_files_sampled": 352,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 1784
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "agent-browser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.26.0"
        },
        {
          "name": "@clack/prompts",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.8.2"
        },
        {
          "name": "@mysten/sui",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.45.2"
        },
        {
          "name": "@opentui/core",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.97"
        },
        {
          "name": "@opentui/solid",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.97"
        },
        {
          "name": "lyra-core",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "lyra-gateway",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "lyra-plugin-onchain",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "lyra-plugin-system",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "lyra-plugin-telegram",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "picocolors",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "qrcode-terminal",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.12.0"
        },
        {
          "name": "solid-js",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.9.12"
        },
        {
          "name": "@mysten/sui",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.40.0"
        },
        {
          "name": "@noble/curves",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "gray-matter",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.3"
        },
        {
          "name": "qrcode-terminal",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.12.0"
        },
        {
          "name": "zod",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.24.1"
        },
        {
          "name": "@mysten/sui",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.45.2"
        },
        {
          "name": "@noble/curves",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "lyra-core",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "lyra-plugin-onchain",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "lyra-plugin-system",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "lyra-plugin-telegram",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "zod",
          "manifest": "packages/gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.24.1"
        },
        {
          "name": "@7kprotocol/sdk-ts",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.0"
        },
        {
          "name": "@cetusprotocol/aggregator-sdk",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.1"
        },
        {
          "name": "@mysten/deepbook-v3",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.18.0"
        },
        {
          "name": "@mysten/sui",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.40.0"
        },
        {
          "name": "@mysten/walrus",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.6.4"
        },
        {
          "name": "@pythnetwork/pyth-sui-js",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.2.0"
        },
        {
          "name": "@scallop-io/sui-scallop-sdk",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.5"
        },
        {
          "name": "@suilend/sdk",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.99"
        },
        {
          "name": "@suilend/sui-fe",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.3.49"
        },
        {
          "name": "lyra-core",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.0"
        },
        {
          "name": "navi-sdk",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.7.3"
        },
        {
          "name": "zod",
          "manifest": "packages/plugin-onchain-one/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.23.8"
        },
        {
          "name": "@mysten/sui",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.20.3"
        },
        {
          "name": "@wormhole-foundation/sdk",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "@wormhole-foundation/sdk-sui",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "lyra-core",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@wormhole-foundation/sdk-evm",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "@wormhole-foundation/sdk-sui-cctp",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "@wormhole-foundation/sdk-evm-cctp",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "@wormhole-foundation/sdk-base",
          "manifest": "packages/plugin-onchain-two/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "lyra-core",
          "manifest": "packages/plugin-onchain/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "lyra-plugin-onchain-one",
          "manifest": "packages/plugin-onchain/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "lyra-core",
          "manifest": "packages/plugin-system/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "agent-browser",
          "manifest": "packages/plugin-system/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.26.0"
        },
        {
          "name": "zod",
          "manifest": "packages/plugin-system/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.24.1"
        },
        {
          "name": "@mysten/sui",
          "manifest": "packages/plugin-telegram/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.45.0"
        },
        {
          "name": "grammy",
          "manifest": "packages/plugin-telegram/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.42.0"
        },
        {
          "name": "lyra-core",
          "manifest": "packages/plugin-telegram/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "zod",
          "manifest": "packages/plugin-telegram/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.23.8"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 29,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "rifkyeasy",
          "commits": 135,
          "avatar_url": "https://avatars.githubusercontent.com/u/239689192?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 8,
            "reason": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/19 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "38 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "892f33455c3bf47fc8ff335e5b3cae35b69bcd5d",
        "ran_at": "2026-07-24T02:25:07Z",
        "aggregate_score": 2.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T09:11:42Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-20T09:10:42Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/lyraai-protocol/lyra",
    "host": "github.com",
    "name": "lyra",
    "owner": "lyraai-protocol"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 24,
        "vitality": 75,
        "community": 34,
        "governance": 50,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 135,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 5
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "5/52 weeks with commits",
                "points": 3.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "135 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 135
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 7,
              "latest_release_tag": "v0.5.0",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 5.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "7 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~5.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 5.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 34,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "packages": [
                "lyra-ai-agent",
                "lyra-core",
                "lyra-gateway",
                "lyra-plugin-system",
                "lyra-plugin-onchain",
                "lyra-plugin-telegram",
                "lyra-plugin-onchain-one"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 9378
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "9,378 downloads/month across npm",
                "points": 53,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 9378,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 50,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 29,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "29/29 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 29,
                      "decided": 29
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/19 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "lyraai-protocol",
              "public_repos": 3,
              "account_age_days": 12
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of lyraai-protocol",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "lyraai-protocol"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "3 public repos, account ~0 yr old",
                "points": 4.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 3
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "lyra-ai-agent",
                "lyra-core",
                "lyra-gateway",
                "lyra-plugin-system",
                "lyra-plugin-onchain",
                "lyra-plugin-telegram",
                "lyra-plugin-onchain-one"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "7 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 7,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "19 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
                "points": 16,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "ai-agent",
                "blockchain",
                "deepbook",
                "defi",
                "move",
                "non-custodial",
                "sui",
                "typescript",
                "walrus",
                "web3"
              ],
              "has_wiki": false,
              "homepage": "https://lyraai.space",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://lyraai.space",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 24,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 24,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 2.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/19 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "38 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 68,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 1784
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 44,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/cli/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/gateway/tsconfig.json",
                "packages/plugin-onchain-one/tsconfig.json",
                "packages/plugin-onchain-two/tsconfig.json",
                "packages/plugin-onchain/tsconfig.json",
                "packages/plugin-system/tsconfig.json",
                "packages/plugin-telegram/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/gateway/tsconfig.json, packages/plugin-onchain-one/tsconfig.json, packages/plugin-onchain-two/tsconfig.json, packages/plugin-onchain/tsconfig.json, packages/plugin-system/tsconfig.json, packages/plugin-telegram/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/gateway/tsconfig.json, packages/plugin-onchain-one/tsconfig.json, packages/plugin-onchain-two/tsconfig.json, packages/plugin-onchain/tsconfig.json, packages/plugin-system/tsconfig.json, packages/plugin-telegram/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 51042,
              "source_files_sampled": 352,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/352 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 352,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:lyra-ai-agent@0.4.3; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T02:25:22.738870Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/lyraai-protocol/lyra.svg",
  "full_name": "lyraai-protocol/lyra",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.