原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [
"ai-agents",
"claude-code",
"cli",
"codex",
"config-sync",
"cursor",
"developer-tools",
"mcp"
],
"is_fork": false,
"size_kb": 18651,
"has_wiki": true,
"homepage": "https://samplexbro.github.io/agentsmesh/",
"languages": {
"CSS": 10993,
"MDX": 388527,
"Astro": 5574,
"Shell": 7910,
"Python": 757052,
"JavaScript": 16844,
"TypeScript": 8976446,
"Go Template": 680
},
"pushed_at": "2026-07-22T20:39:33Z",
"created_at": "2026-03-25T07:35:43Z",
"owner_type": "User",
"updated_at": "2026-07-26T20:20:50Z",
"description": "One reliable canonical source for AI coding agent rules, commands, skills, MCP, hooks, and permissions — synced across AI coding assistants.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "master",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": "Serhii Zhabskyi",
"type": "User",
"login": "sampleXbro",
"company": null,
"location": "Germany",
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/55853222?v=4",
"created_at": "2019-09-26T18:32:13Z",
"is_verified": null,
"public_repos": 14,
"account_age_days": 2500
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.32.0",
"kind": "minor",
"published_at": "2026-07-22T20:40:22Z"
},
{
"tag": "v0.31.0",
"kind": "minor",
"published_at": "2026-07-20T19:18:05Z"
},
{
"tag": "v0.30.2",
"kind": "patch",
"published_at": "2026-07-10T06:33:50Z"
},
{
"tag": "v0.30.1",
"kind": "patch",
"published_at": "2026-07-08T20:46:36Z"
},
{
"tag": "v0.30.0",
"kind": "minor",
"published_at": "2026-07-07T15:33:22Z"
},
{
"tag": "v0.29.0",
"kind": "minor",
"published_at": "2026-06-28T09:07:25Z"
},
{
"tag": "v0.28.0",
"kind": "minor",
"published_at": "2026-06-26T12:50:57Z"
},
{
"tag": "v0.27.0",
"kind": "minor",
"published_at": "2026-06-26T05:32:57Z"
},
{
"tag": "v0.26.0",
"kind": "minor",
"published_at": "2026-06-23T16:16:35Z"
},
{
"tag": "v0.25.0",
"kind": "minor",
"published_at": "2026-06-18T15:25:12Z"
},
{
"tag": "v0.24.0",
"kind": "minor",
"published_at": "2026-06-16T18:51:30Z"
},
{
"tag": "v0.23.0",
"kind": "minor",
"published_at": "2026-06-13T18:34:10Z"
},
{
"tag": "v0.22.0",
"kind": "minor",
"published_at": "2026-06-03T08:59:44Z"
},
{
"tag": "v0.21.0",
"kind": "minor",
"published_at": "2026-05-29T13:08:35Z"
},
{
"tag": "v0.20.0",
"kind": "minor",
"published_at": "2026-05-27T12:56:42Z"
},
{
"tag": "v0.19.1",
"kind": "patch",
"published_at": "2026-05-25T20:47:53Z"
},
{
"tag": "v0.19.0",
"kind": "minor",
"published_at": "2026-05-25T16:02:42Z"
},
{
"tag": "v0.18.1",
"kind": "patch",
"published_at": "2026-05-15T12:11:21Z"
},
{
"tag": "v0.18.0",
"kind": "minor",
"published_at": "2026-05-11T14:07:24Z"
},
{
"tag": "v0.17.0",
"kind": "minor",
"published_at": "2026-05-11T07:17:30Z"
},
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2026-05-08T17:16:06Z"
},
{
"tag": "v0.15.0",
"kind": "minor",
"published_at": "2026-05-08T09:48:44Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2026-05-06T19:25:56Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2026-05-06T11:51:42Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-05-04T19:04:27Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2026-05-03T19:03:20Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-05-02T08:29:34Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-04-29T09:28:47Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-04-28T08:13:19Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-04-27T08:06:02Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-04-25T20:02:38Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-04-23T10:23:19Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-04-12T13:39:30Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-04-12T11:57:46Z"
},
{
"tag": "v0.2.10",
"kind": "patch",
"published_at": "2026-03-31T10:17:05Z"
},
{
"tag": "v0.2.9",
"kind": "patch",
"published_at": "2026-03-29T14:52:01Z"
},
{
"tag": "v0.2.8",
"kind": "patch",
"published_at": "2026-03-29T10:47:04Z"
},
{
"tag": "v0.2.6",
"kind": "patch",
"published_at": "2026-03-28T17:18:37Z"
},
{
"tag": "v0.2.5",
"kind": "patch",
"published_at": "2026-03-28T07:50:44Z"
},
{
"tag": "v0.2.4",
"kind": "patch",
"published_at": "2026-03-27T22:36:11Z"
},
{
"tag": "v0.2.3",
"kind": "patch",
"published_at": "2026-03-27T10:13:10Z"
},
{
"tag": "v0.2.2",
"kind": "patch",
"published_at": "2026-03-26T12:22:17Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-03-26T08:45:17Z"
}
],
"recent_commits": [
{
"oid": "ac8e24449c34f19925721dc60a0d902f5217b1e3",
"body": "chore: version packages",
"is_bot": false,
"headline": "Merge pull request #104 from sampleXbro/changeset-release/master",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-22T20:38:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70f6a822747a21e0e05b267346110a0949060433",
"body": null,
"is_bot": true,
"headline": "chore: version packages",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-22T20:29:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8662544f7b4fb1c3e8c7aba4f9d5c6ca66a81860",
"body": "Develop",
"is_bot": false,
"headline": "Merge pull request #105 from sampleXbro/develop",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-22T20:29:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "41eeba537784b316735ca078fff1e76dc91ede8a",
"body": "Transitive via @modelcontextprotocol/sdk > ajv > fast-uri (was 3.1.2). Clears GHSA-v2hh-gcrm-f6hx and GHSA-4c8g-83qw-93j6 (host confusion) so 'pnpm audit --prod --audit-level=high' passes CI. Override added to package.json + pnpm-workspace.yaml and lockfile regenerated with pnpm 10 (lockfile stays 9.0); frozen install verified exit 0.",
"is_bot": false,
"headline": "fix(deps): override fast-uri to ^3.1.4 to clear high-severity advisories",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-22T19:59:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0daa7d4ebc472784af354fbb14ab69b389cca4aa",
"body": "…th current repo\n\nPin pnpm 10 (pnpm 11 trips --frozen-lockfile on the lockfile); note CI Node 22/24; document the husky pre-commit gate and lint:dead. Add the load-bearing rules that were missing: never edit generated files (.agentsmesh is source of truth), docs must stay current, strict artifact te\n[…]\ns/interface shapes. Add a dedicated Changesets section (published surface vs no-ship dirs; never hand-edit version/CHANGELOG). Expand the real CI gate list and fix the mis-nested capabilities heading.",
"is_bot": false,
"headline": "docs(contributing): align dev commands, gates, and changeset rules wi…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-22T19:46:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a7229213b9b1a8b90f6373c33fc41a6082e147a5",
"body": "…-in trigger repair\n\nPreToolUse recurrence gate: when the exact action has already failed >=2x and a captured lesson covers it, re-inject the covering rule above the recall bullets as a RECURRENT FAILURE escalation that cuts through session dedup. Advisory-only, once per action per session; the esca\n[…]\n to itself.\n\nSplit captureLesson into capture.ts for the 200-line cap; update CLI/MCP/public importers. Docs (README + cli/reference mdx), changeset, and resynced .agentsmesh/.lock (0.30.1 -> 0.31.0).",
"is_bot": false,
"headline": "feat(lessons): recurrence-gate escalation, per-session telemetry, opt…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-22T19:38:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "69ec8334a702bf53ef5276b0f67e91110e10667b",
"body": "Develop",
"is_bot": false,
"headline": "Merge pull request #103 from sampleXbro/develop",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-21T18:09:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65c153705f76f28262b6e035762ee86adacf126f",
"body": "fix(check): detect stale generated outputs",
"is_bot": false,
"headline": "Merge pull request #102 from VVeb1250/check-stale-outputs",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-21T17:05:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a180aedd95607500c4698a6331e1cba3b0a4a2af",
"body": "pnpm audit --prod --audit-level=high failed on tar versions up to 7.5.18:\n- critical GHSA-23hp-3jrh-7fpw (decompression/parse DoS), patched 7.5.19+\n- high GHSA-8x88-c5mf-7j5w (negative entry size infinite loop), patched 7.5.18+\n\ntar is a direct prod dependency, so bumping the pin from 7.5.13 to 7.5.20\nclears both. Lockfile regenerated with pnpm 10 to match CI; frozen install\nand the audit gate both verified green. Pre-existing issue, unrelated to\nthe check changes on this branch.",
"is_bot": false,
"headline": "fix(deps): bump tar to 7.5.20 to clear high/critical advisories",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-21T16:30:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "49d70d2a098d43ac744d5d4853677b851a6ede80",
"body": "Stale-output detection adds new user-facing behavior plus additive CLI\nJSON and MCP result fields (canonicalDrift, outputDrift, outputsStale).\nUnder semver that is a backward-compatible feature, so minor is the\ncorrect bump for a 0.x release rather than patch.",
"is_bot": false,
"headline": "chore(changeset): bump check-stale-outputs from patch to minor",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-21T16:03:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "626a50699eda27277d9fbe9046f0c1a84e6cf887",
"body": "Per the repo 'plugins are first-class targets' contract, any code that\niterates targets must hold for registered plugin descriptors, not just\nbuiltins. The stale-output scan iterates config.pluginTargets, so add a\nlock-sync test that registers a plugin descriptor with a managedOutputs\nlayout and asserts a hand-added file under its managed dir is reported in\noutputsStale (resolved via getDescriptor, not builtin-only).",
"is_bot": false,
"headline": "test(check): cover stale detection for registered plugin descriptors",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-21T16:03:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "076a683afe9bda0b6bc17035b3ac409635c6d54d",
"body": "The stale-output scan spread config.pluginTargets directly; every other\ncall site in the codebase guards it with '?? []'. ValidatedConfig always\npopulates the field, so this is a robustness/consistency fix for configs\nconstructed outside the Zod parse path.",
"is_bot": false,
"headline": "fix(check): default pluginTargets when scanning for stale outputs",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-21T16:02:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9efbab1f0c7412361a8f0099d4f03bb2e7b49161",
"body": null,
"is_bot": false,
"headline": "fix(check): detect stale generated outputs",
"author_name": "VVeb1250",
"author_login": "VVeb1250",
"committed_at": "2026-07-21T06:30:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8afffa67c60955dade1dc2ac34750ce2726582cc",
"body": "chore: version packages",
"is_bot": false,
"headline": "Merge pull request #101 from sampleXbro/changeset-release/master",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-20T19:16:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8085c8965341dcad3ff90fab4bbaec0a90c8346f",
"body": null,
"is_bot": true,
"headline": "chore: version packages",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-20T19:07:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1231ac42791bda71dcb24947418b053e3e20bbe7",
"body": "Develop",
"is_bot": false,
"headline": "Merge pull request #100 from sampleXbro/develop",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-20T19:06:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8f3fa87c37a6a6e79496c89406350dc0972d704",
"body": "generateRules built the execution-rule output path with\n`rule.source.split('/').pop()`, which on Windows leaves the whole native\nbackslash absolute path as the \"slug\" — emitting a bogus\n`.codex/rules/C:\\...\\.agentsmesh\\rules\\<name>.rules`. Its dirname mkdir\nthrows ENOENT (drive-colon mid-path), so `\n[…]\nename regardless\nof platform. Adds a platform-independent regression test feeding a Windows\nabsolute source. Fixes codex-format-roundtrip, global-roundtrip-codex e2e\nand generate unit test on Windows.",
"is_bot": false,
"headline": "fix(codex-cli): derive .rules slug via both path separators (Windows)",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-19T18:20:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bb8bba0c1a3fdbc1cc516d470c7f7c653a84d0da",
"body": "…act ignores\n\nThe .cursor/, .kiro/, .warp/ (and sibling) ignore patterns were unanchored,\nso they matched the same-named dirs inside tests/e2e/fixtures/ too. Three\nfixture sources were thus silently gitignored and never committed:\n cursor-project/.cursor/cli.json -> permissions.yaml\n kiro\n[…]\nilently skips emission, failing import-capabilities\ne2e only on CI. Root-anchor every generated-artifact pattern (leading /,\nmatching the existing /docs//tasks/ convention) and commit the three files.",
"is_bot": false,
"headline": "test(e2e): recover gitignored import fixtures; anchor generated-artif…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-19T17:00:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0c6774dc818a95e1f5515f0b98dbd258f63c694",
"body": "Trailing working-tree artifacts from the completed check output-drift work\n(1991a3ff): captured lessons (incl. pnpm three-source override sync), the\nFix #98 task log, and the regenerated agents e2e run report.",
"is_bot": false,
"headline": "chore: sync lessons graph and Fix #98 task/e2e artifacts",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-19T16:22:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2e5b97bc49dc4b3e0c0342e91c4bee177ecc8244",
"body": "The hono ^4.12.25 CORS-advisory override (68851507) was added only to\npackage.json pnpm.overrides, leaving pnpm-workspace.yaml and the lockfile\noverrides snapshot stale. This broke CI's pnpm 10 --frozen-lockfile with\nERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Add hono to the workspace overrides and\nregenerate the lock so all three sources agree.",
"is_bot": false,
"headline": "fix(deps): sync hono override across pnpm-workspace.yaml and lockfile",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-19T16:17:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1991a3ff87d7155cd048ea7212f965b3b9b901d0",
"body": "agentsmesh check verified only canonical sources against the lock, so\ndirect edits to generated files passed CI despite documented behavior.\n\n- generate records checksums of all generated outputs in .agentsmesh/.lock\n (outputs map); full runs replace the map, --targets/--features runs\n merge per-p\n[…]\n(passes projectRoot)\n- merge's lock rewrite intentionally omits outputs until regenerate\n- docs: check/generate/merge CLI pages, CI guide, generation pipeline,\n MCP reference, README lock description",
"is_bot": false,
"headline": "fix(check): detect generated-output drift via lock outputs map (#98)",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-19T15:32:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a09ae2043390a67a41acc1db2b41dcb3dacb532d",
"body": "…, sync generated outputs",
"is_bot": false,
"headline": "chore: encode fast audit playbook in update-target-capabilities skill…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:33:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "94539f4ef6bcb18c2d8b4dfff8eed875848e50d7",
"body": "…ect cell formats and fingerprints",
"is_bot": false,
"headline": "test(capabilities): add global-scope ledger conformance harness, corr…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:33:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0ea9e4fbfba472f9fcd4a97c8e9eb0f9d2700caa",
"body": null,
"is_bot": false,
"headline": "fix(crush): merge all global settings features into one crush.json",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:33:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "059b177aaad66ec6b0260faf7987ab219ffceba6",
"body": null,
"is_bot": false,
"headline": "feat(capabilities): add text ledger format for plain-text surfaces",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:33:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4f22f2cdc1b528d5fac28de31342437df5b0192",
"body": null,
"is_bot": false,
"headline": "chore: update lessons graph and task notes",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e421a7451578cd9b64f2306449c17bcf2b278477",
"body": null,
"is_bot": false,
"headline": "docs: regenerate support matrix and sync target docs",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6fa5852c1532e27ff593b3608f47621cc36b8317",
"body": "…ed, 21 rejected cells)",
"is_bot": false,
"headline": "chore(capabilities): record verified research provenance (182 confirm…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f27b64a9b73cf7bbe6fe463acaee597609dc305",
"body": "…te all builtin descriptors",
"is_bot": false,
"headline": "test: sync cross-cutting suites with capability audit changes, valida…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4cca64a1a258a63d4c84248d7d5235be9c01381e",
"body": "…ls round-trip",
"is_bot": false,
"headline": "fix(zed): revert hooks to none (unshipped proposal), wire global skil…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5be661a0a41600bfb8218e552091c93fe5ee455c",
"body": "…ions partial with lint coverage",
"is_bot": false,
"headline": "fix(windsurf): raise global additionalRules to embedded, keep permiss…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc4c1b681ce5ff9501dc7bd1f5f629509f2ca6ca",
"body": "… changeset with raises",
"is_bot": false,
"headline": "fix(warp): move project MCP to .warp/.mcp.json native surface, extend…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5df6c130eda11b9521a78bcfd0785273f6080b0",
"body": "… full test coverage",
"is_bot": false,
"headline": "feat(trae): raise hooks to native, add agents importer round-trip and…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "66e3da4ec102d4b8baaab3f539fd3878622c0930",
"body": "…audit",
"is_bot": false,
"headline": "fix(rovodev): sync global layout tests and changeset with capability …",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "948b97dafe38710f62cd2201aab4d539a3606309",
"body": "…nore)",
"is_bot": false,
"headline": "fix(roo-code): downgrade global ignore to none (workspace-only .rooig…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73b48723c157e13189ab49f323928c80c13b270a",
"body": "…h no-op stubs",
"is_bot": false,
"headline": "feat(replit-agent): raise mcp/hooks/ignore/permissions to partial wit…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27c977f0b9ee0ea91647aa026248aca84a94008a",
"body": "…lint messaging",
"is_bot": false,
"headline": "fix(pi-agent): downgrade mcp to none (no MCP surface in pi), correct …",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "763ff061e22fdc7de5554bd35c932ff76cb013a6",
"body": "…te fix",
"is_bot": false,
"headline": "fix(opencode): sync scoped-settings tests and changeset with rules-ga…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "054ff57e3f4188c0cb31cd994698977d97b5e315",
"body": "…obal and permissions to partial",
"is_bot": false,
"headline": "feat(kiro): migrate hooks to v1 trigger/action schema, raise hooks/gl…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9ac38a0181e4f1ce218ecaaed597c142494f00e3",
"body": null,
"is_bot": false,
"headline": "fix(kilo-code): align hooks comments with plugin-based partial surface",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:03:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5dcf7310810e3fd29e1cb1a9b349fac287299336",
"body": "…dded, permissions/project to partial",
"is_bot": false,
"headline": "fix(junie): correct allowlist.json schema, raise hooks/global to embe…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:02:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac93729e87ed54985e05800125ac1bcaabbac73f",
"body": "…ith lint warnings",
"is_bot": false,
"headline": "feat(jules): raise commands/mcp/hooks/ignore/permissions to partial w…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:02:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27799dd54446ebff7fd9113e6073b3031b6cbd20",
"body": "…rtial, scope-gate lintMcp",
"is_bot": false,
"headline": "feat(goose): raise commands/agents to embedded, mcp/permissions to pa…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:02:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4b78f5754ddcf62d08bf01c1bf90cb9618d68ee",
"body": null,
"is_bot": false,
"headline": "feat(gemini-cli): raise hooks to native with full event mapping",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:02:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "969b4a40c16997859bb9d7147d8ed575bdd13525",
"body": "…e, raise permissions to native",
"is_bot": false,
"headline": "feat(factory-droid): move hooks to .factory/hooks.json primary surfac…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:02:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d06e01fab455de27a0982103160f4a743f49e178",
"body": "…r docs)",
"is_bot": false,
"headline": "fix(deepagents-cli): revert project hooks to none (no file surface pe…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T08:02:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45684bd1f3ffd670b815ab810822baf2c2c015ec",
"body": "…or/cli-config.json",
"is_bot": false,
"headline": "feat(cursor): raise permissions to native, fix global path to ~/.curs…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:57:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "944efc259bdebd0af2d86de6fc40af38057c8319",
"body": "…mmands to embedded",
"is_bot": false,
"headline": "feat(crush): raise permissions to native with round-trip importer, co…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:55:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "26c4a84d4e0998c24d55adbf65e30e1cf2a17df4",
"body": null,
"is_bot": false,
"headline": "fix(copilot): sync capability lint and declarations with verified audit",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:52:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cec0e7acb9036170b7a9e6dbcb7363b1d218fad8",
"body": "…re round-trip)",
"is_bot": false,
"headline": "feat(continue): raise ignore to native for both scopes (.continueigno…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:50:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7addacfaa5a15d5d2211122da43b1b9f48190b1c",
"body": "…er and content contracts",
"is_bot": false,
"headline": "fix(cline): move agents to documented .cline/agents.yaml, sync import…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:47:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91d3885352f02748509156d6c633f74df1d83928",
"body": null,
"is_bot": false,
"headline": "feat(augment-code): raise global hooks from none to native",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:40:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a9698e3cd636e5a04516c52ea3eae3faca7e8cea",
"body": "…ws path to ~/.gemini/antigravity/global_workflows/",
"is_bot": false,
"headline": "feat(antigravity): promote commands to native, correct global workflo…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:37:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a1a0cb92e2ef688b8c0b279d188c3347f2c7d57b",
"body": "…ties",
"is_bot": false,
"headline": "fix(amp): sync tests and lint with downgraded commands/hooks capabili…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:34:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b71fd29dce7dfe9a5fa14f05aaefe1f803662ce6",
"body": "…ledger cells",
"is_bot": false,
"headline": "feat(amazon-q): raise hooks and permissions to embedded, add missing …",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:32:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "580c7ea20922e8776deabf19f80d8f8d6931e1d9",
"body": "…-op stubs",
"is_bot": false,
"headline": "feat(aider): raise mcp/hooks/permissions from none to partial with no…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:29:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e2059144ed9d59ed4a39b8dfc7e9b8654904d4cb",
"body": "… loss, report over-declared cells\n\n- src/core/capabilities/merge.ts: extract mergeCell/hasNonEmptyFingerprint into pure unit-tested module; register pnpm capabilities:merge script\n- scripts/merge-capability-ledger.ts: fix two data-loss bugs — confirmed/rejected cells now keep their researched maxAc\n[…]\nrt over-declared cells independently from unverified so both signals surface together\n- package.json/pnpm-lock.yaml: register capabilities:merge script\n- CONTRIBUTING.md: document audit/merge workflow",
"is_bot": false,
"headline": "feat(capabilities): extract merge logic, fix fingerprint/ceiling data…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:26:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd6d532003f22c0c17588cef19c35495e30234aa",
"body": "…gnore-lint dispatch\n\n- reference/map.ts, output-source-map.ts: track combined-agent output sources so the rewriter resolves references inside merged agent files\n- import-maps/cline.ts, roo-code.ts, trae.ts: add missing import-map entries for agent and hook paths introduced by capability audit\n- gen\n[…]\nlinter.ts: dispatch descriptor.lint.ignore so partial-ignore targets (Jules, Pi Agent, Kiro, etc.) emit warnings\n- zed/lint.ts: remove unused lintHooks export (hooks=none; silent-drop guard covers it)",
"is_bot": false,
"headline": "fix(core): handle combined-agent reference rewrite, rules gate, and i…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-18T07:23:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "41fd09542d4dd9aa93dbc5f88a2f808972adfaef",
"body": "…global ignore\n\n- Rules/AdditionalRules/Commands/Agents (global, native): move from the\n ~/.kilo/ mirror to the documented ~/.config/kilo/ unified config dir;\n non-root rules now register under kilo.jsonc's `instructions` key\n (a bare rules dir isn't auto-loaded at global scope).\n- MCP (global, n\n[…]\ns (workspace-root-only per kilo's own docs).\n- Skills (global) re-verified unchanged: ~/.kilo/skills/ is correct.\n- Update capability-ledger.json, README/website support matrix, and add\n a changeset.",
"is_bot": false,
"headline": "fix(kilo-code): unify global config under ~/.config/kilo/, downgrade …",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T06:47:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cc7de1064b9d275b4d339d98d55d91d3508cab4d",
"body": "…nds, downgrade project hooks\n\n- hooks (project): native -> none; docs.langchain.com/oss/javascript/deepagents/code/hooks\n documents only the global ~/.deepagents/hooks.json, no project-level surface exists\n- hooks (global): broken-fix; generator wrote Claude-Code-style {EventName:[...]} shape,\n D\n[…]\ncells + one rejected for project hooks),\n README/docs support matrices, and blast-radius references (import-maps, contract\n paths, e2e reference-targets, target-contract-matrix projected-agents set)",
"is_bot": false,
"headline": "fix(deepagents-cli): scope global paths per-agent, raise agents/comma…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T06:07:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e61f789a25c82886a45e2542c66a8aff17cf8d1b",
"body": "…schema\n\n- Commands (project + global, none -> native): .rovodev/prompts.yml\n (+ ~/.rovodev/prompts.yml) saved-prompts manifest, with a\n .rovodev/commands/<name>.md content file per canonical command.\n Commands are no longer projected as skills for this target.\n- MCP (project): native -> none. No\n[…]\nls.bash.{default,commands} schema instead of a flat\n allow/deny/ask list.\n- Updated capability ledger, README/website support matrix, contract\n fixtures, and reference-rewrite test helpers to match.",
"is_bot": false,
"headline": "fix(rovodev): raise commands to native, fix mcp path and permissions …",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T04:46:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0fa60696fabf99d37283d74adab0763c63060717",
"body": "…ents/mcp/hooks/rules\n\nRebase the cline target on the standalone CLI's documented layout\n(docs.cline.bot/cli/cli-reference) instead of the VS Code extension's\nIDE-era paths, per confirmed capability-drift research.\n\n- rules (project+global, native): .clinerules/{slug}.md -> .cline/rules/;\n ~/Docume\n[…]\nrkflows/ path is kept.\n\nRecords ledger provenance for every changed cell and syncs README +\nwebsite docs (support matrix, global-mode paths table, CLI reference\nprose, hooks Windows-portability note).",
"is_bot": false,
"headline": "fix(cline): rebase on standalone CLI paths, raise permissions, fix ag…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T03:54:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3462660182002ffa0e221cd17f2c9c070ea83982",
"body": "- commands (project+global): native -> embedded. Amp has no declarative\n slash-command file format (ampcode.com/manual); commands only exist\n via amp.registerCommand(...) in a TS plugin. Generated output is\n unchanged (still .agents/skills/<name>/SKILL.md via the native skills\n surface) -- only \n[…]\nn\n with the verification trail.\n- Updated capability-ledger.json (commands confirmed embedded; hooks\n marked rejected for both scopes) and synced README/website support\n matrix via matrix:generate.",
"is_bot": false,
"headline": "fix(amp): downgrade commands to embedded, hooks to none",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T02:30:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c24a762d6492149448ff2e688b013e085e0fbb37",
"body": "…and frontmatter keys\n\n- additionalRules (global): embedded -> native. Non-root rules now write\n real files to ~/.qwen/rules/<slug>.md (loadRules() reads .qwen/rules/\n from both global and project dirs identically) instead of being folded\n into ~/.qwen/QWEN.md's body. Adds QWEN_GLOBAL_RULES_DIR, \n[…]\nbal,\n commands project+global) as confirmed with source URLs.\n- Docs: regenerate README.md / supported-tools.mdx support matrices;\n hand-update the global-mode paths table row for the new rules dir.",
"is_bot": false,
"headline": "fix(qwen-code): raise global additionalRules to native, fix rule/comm…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T01:59:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27f3a6133935d9c355aa59f8eae57376d18d6369",
"body": "…tive)\n\n- additionalRules (project + global): .opencode/rules/<slug>.md files are\n now also declared in opencode.json's instructions array (project glob\n .opencode/rules/*.md; global absolute ~/.config/opencode/rules/*.md).\n OpenCode does not auto-scan any rules directory (opencode.ai/docs/rules)\n[…]\ntive-directory prefix\n legitimately appearing in its own generated settings file is not a\n cross-target leak; exclude the current target's own prefix from the\n no-target-specific-prefix-leak check.",
"is_bot": false,
"headline": "fix(opencode): fix broken additionalRules and agents (native stays na…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T01:26:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "df5bf44117e026dc555354588c7b5f97aa6c5cd1",
"body": "… commands\n\n- MCP (global): none -> native. ~/.copilot/mcp-config.json (mcpServers key),\n wired via globalSupport.scopeExtras with generator + importer round-trip.\n Corrects a prior ledger cell that pointed at the VS Code extension's\n OS-specific user-profile mcp.json instead of Copilot CLI's own\n[…]\nnote: the research pass also flagged canonical Notification\nhooks as unsupported -- current docs contradict that ('notification' is a\nreal, documented Copilot hook event), so no change was made there.",
"is_bot": false,
"headline": "fix(copilot): raise global mcp/hooks, fix hooks matcher, drop phantom…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-12T00:39:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8cae45c072efb3af8f9b3a47c9e004b67e012b80",
"body": "- permissions (project+global): none -> native via .codex/rules/*.rules\n using the same Starlark prefix_rule(pattern, decision, justification)\n DSL Codex already documents for command-execution permission decisions\n- hooks (project+global): drop canonical Notification hooks (no matching\n Codex li\n[…]\nheaders) on both generate and import; the importer previously\n hardcoded type:'stdio' and dropped url-based servers on import\n\nRecorded ledger provenance for all changed cells and synced README/docs.",
"is_bot": false,
"headline": "fix(codex-cli): raise permissions to native, fix broken hooks/rules/mcp",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T23:44:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d715e69e6c4bed0e064967bde437d914c06ffebf",
"body": "…ns to native\n\n- agents (project/global): emit required groups + non-empty roleDefinition\n in .roomodes / custom_modes.yaml (Roo's modeConfigSchema has no default\n for either, so omitting them silently dropped ALL modes on load)\n- agents (global): fix custom_modes.yaml path to ~/.roo/settings/... \n[…]\nayout.ts/merge.ts to stay under the 200-line limit.\nCore: generatePermissionsFeature now passes scope context to generators.\n\nRecorded ledger provenance for all 6 changed cells and synced README/docs.",
"is_bot": false,
"headline": "fix(roo-code): fix broken agents/rules/mcp/ignore and raise permissio…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T23:39:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fbc1aecf2fd1df15870ce66e411c3d710394bf31",
"body": "warp/mcp/global, copilot/mcp/global, gemini-cli/hooks (proj+global) confirmed\nraise-candidates; windsurf/mcp/global confirmed native; windsurf project,\ncopilot/hooks, kiro/hooks rejected with evidence.",
"is_bot": false,
"headline": "chore(capabilities): record verified research findings in ledger",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T19:11:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c09be1c9e60b3e213676bab1b9b4c24f51e71b9d",
"body": null,
"is_bot": false,
"headline": "feat(warp): support global MCP config (~/.warp/.mcp.json) natively",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T19:05:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "25f84e94785b671a8f7ffe5169603cecb3dc5cac",
"body": "…cate cells)",
"is_bot": false,
"headline": "test(capabilities): enforce ledger integrity (no orphan/invalid/dupli…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T17:57:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5369c3befe275951736497668aa62acd15ad6f86",
"body": "…dd changeset",
"is_bot": false,
"headline": "docs(capabilities): document audit workflow, drop temp knip ignore, a…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T17:47:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a081333abf7411e168190500b3fa4d98d6d4ee8",
"body": null,
"is_bot": false,
"headline": "docs(skill): make update-target-capabilities audit-driven",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T17:18:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6223a3525c1c0bbf6a949d888b4d78f7484b301c",
"body": null,
"is_bot": false,
"headline": "feat(capabilities): seed capability ledger from generated output",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T17:07:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "263aadb2bb7d31a07bcbfc540362dd0ddded8423",
"body": "…ripts",
"is_bot": false,
"headline": "feat(capabilities): add capabilities:audit and capabilities:verify sc…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T16:51:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e428c4ec7810aa649a4e3bde535272cc1164488",
"body": null,
"is_bot": false,
"headline": "test(capabilities): add ledger conformance harness",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T16:47:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b0ce8aec4f54c607264a66cb36551930fa01db9",
"body": null,
"is_bot": false,
"headline": "feat(capabilities): add structural fingerprint parse/derive/check",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T16:45:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f39ea75ff7a38d699981568aa8912163ba73b22",
"body": null,
"is_bot": false,
"headline": "feat(capabilities): add deterministic audit engine (gaps/stale/missing)",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T16:35:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "259cc8791c3c067780ad6be5ad154484237d9b76",
"body": null,
"is_bot": false,
"headline": "feat(capabilities): load and validate the capability ledger",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T16:25:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c486b787082ede99eb5c14ae8cdb1c61479acfdb",
"body": "Add LedgerCell, CapabilityLedger, LEVEL_RANK, CAPABILITY_FEATURES, and\nCAPABILITY_SCOPES to src/core/capabilities/ledger-types.ts. Suppress knip\nunused-export warnings for this file via ignoreIssues since consumers\narrive in subsequent tasks.",
"is_bot": false,
"headline": "feat(capabilities): add capability ledger types and level rank",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-11T16:22:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a09c1ccb813ad7d140d4b2cea4bf27d2f26d4b34",
"body": "chore: version packages",
"is_bot": false,
"headline": "Merge pull request #97 from sampleXbro/changeset-release/master",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-10T06:32:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3a4f87b8dacedfd82be659ba6e4588418555901",
"body": null,
"is_bot": true,
"headline": "chore: version packages",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-10T05:54:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c2a2654cc5905125f54a61ec8a9d1700b3f7a8b2",
"body": "fix(cli): stop interactive prompts hanging behind the status spinner",
"is_bot": false,
"headline": "Merge pull request #96 from sampleXbro/develop",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-10T05:54:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f6e80962c0869e5b7f74f4716e4ef1ffa4e783e6",
"body": "install, uninstall, and refresh held a clack spinner across the whole run;\nits redraw timer overwrote the interactive prompts underneath (skill-pack\nselect, broken-link, invalid-resource confirm, uninstall drift, and the\nrefresh consent prompt), so the command waited on invisible stdin — refresh\nsil\n[…]\nwrites (invalid resources were wrongly dropped from the preview).\n\nTests: refresh spinner-gating, confirm() EOF/error via readLine, readLine\nstream-error, and pool-resolution force+dry-run precedence.",
"is_bot": false,
"headline": "fix(cli): stop interactive prompts hanging behind the status spinner",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-09T20:54:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53aca22f8f9cb6c2f4d1df3c9edbe5a2c5091296",
"body": "chore: version packages",
"is_bot": false,
"headline": "Merge pull request #95 from sampleXbro/changeset-release/master",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-08T20:45:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5e15f301627485639093a7c24570861944f2f15a",
"body": null,
"is_bot": true,
"headline": "chore: version packages",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-08T20:36:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fae4234208ac6fb3b76fcd115210dafafe52abc3",
"body": "Develop",
"is_bot": false,
"headline": "Merge pull request #94 from sampleXbro/develop",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-08T20:36:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5d38ee4630caf9f929058c09cb0d7d90d841a1e1",
"body": "…nment\n\nfix(mcp): reject symlink path escapes",
"is_bot": false,
"headline": "Merge pull request #93 from fengjikui/codex/mcp-writer-symlink-contai…",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-08T20:30:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bdbaf900c9eb1bfec06d91afc39d078dfdc29ed4",
"body": null,
"is_bot": false,
"headline": "Merge branch 'master' into develop",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-08T20:09:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7edbf1f933be681545f2c8c63ef06bb24c8ca792",
"body": "…lessons",
"is_bot": false,
"headline": "chore(lessons): capture MCP path-containment + PR-fetch verification …",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-08T20:06:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "54b4f38f8d0e253d2e2d1a5af78b943cf3851dd2",
"body": "…ete surfaces\n\nBuilds on @fengjikui's PR #93. Anchors containment at the project root — a\n`.agentsmesh` boundary canonicalizes through a symlinked `.agentsmesh` and\ncancels, so a symlinked parent still escaped — and extends the guard to every\nremaining MCP filesystem surface:\n\n- settings config read\n[…]\nws EPERM on the windows-latest CI matrix).\n\nAlso drops the unrelated lessons.json trigger churn that rode in the original PR.\n\nCo-authored-by: sampleXbro <55853222+sampleXbro@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(mcp): complete symlink path containment across all read/write/del…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-08T19:51:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d4e496a5219e120c8de342e2d33e451b7e858ef0",
"body": null,
"is_bot": false,
"headline": "fix(mcp): reject symlink path escapes",
"author_name": "冯基魁",
"author_login": "fengjikui",
"committed_at": "2026-07-07T17:12:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a9fcfb3580c203b3a75dc5876ff1311e6e1dc2de",
"body": "chore: version packages",
"is_bot": false,
"headline": "Merge pull request #92 from sampleXbro/changeset-release/master",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-07T15:32:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbbc7cd1bf2e25d38f7d5b6ccb942f21b1dc1e45",
"body": null,
"is_bot": true,
"headline": "chore: version packages",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-07T15:16:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af206e14d54953e4757bae119bb7aa91e0c790a6",
"body": "Develop",
"is_bot": false,
"headline": "Merge pull request #91 from sampleXbro/develop",
"author_name": "Serhii Zhabskyi",
"author_login": "sampleXbro",
"committed_at": "2026-07-07T15:16:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "47cdd5818e962a2eff4dfbe70c98292747feb3ea",
"body": "The line-50 endsWith assertion compared native join() output against a\nforward-slash literal, so it passed on macOS/Linux but failed on\nwindows-latest CI ('expected false to be true'). Normalize separators\nwith .replaceAll('\\\\', '/') to match the sibling lessons path tests.",
"is_bot": false,
"headline": "fix(lessons): make outcome-log path assertion cross-platform",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-07T14:56:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa877168c4dbc053c1f366c8c9d4f36bb88e1d96",
"body": null,
"is_bot": false,
"headline": "Merge branch 'master' into develop",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-07T14:00:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "096c40df41d5d207bf736338bf8ab74416c81d2c",
"body": null,
"is_bot": false,
"headline": "Merge remote-tracking branch 'origin/master'",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-07T13:59:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "13730ca5ed58fb68ec2f385050ac562f781736f1",
"body": "…ents\n\nThe unsupported-hook warning (and Cursor's unmapped-event handling) now exclude the recall/capture events agentsmesh itself injects — UserPromptSubmit, PostToolUseFailure, SessionStart — since dropping one on a target that can't represent it is not user data loss and the warning would be permanent and unactionable.",
"is_bot": false,
"headline": "fix(lint): stop warning about agentsmesh-injected best-effort hook ev…",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-07T13:50:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b795b83ec437b8cfd7df9f63d7a075d36632150",
"body": "Opt-in outcome log tracks whether a delivered lesson prevented the repeat, feeding recall down-ranking, `validate` health findings (INEFFECTIVE_LESSON/UNCOVERED_FAILURE), and a `stats` effectiveness block. Plus: diff-aware recall, camelCase keyword reach, a capped/silent injection, a recurrence-driv\n[…]\nH capture warning, --scope always universal lessons, and `init --lessons` wiring the lessons.json merge driver. All opt-in and backward-compatible — no change to the CLI, MCP, or lessons.json surface.",
"is_bot": false,
"headline": "feat(lessons): measure effectiveness, sharpen recall, add scope:always",
"author_name": "Serhii Zhabskyi",
"author_login": "serhiizhabskiy",
"committed_at": "2026-07-07T13:28:58Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 43,
"commits_last_year": 776,
"latest_release_at": "2026-07-22T20:40:22Z",
"latest_release_tag": "v0.32.0",
"releases_from_tags": false,
"days_since_last_push": 9,
"active_weeks_last_year": 17,
"days_since_latest_release": 9,
"mean_days_between_releases": 3.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "agentsmesh",
"exists": true,
"license": "MIT",
"keywords": [
"ai-rules",
"ai-agents",
"ai-config",
"ai-coding",
"agentic",
"agent-rules",
"cursor-rules",
"claude-rules",
"config-sync",
"config-management",
"mcp",
"rules",
"skills",
"claude-code",
"cursor",
"copilot",
"continue",
"junie",
"gemini-cli",
"cline",
"codex",
"windsurf",
"antigravity",
"roo-code",
"developer-tools",
"devtools",
"code-assistant",
"cli"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/agentsmesh",
"is_deprecated": false,
"latest_version": "0.32.0",
"repository_url": "https://github.com/sampleXbro/agentsmesh",
"versions_count": 44,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 5677,
"first_published_at": "2026-03-26T07:52:55.603000Z",
"latest_published_at": "2026-07-22T20:39:31.278000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 9
}
]
},
"popularity": {
"forks": 5,
"stars": 21,
"watchers": 2,
"fork_history": {
"days": [
{
"date": "2026-05-02",
"count": 1
},
{
"date": "2026-05-04",
"count": 1
},
{
"date": "2026-05-28",
"count": 1
},
{
"date": "2026-07-07",
"count": 1
},
{
"date": "2026-07-18",
"count": 1
}
],
"complete": true,
"collected": 5,
"total_forks": 5
},
"star_history": null,
"open_issues_and_prs": 7
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tests/consumer-smoke/tsconfig.json",
"tsconfig.json",
"website/tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 389013,
"source_files_sampled": 1832,
"oversized_source_files": 4,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md",
"src/AGENTS.md",
"tests/e2e/fixtures/amp-project/AGENTS.md",
"tests/e2e/fixtures/claude-code-project/CLAUDE.md",
"tests/e2e/fixtures/codex-project/AGENTS.md",
"tests/e2e/fixtures/cursor-project/AGENTS.md",
"tests/e2e/fixtures/deepagents-cli-project/.deepagents/AGENTS.md",
"tests/e2e/fixtures/factory-droid-project/AGENTS.md",
"tests/e2e/fixtures/gemini-project/GEMINI.md",
"tests/e2e/fixtures/goose-project/.goosehints",
"tests/e2e/fixtures/jules-project/AGENTS.md",
"tests/e2e/fixtures/kilo-code-project/AGENTS.md",
"tests/e2e/fixtures/kiro-project/AGENTS.md",
"tests/e2e/fixtures/opencode-project/AGENTS.md",
"tests/e2e/fixtures/pi-agent-project/AGENTS.md",
"tests/e2e/fixtures/rovodev-project/AGENTS.md",
"tests/e2e/fixtures/warp-project/AGENTS.md",
"tests/e2e/fixtures/windsurf-agents-project/AGENTS.md",
"tests/e2e/fixtures/windsurf-project/.windsurfrules"
],
"agent_instruction_max_bytes": 8162
},
"dependencies": {
"manifests": [
"package.json",
"website/package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [
{
"name": "tar",
"direct": true,
"version": "7.5.20",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.3,
"advisory_ids": [
"GHSA-r292-9mhp-454m"
],
"fixed_version": "7.5.21",
"advisory_count": 1,
"oldest_advisory_days": 7
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"moderate": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 113,
"malicious_count": 0,
"assessed_package": "npm:agentsmesh@0.32.0",
"unassessed_count": 0,
"direct_affected_count": 1
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@clack/prompts",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.0"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.29.0"
},
{
"name": "chokidar",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.0.0"
},
{
"name": "diff",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "8.0.4"
},
{
"name": "picomatch",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.4"
},
{
"name": "smol-toml",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.1"
},
{
"name": "tar",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "7.5.20"
},
{
"name": "yaml",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.8.3"
},
{
"name": "zod",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.6"
},
{
"name": "@astrojs/starlight",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^0.32.0"
},
{
"name": "astro",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^5.0.0"
},
{
"name": "sharp",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^0.33.5"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 92,
"open_issues": 7,
"closed_ratio": 0.417,
"closed_issues": 5,
"closed_unmerged_prs": 1
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "serhiizhabskiy",
"commits": 643,
"avatar_url": "https://avatars.githubusercontent.com/u/147726171?v=4"
},
{
"type": "User",
"login": "sampleXbro",
"commits": 94,
"avatar_url": "https://avatars.githubusercontent.com/u/55853222?v=4"
},
{
"type": "User",
"login": "VVeb1250",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/188834110?v=4"
},
{
"type": "User",
"login": "fengjikui",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/56265583?v=4"
}
],
"contributors_sampled": 4,
"top_contributor_share": 0.87
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"deploy-website.yml",
"flake.yml",
"publish.yml"
],
"has_docs_dir": true,
"linter_configs": [
"eslint.config.js"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 5,
"reason": "3 out of 6 merged PRs checked by a CI test -- score normalized to 5",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 2,
"reason": "Found 1/4 approved changesets -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "33 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "ac8e24449c34f19925721dc60a0d902f5217b1e3",
"ran_at": "2026-08-01T08:41:33Z",
"aggregate_score": 3.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-27T10:29:31Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-22T20:38:55Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 23,
"created_at": "2026-04-29T06:03:48Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 24,
"created_at": "2026-04-29T06:05:41Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 25,
"created_at": "2026-04-29T06:07:04Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 32,
"created_at": "2026-04-29T11:48:23Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 35,
"created_at": "2026-04-29T11:50:45Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 36,
"created_at": "2026-04-29T11:51:26Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 37,
"created_at": "2026-04-29T11:52:06Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/sampleXbro/agentsmesh",
"host": "github.com",
"name": "agentsmesh",
"owner": "sampleXbro"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": "The weighted overall 63 is calibrated to 71 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 63,
"calibrated": 71,
"calibration": "2026-08-02"
}
}
],
"value": 71,
"inputs": {
"security": 45,
"vitality": 77,
"community": 58,
"governance": 49,
"calibration": "2026-08-02",
"engineering": 84,
"ai_readiness": 71,
"weighted_overall_raw": 63
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 77,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 69,
"inputs": {
"commits_last_year": 776,
"human_commit_share": 0.95,
"days_since_last_push": 9,
"active_weeks_last_year": 17
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 9 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 9
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "17/52 weeks with commits",
"points": 11.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 17
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "776 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 776
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 43,
"latest_release_tag": "v0.32.0",
"releases_from_tags": false,
"days_since_latest_release": 9,
"mean_days_between_releases": 3.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "43 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 43
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 9 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 9
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~3.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 3.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 58,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 26,
"inputs": {
"forks": 5,
"stars": 21,
"watchers": 2,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "21 stars",
"points": 21.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 21
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "5 forks",
"points": 5,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 5
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "2 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 2
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"readme_badge_services": [],
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 63,
"inputs": {
"packages": [
"agentsmesh"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 5677
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "5,677 downloads/month across npm",
"points": 50.1,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 5677,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "weak",
"name": "Sustainability & Governance",
"value": 49,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 17,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 4,
"top_contributor_share": 0.87
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 87% of commits",
"points": 2.9,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 87
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "4 contributors",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 4
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 58,
"inputs": {
"merged_prs": 92,
"open_issues": 7,
"closed_issues": 5,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": 0.417,
"closed_unmerged_prs": 1,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "42% of issues closed",
"points": 17.5,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 42
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "92/93 decided PRs merged",
"points": 29.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 92,
"decided": 93
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 1/4 approved changesets -- score normalized to 2",
"points": 3,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "weak",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 38,
"inputs": {
"followers": 0,
"owner_type": "User",
"is_verified": null,
"owner_login": "sampleXbro",
"public_repos": 14,
"account_age_days": 2500
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of sampleXbro",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "sampleXbro"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "14 public repos, account ~6 yr old",
"points": 20.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 14
}
},
{
"code": "account_age_years",
"params": {
"years": 6
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"agentsmesh"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 9
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 9 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 9
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "44 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 44
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 84,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.js",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "3 out of 6 merged PRs checked by a CI test -- score normalized to 5",
"points": 10,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "exceptional",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"ai-agents",
"claude-code",
"cli",
"codex",
"config-sync",
"cursor",
"developer-tools",
"mcp"
],
"has_wiki": true,
"homepage": "https://samplexbro.github.io/agentsmesh/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://samplexbro.github.io/agentsmesh/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "8 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 8
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "weak",
"name": "Security",
"value": 45,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 35,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 3.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "3 out of 6 merged PRs checked by a CI test -- score normalized to 5",
"points": 1.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 1/4 approved changesets -- score normalized to 2",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "33 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Matched the npm:agentsmesh@0.32.0 runtime dependency closure — what installing the published package pulls in — 113 packages. Reachability is not analyzed.",
"notes": [
{
"code": "advisories_scope_published",
"params": {
"package": "npm:agentsmesh@0.32.0",
"assessed": 113
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 85,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 113,
"unassessed_packages": 0,
"affected_by_severity": "moderate 1",
"direct_affected_packages": 1
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "1 affected: tar 7.5.20 (moderate 5.3)",
"points": 20.2,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 1,
"packages": "tar 7.5.20 (moderate 5.3)"
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory has been public longer than 90 days",
"points": 40,
"status": "met",
"details": [
{
"code": "advisories_none_stale",
"params": {
"days": 90
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 113,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 3
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 71,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.968,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md",
"src/AGENTS.md",
"tests/e2e/fixtures/amp-project/AGENTS.md",
"tests/e2e/fixtures/claude-code-project/CLAUDE.md",
"tests/e2e/fixtures/codex-project/AGENTS.md",
"tests/e2e/fixtures/cursor-project/AGENTS.md",
"tests/e2e/fixtures/deepagents-cli-project/.deepagents/AGENTS.md",
"tests/e2e/fixtures/factory-droid-project/AGENTS.md",
"tests/e2e/fixtures/gemini-project/GEMINI.md",
"tests/e2e/fixtures/goose-project/.goosehints",
"tests/e2e/fixtures/jules-project/AGENTS.md",
"tests/e2e/fixtures/kilo-code-project/AGENTS.md",
"tests/e2e/fixtures/kiro-project/AGENTS.md",
"tests/e2e/fixtures/opencode-project/AGENTS.md",
"tests/e2e/fixtures/pi-agent-project/AGENTS.md",
"tests/e2e/fixtures/rovodev-project/AGENTS.md",
"tests/e2e/fixtures/warp-project/AGENTS.md",
"tests/e2e/fixtures/windsurf-agents-project/AGENTS.md",
"tests/e2e/fixtures/windsurf-project/.windsurfrules"
],
"agent_instruction_max_bytes": 8162
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md, src/AGENTS.md, tests/e2e/fixtures/amp-project/AGENTS.md, tests/e2e/fixtures/claude-code-project/CLAUDE.md, tests/e2e/fixtures/codex-project/AGENTS.md, tests/e2e/fixtures/cursor-project/AGENTS.md, tests/e2e/fixtures/deepagents-cli-project/.deepagents/AGENTS.md, tests/e2e/fixtures/factory-droid-project/AGENTS.md, tests/e2e/fixtures/gemini-project/GEMINI.md, tests/e2e/fixtures/goose-project/.goosehints, tests/e2e/fixtures/jules-project/AGENTS.md, tests/e2e/fixtures/kilo-code-project/AGENTS.md, tests/e2e/fixtures/kiro-project/AGENTS.md, tests/e2e/fixtures/opencode-project/AGENTS.md, tests/e2e/fixtures/pi-agent-project/AGENTS.md, tests/e2e/fixtures/rovodev-project/AGENTS.md, tests/e2e/fixtures/warp-project/AGENTS.md, tests/e2e/fixtures/windsurf-agents-project/AGENTS.md, tests/e2e/fixtures/windsurf-project/.windsurfrules",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md, src/AGENTS.md, tests/e2e/fixtures/amp-project/AGENTS.md, tests/e2e/fixtures/claude-code-project/CLAUDE.md, tests/e2e/fixtures/codex-project/AGENTS.md, tests/e2e/fixtures/cursor-project/AGENTS.md, tests/e2e/fixtures/deepagents-cli-project/.deepagents/AGENTS.md, tests/e2e/fixtures/factory-droid-project/AGENTS.md, tests/e2e/fixtures/gemini-project/GEMINI.md, tests/e2e/fixtures/goose-project/.goosehints, tests/e2e/fixtures/jules-project/AGENTS.md, tests/e2e/fixtures/kilo-code-project/AGENTS.md, tests/e2e/fixtures/kiro-project/AGENTS.md, tests/e2e/fixtures/opencode-project/AGENTS.md, tests/e2e/fixtures/pi-agent-project/AGENTS.md, tests/e2e/fixtures/rovodev-project/AGENTS.md, tests/e2e/fixtures/warp-project/AGENTS.md, tests/e2e/fixtures/windsurf-agents-project/AGENTS.md, tests/e2e/fixtures/windsurf-project/.windsurfrules"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "92 of 95 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 92,
"sampled": 95
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"pnpm-lock.yaml"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"tests/consumer-smoke/tsconfig.json",
"tsconfig.json",
"website/tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.js",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tests/consumer-smoke/tsconfig.json, tsconfig.json, website/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tests/consumer-smoke/tsconfig.json, tsconfig.json, website/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 389013,
"source_files_sampled": 1832,
"oversized_source_files": 4
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "4/1832 source files over 60KB",
"points": 54.9,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 1832,
"oversized": 4
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"labels": [
"mcp-server",
"library"
],
"scores": {
"cli": 2,
"library": 6,
"mcp-server": 7
},
"primary": "mcp-server",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:npm",
"weight": 6
},
{
"tier": "dependencies",
"label": "mcp-server",
"source": "dep:@modelcontextprotocol/sdk",
"weight": 4
},
{
"tier": "structure",
"label": "mcp-server",
"source": "mcp_signal",
"weight": 3
},
{
"tier": "tags",
"label": "cli",
"source": "tag:cli",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": true
},
"metrics_version": "2.3.1"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-08-01T08:41:50.384805Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/sampleXbro/agentsmesh.svg",
"full_name": "sampleXbro/agentsmesh",
"license_state": "standard",
"license_spdx": "MIT"
}