公开记录
软件健康报告模式 0.27.0 · 指标 2.3.1 · 2026-07-30 17:25 UTC

use-agent-os / agent-os

The Open Agent Operation System

Python · TypeScriptApache-2.0★ 17 星标⑂ 14 复刻始于 2026年7月在 GitHub 上查看 ↗
类型MCP 服务器聊天机器人网络服务网页界面命令行工具如何判定

use-agent-os/agent-os 的健康指数为 100 分中的 71 分,处于「良好」区间。 其得分最高的类别是Engineering Quality(80/100),最低的是Security(46/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

71
总分 / 100
良好

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均,再依据公开记录的分布进行校准,使各等级具有百分位含义;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 34(存在风险)的上限。

71
卓越93-100公开记录中的最高层级(约前 5%);基本满足所有检验标准
优秀80-92各方面均表现强劲;仅有少量不足
良好65-79健康;不足之处有限且可控
中等50-64可接受,但存在明显不足;建议进行审查
薄弱35-49多个领域存在实质性薄弱环节
存在风险20-34存在重大薄弱环节;采用时应保持审慎
危急1-19问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

加权总体分 63 经校准后在公布的指数量表上为 71(记录校准 2026-08-02)。

所有权

AgentOS组织
5 关注者1 个公开仓库始于 2026年7月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
PyPIuse-agent-os2026.7.302,040170 天前agentchatbotgatewayllmmcprouter

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

70良好 · 占总体的 21%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
2.1/36提交节奏 — 52 周中有 3 周有提交
18/18提交量 — 最近一年 361 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year361
human_commit_share1
days_since_last_push0
active_weeks_last_year3

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 18 个发布版本
36/36发布时效 — 最近一次发布版本于 0 天前
27/27发布节奏 — 约每 1.1 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count18
latest_release_tagv2026.7.30
releases_from_tags
days_since_latest_release0
mean_days_between_releases1.1

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

58中等 · 占总体的 17%

流行度与采用

29存在风险
评分方式
19.5/60星标 — 17 个星标
9.3/25复刻 — 14 个复刻
0/15关注者 — 1 位关注者
所用输入
forks14
stars17
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
readme_badges
has_contributing
has_issue_template
has_code_of_conduct
readme_badge_services
has_pull_request_template
评分方式
44.1/80月度下载量 — pypi 合计每月 2,040 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesuse-agent-os
dependents
ecosystemspypi
total_downloads
monthly_downloads2,040
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

57中等 · 占总体的 23%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
8.2/22.5提交分布 — 头号贡献者编写了 63% 的提交
9.5/13.5贡献者广度 — 7 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled7
top_contributor_share0.634
评分方式
28.3/42议题解决 — 67% 的议题已关闭
28.4/30PR 接受 — 已裁定的 PR 中 110/116 已合并
0/13Newcomer PR acceptance — 30 天内没有首次贡献者的 PR 得到裁决
7.5/15OpenSSF Scorecard:Code-Review — Found 6/11 approved changesets -- score normalized to 5
所用输入
merged_prs110
open_issues16
closed_issues33
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio0.673
closed_unmerged_prs6
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
已排除计分(无数据或不适用):newcomer_pr_acceptance。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
5.6/25所有者影响力 — use-agent-os 有 5 位关注者
2.3/25既往记录 — 1 个公开仓库,账户约 0 年
所用输入
followers5
owner_typeOrganization
is_verified
owner_loginuse-agent-os
public_repos1
account_age_days17
评分方式
25/25已发布且可解析 — pypi 上有 1 个软件包
35/35发布时效 — 最近一次发布于 0 天前
20/20版本历史 — 17 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesuse-agent-os
ecosystemspypi
any_deprecated
min_days_since_publish0

工程质量

基础的工程与文档实践是否到位?

80优秀 · 占总体的 19%

工程实践

84优秀
评分方式
24/24CI 工作流 — 7 个工作流
24/24存在测试
16/16Linter 配置 — biome.json, eslint.config.js
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 11 out of 11 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

75良好
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

46薄弱 · 占总体的 16%

安全态势

46薄弱
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — 无数据
2.5/2.5CI-Tests — 11 out of 11 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
3.8/7.5Code-Review — Found 6/11 approved changesets -- score normalized to 5
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 71 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.6
已排除计分(无数据或不适用):branch_protection。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?权重刻意设小(4%):代理工具链是一项真实的维护信号,但完全不具备的仓库仍可达到 100/100。

66良好 · 占总体的 4%
评分方式
45/45代理指令 — AGENTS.md, CLAUDE.md, docs/agents.md, src/agentos/identity/templates/bootstrap/AGENTS.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 97 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.97
agent_instruction_filesAGENTS.md, CLAUDE.md, docs/agents.md, src/agentos/identity/templates/bootstrap/AGENTS.md
agent_instruction_max_bytes10,771
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — biome.json, eslint.config.js
11/11静态类型检查 — frontend/tsconfig.json
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 8 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilespackage-lock.json, uv.lock
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsfrontend/tsconfig.json
agent_commit_share0.08
toolchain_manifests
dependency_bot_commit_share0
评分方式
27/45可类型检查的代码 — Python,已配置类型检查(frontend/tsconfig.json)
54.1/55可控的文件大小 — 采样的 1,401 个源文件中有 23 个超过 60KB
所用输入
primary_languagePython
largest_source_bytes249,033
source_files_sampled1,401
oversized_source_files23

机器可读接口

20存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
20/20MCP 服务器
0/40可运行示例
所用输入
example_dirs
has_mcp_signal
api_schema_files

关键数据

17GitHub 星标
7贡献者
361最近 12 个月提交数
0距最近推送天数
18发布版本数
1巴士系数(bus factor)
16开放议题
npm, PyPI软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index pypi:use-agent-os@2026.7.30; advisories assessed against the repository dependency graph instead

更多细节

Star 与 Fork 历史 0 ★ / 14 ⇿
0Star
14Fork
16发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

03581013151432026-072026-072026-07
主版本 0次版本 0修订 11
OpenSSF Scorecard 4.6 / 10
4.6综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-30 17:25 UTC

10Binary-Artifactsno binaries found in the repo
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests11 out of 11 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
5Code-ReviewFound 6/11 approved changesets -- score normalized to 5
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities71 existing vulnerabilities detected
直接依赖 52
注册表软件包版本约束清单文件
npm@radix-ui/react-slot^1.3.0frontend/package.json
npm@tabler/icons-react^3.45.0frontend/package.json
npm@tanstack/react-query^5.101.2frontend/package.json
npmclass-variance-authority^0.7.1frontend/package.json
npmclsx^2.1.1frontend/package.json
npmdompurify^3.4.12frontend/package.json
npmhighlight.js^11.11.1frontend/package.json
npmlucide-react^1.25.0frontend/package.json
npmmarked^18.0.7frontend/package.json
npmmotion^12.42.2frontend/package.json
npmreact^19.2.7frontend/package.json
npmreact-dom^19.2.7frontend/package.json
npmreact-router^7.18.1frontend/package.json
npmsonner^2.0.7frontend/package.json
npmtailwind-merge^3.6.0frontend/package.json
npmzustand^5.0.14frontend/package.json
PyPIstarlette>=0.40,<2.0pyproject.toml
PyPIpython-multipart>=0.0.20pyproject.toml
PyPIuvicorn>=0.30,<1.0pyproject.toml
PyPIpydantic>=2.0,<3.0pyproject.toml
PyPIpydantic-settings>=2.0,<3.0pyproject.toml
PyPIsqlmodel>=0.0.20,<0.1.0pyproject.toml
PyPIanyio>=4.0pyproject.toml
PyPIhttpx>=0.27,<0.29pyproject.toml
PyPImcp>=1.2.0,<2.0pyproject.toml
PyPIbrotli>=1.1pyproject.toml
PyPIjinja2>=3.1pyproject.toml
PyPIstructlog>=24.0pyproject.toml
PyPItyper>=0.12pyproject.toml
PyPIrich>=13.0pyproject.toml
PyPIwebsockets>=13.0pyproject.toml
PyPIaiosqlite>=0.20pyproject.toml
PyPIapscheduler>=3.10pyproject.toml
PyPIpyyaml>=6.0pyproject.toml
PyPIsqlite-vec>=0.1pyproject.toml
PyPIhtml2text>=2024.2pyproject.toml
PyPIreadability-lxml>=0.8pyproject.toml
PyPIbeautifulsoup4>=4.12pyproject.toml
PyPIcachetools>=5.3pyproject.toml
PyPIpdfplumber>=0.11pyproject.toml
PyPIpillow>=10.0pyproject.toml
PyPIcroniter>=2.0pyproject.toml
PyPItomli-w>=1.0pyproject.toml
PyPIyoyo-migrations>=8.2pyproject.toml
PyPIprompt-toolkit>=3.0pyproject.toml
PyPIquestionary>=2.0pyproject.toml
PyPIpython-docx>=1.1.0pyproject.toml
PyPIpython-pptx>=1.0.0pyproject.toml
PyPIopenpyxl>=3.1.0pyproject.toml
PyPIpypdf>=4.0.0pyproject.toml
PyPIreportlab>=4.0.0pyproject.toml
PyPIpython-telegram-bot>=20.0pyproject.toml
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 19333,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "CSS": 443063,
        "HTML": 1324,
        "Ruby": 2556,
        "Jinja": 15582,
        "Shell": 28286,
        "Python": 12163582,
        "Dockerfile": 4536,
        "JavaScript": 4207,
        "PowerShell": 43334,
        "TypeScript": 2170520
      },
      "pushed_at": "2026-07-30T16:18:20Z",
      "created_at": "2026-07-13T07:30:45Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-30T16:22:35Z",
      "description": "The Open Agent Operation System",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Python",
      "significant_languages": [
        "Python",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://useagentos.dev",
      "name": "AgentOS",
      "type": "Organization",
      "login": "use-agent-os",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/304313632?v=4",
      "created_at": "2026-07-13T06:59:15Z",
      "is_verified": null,
      "public_repos": 1,
      "account_age_days": 17
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2026.7.30",
          "kind": "patch",
          "published_at": "2026-07-30T16:23:32Z"
        },
        {
          "tag": "v2026.7.29",
          "kind": "patch",
          "published_at": "2026-07-29T15:01:07Z"
        },
        {
          "tag": "v2026.7.28",
          "kind": "patch",
          "published_at": "2026-07-28T15:21:15Z"
        },
        {
          "tag": "v2026.7.27",
          "kind": "patch",
          "published_at": "2026-07-27T16:37:30Z"
        },
        {
          "tag": "v2026.7.26",
          "kind": "patch",
          "published_at": "2026-07-26T17:25:51Z"
        },
        {
          "tag": "v2026.7.25",
          "kind": "patch",
          "published_at": "2026-07-25T04:41:33Z"
        },
        {
          "tag": "v2026.7.23",
          "kind": "patch",
          "published_at": "2026-07-23T17:29:14Z"
        },
        {
          "tag": "v2026.7.22.post1",
          "kind": "other",
          "published_at": "2026-07-22T16:35:23Z"
        },
        {
          "tag": "v2026.7.22",
          "kind": "patch",
          "published_at": "2026-07-22T03:18:16Z"
        },
        {
          "tag": "v2026.7.20",
          "kind": "patch",
          "published_at": "2026-07-20T13:57:38Z"
        },
        {
          "tag": "v2026.7.19.post1",
          "kind": "other",
          "published_at": "2026-07-19T15:00:46Z"
        },
        {
          "tag": "v2026.7.19",
          "kind": "patch",
          "published_at": "2026-07-19T13:06:25Z"
        },
        {
          "tag": "v2026.7.18.post1",
          "kind": "other",
          "published_at": "2026-07-18T15:00:39Z"
        },
        {
          "tag": "v2026.7.18",
          "kind": "patch",
          "published_at": "2026-07-18T14:47:46Z"
        },
        {
          "tag": "v2026.7.17.post1",
          "kind": "other",
          "published_at": "2026-07-16T20:40:36Z"
        },
        {
          "tag": "v2026.7.17",
          "kind": "patch",
          "published_at": "2026-07-16T20:01:45Z"
        },
        {
          "tag": "v2026.7.15.post1",
          "kind": "other",
          "published_at": "2026-07-15T11:11:56Z"
        },
        {
          "tag": "v2026.7.15",
          "kind": "patch",
          "published_at": "2026-07-15T03:05:44Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2e422bec178dd1e999ef89c0047ffd66a3eea42b",
          "body": "chore(release): bump version to 2026.7.30",
          "is_bot": false,
          "headline": "Merge pull request #166 from use-agent-os/chore/bump-2026.7.30",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T16:17:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec51eebc61f64b68c006120ed79fb89e9d5de594",
          "body": "A skills release. The agent can now tell which of its installed skills\napplies to a request — descriptions shorten to fit the prompt budget\ninstead of dropping at a cliff, names-only mode points at `skill_list`,\nthe block moves into the cacheable system prompt, and cron turns get\n`skill_view`/`skill\n[…]\ne (#144), runtime dependencies carry upper\nbounds (#153), and the Web UI skill grid and Installed chip are fixed\n(#135, #161, #121).\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump version to 2026.7.30",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T16:13:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c8025ff3de685307214315e68315fa2ee0c5a36",
          "body": "fix(webui): stabilize skill card layout",
          "is_bot": false,
          "headline": "Merge pull request #164 from thanhtan1105/fix/161-skills-layout",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T16:07:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0c15d0edee306c63699e8b9f9ef4529c23761dc",
          "body": null,
          "is_bot": false,
          "headline": "fix(webui): stabilize skill card layout",
          "author_name": "yonle",
          "author_login": "thanhtan1105",
          "committed_at": "2026-07-30T15:59:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d89b5031e819bd15dcda7849bec57ad1d692eede",
          "body": "…led-chip\n\nfix(webui): repair installed skill chip in detail dialog",
          "is_bot": false,
          "headline": "Merge pull request #160 from thanhtan1105/fix/121-skill-detail-instal…",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T15:54:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48076703a84d5afc4ccd47478fdf942fadf4d50b",
          "body": null,
          "is_bot": false,
          "headline": "docs: remove unrelated evaluation guide",
          "author_name": "yonle",
          "author_login": "thanhtan1105",
          "committed_at": "2026-07-30T15:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d58a357a9d29944f737ca1908cd8fbcc3858da7f",
          "body": "fix(skills): stop skill_view spending a whole skill on every read",
          "is_bot": false,
          "headline": "Merge pull request #163 from keyKQ/fix/skill-view-read-ceiling",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T14:36:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f77d0ebb25ffb535cd6a1e12f6812948dac7966",
          "body": "Asked for a skill that is not installed, skill_view answered with what not to\ndo — do not go looking on disk — and then \"tell the user the skill is not\ninstalled\". That is a dead end even when a configured hub carries the skill and\nthe tools to fetch it are sitting in the same session, and a model h\n[…]\nn — whose allowlist carries neither hub tool\n— is offered neither. Installing writes to the machine, so it is always phrased\nas something to offer the user, never something to do unasked.\n\nFixes #162.",
          "is_bot": false,
          "headline": "fix(skills): give skill_view a next step when a skill is not installed",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-30T14:22:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15ccd8b5ff0ee2722c6a919fcf4feabc6fe0d2da",
          "body": "Path.relative_to returns a native path, so on Windows the index offered\n'references\\api.md'. The model quotes that back as file_path, where a\nbackslash is an escape character in the tool call's JSON, and it does not\nmatch how a SKILL.md writes its own links. Emit as_posix() instead.\n\nThe reader already normalised separators, so nothing was unreadable — the\ndefect was in what the agent was told to type.",
          "is_bot": false,
          "headline": "fix(skills): name a skill's linked files with forward slashes on Windows",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-30T13:19:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02cef56c703cf46a68c28ccedb9ff6c66750edb6",
          "body": "skill_view returned every byte of a SKILL.md. That is fine for the shipped\nset — 37 bundled skills, median 2,430 characters, largest 21,647 — but skills\ninstalled from a hub or written for another agent run far larger: 56,209\ncharacters for one, 86,805 for another. At roughly four characters per tok\n[…]\nsolves\nit to the default — verified against a gateway booted from one — the skill\nsnapshot schema is unchanged so no cache is invalidated, and agentos upgrade\nalready restarts the gateway.\n\nRefs #158.",
          "is_bot": false,
          "headline": "fix(skills): stop skill_view spending a whole skill on every read",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-30T12:43:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b9623c2f48516dabc6f88f2720d69314b389d51",
          "body": "fix(skills): make the skills block something the model can act on",
          "is_bot": false,
          "headline": "Merge pull request #159 from keyKQ/fix/skills-block-the-model-can-act-on",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T07:20:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b119d8b92e1a48fbae42fcedbda8e06de2e8008",
          "body": null,
          "is_bot": false,
          "headline": "fix(webui): repair installed skill chip in detail dialog",
          "author_name": "yonle",
          "author_login": "thanhtan1105",
          "committed_at": "2026-07-30T06:27:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "412c7e813840d081369ddd05006cf7f27e8f5da6",
          "body": "An install with skills added could not get the agent to use them: it\nanswered from general knowledge while every skill still reported itself as\noffered. Four independent causes, each sufficient on its own.\n\nThe prompt budget was a cliff. One skill over it and *every* description in\nthe block was dro\n[…]\nwhich reports skill loading as slow and difficult: a name-only\nblock asking for one skill_view per plausible name is a plausible cause of\nthat fan-out, though the slowness itself is not verified here.",
          "is_bot": false,
          "headline": "fix(skills): make the skills block something the model can act on",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-30T05:55:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b0e56f199fad3f62116b54f81e1b7aab23e57fe",
          "body": "fix(assets): refine Capminal symbol logo paths and square tile",
          "is_bot": false,
          "headline": "Merge pull request #157 from use-agent-os/fix/capminal-symbol-logo",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T05:31:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a900aacc3a5c5b01d2b313084177845baab7fda",
          "body": "Update the Capminal brand mark with refined two-blade \"C\" spiral paths for crisper, more detailed rendering. Remove the rounded rx=\"96\" corners from the background tile so it renders as a clean square, and add a descriptive comment documenting the mark.",
          "is_bot": false,
          "headline": "fix(assets): refine Capminal symbol logo paths and square tile",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T04:47:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a0103074c14c9d786d2866b73e0a97fed5c39d4",
          "body": "Feat/capminal skills",
          "is_bot": false,
          "headline": "Merge pull request #144 from Preciousuche/feat/capminal-skills",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-30T04:25:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9a1cd869883fa0ae6f8a9acf0dfab48ba5dd48b",
          "body": "…g fallbacks",
          "is_bot": false,
          "headline": "feat(skills): update Capminal brand asset color and fix logo renderin…",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-29T19:49:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0008f0258cc0428847a9b6defb0c80f8f6a5ae8",
          "body": null,
          "is_bot": false,
          "headline": "chore(packaging): sync uv.lock with pyproject.toml dependency bounds",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-29T18:24:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ef311831e9c8289bb3278adacd37ee95d3ec594",
          "body": null,
          "is_bot": false,
          "headline": "chore(packaging): cap runtime dependencies in pyproject.toml (#153)",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-29T17:54:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c78458d6fed8c422ebb9c22378a29f3cc7d802b5",
          "body": null,
          "is_bot": false,
          "headline": "merge: resolve CHANGELOG.md conflict with upstream/main",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-29T16:54:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af82726e302860298142c82bd02f30995cdeaef4",
          "body": "chore(release): bump version to 2026.7.29",
          "is_bot": false,
          "headline": "Merge pull request #156 from use-agent-os/chore/bump-2026.7.29",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-29T14:53:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaecd7b885e49d1f96c9d4822678f155f9199660",
          "body": "Two changes land since v2026.7.28: Bankr skills published from bankr.bot\nunder an author's wallet address are now browsable and installable through\nthe Bankr source (#150), and SECURITY.md states where audit reports belong,\nthat there is no bug bounty program, and how researchers are credited (#154).\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump version to 2026.7.29",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-29T14:52:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "237ea3aa9041903a0bf7aea75972157ac2b8617f",
          "body": "…policy\n\ndocs(security): reject audit reports as PRs and state no bounty program",
          "is_bot": false,
          "headline": "Merge pull request #154 from use-agent-os/docs/security-audit-report-…",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-29T08:47:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62bef08dd947cb43158200a94d6f205051845af0",
          "body": "An external contributor opened a PR adding a point-in-time SECURITY_AUDIT.md\nat the repository root. The existing policy covers where to send vulnerability\ndetails but says nothing about audit documents, reward programs, or how\nresearchers get credited, so there was nothing to point at when declinin\n[…]\n form rather than a PR, no bug bounty\nexists or is planned, and researchers whose reports lead to a fix are credited\nin that fix's release notes.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(security): reject audit reports as PRs and state no bounty program",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-29T08:29:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90a239d197b18a420e5b985ad21deaa586f26bcd",
          "body": "feat(skills): install Bankr skills published from bankr.bot",
          "is_bot": false,
          "headline": "Merge pull request #150 from keyKQ/feat/bankr-registry-skills",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-29T07:32:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b15064a8eded38a1a9de2577883127334daa9e1",
          "body": "# Conflicts:\n#\tCHANGELOG.md",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'upstream/main' into feat/capminal-skills",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-28T16:23:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d60c5ec4b718cedbae8fd290be863db1b79d33f0",
          "body": null,
          "is_bot": false,
          "headline": "fix(webui): prevent skill cards from overflowing grid tracks (#135)",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-28T16:22:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb16c7eb8c0a056c66f8de7c5f732116105cb773",
          "body": "Bankr publishes in two places. The skills in BankrBot/skills are what the\nBankr source has been able to read; anyone can also publish from bankr.bot,\nwhere a skill lives under its author's wallet address and is served by\napi.bankr.bot/public/skills/<wallet>/<slug> as JSON with the body inline.\nThere\n[…]\nrenders unbranded\nrather than in the Partners group, and author avatars are dropped rather\nthan widening the console's img-src CSP.\n\nShips stock-premium-lp-manager as the first such skill.\n\nFixes #149",
          "is_bot": false,
          "headline": "feat(skills): install Bankr skills published from bankr.bot",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-28T15:32:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f4bb765c133ae6ca4bfad1a40dacc3ad749d1a0",
          "body": "ci: restore Git LFS objects from the Actions cache",
          "is_bot": false,
          "headline": "Merge pull request #148 from use-agent-os/ci/cache-git-lfs-objects",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-28T15:16:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee83482a112d318235a5772c8c8e2ee8848bcd12",
          "body": "The three CI jobs that need the bundled ONNX weights each checked out with\n`lfs: true`, so every run pulled ~45 MB (bge + MiniLM + pilot) three times.\nThat exhausted the account's Git LFS bandwidth quota and blocked checkout on\nevery job with \"This repository exceeded its LFS budget\".\n\nAll three gen\n[…]\nue` + `git lfs pull` path;\ntheir hydration asserts are the last line of defense against shipping a\npointer inside a published wheel.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: restore Git LFS objects from the Actions cache",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-28T15:05:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41cd2adc773d9e66884164678bde5fe294a51f3d",
          "body": "chore(release): bump version to 2026.7.28",
          "is_bot": false,
          "headline": "Merge pull request #147 from use-agent-os/chore/bump-2026.7.28",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-28T14:55:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a56dbf8405508e78f9c2565a5853efa02f1b1af",
          "body": null,
          "is_bot": false,
          "headline": "fix(skills): resolve code review findings for Capminal Skills",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-28T14:54:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6711a3c9b3272be57e13738822e51db766c3f16",
          "body": "Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump version to 2026.7.28",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-28T14:14:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2d14fba65024dd1945e2f124494174ecf6b42063",
          "body": "Cmd/Ctrl+Shift+O starts a new chat from anywhere in the console, reusing the same startNewChat flow as the button. The tooltip shows the platform-appropriate hint.\n\nCloses #120",
          "is_bot": false,
          "headline": "feat(webui): add keyboard shortcut for the new chat button (#131)",
          "author_name": "Wasn",
          "author_login": "HaimiyaWasn",
          "committed_at": "2026-07-28T03:07:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94c28da164de808627f6111c6e336ae7b422589a",
          "body": "Standardizes the route title, sidebar item, page heading, browser tab title, and docs on `Agent Setup`.\n\nCloses #123",
          "is_bot": false,
          "headline": "fix(webui): standardize Agent Setup labels (#125)",
          "author_name": "Kudala Bharani Kumar Reddy",
          "author_login": "kudala-bharani",
          "committed_at": "2026-07-28T02:42:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c857a182045105cd5f5ab859f524ad7a57b4797e",
          "body": null,
          "is_bot": false,
          "headline": "fix(skills): resolve compile error from registry panel signature change",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-27T20:43:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "462d093cdea4c3727629088c91f6f06c632ea7bf",
          "body": "# Conflicts:\n#\tfrontend/src/views/skills/SkillsPage.tsx",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'upstream/main' into feat/capminal-skills",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-27T20:36:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e273de8df1409ef72490a9a53357faa048004f4",
          "body": "…+ tab)",
          "is_bot": false,
          "headline": "feat(skills): add native support for Capminal Skills (partner source …",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-27T18:31:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93fd50533628405dbefbae8c6d8307cce47ab99b",
          "body": "chore(release): bump version to 2026.7.27",
          "is_bot": false,
          "headline": "Merge pull request #143 from use-agent-os/chore/bump-2026.7.27",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-27T16:29:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5441f18f7b9cb9babc751dacbff292a17a4882d",
          "body": "Cut the 2026.7.27 release across every touchpoint the release\nconsistency and install-script guards check: pyproject.toml, uv.lock,\nCHANGELOG.md ([Unreleased] moved into a [2026.7.27] section with an\nempty [Unreleased] reopened), RELEASES.md, README.md install examples\nand wheel URL, install.sh / install.ps1 defaults and usage text, and\nthe CURRENT_VERSION / CURRENT_RELEASE_TAG constants in tests.\n\nNo runtime code changes.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump version to 2026.7.27",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-27T16:28:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0d7d5718cb1d8886245e0549ffc1d61e7dadb20d",
          "body": "…-selection\n\ndocs(config): separate model selection from plain-text mode settings",
          "is_bot": false,
          "headline": "Merge pull request #133 from use-agent-os/docs/ollama-plaintext-model…",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-27T15:33:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e31431a6d4898929c6634a3fd277bac05e0fce68",
          "body": "The Ollama plain-text example hardcoded model = \"qwen2.5:7b\" and\nagent_max_iterations = 8. Copying the snippet could overwrite a user's\nconfigured model or point at a model that is not installed locally, and\nthe tool-loop cap is irrelevant while tools are disabled.\n\nModel selection is now a separate\n[…]\nlock shows only the settings plain-text mode\nrequires.\n\nCo-authored-by: Preciousuche <85787225+Preciousuche@users.noreply.github.com>\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(config): separate model selection from plain-text mode settings",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-27T15:31:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "13e2cdfd98073000a1a3fe37446bd1cf320d8ca2",
          "body": "* feat(skills): make publisher real data behind a server-side allowlist\n\nSkill cards showed partner branding from a name heuristic, so who stands\nbehind a skill was never actually recorded. Add a SkillPublisher field that\na SKILL.md may select by id, and resolve that id against an allowlist so a\nthi\n[…]\nt alone, and an unset\nkey is not materialised.\n\nOne test asserts the point rather than the number: the value it lifts to has to\nactually fit the shipped set in full mode, or the migration is cosmetic.",
          "is_bot": false,
          "headline": "fix(skills): give every surface one answer about a skill (#132)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-27T15:27:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "03fc2d9a882aeb12cb55e9a39ccc4acb51d8731d",
          "body": "…available actions (#129)\n\n* feat(env): look for a credential before asking someone to produce one\n\nA variable reported as missing often is not. The operator has usually already\nrun `gh auth login`, and telling them to go find a token they effectively lost\nis worse than looking where it lives.\n\ncred\n[…]\n skill_view, where the agent is\nactually trying to use the skill, not repeated once per entry across a\nlisting of fifty.\n\n* docs(web-ui): document the credential import offer on the Environment screen",
          "is_bot": false,
          "headline": "feat(env): find credentials that already exist, and stop promising un…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-27T10:06:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d88b7861be9dd44793e76642856b0438398c4262",
          "body": "…view (#128)\n\n* test(memory): add a curated-memory retention benchmark\n\n\"Memory works poorly\" is a felt thing, not a number, so a rebuild has\nnothing to prove itself against. This drives the real turn path --\nbuild_services -> TurnRunner.run -> nudge review -> the `memory` tool --\nagainst a throwawa\n[…]\nad as a\n40-point regression that had not happened. It decides whether a planted\nfact counts as reaching memory, so a bug in it moves every rate the\nbenchmark reports, and both failures are now pinned.",
          "is_bot": false,
          "headline": "fix(memory): stop fabricated profile facts and wake the background re…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-27T10:04:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d44fe7f17b2664316b80c7293b479547ab5495f9",
          "body": "…nt (#127)\n\n* feat(env): add a policy-gated writer for ~/.agentos/.env\n\nAgentOS could read .env files but never write one, so every flow that\ndetected a missing environment variable could only tell the operator to go\nedit a dotfile by hand. This lands the write side.\n\nenv_policy holds the gate. Writ\n[…]\nms that were previously parsed into\nunusable keys now take effect, CLI logs move to stderr, and the skill cache\nis rebuilt once.\n\n* docs(changelog): merge the duplicated Fixed section under Unreleased",
          "is_bot": false,
          "headline": "feat(env): manage environment variables from the Web UI, CLI, and age…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-27T08:30:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bdacd6d07c2f56066e670e188e327b8cde440338",
          "body": "* refactor(memory): remove the session flush stack\n\nDelete the session flush subsystem and update every consumer and test\nto match.\n\nRemoved:\n- memory/session_flush.py, memory/flush.py, memory/archive.py\n- the flush wiring in engine/agent.py, engine/runtime.py, gateway/boot.py\n  and gateway/rpc_sess\n[…]\npended on the receipt.\n\nVerified on a real install carrying all 11 legacy keys: gateway boots\nclean, the keys are ignored with one warning, memory reads intact, and a\nweb-UI turn completes end to end.",
          "is_bot": false,
          "headline": "refactor(memory): remove the session flush stack (#124)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-27T05:26:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5a576a4c7e8d3ba04f4c4e23c1f2f4d3fc24726",
          "body": "chore(release): bump version to 2026.7.26",
          "is_bot": false,
          "headline": "Merge pull request #119 from use-agent-os/chore/bump-2026.7.26",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-26T17:16:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64d6df26644107329887ab23f427f281016c3792",
          "body": "Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump version to 2026.7.26",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-26T17:15:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "95ca8f8d975398c66f100c73ca5689e32493478b",
          "body": "…mand (#118)\n\nFirst half of removing the flush stack. Net -3,156 lines.\n\nRemoved:\n  - gateway/memory_repair_service.py (891) — existed only to retry failed\n    flushes; with the flush service going it has nothing to retry\n  - cli/memory_flush_cmd.py (400) and `agentos memory flush-session`\n  - `agen\n[…]\nCLI/RPC change, taken deliberately on a 0.x line. Both\ncommand groups already errored out under the default config (flush is off),\nso nothing that worked before stops working.\n\nFull suite 6302 passed.",
          "is_bot": false,
          "headline": "refactor(memory): remove the repair service and the flush-session com…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T13:03:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bedf221fd64d33a2f6fc6dc684c797b92d3c52c5",
          "body": "…one (#117)\n\n`flush_compaction_safety_mode = \"block\"` tells compaction to refuse unless a\nsafe flush receipt exists. That is a reasonable demand while the flush path\nis running. With flush disabled -- the default -- no receipt is ever written,\nso \"block\" refuses compaction on every turn.\n\nThe failur\n[…]\nerwise wedge compaction permanently for any user who\nhad set either option.\n\nAdds tests/test_compaction_safe_receipt_gate.py (10 tests). Reverting the\ngate turns 4 of them red. Full suite 6333 passed.",
          "is_bot": false,
          "headline": "fix(compaction): only require a flush receipt when flush can produce …",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T12:39:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "02bd23366a43b6575f8ef4c9bae11154163af727",
          "body": "…tatus (#116)\n\n* refactor(memory): remove Dream consolidation and the orphaned flush_status\n\nTwo removals, both verified dead rather than assumed dead.\n\nflush_status.py had zero production importers. Every `flush_status` hit in\nsrc/ resolved to a different symbol -- mark_compaction_flush_status_with\n[…]\nmpaction_lifecycle stays function-local -- it costs nothing\nand keeps the file safe if that edge ever comes back -- but its comment no\nlonger claims a cycle that is not there.\n\nFull suite 6323 passed.",
          "is_bot": false,
          "headline": "refactor(memory): remove Dream consolidation and the orphaned flush_s…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T11:33:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "720e2f137fb864ed15211016df874ab6e4b27d14",
          "body": "memory/flush_status.py imports from session/compaction_lifecycle at module\nscope. compaction_lifecycle.pre_compaction_flush_enabled imports back from\nmemory/flush_config, but from inside the function body -- which is the only\nreason the cycle does not close at import time.\n\nNothing marked that as lo\n[…]\no a neutral module. That is a real option\nand a better end state, but it moves a module two packages depend on -- worth\ndoing on its own rather than folded into a comment fix.\n\nFull suite 6361 passed.",
          "is_bot": false,
          "headline": "test(memory): pin the memory <-> session import cycle (#115)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T10:05:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4b8b1052d2682810c9f6f331d32463a7d6a6d97",
          "body": "Two write-path defects in the one-time free-form migration.\n\nMEMORY.md was rewritten with a plain write_text, which truncates before the\nnew content lands. Ordering makes that worse than a generic non-atomic write:\noverflow is appended to the archive first, then MEMORY.md is overwritten. A\ncrash dur\n[…]\ny (6 tests) covering both, plus\nthe happy paths so the guards cannot pass by disabling migration. Reverting\neither fix turns 3 of them red. Existing migration tests unchanged.\n\nFull suite 6363 passed.",
          "is_bot": false,
          "headline": "fix(memory): make the MEMORY.md migration non-destructive (#114)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T10:01:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c9dec66192da1cdc3dc70c9ed146371177b79f4",
          "body": "…113)\n\nMemoryManager.degraded only ever grew. status() records up to five\ndegradations per call -- one per store metric plus curated -- and then\nserializes the entire list into its own response.\n\nUnder a health poller against a broken store that compounds: every poll adds\nfive entries, and every pol\n[…]\nAdds tests/test_memory_degraded_bounded.py (8 tests), including a full\nday-of-polling cycle asserting the list stays at five entries. Reverting the\ndedupe turns 3 of them red.\n\nFull suite 6357 passed.",
          "is_bot": false,
          "headline": "fix(memory): stop the degraded list growing once per failed metric (#…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T09:51:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92aa8512259b72d732be3d6201f9c693d47890a4",
          "body": "TurnCaptureService rewrote the day file with Path.write_text, which opens\nwith \"w\" -- truncate first, then write. The file being rewritten is the whole\nday's captures for that session, appended to on every turn and allowed to\ngrow to capture_roll_max_chars (50 KB default). So the truncate window is\n\n[…]\n(8 tests). The decisive one drives a\nreal capture, fails the rename, and asserts the previous day's content is\nstill there byte-for-byte; reverting to write_text turns it red.\n\nFull suite 6357 passed.",
          "is_bot": false,
          "headline": "fix(memory): write turn captures atomically (#112)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T09:48:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "235f148b1fe8f91894c534ceacebc83d5294a6dd",
          "body": "Daily notes are not auto-injected: runtime.py drops them unconditionally\nright before assembling the prompt. But every snapshot build still loaded\nthem first -- a directory scan plus up to daily_notes_total_max_chars of\nfile reads (8 KB default), on session start, after every compaction, and on\never\n[…]\nerting a count of 1, and should: it populates a snapshot\ndirectly, so notes exist in memory and must still be dropped -- a snapshot\ncaptured before this change can carry them.\n\nFull suite 6341 passed.",
          "is_bot": false,
          "headline": "perf(memory): stop reading daily notes that are always discarded (#111)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T09:42:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c256f638e7e60302bf66f7a5cd6f140df4def77b",
          "body": "…(#109)\n\n#106 introduced _read_raw_checked and routed every WRITE path through it,\nso a transient read failure could no longer flush emptiness over real\nentries. The READ path was left on _read_file, whose own docstring admits it\n\"Returns [] for both empty AND unreadable\" -- and that is the path dec\n[…]\nllowed\nby a recovered file preserves all prior entries and appends normally.\n\nAdds tests/test_memory_curated_load_failure.py (8 tests). Reverting the\nguard turns 3 of them red. Full suite 6338 passed.",
          "is_bot": false,
          "headline": "fix(memory): surface unreadable curated files instead of going blind …",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T09:00:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9aba9700f33b6c334397ba1962df7193ca97a6d6",
          "body": "… (#110)\n\nUSER.md is a curated memory store in its own right. CuratedMemoryStore\nresolves it alongside MEMORY.md (curated.py `_path_for`), loads it,\nsanitizes it, and puts it in the frozen snapshot that enters the system\nprompt. The periodic memory review added in #108 writes user-profile facts\nther\n[…]\nest_memory_user_md_notify.py (11 tests), including negative cases\nso the widening does not sweep in every root-level markdown file. Reverting\nthe predicate turns 2 of them red. Full suite 6341 passed.",
          "is_bot": false,
          "headline": "fix(memory): treat USER.md as a memory source for write notifications…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T08:51:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfa27fe4d99dc74a3aad05202409d949faf2e8e9",
          "body": "* feat(memory): periodic memory-review nudge\n\nCurated memory only fills up when something asks the agent to write to it.\nLeft alone an agent runs for hundreds of turns with an empty MEMORY.md,\nbecause saving is never the most urgent thing in any single turn -- the\nrecent durability fixes made memory\n[…]\nt trigger reviews.\n\nAdds a behavioural test that drives the stage with a transcript port\nreturning False and asserts the nudge still counted; re-nesting the call\nturns it red.\n\nFull suite 6330 passed.",
          "is_bot": false,
          "headline": "feat(memory): periodic memory-review nudge (#108)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T08:19:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15d991e598fcffad37fb2863fe7580c2dac61f90",
          "body": "* fix(memory): restore hermes durability guards in curated store\n\nCuratedMemoryStore was adapted from hermes-agent tools/memory_tool.py but\ndropped several guards the original relies on, two of which could silently\ndestroy or freeze curated memory.\n\nUnreadable != empty. _read_file mapped OSError to \n[…]\nliberately not changed: the curated `memory` tool still does not fire\non_memory_write. Leaving the frozen snapshot alone mid-session is the\nprefix-cache invariant upstream relies on, not an oversight.",
          "is_bot": false,
          "headline": "fix(memory): lock curated writes on Windows, widen injection scan (#107)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T06:30:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dd2035e55e0c3819372d6b0a03d18ff8c23a5e4",
          "body": "CuratedMemoryStore was adapted from hermes-agent tools/memory_tool.py but\ndropped several guards the original relies on, two of which could silently\ndestroy or freeze curated memory.\n\nUnreadable != empty. _read_file mapped OSError to [], and UnicodeDecodeError\nwas not caught at all. A transient lock\n[…]\nr paths still carry it,\nwhich is where it is actually needed.\n\nAdds tests/test_memory_curated_durability.py (17 tests) covering each guard,\nincluding that a failed read leaves the file byte-identical.",
          "is_bot": false,
          "headline": "fix(memory): restore hermes durability guards in curated store (#106)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-26T06:30:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf938af449763fec558777c08829376e3fe5cc6f",
          "body": "feat(gateway)!: simplify channel access to pairing",
          "is_bot": false,
          "headline": "Merge pull request #104 from keyKQ/codex/role-free-pairing-control",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T17:34:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b22a8460669190b56e99153f1dc7b7c0e4097492",
          "body": null,
          "is_bot": false,
          "headline": "fix(cron): scope job management to profiles",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T15:48:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6476a7bf65fea1cdc8d649ba6fe25be8dc219fe7",
          "body": "Render common Markdown as escaped Telegram HTML, convert tables into mobile-friendly labeled rows, and preserve explicit parse-mode overrides. Fall back to plain text on entity parse errors and cover messages, edits, captions, and forum replies.",
          "is_bot": false,
          "headline": "fix(telegram): render markdown replies",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T15:00:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f964cc81daab5c6d6f170ec705857d312da843c2",
          "body": "Keep admission proofs and validators outside persisted route metadata while preserving queued-turn revalidation. Add network headroom to Telegram long polling and cover both regressions.",
          "is_bot": false,
          "headline": "fix(telegram): keep pairing runtime state serializable",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T15:00:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2174d776beb5687033ae8d9f2404748f8116f79b",
          "body": "Replace role and scope authorization with binary Control and Channel connection surfaces backed by explicit RPC audiences.\n\nRequire durable Telegram pairing, safe group admission, and grant revalidation before turns and tools. Remove owner/admin elevation from tools, cron, CLI, and Control UI while preserving sandbox and approval policy.\n\nBREAKING CHANGE: channel roles, scoped tokens, access modes, and unauthenticated public Control are removed.",
          "is_bot": false,
          "headline": "feat(gateway)!: replace channel roles with pairing surfaces",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T15:00:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b68e8932d0457800a1de980a82a4b47ee020565",
          "body": "fix(gateway): non-destructive /new and /reset when flush unavailable",
          "is_bot": false,
          "headline": "Merge pull request #102 from use-agent-os/fix/session-reset-flush-gate",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T14:19:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eef97b0f1735b89548da91c5fd985aeb8f1f2de1",
          "body": "sessions.reset failed closed with flush_unavailable whenever the flush\nservice was disabled (the default) and no durable checkpoint receipt\ncovered the transcript, intermittently breaking /new and /reset on\nWebUI and Telegram.\n\n- session: add rotate_session_id_archive_only() and report archive\n  suc\n[…]\n when a checkpoint\n  receipt covers the transcript\n- channels: add ChannelSessionPointers and route channel /new to a\n  fresh session key (WebUI \"New Chat\" parity), leaving the old\n  session untouched",
          "is_bot": false,
          "headline": "fix(gateway): non-destructive /new and /reset when flush unavailable",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T13:58:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "229354e99ed306ea7df57a7ed4d71f30c7df0531",
          "body": "fix(telegram): allow admitted DM slash commands",
          "is_bot": false,
          "headline": "Merge pull request #101 from use-agent-os/fix/telegram-dm-slash-commands",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T07:27:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6870ff6433f5bf90ed6ba625624c2e4e435906bd",
          "body": null,
          "is_bot": false,
          "headline": "fix(telegram): allow admitted DM slash commands",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T07:26:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13c81056feae936c34000764fc189e88edc9e819",
          "body": "…ting\n\ndocs(security): establish private vulnerability reporting",
          "is_bot": false,
          "headline": "Merge pull request #99 from keyKQ/codex/enable-private-security-repor…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:46:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bedb69f653b585b36ed13424257152e919fd3f4b",
          "body": "Add native Telegram typing feedback with a four-second refresh cadence, route chat and forum-topic context through the shared keepalive, and isolate Bot API failures from turn execution. Advertise the capability, document the behavior, and cover payloads, routing, policy selection, cadence, fallback targets, and failure handling with offline regression tests.\n\nFixes #92",
          "is_bot": false,
          "headline": "feat(telegram): show typing indicators during turns (#100)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:44:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5e71260313bbd915809b505b5e109af3f4de341",
          "body": "…e-security-reporting",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'upstream/main' into codex/enable-privat…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:38:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4074db86eed1154e629d834ab8e8f3e04ec5ea90",
          "body": "fix(slack): dispatch socket mode slash commands",
          "is_bot": false,
          "headline": "Merge pull request #98 from keyKQ/codex/fix-slack-socket-slash-commands",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:30:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f1ac1fab635c83237abde5e52263291b9aa79fc",
          "body": "Point security researchers to the enabled private advisory form and enforce the reporting contract with an offline release-hygiene regression test.",
          "is_bot": false,
          "headline": "docs(security): document private vulnerability reporting",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:27:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e1df8f1716182e30eade31bac0d0215260ad182",
          "body": "Normalize slash_commands envelopes through a shared webhook and Socket Mode path so sender, channel, team, command text, and group classification are preserved.\n\nTreat native slash commands as directed interactions so mention-only group gating does not discard them, and add regression coverage for acknowledgement and enqueue behavior.\n\nFixes #55",
          "is_bot": false,
          "headline": "fix(slack): dispatch socket mode slash commands",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:19:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a3e0867db07ce4a37b76a92df7207de2d18e08f",
          "body": "…tion\n\nfix(channels): grant admitted senders read access",
          "is_bot": false,
          "headline": "Merge pull request #97 from keyKQ/codex/fix-channel-command-authoriza…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:15:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc0304466407218bf6504bdec92ac0323416c519",
          "body": "fix(slack): classify slash command conversations correctly",
          "is_bot": false,
          "headline": "Merge pull request #96 from keyKQ/codex/fix-slack-channel-classification",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:15:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9503bbd43cfcf238ab46bddff51eb74a2605f66",
          "body": "Acknowledge application commands before dispatch and complete deferred original responses for command, batch, and streaming reply paths.",
          "is_bot": false,
          "headline": "fix(discord): complete native interaction responses (#95)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:11:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb9d154b274c2a9f33b65368e04c9429465f5055",
          "body": "Grant operator.read to channel senders after access-policy admission while reserving operator.write for configured channel admins. Document the permission model and cover read/write authorization tiers.\n\nRefs #57",
          "is_bot": false,
          "headline": "fix(channels): grant admitted senders read access",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:07:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb53e4fa01a1eb9e2b348cf4feb36132ef8ce8ac",
          "body": "Derive Slack conversation types from channel ID prefixes and mark native slash forms as explicit interactions. Preserve group access controls while bypassing mention-only gating for slash commands.\n\nRefs #56",
          "is_bot": false,
          "headline": "fix(slack): classify slash command conversations correctly",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:04:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5defda024cd9232d24a15c430fad835d57fa99d0",
          "body": "Gracefully degrade Discord native command registration failures without aborting gateway startup. Adds regression coverage for REST errors and exhausted rate-limit retries.\\n\\nFixes #54",
          "is_bot": false,
          "headline": "fix(discord): tolerate command registration failures (#94)",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T06:03:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d973e4a85dca41bff846555c345f1d080302f48",
          "body": "Acknowledge application commands before dispatch and complete deferred original responses for command, batch, and streaming reply paths.",
          "is_bot": false,
          "headline": "fix(discord): complete native interaction responses",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T05:59:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a82a3e2e88078434b1e130ca3e1936014c23681",
          "body": "…plies\n\nfix(telegram): preserve forum command reply targets",
          "is_bot": false,
          "headline": "Merge pull request #93 from keyKQ/codex/fix-telegram-forum-command-re…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T05:44:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9515e13fe68ee8008b7d7d55f1c05a88f82c2cd5",
          "body": "…mentions-51\n\nfix(telegram): handle native bot command mentions",
          "is_bot": false,
          "headline": "Merge pull request #64 from thanhtan1105/fix/telegram-native-command-…",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T05:43:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72e57dc3775d651b8b05e6438c5311a892d5d7ea",
          "body": "feat(provider): add OpenCAP gateway support",
          "is_bot": false,
          "headline": "Merge pull request #63 from thanhtan1105/feat/opencap-llm-gateway",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T05:41:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe2209ee768c37401f385de1fb3d503f54a75b3e",
          "body": "Use the gateway route channel metadata as the Telegram chat ID and map a thread-targeted reply_to value to message_thread_id.\n\nAdd an end-to-end regression test from an inbound forum command through the Bot API payload.\n\nFixes #50",
          "is_bot": false,
          "headline": "fix(telegram): preserve forum command reply targets",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T05:36:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ee498aab03fc5c873122ab5a4ff3c906dda2ad8",
          "body": null,
          "is_bot": false,
          "headline": "fix(telegram): resolve native command edge cases",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T05:31:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32fad70f2085ac7d8f4d08690aeef8861b6cde46",
          "body": null,
          "is_bot": false,
          "headline": "fix(provider): resolve OpenCAP conflicts with React console",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-25T05:31:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed4a6b727858ea14900fd3d4b26770ad524b5793",
          "body": "chore(release): bump version to 2026.7.25",
          "is_bot": false,
          "headline": "Merge pull request #91 from use-agent-os/chore/bump-2026.7.25",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T04:32:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ede3c71d33f1e61645ed7deba486ea1bd6ee08ff",
          "body": null,
          "is_bot": false,
          "headline": "docs: add version bump guidelines for release cuts",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T04:32:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17b1394d1f375b45535d82b60fd350a943494480",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump version to 2026.7.25",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-25T04:17:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23bac767ce41430905e1e36fb09d20f090e254d5",
          "body": "fix(platform): resolve windows compatibility type-checking and test s…",
          "is_bot": false,
          "headline": "Merge pull request #89 from Preciousuche/fix/windows-compatibility",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-24T16:43:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ded736bd09df100e538525d12ea390512e7e174c",
          "body": "…ark latency ceiling",
          "is_bot": false,
          "headline": "fix(platform): explicitly define and document windows-specific benchm…",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-24T14:45:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24ff9ba2fd3e9d14e93606823aaea2992b99657f",
          "body": "…uite bugs",
          "is_bot": false,
          "headline": "fix(platform): resolve windows compatibility type-checking and test s…",
          "author_name": "Bukee",
          "author_login": "bukeeastrey",
          "committed_at": "2026-07-24T13:04:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6fc2aa254d9e8f56d6580f27bea026b751ada1",
          "body": "fix(frontend): repair settings, Bankr icons, and session reset",
          "is_bot": false,
          "headline": "Merge pull request #88 from keyKQ/codex/fix-issues-82-84-85",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-24T12:31:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a125bae48428ab64fff6b8ef11f9dcfeaa986836",
          "body": null,
          "is_bot": false,
          "headline": "test(chat): stabilize tool output modal test",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-24T12:14:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fabcd042a96c715b5d670a66fdcec2aee52d2194",
          "body": "Restore embedded Config layout and YAML sizing, use the Bankr brand asset when catalog metadata omits a logo, and add an explicit no-backup reset recovery action shared by chat controls.\n\nRefs #82, #84, #85",
          "is_bot": false,
          "headline": "fix(frontend): repair settings, Bankr icons, and session reset",
          "author_name": "Key KQ",
          "author_login": "keyKQ",
          "committed_at": "2026-07-24T11:56:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "859adf36a9db97dd6cbbe14a0566db775b20eaa0",
          "body": "fix(cli): wrap onboarding prompt input",
          "is_bot": false,
          "headline": "Merge pull request #87 from use-agent-os/fix/cli-prompt-line-breaks",
          "author_name": "andreapn.eth",
          "author_login": "andreapn",
          "committed_at": "2026-07-24T11:14:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 18,
      "commits_last_year": 361,
      "latest_release_at": "2026-07-30T16:23:32Z",
      "latest_release_tag": "v2026.7.30",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 1.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "use-agent-os",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "agent",
            "chatbot",
            "gateway",
            "llm",
            "mcp",
            "router",
            "Development Status :: 3 - Alpha",
            "License :: OSI Approved :: Apache Software License",
            "Operating System :: OS Independent",
            "Programming Language :: Python :: 3.12"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/use-agent-os/",
          "is_deprecated": false,
          "latest_version": "2026.7.30",
          "repository_url": "https://github.com/use-agent-os/agent-os",
          "versions_count": 17,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2040,
          "first_published_at": "2026-07-15T02:55:50.778642Z",
          "latest_published_at": "2026-07-30T17:23:26.985764Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 14,
      "stars": 17,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-14",
            "count": 1
          },
          {
            "date": "2026-07-15",
            "count": 1
          },
          {
            "date": "2026-07-16",
            "count": 1
          },
          {
            "date": "2026-07-18",
            "count": 1
          },
          {
            "date": "2026-07-19",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          },
          {
            "date": "2026-07-24",
            "count": 1
          },
          {
            "date": "2026-07-27",
            "count": 3
          },
          {
            "date": "2026-07-28",
            "count": 1
          },
          {
            "date": "2026-07-29",
            "count": 2
          }
        ],
        "complete": true,
        "collected": 14,
        "total_forks": 14
      },
      "star_history": null,
      "open_issues_and_prs": 18
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "frontend/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 249033,
      "source_files_sampled": 1401,
      "oversized_source_files": 23,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "docs/agents.md",
        "src/agentos/identity/templates/bootstrap/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 10771
    },
    "dependencies": {
      "manifests": [
        "frontend/package.json",
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "@radix-ui/react-slot",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.0"
        },
        {
          "name": "@tabler/icons-react",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.45.0"
        },
        {
          "name": "@tanstack/react-query",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.101.2"
        },
        {
          "name": "class-variance-authority",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "dompurify",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.4.12"
        },
        {
          "name": "highlight.js",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.11.1"
        },
        {
          "name": "lucide-react",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.25.0"
        },
        {
          "name": "marked",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.0.7"
        },
        {
          "name": "motion",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.42.2"
        },
        {
          "name": "react",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-dom",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-router",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.18.1"
        },
        {
          "name": "sonner",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.6.0"
        },
        {
          "name": "zustand",
          "manifest": "frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.14"
        },
        {
          "name": "starlette",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.40,<2.0"
        },
        {
          "name": "python-multipart",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.0.20"
        },
        {
          "name": "uvicorn",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.30,<1.0"
        },
        {
          "name": "pydantic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0,<3.0"
        },
        {
          "name": "pydantic-settings",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0,<3.0"
        },
        {
          "name": "sqlmodel",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.0.20,<0.1.0"
        },
        {
          "name": "anyio",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.0"
        },
        {
          "name": "httpx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.27,<0.29"
        },
        {
          "name": "mcp",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.2.0,<2.0"
        },
        {
          "name": "brotli",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.1"
        },
        {
          "name": "jinja2",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.1"
        },
        {
          "name": "structlog",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=24.0"
        },
        {
          "name": "typer",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.12"
        },
        {
          "name": "rich",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=13.0"
        },
        {
          "name": "websockets",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=13.0"
        },
        {
          "name": "aiosqlite",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.20"
        },
        {
          "name": "apscheduler",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.10"
        },
        {
          "name": "pyyaml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0"
        },
        {
          "name": "sqlite-vec",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.1"
        },
        {
          "name": "html2text",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2024.2"
        },
        {
          "name": "readability-lxml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.8"
        },
        {
          "name": "beautifulsoup4",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.12"
        },
        {
          "name": "cachetools",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=5.3"
        },
        {
          "name": "pdfplumber",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.11"
        },
        {
          "name": "pillow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=10.0"
        },
        {
          "name": "croniter",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0"
        },
        {
          "name": "tomli-w",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.0"
        },
        {
          "name": "yoyo-migrations",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=8.2"
        },
        {
          "name": "prompt-toolkit",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.0"
        },
        {
          "name": "questionary",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0"
        },
        {
          "name": "python-docx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.1.0"
        },
        {
          "name": "python-pptx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.0.0"
        },
        {
          "name": "openpyxl",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.1.0"
        },
        {
          "name": "pypdf",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.0.0"
        },
        {
          "name": "reportlab",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.0.0"
        },
        {
          "name": "python-telegram-bot",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=20.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 110,
        "open_issues": 16,
        "closed_ratio": 0.673,
        "closed_issues": 33,
        "closed_unmerged_prs": 6
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "keyKQ",
          "commits": 239,
          "avatar_url": "https://avatars.githubusercontent.com/u/122466625?v=4"
        },
        {
          "type": "User",
          "login": "andreapn",
          "commits": 103,
          "avatar_url": "https://avatars.githubusercontent.com/u/107019027?v=4"
        },
        {
          "type": "User",
          "login": "thanhtan1105",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/12711672?v=4"
        },
        {
          "type": "User",
          "login": "bukeeastrey",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/158785820?v=4"
        },
        {
          "type": "User",
          "login": "iamhaniofficial",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/306947529?v=4"
        },
        {
          "type": "User",
          "login": "kudala-bharani",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/121555407?v=4"
        },
        {
          "type": "User",
          "login": "HaimiyaWasn",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/116284029?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.634
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "frontend.yml",
        "live-release-e2e.yml",
        "llm-e2e.yml",
        "pypi-publish.yml",
        "webui-browser-smoke.yml",
        "wheelhouse-release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json",
        "eslint.config.js"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "11 out of 11 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 5,
            "reason": "Found 6/11 approved changesets -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "71 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2e422bec178dd1e999ef89c0047ffd66a3eea42b",
        "ran_at": "2026-07-30T17:25:38Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-30T17:23:32Z",
      "oldest_open_prs": [
        {
          "number": 155,
          "created_at": "2026-07-29T09:18:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 167,
          "created_at": "2026-07-30T17:17:01Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-30T16:17:01Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 126,
          "created_at": "2026-07-27T06:54:59Z",
          "last_comment_at": "2026-07-27T15:38:51Z",
          "last_comment_author": "andreapn"
        },
        {
          "number": 135,
          "created_at": "2026-07-27T16:08:20Z",
          "last_comment_at": "2026-07-28T02:40:22Z",
          "last_comment_author": "keyKQ"
        },
        {
          "number": 136,
          "created_at": "2026-07-27T16:08:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 137,
          "created_at": "2026-07-27T16:08:29Z",
          "last_comment_at": "2026-07-28T17:07:04Z",
          "last_comment_author": "Preciousuche"
        },
        {
          "number": 138,
          "created_at": "2026-07-27T16:08:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 139,
          "created_at": "2026-07-27T16:17:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 140,
          "created_at": "2026-07-27T16:17:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 141,
          "created_at": "2026-07-27T16:19:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 142,
          "created_at": "2026-07-27T16:26:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 145,
          "created_at": "2026-07-28T05:59:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 151,
          "created_at": "2026-07-29T08:24:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 152,
          "created_at": "2026-07-29T08:24:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 153,
          "created_at": "2026-07-29T08:24:57Z",
          "last_comment_at": "2026-07-29T17:15:01Z",
          "last_comment_author": "Preciousuche"
        },
        {
          "number": 158,
          "created_at": "2026-07-30T05:50:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 161,
          "created_at": "2026-07-30T06:22:43Z",
          "last_comment_at": "2026-07-30T13:57:56Z",
          "last_comment_author": "thanhtan1105"
        },
        {
          "number": 165,
          "created_at": "2026-07-30T15:52:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/use-agent-os/agent-os",
    "host": "github.com",
    "name": "agent-os",
    "owner": "use-agent-os"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": "The weighted overall 63 is calibrated to 71 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 63,
            "calibrated": 71,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 71,
      "inputs": {
        "security": 46,
        "vitality": 70,
        "community": 58,
        "governance": 57,
        "calibration": "2026-08-02",
        "engineering": 80,
        "ai_readiness": 66,
        "weighted_overall_raw": 63
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "commits_last_year": 361,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "361 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 361
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 18,
              "latest_release_tag": "v2026.7.30",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 1.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "18 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 18
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 58,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 29,
            "inputs": {
              "forks": 14,
              "stars": 17,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "17 stars",
                "points": 19.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "14 forks",
                "points": 9.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 55,
            "inputs": {
              "packages": [
                "use-agent-os"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 2040
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,040 downloads/month across pypi",
                "points": 44.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2040,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 30,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.634
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 63% of commits",
                "points": 8.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 63
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 74,
            "inputs": {
              "merged_prs": 110,
              "open_issues": 16,
              "closed_issues": 33,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 0.673,
              "closed_unmerged_prs": 6,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "67% of issues closed",
                "points": 28.3,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 67
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "110/116 decided PRs merged",
                "points": 28.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 110,
                      "decided": 116
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 6/11 approved changesets -- score normalized to 5",
                "points": 7.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "weak",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "followers": 5,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "use-agent-os",
              "public_repos": 1,
              "account_age_days": 17
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of use-agent-os",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "use-agent-os"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "1 public repos, account ~0 yr old",
                "points": 2.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 1
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "use-agent-os"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "17 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json, eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json, eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "11 out of 11 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "weak",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "11 out of 11 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 6/11 approved changesets -- score normalized to 5",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "71 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 66,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.97,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "docs/agents.md",
                "src/agentos/identity/templates/bootstrap/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 10771
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, docs/agents.md, src/agentos/identity/templates/bootstrap/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, docs/agents.md, src/agentos/identity/templates/bootstrap/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "frontend/tsconfig.json"
              ],
              "agent_commit_share": 0.08,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json, eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json, eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "frontend/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "frontend/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "8 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 8,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 249033,
              "source_files_sampled": 1401,
              "oversized_source_files": 23
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (frontend/tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "frontend/tsconfig.json",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "23/1401 source files over 60KB",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1401,
                      "oversized": 23
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "mcp-server",
        "chat-bot",
        "library",
        "network-service",
        "web-ui",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "web-ui": 4,
        "library": 6,
        "chat-bot": 6,
        "mcp-server": 7,
        "network-service": 4
      },
      "primary": "mcp-server",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:pypi",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "chat-bot",
          "source": "dep:python-telegram-bot",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:typer",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "mcp-server",
          "source": "dep:mcp",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "network-service",
          "source": "dep:starlette",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "web-ui",
          "source": "dep:react-dom",
          "weight": 4
        },
        {
          "tier": "structure",
          "label": "mcp-server",
          "source": "mcp_signal",
          "weight": 3
        },
        {
          "tier": "tags",
          "label": "chat-bot",
          "source": "tag:chatbot",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index pypi:use-agent-os@2026.7.30; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T17:25:58.487717Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/u/use-agent-os/agent-os.svg",
  "full_name": "use-agent-os/agent-os",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v2.3.1、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计PyPI.