96
/ 100
Polished and well engineered. Punching above its star count.
Security Governance for Agentic AI
Outstanding. A score of 96/100 puts this repo in a very small tier of truly well-engineered projects.
Top fixes
Highest-impact changes first, ranked by point weight
- 1CI/CD14pt
Add a lint step to catch style issues automatically.
- 2CI/CD14pt
Add `tsc --noEmit`, `mypy`, or `cargo check` to catch type errors before they merge.
- 3CI/CD14pt
Upload coverage to Codecov, Coveralls, or report it with `--coverage` flags.
- 4Reproducibility6pt
Add .github/dependabot.yml with at least one package-ecosystem entry so dependencies are updated automatically.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
96
Contributing guide is detailed and thorough.
README is present.
README documents how to install the project.
Licensed under Apache-2.0.
Engineering
94
CI is configured (.github/workflows/ci.yml).
Lockfile present (go.sum). Installs are reproducible.
Test files detected (bundles/splunk_local_bridge/s3_exporter/tests).
Formatting enforced (.golangci.yml).
Issue or PR templates present.
Project health
100
Dependency manifest found (go.mod).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- 54 / 129Commits (30d / 90d)
- 134Forks
- 17Releaseslatest 2mo ago
Community
- 87% - GoodCommunity health
- 4 bus factorauthors own >50% of commits
- 763Watchers
Responsiveness
- 3d 1hMedian issue response
- 22hMedian PR merge time
- 33Open issues
Repository files33 root entries
- .devin
- .githubGood: CI is configured (.github/workflows/ci.yml).Good: Issue or PR templates present.
- bundlesGood: Test files detected (bundles/splunk_local_bridge/s3_exporter/tests).Good: Environment pinned via bundles/local_observability_stack/docker-compose.yml.
- cli
- cmd
- docs
- docs-site
- extensions
- internal
- packaging
- plugins
- policies
- schemas
- scripts
- skills
- test
- .gitignoreGood: .gitignore present.
- .golangci.ymlGood: Formatting enforced (.golangci.yml).
- .goreleaser.yaml
- CHANGELOG.md
- CODE_OF_CONDUCT.mdGood: Code of conduct present.
- CONTRIBUTING.mdGood: Contributing guide is detailed and thorough.Issue: Contributing guide lacks a setup section (−12 pts).Fix: Show new contributors how to get a local dev environment running.Issue: Contributing guide lacks a code style section (−8 pts).Fix: Describe your linting/formatting rules and how to run them.Issue: Contributing guide lacks a testing section (−8 pts).Fix: Show contributors how to run the test suite (e.g. npm test, pytest, cargo test).Good: Contributing guide describes the PR/review workflow.Issue: Contributing guide has no code examples (−5 pts).Fix: Add code blocks showing example commands for setup, running tests, and submitting a PR.
- go.modGood: Dependency manifest found (go.mod).
- go.sumGood: Lockfile present (go.sum). Installs are reproducible.
- LICENSEGood: Licensed under Apache-2.0.
- Makefile
- MANIFEST.in
- NOTICE
- pyproject.toml
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- RELEASE_NOTES_0.3.0.md
- SECURITY.mdGood: Security policy present.
- uv.lock
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/cisco-ai-defense/defenseclaw)