98

/ 100

GradeA

Polished and well engineered. Punching above its star count.

Top 3% of 5,156 graded repos

Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.

Outstanding. A score of 98/100 puts this repo in a very small tier of truly well-engineered projects.

Top fixes

Highest-impact changes first, ranked by point weight

2 to address
  1. 1
    Install and run instructions9pt

    Add a .env.example listing all required environment variables so contributors know what to set up.

  2. 2
    Reproducibility6pt

    Add .github/dependabot.yml with at least one package-ecosystem entry so dependencies are updated automatically.

Working through the fixes? Let every push regrade itself.

The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.

Install the GitHub App

Scorecard

Every check, grouped by category and sorted worst-first

Documentation

97

Install and run instructions9pt90

README documents how to install the project.

README12pt100

README is present.

License6pt100

Licensed under Apache-2.0.

Contributing guide5pt100

Contributing guide is detailed and thorough.

Engineering

98

Reproducibility6pt85

Lockfile present (go.sum). Installs are reproducible.

Tests18pt100

Test files detected (bench/egress/harness/memory_test.go).

CI/CD14pt100

CI is configured (.github/workflows/ci.yaml).

Linting and formatting5pt100

Formatting enforced (.golangci.yml).

Issue and PR templates6pt100

Issue or PR templates present.

Project health

100

Dependency manifest6pt100

Dependency manifest found (go.mod).

Repository metadata5pt100

Repository has a description.

Activity5pt100

Actively maintained (pushed within the last month).

Housekeeping3pt100

.gitignore present.

Repository health signals

Activity, community, and responsiveness at scan time

Activity

  • 159 / 465
    Commits (30d / 90d)
  • 87
    Forks
  • 44
    Releaseslatest 5mo ago

Community

  • 100% - Good
    Community health
  • 1 bus factorlow
    author own >50% of commits
  • 737
    Watchers

Responsiveness

  • 20h
    Median issue response
  • <1h
    Median PR merge time
  • 7
    Open issues
Repository files49 root entries
  • .clusterfuzzlite
    Good: Environment pinned via .clusterfuzzlite/Dockerfile.
  • .github
    Good: CI is configured (.github/workflows/ci.yaml).
    Good: Issue or PR templates present.
  • assets
  • bench
    Good: Test files detected (bench/egress/harness/memory_test.go).
  • charts
  • cmd
  • configs
  • deploy
  • docs
  • enterprise
  • examples
  • internal
  • schemas
  • scripts
  • sdk
  • test
  • testdata
  • tests
  • tools
  • .coderabbit.yaml
  • .dockerignore
  • .gitattributes
  • .gitignore
    Good: .gitignore present.
  • .gitleaks.toml
  • .golangci.yml
    Good: Formatting enforced (.golangci.yml).
  • .goreleaser.yaml
  • .pre-commit-config.yaml
  • action.yml
  • AGENTS.md
  • CHANGELOG.md
  • CHARTER.md
  • CLAUDE.md
  • CODE_OF_CONDUCT.md
    Good: Code of conduct present.
  • codecov.yml
  • CONTRIBUTING.md
    Good: Contributing guide is detailed and thorough.
    Good: Contributing guide includes setup/install instructions.
    Good: Contributing guide describes code style expectations.
    Good: Contributing guide explains how to run tests.
    Good: Contributing guide describes the PR/review workflow.
    Good: Contributing guide includes code examples.
  • Dockerfile
  • Dockerfile.goreleaser
  • Dockerfile.init
  • Dockerfile.license-service
  • go.mod
    Good: Dependency manifest found (go.mod).
  • go.sum
    Good: Lockfile present (go.sum). Installs are reproducible.
  • GOVERNANCE.md
  • LICENSE
    Good: Licensed under Apache-2.0.
  • Makefile
  • PR-NOTES.md
  • README.md
    Good: README is present.
    Good: README is well structured with multiple sections.
    Good: README includes screenshots or visuals. Great for first impressions.
    Good: README has code examples.
    Good: README links to a live demo or deployed app.
    Good: README includes status badges.
    Good: README documents how to install the project.
    Good: README documents how to run the project.
  • renovate.json
  • SECURITY.md
    Good: Security policy present.
  • SPONSORS.md
RepoGrade badge preview

Add this badge to your README

It updates automatically each time the repo is re-graded.

[![RepoGrade](https://www.repo-grade.com/api/badge/luckypipewrench/pipelock)](https://www.repo-grade.com/report/luckypipewrench/pipelock)

More graded Go repos