# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 41 → 55 (+14.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 35 → 48 (+13.5)
- Architecture 69 → 91 (+22.4)
- Maturity 74 → 80 (+5.6)
- Readiness 26 → 41 (+14.8)
- Security 78 → 100 (+21.5)

## Resolved (17)

- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: evals/fixtures/code-simplification/config-parser.js (evals/fixtures/code-simplification/config-parser.js)
- Hotspot: scripts/lib/skill-lint.js (scripts/lib/skill-lint.js)
- Hotspot: scripts/run-evals.js (scripts/run-evals.js)
- Hotspot: scripts/validate-commands.js (scripts/validate-commands.js)
- LLM evaluation failed
- No automated tests
- No exposed public API
- No tests found
- Scanner failed to run — not a clean result
- Test reliability not included

## New (28)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- FunctionTooLong: run-evals.runDeterministic (scripts/run-evals.js)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No dependency advisory monitoring
- Scanner failed to run — not a clean result
- Scanner failed to run — not a clean result
- Workflow token permissions not restricted
- run-evals.parseGrading (cognitive 26) (scripts/run-evals.js)
- run-evals.parseGrading (cyclomatic 26) (scripts/run-evals.js)
- run-evals.runBehavioral (cognitive 29) (scripts/run-evals.js)
- run-evals.runBehavioral (cyclomatic 20) (scripts/run-evals.js)
- …and 8 more

## Changes since last survey

- 161 commits — 115 feature/other, 46 fixes

## By area

- (repo) — 67 commits
- (root) — 14 commits
- scripts/run-evals-test.js — 8 commits
- .github/workflows — 7 commits
- scripts/lib — 5 commits
- skills/security-and-hardening — 5 commits
- .claude/commands — 4 commits
- docs/advanced-per-agent-configuration.md — 4 commits
- evals/cases — 4 commits
- scripts/validate-reference-links-test.js — 4 commits
- docs/getting-started.md — 3 commits
- skills/context-engineering — 3 commits
- skills/interview-me — 3 commits
- skills/shipping-and-launch — 3 commits
- docs/adoption-guide.md — 2 commits
- hooks/SIMPLIFY-IGNORE.md — 2 commits
- references/performance-checklist.md — 2 commits
- skills/frontend-ui-engineering — 2 commits
- skills/observability-and-instrumentation — 2 commits
- .gemini/commands — 1 commit

## Notable commits

- fix: Merge #469: fix references/ links and add CI validator (#468)
- fix: Merge #501: add hook regression coverage and a bash 5.2 simplify-ignore fix
- fix: Merge #510: fix and CI-wire the SessionStart envelope test
- fix: Merge #570: fix stale skill count in README heading
- fix: Merge pull request #434 from ayobamiseun/fix/rank1-description-vocab
- fix: Merge pull request #505 from abhisheksharma2411/fix/skill-lint-frontmatter-and-exempt-lookup
- fix: Merge pull request #531 from ayobamiseun/fix/518-plan-clobber-guard
- fix: Potential fix for pull request finding
- fix: fix(agents): align code-reviewer severity labels with the code-review skill
- fix: fix(commands): mirror incomplete-plan guard across tools
- fix: fix(context): address nucliweb review — merge duplicate red flag, wire Level 5 to budget section
- fix: fix(context): correct lost-in-the-middle mechanism per federicobartoli review
- fix: fix(evals): add missing owner to negative trigger tests
- fix: fix(evals): bind grader results to declared expectations by id
- fix: fix(evals): canonicalize expectation text and recompute pass_rate
- fix: fix(evals): clear result slot up front instead of on rejection
- fix: fix(evals): record executor model and timestamp in grading.json
- fix: fix(evals): reject incomplete grader results
- fix: fix(evals): reject null grader expectations without crashing
- fix: fix(evals): remove stale grading.json when grading is rejected
- …and 141 more
