# Changelog

## Score

- CAI 66 → 45 (-20.9)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 79 → 80 (+1.3)
- Maturity 72 → 51 (-20.2)
- Readiness 65 → 33 (-32.4)
- Security 57 → 52 (-4.5)

## Resolved (19)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further sole-owners (lower concentration)
- Hotspot: packages/cli/src/commands/auth.ts (packages/cli/src/commands/auth.ts)
- Hotspot: packages/cli/src/commands/docs.ts (packages/cli/src/commands/docs.ts)
- Hotspot: packages/cli/src/commands/generate.ts (packages/cli/src/commands/generate.ts)
- Hotspot: packages/cli/src/commands/remove.ts (packages/cli/src/commands/remove.ts)
- Hotspot: packages/cli/src/commands/setup.ts (packages/cli/src/commands/setup.ts)
- Hotspot: packages/cli/src/commands/skill.ts (packages/cli/src/commands/skill.ts)
- Hotspot: packages/cli/src/utils/auth.ts (packages/cli/src/utils/auth.ts)
- Hotspot: packages/mcp/src/index.ts (packages/mcp/src/index.ts)
- Low CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
- Off-boarding risk: anonymized user #1
- PR-triggered workflow without a permissions block
- The 'Available Tools' section lists resolve-library-id but does not show how to invoke it from a Cursor prompt or agent call. (plugins/cursor/context7/README.md)
- The API Key section recommends creating an API key but does not explain how to verify it is used after export. (plugins/copilot/context7/README.md)

## New (47)

- Boundary-crossing change coupling: templates.ts ↔ index.ts (packages/cli/src/setup/templates.ts)
- Change coupling: docs.ts ↔ api.ts (packages/cli/src/commands/docs.ts)
- Change coupling: index.ts ↔ api.ts (packages/mcp/src/index.ts)
- Change coupling: setup.ts ↔ templates.ts (packages/cli/src/commands/setup.ts)
- Change coupling: skill.ts ↔ api.ts (packages/cli/src/commands/skill.ts)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 27 more

## Changes since last survey

- 3 commits — 3 feature/other, 0 fixes

## By area

- packages/mcp — 2 commits
- docs/howto — 1 commit

## Notable commits

- change: Add hyperlink in Documentation for user creation of API key in browser (#2992)
- change: chore(release): version packages (#2997)
- change: feat: MCP v2 (#2843)
