Atlas / MCP servers / kastalien-research / Thoughtbox

ThoughtboxBLOCK

mcp/kastalien-research/thoughtbox

Thoughtbox is an intention ledger for agents. Evaluate AI's decisions against its decision-making.

Verdict
BLOCK
Grade
F
Trust score
30 /100
Exposed tools
164 118r · 42w · 4d
Transport
streamable-http · stdio
License
MIT
Stars
66
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Multi-agent collaborative reasoning that's auditable. Thoughtbox is an MCP server for structured, multi-agent reasoning, with a companion web app for workspace and inspection flows. Every step is recorded as a structured thought in a persistent reasoning ledger that can be visualized, exported, and analyzed.

Runtime modes: Local development can use filesystem or in-memory storage. Deployed mode uses Supabase-backed storage, and the current production MCP server runs on Cloud Run.

Observatory UI showing a reasoning session with 14 thoughts and a branch exploration (purple nodes 13-14) forking from thought 5.

Code Mode

Thoughtbox exposes exactly two MCP tools using the Code Mode pattern:

  • `thoughtbox_search` — Write JavaScript to query the operation/prompt/resource catalog. The LLM has full programmatic filtering power over the catalog.
  • `thoughtbox_execute` — Write JavaScript using the tb SDK to chain operations. Access thoughts, sessions, knowledge, notebooks, hub, observability, and protocol tools through a unified namespace.

Workflow: search to discover available operations, then execute code against them. Use console.log() for debugging — output is captured in response logs.

This replaces per-operation tool registration with a two-tool surface that scales without context window bloat.

Multi-Agent Collaboration

The Hub is the coordination layer. Agents register with role-specific profiles, join shared workspaces, and work through a structured problem-solving workflow — all via thoughtbox_execute.

The workflow: register → create workspace → create problem → claim → work → propose solution → peer review → merge → consensus

Workspace primitives:

  • Problem — A unit of work with dependencies, sub-problems, and status tracking (open → in-progress → resolved → closed)
  • Proposal — A proposed solution with a source branch reference
Read from source at commit 437eeaaba9a8OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add thoughtbox -- npx -y @kastalien-research/[email protected]
03

Exposed tools (164)

118 read · 42 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ARCHITECTreadStructural design specialist
DEBUGGERreadRoot cause analysis specialist
M10-testreadTesting per-session isolation
MANAGERreadDelegation and team coordination specialist
RESEARCHERreadParallel hypothesis investigation specialist
REVIEWERreadCode and proposal review specialist
SECURITYreadRisk and vulnerability detection specialist
add_dependencywriteAdd a dependency between problems. The problem cannot be claimed until its dependency is resolved.
affectedreadTransitive dependents of a claim: claims reachable by reverse depends_on edges. Cycle-safe and depth-capped (default 10, max 20); each result carries its edge distance.
arch-reviewreadArchitecture review workspace
assertwriteCreate a new typed claim in a hub workspace with status asserted. Returns the claim with its generated id.
badread...
bind_final_validatorreadPin a notebook code cell as the predicate that gates terminalState=
blocked_problemsreadList problems that are blocked by unresolved dependencies.
branchreadToolhost for managing reasoning branches.
branch-managementwriteSpawn and merge reasoning branches
branch-retrievalreadList and inspect branches
branch_getreadRetrieve a specific branch with its metadata and all thoughts.
branch_listreadList all branches for a session with thought counts and status.
branch_mergewriteMerge branch results back into the main track.
branch_readreadRead thoughts from this branch, ordered by thought number.
branch_spawnwriteCreate a new reasoning branch from a main-track thought.
branch_statusreadGet the status of the current branch (thought count, context).
branch_thoughtreadRecord a thought on this branch. Thoughts are numbered sequentially within the branch.
caching-decisionreadRedis selected
cell-operationswriteAdd, update, list, and retrieve cells
changed_sincereadDigest query: claims whose status changed strictly after a timestamp, oldest transition first. For session-start recall and natural-boundary syncs (spec §11.1). Optionally narrowed to one hub workspace. Read-only.
checkpointwriteSubmit a diff for Cassandra adversarial audit. The audit result (approved/rejected) and optional feedback are recorded.
claim_diffreadClaim-level diff between two branches in a workspace: added, removed, shared, superseded claims and crossing contradicts edges (SPEC-MERGE-EVIDENCE diffBranchClaims; the same computation feeding merge-evidence notebooks). A claim belongs to a branch when an evidenceRef is
claim_problemreadClaim a problem to work on. Auto-generates a branch name if not provided. Sets status to in-progress.
clear_folderdestructiveWhether to clear the .interleaved-thinking folder after completion, keeping only final-answer.md (default: false)
collab-wsreadCollaboration workspace
collection-dsreadCollection
completereadEnd the Theseus session with a terminal state. Bridges a knowledge entry if a summary is provided.
create_problemwriteDefine a new problem to be solved within a workspace.
create_proposalwritePropose a solution to a problem. References a thought branch containing the work.
create_sub_problemwriteCreate a sub-problem under an existing parent problem. Sub-problems inherit workspace scope.
create_workspacewriteCreate a new collaboration workspace. The creating agent becomes the coordinator.
decisionread...
decision-1read...
decision-2read...
deletedestructiveRemove a stored variable. Returns { deleted: boolean } (false if the name was not set).
deployment-dsreadDeployment
endorse_consensusreadEndorse an existing consensus marker to show agreement.
entity-managementwriteCreate, read, and observe entities in the knowledge graph
evidence-enginewritePersist, run, inspect, cancel, and retrieve artifacts for Notebook Evidence Engine modes
executionwriteRun code cells and install dependencies
extract_claimsreadExtract atomic claims from a text artifact
getwriteRead back a value stored earlier in this MCP session via tb.vars.set. Throws a clear error naming the variable if it was never set (or the session restarted) — use tb.vars.list() to see what exists.
get_profile_promptreadGet the behavioral prompt for a specific profile role. Includes domain-specific mental models and guidelines.
get_sessionreadRead a reasoning session through the broker proxy
graph-structurewriteCreate relations and traverse the graph
healthreadCheck health of Thoughtbox infrastructure services (Thoughtbox server, Supabase OTEL store). Optionally filter to specific services.
initwriteStart a Theseus refactoring session with a declared file scope. All subsequent operations are scoped to these files until a visa expands the boundary.
inputreadYour task/question. May include
integration-testreadIntegration test workspace
interleaved-thinkingreadUse this Thoughtbox server as a reasoning workspace to alternate between internal reasoning steps and external tool/action invocation. Enables structured multi-phase execution with tooling inventory, sufficiency assessment, strategy development, and execution.
invalidatereadMark a claim invalidated. Append-history-style: the claim row is preserved (no hard delete). Idempotent on already-invalidated claims; rejected for superseded claims.
join_workspacereadJoin an existing workspace. Returns current workspace state including problems and proposals.
knowledge_add_observationwriteAdd an observation to an existing entity. Observations are timestamped notes that track how an entity evolves over time.
knowledge_create_entitywriteCreate a new entity in the knowledge graph. Entities represent insights, concepts, workflows, decisions, or agents.
knowledge_create_relationwriteCreate a directed relation between two entities. Relations form the edges of the knowledge graph.
knowledge_get_entityreadRetrieve full details of a specific entity by ID, including all properties and metadata.
knowledge_list_entitiesreadList entities with optional filtering by type, visibility, name pattern, or date range.
knowledge_query_graphreadTraverse the knowledge graph starting from an entity. Follows relations up to a specified depth, with optional filtering by relation type.
knowledge_statsreadGet aggregate statistics for the knowledge graph: entity counts by type, relation counts, and general health metrics.
linkwriteCreate a typed edge between two claims in the same workspace. depends_on edges feed the affected traversal. Idempotent per (from, to, kind).
listreadList the names (and serialised sizes in bytes) of all variables stored in this MCP session.
list_consensusreadList all consensus markers in a workspace with endorsement counts.
list_mcp_assetsreadOverview of all MCP capabilities, tools, resources, and quickstart guide
list_problemsreadList all problems in a workspace with their status and assignments.
list_proposalsreadList all proposals in a workspace with their review status.
list_workspacesreadList all available workspaces. Does not require registration.
mark_consensusreadRecord a consensus decision. Links to a thought reference for traceability.
merge_proposalwriteMerge an approved proposal. Requires at least one approval review.
neverreadnever
notebook-managementwriteCreate, list, load, and export notebooks
notebook_add_cellwriteAdd a cell to a notebook (title, markdown, or executable code)
notebook_cancel_runwriteCancel a running notebook evidence run.
notebook_createwriteCreate a new headless notebook for literate programming or Notebook Evidence Engine workflows with JavaScript/TypeScript support. See thoughtbox://notebook/capabilities for evidence modes and templates.
notebook_exportreadExport a notebook to .src.md format. Always returns the notebook content as a string. Optionally writes to a filesystem path if provided. - STDIO mode: Provide
notebook_fitnessreadRead the fitness ledger for a runbook template (SPEC-AGX-SUBSTRATE §7).
notebook_get_artifactreadRetrieve a Notebook Evidence Engine artifact by artifactId.
notebook_get_cellreadGet complete details of a specific cell including content and execution results
notebook_get_runwriteRetrieve a run record, including its typed status, outputs, and artifact references.
notebook_install_depswriteInstall pnpm dependencies defined in the notebook
notebook_instantiatereadReconstruct a live notebook from a persisted, versioned runbook template and
notebook_listreadList all active notebooks with their metadata
notebook_list_cellsreadList all cells in a notebook with their metadata
notebook_list_runsreadList notebook evidence runs, optionally filtered by notebookId.
notebook_loadreadLoad a notebook from .src.md format. Accepts exactly one source: -
notebook_persistreadPersist the current notebook document. Always stores an in-process artifact for replay/export; with a durable backend configured (FileSystem locally, Supabase deployed) the document also persists durably — upsert by notebookId, latest wins — and the response
notebook_run_cellwriteExecute a code cell and capture output (stdout, stderr, exit code).
notebook_start_runwriteExecute a notebook
notebook_update_cellwriteUpdate the content of an existing cell
notebook_validatewriteRun a code cell as a deterministic predicate over JSON-serialisable observed data. The cell receives the observed value as a JSON file pointed to by process.env.TB_OBSERVED_PATH and must write its verdict to process.env.TB_VERDICT_PATH as {
outcomereadRecord whether tests passed or failed after a modification. Tracks the B (brittleness) counter.
parallel-verificationwriteExecute parallel hypothesis exploration using Thoughtbox. Pass your task/question - optional max_branches param can be included or will default to 3.
persistentread...
planwriteRecord a primary action step with a pre-committed recovery step. Each move must be paired with a notebook code cell that will deterministically decide that move
post_messagewritePost a message to a problem
post_system_messagewritePost a system message to a problem
probereadIssue a single outbound broker proxy call
queryreadList claims in a workspace filtered by type, status, creating agent, and/or statement substring.
quick_joinreadRegister and join a workspace in a single call. Combines register + join_workspace for efficient onboarding.
read_channelreadRead messages from a problem
ready_problemsreadList problems that are ready to claim (no unresolved dependencies, status is open).
reflectreadForm a falsifiable hypothesis when the state step tracker reaches S=2 (both primary and backup moves failed). Must include explicit disproof criteria. Required before the protocol allows further action steps. Failed moves are forbidden; generate new primary + backup.
registerreadRegister as an agent in the hub. Required before any other hub operation. Returns a unique agentId.
remove_dependencydestructiveRemove a dependency between problems.
researchreadResearch workspace
reviewread...
review-wsreadReview workspace
review_proposalreadReview a proposal with approve/request-changes/reject verdict.
runbook_add_await_cellwriteAuthor an await cell (SPEC-AGX-SUBSTRATE B6): a claim subscription plus a
runbook_advancereadPull-based advancement of a durable runbook instance (tb.runbook.advance —
runbook_statusreadRead-only snapshot of a durable runbook instance: derived status
sessionreadToolhost for managing Thoughtbox reasoning sessions. List, search, retrieve, resume, export, and analyze sessions.
session-analysisreadAnalyze session structure and quality metrics
session-analysis-guidereadProcess guide for qualitative analysis of reasoning sessions. Teaches how to identify key moments and record learnings to the knowledge graph.
session-managementreadResume and export sessions
session-retrievalreadList, search, and retrieve session details
session_analyzereadAnalyze the structure and quality metrics of a reasoning session. Returns objective metrics (linearity, revision rate, branch depth, convergence) - qualitative analysis is done client-side using the session-analysis-guide resource.
session_exportreadExport a session to markdown format, optionally using cipher notation for compression. Useful for injecting session context into hooks or sharing reasoning chains.
session_getreadRetrieve full details of a specific reasoning session, including all thoughts, branches, and metadata.
session_inforeadRetrieve detailed information about a specific reasoning session including thought count, duration, and metadata.
session_listreadList previous reasoning sessions for the current user. Returns session metadata including title, tags, thought count, and timestamps.
session_query_thoughtsreadStructured queries over a session
session_resumereadLoad a previous session into the active ThoughtHandler, allowing continuation of reasoning from where it left off. After resuming, subsequent thoughtbox calls will append to this session.
session_resume_latestreadResume the most recently updated session in the current workspace without knowing its ID. Convenience wrapper around session_list + session_resume; optionally filter by tags. Returns the same payload as session_resume, or { success: false } when the workspace has no sessions.
session_searchreadSearch for reasoning sessions by title or tags using a keyword query.
session_timelinereadRetrieve the chronological timeline of OTEL events (tool calls, API requests, errors) for a Claude Code session. Events are ordered by timestamp.
sessionsreadList reasoning sessions with optional filtering by status (active, idle, or all) and a result limit.
sleep_foreverreadSleeps past every budget to exercise timeout enforcement
statuswriteFetch a merge commit by id: status, evidence notebook id + hash, verdict, attribution, and decision timestamps. Read-only.
subscribereadRegister a subscriber (agent or runbook cell ref) on a claim. Defaults to the acting agent. Idempotent per (claim, subscriber).
supersedereadReplace a claim with a new one: asserts the replacement and marks the old claim superseded with a superseded_by pointer. The old claim is preserved.
supportreadAttach evidence to a claim and mark it supported. Rejected for invalidated or superseded claims.
taskreadThe task to complete using interleaved thinking approach
testread...
test-wsread...
thoughtbox-interleaved-guidesreadIRCoT-style interleaved reasoning guides centered on Thoughtbox as the canonical reasoning workspace. Mode parameter: research, analysis, or development.
thoughtbox_core_outcomesreadCausal-lift core outcomes: end-user tasks where only the final result matters
thoughtbox_executewriteRun JavaScript using the \
thoughtbox_negative_controlsreadCausal-lift negative controls: simple, direct tasks where Thoughtbox should stay out
thoughtbox_notebookwriteNotebook toolhost for literate programming with JavaScript/TypeScript. Create, manage, and execute interactive notebooks with markdown documentation and executable code cells.
thoughtbox_searchreadDiscover Thoughtbox operations, prompts, resources, and public tool surfaces by querying this catalog with JavaScript.
thoughtbox_sessionreadToolhost for managing Thoughtbox reasoning sessions. List, search, retrieve, resume, export, and analyze sessions.
thoughtbox_theseusreadTheseus Protocol: friction-gated refactoring for autonomous agents. Prevents scope drift via boundary locking, test-write locks, epistemic visas, and adversarial auditing (Cassandra). Operations: - init: Start a refactoring session with declared file scope (args: { scope: [
thoughtbox_thoughtwriteAdvanced reasoning tracking tool. Submit thoughts, track state changes, audit decisions, and build branches or revisions.
thoughts_limitreadMaximum number of thoughts to use (default: 100)
unsubscribedestructiveRemove a subscriber from a claim. No-op when the subscription does not exist.
update_problemwriteUpdate problem status or resolution. Status transitions: open → in-progress → resolved → closed.
v1-decisionreadAgreed on Redis
visareadRequest an epistemic visa to touch an out-of-scope file. Requires justification and acknowledgment of the scope-creep anti-pattern.
whoamireadGet current agent identity, role, and workspace memberships.
workspace_digestreadGet a comprehensive digest of workspace state: agents, problems, proposals, and consensus.
workspace_statusreadGet current status of a workspace including agent activity and problem summary.
wsreadtest
ws-1read...
ws-2read...
ws-areadA
ws-breadB
xreadx
04

Trust audit

BLOCKgrade F · trust 30/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (10 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/utils/validate-handoff.mjs:18
await exec(`git merge-base --is-ancestor ${sha} HEAD`, { cwd: ROOT });
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.agents/skills/supabase/SKILL.md:14
- **Local DB URL**: `postgresql://postgres:[email protected]:54322/postgres`
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.claude/skills/supabase/SKILL.md:14
- **Local DB URL**: `postgresql://postgres:[email protected]:54322/postgres`
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
apps/web/.roo/skills/writing-clearly-and-concisely/signs-of-ai-writing.md:165
> Operating in the current Afghan media environment presents numerous challenges, including[...] Despite these challenges, Amu TV has managed to continue to provide a vital service to the Afghan popul
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/web/src/lib/repo/timeline.ts
timeline.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/http/drift-http.ts
drift-http.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/merge-evidence/claim-diff.ts
claim-diff.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
apps/web/.augment/skills/nextjs-supabase-auth
apps/web/.augment/skills/nextjs-supabase-auth
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
apps/web/.augment/skills/vercel-react-best-practices
apps/web/.augment/skills/vercel-react-best-practices
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
apps/web/.claude/skills/nextjs-supabase-auth
apps/web/.claude/skills/nextjs-supabase-auth
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
apps/web/.claude/skills/vercel-react-best-practices
apps/web/.claude/skills/vercel-react-best-practices
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
apps/web/.roo/skills/nextjs-supabase-auth
apps/web/.roo/skills/nextjs-supabase-auth
Why it matters. link not followed
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/eval-run.ts:299
`Δcost=$${costDelta?.toFixed(4) ?? "?"} Δlatency=${(latencyDeltaMs / 1000).toFixed(1)}s ` +
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/eval-run.ts:300
`Δtokens=${tokenDelta ?? "?"} vs scratchpad baseline`,
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
apps/web/.roo/skills/coolify-compose/examples/multi-service/before.yml:14
- DATABASE_URL=postgres://plausible:password123@plausible-db:5432/plausible
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/__tests__/supabase-test-helpers.ts:29
'postgresql://postgres:[email protected]:54322/postgres';
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_folder, delete, remove_dependency, unsubscribe
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gcloudignore
.gcloudignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/web/.eslintignore
.eslintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
infra/gcp/.terraform.lock.hcl
.terraform.lock.hcl
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/web/src/app/(auth)/sign-up/claim/ClaimPanel.tsx:5
import { resendWelcomeEmailAction } from '../../actions'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/web/src/app/api/merge/[id]/approve/route.ts:30
} from "../../merge-db";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/changelog-parse.ts:98
entry = `${entry} ([${shortHash}](../../commit/${commit.hash}))`;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/audit/__tests__/manifest-generator.test.ts:7
import type { ThoughtData } from '../../persistence/types.js';

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 437eeaaba9a8full audit observations/trust-audit/mcp-server/kastalien-research__thoughtbox.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07437eeaaba9a8BLOCKF30first audit
06

Questions

What is the Thoughtbox MCP server?

Thoughtbox is an intention ledger for agents. Evaluate AI's decisions against its decision-making.

What tools does Thoughtbox expose?

164 in total: 118 read-only, 42 that write, and 4 that can delete or overwrite (clear_folder, delete, remove_dependency, unsubscribe). Every one is listed on this page with its risk.

Is Thoughtbox safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (30/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Thoughtbox need?

It reads ANTHROPIC_API_KEY, LANGSMITH_API_KEY, NEXT_PUBLIC_SUPABASE_ANON_KEY, OAUTH_JWT_SECRET, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, SUPABASE_ACCESS_TOKEN, SUPABASE_SERVICE_ROLE_KEY, SUPABASE_TEST_ANON_KEY, SUPABASE_TEST_JWT_SECRET, SUPABASE_TEST_SERVICE_ROLE_KEY and TB_BRANCH_SIGNING_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Thoughtbox run?

It speaks streamable-http and stdio, so it runs as a local process your client starts. It is published on npm as thoughtbox-claude-code at 0.1.8.

How current is this page?

The grade is for one exact copy of the source (437eeaaba9a8), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement