Skip to content

Add Game Development Studio - #562

Merged
kantorcodes merged 3 commits into
hashgraph-online:mainfrom
theisegoria:add-game-development-studio
Oct 3, 2026
Merged

kantorcodes merged 3 commits into
hashgraph-online:mainfrom
theisegoria:add-game-development-studio

Conversation

@theisegoria

Copy link
Copy Markdown
Contributor

Adds Game Development Studio to Community Plugins → Development & Workflow, alphabetically between ga4-gsc-clarity-mcp-server and Gangsta Agents. It provides a local CLI, agent skills, and an MCP server for game asset production, vendoring, visual debugging, and performance analysis.

Submitted in response to the invitation in theisegoria/game-development-studio#3.

Verification:

  • Confirmed the public repository and published, non-prerelease v1.1.0 release, and checked the description against its current README.
  • Existing project CI and Windows CLI installation checks passed; these were inspected, not rerun for this Markdown-only change.
  • Searched the catalog and existing issues/PRs for duplicate listings/submissions; none found.
  • Verified one README insertion, the required entry format, alphabetical placement, and git diff --check.

The directory's centralized source scan and maintainer review remain pending. No generated compatibility exports were edited.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

@theisegoria, the required source scan must pass before merge.

The centralized source scan returned: failure. A passing scan (score at least 80 with no critical or high findings) is required before merge. Review the rule-level findings and rerun the scan.

Scanner CI in the source repository is optional. The centralized scan must pass; review its findings and rerun the contribution check.

Push the correction and this comment will update on the next check. Contribution requirements. Latest sweep.

@theisegoria

Copy link
Copy Markdown
Contributor Author

Thanks for running the centralized check. We reviewed the v3.0.123 scan failure and opened draft Action-pinning fixes:

These are pending review and not landed. They pin existing Action refs to commits resolved from the official upstream repositories, preserve tests, and add an immutable-ref check.

For the reported 12 high findings, static review found 12 candidate files containing synthetic test inputs: mocked provider keys, redaction fixtures, and a database fixture identifier. Examples at the inspected v1.1.0 source revision:

The original job logs show counts/category results but no individual locations or checkout SHA; no findings artifact was retained. This is a candidate mapping, not a claim that we recovered the original rule-level results or validated every possible secret path.

The interface warning also appears to reflect a contract mismatch: the skills-only verifier explicitly prohibits screenshots in the plugin; marketing images stay at repository scope. The nested distribution/skills-repo marketplace is an unbuilt export template: its local plugin directory is populated by scripts/build-skills-repository.mjs in the exported repository.

Could you provide the exact rule IDs/file locations and advise on precise scanner handling of these test fixtures, the skills-only screenshot contract, and the unbuilt template? We have not removed tests, added suppressions, or requested repeated scans. The submission remains pending the required checks and maintainer review.

kantorcodes commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Correction: the latest centralized scan scored 85/100 (0 critical, 12 high, 0 medium, 2 low, 2 informational), which meets the catalog threshold; at scores of 80 or higher, advisory high findings and a nonzero scanner exit do not block listing, and source-owned scanner CI is optional. The source hardening changes and detailed scan evidence are reported merged, so no further scanner remediation is required for this listing. The PR remains a draft and is currently not mergeable against main; once it is marked ready and its branch is current, rerun the required catalog checks and request review, and I can resolve a conflict if that is the only remaining blocker.

@theisegoria

Copy link
Copy Markdown
Contributor Author

Following the request for detailed findings: source hardening PR #7 and exported-skills PR #4 are now merged. Both passed exact-head CI, and the v1.3.1 release changes were preserved.

The complete detailed JSON from a new actual scan, rather than the earlier aggregate reconstruction, is included below. Source: 3a9cd3f08f970ded8db71d31e71ac665f313f9cd. Scanner: official plugin-scanner==3.0.123, matching action caba2e96aa8ad2feb6cf6fca52442b52e22e779f. Wheel SHA-256 d176d4d35c980e4e66c9e72bd79d0a100efbf40bea9d5f4dae35c8609eb7d04d; hash and PyPI provenance against hashgraph-online/hol-guard verified before installation, with the action's hash-locked dependencies.

Outcome: 85/100; 0 critical, 12 high, 0 medium, 2 low, 2 informational. The high-severity gate still fails. The JSON's policy/verify booleans do not override the Action's FAIL_ON=high exit condition.

Run configuration: isolated tracked-file snapshot, MODE=scan, default profile, JSON output outside the snapshot, TRUST_REPOSITORY_POLICY=false, ONLINE=false, minimum 80, fail on high, no uploads/submissions/comments. Local host was macOS/Python 3.11 (central runner uses Linux/Python 3.12); Cisco extras were not installed, matching the directory action. Cisco skill scanning reports unavailable. This run does not establish the old centralized runner's unrecorded checkout SHA.

Two independent static reviews traced the actual reported locations. Each high finding below is HARDCODED_SECRET; the review disposition is non-actionable fixture/identifier, not a live credential leak. No credential validation or provider calls were made. Values are intentionally omitted. The scanner reports the first retained match per file, so these dispositions cover the reported locations, not every literal in each file.

Actual reported location Static evidence
apps/macos/Anvil/Tests/AnvilKitTests/GameDevCLIClientTests.swift:54 Temporary local echo fixture; asserts diagnostic redaction.
apps/macos/Anvil/Tests/AnvilKitTests/StreamingTests.swift:249 Local runtime fixture; asserts streamed output redaction.
apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/GameDevCLIClientTests.swift:54 Temporary local echo fixture; asserts diagnostic redaction.
apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/ModelTests.swift:100 In-memory invocation-description redaction test.
tests/asset-packages.test.ts:37 Synthetic provenance; asserts persisted token redaction.
tests/audio.test.ts:50 Dummy provider credential with mocked fetch.
tests/codebase-memory-artifact.test.ts:52 Database project/path identifier, not authentication material.
tests/durable-jobs.test.ts:25 Synthetic persisted request; asserts redaction.
tests/http-and-status.test.ts:354 In-memory redaction fixture; asserts masked output.
tests/leonardo-image.test.ts:52 Dummy provider credential with mocked fetch.
tests/provider-contracts.test.ts:27 Dummy provider credential with mocked fetch.
tests/refutation-fixes.test.ts:410 Constructor rejects HTTP before a request can occur.

The four other findings are documented separately:

  • DEPENDABOT_MISSING: accurate observation at repository root.
  • DEPENDABOT_MISSING: separate observation under distribution/skills-repo; its scope is visible in the categories, although the flat finding path is the same.
  • CODEXIGNORE_MISSING: accurate hygiene observation; existing closed release rosters still govern shipped contents.
  • PLUGIN_JSON_INTERFACE_ASSET_SCREENSHOTS: contract mismatch. The skills-only verifier explicitly prohibits the screenshot field/assets in the plugin; marketing images are repository-scoped. The nested marketplace is an unbuilt export template, populated by the export script, not an installed plugin tree.

Tests are unchanged. No scanner thresholds, suppressions, or exclusions were added. Could you review these per-finding dispositions and advise on precise fixture/semantic handling that still catches real credentials in tests? We will synchronize this PR once to request the supported centralized rescan against the merged source, then report its actual result. The listing stays draft pending a passing centralized gate and maintainer review.

The JSON below retains all scanner fields and findings. Only the workstation-specific absolute snapshot prefix was replaced with . for privacy. Original report SHA-256: ac2026db92d905aca2feeb7c45194cec285a59fbe2a5b8342be3a30bc9406274. Published normalized JSON SHA-256: 24219927b5cb5ceafb6a0daafb5152c5591a9a0997999cc0f89be68ed2bafa82.

Complete detailed scanner JSON (privacy-normalized paths)
{
  "schema_version": "scan-result.v1",
  "tool_version": "3.0.123",
  "profile": "default",
  "policy_pass": true,
  "verify_pass": true,
  "scope": "repository",
  "score": 85,
  "raw_score": 85,
  "effective_score": 85,
  "grade": "B",
  "ecosystems": [
    "codex"
  ],
  "packages": [
    {
      "ecosystem": "codex",
      "packageKind": "single-plugin",
      "rootPath": ".",
      "manifestPath": "./.codex-plugin/plugin.json",
      "name": "game-development-studio",
      "version": "1.3.1"
    },
    {
      "ecosystem": "codex",
      "packageKind": "marketplace",
      "rootPath": "./distribution/skills-repo",
      "manifestPath": "./distribution/skills-repo/.agents/plugins/marketplace.json",
      "name": "game-development-studio-skills",
      "version": null
    }
  ],
  "summary": {
    "gradeLabel": "Good",
    "findings": {
      "critical": 0,
      "high": 12,
      "medium": 0,
      "low": 2,
      "info": 2
    },
    "integrations": [
      {
        "name": "codex:source-3a9cd3f / cisco-skill-scanner",
        "status": "unavailable",
        "message": "Cisco skill scanner not installed or resolves to an unsafe path; deep skill scan skipped.",
        "findingsCount": 0,
        "metadata": {
          "policy": "balanced"
        }
      },
      {
        "name": "codex:source-3a9cd3f / cisco-mcp-scanner",
        "status": "skipped",
        "message": "No .mcp.json found.",
        "findingsCount": 0,
        "metadata": {}
      }
    ]
  },
  "trust": {
    "total": 0.0,
    "execution": {
      "includeExternal": false,
      "computedAt": "2026-10-02T22:31:31.839853+00:00"
    },
    "domains": []
  },
  "categories": [
    {
      "name": "[codex:.] Manifest Validation",
      "score": 28,
      "max": 31,
      "checks": [
        {
          "name": "plugin.json exists",
          "passed": true,
          "points": 4,
          "maxPoints": 4,
          "message": "plugin.json found",
          "findings": []
        },
        {
          "name": "Valid JSON",
          "passed": true,
          "points": 4,
          "maxPoints": 4,
          "message": "plugin.json is valid JSON",
          "findings": []
        },
        {
          "name": "Required fields present",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "All required fields (name, version, description) are present.",
          "findings": []
        },
        {
          "name": "Version follows semver",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "Version \"1.3.1\" follows semver.",
          "findings": []
        },
        {
          "name": "Name is kebab-case",
          "passed": true,
          "points": 2,
          "maxPoints": 2,
          "message": "Name \"game-development-studio\" is kebab-case.",
          "findings": []
        },
        {
          "name": "Recommended metadata present",
          "passed": true,
          "points": 4,
          "maxPoints": 4,
          "message": "Recommended plugin metadata is present.",
          "findings": []
        },
        {
          "name": "Interface metadata complete if declared",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "Interface metadata contains the expected publishable fields.",
          "findings": []
        },
        {
          "name": "Interface links and assets valid if declared",
          "passed": false,
          "points": 0,
          "maxPoints": 3,
          "message": "Interface links or assets are invalid: screenshots",
          "findings": [
            {
              "ruleId": "PLUGIN_JSON_INTERFACE_ASSET_SCREENSHOTS",
              "severity": "info",
              "title": "Interface asset or URL \"screenshots\" is invalid",
              "description": "The interface field \"screenshots\" must use HTTPS or point to a safe in-repo asset.",
              "remediation": "Update \"screenshots\" to use HTTPS or an existing relative asset path.",
              "filePath": ".codex-plugin/plugin.json",
              "lineNumber": null,
              "source": "native"
            }
          ]
        },
        {
          "name": "Declared paths are safe",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "Declared manifest paths stay within the plugin directory.",
          "findings": []
        }
      ]
    },
    {
      "name": "[codex:.] Security",
      "score": 9,
      "max": 16,
      "checks": [
        {
          "name": "SECURITY.md found",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "SECURITY.md found",
          "findings": []
        },
        {
          "name": "LICENSE found",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "LICENSE found (MIT)",
          "findings": []
        },
        {
          "name": "No hardcoded secrets",
          "passed": false,
          "points": 0,
          "maxPoints": 7,
          "message": "Hardcoded secrets found in: apps/macos/Anvil/Tests/AnvilKitTests/GameDevCLIClientTests.swift, apps/macos/Anvil/Tests/AnvilKitTests/StreamingTests.swift, apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/GameDevCLIClientTests.swift, apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/ModelTests.swift, tests/asset-packages.test.ts and 7 more",
          "findings": [
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in apps/macos/Anvil/Tests/AnvilKitTests/GameDevCLIClientTests.swift.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "apps/macos/Anvil/Tests/AnvilKitTests/GameDevCLIClientTests.swift",
              "lineNumber": 54,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in apps/macos/Anvil/Tests/AnvilKitTests/StreamingTests.swift.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "apps/macos/Anvil/Tests/AnvilKitTests/StreamingTests.swift",
              "lineNumber": 249,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/GameDevCLIClientTests.swift.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/GameDevCLIClientTests.swift",
              "lineNumber": 54,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/ModelTests.swift.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/ModelTests.swift",
              "lineNumber": 100,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/asset-packages.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/asset-packages.test.ts",
              "lineNumber": 37,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/audio.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/audio.test.ts",
              "lineNumber": 50,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/codebase-memory-artifact.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/codebase-memory-artifact.test.ts",
              "lineNumber": 52,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/durable-jobs.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/durable-jobs.test.ts",
              "lineNumber": 25,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/http-and-status.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/http-and-status.test.ts",
              "lineNumber": 354,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/leonardo-image.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/leonardo-image.test.ts",
              "lineNumber": 52,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/provider-contracts.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/provider-contracts.test.ts",
              "lineNumber": 27,
              "source": "native"
            },
            {
              "ruleId": "HARDCODED_SECRET",
              "severity": "high",
              "title": "Hardcoded secret detected",
              "description": "Potential secret material was detected in tests/refutation-fixes.test.ts.",
              "remediation": "Remove the secret from source control and load it securely at runtime.",
              "filePath": "tests/refutation-fixes.test.ts",
              "lineNumber": 410,
              "source": "native"
            }
          ]
        },
        {
          "name": "No dangerous MCP commands",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No .mcp.json found, skipping check",
          "findings": []
        },
        {
          "name": "MCP remote transports are hardened",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No .mcp.json found, skipping transport hardening checks.",
          "findings": []
        },
        {
          "name": "No approval bypass defaults",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "No risky approval or sandbox defaults detected.",
          "findings": []
        },
        {
          "name": "Cisco MCP scan completed",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No .mcp.json found.",
          "findings": []
        },
        {
          "name": "No elevated Cisco MCP findings",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No .mcp.json found.",
          "findings": []
        },
        {
          "name": "MCP sources analyzable",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No .mcp.json found.",
          "findings": []
        }
      ]
    },
    {
      "name": "[codex:.] Operational Security",
      "score": 17,
      "max": 20,
      "checks": [
        {
          "name": "Third-party GitHub Actions pinned to SHAs",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "All third-party GitHub Actions and reusable workflows are pinned to immutable SHAs.",
          "findings": []
        },
        {
          "name": "No write-all GitHub Actions permissions",
          "passed": true,
          "points": 4,
          "maxPoints": 4,
          "message": "No GitHub Actions workflow requests write-all permissions.",
          "findings": []
        },
        {
          "name": "No privileged untrusted checkout patterns",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "No privileged workflow checks out untrusted branch content.",
          "findings": []
        },
        {
          "name": "Dependabot configured for automation surfaces",
          "passed": false,
          "points": 0,
          "maxPoints": 3,
          "message": "Dependabot is not configured for workflows or dependency manifests.",
          "findings": [
            {
              "ruleId": "DEPENDABOT_MISSING",
              "severity": "low",
              "title": "Dependabot configuration is missing",
              "description": "Automation or dependency surfaces exist, but .github/dependabot.yml is missing.",
              "remediation": "Add Dependabot updates for GitHub Actions and dependency manifests.",
              "filePath": ".github/dependabot.yml",
              "lineNumber": null,
              "source": "native"
            }
          ]
        },
        {
          "name": "Dependency manifests have lockfiles",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "Detected dependency manifests are paired with lockfiles or pinned requirements.",
          "findings": []
        }
      ]
    },
    {
      "name": "[codex:.] Best Practices",
      "score": 12,
      "max": 15,
      "checks": [
        {
          "name": "README.md found",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "README.md found",
          "findings": []
        },
        {
          "name": "Skills directory exists if declared",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "Skills directory \"./skills/\" exists",
          "findings": []
        },
        {
          "name": "SKILL.md frontmatter",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "All SKILL.md files have valid frontmatter",
          "findings": []
        },
        {
          "name": "No .env files committed",
          "passed": true,
          "points": 3,
          "maxPoints": 3,
          "message": "No .env files found",
          "findings": []
        },
        {
          "name": ".codexignore found",
          "passed": false,
          "points": 0,
          "maxPoints": 3,
          "message": ".codexignore not found",
          "findings": [
            {
              "ruleId": "CODEXIGNORE_MISSING",
              "severity": "info",
              "title": ".codexignore is missing",
              "description": "A .codexignore file helps prevent accidental inclusion of local artifacts and secrets.",
              "remediation": "Add a .codexignore file with generated assets, local state, and secret paths.",
              "filePath": ".codexignore",
              "lineNumber": null,
              "source": "native"
            }
          ]
        }
      ]
    },
    {
      "name": "[codex:.] Marketplace",
      "score": 0,
      "max": 0,
      "checks": [
        {
          "name": "marketplace.json valid",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No marketplace.json found, check not applicable",
          "findings": []
        },
        {
          "name": "Policy fields present",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No marketplace.json found, check not applicable",
          "findings": []
        },
        {
          "name": "Marketplace sources are safe",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No marketplace.json found, check not applicable",
          "findings": []
        }
      ]
    },
    {
      "name": "[codex:.] Skill Security",
      "score": 5,
      "max": 5,
      "checks": [
        {
          "name": "Cisco skill scan completed",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "Cisco skill scanner not installed or resolves to an unsafe path; deep skill scan skipped.",
          "findings": []
        },
        {
          "name": "No elevated Cisco skill findings",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "Cisco scan not executed; elevated findings check not applicable.",
          "findings": []
        },
        {
          "name": "Skills analyzable",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "Cisco scan not executed; analyzability not applicable.",
          "findings": []
        },
        {
          "name": "No risky local skill instructions",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "No risky local skill instructions detected.",
          "findings": []
        }
      ]
    },
    {
      "name": "[codex:.] Code Quality",
      "score": 10,
      "max": 10,
      "checks": [
        {
          "name": "No eval or Function constructor",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "No eval() or new Function() usage detected",
          "findings": []
        },
        {
          "name": "No shell injection patterns",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "No shell injection patterns detected",
          "findings": []
        }
      ]
    },
    {
      "name": "[codex:distribution/skills-repo] Repository Marketplace",
      "score": 15,
      "max": 15,
      "checks": [
        {
          "name": "marketplace.json valid",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "marketplace.json is valid",
          "findings": []
        },
        {
          "name": "Policy fields present",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "All plugins have required policy fields",
          "findings": []
        },
        {
          "name": "Marketplace sources are safe",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "Marketplace sources are relative-safe local paths.",
          "findings": []
        }
      ]
    },
    {
      "name": "[codex:distribution/skills-repo] Repository Operational Security",
      "score": 14,
      "max": 17,
      "checks": [
        {
          "name": "Third-party GitHub Actions pinned to SHAs",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "All third-party GitHub Actions and reusable workflows are pinned to immutable SHAs.",
          "findings": []
        },
        {
          "name": "No write-all GitHub Actions permissions",
          "passed": true,
          "points": 4,
          "maxPoints": 4,
          "message": "No GitHub Actions workflow requests write-all permissions.",
          "findings": []
        },
        {
          "name": "No privileged untrusted checkout patterns",
          "passed": true,
          "points": 5,
          "maxPoints": 5,
          "message": "No privileged workflow checks out untrusted branch content.",
          "findings": []
        },
        {
          "name": "Dependabot configured for automation surfaces",
          "passed": false,
          "points": 0,
          "maxPoints": 3,
          "message": "Dependabot is not configured for workflows or dependency manifests.",
          "findings": [
            {
              "ruleId": "DEPENDABOT_MISSING",
              "severity": "low",
              "title": "Dependabot configuration is missing",
              "description": "Automation or dependency surfaces exist, but .github/dependabot.yml is missing.",
              "remediation": "Add Dependabot updates for GitHub Actions and dependency manifests.",
              "filePath": ".github/dependabot.yml",
              "lineNumber": null,
              "source": "native"
            }
          ]
        },
        {
          "name": "Dependency manifests have lockfiles",
          "passed": true,
          "points": 0,
          "maxPoints": 0,
          "message": "No dependency manifests found.",
          "findings": []
        }
      ]
    }
  ],
  "findings": [
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in apps/macos/Anvil/Tests/AnvilKitTests/GameDevCLIClientTests.swift.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "apps/macos/Anvil/Tests/AnvilKitTests/GameDevCLIClientTests.swift",
      "lineNumber": 54,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in apps/macos/Anvil/Tests/AnvilKitTests/StreamingTests.swift.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "apps/macos/Anvil/Tests/AnvilKitTests/StreamingTests.swift",
      "lineNumber": 249,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/GameDevCLIClientTests.swift.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/GameDevCLIClientTests.swift",
      "lineNumber": 54,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/ModelTests.swift.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "apps/macos/GameDevelopmentStudio/Tests/GameDevelopmentStudioTests/ModelTests.swift",
      "lineNumber": 100,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/asset-packages.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/asset-packages.test.ts",
      "lineNumber": 37,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/audio.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/audio.test.ts",
      "lineNumber": 50,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/codebase-memory-artifact.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/codebase-memory-artifact.test.ts",
      "lineNumber": 52,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/durable-jobs.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/durable-jobs.test.ts",
      "lineNumber": 25,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/http-and-status.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/http-and-status.test.ts",
      "lineNumber": 354,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/leonardo-image.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/leonardo-image.test.ts",
      "lineNumber": 52,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/provider-contracts.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/provider-contracts.test.ts",
      "lineNumber": 27,
      "source": "native"
    },
    {
      "ruleId": "HARDCODED_SECRET",
      "severity": "high",
      "category": "security",
      "title": "Hardcoded secret detected",
      "description": "Potential secret material was detected in tests/refutation-fixes.test.ts.",
      "remediation": "Remove the secret from source control and load it securely at runtime.",
      "filePath": "tests/refutation-fixes.test.ts",
      "lineNumber": 410,
      "source": "native"
    },
    {
      "ruleId": "DEPENDABOT_MISSING",
      "severity": "low",
      "category": "operational-security",
      "title": "Dependabot configuration is missing",
      "description": "Automation or dependency surfaces exist, but .github/dependabot.yml is missing.",
      "remediation": "Add Dependabot updates for GitHub Actions and dependency manifests.",
      "filePath": ".github/dependabot.yml",
      "lineNumber": null,
      "source": "native"
    },
    {
      "ruleId": "DEPENDABOT_MISSING",
      "severity": "low",
      "category": "operational-security",
      "title": "Dependabot configuration is missing",
      "description": "Automation or dependency surfaces exist, but .github/dependabot.yml is missing.",
      "remediation": "Add Dependabot updates for GitHub Actions and dependency manifests.",
      "filePath": ".github/dependabot.yml",
      "lineNumber": null,
      "source": "native"
    },
    {
      "ruleId": "PLUGIN_JSON_INTERFACE_ASSET_SCREENSHOTS",
      "severity": "info",
      "category": "manifest-validation",
      "title": "Interface asset or URL \"screenshots\" is invalid",
      "description": "The interface field \"screenshots\" must use HTTPS or point to a safe in-repo asset.",
      "remediation": "Update \"screenshots\" to use HTTPS or an existing relative asset path.",
      "filePath": ".codex-plugin/plugin.json",
      "lineNumber": null,
      "source": "native"
    },
    {
      "ruleId": "CODEXIGNORE_MISSING",
      "severity": "info",
      "category": "best-practices",
      "title": ".codexignore is missing",
      "description": "A .codexignore file helps prevent accidental inclusion of local artifacts and secrets.",
      "remediation": "Add a .codexignore file with generated assets, local state, and secret paths.",
      "filePath": ".codexignore",
      "lineNumber": null,
      "source": "native"
    }
  ],
  "timestamp": "2026-10-02T22:31:31.839873+00:00",
  "pluginDir": ".",
  "repository": {
    "marketplaceFile": "./distribution/skills-repo/.agents/plugins/marketplace.json",
    "localPluginCount": 1
  },
  "plugins": [
    {
      "name": "game-development-studio",
      "pluginDir": ".",
      "score": 84,
      "grade": "B",
      "trust": {
        "total": 60.46,
        "execution": {
          "includeExternal": false,
          "computedAt": "2026-10-02T22:31:31.837025+00:00"
        },
        "domains": [
          {
            "domain": "plugin",
            "label": "Codex Plugin Trust",
            "score": 83.06,
            "spec": {
              "id": "HOL-HCS-CODEX-PLUGIN-TRUST-DRAFT",
              "version": "0.1.0",
              "path": "docs/trust/plugin-trust-draft.md",
              "derivedFrom": [
                "HCS-26",
                "HCS-28"
              ]
            },
            "profile": {
              "id": "hol-codex-plugin-trust/baseline",
              "version": "0.1"
            },
            "adapters": [
              {
                "id": "verification.manifest-integrity",
                "label": "Manifest Integrity",
                "weight": 0.35,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Manifest integrity blends existence, JSON validity, required fields, and semver checks.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "verification.interface-integrity",
                "label": "Interface Integrity",
                "weight": 0.25,
                "contributionMode": "conditional",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 60.0,
                "components": [
                  {
                    "key": "score",
                    "score": 60.0,
                    "rationale": "Interface integrity applies when the plugin declares an install surface.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "verification.path-safety",
                "label": "Path Safety",
                "weight": 0.2,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Path safety uses the scanner's declared-path safety check.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "verification.marketplace-alignment",
                "label": "Marketplace Alignment",
                "weight": 0.2,
                "contributionMode": "conditional",
                "applicable": false,
                "emitted": false,
                "includedInDenominator": false,
                "score": 0.0,
                "components": []
              },
              {
                "id": "security.disclosure",
                "label": "Disclosure",
                "weight": 0.15,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Disclosure is one explicit signal, not a proxy for the entire security posture.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "security.license",
                "label": "License",
                "weight": 0.1,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "License clarity remains a separate scored signal.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "security.secret-hygiene",
                "label": "Secret Hygiene",
                "weight": 0.35,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 0.0,
                "components": [
                  {
                    "key": "score",
                    "score": 0.0,
                    "rationale": "Secret hygiene uses the scanner's hardcoded-secret detection.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "security.mcp-safety",
                "label": "MCP Safety",
                "weight": 0.2,
                "contributionMode": "conditional",
                "applicable": false,
                "emitted": false,
                "includedInDenominator": false,
                "score": 0.0,
                "components": []
              },
              {
                "id": "security.approval-hygiene",
                "label": "Approval Hygiene",
                "weight": 0.2,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Approval hygiene checks for bypass-style defaults.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.documentation",
                "label": "Documentation",
                "weight": 0.15,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Documentation reflects README coverage for operators and maintainers.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.manifest-metadata",
                "label": "Manifest Metadata",
                "weight": 0.2625,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Manifest metadata tracks the scanner's recommended-metadata check.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.discoverability",
                "label": "Discoverability",
                "weight": 0.15,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Discoverability uses category plus keyword coverage.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.provenance",
                "label": "Provenance",
                "weight": 0.1875,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Provenance reflects author, homepage, and repository metadata coverage.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "operations.action-pinning",
                "label": "Action Pinning",
                "weight": 0.2625,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Action pinning uses the scanner's immutable-action check.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "operations.permission-scope",
                "label": "Permission Scope",
                "weight": 0.15,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Permission scope uses the least-privilege workflow check.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "operations.untrusted-checkout",
                "label": "Untrusted Checkout",
                "weight": 0.1875,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Untrusted-checkout protection uses the scanner's privileged-workflow check.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "operations.update-automation",
                "label": "Update Automation",
                "weight": 0.15,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 50.0,
                "components": [
                  {
                    "key": "score",
                    "score": 50.0,
                    "rationale": "Update automation combines Dependabot coverage and lockfile hygiene.",
                    "evidence": []
                  }
                ]
              }
            ]
          },
          {
            "domain": "skills",
            "label": "Skill Trust",
            "score": 37.86,
            "spec": {
              "id": "HCS-28",
              "version": "0.1",
              "path": "docs/trust/skill-trust-local.md",
              "derivedFrom": [
                "HCS-26",
                "HCS-28"
              ]
            },
            "profile": {
              "id": "hcs-28/baseline",
              "version": "0.1"
            },
            "adapters": [
              {
                "id": "verification.review-status",
                "label": "Review Status",
                "weight": 0.5,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": false,
                "includedInDenominator": true,
                "score": 0.0,
                "components": [
                  {
                    "key": "score",
                    "score": 0.0,
                    "rationale": "No explicit version-scoped verification record is present locally, so the HCS-28 review-status adapter remains 0.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "verification.publisher-bound",
                "label": "Publisher Bound",
                "weight": 0.2,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Local bundled-skill normalization maps publisher binding to the declared plugin author metadata.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "verification.repo-commit-integrity",
                "label": "Repo Commit Integrity",
                "weight": 0.4,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": false,
                "includedInDenominator": true,
                "score": 0.0,
                "components": [
                  {
                    "key": "score",
                    "score": 0.0,
                    "rationale": "Repo-commit integrity requires both a repository URL and a commit reference in local bundled-skill metadata.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "verification.manifest-integrity",
                "label": "Manifest Integrity",
                "weight": 0.3,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Every bundled SKILL.md parsed successfully and includes the required frontmatter fields.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "verification.domain-proof",
                "label": "Domain Proof",
                "weight": 0.1,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "Homepage and repository hosts align, satisfying the local domain-proof mapping.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.links",
                "label": "Metadata Links",
                "weight": 0.3,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "HCS-28 metadata.links awards 100 for homepage+repo, 60 for either one, and 0 otherwise.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.description",
                "label": "Metadata Description",
                "weight": 0.25,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 100.0,
                "components": [
                  {
                    "key": "score",
                    "score": 100.0,
                    "rationale": "HCS-28 metadata.description uses the published description-length thresholds.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.taxonomy",
                "label": "Metadata Taxonomy",
                "weight": 0.2,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 0.0,
                "components": [
                  {
                    "key": "score",
                    "score": 0.0,
                    "rationale": "HCS-28 metadata.taxonomy follows the published tag-count and language-count matrix.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "metadata.provenance",
                "label": "Metadata Provenance",
                "weight": 0.25,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": true,
                "includedInDenominator": true,
                "score": 70.0,
                "components": [
                  {
                    "key": "score",
                    "score": 70.0,
                    "rationale": "HCS-28 metadata.provenance awards 100 for repo+commit, 70 for repo only, and 40 for commit only.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "upvotes",
                "label": "Upvotes",
                "weight": 1.0,
                "contributionMode": "conditional",
                "applicable": true,
                "emitted": false,
                "includedInDenominator": false,
                "score": 0.0,
                "components": [
                  {
                    "key": "score",
                    "score": 0.0,
                    "rationale": "The HCS-28 upvotes adapter is conditional and only contributes when a local upvote count is available.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "safety.cisco-scan",
                "label": "Cisco Safety Scan",
                "weight": 1.0,
                "contributionMode": "universal",
                "applicable": true,
                "emitted": false,
                "includedInDenominator": true,
                "score": 0.0,
                "components": [
                  {
                    "key": "score",
                    "score": 0.0,
                    "rationale": "Cisco skill scanner not installed or resolves to an unsafe path; deep skill scan skipped.",
                    "evidence": []
                  }
                ]
              },
              {
                "id": "repository.health",
                "label": "Repository Health",
                "weight": 1.0,
                "contributionMode": "conditional",
                "applicable": true,
                "emitted": false,
                "includedInDenominator": false,
                "score": 0.0,
                "components": [
                  {
                    "key": "score",
                    "score": 0.0,
                    "rationale": "Repository health is conditional in HCS-28 and is omitted in local read mode unless a persisted external score exists.",
                    "evidence": []
                  }
                ]
              }
            ]
          }
        ]
      },
      "summary": {
        "findings": {
          "critical": 0,
          "high": 12,
          "medium": 0,
          "low": 1,
          "info": 2
        },
        "integrations": [
          {
            "name": "cisco-skill-scanner",
            "status": "unavailable",
            "message": "Cisco skill scanner not installed or resolves to an unsafe path; deep skill scan skipped.",
            "findingsCount": 0,
            "metadata": {
              "policy": "balanced"
            }
          },
          {
            "name": "cisco-mcp-scanner",
            "status": "skipped",
            "message": "No .mcp.json found.",
            "findingsCount": 0,
            "metadata": {}
          }
        ]
      }
    }
  ],
  "skippedTargets": [
    {
      "name": "game-development-studio",
      "reason": "local plugin manifest not found",
      "sourcePath": "./plugins/game-development-studio"
    }
  ]
}

@theisegoria

Copy link
Copy Markdown
Contributor Author

The single requested centralized rescan has completed: run 37073433730.

Result: 85/100; 0 critical, 12 high, 0 medium, 2 low, 2 informational. The README contribution check passed. The source gate still fails because of the high findings; the Action-pinning findings are cleared.

Please re-review the complete detailed JSON and per-finding evidence. Two static reviews classify the actual twelve reported locations as test fixtures or a non-authentication identifier, with immutable source links and scope limitations documented. We are requesting precise scanner handling or an evidence-based disposition, not a lowered threshold or blanket test exclusion.

The listing remains draft as requested. Tests, scanner thresholds, and genuine security checks are unchanged; no further rescan has been requested.

@theisegoria
theisegoria marked this pull request as ready for review October 3, 2026 01:36
@theisegoria

Copy link
Copy Markdown
Contributor Author

@kantorcodes PR #562 is now ready for review and mergeable, updated to current catalog main at head 4efe3d85548bd736c112042ab5092cfe899f0646. The diff remains exactly the one Game Development Studio README entry, with its placement and link verified.

Following your corrected guidance, the required checks were refreshed. The latest completed run passed catalog validation and returned 85/100 (0 critical, 12 high, 0 medium, 2 low, 2 informational).

There is still a mismatch between the stated admission policy and automation: .github/workflows/sweep-open-prs.yml passes fail_on_severity: high, then the gate rejects the scan job's nonzero result. Consequently, the check remains failed even though your comment says advisory high findings at scores ≥80 do not block listing. We have not changed that policy, weakened checks, or requested another identical scan.

The formal reviewer-assignment endpoint returned HTTP 404, including the one authorized retry; our account has no write/triage permission on this repository. Please review this ready submission and reconcile the catalog gate with the intended policy through the repository's supported process. The detailed report and per-finding evidence are available for that review.

No merge has been performed on this repository.

Copy link
Copy Markdown
Member

Confirmed on head 4efe3d85548bd736c112042ab5092cfe899f0646: the centralized scan scored 85/100, which clears the catalog's ≥80 scanner policy; the scan job exits nonzero only because this workflow sets fail_on_severity: high, and the open-contribution gate propagates that exit despite the qualifying score (run). Please update the gate to enforce the score threshold rather than advisory finding severity, then rerun it; the three PR-target workflows are also action_required and need maintainer authorization before merge. Source-repository scanner CI is not required.

@kantorcodes
kantorcodes merged commit ed82bb8 into hashgraph-online:main Oct 3, 2026
4 of 9 checks passed
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

🎉 Congrats @theisegoria, your plugin has been merged and is now listed in the HOL Registry!

Claim your plugin

As the author, you can verify ownership to unlock:

  • Owner-verified badge on your plugin's registry listing
  • Trust score visibility and install analytics for your plugin
  • Dashboard access at hol.org/guard/plugins to track installs, trust, and engagement

How to claim

Open your link and choose "Continue with GitHub", using the GitHub account that maintains the repository. HOL requests only read:user and user:email — it does not request write access to your repositories.

The whole process takes under 30 seconds, and your listing gets the ✅ owner-verified badge.

If you have any questions, feel free to ask here or reach out at support@hol.org.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants