{"_id":"@agentlair/agent-report","_rev":"2-d95d837c1f9edfafc6b5366b45b5896e","name":"@agentlair/agent-report","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@agentlair/agent-report","version":"0.1.0","keywords":["agent","ai","audit","trust","security","cli","behavioral-analysis"],"author":{"name":"AgentLair","email":"hello@agentlair.dev"},"license":"MIT","_id":"@agentlair/agent-report@0.1.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://github.com/piiiico/agent-report#readme","bugs":{"url":"https://github.com/piiiico/agent-report/issues"},"bin":{"agent-report":"bin/agent-report.js"},"dist":{"shasum":"de906e10ea20c12908ff2e6669345cc189507c63","tarball":"https://registry.npmjs.org/@agentlair/agent-report/-/agent-report-0.1.0.tgz","fileCount":5,"integrity":"sha512-YdQhQEdE8LyL0wpm02U99b7+wpDTP18JmtNdzPWGcujf14i+G33VzMb7ToaF+jwUh+dGYpYi8Juh9zY38a/wYA==","signatures":[{"sig":"MEUCIQCHCkWIfaKUNoVkggudwpDmdpJAPyAKZ/TrcRVdlvd6xwIgNB8nRFugvpIApVY8pqAzbAG9WyFWDSI/5N14SGWGA5o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":54392},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"744ce6a8250c721ed417a477b83c2da1c1ff6301","scripts":{"dev":"bun run src/cli.ts","build":"bun build ./src/index.ts --outdir ./dist --target node && bun build ./src/cli.ts --outfile ./bin/agent-report.js --target node","typecheck":"tsc --noEmit"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agent-report.git","type":"git"},"_npmVersion":"10.9.7","description":"Behavioral audit for agent workspaces. Makes 'feels trustworthy' into a number.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.7.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-report_0.1.0_1775979537793_0.5159451800156536","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentlair/agent-report","version":"0.2.0","description":"Behavioral audit for agent workspaces. Makes 'feels trustworthy' into a number.","type":"module","bin":{"agent-report":"bin/agent-report.js"},"main":"./dist/index.js","types":"./dist/index.d.ts","scripts":{"build":"bun build ./src/index.ts --outdir ./dist --target node && bun build ./src/cli.ts --outfile ./bin/agent-report.js --target node","test":"bun test","test:ci":"bun test --bail","dev":"bun run src/cli.ts","typecheck":"tsc --noEmit"},"keywords":["agent","ai","audit","trust","security","cli","behavioral-analysis"],"author":{"name":"AgentLair","email":"hello@agentlair.dev"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/piiiico/agent-report.git"},"devDependencies":{"@types/bun":"latest","typescript":"^5.7.0"},"_id":"@agentlair/agent-report@0.2.0","gitHead":"e2fc50c1d3419f204c69f6fc63487c5a2a177b02","bugs":{"url":"https://github.com/piiiico/agent-report/issues"},"homepage":"https://github.com/piiiico/agent-report#readme","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-cVi0FWoDtt6XqDzIi1NEVwwBq5hm3OiQNM0h5quKb+Bd5socwceNpsch5rcEyekTNTfZ3dj4dKZvIlrTDRqaqQ==","shasum":"3ced37fe72b1c55e221ac5eb40311e9f8f4172e8","tarball":"https://registry.npmjs.org/@agentlair/agent-report/-/agent-report-0.2.0.tgz","fileCount":5,"unpackedSize":61002,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCD3e80S1W9XoX5Xs4wTsYWkXg5syMS1BeCzU760nKRjAIhAIRN71Vw/RhdnjpWUC9lo+SJO+RAHAeDU3+OjunRXYpm"}]},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"directories":{},"maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-report_0.2.0_1775989375012_0.33628293685513966"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-12T07:38:57.740Z","modified":"2026-04-12T10:22:55.316Z","0.1.0":"2026-04-12T07:38:57.925Z","0.2.0":"2026-04-12T10:22:55.186Z"},"bugs":{"url":"https://github.com/piiiico/agent-report/issues"},"author":{"name":"AgentLair","email":"hello@agentlair.dev"},"license":"MIT","homepage":"https://github.com/piiiico/agent-report#readme","keywords":["agent","ai","audit","trust","security","cli","behavioral-analysis"],"repository":{"type":"git","url":"git+https://github.com/piiiico/agent-report.git"},"description":"Behavioral audit for agent workspaces. Makes 'feels trustworthy' into a number.","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"readme":"# agent-report\n\nBehavioral audit for agent workspaces. Makes \"feels trustworthy\" into a number.\n\n```\nnpx @agentlair/agent-report\n```\n\nZero config. Just run it in any git repository.\n\n## What it does\n\nScans your repo and produces a **trust score (0-100)** based on:\n\n- **Git author analysis** — detects agent vs human commits (Claude, Copilot, Devin, Dependabot, etc.)\n- **Churn hotspots** — files agents keep modifying = instability signals\n- **Test coverage** — are agent-written files tested?\n- **Dependency risk** — known vulnerable packages, typosquatting detection\n- **Trust score** — weighted composite of all signals\n\n## Usage\n\n```bash\n# Scan current directory\nnpx @agentlair/agent-report\n\n# Scan a specific directory\nnpx @agentlair/agent-report ./my-project\n\n# Output as JSON\nnpx @agentlair/agent-report --json\n\n# Limit commit history\nnpx @agentlair/agent-report --max-commits 1000\n```\n\n## Example output\n\nRunning on **vercel/ai** (44% of recent commits from release bots):\n\n```\n  ╔══════════════════════════════════════╗\n  ║         agent-report v0.1.0         ║\n  ╚══════════════════════════════════════╝\n\n  Directory: ./vercel-ai\n  Scanned:   2026-04-12\n\n  TRUST SCORE   ⚠ 66\n\n\n── Score Breakdown ───────────────────────────────────\n\n  Git Hygiene      ██████████████████░░  90\n  Churn Stability  ██████████░░░░░░░░░░  50\n  Test Coverage    ██████░░░░░░░░░░░░░░  30\n  Dependency Risk  ████████████████████  100\n\n── Git Summary ───────────────────────────────────────\n\n  Total commits:  50\n  Agent commits:  22 (44%)\n  Human commits:  28\n\n  Authors:\n    🤖 agent  vercel-ai-sdk[bot]  22 commits (95% confidence)\n    👤 human  Aayush Kapoor       10 commits\n    👤 human  Felix Arntz          6 commits\n    👤 human  Walter Korman        4 commits\n    ...\n\n── Churn Hotspots ────────────────────────────────────\n\n  Files agents keep modifying — potential instability signals\n\n  ⚡ .changeset/pre.json              19 changes, 100% agent\n  ⚡ pnpm-lock.yaml                   19 changes,  95% agent\n  ⚡ examples/ai-e2e-next/package.json 18 changes, 100% agent\n  ...\n\n── Test Coverage ─────────────────────────────────────\n\n  Test files in repo:     498\n  Agent-written files:      1\n  With matching tests:      0\n  Without tests:            1\n\n  Untested agent-written files:\n    ✗ packages/gateway/src/gateway-language-model-settings.ts\n```\n\nRunning on **cline/cline** (0% agent commits, 14 contributors):\n\n```\n  TRUST SCORE   ✓ 90\n\n  Git Hygiene      ████████████████████  100\n  Churn Stability  ████████████████████  100\n  Test Coverage    ████████████████░░░░   80\n  Dependency Risk  ████████████████░░░░   81\n\n  Total commits:  50  |  Agent: 0 (0%)  |  Human: 50\n```\n\nRunning on **anthropic-sdk-python** (74% auto-generated by stainless-app bot):\n\n```\n  TRUST SCORE   ⚠ 65\n\n  Git Hygiene      ██████████████░░░░░░  70\n  Churn Stability  ███████████████░░░░░  75\n  Test Coverage    ██████░░░░░░░░░░░░░░  30\n  Dependency Risk  ████████████████████  100\n\n  Agent commits:  37/50 (74%)\n  🤖 stainless-app[bot]  37 commits (95% confidence)\n\n  Churn hotspots: .stats.yml, CHANGELOG.md, _version.py (all 100% agent)\n  250 agent-written files with 0 directly matched tests\n```\n\n## Programmatic API\n\n```typescript\nimport { scan, renderTerminal } from \"@agentlair/agent-report\";\n\nconst report = await scan({ dir: \"./my-repo\" });\nconsole.log(report.trustScore); // 0-100\nconsole.log(renderTerminal(report)); // Pretty terminal output\n```\n\n## Score breakdown\n\n| Component | Weight | What it measures |\n|-----------|--------|-----------------|\n| Git Hygiene | 30% | Agent ratio, commit quality, author diversity |\n| Churn Stability | 20% | Files agents keep churning = instability |\n| Test Coverage | 30% | Agent-written code with matching tests |\n| Dependency Health | 20% | Known risky deps, typosquatting, dep count |\n\n## Agent detection\n\nDetects agents by:\n- Email patterns (`noreply@anthropic.com`, `[bot]@users.noreply.github.com`, etc.)\n- Name patterns (`Claude`, `Copilot`, `Devin`, `[bot]` suffix, etc.)\n- Co-author tags (`Co-Authored-By: Claude`)\n- GitHub bot conventions\n\n## Why this exists\n\n> \"I've never opened any of these CLI scripts it's written\"\n\nMost developers using AI agents never review what the agents produce. This tool makes the invisible visible — a behavioral audit you can run before merging, deploying, or trusting agent-written code.\n\nThis is the open-source entry point to [AgentLair](https://agentlair.dev) — trust infrastructure for the agentic economy.\n\n## From snapshot to continuous monitoring\n\n`agent-report` gives you a point-in-time audit. [AgentLair](https://agentlair.dev) provides continuous behavioral trust scoring across your entire agent fleet — identity, governance, and cross-organization trust data.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}