{"_id":"express-recon","_rev":"31-cddbbfafd50c9b10e379470c99e4a50d","name":"express-recon","dist-tags":{"latest":"0.21.1"},"versions":{"0.1.0":{"name":"express-recon","version":"0.1.0","keywords":["express","security","audit","routes","middleware","authentication","authorization","static-analysis","sast","mcp"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.1.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"6c24b726f8d8efdc2249178ae15a0cdf1ab83423","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.1.0.tgz","fileCount":24,"integrity":"sha512-PH2Y2U1kzQNjdCLKSYkJGFtUbk9aTlKnAkuCkGYNyekHbWdJxtko6qPBhG8ZYAk921FWJoKGzkntDBK5fN/aDA==","signatures":[{"sig":"MEYCIQDgplHYGyxHrV7MLu3mgw5go7K5L7/UkDKnQUR3mFPs1AIhAPjNKLOS4faCu16/n69G2sCL/Ohcsu3pLMkEN4ISYY4x","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":75693},"main":"src/index.js","engines":{"node":">=18"},"gitHead":"199f0ae782b4ea0bf8b3643a9b17301e5c2ce6cb","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test testcases/"},"_npmUser":{"name":"naveenyagati","email":"naveenyagati@protonmail.com"},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.16.0","description":"Inventory & audit harness for Express 4/5 route surfaces — for humans, CI, and AI agents. Statically or at runtime enumerate routes, middleware chains, and flag unauthenticated endpoints.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"zod":"4.4.3","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.1.0_1781034706037_0.7232059079314905","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"express-recon","version":"0.1.1","keywords":["express","security","audit","routes","middleware","authentication","authorization","static-analysis","sast","mcp"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.1.1","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"3e5178c741b2f6f4ad4d3c3a4c47316ab165432e","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.1.1.tgz","fileCount":24,"integrity":"sha512-komWti3RggsjhxqqqF8HpoiKWtAgXmt7nu6NfOoHehns/lQbYfK2yARj1eUWfJdY9akE2B7Xxy/NADFypglTsA==","signatures":[{"sig":"MEYCIQCmiP78feeNrSUQED+JkUKtPYvBLFukId8fWSyRhTJgCgIhAIDVbebgqBlXCzmiJyPO05ooXB48Zf0sph3+CwIXpZbZ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":76351},"main":"src/index.js","engines":{"node":">=18"},"gitHead":"a9102a4859485f96a12bde4c6bf811486ec58139","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.16.0","description":"Inventory & audit harness for Express 4/5 route surfaces — for humans, CI, and AI agents. Statically or at runtime enumerate routes, middleware chains, and flag unauthenticated endpoints.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"zod":"4.4.3","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.1.1_1781075730737_0.30312991123811206","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"express-recon","version":"0.2.0","keywords":["express","security","audit","routes","middleware","authentication","authorization","static-analysis","sast","mcp"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.2.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"99d43ba8523b2aee55820c87f6eed3e034c8c0ff","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.2.0.tgz","fileCount":24,"integrity":"sha512-tqPnLlPfnoL0xRrlgLPoLUZGCVbbWkDh5nIU4OUkzvLQPPjgBlxl8z6mXYro41qcODcQ6TAWLSkEVHxd5MzEkw==","signatures":[{"sig":"MEUCIQDlGd7/6k6UicP6gg70V0YNwmkiEMU6z6a/HoqsKXXiUwIgbJvDGVnEX8BRRflB2z3QLwWLxYHMLBjtVfOGFZWo9k8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":87237},"main":"src/index.js","engines":{"node":">=18"},"gitHead":"5fa8ee28b647448fabbec54fff7bfdbeb7b028a5","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","check:version":"node scripts/check-version.js","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.16.0","description":"Inventory & audit harness for Express 4/5 route surfaces — for humans, CI, and AI agents. Statically or at runtime enumerate routes, middleware chains, and flag unauthenticated endpoints.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"zod":"4.4.3","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.2.0_1781089647377_0.2781991115285012","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"express-recon","version":"0.3.0","keywords":["express","security","audit","routes","middleware","authentication","authorization","static-analysis","sast","mcp"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.3.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"6547591a7490b65918610cb5902eef22c81e9b45","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.3.0.tgz","fileCount":25,"integrity":"sha512-rpOlKrKUkgAIkhVAM5hYm0aheYFEs7OrwtHCh0MeTu3IHJNRs9NkQS+wm/Xt3ctCwMbZXRe9P1ESAafltG4tog==","signatures":[{"sig":"MEQCIB5aFaM3Sw6wKj0+2Hag+nMDB/DXGJdJ3l3ggiQHn7sUAiAUhAIHW8lN64b/5Vsvk5GCvkp25DfWxD1N3evSuS1kDw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":134592},"main":"src/index.js","engines":{"node":">=18"},"gitHead":"560ca90d32e8a3a03ef02b31be78fd19cdc842e5","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","check:version":"node scripts/check-version.js","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"12.0.1","description":"Inventory & audit harness for Express 4/5 route surfaces — for humans, CI, and AI agents. Statically or at runtime enumerate routes, middleware chains, and flag unauthenticated endpoints.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"4.4.3","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.3.0_1783952157581_0.6901574163000077","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"express-recon","version":"0.4.0","keywords":["express","security","audit","routes","middleware","authentication","authorization","static-analysis","sast","mcp"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.4.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"da5d098b325a8d061f1c1b7e1febf3fcbc39a1a7","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.4.0.tgz","fileCount":28,"integrity":"sha512-2uPFyDJA1G4ABZr/qyEDnktVRLoFZrK8hMfGSgs8GBe0qUEGBu7ih7yD/ir1DfChX1xnORju+ynyNAnwLWBgHg==","signatures":[{"sig":"MEQCIHFmRm9icLCVl3H9/4AK6tT6ibt775J6ia7rHzk+TSyrAiBeAiE0w8rZHltK61vxDKXcIvtssdUne01Vp9q7GXGAuw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":175453},"main":"src/index.js","engines":{"node":">=18"},"gitHead":"aa32682e59dabccb00cd42bbdbc3177753d5afdb","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","check:version":"node scripts/check-version.js","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"12.0.1","description":"Inventory & audit harness for Express 4/5 route surfaces — for humans, CI, and AI agents. Statically or at runtime enumerate routes, middleware chains, and flag unauthenticated endpoints.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"4.4.3","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.4.0_1784115432860_0.43866792371826047","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"express-recon","version":"0.5.0","keywords":["express","security","audit","routes","middleware","authentication","authorization","static-analysis","sast","mcp"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.5.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"526247e83bcb11063e7ecb1cc08e08fdb1394285","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.5.0.tgz","fileCount":35,"integrity":"sha512-hh71fzKjteh1VBdKDMk88YLC2a2Wdf65zRLWg8ePrcLPWRpIgJkbYoPDDg3JTQRWtNMTUbS+Yyr/uQKKdtEtPg==","signatures":[{"sig":"MEYCIQCRj1lZJ07MZpyCIQhaAA7adNYhONljFKMv1jvI4zgb7wIhANQeXic5Rswyx0rajVa8e8nfvcAuX/8SI275EkeHbNBJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":278091},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"c5817ba8be6526395c4313edf2b30dd174f9f45d","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","check:version":"node scripts/check-version.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Inventory & audit harness for Express 4/5 route surfaces — for humans, CI, and AI agents. Statically or at runtime enumerate routes, middleware chains, and flag unauthenticated endpoints.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.5.0_1784801709659_0.7202310305242057","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"express-recon","version":"0.6.0","keywords":["audit","authentication","authorization","express","github","mcp","middleware","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.6.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"f29caf02e274543029c411023995b0d1c36ee19e","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.6.0.tgz","fileCount":41,"integrity":"sha512-6bi1DrehP2YwrSzvNQfZk8uzP+/ochJ24B8YVp4qVzutV+5v7RhaQxKldHiQ4L9bbQ4jcjgaX7mgQ07/SJm77g==","signatures":[{"sig":"MEQCIENCEVZEIRptQQ1xsJwzh+0ky3CF8ixAtAcjwBSmNOdRAiBikqxzBqdRm7RIM1Vaw+F/Gxa2vgqcQooP7I1Y3AFqCQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":452468},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"9e22cde4b67efbde9d8079ed15519a3a63354f88","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express 4/5 route and GitHub organization inventory, configuration-relative auth audit, OpenAPI reconciliation, and middleware review.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.6.0_1788013661589_0.14189708057073913","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"express-recon","version":"0.7.0","keywords":["audit","authentication","authorization","express","github","mcp","middleware","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.7.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"3c048ed894bc27043551a06efb026a44edbb5fa1","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.7.0.tgz","fileCount":43,"integrity":"sha512-c/iObRAAZAMSwHEOM/i/Yh+kTdM7/NFseovZ4VH7wBvcI29RTOQ5/BVHZy0q+8q1kIViLWAU0EdLWOpmSCO3Jw==","signatures":[{"sig":"MEUCIQCKeAMXasbZCV89NnNXGNIhM7Qvt9D6NgZohLV1wONYOQIgOWK7T+LYFxjKm7TyMr0m4EYDQCY2sUzoupF9K+1kcKI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":493562},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"2d1784c45d3a5b7be92dfc3b303a8bba395fd7b7","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express 4/5 route and GitHub organization inventory, configuration-relative auth audit, OpenAPI reconciliation, and middleware review.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.7.0_1788017227998_0.5401690165612585","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"express-recon","version":"0.7.1","keywords":["audit","authentication","authorization","express","github","mcp","middleware","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.7.1","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"11a435826e0dd37f45141bc08f523c216008ec34","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.7.1.tgz","fileCount":43,"integrity":"sha512-Jo47cgkCAbq9eWUysgJOKFYDy1I1tF9hbBSwvXMlKRB6hJSQHErCsy16gEg+xcQriP4pwIANydfw02bz4ktdwQ==","signatures":[{"sig":"MEQCIGYUjT3h0q95a51GHRJflKJsqZ8Wol2B1pu4o2Asjm9EAiBt4jaN4W4oTQAh+AoU44PiXVBcyAAsKA93mZCyJqEzPw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":493570},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"44cfc1764148b799e05da886f3c3019edfd867ce","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express 4/5 route and GitHub organization inventory, configuration-relative auth audit, OpenAPI reconciliation, and middleware review.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.7.1_1788017611815_0.1323275678616811","host":"s3://npm-registry-packages-npm-production"}},"0.7.2":{"name":"express-recon","version":"0.7.2","keywords":["audit","authentication","authorization","express","github","mcp","middleware","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.7.2","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"d690b88681326d1f8de3d44f527a9e154e19d13d","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.7.2.tgz","fileCount":43,"integrity":"sha512-GBpJvZdw84Z19JUN9aGl5lBYeqHfER5T1ZqlOlFAK6f8ZlvAZ1md3f+pPimeUFvBoI0Ir4Gt/rDWwnqm70Qhxg==","signatures":[{"sig":"MEUCICGk7v/2anlkdrk+kCVuDLD+eM0pOatKj4jJNHbnDpATAiEA2hWcPjYTbNx3lRmZOxy6Bn0u1zf8LVwxEeW9LUOYshU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.7.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":494258},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"45fffbfd7b50898ac9948603821f31615d3b323c","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express 4/5 route and GitHub organization inventory, configuration-relative auth audit, OpenAPI reconciliation, and middleware review.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.7.2_1788021521007_0.5340783595738978","host":"s3://npm-registry-packages-npm-production"}},"0.7.3":{"name":"express-recon","version":"0.7.3","keywords":["audit","authentication","authorization","express","github","mcp","middleware","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.7.3","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"4690030a67a6c522e944077818aafe46e3dbfc23","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.7.3.tgz","fileCount":43,"integrity":"sha512-eJmb3E8GmESNaCG8QZh2bV6wsbiGSkaQNv30hTh9Kkyj/9YKnHwzYNNOcqeHsngaSMKCS4qvNqw10eOOQNMlOA==","signatures":[{"sig":"MEYCIQC2Aaizj2vcqWpgtgBqvpgejYdMwsB+6brHqY15+UBmeQIhAIrrNDnwzElWvuodkDQiRKTZ5FKrMNvvbsujs7Zf496Z","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.7.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":496503},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"fc86f4a0e232c7cf37bb3d74af1ef743f4c04b46","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express 4/5 route and GitHub organization inventory, configuration-relative auth audit, OpenAPI reconciliation, and middleware review.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.7.3_1788028954701_0.5791587884740201","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"express-recon","version":"0.8.0","keywords":["audit","authentication","authorization","express","github","mcp","middleware","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.8.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"33c3c4f02f6b63d8874157c38c2e8da007b89cf2","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.8.0.tgz","fileCount":44,"integrity":"sha512-q8oojzvFBO7GcOw+y5p1Uyh1ejuffSQTRFtl1jiIk7+scJB4U5EnNNif6JH4JtVxalqzPrU3zgFKY8nluBbyiw==","signatures":[{"sig":"MEUCIFI+fXwTqHIln1IheDE9q0LDEGf+dv9KViT0dRSD3gkGAiEAlQQEn6e5/rASfDsGrieVy2zOckgVWFYPqcOvHVTqvTQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":556305},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"e876ca4d7eed08590f88b1cc80a1078204821d8c","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express 4/5 route and GitHub organization inventory, configuration-relative auth audit, OpenAPI reconciliation, and middleware review.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.8.0_1788213862885_0.7320050832507174","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"express-recon","version":"0.9.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.9.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"eb932f4f585c549ad0938c6ec6502013b79c5440","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.9.0.tgz","fileCount":49,"integrity":"sha512-xRY6ETz27Zjjs4iNXynyjvx/H4ZwAMvS/N+vouVya0a3iH6g78+RGGbpL3JQre6Zj030U5VattH5rIRi0a5ZvA==","signatures":[{"sig":"MEYCIQCCJxGvFhAHEB80hzrW1uvrYYLWdZ2ghTwKaK05a75KHwIhAOL7O0Hmv0PMtxlMpOMOjaOFyidTS0rMi3Vmsv6okDrk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":734730},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"71871b3e0453e1d833a88251550455bb036c2800","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","swagger-ui-dist":"5.32.14","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.9.0_1788273587026_0.28624781036853597","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"express-recon","version":"0.10.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.10.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"daa2396e4d584f0bf26655d827a6f368a7ecef3d","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.10.0.tgz","fileCount":49,"integrity":"sha512-rdQ8ZphYD3f/z9VEtLeHv/zzSoVf3swhi81JHd2w5IGFTxsER2Bh6Oi0/Tw+O998p86o6v0WDqQVzxvgKA7ihQ==","signatures":[{"sig":"MEUCIECFaa8OU45KK13/IaZY5wu8yOCdl2hbTPS/0wqmak/rAiEAhirLtn55uK9wYh08Ox9zUdk+1YMWSw8JxL0hdYNoIPE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":761470},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"426d41dbfee7cdbe634fe9ea957cd649ff3fb9c5","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","swagger-ui-dist":"5.32.14","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.10.0_1788279836252_0.14177505868405205","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"express-recon","version":"0.11.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.11.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"c6c4910fc8acea86dd73027654b8675685c38e8f","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.11.0.tgz","fileCount":52,"integrity":"sha512-DY4RSvZVq5ZQ6DiGeLyJg0uoCl7CDQ+bNsn5E9RnntFHoNShbaFtfgbv8O0qSfyPnXNt02mtD8cJ/tA7Mb8q3g==","signatures":[{"sig":"MEUCIDtV97jYKQDs010mh6ZgltE0Nd+4o9ayE8qigM/L4SKtAiEAyB/WMdwIyO0sLLiCXVR90k/QcwmK60B0TctfXXiAyUg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":832446},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"4bd1404b58cba144fd75109389079dc80e09e5b9","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","swagger-ui-dist":"5.32.14","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.11.0_1788283212122_0.3092849906729167","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"express-recon","version":"0.12.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.12.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"13fd1f0b26ac763479e61a59d766a1e65b3a025b","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.12.0.tgz","fileCount":53,"integrity":"sha512-vUyNWXU+2HCvdkw9kAklekq7Ai7W3/rsXSIed/q1NKF7N1+jxTKnovazYxNecREsF/+McWaddOM/thC5BwaZyg==","signatures":[{"sig":"MEUCICmFl1URlPfL+R6sMEn4q0yLZ4GCmxomtw6o0h2oPYX9AiEA6fPDEoPTr/5gZcvDVmGtO2N+b3+j5ijxHq27hgGOM8Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":872364},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"e54d2763661cece16ab61b7e93aaeeac596cf656","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check src testcases","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","swagger-ui-dist":"5.32.14","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","ajv-formats":"^3.0.1","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.12.0_1788347183921_0.023271161807754126","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"express-recon","version":"0.13.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.13.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"05276e3a26b321ff771d9ba4b0db795cc04e97ed","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.13.0.tgz","fileCount":57,"integrity":"sha512-tFQCfTmhJ+QUCThQywV76hmQXs/4FnhWKGw815o46wuejWF3+PtujRq3EwCAj5O5v9oyxYK2cQiRt13hjjn9jw==","signatures":[{"sig":"MEUCIQC/bYx1keS9HYK2hIuA5jve3FncFMowu4DoRTbKz+nxyAIgZlBxvIFRaWqB8caizQAbWVcKq09Qt08RXPZXR3ZGJLw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1021987},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"de63a27826bdc579a35da78ddea4eb254c1fbe6c","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.13.0_1788375963681_0.6599401374441416","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"express-recon","version":"0.14.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.14.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"e2a74ce08670629e5e7c36bcd8252ef0aeddd8ed","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.14.0.tgz","fileCount":57,"integrity":"sha512-v5bDqb+GSHpsckOUiIyDmZyFRCjFcMXcOfRSru0PdcH3/YHzB4r9hor0PhhnqVP+1Z7mmEbtqAfm5KPE7CAulQ==","signatures":[{"sig":"MEUCIQDACxbFf2kxDgUxDznD2M40q/ohFQbj7tT7ob4Q65rGRAIgKUYiujsJPWNPj31IMfve9QdFwkNOvG5Luy8Vfm1bTRU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.14.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1056167},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"b6a990fd5ceab30c1281095110f12a8cdb682c89","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.14.0_1788513488154_0.09705781050104045","host":"s3://npm-registry-packages-npm-production"}},"0.15.0":{"name":"express-recon","version":"0.15.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.15.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"a6d95a03def8cbec909a74f4602809898f2482a0","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.15.0.tgz","fileCount":65,"integrity":"sha512-wexx18c8vTmqhO6NVbP6bTvU309JHILE6cgFWHbP9JIEDiClwn+vSX5KLy/COmCyfoPNUyU8RITz31gq6/qkHQ==","signatures":[{"sig":"MEUCIQCKS97Zc3+6Pm9OUHgSfsT6T0LgWGqLroQLMjrSUgaHjwIgIWtAWenUfaylwV1eZ8+spCUmPKgazUPqe43mxNtzW3w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.15.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1201205},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"5fac257430c501caeed0a34cea56809fa4eecc38","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.15.0_1788887606792_0.8705534546199134","host":"s3://npm-registry-packages-npm-production"}},"0.16.0":{"name":"express-recon","version":"0.16.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.16.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"28ff5619852456b9ca2e98cb85c96ec71d8a0963","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.16.0.tgz","fileCount":79,"integrity":"sha512-+1JGJk+jgF5SF1ulzDKOEoFcFYD7xGOEeXa/9ot6uHyxWagOw+tGhpOJtay4jiZaecP28/XIXDBJkNdtax/aXw==","signatures":[{"sig":"MEYCIQDLLbLGcDRjaCDyL0yAI8Hv1uPvFCob+YbN0DRwc1AWEAIhAIOXbhm1H/orsXBs6dVrhzSAfNhu4fyRc0cyZTOFoQjM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.16.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1331844},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"e54d099fd554c0b1f661dc247c358c33bdd10139","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.16.0_1788895154625_0.7199878936804402","host":"s3://npm-registry-packages-npm-production"}},"0.17.0":{"name":"express-recon","version":"0.17.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.17.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"d08342feb3f96c97310901824a7b4f51c0c385f7","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.17.0.tgz","fileCount":89,"integrity":"sha512-3b015bneWvrHlzcMal2GfmWNS7uWSfPGftEJZaErv6wxVoQTsMkYt1/8qC/66gq6fkS9BFPUT9hNnJwsk36RDQ==","signatures":[{"sig":"MEYCIQDmSkD808hvaossGdy4XymqwV4aebrOwShnyQxx0eNtbQIhALrmIM2V9dV5ct9zlxihyP78UjrTXAkmgyPbQZglvVy2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.17.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1410064},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"dfd06a3ff3a1c3a55ee06243e41d829e72099586","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.17.0_1788955688335_0.44909466101499085","host":"s3://npm-registry-packages-npm-production"}},"0.17.1":{"name":"express-recon","version":"0.17.1","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.17.1","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"a272d41f2ece04a72bbb844af2c981c47d5cfe97","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.17.1.tgz","fileCount":90,"integrity":"sha512-kknVmFUy3CtyEoed2abxyKGXPuc8iRTIty3ELcu7hjYN1e8y0UhPNOXP0dtH6v4fIXKmLLlr41hBYJvhLJXyZg==","signatures":[{"sig":"MEUCID6zCI6to9cXMFX0U6nqkKIpE8cyNf/ZqOtdBHNyAcZlAiEAuBlt/zRCBLIDgp7s3K4OUIP2zihb0pPUrE33ifY5mGs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.17.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1414792},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"d3a57bd6d81f42eb4a160817e5386851dddb4940","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.17.1_1788957850551_0.3747253814368712","host":"s3://npm-registry-packages-npm-production"}},"0.17.2":{"name":"express-recon","version":"0.17.2","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.17.2","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"35bcc45e08721e087a1c45e80815928efca74899","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.17.2.tgz","fileCount":90,"integrity":"sha512-Cc1pDNpa3igxtqZU6LHavYmoJoHdxc2Up7oFJNXUle9ohT6f7l6rtOJstQM3phXu0CbfH5KzUhvEs9yW4I7Cvw==","signatures":[{"sig":"MEUCIQD0KOxPTvjCxHc+FGZuEnwr7cbs+344gSARAI1nxmuVJwIgeEtKgKP6Lo6VKm0A0BYWkuOth6LdrXcmV2HHcPKcE8k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.17.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1415126},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"9200f822cfdbbac20a3f413078b6c11bb3f369ae","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.17.2_1788958673518_0.0958654652715849","host":"s3://npm-registry-packages-npm-production"}},"0.17.3":{"name":"express-recon","version":"0.17.3","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.17.3","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"0d9ce322270d96478a590b048bb0db4e4809d960","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.17.3.tgz","fileCount":91,"integrity":"sha512-w24zVbWn60gFZOqyshUe4ZpNtU6g+a1qHOJOFi0pHQphtCKZm6ZlWBiL+0QNEEvCzUHOWCIPyujPWeX/3Vii4w==","signatures":[{"sig":"MEQCIDOLo9q3k7gCSIGemeRHlsrawAFF1hYtz27hp+BtnILQAiBpSigZGDj8DbNBfPVBK6OIP0zcjnac9iWyqMdyYCpNig==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.17.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1433199},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"d34c136fcf0827a6bb4d12f85130127a76e07f44","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.17.3_1788970616604_0.9654362268670489","host":"s3://npm-registry-packages-npm-production"}},"0.17.4":{"name":"express-recon","version":"0.17.4","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.17.4","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"0105253666375e4b29cbd8e8ad4ff6b5bcef26e8","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.17.4.tgz","fileCount":93,"integrity":"sha512-5pX/VHw7++Ww36rdXuYtXMR6O9SAKYaKHKkWE0D30EyryR9cKbLEyHxke+bG5cBNtsUkN0ug/3ffkALVNJJRMw==","signatures":[{"sig":"MEUCICGVTMxxWAkPST2lFfuayh7erk7zvpuVH8QZtmiI+1X/AiEAj326dpZX+YW5fq4u3/UlYoukaynrKYcB+xkUcNFO+/c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.17.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1455309},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"266a295352bf9e7b19a7e00ce226055e3f312fdb","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.17.4_1788975942091_0.34391574561818805","host":"s3://npm-registry-packages-npm-production"}},"0.18.0":{"name":"express-recon","version":"0.18.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.18.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"cc0d486860fe1f2ea96ea9c3a6132c719591644b","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.18.0.tgz","fileCount":96,"integrity":"sha512-RnjjjHnrozKnMtNdTAy99Wv7sjBLavX8Hjqvso/t0YoNRjEP+SJWzTA1zadO35mg9bGnyFFnvByoqVXS0P0kbg==","signatures":[{"sig":"MEUCIA+ctyiO83fTiS2dHjF7wjDYW7Dg4PCWnd3NPlOz2WjqAiEAvpVv8v+hzFleeMCujPhlNma1tKP2GL7XvMHiESoRhUo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGICTGG4PEziidspgOyupW75sdei4wASY1IhHveepDTUAiASkTzk021IDUFn99kOJdWTv1OCYYR9SOEUMg36vbVivA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.18.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1503888},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"aeb9252585a961e22ea58dd5d180acd78dafe16f","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.18.0_1789554391998_0.49014335228139005","host":"s3://npm-registry-packages-npm-production"}},"0.19.0":{"name":"express-recon","version":"0.19.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.19.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"68e7da3e24207954dac13e1cbbc6a3c08b9ad2c7","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.19.0.tgz","fileCount":96,"integrity":"sha512-LUUStIALZcSYdiHFORWpOb2MBUt1i4IzC82/PV9A8TXdBJ86OnuChYojrrwfDDQ+FO4OBs1l7pmBWMzKCyHzqA==","signatures":[{"sig":"MEUCIQCyvHEN6vgL3RRTyESnrq+1+zqX8l96LCmf1CdYj93WhwIgEXa30vRGya1VqhT/m+KIIEN7TGvCJBliMAwbcL9y8eY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQC0Hak0wC0Yoa2dLpoffa6KpIaRIUPOuRbvnFszU+SHuQIgEGsZLGr39jeLKjr/XaDL1AiqFJ7fqnNN3Fkhgfehfyw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.19.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1515402},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"e06bac1399e4029eae779722311581e505cb0e0f","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.19.0_1789588937367_0.6769772206688331","host":"s3://npm-registry-packages-npm-production"}},"0.19.1":{"name":"express-recon","version":"0.19.1","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.19.1","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"244938a453a0ba231c13eb0ef1764692bff7c2e4","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.19.1.tgz","fileCount":96,"integrity":"sha512-TnDyP/jXZpNzhZonujggoFFD9iy0R3XP2CkfoTrhddBQQSRxR0eZ9RLMIX3Es9P5+exfZaoRGO2ABYEvg17w0A==","signatures":[{"sig":"MEUCIQCHlU00sZ8QylMcnqSKC9xKOgvrYCBYQuBp39dnxGEuggIgFeFbzXfwJRRauklU3bdN2nTRJCKko89f5JXzmVVwKns=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIBbJyTtXxmTz7EC+Hw5A661eE3khkJjw3cfXgW6sQGqVAiBUQLZyLaLhhTYdnwEQZzCe1IO2DyNleP75t++e4mBBuA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.19.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1519393},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"ef69c2d2873f5c39c424aa91ef1e243b6ecdca45","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.19.1_1789623746531_0.5190967663925314","host":"s3://npm-registry-packages-npm-production"}},"0.20.0":{"name":"express-recon","version":"0.20.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.20.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"b067540d86702047c1bd03cbae031126e3197ad5","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.20.0.tgz","fileCount":99,"integrity":"sha512-mDVCv+zMKbh+WNJbayDMBhpYQ2IFFRqmR+FEKUSBBsVgs+yeUWqwhcFM/MpOCdyF3NeTba4WYb8HOwTbnxx8Lg==","signatures":[{"sig":"MEQCIC632DigrClfd2hCOtmMgPFFVyPSg9iXi/mEiw0W8k8/AiBDg68a0ZZ67vnUaMqBVGRqQxNmdkhd2M7+3AXDdbVQug==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIERYZzs9wnH7o4fpTYetJ5yIoSD8RC/PlMwewerhqRkwAiAOFvakxxmyJuk4Uq3iISmq1DrjM2K1XIHxpTp7Ud6RqQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.20.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1560527},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"94cf95761885b71f0dfbf44ef81e5aabbd636a75","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.20.0_1789721441826_0.3556162644703531","host":"s3://npm-registry-packages-npm-production"}},"0.21.0":{"name":"express-recon","version":"0.21.0","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"author":{"name":"chiz0me"},"license":"MIT","_id":"express-recon@0.21.0","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"homepage":"https://github.com/chiz0me/express-recon#readme","bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"dist":{"shasum":"65be2dfd72f883da0e7fec5093094258f0634e57","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.21.0.tgz","fileCount":99,"integrity":"sha512-4xY2H9oi7UJ3meddQNAiUO5ihZHHmAsECpms/YmPfaRRSmEo2pVZUurIMeAf5Nc3vn2RZ9GWpubxCxeL7sMxzg==","signatures":[{"sig":"MEUCIQClKjcqd9/rF6R5ef5cmYbZjhOoxjhZPerb98tmlunhfAIgfzDCSjEv+098Ha0jKG1q3+4bajVhZoywn7mJE6oZ/U4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIHjDS5zqP8dA2HHUZIPz+J6AevxrBXtkcAXZsuvDbhcwAiB15dPHw5SJmBLhmZ/l9BJb1rz/vyxKI4asvXxdPjuiMA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.21.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1566022},"main":"src/index.js","engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"f058602bd7766b4deb1ccef6dafc041febda3a5b","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"tmp":"tmp/express-recon_0.21.0_1789726260421_0.3768634181284818","host":"s3://npm-registry-packages-npm-production"}},"0.21.1":{"_id":"express-recon@0.21.1","bin":{"express-recon":"src/cli.js","express-recon-mcp":"src/mcp/server.js"},"bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"dist":{"shasum":"f6b99e6d60b2eb19c14b4fefa3c79c17c3a56051","tarball":"https://registry.npmjs.org/express-recon/-/express-recon-0.21.1.tgz","fileCount":99,"integrity":"sha512-z8f4gQXb/WCwyerY5yY3vDZsNxlC3Y/c2yd8SrYWRgZIfgV7bz46+5nr7YWydIDROdZAYEz2ChGVPHvYcVjnog==","signatures":[{"sig":"MEUCIDcQgw5rdXhXaj01hthMIPgMwZYkUZSNrUAfgIabzA73AiEAxOVWT7K4Kt0s+CrHDj/Sskf7Ge/NWsGLqEJuEzFxmjY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDO/5RxeDSdFFdV0WnEwN+pEqTcddfGKVA8LLUJ2R0fswIgBj9M2mEQh7hRlcWHKNIYpALEkJW8EME4p6bR0diYoZA="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/express-recon@0.21.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1567411},"main":"src/index.js","name":"express-recon","author":{"name":"chiz0me"},"engines":{"node":"^20.19.0 || >=22.12.0"},"gitHead":"64aeb75c215d6ff5310e9f86bda6a15c107af45b","license":"MIT","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test","check":"npm run lint && npm run fmt:check && npm run docs:coverage && npm run schemas:check && npm run test:coverage && npm run check:version","version":"node scripts/sync-version.js && git add .claude-plugin/plugin.json","fmt:check":"oxfmt --check .","audit:prod":"npm audit --omit=dev --audit-level=high","docs:check":"npm run docs:coverage && node --test testcases/documentation.test.js","logo:build":"node scripts/build-logo-variants.mjs","check:version":"node scripts/check-version.js","docs:coverage":"node scripts/check-documentation-coverage.js","schemas:check":"node scripts/export-schemas.js --check","test:coverage":"node --test --experimental-test-coverage --test-coverage-include=\"src/**/*.js\" --test-coverage-lines=92 --test-coverage-branches=77 --test-coverage-functions=90","prepublishOnly":"node scripts/check-version.js","schemas:export":"node scripts/export-schemas.js"},"version":"0.21.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:102291a6-237d-4937-abb9-9a647f54d6a9"}},"homepage":"https://github.com/chiz0me/express-recon#readme","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"_npmVersion":"11.18.0","description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","directories":{},"maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.20.0","zod":"4.4.3","yaml":"2.9.0","oxc-parser":"0.135.0","ajv-formats":"3.0.1","ajv-draft-04":"1.0.0","swagger-ui-dist":"5.32.14","@octokit/auth-app":"8.3.1","@readme/openapi-schemas":"4.0.0","@modelcontextprotocol/sdk":"1.29.0"},"scarfSettings":{"enabled":false},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"^0.41.0","oxlint":"^1.56.0","express":"^5.1.0","@resvg/resvg-js":"^2.6.2"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/express-recon_0.21.1_1789727349688_0.5497050420413967"}}},"time":{"created":"2026-06-09T19:51:45.753Z","modified":"2026-09-18T10:29:10.118Z","0.1.0":"2026-06-09T19:51:46.180Z","0.1.1":"2026-06-10T07:15:30.876Z","0.2.0":"2026-06-10T11:07:27.517Z","0.3.0":"2026-07-13T14:15:57.724Z","0.4.0":"2026-07-15T11:37:13.006Z","0.5.0":"2026-07-23T10:15:09.807Z","0.6.0":"2026-08-29T14:27:41.742Z","0.7.0":"2026-08-29T15:27:08.168Z","0.7.1":"2026-08-29T15:33:31.953Z","0.7.2":"2026-08-29T16:38:41.174Z","0.7.3":"2026-08-29T18:42:34.825Z","0.8.0":"2026-08-31T22:04:23.061Z","0.9.0":"2026-09-01T14:39:47.179Z","0.10.0":"2026-09-01T16:23:56.412Z","0.11.0":"2026-09-01T17:20:12.301Z","0.12.0":"2026-09-02T11:06:24.074Z","0.13.0":"2026-09-02T19:06:03.856Z","0.14.0":"2026-09-04T09:18:08.360Z","0.15.0":"2026-09-08T17:13:26.945Z","0.16.0":"2026-09-08T19:19:14.810Z","0.17.0":"2026-09-09T12:08:08.470Z","0.17.1":"2026-09-09T12:44:10.710Z","0.17.2":"2026-09-09T12:57:53.669Z","0.17.3":"2026-09-09T16:16:56.768Z","0.17.4":"2026-09-09T17:45:42.226Z","0.18.0":"2026-09-16T10:26:32.101Z","0.19.0":"2026-09-16T20:02:17.458Z","0.19.1":"2026-09-17T05:42:26.665Z","0.20.0":"2026-09-18T08:50:41.921Z","0.21.0":"2026-09-18T10:11:00.528Z","0.21.1":"2026-09-18T10:29:09.790Z"},"bugs":{"url":"https://github.com/chiz0me/express-recon/issues"},"author":{"name":"chiz0me"},"license":"MIT","homepage":"https://github.com/chiz0me/express-recon#readme","keywords":["audit","authentication","authorization","express","fastify","github","mcp","middleware","nestjs","offline","openapi","organization-inventory","routes","sast","security","static-analysis","swagger"],"repository":{"url":"git+https://github.com/chiz0me/express-recon.git","type":"git"},"description":"Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.","maintainers":[{"name":"naveenyagati","email":"naveenyagati@protonmail.com"}],"readme":"<p align=\"center\">\n  <picture>\n    <source media=\"(prefers-color-scheme: dark)\" srcset=\"assets/logo/lockup-dark.svg\">\n    <img src=\"assets/logo/lockup-light.svg\" alt=\"express-recon\" width=\"300\">\n  </picture>\n</p>\n\n# express-recon\n\nFor GitHub App authentication, portable application workspaces, offline validation,\nand Git-friendly rendering, see the [Git inventory workflow](docs/git-inventory-workflow.md).\n\nFast, offline-first route scanner, authentication auditor, and OpenAPI generator for **Express**, **Fastify**, and **NestJS**.\n\nIt statically inspects supported JavaScript and TypeScript route patterns, authentication middleware, and schema evidence to generate an OpenAPI (Swagger) inventory — **without executing your code or running your server** (with optional worker execution available for runtime Express inspection). Unresolved paths and incomplete route graphs remain visible for review instead of being presented as confirmed coverage.\n\n> 💡 **In Simple Words**:\n>\n> - **Route Inventory**: Recovers supported endpoints (`GET /users`, `POST /login`, etc.) and attached middleware, while reporting analysis gaps explicitly.\n> - **`public`**: Means no recognized authentication middleware was found by your audit configuration on this route. (This is relative to your configuration and does not prove the endpoint is reachable from the public internet).\n> - **`proven`**: Means a recognized authentication guard or middleware configured in your allowlist was located on the route (it does not prove the internal logic inside that guard is bug-free).\n> - **`unknown`**: Means the route has an inline function or custom logic that needs a quick manual review by a developer.\n> - **OpenAPI / Swagger**: Automatically generates or updates an OpenAPI 3.1 contract from your actual routes and validation schemas.\n\n---\n\n## Why express-recon?\n\n- 🔒 **Safe Static-First Analysis**: Static mode analyzes code using Abstract Syntax Tree (AST) parsing without booting your application, connecting to databases, or executing code. For advanced Express inspection, optional runtime and hybrid modes execute trusted code in an isolated worker process.\n- 🌐 **Local-First and Private by Default**: Runs entirely on your local machine or CI runner without external cloud dependencies. No source code, routes, or tokens are sent externally unless you explicitly invoke remote features (such as scanning remote Git repositories or sending webhook notifications).\n- ⚡ **Multi-Framework Support**: Works seamlessly across Express 4 & 5, Fastify 4 & 5, and NestJS 10 & 11 (including TypeScript DTOs and decorators).\n- 🛡️ **CI/CD Quality Gates**: Can block pull requests on configured route, documentation, completeness, or policy findings.\n- 🤖 **AI-Ready with MCP**: Comes with a built-in Model Context Protocol (MCP) server so AI coding assistants (like Cursor, Claude Desktop, or Gemini CLI) can understand your backend architecture safely.\n\n---\n\n## Start here\n\n**System Requirements**: Node.js `^20.19.0` or `>=22.12.0`.\n\nInstall `express-recon` in your project as a development dependency so your whole team and your CI pipeline use the locked version:\n\n```bash\nnpm install --save-dev express-recon\nnpx --no-install express-recon --help\n```\n\nThe package installs two binaries: `express-recon` for CLI workflows and `express-recon-mcp` for the static local MCP server.\n\n> ℹ️ **Good to know**:\n> Local commands like `discover`, `inventory`, `audit`, `docs`, `refresh`, and middleware review do not use the network, do not install packages, and do not import application code. Installing the npm package is the only step that uses the network.\n\n---\n\n## Five-minute quick start tutorial\n\nFollow these four simple steps to scan your project, find all API endpoints, and check your security guards.\n\n### Step 1: Discover your repository structure\n\nRun `discover` to find all applications, frameworks, entry files, and existing Swagger/OpenAPI files in your project:\n\n```bash\nnpx --no-install express-recon discover --src . --out .express-recon\n```\n\n**What happens?**\nThis creates `.express-recon/discovery.json`. It inspects your project and identifies:\n\n- Which frameworks are in use (Express, Fastify, or NestJS).\n- Each distinct application and its unique ID (for example, `app:src/app.js#app`).\n- Where your main server file is located.\n- Any existing OpenAPI specifications or JSDoc comments.\n\n### Step 2: Build a complete route inventory\n\nRun `inventory` to get a list of every API route without any security judgment:\n\n```bash\nnpx --no-install express-recon inventory --src . --format json,md --out .express-recon\n```\n\n**What happens?**\nThis writes two files:\n\n1. `routes.json`: A machine-readable catalog of every endpoint, method, and middleware.\n2. `routes.md`: A clean, readable Markdown table showing all your routes.\n\n> 💡 **Ignoring files**:\n> If you have files you want to skip (such as build outputs, tests, or legacy code), create an `.express-reconignore` file in your project root. It uses standard glob patterns (like `client/**` or `dist/**`).\n>\n> **Important**: Add `.express-recon/` to your `.gitignore` so generated reports are not accidentally committed, unless you intentionally want to save a baseline.\n\n### Step 3: Identify authentication guards\n\nRun `suggest-auth` to automatically detect functions in your code that look like authentication middleware:\n\n```bash\nnpx --no-install express-recon suggest-auth --src . > .express-recon/auth-candidates.json\n```\n\n**What happens?**\nThe tool looks for common auth naming patterns (such as `requireAuth`, `authenticate`, `verifyToken`, `jwtGuard`, `requireAdmin`) and ranks them for you.\n\nCheck these candidates, then create a simple configuration file named `recon.config.yaml` in your project root:\n\n```yaml\n# 1. Tell express-recon which middleware protect your APIs:\nauthMiddleware:\n  requireAuth: authenticated\n  requireAdmin:\n    tags: [admin]\n    roles: [administrator]\n\n# 2. List routes that are intentionally public (so audit will not flag them):\nacceptedPublic:\n  - applicationId: app:src/app.js#app\n    method: GET\n    path: /health\n  - \"POST /login\"\n  - \"POST /register\"\n```\n\n> 💡 **Tip**: In single-app repositories, simple strings like `\"POST /login\"` work great. For multi-app monorepos, use the structured form with `applicationId` to target the specific app.\n\n### Step 4: Audit routes and enforce security in CI/CD\n\nNow, run `audit` to check every route against your configuration and fail if any unauthenticated endpoint is exposed:\n\n```bash\nnpx --no-install express-recon audit --src . --config recon.config.yaml \\\n  --format json,md --out .express-recon \\\n  --fail-on public,unknown,incomplete\n```\n\n**Understanding Exit Codes**:\n\n- **Exit code `0`**: All checks passed! Every route is either authenticated (`proven`) or explicitly listed in `acceptedPublic`.\n- **Exit code `2`**: Security rule matched! One or more routes are unprotected (`public`), need review (`unknown`), or have incomplete static coverage. In CI/CD pipelines (like GitHub Actions), this will intentionally fail the build to stop vulnerable code from being deployed.\n- **Exit code `1`**: General operational error (such as a missing file or invalid CLI flag).\n\n## Choose the right workflow\n\nHere is a quick cheat sheet to help you pick the right command for your task:\n\n| What do you want to do?                          | Command to run       |   Does code run?    |   Uses network?    | Primary output                                      |\n| :----------------------------------------------- | :------------------- | :-----------------: | :----------------: | :-------------------------------------------------- |\n| **Understand an unfamiliar repo**                | `discover`           |         No          |         No         | Apps, packages, entry points, and existing docs     |\n| **List all routes without security checks**      | `inventory`          | No (in static mode) |         No         | Complete route registry in JSON & Markdown          |\n| **Check auth and enforce security rules**        | `audit`              | No (in static mode) |         No         | Security findings, audit summary, and policy checks |\n| **Combine OpenAPI, JSDoc, and code routes**      | `docs`               |         No          |         No         | Reconciled OpenAPI 3.1 specification & drift report |\n| **Keep an AI-enriched OpenAPI spec up to date**  | `refresh`            |         No          |         No         | Updated OpenAPI spec preserving manual descriptions |\n| **Review complex middleware with an AI agent**   | `review-middleware`  | No (in static mode) |         No         | Bounded evidence bundle for human or AI review      |\n| **Validate and import review suggestions**       | `import-review`      |         No          |         No         | Validated advisory configuration suggestions        |\n| **Scan a single remote Git repository**          | `scan-repo`          |         No          |  Yes (Git fetch)   | Provenance plus complete static inventory/audit     |\n| **Scan every repository in a GitHub Org**        | `scan-org`           |         No          |  Yes (GitHub API)  | Multi-repo inventory with progress and HTML sites   |\n| **View saved reports in a browser (Swagger UI)** | `render`             |         No          |         No         | Clean, self-contained offline HTML website          |\n| **Send route change alerts to Slack/Webhook**    | `notify`             |         No          | Yes (Webhook POST) | Signed, secure notification events                  |\n| **Inspect complex dynamic Express routing**      | `inventory` (hybrid) |       **Yes**       |   App-dependent    | Combined static and runtime route observations      |\n\n---\n\n## Framework support at a glance\n\n`express-recon` understands the unique routing and lifecycle patterns of each framework:\n\n| Framework            | Static route discovery                                                                                      | Lifecycle & Middleware evidence                                     | Runtime / Hybrid mode                  |\n| :------------------- | :---------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------ | :------------------------------------- |\n| **Express (4 & 5)**  | Apps, routers, nested mounts, route chaining (`app.route()`), input schemas (Zod, Joi, `express-validator`) | `app.use()`, router middleware, and route-level guards              | Fully supported for trusted local code |\n| **Fastify (4 & 5)**  | Root instances, plugins, prefixes, encapsulated scopes, direct registrars, and route `schema` options       | Request hooks (`onRequest`, `preHandler`, etc.) and per-route hooks | Static-first (use `--mode static`)     |\n| **NestJS (10 & 11)** | Modules, controllers, global prefixes, route mappings, TypeScript DTOs, and `class-validator`               | Guards (`@UseGuards`), interceptors, pipes, and filters             | Static-first (use `--mode static`)     |\n\n> ℹ️ **How it handles unknown patterns**:\n> If Fastify or NestJS uses dynamic wiring (such as an unresolved object spread or dynamic module import), `express-recon` does not pretend everything is fine. It marks the affected route as `unknown` or adds an opaque route diagnostic, alerting you that manual review is needed.\n\n---\n\n## Key concepts explained in simple words\n\n`express-recon` follows a strict principle: **separate facts from security decisions**.\n\n1. **`inventory` records facts**: It lists routes, middleware names, source file line numbers, and request/response shapes. It never makes a security judgment on its own.\n2. **`audit` applies your security decisions**: It takes the inventory and checks it against your `authMiddleware` rules and `acceptedPublic` list.\n3. **The Three Auth Statuses**:\n   - 🟢 **`proven`**: The route has a confirmed guard that matched your `authMiddleware` configuration.\n   - 🔴 **`public`**: No configured guard matched this route. This indicates that no recognized authentication middleware was found under your current configuration (it is configuration-relative and does not prove reachability or lack of network-level security).\n   - 🟡 **`unknown`**: An inline closure or anonymous function is in the middleware chain. It might be checking auth, or it might not. You should inspect it manually.\n4. **Stable Application IDs**: In modern projects, a single repository might contain multiple services. `express-recon` gives each detected app a stable identifier (e.g. `app:src/app.js#app`, `fastify:src/server.js#server`, or `nestjs:src/main.ts#app`). Identical paths in separate apps are never accidentally mixed up.\n\nEvery JSON report is deterministic and versioned. Run `npx --no-install express-recon schema` to view its JSON Schema. For field-by-field details, see the [CLI and report reference](./docs/reference.md).\n\n## Common workflows\n\n### 1. Working with Monorepos and Multi-App Repositories\n\nIf your repository contains multiple services (for example, a public API in `apps/public` and an admin API in `apps/admin`), run `discover` first to see their unique application IDs:\n\n```bash\nnpx --no-install express-recon discover --src . --out .express-recon\n```\n\nThen, target a specific app using `--app-id`:\n\n```bash\nnpx --no-install express-recon docs --src . \\\n  --app-id 'app:apps/public/src/app.js#app' \\\n  --out .express-recon/public-api\n```\n\n> 💡 **Why use `--app-id`?**\n> In a monorepo, multiple packages might have an `app.js` or `server.ts`. Specifying `--app-id` ensures that `express-recon` audits only the intended application and does not accidentally mix routes from different services.\n\nFor trusted hybrid scans on an Express app, you can bind the runtime entry point to that exact app ID:\n\n```bash\nnpx --no-install express-recon audit --mode hybrid --src . \\\n  --app ./apps/public/src/app.js \\\n  --app-id 'app:apps/public/src/app.js#app' \\\n  --config recon.config.yaml --format json\n```\n\n---\n\n### 2. Merging Existing OpenAPI specs and swagger-jsdoc\n\nIf your project already has an OpenAPI specification or JSDoc comments (`@openapi` or `@swagger`), run `docs` to reconcile them with your actual code:\n\n```bash\nnpx --no-install express-recon docs --src . --app-id 'app:src/app.js#app' \\\n  --out .express-recon/docs \\\n  --fail-on docs-conflict,docs-incomplete\n```\n\n**How conflicts are resolved**:\n\n1. **Authored OpenAPI specification** has the highest priority and is treated as truth.\n2. **JSDoc comments** fill in any missing parameter descriptions, summaries, and tags.\n3. **Static code analysis** fills in any remaining routes or parameter shapes found in your source code.\n4. **Conflict detection**: If code and docs disagree (for example, a route exists in code but is missing from docs, or vice versa), it is clearly flagged in `docs-report.json`.\n\n> 📘 Learn more in the detailed [OpenAPI guide](./docs/openapi.md).\n\n---\n\n### 3. Keeping AI-Enriched OpenAPI Documentation in Sync (`refresh`)\n\nWhen documenting an API, you or an AI agent might write rich summaries and descriptions in `openapi.json`. When the backend code changes, you don't want those manual descriptions to be wiped out!\n\nThe `refresh` command creates a living documentation workspace:\n\n```bash\n# 1. Initialize or update the documentation workspace:\nnpx --no-install express-recon refresh --src . \\\n  --app-id 'app:src/app.js#app'\n```\n\nBy default, this writes to `.express-recon/api`. On every run, it performs a fresh static inventory, compares routes with the previous run, and rebuilds an offline Swagger UI site under `api-reference/`.\n\n**How to safely enrich descriptions**:\n\n1. You or an AI agent can edit `summary`, `description`, `parameters`, `requestBody`, `responses`, and `components.schemas` in `.express-recon/api/openapi.json`.\n2. Explicitly accept your changes:\n   ```bash\n   npx --no-install express-recon refresh --src . --accept-enrichment\n   ```\n\n**Why this is helpful**:\n\n- Your accepted descriptions are saved in `openapi.enrichment.json`.\n- When backend code changes, routes that stayed the same keep their descriptions automatically.\n- Only newly added or modified routes are flagged as `unreviewed` or `stale` in `refresh-report.json`.\n- If a description depends on delegated code beyond the detected route and handler files, add repository-relative paths to that operation's `x-express-recon.enrichmentSources` before acceptance.\n- In CI/CD, you can gate on `--fail-on enrichment-stale,enrichment-unreviewed` to ensure all API changes are properly documented.\n\n---\n\n### 4. Reviewing Complex Middleware with an AI Agent\n\nIf your project has complex custom middleware that the static scanner cannot automatically verify, you can bundle the evidence for review:\n\n```bash\n# 1. Create a review bundle of all uncertain middleware:\nnpx --no-install express-recon review-middleware --src . --out .express-recon/review\n\n# 2. Provide middleware-review.json to a teammate or an AI model, then validate their response:\nnpx --no-install express-recon import-review \\\n  --review .express-recon/review/middleware-review.json \\\n  --assessment middleware-assessment.yaml \\\n  --out .express-recon/review\n```\n\nThe review bundle extracts exact code snippets, callsites, and routes. The `import-review` command validates the assessment against a strict schema and provides advisory suggestions without granting automatic authority. See the [AI agent guide](./docs/ai-agent-guide.md).\n\n### 5. Scanning Remote Git Repositories and GitHub Organizations\n\n#### Scanning a single Git repository (`scan-repo`)\n\nYou can scan a remote repository directly without manually cloning it or running `npm install`:\n\n```bash\nnpx --no-install express-recon scan-repo --repo owner/project --ref main \\\n  --out .express-recon/remote\n```\n\n**How it works safely**:\n\n- Performs a shallow Git fetch over HTTPS without checking out files, running hooks, installing dependencies, or executing code.\n- Generates `repo-scan.json` containing discovery, inventory/audit, documentation status, and commit provenance.\n- For private repositories, set the `GH_TOKEN` (recommended) or `GITHUB_TOKEN` environment variable. The token is used in-memory and never saved to disk.\n- See [SECURITY.md](./SECURITY.md) for details on the security model.\n\n#### Scanning an entire GitHub organization (`scan-org`)\n\nTo get a complete security inventory of every backend service across your company or GitHub organization:\n\n```bash\n# 1. Scan all repositories in an organization (skips forks and archived repos by default):\nnpx --no-install express-recon scan-org --org acme \\\n  --concurrency 2 --max-repos 500 \\\n  --fail-on incomplete\n\n# 2. Resume an interrupted scan (picks up right where it left off!):\nnpx --no-install express-recon scan-org --org acme \\\n  --concurrency 4 --max-repos 500 \\\n  --fail-on incomplete --resume\n\n# 3. Update an existing scan (only rescans repos that had new git commits):\nnpx --no-install express-recon scan-org --org acme \\\n  --max-repos 500 --concurrency 2 --update\n\n# 4. Compare today's scan with last month's scan to see newly added or removed routes:\nnpx --no-install express-recon scan-org --org acme \\\n  --baseline .express-recon/acme-before \\\n  --out .express-recon/acme-current --concurrency 2 --max-repos 500 \\\n  --fail-on incomplete\n```\n\nOrganization scans always use durable output: omitting `--out` derives `.express-recon/<lowercase-organization>` from the current directory.\n\n**Key features for organization scanning**:\n\n- **Framework Detection**: Distinguishes Express, Fastify, and NestJS apps from packages that merely list the framework as a dependency.\n- **Checkpoint & Resume (`--resume`)**: If your network disconnects or CI times out, running with `--resume` verifies SHA-256 digests and only scans incomplete or failed repositories.\n- **Smart Updates (`--update`)**: Compares GitHub push commit markers and only scans repositories that have changed since the last inventory.\n- **Delta Reports (`--baseline`)**: Compares two organization runs and generates `organization-delta.json`, detailing new routes, deleted routes, and auth regressions.\n- **Token Efficiency for AI**: Set `EXPRESS_RECON_CONTEXT=agent` so AI assistants inspect the compact aggregate index first without wasting context tokens on massive logs. See the [AI agent guide](./docs/ai-agent-guide.md#keep-organization-scans-token-efficient).\n\nCheck out our production-ready [scheduled organization inventory example](./examples/github-actions/scheduled-org-inventory/README.md) for automated GitHub Actions workflows with Slack notifications.\n\n---\n\n### 6. Browsing Saved Reports as an Offline HTML Website (`render`)\n\nTurn your JSON scan reports into a beautiful, static HTML website with an interactive Swagger UI:\n\n```bash\n# Render from the default .express-recon/ output directory:\nnpx --no-install express-recon render\n\n# Render from an organization scan:\nnpx --no-install express-recon render \\\n  --input .express-recon/acme \\\n  --out .express-recon/acme-site\n\n# Render a side-by-side comparison of changes between two scans:\nnpx --no-install express-recon render \\\n  --baseline .express-recon/acme-before \\\n  --input .express-recon/acme-current \\\n  --out .express-recon/acme-changes-site\n\n# Render a single OpenAPI file with packaged Swagger UI:\nnpx --no-install express-recon render \\\n  --input .express-recon/docs/openapi.json \\\n  --out .express-recon/api-reference\n```\n\nWith no paths, `render` looks only at the current directory, `.express-recon/`, and its immediate child directories. The default output is a sibling named `<input>-html`.\n\nOrganization pages show repositories with discovered routes in the main table,\ngrouped as **complete** and **incomplete**. Repositories with zero discovered\nroutes, including complete scans, are collapsed below under **No routes discovered**.\nOther statuses are grouped in a collapsed reference table. Each table has independent\nsearch, completion/status, and framework filters. Framework choices reflect the\nsaved evidence; mixed-framework repositories match each included framework.\nWhen saved domain data includes hostnames, a separate **Domain** filter searches\nany part of a hostname, ignoring case, and combines with the other filters.\nRepository tables wrap long values on wide screens and use labelled rows on\nnarrow screens so all columns remain visible without horizontal scrolling.\nThe overview groups related totals into summary cards, with percentages alongside\nraw counts. **Also in API docs** shows how many discovered routes match authored\nOpenAPI, Swagger, or JSDoc evidence, and route details identify their documentation\nsources. Each route counts once, even if multiple specifications or path variants\nmatch. Missing evidence, uncertain paths, and ambiguous application ownership stay\n**Not checked** rather than implying zero overlap. Generated-only operations do\nnot count as authored documentation. Invalid API specifications appear in a\ncollapsed **Show details** section below the repository tables.\nRepository tables sort each completion group by route count from high to low by\ndefault. The **Sort** control can reverse that order, sort by app/module count,\nor sort repository names alphabetically without changing the active filters.\n\nOptional saved `gin-recon` outputs are supported by the renderer only—no Gin\nscanner or changes to the scan architecture are required. Point `--input` at a\n`fleet.json`, its directory, or a bundle containing that directory. When an\norganization output also contains a matching Gin fleet (directly or one directory\nbelow), its routes, per-module OpenAPI references, middleware suggestions, and\nproducer statistics are included automatically. Original JSON evidence is linked\nfor download. Existing Express scans and Gin scans retain separate detail pages.\nSee the [render reference](docs/reference.md#render) for limits and trust boundaries.\n\nDeployment domains can be scanned independently and saved as\n`domain-inventory.json` beside `organization-inventory.json`. Plain\n`express-recon render --input <scan-output>` automatically reads this optional\nsidecar: it adds repository domain counts, `domains.html`, joined evidence in\n`domain-merge.json`, and safe OpenAPI server enrichment. The original route\nartifacts and domain catalog are not rewritten. `scan-org --update`, `--resume`\nand `--overwrite` leave this producer-owned sidecar (and optional\n`domain-bindings.json`) untouched. The separate `domain-recon` package can write\nit directly with `scan --org <owner> --express-output <scan-output>`.\nSee the [domain sidecar contract](docs/render-integration.md#deployment-domain-sidecar).\n\nOther tools can export a versioned `render-bundle.json` with routes, OpenAPI,\nstatistics, and JSON evidence. Matching bundles alongside an organization output\nare included automatically; arbitrary files are not guessed or executed.\nSee the [schemas and integration guide](docs/render-integration.md),\n[synthetic example](examples/render-bundle/README.md), and reusable\n[`express-recon-render-port`](skills/express-recon-render-port/SKILL.md) skill.\n\n**Why the offline site is great**:\n\n- **100% Offline**: Embedded CSS and JavaScript. Open `index.html` directly in your browser (`file://`) without running a web server or needing an internet connection.\n- **Direct-file compatible**: Each page includes its viewing assets and branding, including Swagger UI on API pages. Keep the output folder together for links to other pages and evidence downloads.\n- **Packaged Swagger UI**: Easily browse and inspect API endpoint contracts without sending live network requests.\n- **Privacy & Security**: Built with a strict Content Security Policy (CSP). It disables external network calls, tracking, and remote analytics.\n\n---\n\n### 7. Enforcing Pull-Request Security Gates in CI/CD\n\nPrevent developers from accidentally merging unauthenticated routes or breaking documentation:\n\n```bash\n# Step 1: Scan the base branch (e.g. main)\nnpx --no-install express-recon audit --src ./base --config recon.config.yaml \\\n  --format json --out ./base-results --fail-on incomplete\n\n# Step 2: Scan the pull request and fail ONLY on newly introduced public routes or regressions:\nnpx --no-install express-recon audit --src ./current --config recon.config.yaml \\\n  --baseline ./base-results/routes.json \\\n  --format json,md --out ./current-results \\\n  --fail-on new,regression,incomplete\n```\n\n- If a developer introduces a new route without auth, `audit` exits with code `2`, blocking the PR.\n- Existing accepted routes from the baseline do not cause false alarms.\n- See our ready-to-copy [GitHub Actions PR workflow](./examples/github-actions/express-recon-pr.yml) with automated PR comments and annotations.\n\nTo send real-time alerts when new routes are merged:\n\n- Use our [trusted Slack notifier example](./examples/github-actions/slack-new-routes/README.md) to post new endpoints directly to your team's Slack channel.\n- Or use our [signed webhook example](./examples/github-actions/webhook-new-routes/README.md) for custom webhook listeners.\n  The `notify` command emits bounded events for added/removed/semantically changed routes,\n  authentication regressions, and incomplete scans from either a repository or\n  organization comparison. Delivery uses HMAC-SHA256 Standard Webhooks headers,\n  an exact committed hostname allowlist, HTTPS-only/no-redirect requests, current\n  plus previous secret rotation, bounded retry, and deterministic event IDs for\n  receiver-side deduplication. Secrets are read only from named environment\n  variables; `--dry-run` needs neither a URL nor a secret.\n\n```bash\nnpx --no-install express-recon notify \\\n  --input current-results/routes.json \\\n  --events routes.added,routes.changed,auth.regressed,scan.incomplete \\\n  --dry-run\n```\n\n## Runtime and hybrid trust boundary\n\nStatic mode is the default and is appropriate for untrusted source. Runtime and\nhybrid modes import the app inside a bounded child process. That process contains\ncrashes, `process.exit()`, leaked timers, and serialized output, but it is **not\nan OS sandbox**: trusted target code retains filesystem, process, and network\npermissions.\n\n```bash\n# Explicit trusted entry:\nnpx --no-install express-recon inventory --mode hybrid --src . --app ./src/app.js\n\n# Conservative auto-selection; fails unless discovery finds exactly one app and\n# one high-confidence entry:\nnpx --no-install express-recon inventory --mode hybrid --src . \\\n  --app auto --allow-exec\n```\n\nThe worker sets `EXPRESS_RECON_DRY=1`, starts with an isolated environment, and\ncan stub common infrastructure clients. Native ESM dependency imports are not\nintercepted by the CommonJS stubbing layer. Full boot configuration and static\nresolution details are in the [reference](./docs/reference.md) and\n[security model](./SECURITY.md).\n\n## MCP server for AI agents\n\nThe stdio MCP server exposes static local tools only. It cannot acquire remote\nrepositories or execute target code.\n\n```jsonc\n{\n  \"mcpServers\": {\n    \"express-recon\": {\n      \"command\": \"npx\",\n      \"args\": [\"--no-install\", \"express-recon-mcp\"],\n    },\n  },\n}\n```\n\nCore tools include `discover_repository`, `inventory_routes`, `audit_routes`,\n`query_audit`, `explain_route`, `finding_by_fingerprint`, `suggest_auth`, `openapi_spec`,\n`reconcile_openapi`, token-bounded `refresh_openapi`/`query_refresh`,\n`review_middleware`, `import_middleware_review`, `validate_policies`, and\n`report_schema`.\n\n`query_audit` pages are byte-bounded and tied to a retained analysis snapshot,\nconfiguration, and filters. Pass the returned `snapshotId` to `explain_route`\nfor the bounded registration and uncertainty evidence behind one route.\n\nUseful requests are precise about the evidence boundary:\n\n> Inventory every supported app in this repository. Group results by framework\n> and application ID, and report coverage and partial paths before conclusions.\n\n> Audit routes using `requireAuth` as the only confirmed authentication guard.\n> List `public` and `unknown` separately; do not call either internet-reachable.\n\n> Reconcile the selected app's existing OpenAPI document and report code-only,\n> docs-only, conflicting, duplicate, and incomplete operations.\n\nSee the [AI agent guide](./docs/ai-agent-guide.md) for tool selection and a\nrequired evidence checklist.\n\nThe MCP server intentionally has no remote or organization-scanning tool. Run\n`scan-org` explicitly in the CLI, then give an agent the generated aggregate and\nper-repository reports.\n\n## Library\n\n```js\nconst {\n  inventory,\n  audit,\n  discover,\n  buildReport,\n  compareOrganizationReports,\n  reconcileDocumentation,\n  createMiddlewareReview,\n  applyMiddlewareAssessments,\n  scanRepository,\n  scanOrganization,\n  renderHtmlSite,\n  buildNotificationEvents,\n  deliverWebhook,\n  signWebhook,\n  validateNotificationEvent,\n  verifyWebhookSignature,\n  executeRuntime,\n  formatters,\n} = require(\"express-recon\");\n\nconst source = inventory({ mode: \"static\", src: \".\" });\nconst report = buildReport(source, {\n  command: \"inventory\",\n  mode: \"static\",\n  sourceRoot: \".\",\n});\n\nconsole.log(formatters.markdown.format(report));\n\nasync function observeOrganization() {\n  return scanOrganization(\"acme\", {\n    concurrency: 2,\n    onProgress(event) {\n      process.stderr.write(`${JSON.stringify(event)}\\n`);\n    },\n  });\n}\n\nrenderHtmlSite(\".express-recon/acme\", \".express-recon/acme-site\");\n```\n\nStatic library inventory supports Express, Fastify, and NestJS repositories.\nPassing an already loaded Express app to `inventory()`/`audit()` executes it in\nthe caller's process; runtime and hybrid modes are Express-only. Prefer\n`executeRuntime()` when a bounded worker result is needed. The\n[library reference](./docs/reference.md#library-api) describes the\nshared behavior; the [complete API reference](./docs/api.md) documents every\npublic export.\n\n## Documentation\n\n- [CLI, configuration, report, policies, modes, and library reference](./docs/reference.md)\n- [Complete library API](./docs/api.md)\n- [AI agent and middleware-review guide](./docs/ai-agent-guide.md)\n- [OpenAPI/JSDoc reconciliation guide](./docs/openapi.md)\n- [CI/CD examples](./examples/README.md)\n- Bundled AI skills: [`express-recon-audit`](./skills/express-recon-audit/SKILL.md)\n  and [`openapi-doc`](./skills/openapi-doc/SKILL.md)\n- [Security and execution trust model](./SECURITY.md)\n- [Contributing and local development](./CONTRIBUTING.md)\n- [Release process](./RELEASING.md)\n\n`npm run docs:coverage` derives the supported CLI, configuration, library, and\nexample surfaces from the repository and requires 100% documentation and public\nAPI JSDoc coverage.\n\n## Known boundaries\n\n- Static analysis cannot fully recover data-driven route registration, arbitrary\n  dependency injection, computed mounts, or every TypeScript resolution pattern.\n  It retains partial evidence and diagnostics instead of silently dropping it.\n- Documentation-only operations are split into verified and unverified drift\n  when unresolved route graphs or opaque route providers prevent a sound stale-\n  documentation conclusion.\n- Auth classification is only as sound as the reviewed middleware allowlist.\n- OpenAPI generation prefers statically resolved framework schemas, validators,\n  DTOs, and returned literals over field-name placeholders. Unsupported\n  computation and low/medium-confidence fragments remain explicitly unrefined;\n  the bundled `openapi-doc` skill provides the deeper AI-assisted pass.\n- `scan-repo` is non-executing, but Git protocol parsing and network transfer\n  still process untrusted remote data.\n- Organization scans are API-visible rather than proof of every repository that\n  exists; token permissions define visibility.\n- Runtime/hybrid mode is Express-only and for trusted local code only.\n\n## Frequently asked questions (FAQ)\n\n<details>\n<summary><b>1. Does express-recon execute my backend code or start the server?</b></summary>\n\n**In static mode (the default), no.** Static analysis parses your code's AST using `oxc-parser`, reading `.js` and `.ts` files as structured text without booting your server, connecting to databases, or executing any code. If you explicitly choose runtime or hybrid mode for advanced Express inspection, it executes trusted code in an isolated worker process.\n\n</details>\n\n<details>\n<summary><b>2. Why did my audit command exit with code 2?</b></summary>\n\nExit code `2` is an intentional policy gate signal, not an application crash. With `--fail-on public,unknown`, `express-recon` returns exit code `2` when a route has no configured guard match (`public`) or has middleware that still requires review (`unknown`). In CI/CD, this stops the job on those configured policy findings; it does not prove that a route is internet-reachable or that a recognized guard is effective at runtime.\n\n</details>\n\n<details>\n<summary><b>3. How do I mark an endpoint like /health or /login as public without failing the audit?</b></summary>\n\nAdd it to the `acceptedPublic` list in your `recon.config.yaml`:\n\n```yaml\nacceptedPublic:\n  - \"GET /health\"\n  - \"POST /login\"\n```\n\nOnce listed, `audit` knows this route is intentionally open to the public and will not flag it as a violation.\n\n</details>\n\n<details>\n<summary><b>4. Does it support TypeScript and path aliases?</b></summary>\n\n**Yes!** `express-recon` parses TypeScript natively, resolves `tsconfig.json` path aliases (such as `@/controllers/*`), handles barrel exports (`index.ts`), and extracts TypeScript DTO validation schemas.\n\n</details>\n\n---\n\nMIT licensed. Security issues should be reported privately as described in\n[SECURITY.md](./SECURITY.md).\n\n### Classify before organization scans\n\nUse `classify-org --org acme --out .express-recon/acme` to build a persistent\nframework catalog and JavaScript/Gin scan plan without cloning every repository.\nPass `--classification-cache .express-recon/acme/repository-classification.json`\nto `scan-org` to use it. Exact-commit classifications survive `--overwrite` fresh\nroute scans; `--reclassify` forces fresh classification. Unknown repositories stay\neligible, and mixed-framework repositories can run both scanners. See the\n[classification reference](docs/reference.md#classify-org).\n","readmeFilename":"README.md"}