Open-source coding-agent harness you can actually change — own the loop (prompts, gates, routing, skills, terminal states), use any model, run long tasks while you're away.
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed v5.85.2 · analyzer v28 · 7m ago
skills & prompt files 16
- skill package/dist/bundled-plugins/awa-bundled/skills/automate/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/contract/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/devils-advocate/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/diagnose/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/gather/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/ground-claim/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/ground-state/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/intent-lock/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/parallelize/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/refactor/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/research/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/review/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/shadow-verify/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/ship/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/simplify/SKILL.md
- skill package/dist/bundled-plugins/awa-bundled/skills/spec/SKILL.md
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 4
filesystem 1
- fs package/dist/postinstall.mjs :14
import { existsSync, readFileSync } from 'node:fs';
shell / exec 3
- shell package/dist/index.mjs :858
?`,"m");o=o.replace(l,"")}let s=`${e}=${n}`,i=new RegExp(`^${Cs(e)}=.*$`,"m");i.test(o)?o=o.replace(i,s):(o&&!o.endsWith(` - shell package/dist/postinstall.mjs :13
import { execSync, execFileSync } from 'node:child_process'; - shell package/dist/telegram.mjs :156
`)}`}function Ni(t,e){try{let n=e??Intl.DateTimeFormat().resolvedOptions().timeZone??"UTC",r=new Intl.DateTimeFormat("en-CA",{timeZone:n,year:"numeric",month:"2-digit",day:"2-digit"}).formatToParts(t)
install hooks 1
- postinstall package/package.json :104
node dist/postinstall.mjs || node scripts/postinstall.mjs || true
declared dependencies 36
- @modelcontextprotocol/sdk@^1.29.0
- @anthropic-ai/sdk@^0.74.0
- @mozilla/readability@^0.6.0
- @vscode/ripgrep@^1.18.0
- ansi-escapes@^7.3.0
- better-sqlite3@^12.9.0
- chalk@^5.3.0
- commander@^12.1.0
- dotenv@^16.4.7
- emphasize@^7.0.0
- jsdom@^29.1.1
- log-update@^8.0.0
- marked@^17.0.5
- node-cron@^4.2.1
- openai@^6.38.0
- ora@^8.1.1
- playwright@^1.49.0
- string-width@^8.2.0
- telegraf@^4.16.3
- turndown@^7.2.4
- undici@^7.27.0
- wrap-ansi@^10.0.0
- zod@^4.3.6
- @types/better-sqlite3@^7.6.13
- @types/jest@^30.0.0
- @types/jsdom@^28.0.3
- @types/node@^22.19.10
- @types/node-cron@^3.0.11
- @types/turndown@^5.0.6
- @vitest/coverage-v8@^2.1.8
- @xterm/headless@^6.0.0
- esbuild@^0.28.0
- node-pty@^1.1.0
- tsx@^4.19.2
- typescript@^5.7.3
- vitest@^2.1.8