Direct package risk: frontmatter, activation body, dependencies, references, tests, and proof.
Public Doctor reports
Readable risk evidence before install.
Doctor first identifies the submitted GitHub shape, then reports the reliability risks that matter for that shape: one skill, many skill folders, a plugin workspace, or a source repo with no importable skill package.
How the score works
Static signals, cited basis, clear limits.
The score is a deterministic heuristic. It adds source findings such as broad activation text, buried obligations, implicit dependencies, missing proof surfaces, and namespace hazards. It does not claim a runtime failure or judge domain quality.
Read the score modelWorkspace risk rolls up per-package profiles while keeping every path as package identity.
Plugin roots, repeated names, and repeated content are valid only when namespace/path identity survives.
Doctor stops at shape guidance so public CI does not spend cycles analyzing an arbitrary code repo.
Public proof
Recent Doctor reports
Rendered report
Report
Public automation