THE PUBLIC PLAY REGISTRY

Real plays.
Open contracts.

Inspect what a Play reads, writes, and needs before you run it. Every artifact below comes from its published registry manifest.

ALL PUBLIC PUBLISHERS · MODIQO PINNED FIRST
PLAYOFFS FIELD KIT · 150 STARTING POINTS
Need a Play to build?

Browse research-backed ideas that connect APIs, browsers, and local commands.

EXPLORE 150 IDEAS →
START HEREmodiqo / 0.2.2

Hello

Is it down, or is it just you — for YOUR machine. Probes the AI harnesses you actually have installed (claude, codex, agy, pi, hermes, opencode), ranks them by session recency, checks version drift and provider status, reads live model prices from LiteLLM, checks common infra (AWS, Supabase, Cloudflare, GitHub with Actions, HuggingFace), and surfaces this week's npm/cargo/pip advisories. A parallel dependency DAG with provable step-to-step dataflow; every source degrades to a labeled unknown instead of failing the play; ends in one classified briefing with a glyph stage ledger. S0-clean, reads public data only, writes nothing, carries no keys, needs only python3.

ROTE PLAY · PUBLISHED CONTRACTmodiqo/[email protected]
@01Hf Status@02Advisories@03Aws Events@04Infra Status@05Model Pricing@06Sessions Rank@07Version Drift@08Probe Harnesses@09Provider Status
EXECUTION
ROTE
INPUTS
0 PARAMETERS
EFFECT
READ ONLY
TRUST
DIGEST VERIFIED
167 CURRENT-VERSION DOWNLOADSPUBLISHED AUG 17, 2026
MOST DOWNLOADED · CURRENT VERSIONS

Proven paths, ready to inspect.

LIFETIME DOWNLOADS · NOT A TREND
01 · MODIQO / Engineering TOPICV0.1.4

List Top Committers

Lists top contributors for a GitHub repository, ranked by contribution count, with contribution share and profile URL.

@01Auth Github@02Contributors
2 STEPS3 INPUTSREAD ONLY160 DOWNLOADS
APISESSIONSGITHUB
CLICK ANYWHERE TO OPEN ↗
02 · MODIQO / Engineering TOPICV0.1.2

Search Github Repositories

Searches GitHub repositories by keyword and optional language, returning ranked repository details and aggregate result counts.

@01Auth Github@02Search One Language@03Search All Languages
3 STEPS4 INPUTSREAD ONLY142 DOWNLOADS
APISESSIONSGITHUB
CLICK ANYWHERE TO OPEN ↗
03 · MODIQO / Workplace TOPICV0.1.7

Retrieve Recent Emails

Retrieves recent Gmail messages matching a Gmail search query and returns normalized sender, subject, date, and snippet details.

@01Details@02Messages@03Google Auth@04Validate Inputs
4 STEPS2 INPUTSREAD ONLY127 DOWNLOADS
APISESSIONSGMAIL
CLICK ANYWHERE TO OPEN ↗
04 · MODIQO / Workplace TOPICV0.1.8

Retrieve Rideshare Receipts

Finds Uber, Lyft, and Waymo receipt emails in a date range, extracts trip and fare details, deduplicates updates, and totals spend.

@01Details@02Messages@03Google Auth@04Validate Inputs
4 STEPS3 INPUTSREAD ONLY115 DOWNLOADS
APISESSIONSGMAIL
CLICK ANYWHERE TO OPEN ↗
05 · MODIQO / Workplace TOPICV0.1.6

Check Calendar Meetings

Lists Google Calendar events between two timestamps with timing, attendees, location, organizer, and meeting links.

@01Events@02Auth Calendar@03Normalize End@04Normalize Start@05Validate Inputs
5 STEPS4 INPUTSREAD ONLY108 DOWNLOADS
APISESSIONSCALENDAR
CLICK ANYWHERE TO OPEN ↗
06 · MODIQO / Engineering TOPICV0.1.1

My Open Prs Review Status

Lists open pull requests by one GitHub user with review status and reviewer comment counts.

@01Reviews@02Auth Github@03Current User@04Search Query@05Selected Prs+3
8 STEPS4 INPUTSREAD ONLY68 DOWNLOADS
APISESSIONSGITHUB
CLICK ANYWHERE TO OPEN ↗
THE PUBLIC INDEX

Every published Play.

344 MANIFESTS · PUBLIC
FILTER INDEX
#PLAYREACHPATHEFFECTDOWNLOADS
01HelloIs it down, or is it just you — for YOUR machine. Probes the AI harnesses you actually have installed (claude, codex, agy, pi, hermes, opencode), ranks them by session recency, checks version drift and provider status, reads live model prices from LiteLLM, checks common infra (AWS, Supabase, Cloudflare, GitHub with Actions, HuggingFace), and surfaces this week's npm/cargo/pip advisories. A parallel dependency DAG with provable step-to-step dataflow; every source degrades to a labeled unknown instead of failing the play; ends in one classified briefing with a glyph stage ledger. S0-clean, reads public data only, writes nothing, carries no keys, needs only python3.ROTE9 STEPSREAD ONLY167 ↓02List Top CommittersLists top contributors for a GitHub repository, ranked by contribution count, with contribution share and profile URL.APISESSIONSGITHUB2 STEPSREAD ONLY160 ↓03Search Github RepositoriesSearches GitHub repositories by keyword and optional language, returning ranked repository details and aggregate result counts.APISESSIONSGITHUB3 STEPSREAD ONLY142 ↓04Retrieve Recent EmailsRetrieves recent Gmail messages matching a Gmail search query and returns normalized sender, subject, date, and snippet details.APISESSIONSGMAIL4 STEPSREAD ONLY127 ↓05Retrieve Rideshare ReceiptsFinds Uber, Lyft, and Waymo receipt emails in a date range, extracts trip and fare details, deduplicates updates, and totals spend.APISESSIONSGMAIL4 STEPSREAD ONLY115 ↓06Check Calendar MeetingsLists Google Calendar events between two timestamps with timing, attendees, location, organizer, and meeting links.APISESSIONSCALENDAR5 STEPSREAD ONLY108 ↓07My Open Prs Review StatusLists open pull requests by one GitHub user with review status and reviewer comment counts.APISESSIONSGITHUB8 STEPSREAD ONLY68 ↓08Recent Github IssuesFetches the most recently created issues for a GitHub repository, excluding pull requests.APISESSIONSGITHUB2 STEPSREAD ONLY52 ↓09Github Recent Issues Install Uri SmokeLists recent issues for a GitHub repository and verifies the published install command.APISESSIONSGITHUB2 STEPSREAD ONLY48 ↓10List Linear IssuesLists Linear issues with an optional workflow-state shortcut or a raw GraphQL IssueFilter JSON object.APISESSIONSLINEAR4 STEPSREAD ONLY45 ↓11Github Authored Issues ReportLists up to 1,000 issues authored by a GitHub user and verifies completeness against GitHub's search total.APISESSIONSGITHUB6 STEPSREAD ONLY41 ↓12List Git Worktrees With Pr StatusList a local repo's git worktrees with source size (excluding target/node_modules/.git build & dependency dirs so it fits the per-step time budget), dirty/clean status, and the linked GitHub PR for each (branch match for attached worktrees, head-sha match for detached), scanning the most-recently-updated PRs.APISESSIONSGITHUB3 STEPSREAD ONLY39 ↓13Fetch Stripe Payables ReceivablesFetches Stripe charges and payouts for a calendar-date range with transaction details and currency totals.APISESSIONSSTRIPE5 STEPSREAD ONLY39 ↓14Summarize Stacked Github PrsBuilds the complete GitHub pull-request stack rooted at a bottom PR, explains every PR from the user's point of view, and renders the branch relationships as Mermaid.APISESSIONSGITHUB3 STEPSREAD ONLY32 ↓15Elevenlabs Tts MemoSynthesizes text with an ElevenLabs voice and saves the returned audio to a local file.APISESSIONSELEVENLABS3 STEPSREAD ONLY31 ↓16Dns Propagation CheckCompares authoritative DNS answers with Cloudflare, Google, and Quad9 in parallel, then explains whether a record is consistent, still propagating, misconfigured, divergent, or indeterminate. Authoritative discovery and each public resolver are independent DAG steps, so probes run concurrently, degrade to labeled unknowns instead of failing the play, and the verdict join shows exactly which source said what.ROTE6 STEPSREAD ONLY23 ↓17Play DagParses the rote frontmatter of any play and draws its step DAG in three formats at once — an ASCII layer view for the terminal, Mermaid for anything that renders markdown, and a canonical JSON graph for machines. All three are rendered from one canonical semantic model under a representation-parity contract — ordering edges, value edges with exact jq paths, and for_each fan-out (selector, source, max_concurrency) appear in every complete view, and the only lossy view (the one-line summary) declares itself lossy. Accepts a local path, an owner/name reference, or a canonical https play URI; for URIs it verifies the signed-in identity, checks access, and pulls the play before parsing. Distinguishes ordering edges (depends_on) from value edges (@step refs with exact jq paths) and computes the parallel execution layers the runner will use. Its own four-step DAG demonstrates every edge kind it visualizes.ROTE4 STEPSREAD ONLY21 ↓18Cloudflare List ResourcesLists Cloudflare registered domains, Workers scripts, and Pages projects for a supplied or automatically discovered account.APISESSIONSCLOUDFLARE8 STEPSREAD ONLY21 ↓19Whale Flow MonitorMonitor whale accumulation on Polymarket. Combines the public Gamma API (market metadata, pricing) with the public Data API (holders, leaderboard) to identify markets where top-performing traders are building positions, flagging whale clustering and smart-money flow signals. Migrated to the steps DAG form: market discovery and the trader leaderboard fetch run in parallel as independent roots, per-market holder fetches fan out from discovery, and the correlation join cross-references holders against the leaderboard — each source degrades to a labeled unknown instead of failing the play.ROTE4 STEPSREAD ONLY19 ↓20Cloudflare Worker DetailsLists Cloudflare Workers with settings, bindings, routes, and optional deployment history for an account or one script.APISESSIONSCLOUDFLARE6 STEPSREAD ONLY19 ↓21Process Only Play Run VerificationRuns a portable local printf process and returns its captured stdout, proving process-only registry plays execute through rote play run.ROTE1 STEPSREAD ONLY12 ↓22Hacker News Browser Top StoriesBrowse the public Hacker News front page in an isolated headless browser and return the top story links.BROWSERSHELL3 STEPSREAD ONLY12 ↓23Website Launch ReadinessChecks a public website launch across DNS, HTTP, TLS, security headers, essential metadata, robots, sitemap, and optional local Lighthouse scores. Each probe family is its own DAG step in a four-layer graph, so DNS and the page fetch run in parallel, TLS/robots/sitemap/Lighthouse fan out from the fetched final origin, any single probe degrades to a labeled unknown instead of failing the play, and the readiness join shows exactly which probe said what.ROTE8 STEPSREAD ONLY11 ↓24Package Name SearchChecks candidate package names across npm, PyPI, and crates.io in parallel, then ranks names by likely availability without claiming publish guarantees. Each registry is its own DAG step, so probes run concurrently, an unreachable registry degrades to labeled indeterminate rows instead of failing the play, and the ranking join shows exactly which registry said what.ROTE5 STEPSREAD ONLY11 ↓25Dependency Vulnerability CheckRecursively discovers common dependency lockfiles, checks pinned package versions against OSV per ecosystem, and returns deterministic findings with fix versions and novice-friendly guidance. Discovery, the six per-ecosystem OSV queries, detail enrichment, and the report join are separate DAG steps, so ecosystem queries run in parallel, empty ecosystems skip with a label, failed detail lookups degrade to labeled minimal findings, and an interrupted run resumes at the failed stage without re-parsing lockfiles.ROTE10 STEPSREAD ONLY11 ↓26Registry Play InventoryLists every public Play owned by organizations visible to the current authenticated Rote profile, ranked by current-version lifetime downloads and grouped by organization.ROTE2 STEPSREAD ONLY10 ↓27Provider Outage TriageCorrelates direct DNS, TLS, and HTTP checks with official provider status feeds to classify whether a failure is likely in the application, network, DNS, TLS, or an upstream provider. The direct checks form a dependency chain (TLS needs DNS, HTTP needs both) while the status feeds probe in parallel, every source degrades to a labeled unknown instead of failing the play, and the correlation join shows exactly which observation drove the classification.ROTE6 STEPSREAD ONLY10 ↓28Weather Updates For CitiesReports current temperatures for a single editable station list, includes wind for the reference station, emits a threshold alert, verifies a live page headline, and captures Python toolchain provenance.APIBROWSERSHELLSESSIONSOPEN-METEO8 STEPSREAD ONLY8 ↓29Agent Work Daily CloseAudits recent Codex, Claude Code, and Pi sessions for redacted credential exposure, normalized tool use, cross-session lineage, Git closure, and token-to-outcome attribution.ROTE5 STEPSREAD ONLY8 ↓30Startup Equity HealthComputes startup equity-health metrics for a private company and explains them for a prospective employee: capital efficiency (total raised / ARR), valuation multiple (valuation / ARR), liquidation preference stack share (raised / valuation), an acquisition payout waterfall across exit prices, post-lockup IPO scenarios, and an after-tax take-home (earn-out) estimate reflecting vesting cliff, 409A strike cost, and blended federal+state taxes — ending with the questions an employee should ask the employer. Each computation stage is its own DAG step with explicit value edges (the derived metrics flow from core_metrics into the waterfall, IPO, and take-home stages), so every intermediate number is inspectable per step. The invoking agent elicits the financial inputs from public web coverage before calling, and passes provenance via the sources parameter.ROTE6 STEPSREAD ONLY7 ↓31Second OpinionCross-examines one AI coding assistant's answer with a different assistant. Asks the first for a conclusion plus reasoning, gives the second the original question, the same material and the first answer, and asks whether it holds up and which single claim it would challenge first. Leads with the disagreement, then the verdict, then both reasonings. Refuses to run both roles as the same assistant.ROTE4 STEPSREAD ONLY7 ↓32Email Domain ReadinessChecks an email domain for MX, SPF, DMARC, optional DKIM, MTA-STS, TLS-RPT, CAA, and DNSSEC readiness without claiming inbox placement. Every record family is its own DAG step, so the eight probes run in parallel, any single lookup degrades to a labeled indeterminate instead of failing the play, and the readiness join shows exactly which record said what.ROTE10 STEPSREAD ONLY7 ↓33Domain Provider SearchChecks domain registration evidence with authoritative RDAP and DNS, then ranks registrar providers with a transparent feature matrix. No provider login or API key is required.ROTE1 STEPSREAD ONLY7 ↓34Search NotionSearch Notion workspace pages for a topic and summarize the most relevant hits.APISESSIONSNOTION-MCP2 STEPSREAD ONLY6 ↓35Property Public Record Quick ScanBuilds a provenance-preserving public-record evidence pack for a Texas or Miami property from one address, then identifies early acquisition risks and evidence gaps.ROTE1 STEPSREAD ONLY4 ↓36Evaluate Agentic Web SearchEvaluates final agent answers across isolated web-search arms with strict pilot and publication gates, traceable grading, human audits, confidence intervals, statistical ties, and Pareto reports.ROTE14 STEPSREAD ONLY3 ↓37Friction Free City Micro AdventureBuilds a realistic low-friction micro-itinerary for a city from available time, budget, mobility, weather tolerance and interests. Resolves the city, reads live forecast and air quality, ranks candidate venues by geodesic travel feasibility, verifies venue pages in a browser, and reports a scheduled plan with budget totals.APIBROWSERSHELLSESSIONSOPEN-METEOOPEN-METEO-AIR-QUALITYOPEN-METEO-ELEVATIONOPEN-METEO-GEOCODING18 STEPSREAD ONLY3 ↓38Seller Narrative Cross ExaminerCross-examines seller and listing claims against independently sourced property, association, permit, insurance, legal, and market evidence; labels each claim supported, mixed, unsupported, or unverified and converts gaps into document requests and offer protections.ROTE2 STEPSREAD ONLY3 ↓39Condo Buyer DiligenceEducates a prospective U.S. condo buyer from an address or area, purchase price, and intention. Runs public-source location and market checks in parallel, calculates mortgage and ownership scenarios, labels evidence quality, and returns a novice-readable report plus JSON.ROTE8 STEPSREAD ONLY3 ↓40Offer Strategy Decision RoomSynthesizes exit liquidity, assessment exposure, seller-claim reliability, adjusted comparables, and micro-market scenarios from one provenance-preserving evidence pack into a bid ceiling, contingency package, evidence requests, and explicit walk triggers.ROTE2 STEPSREAD ONLY2 ↓41Micro Market Future State SimulatorSimulates bear, base, and bull micro-market states from supply pipeline, absorption, insurance and tax pressure, employment, climate exposure, and local planning evidence to identify the variables that can break an acquisition thesis.ROTE2 STEPSREAD ONLY2 ↓42Exit Liquidity Buyer Pool CompressorMeasures how financing, warrantability, inventory, days-on-market, and sale-to-list evidence compress the future buyer pool for a Texas or Miami property; returns a resale-liquidity tier, pricing haircut range, contingencies, and walk triggers.ROTE2 STEPSREAD ONLY2 ↓43Comparable Sale Reality AdjusterRe-underwrites comparable sales for recency, distance, condition, floor or view, HOA burden, distress, and financing quality to produce an evidence-weighted value range and offer adjustment for Texas and Miami properties.ROTE2 STEPSREAD ONLY2 ↓44Assessment Bomb ForecasterForecasts low, base, and high per-unit special-assessment exposure from reserves, known projects, deductibles, insurance trends, and structural or milestone obligations for Texas and Miami acquisitions.ROTE2 STEPSREAD ONLY2 ↓45Hackathon Submission ReadinessAudits a repository the way a hackathon judge reads it: cold, on a deadline, unwilling to debug someone else's setup. Six probe families run as parallel DAG steps (README cold-open, credentials, secret shapes, repo hygiene, TODO density, demo-path fragility), any single probe degrades to a labeled indeterminate instead of failing the play, and the readiness join reports blockers, risks and what it deliberately did not check. The cold-open probe resolves every fenced README command against what the project actually defines, catching the paste that dies on a judge's first try, and the credentials probe separates environment variables read with a fallback from those read without one, because only the second kind stops a run on a machine that has none of them set. Read-only: never writes to the audited repo, never runs its build, carries no credentials, needs only python3 and git.ROTE8 STEPSREAD ONLY19 ↓46Ci Test HealerAutonomous Universal Cloud LLM CI/CD Failure Diagnoser & Self-Healing Repair Play for Node.js, Go, Python, Rust, and MakeROTE4 STEPSREAD ONLY18 ↓47Git History Secret ScanFinds credentials that live in git history, not just the working tree. Deleting a .env and committing does not remove it: every blob ever committed stays reachable, and a hackathon repo is usually made public at submission time. Three independent stages run as parallel DAG steps (history blob scan across every ref, env files that were ever committed, and and whether the repository it is pushed to is actually public, asked of your own gh session rather than assumed from the host), then one join weighs each finding against that exposure. A stage that cannot complete becomes a labeled indeterminate rather than a silent pass, and every report states how many objects it actually walked, because a partial scan and a clean repository must not read the same. Read-only: never rewrites history, never mutates the repository. It makes no network call of its own: the one optional lookup shells out to your existing gh login, and when gh is missing or logged out the report says the visibility was not resolved and why, rather than guessing either way.ROTE5 STEPSREAD ONLY18 ↓48Playoffs StandingsLive standings for the Modiqo public Play registry: total plays and owners, top-N by lifetime downloads, everything published in the last H hours, and per-owner aggregates. Every run also compares itself against your last run and shows what changed since then -- plays that newly appeared (with age), the biggest download gainers, and any references that vanished; the first run just saves a baseline. Set author to track one publisher's own plays with rank, downloads, and delta. Fetches the live endpoint with retry and falls back to the cached feed with a labeled warning instead of failing (urllib chokes on this CDN's chunked responses; the proven path is curl --compressed). Read-only against the registry; saves only a small snapshot under its own run workspace so the next run can show you what changed. Plays are tracked by owner/name across version bumps: a bump shows as UPDATED, never as one play GONE plus one NEW, and the saved baseline keeps each play's high-water download count so the registry's ~10-minute feed cache can never fake a gain. No credentials, no browser; needs only python3 and curl.ROTE2 STEPSREAD ONLY13 ↓49Reach CheckSee what a Play actually reaches on this machine before you publish it or run it. rote play inspect shows what a Play declares and resolves those declarations against your host. This reads the step bodies themselves, follows sh -c, python3 -c and @resource files, and reports the executables, imports, adapters, browser steps, environment variables and writes they really touch, together with which of them are missing here. It also flags argv paths that point at a user home directory or do not resolve here, which is how a published Play ends up running only on its author's machine. It never runs, imports or pulls the Play it reads, and it writes nothing. The one subprocess it runs is rote play inspect, to report rote's own verdict beside this one, and offline=true skips it.ROTE3 STEPSREAD ONLY11 ↓50Audit PlayCompares the grants an agent was given with the tools it used. By default it looks at every project on this machine. It reads the harness config for MCP servers, rote adapters and play dependencies, the policy files for allow and deny rules, and the transcripts for every tool call and its result. It reports grants never used, tools used without a rule, unused write grants, idle servers, and blocked requests, then proposes a review only least privilege profile. Read only, no network, python3 only. It never revokes anything.ROTE5 STEPSREAD ONLY11 ↓51Ci Self HealerAutonomous Universal Cloud LLM CI/CD Failure Diagnoser & Self-Healing Repair Play for Node.js, Go, Python, Rust, and MakeROTE4 STEPSREAD ONLY10 ↓52Web Game Build ReadinessChecks whether a web game build will run on someone else's machine, before you upload it. Five probe families run as parallel DAG steps (entry point, asset case and existence, machine-local references, engine companion files, build weight), any single probe degrades to a labeled indeterminate instead of failing the play, and the join reports blockers, risks and what it deliberately did not check. The asset-case probe resolves every reference in your HTML, JS and CSS against the exact filename on disk: macOS and Windows ignore case, so a build requesting Player.png when the file is player.png loads perfectly for you and 404s on a Linux host. Read-only: never writes into the build, never launches it, carries no credentials, needs only python3.ROTE7 STEPSREAD ONLY10 ↓53Floor CheckSee the lowest Python version your code will actually run on, before someone on an older interpreter finds out for you. Syntax checks and linters read code that parses; they say nothing about code that parses and then raises. A union annotation like "int | None" compiles on 3.9 and throws TypeError the moment the module is imported, and "import tomllib" compiles and then fails to find the module. This reads the source with ast, finds both classes, and compares what the code needs against what the project declares in pyproject.toml, setup.cfg or deps.toml. It never imports, executes or pulls anything it reads, it writes nothing, and it runs no subprocess at all.ROTE2 STEPSREAD ONLY9 ↓54Play Quality DoctorDiagnoses why a play scores what it does on the registry quality rubric, then derives the exact frontmatter to fix it. 67 of the 119 scored plays in the registry sit at the 0.45 floor, and the rubric that puts them there is not documented anywhere an author would look: two of its signals are lost by declaring the right thing under the wrong key, so plays that genuinely ship fixtures and genuinely parametrize still score zero. This asks the registry's own scorer for the authoritative number, reads the target's real content in a parallel step, and joins the two into one block per failing signal. Every generated fix comes from the play itself: fixtures from the files that exist on disk, the output schema from the keys really passed to out.result(), tags from the taxonomy the registry actually uses. A fix it cannot derive is named as underivable with the reason, never guessed, because a plausible wrong fix costs you more than an admitted gap. Read-only: never edits the play it grades, needs no credentials, makes no network call.ROTE4 STEPSREAD ONLY9 ↓55Git HygieneThe cleanup nobody wants by hand. Audits a git repo for stale branches, unpushed work, dirty worktrees, merged-but-not-pruned branches — one sweep with a safe prune mode behind the apply=true gate. Read-only by default; writes only on explicit opt-in. ROTE5 STEPSREAD ONLY9 ↓56LocAudit repository lines of code, file counts, comment lines, and language percentage breakdowns.ROTE4 STEPSREAD ONLY8 ↓57HeadhunterEvery job scored with the evidence quoted back at you, a status column that is never overwritten, and a first run that works with zero setup. Headhunter sweeps HN Who's Hiring, YC companies hiring on HN, and the SimplifyJobs intern and new-grad lists daily, scores every listing against your CV or an agent-built weighted profile, and merges into a living CSV plus an .xlsx twin (new rows highlighted, built stdlib-only). Finds the newest thread itself; vanished listings are marked stale, never deleted; salary reported only when the listing states it; junior profiles never drown in senior-only roles. Columns include india-location and visa-sponsorship flags. Three-stage design: your agent builds a weighted profile once (resources/profile-prompt.md), the play hunts deterministically, your agent re-ranks over the companion handoff file (resources/rerank-prompt.md). If an optional source is down the run degrades to a warning, never a dead run. Writes the CSV at csv_path, the xlsx twin, a .handoff.json beside the CSV, and ~/.headhunter.json which remembers your cv_path so bare reruns stay personal. A first run with no CV is clearly labelled a demo run and writes to -demo files instead, so the sheet you keep real applications in stays untouched until you point it at a real CV. Warns when a profile is older than 30 days. No adapters, no credentials, no keys; needs only curl and python3.ROTE7 STEPSREAD ONLY8 ↓58Sweep Git ReposSweeps one folder of git repos and tells you what changed since the last time you looked. It lists uncommitted work, commits you never pushed, branches that fell behind upstream, and repos that appeared or disappeared. It also warns if a .env or key file was ever committed (it shows the path and commit, never the contents) and if anyone committed under an email that is not yours. It only reads your repos and never writes to them. It needs python3 and git, no credentials, and no network. The first run saves a baseline.ROTE5 STEPSREAD ONLY8 ↓59Hackathon Portfolio TriageRanks every hackathon entry you have open by which one will cost you an entry first. Reads a manifest of name, repo and deadline, fans out one readiness audit per repository as its own parallel DAG step, then joins deadline pressure against unresolved findings. A clean entry never outranks a broken one however close its deadline, because a clean entry needs no work. A repository that cannot be audited becomes a labeled indeterminate rather than a silent pass, and an entry whose deadline has already passed is listed rather than dropped. Answers what to fix next, not how long is left. Read-only: never writes to an audited repo, never runs its build, carries no credentials, needs only python3 and git.ROTE3 STEPSREAD ONLY8 ↓60Git Handoff SnapshotCreates a compact Git handoff with branch, upstream ahead/behind, HEAD, changed paths, numstat diff statistics, stash count, and recent commit metadata without reading file contents or patch hunks.ROTE7 STEPSREAD ONLY8 ↓61Ship RecapYou've been heads-down building all day and haven't posted a word. Ship Recap reads your last 24 hours of commits and Claude Code or Codex transcripts, finds the moment worth telling, and drafts the X and LinkedIn posts with an illustration, on one page on your own machine. It never posts, and every filename and number in a draft traces back to something that happened.ROTE9 STEPSREAD ONLY8 ↓62New Developer Repo NavigatorCreate a practical starting guide for a local repository. It identifies stack signals, likely application, test, database, and documentation entry points, plus declared setup and test commands. Read-only: it never runs setup commands, reads secret values, or modifies files.ROTE1 STEPSREAD ONLY8 ↓63Agent Resource AuditReports every agent-related process running on THIS machine right now -- Claude Code, Codex, Cursor and Windsurf helpers, Copilot, Aider, opencode, gemini-cli, MCP servers, codex-companion, and rote play or proc child processes -- grouped into harness-cli, desktop-app, mcp-server, companion, known-daemon, or helper, each with its resident memory, CPU percent, and age, ranked by memory alongside the total agent memory footprint against total system RAM. Two roots enumerate the process table and read total RAM in parallel, then one join step classifies and ranks. A process is only ever labeled orphan-suspect under a conservative rule -- reparented to launchd (ppid 1), agent-shaped (harness-cli, mcp-server, or companion), and running more than ten minutes -- never a certainty, and known daemons and desktop-app helpers are excluded from that label outright. The only signals collected are pid, ppid, resident memory, CPU percent, elapsed time, and the first 200 characters of the command line, plus (for the sessions join below) a Claude Code session id when one is disclosed in the process own argv -- never environment variables, never file contents. Nothing is ever killed or signaled: an orphan-suspect prints its kill command as text under an explicit note that nothing was executed, for you to read and run yourself. A third root step lists agent SESSION files on disk across harnesses -- Claude Code and Codex to start -- one row per session with harness, session id, started time, and last-interaction time, joined against the same process table by the session id a running Claude Code process discloses in its own argv, in either of two verified shapes (--session-id <uuid>, or --resume=<uuid> for the VS Code extension in-place-resume shape), to classify each as running-active, running-idle, or resumable (no matching process), with pid, resident memory, and CPU percent attached for the running ones, a totals line summarizing how many are running versus resumable and how much memory they hold, and idle_minutes / max_age_days / harness parameters. Codex sessions cannot be joined to a process the same way -- its own process arguments carry no equivalent session id -- so every codex session is reported honestly as resumable, with a separate note only when a codex process is detected running at all. Session files are listed by stat metadata only (name, birth and modified timestamps) -- their contents are never opened, the same trust line as every other step here. Advisories for idle or resumable sessions -- an exit-and-resume suggestion, or the resume command itself -- are printed as text only, exactly like the orphan-suspect kill hints above: nothing here is ever executed on your behalf. Read-only, no credentials, no network; needs only python3.ROTE4 STEPSREAD ONLY7 ↓64First IssueFinding an issue labelled "good first issue" is easy; GitHub search does it. Knowing which ones are not traps is the hard part, and that is what this scores. Every candidate is filtered at the search index for unassigned, no linked pull request, live repository, and a short comment thread, then ranked against your own weighted skill profile with the matching evidence quoted on each row. The repositories behind your top matches are checked for real activity, so an issue in an abandoned or archived project is flagged rather than recommended, and the top picks are spread across projects so one prolific repo cannot fill your whole list. Red flags are shown, never scored away: a busy thread that may already be claimed, a stale issue freshly bumped, a reporter who is not a maintainer, an issue too thin to start without asking. Honest limit: it does not read comment threads, because that costs one API call per issue and would break the keyless budget, so an issue with a couple of comments may still be quietly taken; the companion re-rank prompt has your agent confirm the top few. Reads the public GitHub API with plain GETs and writes exactly two files: it creates and merges the CSV at csv_path, where your status column is never overwritten and issues that disappear are marked stale rather than deleted, and it writes a .handoff.json beside that CSV for the final agent pass. It changes nothing on GitHub and never comments, claims or opens anything. Runs cold with a bundled demo profile. No adapters, no credentials, no keys; needs only curl and python3.ROTE4 STEPSREAD ONLY7 ↓65Play PreflightWe preflighted all 161 public Plays in the registry. Every one returns a contract rote marks not fully resolved, and every one reports write_permissions as an empty list. An empty list reads like a guarantee. It only means nobody asked. Preflight tells you what a Play will carry, require and attempt before you grant it process access. It reads rote's own contract via play inspect --json, rehearses the run with rote's non-executing resolver via play run --dry-run, and scans the package itself for captured secrets, hardcoded author paths, and symlinks that escape it. It never executes the target Play, and it does not reimplement rote's contract logic. It asks rote. Run it with no arguments to watch it catch a bundled compromised sample, then point it at anything you are about to trust. Full registry findings ship in the package as REPORT.md. Effect disclosure: rote owns its own installation, workspace and backup behaviour, and running any Play may create rote run workspaces, logs and artifacts. With fetch=true this Play additionally asks rote to download a package, which may create package, lock and backup entries under ~/.rote/flows. It passes --no-deps, so no dependency is installed. With fetch=false Preflight does not invoke rote registry play pull at all. Rote has no frontmatter field for a filesystem effect, so none of this can appear in write_permissions, which records adapter mutations only.ROTE1 STEPSREAD ONLY7 ↓66Repo Fire CheckOne screen. Zero credentials. Is anything on fire in my repos today? A deterministic local-git fire alarm for up to 20 clones: unpushed commits, dirty worktrees, unresolved conflicts, CI and review state, lockfile rot, stale branches. Fixed seven-row checklist, one health score, day-over-day delta and streak. Day one already has yesterday in it: with no saved history the play reconstructs yesterday's card from git itself (commit dates, branch ages, lockfile mtimes), so the very first run reports real movement instead of an empty baseline, and names the rows it could not reconstruct. Finds your clones automatically -- no ~/src convention required -- and a scan that reached zero repositories reports UNKNOWN, never a perfect score. No LLM anywhere: identical repo state produces an identical card. Reads your repositories with plain git (strictly read-only); the optional gh CLI upgrades CI and review rows and degrades silently to a cached snapshot without it. Writes only its own state, listed by path, mode and reason in the play source (write_permissions): one append-only history line (~/.rote/fire-check/history.jsonl) and a CI snapshot cache; pass record_history=false for a fully read-only run. macOS and Linux only (Windows unsupported). Requires git and python3; gh optional. Pass demo=true to run bundled deterministic fixtures with a [DEMO] badge.ROTE8 STEPSREAD ONLY7 ↓67Women Safety Sos AlertReal-time emergency women safety SOS alert and community dispatch broadcast.ROTE1 STEPSREAD ONLY6 ↓68Git Handoff ProofChecks whether the command that passes in your workspace also passes at the exact commit you're about to hand off—on the same machine, in a temporary linked worktree.ROTE5 STEPSREAD ONLY6 ↓69Submission Survival CheckCheck your coding assignment before your professor does. Finds missing required files, undeclared dependencies, hardcoded local paths, broken run instructions, suspicious submission clutter, and machine-specific assumptions that can turn 'works on my laptop' into a zero. Read-only: never executes student code or reads secret values.ROTE1 STEPSREAD ONLY6 ↓70Works On My Machine InvestigatorFind hidden environmental assumptions behind software that works locally but fails in CI or on another machine. Compares declared runtimes, lockfiles, environment-variable names, CI, Docker, scripts, tooling, and case-sensitive imports. Read-only: never executes project code, reads secret values, modifies files, or contacts services.ROTE1 STEPSREAD ONLY6 ↓71Incident Time MachineReconstruct a local Git timeline around an incident time. It lists nearby commits, changed areas, and plausible triggers while preserving uncertainty. Read-only: no remote, deploy, CI, or repository mutations occur.ROTE1 STEPSREAD ONLY6 ↓72Claim Vs Reality AuditorAudit repository-change claims against local Git evidence. It classifies claims as VERIFIED, CONTRADICTED, UNPROVEN, or NOT CHECKABLE without running tests or changing files.ROTE1 STEPSREAD ONLY6 ↓73Playoffs ScaffoldingUniversal AI Pattern-Aware & Self-Healing Feature & API Scaffolder for Node.js, Go, Python, and RustROTE4 STEPSREAD ONLY6 ↓74Release Notes From Tag RangeRelease notes from a tag range on a public GitHub repo: categorized changelog, evidence map, and validation counts. Unauthenticated GitHub REST only, strictly read-only.ROTE1 STEPSREAD ONLY6 ↓75Environment Drift DetectiveFind likely environment configuration drift across a local repository. It compares environment-variable names, Node-version signals, and documented ports in README, example env files, Docker, Compose, CI, and source references. Secret values are never inspected or printed; results are static evidence, not deployment validation.ROTE1 STEPSREAD ONLY6 ↓76Test Gap MapperMap a local Git change to likely corresponding test areas. It compares changed production paths with test filenames and directories, flags plausible gaps, and recommends a safe test-review order. Read-only: it never executes tests, edits files, or claims coverage is complete.ROTE1 STEPSREAD ONLY6 ↓77Bug Reproduction InvestigatorTurn a bug report into a grounded repository investigation plan. It matches the report against filenames, source text, and test names; suggests a minimal reproduction path; and labels missing runtime evidence explicitly. Read-only: it never executes the application, tests, or network calls and never changes files.ROTE1 STEPSREAD ONLY6 ↓78Stale Documentation DetectorFind documentation references that no longer match a repository. It cross-checks documented commands, files, directories, environment examples, and Node requirements against local project evidence, then ranks potential stale references. Read-only and bounded: it never edits docs, runs commands, or contacts external services.ROTE1 STEPSREAD ONLY6 ↓79Git Worktree Safety SnapshotCheck whether a local Git worktree is safe to hand off or switch away from. It reports local changes, detached-HEAD state, upstream availability, and known divergence without contacting a remote. Read-only: no files, branches, stashes, commits, fetches, or pushes are changed.ROTE1 STEPSREAD ONLY6 ↓80Git Change Review PlannerPlan a focused review for local Git changes. The Play verifies a base revision, compares it with HEAD, groups changed paths into review areas, and returns targeted checks. Read-only: it never changes the repository, fetches, pushes, or contacts a remote.ROTE2 STEPSREAD ONLY6 ↓81Ai Code Change Risk GateClassifies the engineering risk of a code change by analyzing git diffs for high-risk patterns in auth, payments, security, and infrastructure.ROTE16 STEPSREAD ONLY5 ↓82Context Compaction OptimizerAnalyze context load, predict compaction, assess information loss risk, recommend offloadsROTE1 STEPSREAD ONLY5 ↓83Pre Submission GateOne decision and one ordered fix queue for a repository you are about to submit, joined from four independent audits rather than four reports to reconcile by hand at 2am. Credentials reachable from git history, whether the project location breaks its own build, how the repository reads to a judge opening it cold, and whether a web build inside it loads anywhere else, all run as parallel DAG steps. This is a join rather than a wrapper, because three things only become possible once the answers sit together: the same underlying fact surfacing in two audits collapses to one problem with both sources named, so the queue counts problems rather than mentions; severities that were never comparable across audits get one order, with a published credential first because it cannot be taken back and a location that breaks your build next because it blocks every other fix; and a dimension that did not answer is carried as unanswered rather than silently counted as clean, so the gate refuses to say SHIP when it did not look. A repository with no web build reports that dimension NOT APPLICABLE, which is a reading and is labelled differently from unanswered. Read-only throughout: every audit reads, none executes, nothing is written, no credential is carried and no network call is made.ROTE6 STEPSREAD ONLY5 ↓84Hackathon RadarWhat opens, what closes tonight, and what changed since yesterday - one digest, zero setup. Sweeps Devpost, Devfolio, Unstop and MLH every morning, sorts strictly by soonest deadline, and puts a countdown on every row. Prizes and dates appear only when the source states them: a listing with no cash pool says how many non-cash prizes it has instead of claiming zero, and nothing is converted between currencies. Remembers what it showed you, so later runs mark what is genuinely new instead of repeating yesterday. The same event cross-listed on two platforms collapses into one row that says where else it appears. Every source reports its own health in a footer, and a source that is down costs you that source, never the run. Writes a markdown digest at out_path and its memory at state_path; optional place filter narrows to a city or country. No adapters, no credentials, no keys; needs only curl and python3.ROTE5 STEPSREAD ONLY5 ↓85Why Is Ci Mad At MeCorrelate a CI failure log with a local repository diff, workflows, runtime signals, dependencies, and relevant paths. Separates evidence from hypotheses and never runs code or contacts CI.ROTE1 STEPSREAD ONLY5 ↓86New Repo SpeedrunTurn unfamiliar-repository archaeology into a short starting guide: purpose signals, directories, entrypoints, declared tests, setup clues, and environment contracts. Read-only.ROTE1 STEPSREAD ONLY5 ↓87Pr Review Me FirstReview a local Git diff before opening a PR. Flags debug leftovers, unfinished markers, configuration/API risk, unrelated scope signals, test evidence gaps, and reviewer questions. Read-only.ROTE1 STEPSREAD ONLY5 ↓88Dependency WhyExplain why a dependency appears to exist by searching manifests, imports, configs, scripts, and static usage. Read-only and explicit about unknown or dynamic usage.ROTE1 STEPSREAD ONLY5 ↓89Test TheaterRead-only ast audit of a Python test suite, joined with git history. CANNOT_FAIL marks tests that provably cannot fail - every assertion is on literals, or every assertion sits inside a try that swallows it. NO_VALUE_CHECK marks tests with no assertion anywhere. WEAK marks permanently-skipped and duplicate-body tests. Everything else stays NOT_ANALYZED, because a test is never labelled good. Resolves assertions delegated to same-file helper functions, ignores functions merely nested inside a test (route handlers, CLI commands), and treats mock assert_called_with as a real assertion, so a suite is not libelled for asserting somewhere the parser did not look first. Recognises pytest assert, unittest self.assert*, and async tests. Every finding carries the commit and age of the line that introduced it; a shallow clone reports as such rather than giving every line one meaningless date. Pass base_ref such as origin/main to get a per-pull-request gate - findings are then split NEW_IN_BRANCH from PREEXISTING and only what this branch introduced is listed, with anything unattributable left GIT_INDETERMINATE rather than blamed on the branch. Never imports or executes the suite under audit - only ast.parse touches it. Zero credentials, python3 and git only.ROTE2 STEPSREAD ONLY5 ↓90What Can I SkipCreate risk-aware exam triage from syllabus topics, days remaining, and optional weighting supplied by you. Separates must-understand, high-value next, quick wins, and deferrable work without pretending to guarantee grades.ROTE1 STEPSREAD ONLY5 ↓91Teach Me My Own CodeTeach a project back to its author: map recognizable areas, complex control flow, algorithms, magic values, dependencies, and questions to practice. Read-only and non-executing.ROTE1 STEPSREAD ONLY5 ↓92Assignment To ChecklistConvert messy assignment instructions into deliverables, filenames, formatting, rubric, deadlines, and easy-to-miss constraints, with optional evidence hints from a submission folder. Read-only.ROTE1 STEPSREAD ONLY5 ↓93Where Did I StopRemind yourself what you were building after time away. Reads Git state, unfinished markers, and bounded source signals to propose the smallest next action. Read-only: never executes project code or changes Git.ROTE1 STEPSREAD ONLY5 ↓94Exam Panic PlannerTurn syllabus topics and days remaining into a dependency-first exam plan with realistic practice and postponement guidance. Read-only and uncertainty-aware.ROTE1 STEPSREAD ONLY5 ↓95Wtf Did Professor SayExtract what was taught, emphasized, assigned, and time-sensitive from messy lecture notes, transcripts, slides, or announcements. Read-only text analysis with explicit UNKNOWN states.ROTE1 STEPSREAD ONLY5 ↓96Project Kickoff PageCreates a Notion kickoff page for a repository you are starting work on, seeded with milestones worked out from which project phases that repository has and has not reached. It detects first commit, whether someone else could run it, tests, CI, deploy config and a licence, then schedules only the phases still ahead, back-planning target dates from your deadline. Audit findings are kept in their own section, because a finding with a checkbox in front of it is not a milestone. Two independent readings run as parallel DAG steps, a pure transform composes the page, and one declared adapter step creates it. WRITES: creates exactly one new Notion page per run, at workspace level unless a parent page id is supplied. It never edits, archives or deletes anything that already exists.APISESSIONSNOTION-MCP6 STEPSWRITES5 ↓97Github Shame CleanerWould you send this repository to a recruiter? Perform a read-only portfolio audit for setup clarity, debug traces, TODOs, abandoned files, generated clutter, oversized files, commit-message quality, and exposed-secret indicators without revealing values.ROTE1 STEPSREAD ONLY5 ↓98Tutorial Hell DetectorFind signs that a student project accumulated conflicting tutorials: duplicate approaches, routing systems, stale configs, dead experiments, multiple package managers, and outdated README instructions. Read-only: never executes code or reads secrets.ROTE1 STEPSREAD ONLY5 ↓99Viva Survival ModeExplain your own code before the professor asks. Finds complex functions, architecture signals, dependencies, algorithms, magic numbers, and likely viva questions in a local project. Read-only: never executes code or reads secret values.ROTE1 STEPSREAD ONLY5 ↓100Feature ScaffoldingUniversal AI Pattern-Aware & Self-Healing Feature & API Scaffolder for Node.js, Go, Python, and RustROTE4 STEPSREAD ONLY5 ↓101Agent Instruction Collision MapYour AI agent has too many bosses. Scans AGENTS.md, Cursor rules, CLAUDE.md, and Copilot instructions for conflicts, duplicates, and orphans before any agent work begins. Read-only with path-line evidence.ROTE1 STEPSREAD ONLY5 ↓102Clients FinderSearch freelance platforms (Upwork, LinkedIn, Freelancer, PeoplePerHour, YT Jobs, Workana, job boards) to find clients hiring editors for a given niche and produce a tabular lead listAPISESSIONSEXA-SEARCH8 STEPSREAD ONLY5 ↓103Documentation Contract RefereeReferees executable claims in README files and runbooks against repository evidence: commands, prerequisites, Markdown anchors, package scripts, Make targets, Just recipes, package manager, versions, and environment templates. Returns a compact contract verdict with coverage, evidence, and fixes. Credential-free and never executes copied documentation commands.ROTE4 STEPSREAD ONLY5 ↓104Model Price ScoutCheapest capable model, right now. Fetches live pricing from LiteLLM's public model catalog, classifies by capability tier (flagship / mid / fast / embedding), filters by provider and budget, ranks cheapest-per-M-input- token, and prints a decision table. Read-only, no credentials, no auth. Complements (does not replace) modiqo/hello, which surfaces pricing as one of nine subsystems. ROTE4 STEPSREAD ONLY5 ↓105Auth Security AuditAudits jsonwebtoken and bcryptjs usage across Express auth routes under a source directory: verifies password hashing (bcrypt salt rounds, compare usage, no plaintext storage) and JWT lifecycle (signing expiry, middleware verification, bearer extraction, 401 handling), then emits a security verification checklist plus prioritized recommendations. Process-only, read-only, needs python3.ROTE2 STEPSREAD ONLY5 ↓106Security Sensitive Change ScoutFind local Git changes that deserve additional security review. It classifies changed paths and diff context for authorization, authentication, uploads, cryptography, CORS, and dependency changes, then provides review prompts. It does not claim to find every vulnerability, inspect secret values, or make changes.ROTE1 STEPSREAD ONLY5 ↓107Release Readiness InvestigatorAssess release readiness from inspectable local repository evidence. It checks working-tree state, release documentation, CI and test declarations, dependency or migration changes, and changed modules without obvious tests; then returns GO, CAUTION, or BLOCKED with next checks. Read-only: it never runs tests, changes Git state, installs packages, or contacts services.ROTE1 STEPSREAD ONLY5 ↓108Api Breaking Change DetectorDetect likely public-interface breaking changes in a local Git range. It compares removed and added route declarations, exported function signatures, and exported types, then separates evidence-backed findings from heuristics. Read-only: it never changes Git state, runs tests, or contacts remotes.ROTE1 STEPSREAD ONLY5 ↓109Test Command FinderFind a repository's declared test and quality-check entry points before you run anything. It reads common manifests and Makefiles, returns safe command candidates with their source, and redacts obvious secrets. Read-only: it does not execute commands, install dependencies, or modify files.ROTE1 STEPSREAD ONLY5 ↓110Repository Handoff SnapshotCreate an evidence-backed repository handoff checklist in under a minute. It checks for onboarding, contribution, license, documentation, CI, examples, and build-manifest signals, then highlights gaps a new maintainer should address. Read-only: it never edits the repository or contacts external services.ROTE1 STEPSREAD ONLY5 ↓111Dependency Upgrade Impact MapperEstimate a dependency upgrade's likely blast radius before installing anything. It maps direct imports, indirect mentions, and configuration references for a named package, then returns risk-ranked locations and suggested checks. Read-only static analysis: it never changes dependencies, runs package scripts, or contacts a registry.ROTE1 STEPSREAD ONLY5 ↓112Ci Failure InvestigatorTurn a CI failure log into an evidence-backed investigation brief. It identifies the failing stage, separates primary errors from warnings, extracts file and line evidence, and suggests non-mutating verification commands. Read-only: analyzes one local log and never contacts services or edits files.ROTE1 STEPSREAD ONLY5 ↓113Git Handoff SnapshotCreates a compact Git handoff with branch, upstream ahead/behind, HEAD, changed paths, numstat diff statistics, stash count, and recent commit metadata without reading file contents or patch hunks.ROTE7 STEPSREAD ONLY5 ↓114Dev DoctorSub-second parallel system and dev environment auditorROTE5 STEPSREAD ONLY5 ↓115Clone Repo Into FolderEnsure a base directory exists and clone a git repo into it, skipping the clone if already presentROTE6 STEPSREAD ONLY5 ↓116Weather Station ConformanceCurrent temperature for several weather stations plus a reference station temperature and wind speed, a note when the reference is at or above a chosen threshold, a headline lifted from a live dashboard page, and a record of the host python that produced the reading.APIBROWSERSHELLOPEN-METEO8 STEPSREAD ONLY5 ↓117My Linear IssuesList Linear issues assigned to the current user (assignee=me)SESSIONS0 STEPSREAD ONLY5 ↓118Mcp DoctorIs each of your configured MCP servers healthy, and what should you do about the ones that are not? mcp-context-tax (already published, ours) MEASURES the token cost of what your servers advertise; mcp-doctor DIAGNOSES health and tells you what to do about each one -- two tools, not one tool twice. Five jobs, in order: discovers MCP server configs across installed harnesses on this machine (the same well-known, harness-owned paths as mcp-context-tax -- Claude Code global and per-project mcpServers, Claude Desktop, Cursor, Codex config.toml mcp_servers tables, Windsurf -- never a filesystem walk for stray project .mcp.json files; an unreadable or unexpectedly-shaped config file degrades only that one source, never the whole scan); starts each configured local stdio server in an isolated process group and a minimal allowlisted environment (PATH plus locale/timezone variables only, never this play's own ambient environment) solely for the standard MCP handshake, then terminates that whole process group -- nothing else on the machine is signaled (remote servers are never contacted at all -- this play makes zero network calls of its own, and it does not enforce that a spawned local server won't reach the network on its own, e.g. a launcher fetching a package); classifies every server into exactly one honest state -- healthy, needs-auth, slow-coldstart, unresponsive, config-error, remote-not-probed, or capped -- measuring COLD-START TIME explicitly (monotonic milliseconds from spawn to the first well-shaped initialize response, a real measurement, never an estimate) so a slow uvx/npx first-run download reads as slow, not as a hang; writes a short text-only ADVISORY for every non-healthy server -- what to check or run by hand, never executed by this play, the same house pattern our own mcp-context-tax established; and detects CONFIG DRIFT across those same discovered rows -- the same server name declared in more than one config scope with a different command or args (scope shadowing, where which one wins depends on the harness's own precedence rules) or with an identical definition (a redundant duplicate declaration). Read-only against your configs: only a has_env boolean and the env var NAMES COUNT survive, never a value; a server's command-line argument VALUES are never displayed, only a structural summary (flag names, length-bucketed placeholders) -- an advisory that shows a command line shows only that redacted structural form, never a real argument value. No credentials transmitted beyond that minimal allowlisted environment; needs only python3.ROTE2 STEPSREAD ONLY4 ↓119Mcp Context TaxHow many tokens of your context window do your configured MCP servers consume before you type a word? Five jobs, in order: discovers MCP server configs across installed harnesses on this machine (Claude Code global and per-project mcpServers, Claude Desktop, Cursor, Codex config.toml mcp_servers tables, Windsurf -- only well-known user-level paths, never a filesystem walk for stray project .mcp.json files; an unreadable or unexpectedly-shaped config file degrades only that one source, never the whole scan); sorts each into stdio (local, spawnable) or remote (never contacted -- this play makes zero network calls of its own; it cannot confine a spawned local server that reaches the network on its own, e.g. a launcher fetching a package); starts each configured local stdio server in an isolated process group and a minimal allowlisted environment (PATH plus locale/timezone variables only, never this play's own ambient environment) solely to read its advertised schemas, then terminates that whole process group -- nothing else on the machine is signaled; performs the standard MCP handshake (initialize, notifications/initialized, tools/list, resources/list, prompts/list) against each one inside a bounded per-server timeout, accepting only well-formed JSON-RPC 2.0 replies so a stray log line can't spoof one; and estimates the token cost of what each server advertises from the JSON schema size, chars divided by four, always labeled an ESTIMATE and never a real tokenizer count. Every server lands in exactly one honest bucket: healthy, needs-auth, slow, unresponsive, remote-not-probed, or config-error -- a server that needed credentials this play was never given, or one that refused to spawn at all, is a labeled degrade (a short fixed reason code, never raw child output that could itself echo a credential), never a crash, and a handful of servers legitimately land in each bucket on a real machine. This measures your standing configuration right now, not a recorded trace from some other day -- different from the ideas list, which asks for a token count against a saved transcript. Read-only against your configs: only the advertised tool/resource/prompt schemas and their byte sizes are collected, never environment variable values (only a has_env boolean and the env var NAMES COUNT survive), and a server's command-line argument VALUES are never displayed at all -- only a structural summary (flag names, length-bucketed placeholders); the real values exist only long enough to spawn a server for probing, via a private owner-only-readable file this play never prints. No credentials transmitted beyond that minimal allowlisted environment; needs only python3.ROTE2 STEPSREAD ONLY4 ↓120Commit Attribution GuardScans your recent commit messages for AI-attribution marks you may not have meant to publish -- Co-Authored-By trailers naming an AI tool, "Generated with/by" footers, robot-emoji-plus-tool-name body marks -- before that history goes public. Identity hygiene for commit metadata, NOT a repo audit: commit-history scanning (scan_log) reads commit messages only, never code. The one narrow, explicitly-scoped exception is scan_config's attribution-SOURCE check, which does read commit.template/hook file bytes to test them for a structural match -- but returns only a "class:tool" pattern identifier, never the source text itself, so no hook or template code line ever leaves this play. Five jobs across two layers: validate_repo resolves the repo path (expanding ~, going absolute) and int-guards depth, treating a real but empty repository as a clean pass rather than a failure; scan_log reads git log for the requested depth and classifies every match into exactly one of two structural shapes -- TRAILER, a Co-Authored-By or Signed-off-by trailer (recognized via git's own `interpret-trailers --parse`, so folded/continuation lines and paragraph-eligibility follow git's real rules) whose value names an AI tool, or BODY-MARK, a "Generated with/by <tool>" phrase (tool as direct object, in the commit BODY only) or a robot emoji sharing a line with a tool name -- and never flags a commit that merely discusses AI in prose (a subject like "fix claude integration bug", a quoted mention like `explains why "Generated with Claude" is forbidden`, or a body describing the removal of an old trailer, matches neither shape); scan_config checks attribution SOURCES that could re-inject a mark into a future commit -- a configured commit.template file and prepare-commit-msg/commit-msg hooks -- requiring the same structural match shapes (never a bare tool-name mention), degrading per-source rather than failing, and staying inside the repository: a configured path that resolves (symlinks included) outside the repo's real working directory is reported as out of scope and never opened (user-level ~/.claude settings are also out of scope); the presentation renders a clean bill when nothing is found and otherwise a findings table naming only the sha, the class, and the single matched line for scan_log findings, or the class:tool pattern identifier (never source text) for scan_config findings -- never the full commit message and never any code. Read-only, no credentials, no network; needs python3 and git.ROTE3 STEPSREAD ONLY4 ↓121Repo BloatFinds what makes a git repository permanently expensive to clone. A clone downloads history, not the working tree, so deleting a large file changes nothing about what every future clone pays: the blob stays reachable from an old commit forever. This walks the whole object store with cat-file --batch-check, ranks the biggest blobs by their real on-the-wire size, names the commit and path that introduced each one, and sorts every one of them into current, superseded, or deleted-yet-still-downloaded. Separates bytes reachable from a branch (every clone pays) from bytes only the reflog or a dangling object still holds (local disk only, reclaimed by git gc). Compares pack size against what a checkout actually writes, and lists files still tracked that should have been ignored, including the ones .gitignore already excludes while the index keeps carrying them. Reports the fix honestly: history can only be removed by a rewrite that changes every commit hash. Read-only, contacts no remote, needs only git and python3.ROTE2 STEPSREAD ONLY4 ↓122Pr PreflightAnswers one question before you request review: is this branch actually ready? Checks rebase state against base, flags commits with uninformative messages, reports whether source changes arrived without test changes, and catches uncommitted work that would silently miss the PR. Read-only, no credentials, no writes, needs only git.ROTE5 STEPSREAD ONLY4 ↓123Migration GuardReviews SQL migrations for the operations that take a production database down: index builds that lock writes, column type changes that rewrite the table, constraints added without NOT VALID, and destructive statements with no WHERE clause. Statement-level analysis, so comments and string literals never trigger findings, tables created in the same migration are treated as empty, and the SQLite table-rebuild pattern is recognised instead of flagged. Read-only, never connects to a database, no credentials.ROTE2 STEPSREAD ONLY4 ↓124Hn Launch Reality CheckTells you what a launch post actually gets before you write one, by measuring the current Show HN, Ask HN and front page listings side by side. The front page is the survivors; the median is the outcome, and the gap between them is why launches feel like failures. Three listing calls run as parallel steps, each fans out to fetch its posts individually, and one join reduces them to three distributions. It reports the median, the quartiles and the share that got almost nothing, never a single average, because an average over this data is dominated by a handful of outliers and would tell a founder precisely the wrong thing. It is equally careful about what the numbers are not: these are the posts listed right now, ranked by the site's own algorithm, which is not a random sample of everything ever posted, and the report says so rather than implying a historical median it never measured. A category that fails is reported as not read rather than as zero, and the sample size shown is the number of posts actually fetched rather than the number requested, because a median over 12 posts presented as one over 50 is a false claim about precision. It reads the first 40 posts listed in each category, a width fixed in the play because the fan-out slice takes a literal bound, and the report states the sample it actually achieved. Needs no account, no credential and no key. Read-only: it lists and reads public posts, and writes or posts nothing.APIHACKER-NEWS-API7 STEPSREAD ONLY4 ↓125Outdoor Work WindowNames a place and answers which of the coming days are workable outdoors, judged against thresholds you set, with every rejection stated as a measurement rather than an adjective. Three adapters answer three questions none of the others can: geocoding turns the place name into coordinates, the forecast supplies rain, wind and heat at those coordinates, and a separate air quality service supplies particulates, the two readings running as parallel steps because neither depends on the other. A day counts as workable only when every dimension answered for it: a forecast day with no air quality reading is reported NOT JUDGED and is never counted workable, because a crew scheduled on a day nobody checked is exactly the failure this exists to prevent, and "nothing was wrong" must not render the same as "one source had no reading". Thresholds for rain, wind, heat and PM2.5 are parameters, since a safety policy belongs to the organisation running the work rather than to this play, and every report restates the ones it used so the verdict is checkable. None of the three adapters needs a credential, so it answers on a first run with nothing to sign up for. Read-only: three GET requests to public forecast services, nothing written and nothing stored.APIOPEN-METEOOPEN-METEO-AIR-QUALITYOPEN-METEO-GEOCODING5 STEPSREAD ONLY4 ↓126Market Signal QualityGrades how much weight a prediction market price can actually carry, because a price is only as meaningful as the market behind it. A market showing 80% on fifty dollars of liquidity with a forty cent spread is not an eighty percent forecast, it is noise wearing a number, and a report that prints both at the same size is worse than no report. Two listings run as parallel steps, one ordered by liquidity and one by how soon the market resolves, because the biggest markets and the ones about to settle are different questions and neither answers the other. A join dedupes them and grades every price against stated thresholds for liquidity, 24 hour volume and spread, naming each reason a price is thin rather than reducing it to a label. A listing that fails is reported as unread and the set is called partial rather than presented as everything available. This is a read-only report of figures the venue itself publishes, and it grades their depth, not their accuracy: a well backed market can still be wrong. It is not financial advice, recommends no position, places no order and needs no account or credential of any kind.APIPOLYMARKET-GAMMA3 STEPSREAD ONLY4 ↓127Skill Rot DetectorAgent Configuration Health System: Discover skills and rules across harnesses (Claude, Antigravity, Cursor, Codex, Windsurf), compute Skill Health Scores (0-100), detect duplicate/stale/conflicting rot, perform safe-removal analysis, and visualize context budgets.ROTE1 STEPSREAD ONLY4 ↓128Meeting FairnessStop the same person always taking the 6am call. Evaluates if your recurring meeting time is quietly unfair across timezones, accounting for DST shifts, rotation alternatives, and optional Google Calendar sync.ROTE1 STEPSREAD ONLY4 ↓129ScamcheckScreen suspicious messages for common scam warning signals.ROTE1 STEPSREAD ONLY4 ↓130Hire Candidate With EvidenceBuild a public-GitHub-REST-API candidate evidence report for hiring evaluation across any target role or technology stack.APISESSIONSGITHUB6 STEPSREAD ONLY4 ↓131Play Score FixScore your own Play before you publish it, and get the exact text that fixes what is missing. Runs the real rote scorer rather than guessing, then turns each failing signal into paste-ready frontmatter written against your play's own name and step list. The eight signals are worth fixed points and four of them are pure metadata, so most plays sitting below a full mark are about twenty minutes of frontmatter away from one. Reports the points on the table and orders the work by what is worth most. Reads your play files and writes nothing. Point it at a play, a directory of plays, or the directory you are standing in.ROTE5 STEPSREAD ONLY4 ↓132Token TabYour coding sessions already wrote down every token they used, split four ways across model tiers at different prices, with subagent spend buried in subdirectories. It is unreadable by hand, so nobody reads it. This reads it. You get a table of tokens and list-price equivalent per model, your heaviest sessions with subagent cost broken out, and exactly four waste checks: the same file re-read within one session, a near-zero cache-read rate that means something near the front of your prompt keeps changing and the whole prefix is being re-billed, a subagent that cost real money to make two tool calls, and a run of mechanical edits on a top-tier model. Every finding names its evidence and what to change. Two promises it keeps: the money figure is API list-price equivalent and the report says plainly that it is not a bill, because on a subscription it is not what you paid; and prices come from a bundled table that carries its source URL and an as-of date, so a model missing from it is reported as tokens with the cost left blank rather than guessed. It reads counts, costs and file paths, never prompt text, file contents or tool results. It writes a markdown report at out_path and a claude-md.proposed.diff beside it which it never applies - suggested rules are yours to paste in or ignore. Zero network, so it cannot break when a website changes. Runs cold on bundled demo logs. No adapters, no credentials, no keys; needs only python3.ROTE2 STEPSREAD ONLY4 ↓133Org Public Exposure AuditAnswers one question about a whole GitHub organisation or account: which of our public repositories carry credentials in their git history, and which public repositories did we fail to check at all. The second half is the point. Every scanner reports what it found, but a compliance answer is only usable if it also reports what it never looked at, because "we found nothing" and "we scanned 6 of 84" are different sentences that a summary count silently merges. This refuses to merge them: unscanned public repositories are listed by name with the reason, and the verdict cannot be CLEAN while any remain. It asks GitHub for the inventory and the filesystem for what is reachable as two independent parallel steps, scans the intersection, then joins all three. It never clones anything: fetching an organisation onto the caller's disk is a large surprising write, so the gap is reported instead, which is both safer and the honest answer. The one network call is your own authenticated gh session; this play carries no token and writes none. Read-only throughout: it reads local git history, rotates nothing, and modifies no repository.ROTE5 STEPSREAD ONLY4 ↓134Build Environment TrapsFinds the reasons a build fails that have nothing to do with the code, and that no error message ever names. A project inside iCloud, Dropbox, OneDrive or Google Drive does not report that it is being synced: the sync client fights the build over the same thousands of files in node_modules and the build sits at 0% CPU forever. A file evicted to the cloud does not report that it is a placeholder: it reads as missing or empty. A path with a space in it does not ask to be quoted: a script truncates it and blames a filename nobody asked for. Two tracked files differing only in case do not warn you: the default macOS filesystem silently keeps one, so the working tree stops matching the repository. Four probes run as parallel DAG steps, any one degrades to a labeled indeterminate rather than failing the play, and severity follows evidence, so a synced folder is a risk while a synced folder that already contains a dependency directory is a blocker, because that is the case that actually hangs. Read-only: never writes, never downloads, and never touches a cloud placeholder in a way that would pull it down. Needs python3, and git only for the case check, which is reported as unread rather than clean when git is unavailable.ROTE6 STEPSREAD ONLY4 ↓135Repo Leak DoctorZero-credential local git history and secret auditor for pre-push verification.ROTE3 STEPSREAD ONLY4 ↓136Release NotesShip notes without the guilt. From a git range (two tags/SHAs), compose a categorized changelog draft: commits classified feat/fix/perf/chore/breaking, enriched with authors, rendered as markdown ready to paste — and optionally opened as a draft GitHub release, gated behind apply=true. Demonstrates the authority-boundary pattern: dry-run by default, mutation only on explicit opt-in. ROTE4 STEPSREAD ONLY4 ↓137Pkg VetVet npm/PyPI/crates packages BEFORE installing. Checks OSV advisories, typosquat distance, package age, version count, maintainer signals, and license flags. Returns a deterministic verdict (SAFE / CAUTION / AVOID) with per-source evidence and a stage ledger. Read-only, no credentials. Complements (does not replace) installed-lockfile scanners such as modiqo/dependency-vulnerability-check. ROTE5 STEPSREAD ONLY4 ↓138Env Drift AuditorAudits local .env files against templates without exposing secrets.ROTE4 STEPSREAD ONLY4 ↓139Site StatusChecks the live operational status of GitHub, npm, and Cloudflare using their public status JSON APIs. No authentication required. Read-only HTTP GETs only. ROTE1 STEPSREAD ONLY4 ↓140Kuwahara Dither ImageApplies Kuwahara-filter + ordered (Bayer) dithering to an image, following https://enochchau.com/blog/2022/kuwahara-dithering: downscale, Kuwahara filter, ordered dither + color quantization, nearest-neighbor upscale.ROTE2 STEPSREAD ONLY4 ↓141Audio Semantic ChaptersSplits any audio/video file into semantic chapters as tagged MP3s: transcribes with Whisper, has a model divide the transcript into at most max_chapters sections, snaps each boundary to a quiet point so transitions are smooth, then verifies every cut by re-transcribing the head of each chapter.ROTE8 STEPSREAD ONLY4 ↓142Hackernews Top Stories Local DigestReads the Hacker News front page in a headless browser, fetches each top story's article with curl, and produces per-story summaries plus a themes-of-the-day synthesis using a local LM Studio model. Client-rendered pages are reported as unfetchable rather than guessed at.APIBROWSERSHELLSESSIONSLMSTUDIO6 STEPSWRITES4 ↓143Weather Station UpdatesReports current temperatures for a single editable station list, includes wind for the reference station, emits a threshold alert, verifies a live page headline, and captures Python toolchain provenance.APISESSIONSOPEN-METEO4 STEPSREAD ONLY4 ↓144Session DigestDigests your recent LOCAL agent session transcripts into "what happened while you were away" -- Claude Code transcripts under ~/.claude/projects, plus Codex transcripts under ~/.codex/sessions when present -- into counts only: sessions, duration, tool calls by tool, files edited/written, shell commands run, errors, and token usage totals where the transcript records them. One root step locates transcripts inside your look-back window and packs their paths; two parallel steps then stream each file line-by-line and aggregate -- Claude Code and Codex use different JSONL record shapes across their own versions, so each source gets its own defensive parser that treats an unrecognized record shape as uninformative rather than fatal, and degrades just that one file (never the whole run) on a genuine parse disaster. The presentation body joins both sources into one digest, degraded rows rendered honestly rather than hidden. The trust line is literal: message text, prompt content, and command argv are never read into the output -- shell commands run are a COUNT only, file paths are reported home-redacted, and nothing here is ever quoted back to you, only counted. Inspired by Anthropic's Apache-2.0-licensed receipts plugin; this is an independent implementation against the Python standard library, sharing no code with it. Read-only, no credentials, no network; needs only python3.ROTE3 STEPSREAD ONLY3 ↓145Flake FinderWhich of your CI jobs fail at random? `gh run list` cannot tell you, and not for want of a flag: it prints one line per run carrying a run-level conclusion, so a red run on a 134-job matrix names none of the 134, and nothing in it groups a job across the runs it appeared in. Flakiness is only visible on those two axes at once, per job and across history, which is why every single-run tool walks past it. This play samples recent completed runs on the default branch, where the code is presumably good, fans the job listings out in parallel, and groups every conclusion by job name. A job that both passed and failed there is flaky, reported with its rate and counts; a job that only ever failed is broken, a different problem, listed separately. Cancelled and skipped runs are counted and shown but never scored as failures, because a busy default branch cancels superseded runs constantly and counting those would manufacture flakes that do not exist. A single failure with no passing observation is called unconfirmed rather than broken, and when a run holds more jobs than one page returns the counts say so and call themselves a lower bound. Read-only, one required argument, and no API key beyond the gh CLI you have already signed in to.ROTE3 STEPSREAD ONLY3 ↓146Npm Scripts AuditAudits the npm code that runs without anyone reading it. Two halves, both fully offline: your own package.json scripts (a remote URL piped into a shell, a recursive delete whose target expands at run time or resolves outside the project, a write outside the project directory, a binary no declared dependency provides, npm publish with no prepublishOnly guard) and, the expensive half, every INSTALLED dependency that carries a preinstall, install or postinstall hook. Those hooks execute arbitrary code with your privileges on every npm install, so the play follows each hook command into the package files it actually runs and reports whether the code reaches the network, compiles locally, or does nothing, with the file and line as evidence. No registry call, no API key, no credentials.ROTE2 STEPSREAD ONLY3 ↓147Daily Inbox TriageRead-only inbox triage for Gmail. Classifies a search window from message headers alone into Act now, Act this week and No action, and names every message it could not decide instead of guessing. Urgency is a testable rule, not a vibe: something is urgent only if it states a deadline inside 24 hours or blocks another person. Reads headers only, never message bodies; never writes to your mailbox. Writes one PDF into your working folder each run -- disable with report='. APISESSIONSGMAIL6 STEPSREAD ONLY3 ↓148Unpushed WorkFinds work that exists only on this machine. Scans every git repo under a directory and ranks them by how much would be lost if the disk died tonight: repos with no remote at all, branches never pushed, commits ahead of upstream, uncommitted changes, and forgotten stashes. Read-only, no credentials, no writes, needs only git and python3.ROTE2 STEPSREAD ONLY3 ↓149Ts StrictnessReports what a TypeScript project's compiler settings actually enforce, and what they quietly let through. tsconfig.json is read as the JSONC it really is (comments and trailing commas make plain JSON parsing fail on a large share of real configs), every `extends` is resolved first (a relative file, a directory, or a package name found in node_modules), and `strict: true` is expanded into the flag family it implies, so noImplicitAny is never reported as missing when strict is on, while an explicit `"noImplicitAny": false` alongside `strict: true` is reported as the hole it is. Then it counts the escape hatches in your own source: `any` matched in type position only (never the substring in company, many or anyone, and never a cast quoted in a string or mentioned in a comment) plus @ts-ignore, @ts-expect-error, @ts-nocheck and eslint-disable directives with their file and line. An unresolvable `extends` is reported as undetermined rather than guessed. Read-only, entirely offline, no tsc invocation, no credentials.ROTE2 STEPSREAD ONLY3 ↓150Shell SafetyAudits shell scripts for the mistakes that make them silently do the wrong thing, with shell syntax actually parsed instead of grepped. Finds a missing set -euo pipefail, an unquoted expansion that word-splits a path, a recursive rm on a variable nothing proves is non-empty, a cd whose failure nobody checks, ls output being parsed, an unquoted variable inside [ ], and a pipeline whose exit status reports only its last command. It knows where quoting does not matter, so it does not invent findings: no report inside [[ ]] or (( )), none on x=$y, $#, $?, ${#x} or a word that already contains a deliberate glob, none for the pipefail that POSIX sh does not have, and none demanding set -e in a sourced library where it would change the caller's shell. #!/bin/bash -e counts as errexit, and a function that enables pipefail for one pipeline is judged at that line rather than at end of file. Read-only, never executes a script it audits.ROTE2 STEPSREAD ONLY3 ↓151Hooks Vs CiFinds where the checks on your machine and the checks in CI have drifted apart, which is why a green local commit fails in CI and why a green CI run misses what a hook would have caught. Compares active git hooks, husky, lefthook and .pre-commit-config.yaml against what the workflows actually invoke, normalising on the resolved tool so npm run lint, npm-run-all lint and eslint . count as one check rather than three. Reports checks CI runs that no local hook runs, checks a local hook runs that CI never enforces, tool and runtime version differences between the two, and configured hooks whose tool is not installed here. Ignores .sample hooks because git never executes them, and separates per-commit gates from workflows that only fire on a schedule or a button. Read-only, no network, no CI credentials.ROTE4 STEPSREAD ONLY3 ↓152Frontend State PlannerPlan the complete UI state model for a feature: initial, loading, success, empty, validation failure, API failure, unauthorized, offline, and timeout. Read-only planning only; no network or code generation.ROTE1 STEPSREAD ONLY3 ↓153Json To TypesGenerate a clean inferred TypeScript interface from sample JSON and identify nullable or questionable fields. Inference is explicitly sample-based; no API calls or files are written.ROTE1 STEPSREAD ONLY3 ↓154What Should I AutomateMost of what you repeat is not worth automating, and nothing tells you which part is. A one-day burst of 19 identical prompts is a loop, not a habit; a request you make twice a week for three months is the thing worth keeping. This reads your local Claude Code and Codex transcripts, drops harness-injected noise, clusters near-duplicate requests, attributes the real token cost of each cluster and prices it against the live LiteLLM rate table, then returns a ranked CRYSTALLIZE / NOT YET / DO NOT with the reason for each. It refuses to recommend a burst no matter how many times that burst ran. Honest about its limits: the Play-shape test counts action verbs and enumerated steps as a proxy for 'this is a procedure', so it measures shape rather than meaning; recurrence is activity on two or more separate days, which does not separate a weekly habit from two adjacent days; and the spend it reports is what you already paid, not what crystallizing would save. Reads only local files and one public rate table, writes only inside its own run workspace, carries no credentials.ROTE5 STEPSREAD ONLY3 ↓155Demo Data FactoryCreate a synthetic demo-data blueprint with normal, edge, empty, date, long-text, and error cases from an app schema. Never reads production data or writes files.ROTE1 STEPSREAD ONLY3 ↓156Mock Api From ExampleTurn example JSON or a short response description into a static mock API contract covering success, empty, loading-equivalent, and error responses. It does not start a server or write files.ROTE1 STEPSREAD ONLY3 ↓157Judge Question GeneratorGenerate realistic hackathon judging questions across users, problem, technical choices, differentiation, feasibility, limitations, scale, security, and substantiated value claims.ROTE1 STEPSREAD ONLY3 ↓158Integration Contract MakerDraft a compact frontend-backend contract with endpoint, request, response, status/error cases, ownership, assumptions, and unresolved decisions before teammates code separately.ROTE1 STEPSREAD ONLY3 ↓159Api First CallTurn API documentation or a snippet plus a desired action into a smallest-first request draft with endpoint, method, headers, body, examples, response expectations, and common mistakes. Never exposes supplied secrets or calls the API.ROTE1 STEPSREAD ONLY3 ↓160Review GateDecides whether a pull request is safe to merge, and says exactly what is blocking it. `gh pr view` and every check built on GitHub REST v3 share one blind spot: review-thread resolution (`isResolved`) exists only in the GraphQL API, so a pull request carrying unresolved blocking feedback reports as ready. On grafana/grafana#131909 that gap hid a High-severity finding, an unclamped `toFixed` that throws, behind zero failing checks and no merge conflicts. This play reads threads through GraphQL and checks through `gh pr view`, single-sourcing every field so the two readings can never contradict each other, and names each unresolved thread with file, line, author and permalink. It degrades honestly rather than optimistically: pending checks are reported as pending and never counted toward a pass, uncomputed mergeability is reported as unknown, and more than 100 threads labels the count a lower bound. The verdict can fall to cannot-confirm, but never to safe. Read-only, and needs no API key beyond the gh CLI you already have.ROTE2 STEPSREAD ONLY3 ↓161Parent Medication DispenserSmart interval-based medication alert dispatcher for parents and family members with interactive Telegram confirmation cards.ROTE1 STEPSREAD ONLY3 ↓162Oss Issue Claim GateBefore you write a line of code against an open-source issue, find out whether it is already someone else's. Reads the issue, every comment, and the cross-referenced pull requests, and returns one of three answers - CLEAR, TAKEN, or UNKNOWN. Claim detection covers the polite forms people actually use - asking whether anyone is on it and then starting, offering to take it, saying a fix is ready - not just the direct ones. Five ways an issue is taken and it checks all five - an assignee who is not you, a label the repository uses to reserve work, a comment from someone else claiming it, an open pull request from another author, and an issue that is not open. UNKNOWN is a real third state - a signal it could not read never collapses into CLEAR, because a false CLEAR costs your standing in a repository and a false TAKEN costs one issue. Public repositories need no credentials at all - the read path is unauthenticated. GITHUB_TOKEN is optional, raises the rate limit, and is the only way the claim comment gets posted. Writes nothing unless you pass post_claim, the verdict is CLEAR, and you have not already commented - and when it does write, it returns the comment id so you can undo it. Runs on python3 alone.ROTE5 STEPSREAD ONLY3 ↓163Evidence Backed Launch VideoTurns a product URL into a rendered MP4 launch video where every frame traces back to the real site, and says so. It captures the page once (screenshots, visible copy, brand colours), builds the cut from that evidence, renders it, and prints a ledger naming the source of every frame. In evidence mode it will not write a word the site does not publish, and will not put the same words on screen twice: a beat with no backing of its own is omitted and reported, never filled with a plausible tagline and never padded by repeating copy an earlier frame already showed, which matters because a site whose title equals its first heading is the normal case rather than the exception. Illustrative mode allows generic placeholder copy and marks each one INVENTED in the same ledger. A launch video is the one artifact where invention is the norm and an invented claim is indistinguishable from a real one once it is on screen; this makes that difference checkable. Writes only inside the output directory you name, uploads nothing, and never touches the captured site.ROTE5 STEPSREAD ONLY3 ↓164Pr Audit DraftRun a PR auditor, collect git metadata, and generate a polished PR description draft with audit report, security review, diff statistics, and test plan.ROTE5 STEPSREAD ONLY3 ↓165Agent ReadyCan an AI agent actually use your website? Scans any site against the agent-discovery standards — ARD capability manifest, RFC 9727 API catalog, RFC 8414/9728 OAuth discovery, auth.md, MCP server card, A2A agent card, agent-skills index, WebMCP, Link headers, markdown negotiation, robots/sitemap, DNS-AID — and returns one classified briefing: a readiness level 0-5, every check bucketed pass/fail/neutral, and a concrete fix for each failure. Optional fail_below turns it into a CI gate. Read-only, no credentials, one external call.ROTE2 STEPSREAD ONLY3 ↓166Pod Cidr CheckCheck each Kubernetes node's podCIDR across two cluster contexts and flag overlap.ROTE2 STEPSREAD ONLY3 ↓167Token AuditAI Prompt & Token Budget Auditor Play: Audits token counts, prompt bloat, and API costs.ROTE1 STEPSREAD ONLY3 ↓168Cloud Zombie HunterZombie Cloud & Cost Waste Hunter Play: Audits unattached volumes and idle cloud resources.ROTE1 STEPSREAD ONLY3 ↓169Git PruneSmart Git Branch Janitor: Safely audits and prunes merged local branches.ROTE1 STEPSREAD ONLY3 ↓170Docker ScrubUniversal Docker disk bloat auditor and safe space reclaimer Play.ROTE1 STEPSREAD ONLY3 ↓171Env SyncDeterministic .env drift auditor & auto-template sync play for polyglot codebases.ROTE1 STEPSREAD ONLY3 ↓172Whats Holding This PortDiagnoses whether a local TCP or UDP port is free, attributes observable owners, optionally probes the endpoint, and reports one evidence-backed verdict.ROTE4 STEPSREAD ONLY3 ↓173List My Github IssuesLists GitHub issues assigned to the authenticated gh user in one repository and renders them as a markdown table.ROTE2 STEPSREAD ONLY3 ↓174Posthog Project DauRetrieve daily active users (distinct persons per day) for a PostHog project over a lookback window via HogQL.APISESSIONSPOSTHOG-MCP4 STEPSREAD ONLY3 ↓175Cap Table ModelDeterministic, dependency-free cap-table calculator for existing ownership, estimated pre-round SAFE positions, and priced financing rounds. Handles pre- and post-money SAFEs, caps, discounts, chronological MFN elections, YC 7% SAFEs, Series issuance, option-pool refreshes, and exact share reconciliation. Priced-round returns pre-round and post-round views from one solve. Ships one BigInt engine, requires only Node 18 or newer, and performs no network access, authentication, or runtime installation. Based on the transaction semantics of https://github.com/1984vc/cap-table.ROTE1 STEPSREAD ONLY3 ↓176Pr Manager Release ContextGathers release-level commit/PR/file-change context from a local git repo and produces a structured changelog-grade technical handoff package for the bob-announcement-manager agent.ROTE0 STEPSREAD ONLY3 ↓177License GuardAnswers the question that matters before you open-source or ship a product: is a reciprocal licence hiding in your dependency tree? Reads installed package manifests offline, classifies every licence by SPDX expression (respecting that OR can be satisfied by its permissive branch while AND cannot), and reports strong copyleft, non-free and unrecognised licences against your own project's licence. No registry calls, no API key, no rate limit, no credentials.ROTE2 STEPSREAD ONLY2 ↓178Iac ExposureAudits Terraform for the configurations that put a network or a data store on the public internet, or make a destroy unrecoverable. Block context is parsed rather than grepped, which matters more here than anywhere: cidr_blocks 0.0.0.0/0 inside an egress block is how nearly every workload reaches the internet, while the same line inside ingress is an open door, and a route table's default route is neither. Severity follows the port, so an open 443 on a load balancer is reported as normal while 22 or 5432 is critical. Both the classic ingress block and the modern aws_vpc_security_group_ingress_rule with cidr_ipv4 are understood. Read-only, never contacts a cloud provider, needs no credentials.ROTE2 STEPSREAD ONLY2 ↓179Laptop Loss DrillOne question, answered with evidence: if this laptop died right now, what would you lose? Two readings joined into a verdict: your last backup (Time Machine consulted read-only via tmutil; unreachable or unconfigured states reported honestly, never papered over) and the work that exists NOWHERE but this disk -- unpushed commits counted against every remote-tracking ref, branches with no upstream at all, stashes, and dirty files, from a bounded sweep of the git repositories under base_dir. Loss claims are conservative: a commit reachable from any pushed ref is never counted as lost. This is loss exposure, not work triage -- it answers what is unrecoverable, not what needs attention. Every git read uses --no-optional-locks with a scrubbed environment; one unreadable repo degrades to a labeled unknown, never a crash. Zero loss renders a positive verdict: backed up and pushed means this laptop is replaceable. Read-only, no credentials, no network; needs only python3 and git.ROTE2 STEPSREAD ONLY2 ↓180Mcp Config Secrets Auditmcp-context-tax (already published, ours) MEASURES the token cost of what your MCP servers advertise; mcp-doctor (already published, ours) DIAGNOSES their health -- this completes the trilogy: mcp-config-secrets-audit reports SECRET POSTURE across the exact same discovered configs, never cost, never health, never a value. Three jobs, in order: (1) reads the same fixed, well-known set of harness-owned config files its siblings already read (Claude Code global + per-project mcpServers, Claude Desktop, Cursor, Codex config.toml mcp_servers tables -- incl. a narrow TOML fallback reader for interpreters without stdlib tomllib -- Windsurf; never a filesystem walk for a stray project .mcp.json) and classifies EVERY env var value each declared server carries by SHAPE, at the exact moment it is read off disk and before anything is packed into this play's own inter-step data or printed anywhere: a literal secret-shape (an OpenAI-style sk- key, a GitHub ghp_ token, an AWS AKIA access key id, a JWT, or a 40+ character high-entropy token) versus safe indirection ($VAR, ${VAR}, or empty) versus an unremarkable plain literal (a file path, a short flag value); every classified value is reduced to its var NAME, its shape, a 4-character preview, and its length -- the raw value itself never survives past that one read, never packed, never printed, in any representation this play produces, including its own JSON result; (2) reads each config file's own permission bits once, independent of whether its contents parsed, and calls out the single combination that matters most -- a file that is world- or group-readable AND holds at least one inline secret-shaped value -- as the top finding, distinct from a merely loose-permissioned file holding nothing and a locked-down file that happens to hold a secret; (3) reports counts per config file (one file per harness in this play's fixed set) and a short, text-only, NEVER EXECUTED advisory whenever at least one inline secret-shaped value was found: move it to your OS keychain or a local env manager and reference it by name -- MCP configs travel in backups and dotfile repos. Unlike either of its siblings, this play never spawns anything at all -- no handshake, no probe, no process beyond reading files and stat()ing them; deliberately simpler and safer than mcp-context-tax or mcp-doctor, because a secrets audit never needs to run the thing it is auditing. Disabled server blocks (enabled: false) are still audited, on purpose -- a secret sitting in a config block a harness currently ignores is still a secret sitting in cleartext on disk. Read-only, no credentials transmitted, no network calls, no server spawned; needs only python3.ROTE2 STEPSREAD ONLY2 ↓181Shell History Leak ScanA git-history scanner reads what got committed. It never reads what got TYPED: an export/curl/psql/python invocation carrying a raw credential at a shell prompt lands in ~/.zsh_history, ~/.bash_history, ~/.local/share/fish/fish_history, ~/.python_history, or ~/.psql_history instead -- files no commit-scanner ever opens. himanshu-jha's git-history-secret-scan covers commits; this covers the shell. Five jobs: locate_histories stats all five known files -- present or not, readable or not -- every one reported on by name, never silently skipped, and never opening or reading a single one; scan streams every located, readable file line by line -- a multi-gigabyte history is never loaded whole -- parsing zsh's EXTENDED_HISTORY `: <ts>:<elapsed>;cmd` framing and its backslash line-continuation so a multi-line paste reads as the one logical entry it was, plus fish's `- cmd: ...` block form, and never treating a `#`-led comment line (however common a typed "remember to rotate the api key" aside is) as a command; it classifies what it reads as secret-shaped -- export/declare/set (bash, zsh, and fish's `set -x` form alike) or a bare inline VAR=value prefix where the NAME looks secret-related (key, token, secret, password, credential, auth) AND the value is a literal, never a $VAR or backtick indirection (`export KEY=$FROM_ENV` is the deliberately SAFE case and is never flagged, only a real value sitting in the clear is); a `curl -H "Authorization: Bearer <token>"` header, quoted or not, and a bare Bearer token besides; a --password/--token (or lookalike) flag carrying a literal value, never a bare flag; and well-known token shapes -- sk-, ghp_, gho_, xox[bp]-, AKIA, an eyJ-led JWT -- matched anywhere in a line, never double-counted against a match a name or flag already explained; every finding is then reduced, everywhere including this play's own JSON, to file, line number, a short SHAPE label, the variable/flag name, and the first 4 characters plus total length of the matched value -- NEVER the full value, never the full line, which can hold an unrelated private command sharing a history entry with a real secret -- and max_findings caps how many are listed individually, the rest only ever a count; and the report closes with a text-only remediation note (rotate first, then how to scrub a line without a still-open second shell silently re-writing it back over your edit) plus a CHECKED/UNVERIFIED coverage ledger, never a claim of a clean bill unless at least one file was actually scanned. Nothing is ever executed on your behalf, and no history file is ever written, moved, or truncated by this play itself. Read-only, no credentials, no network; needs only python3.ROTE2 STEPSREAD ONLY2 ↓182Agent Disk TaxWhat does your agent tooling cost you in DISK, right now, by category, with the single largest offenders named? Five jobs, in order: discovers which of a fixed, well-known table of candidate roots exist on this machine -- Claude Code transcripts and non-transcript state, Codex, rote itself, playwright browser downloads, uv and npm/npx caches, ollama and lm-studio models, huggingface downloads, plus agent worktree directories -- never a filesystem walk to go looking for categories outside that table, with exactly one narrow, disclosed exception (a single non-recursive listing of ~/.claude itself, done once, to find worktree-named subdirectories); walks each included category's root(s) with a pure-python directory walk (os.scandir over an explicit stack, no `du` dependency -- this keeps every dependency at python3), checked against its deadline on every directory entry rather than once per directory, inside its own per-category time budget, so one huge category (a multi-gigabyte transcript history) can never block or starve another; counts total bytes and file count for that category while tracking its largest N files and its oldest and newest modification time; and, whenever that budget is hit before every root finishes walking, labels the category's figures PARTIAL and states plainly that the true size is AT LEAST what is shown -- never a silent truncation. A category root that is itself a symlink is never accepted as existing, and no two categories may claim overlapping roots -- both rejected before any root is ever walked, closing the one way this fixed table could otherwise be tricked into scanning outside its disclosed scope or double-counting a category. Regular-file hard links are deduplicated by inode within each category (content-addressable caches like uv/npm commonly hard-link the same blob under multiple names); the same file hard-linked into a DIFFERENT category is not deduplicated across that boundary, disclosed rather than silently left inflated. Every included category then lands in one table ranked by size, plus one merged "largest files" list across every category that is exact, not approximate (a file cannot be in the whole scan's top N without also being in its own category's top N, so merging each category's own top N and re-sorting is provably exact for any category that finished walking within its budget). The agent-worktrees category is reported differently, judgment-free: one row per worktree directory with its own size and last-modified time, and only a stated calendar fact ("untouched 14+ days") where the math says so -- never a recommendation to remove one, and this play removes nothing regardless. This is the disk half of our tax family: context-tax measures what your servers cost in tokens; this measures what your tooling costs in disk. Every path this play prints -- category roots, largest-file paths, worktree paths alike -- has the local home directory replaced with "~" before it reaches stdout, a report, or a fixture shipped with this play. Claude transcript file paths in the largest-files list default to filename only, since Claude Code's own transcript folder naming embeds the original project path; an opt-in parameter shows the full path. Sizes are POSIX apparent size (st_size), not on-disk block-allocated size, which is why this play makes no `du` calls of its own. Nothing is ever written, moved, or deleted by this play -- not even a cache file of its own -- and its own written advice never goes further than "review this yourself"; it prints no rm command, ever. Read-only, no network calls, no credentials read or transmitted; needs only python3.ROTE2 STEPSREAD ONLY2 ↓183Reviewer FinderAssigning a reviewer is a guess unless you know who has actually touched the code. GitHub will not tell you: a pull request lists who was requested, never whether any of them have ever edited these files, and CODEOWNERS answers a different question — who owns a path by policy, not who still has context. The obvious substitute, counting commits on the changed files and taking the top name, is worse than nothing on a real repository. On a recent kubernetes pull request the three highest committers to the changed files were a CI bot, the pull request author, and a second bot. This play reads the files a pull request touches, drops lockfiles and generated paths so dependency bumps stop impersonating expertise, then reads recent authorship of each remaining path and ranks people by how much of THIS change they have touched rather than how many commits they have anywhere. Automation is excluded, and because accounts like denobot and crowlbot report as ordinary users rather than bots, anything dropped on a name heuristic is listed so a misjudged human stays visible instead of vanishing. Expertise that has gone cold is flagged with its age, files only one person has ever touched are reported as a bus-factor risk, and reviewers already requested are shown with what they have actually touched — described as no recent commit history on these paths, never as a wrong reviewer, since an approver may be there for policy rather than code. It reads commit authorship only, it cannot follow renames, and it says so rather than pretending otherwise. Read-only, two arguments, no API key beyond the gh CLI you have already signed in to.ROTE3 STEPSREAD ONLY2 ↓184Tracked LeaksFinds the files git is TRACKING that should never have been committed, and the gap between what a repo's .gitignore claims to exclude and what its index actually holds. Adding a pattern to .gitignore does nothing for a file that is already tracked, which is exactly why the same leak keeps coming back, so every finding is checked with `git check-ignore --no-index` and then dated and tested for reachability from a remote-tracking ref, because a pushed secret is a rotation job and an unpushed one is a rebase. Precision is the point: `.env.example`, `.env.sample` and `.env.local.example` are meant to be committed and are never flagged, a `!`-negated ignore rule is read as the repo re-including a file rather than as a gap, a credential-shaped file under a test fixture path is reported apart from one at the repo root, and a `.pem` with no PRIVATE KEY header or a `.npmrc` with no auth token is cleared by inspection instead of raised. Read-only, needs no credentials, and never prints the contents of any file it finds, only the path.ROTE2 STEPSREAD ONLY2 ↓185Test Gap MapMaps the files a branch changed onto the CI jobs that would actually select them, and finds the code that changed but never reaches a test. Resolves GitHub path filters properly: a workflow with no paths filter matches every file and therefore covers everything, ** crosses directory boundaries while * does not, and paths-ignore subtracts. Test-running jobs are identified from real run commands and action names, never from test-shaped words in comments, because a false positive there hides the gap it should report. Read-only, no CI credentials, no API calls.ROTE3 STEPSREAD ONLY2 ↓186Shadow SchedulerFinds every recurring job that runs behind your back, grouped by what it actually does rather than which scheduler owns it. Reads launchd agents and daemons, the user crontab, and GitHub Actions schedule triggers, normalises all three to a single shape with an estimated runs-per-day, then surfaces the findings that matter: the same effect scheduled twice by different systems, jobs whose target binary or script no longer exists, and the heaviest consumers of your machine. Read-only, no credentials, nothing is executed or unloaded.ROTE2 STEPSREAD ONLY2 ↓187Py Lock DriftFinds where a Python project's declared dependencies and its lock file disagree, which is how "works on my machine" happens. Compares pyproject.toml, requirements files and Pipfile against uv.lock, poetry.lock, Pipfile.lock or pip-compile output and reports five things: packages declared but absent from the lock, packages the lock still carries as direct dependencies that nothing declares any more, declared constraints the locked version violates, a lock whose own record of the manifest no longer matches it, and direct dependencies with no version specifier at all. Only direct dependencies are compared in the locked-but-undeclared direction, because a lock legitimately holds the whole transitive closure; names fold under PEP 503 so Flask_Login and flask-login are one package. Offline, no index call, no API key, no credentials.ROTE2 STEPSREAD ONLY2 ↓188Kubernetes GuardAudits Kubernetes manifests for the security and reliability gaps that only show up in production: containers with no resource limits or requests, missing or incomplete securityContext, privileged: true, added capabilities, hostPath/hostNetwork/hostPID, :latest or untagged images, missing liveness and readiness probes, and secrets passed as plain env values instead of a secretKeyRef. Structure is parsed rather than grepped, which is what makes it usable on real repositories. Helm templates are rendered against the chart's own values.yaml, so `resources: {{ toYaml .Values.resources | nindent 12 }}` is read as the limits values.yaml actually sets rather than reported as a missing limit; an action that cannot be resolved becomes an explicit unknown, never an absence. Every finding names its container, because in a multi-container pod the settings differ per container. Kubernetes' own securityContext inheritance is applied, so runAsNonRoot set on the pod counts for its containers while readOnlyRootFilesystem, which never inherits, does not. Probes are only expected where Kubernetes uses them: long-running workloads and native sidecars, not Jobs or init containers. Read-only, never contacts a cluster, needs no kubeconfig.ROTE2 STEPSREAD ONLY2 ↓189Dockerfile AuditAudits Dockerfiles with multi-stage builds actually understood, because only the final stage ships. A credential in the shipped stage is recoverable from the published image and is reported as critical, while the same line in a discarded builder stage is reported separately and lower. A missing USER is not flagged when the base image is a nonroot variant that already drops privileges. Also finds unpinned base images, remote ADD without a checksum, remote scripts piped into a shell, and a whole-context COPY with no .dockerignore, which quietly bakes .git history and .env files into the image. Read-only, never builds or pulls anything.ROTE2 STEPSREAD ONLY2 ↓190Dep SkewFinds the same dependency declared at different versions inside one dependency set, which is what silently doubles a bundle, produces "two copies of React" bugs, and makes upgrades unpredictable. Reads declared ranges from package.json, pyproject.toml, requirements*.txt and Cargo.toml; installed trees are pruned, because node_modules records what a resolver already picked rather than what anyone asked for. Scope is the whole point: ranges are compared only inside one npm/pnpm/yarn or Cargo workspace, or one project's own manifests, so two unrelated repos that both use lodash are never called skew. Findings are ranked by real distance, so a 1.x-vs-3.x split outranks a caret-vs-tilde difference, 0.x minors count as major because semver says they break, and a range already forced by resolutions/overrides or inherited through workspace = true is reported as pinned instead of as a finding. Offline, read-only, no credentials.ROTE2 STEPSREAD ONLY2 ↓191Compose AuditAudits docker-compose files for what they expose to the host and for the settings that make a stack fragile. The whole value is a distinction a grep cannot make: ports "127.0.0.1:5432:5432" is correctly bound to loopback and is never reported, while "5432:5432" publishes the same database on every interface the host has and is reported as critical. Both the short string form and the long target/published/host_ip form are understood, along with the IPv6 bracket form and a variable host port. Also finds privileged: true, a mounted docker socket, host network/pid/ipc namespaces, secrets written as plain environment values, :latest and untagged images, missing restart and healthcheck, bind mounts of sensitive host paths, and env_file entries naming a file that is not there. Compose files are parsed, including anchors and merge keys, so a privilege that arrives through <<: *defaults is attributed to the service that inherits it. Read-only, contacts no daemon, needs no credentials.ROTE2 STEPSREAD ONLY2 ↓192Ci Supply ChainAudits GitHub Actions workflows for the exposures that hand your repository secrets to someone else: pull_request_target checking out the pull request head, attacker-controlled context interpolated straight into a shell command, actions pinned to a movable branch or tag instead of a commit SHA, remote scripts piped into a shell, and workflows with no permissions block. Two rules deliberately require a combination, because pull_request_target on its own is ordinary and github.sha is not attacker-controlled, and flagging those teaches you to ignore the tool. Read-only, no tokens, no API calls.ROTE2 STEPSREAD ONLY2 ↓193A11y GuardAudits JSX, TSX, HTML, Vue and Svelte files for accessibility barriers that actually block people: images with no alt text, click handlers on elements no keyboard can reach, form fields with no accessible name, interactive elements hidden from screen readers, and media with no captions. Every finding cites its WCAG success criterion and the fix. Tags are parsed with a brace-aware scanner, so JSX arrow functions in attributes do not corrupt results, and comments never produce findings. Read-only, no build step, no browser, no credentials.ROTE2 STEPSREAD ONLY2 ↓194Migration Blast RadiusRead-only migration blast-radius analysis. Given a repository, migration description, and target version, discovers Node/runtime manifests, maps API surface and dependency usage, identifies Rust equivalents where applicable, assesses config/build/test impact, and produces a risk-ranked ordered migration plan. Never modifies files. Supports nodejs-to-rust and generic dependency migrations.ROTE7 STEPSREAD ONLY2 ↓195Play Smoke TestA smoke test for a Play: does it actually run? That is the whole scope, and the name says so because the play does one thing. Every other tool in this space refuses to find out, and says so in its own output. reach-check reads what a Play reaches and never executes it. floor-check reads which Python it needs and never imports it. audit-play reads whether the contract is honest. play-quality-doctor grades the registry rubric and lists "whether your play works, scoring never runs it" under what it cannot tell you. So a Play can hold a clean contract, a 1.00 score and a fully resolved manifest while being broken on its own defaults, and nothing above would notice. This runs it in a temporary directory on the defaults it ships with, and reports the exit status, how long it took, and how many steps completed, failed or were blocked. It refuses by default to run anything that does not declare effect-read-only, because executing an unknown Play that writes is not a test, it is a side effect on your account, and allow_effects=true is the only way past that. A green run is one sample on one input and the report says so: it reads exit status, not answers. For what a Play reaches, what Python it needs, whether its contract is honest or why it scores what it scores, run the four plays named above instead. This deliberately does none of that.ROTE2 STEPSREAD ONLY2 ↓196Pulled Play InventoryLists every Play package installed on this machine with its version, the date it was pulled, its step count and its size on disk. Read-only, python3 standard library only, no network and no credentials.ROTE2 STEPSREAD ONLY2 ↓197Event Brief From Public UrlsTurn any hackathon or event link into a clear 1-page summary. Tells you the exact deadline, timezone, prizes, submission rules, setup commands, and official links. Catches and highlights when rules on different pages disagree with each other so you never miss a requirement. 100% read-only, zero setup, zero API keys, needs only python3.ROTE2 STEPSREAD ONLY2 ↓198Agent Whisper MapYour AI agent reads invisible ink. Scans a repo for zero-width smuggling, Trojan-Source bidi, homoglyphs, hidden HTML comments, and prompt-injection phrases — then shows what you see vs what the agent reads. Read-only, zero adapters, Python stdlib.ROTE1 STEPSREAD ONLY2 ↓199Repo Health SnapshotTop committers plus issues opened in the last N days for a GitHub repository, combined into one snapshotAPISESSIONSGITHUB3 STEPSREAD ONLY2 ↓200Dataset Eval Sanity CheckCheck a JSONL dataset for duplicate rows, missing required keys, and text length outliers with exact row citations.ROTE1 STEPSREAD ONLY2 ↓201Training Health CheckRun a deterministic training health checker against plain-text and W&B offline logs and compare their verdicts.ROTE3 STEPSREAD ONLY2 ↓202Return Warranty GuardianScan Gmail receipts and order confirmations to extract structured purchase records and produce return-window and warranty countdown reports with zero email mutations.ROTE1 STEPSREAD ONLY2 ↓203Panel Collision CheckDetect Greenhouse interview panels scheduled during a panelist's active on-call rotation, release freeze window, or incident load — then propose reschedule alternatives without editing calendars.ROTE1 STEPSREAD ONLY2 ↓204Email Priority BriefSource-credited standalone extension of modiqo/[email protected]: preserves normalized Gmail emails, then classifies priority, extracts stated deadlines, suggests actions, and returns a concise briefing.APISESSIONSGMAIL3 STEPSREAD ONLY2 ↓205Invisible DiffReviews only added Git source lines for directional controls, invisible identifier characters, normalization collisions, and high-confidence mixed-script lookalikes. Returns CLEAN, REVIEW, BLOCK, or INCOMPLETE with escaped path-line evidence. Run with no arguments for a deterministic demo.ROTE8 STEPSREAD ONLY2 ↓206Find Dirty Git ReposFind git repositories under a base folder that have uncommitted changesROTE2 STEPSREAD ONLY2 ↓207Hackathon Scope CutterCut an ambitious hackathon idea into a demo-critical end-to-end slice, useful-if-time-remains work, cuts, dependencies, and an honest finish line.ROTE1 STEPSREAD ONLY2 ↓208Error To Search QueryExtract the useful signal from a noisy error or stack trace, identify likely technology context, and produce precise search queries plus evidence to collect next. Read-only and secret-redacting.ROTE1 STEPSREAD ONLY2 ↓209Demo Script BuilderBuild a timed hackathon demo sequence with problem opening, feature order, narration during waits, strongest moment, fallback, and closing.ROTE1 STEPSREAD ONLY2 ↓210Hackathon Decision GateEvaluates whether a public hackathon is worth entering now, preserving cited requirements, UNKNOWNs, and authoritative conflicts.ROTE8 STEPSREAD ONLY2 ↓211Claim TrialTests one technical claim at an exact local Git revision. Runs a baseline and hostile probe in separate disposable worktrees, returns SUPPORTED, DISPROVEN, or INCONCLUSIVE with bounded evidence, and verifies the source checkout stayed unchanged. Run with no arguments for the bundled cancellation-lock demonstration.ROTE7 STEPSREAD ONLY2 ↓212Merged Branch EvidenceDecides which local branches are safe to delete, and says why for each one. `git branch --merged` answers a narrower question than the one you are asking: it reports whether the base branch contains the branch tip as an ancestor, which is true after a merge commit or a fast-forward and false after every squash and every rebase. On a repository that squashes, branches whose work shipped weeks ago keep reporting as unmerged, and `git cherry` agrees with it because a squash rewrites the patch ids too. This play gathers four independent sources instead: reachability, the pull request number GitHub appends to a squash commit subject, the pull request state from gh, and whether the branch still holds commits the base does not. It then names a verdict per branch with the evidence behind it. Two failure directions matter and both appear here: a branch that merged invisibly and gets kept forever, and a branch whose pull request merged but which has kept receiving commits since, where deleting on the strength of `merged` drops that work. Without gh a squash cannot be ruled out from git alone, so those branches are reported as undetermined rather than guessed at. Read-only: it never checks out, deletes, or writes anything, and prints the delete command for you to run yourself.ROTE6 STEPSREAD ONLY2 ↓213Pr Review VerdictAnswers the question you actually have after a review lands: what did the reviewers decide, and where is the substance. Reading a pull request's review state wrong is the common failure, and it fails in the direction that looks like good news. GitHub keeps every review a person ever submitted, so the reviewer who requested changes in March and approved in April appears as both; only the newest verdict per reviewer is that person's position. A COMMENTED review is a remark, not a decision, and DISMISSED is a decision that was taken back. The pull-request-level review decision GitHub exposes stays empty unless a branch protection rule requires reviews, so an unprotected repository reports nothing on a pull request a reviewer is blocking. And zero inline comments means two opposite things: on an approval the body is the whole review, but on a blocking review it means the objection does not attach to any changed line, which is the shape most worth reading in full and exactly the one a count of inline comments reads as nothing to fix. This play applies those rules to one pull request and reports a single verdict, one next action, and per reviewer where the substance is. Read-only: four GitHub reads through your existing gh sign-in, no writes, and it degrades to the anonymous public API when gh is absent.ROTE5 STEPSREAD ONLY2 ↓214Hackathon Readiness AuditorAudits a local project for hackathon submission readiness and returns a score, blockers, evidence, and prioritized fixes without exposing secret values.ROTE2 STEPSREAD ONLY2 ↓215Gmail Subscription AuditScan Gmail receipts/renewal emails over a lookback window and produce a table of recurring subscriptions: vendor, amount, cadence, last charged, and unused-60+-days flag.APISESSIONSGMAIL-API4 STEPSREAD ONLY2 ↓216Downloads FiledYour Downloads folder is where files go to be forgotten. This files the recent ones into a dated folder and leaves a manifest that puts every one of them back. Dry run by default - the first time you run it, it touches nothing and shows you the exact plan, so you can decide with the moves in front of you rather than after. It never overwrites - a name that already exists in the destination gets a numbered suffix, and the manifest records the rename. It never moves bundles or installers, because moving a .app or a .dmg breaks things in ways nobody connects back to a sweep they ran three days ago. Directories and dotfiles are left alone. After moving, it checks that every file is actually at its destination and actually gone from the source, and reports any that are not rather than claiming success. Two sweeps on the same day extend one manifest instead of replacing it, so the first sweep's files stay recoverable. Undo ships with the play as a script that refuses to overwrite anything sitting at the original path. No credentials, no network, python3 alone.ROTE5 STEPSREAD ONLY2 ↓217Standup From GitWhat did you actually do yesterday. Walks every git repository on your machine, not one, and reads back your own commits in a window you choose, plus the repositories carrying uncommitted work you have forgotten about. Standup is daily and the answer lives scattered across six checkouts, which is why the honest answer is usually a guess. Reads nothing but git. Writes nothing anywhere, makes no network call, and needs no credential of any kind - every git command it runs is a read, and the play has no code path that modifies a repository. A repository it cannot read is named as unreadable rather than dropped, because a checkout that quietly vanishes from a standup is worse than one reported as broken, and the verify step checks that every repository discovered is accounted for in the summary rather than assuming it. A quiet day returns the outcome empty, which is a real answer and not a failure. Runs on python3 and git alone.ROTE5 STEPSREAD ONLY2 ↓218Keep My NotesKeep My Notes When I Re-export merges a fresh CSV export with a previous annotated copy by exact stable-ID string. Fresh platform values win; only explicitly named manual columns carry forward, new rows receive blank manual fields, missing rows are archived separately, and changed matched rows include old/new platform evidence for review. Inputs are read-only and proved unchanged. After every refusal preflight passes, the Play uses one run-owned staging directory beside output_dir, creates output_dir if absent, and exclusively creates refreshed.csv, missing-from-fresh.csv, needs-review.csv, and refresh-receipt.json without overwriting existing paths. It reopens and verifies every output before reporting VERIFIED, removes temporary state on terminal paths, and bounds post-commit rollback to unchanged files created by that run. Canonical JSON is complete; the one-line summary is intentionally lossy.ROTE11 STEPSREAD ONLY2 ↓219Mongoose Integrity ValidatorMongoose Integrity Checklist: scans backend/src models and services/controllers to report model coverage, indexed query health, and missing validation warnings. Read-only.ROTE3 STEPSREAD ONLY2 ↓220Merge CanaryWill your feature branch still work after merging latest main? Creates a temporary merge, checks for conflicts, and classifies the result as GREEN, TEXT_CONFLICT, SEMANTIC_CONFLICT, BRANCH_ALREADY_RED, or INDETERMINATE. Never modifies your current checkout. Read-only, no credentials. ROTE3 STEPSREAD ONLY2 ↓221Dep VetDependency health scanner. Finds lockfiles, parses dependencies, checks for outdated packages (npm registry), and scans for known vulnerabilities (OSV.dev). Returns a deterministic verdict (HEALTHY / STALE / VULNERABLE) with prioritized recommendations. Read-only, no credentials. ROTE5 STEPSREAD ONLY2 ↓222Check App HealthCheck deployed app health endpoints and fetch recent commits if unhealthyROTE1 STEPSREAD ONLY2 ↓223ShipproofProves that an exact GitHub commit passed CI, matches the commit fingerprint exposed by a deployment, and is visibly live on the public page.ROTE4 STEPSREAD ONLY2 ↓224Java Smoke CheckCompile a no-build-tool Java project and smoke-test that it boots and exits cleanly with scripted stdinROTE4 STEPSREAD ONLY2 ↓225PlaybenchBenchmarks the same task with and without a pinned Rote Play using isolated workspaces, harness token telemetry, blind quality evaluation, and deterministic comparison gates.ROTE1 STEPSREAD ONLY2 ↓226Precog PreflightNeural pre-flight for a landing page: renders it in real Chrome, measures pixels and copy, forecasts CTA click-through with every coefficient printed, and ranks what to change. Exits non-zero on a weak grade so it can gate a deploy.ROTE2 STEPSREAD ONLY2 ↓227Context Window GuardCheck prompts against LLM context windows, estimate tokens, flag safety marginROTE1 STEPSREAD ONLY2 ↓228Merge CanaryRun one identical non-interactive check on a topic ref alone and after a temporary merge with a selected base ref already present locally. No network fetch is performed. Canonical JSON is complete; the one-line summary is intentionally lossy.ROTE11 STEPSREAD ONLY2 ↓229Ai Visibility AuditScore any public URL's discoverability to AI assistants (0-100) with personalized fix recommendationsROTE1 STEPSREAD ONLY2 ↓230Radahn Parallel Stress CannonStarscourge Radahn meteor: launches parallel load tests against microservices to find auto-scaling breakpoints.ROTE1 STEPSREAD ONLY2 ↓231Viper Pit Env EncryptorValorant Viper poison cloud: encrypts sensitive staging .env files with AES-256-GCM and rotates secrets into AWS Secrets Manager.ROTE1 STEPSREAD ONLY2 ↓232Dragonrot Log DiagnosticianSekiro cure: parses distributed crash logs across microservices, dedupes stack traces, and isolates root-cause failures.ROTE1 STEPSREAD ONLY2 ↓233Grace Point Rollback MedicElden Ring Grace Point: automatically snapshots state and orchestrates instant zero-downtime rollback on deployment failure.ROTE1 STEPSREAD ONLY2 ↓234Site Retake Smoke TesterValorant post-plant smoke tester: executes automated parallel health checks and endpoint latency probes post-deployment.ROTE1 STEPSREAD ONLY2 ↓235Radiant Cors SentinelValorant Radiant rank security probe: audits CORS origin whitelists, credential headers, and preflight OPTIONS responses.ROTE1 STEPSREAD ONLY2 ↓236Malenia Agent OrchestratorI am Malenia, Blade of Miquella: Auto-orchestrates multi-agent swarm tasks, resolving Play dependencies concurrently.ROTE1 STEPSREAD ONLY2 ↓237Tarnished Auth WardenAudits JWT, OAuth2, RBAC, and middleware headers for broken object-level authorization (BOLA) and expired signatures.ROTE1 STEPSREAD ONLY2 ↓238Mikiri Rate Limiter GuardCounter incoming traffic spikes by auto-tuning Token Bucket & Leaky Bucket middleware rate limits and DDoS thresholds.ROTE1 STEPSREAD ONLY2 ↓239Erdtree S3 Micro DeployAutomates multi-service serverless Lambda packaging and parallel S3 asset deployment with integrity hashing.ROTE1 STEPSREAD ONLY2 ↓240Bundle Diet GuruPut your frontend on a diet: inspects build bundles, flags heavy JS chunks (>500KB), and identifies un-treeshaken vendor bloat.ROTE1 STEPSREAD ONLY2 ↓241Pr Aura CheckGive your Pull Request +1000 Aura: audits uncommitted files, branch cleanliness, and generates a copy-paste PR Markdown template.ROTE1 STEPSREAD ONLY2 ↓242Env Vibe CheckIs your .env valid or is it capping? Audits .env against .env.example, flags missing keys, empty values, and config drift.ROTE1 STEPSREAD ONLY2 ↓243Port Ghost BusterPort already in use? Not anymore bestie: finds and frees zombie processes hogging ports 3000, 4200, 5000, 8080.ROTE1 STEPSREAD ONLY2 ↓244Leak Check FrNo cap on security: scans git staged diffs and working directories for exposed API tokens, AWS keys, and unmasked secrets before commit.ROTE1 STEPSREAD ONLY2 ↓245Lambda Deploy AuditorAudits, optimizes, and verifies AWS Lambda Node.js deployments by stripping non-target native binaries, validating env keys, and checking package size limits.ROTE1 STEPSREAD ONLY2 ↓246Github Pr Merge ReadinessAssesses a GitHub pull request's CI, reviews, unresolved comments, mergeability, and changed-test coverage, then returns a READY or BLOCKED verdict.APISESSIONSGITHUB8 STEPSREAD ONLY2 ↓247Inbox Action BriefCreates a read-only Gmail Inbox Action Brief from matching messages.APISESSIONSGMAIL4 STEPSREAD ONLY2 ↓248Text To ActionConvert unstructured text into a concise, evidence-only actionable plan.ROTE0 STEPSREAD ONLY2 ↓249LinkcheckChecks a list of URLs and reports reachable, broken, redirected, and HTTP status results.ROTE1 STEPSREAD ONLY2 ↓250PlayfitRecommends a small set of Community Plays by matching the caller's project, harness-accessible tools and apps, recent tool-use signals, workflows, and interests against bounded registry searches and verified host readiness.ROTE1 STEPSREAD ONLY2 ↓251LogdigestCompresses noisy application logs into clustered error evidence for faster debugging.ROTE1 STEPSREAD ONLY2 ↓252PortcheckChecks whether a local TCP port is available for development.ROTE1 STEPSREAD ONLY2 ↓253Api HealthAPI endpoint health monitor. Parses endpoints from OpenAPI specs or route files, checks HTTP status codes, measures response times, and returns a deterministic verdict (HEALTHY / DEGRADED / UNHEALTHY) with prioritized recommendations. Read-only, no credentials. ROTE4 STEPSREAD ONLY2 ↓254Readme HealthREADME completeness auditor. Scans for README files, checks standard section coverage (Installation, Usage, License, etc.), link quality, and code block formatting. Returns a deterministic verdict (HEALTHY / NEEDS_WORK / INCOMPLETE) with prioritized recommendations. Read-only, no credentials. ROTE5 STEPSREAD ONLY2 ↓255Env Diff.env drift auditor. Scans for .env files and templates, compares keys, finds missing/extra keys, checks for potential secret leaks, and returns a deterministic verdict (CLEAN / DRIFT / LEAK). Read-only, no credentials. ROTE5 STEPSREAD ONLY2 ↓256Auth ScanAuth security audit for Express/Node.js backends. Scans source for auth files, audits bcrypt hashing (salt rounds, compare usage, plaintext), JWT lifecycle (sign, verify, expiry, env secret, bearer extraction), middleware coverage, and refresh tokens. Returns a deterministic verdict (PASS / PASS_WITH_WARNINGS / FAIL) with a checklist, prioritized recommendations, and evidence. Read-only, no credentials. ROTE5 STEPSREAD ONLY2 ↓257EnvguardAudits repository environment configuration without modifying the repository. Detects environment variables used by application code, compares them with .env.example, and provides file/line evidence for undocumented variables. ROTE1 STEPSREAD ONLY2 ↓258Token AuditAI Prompt & Token Budget Auditor. Scans a directory for prompt files, estimates token counts, flags bloat (>4k tokens), and projects monthly API costs across models (GPT-4o, Claude 3.5 Sonnet, etc.). Read-only, no credentials, no auth. ROTE4 STEPSREAD ONLY2 ↓259Docker ScrubReclaim Docker disk space safely. Scans for dangling images, unused volumes, and build cache; computes a cleanup plan; optionally executes it behind the apply=true gate. Read-only by default; writes only on explicit opt-in. Zero credentials, no auth. ROTE4 STEPSREAD ONLY2 ↓260Domain Perimeter HealthComprehensive DNS propagation, SSL/TLS certificate lifespan, HTTP security posture, and CDN edge diagnostic. Probes Cloudflare, Google, and Quad9 DoH in parallel, audits TLS cipher and certificate expiration, inspects HSTS/CSP headers, and generates a security grade with a stage ledger.ROTE7 STEPSREAD ONLY2 ↓261Cross Cluster Service DiagnosisDiagnose why a service in one Kubernetes cluster can't reach a service in another cluster: checks DNS resolution, then Service/Pod-CIDR routing, and reports the exact broken layer with remediation optionsROTE15 STEPSREAD ONLY2 ↓262Github Nextest Ci ReportBuilds a self-contained interactive report from GitHub Actions nextest logs, with every test execution, sortable durations, name filters, clickable histogram bins, and CSV export.ROTE4 STEPSREAD ONLY2 ↓263ShipquestTurn local Git evidence into a truthful, time-boxed quest board without changing the repository.ROTE5 STEPSREAD ONLY2 ↓264Github Pr ReviewInteractive GitHub pull-request reviewer: a terminal menu (node:readline/promises) to view your own open PRs (approvals + CI check status) or triage incoming review-requested PRs (fetch diff, summarize, then approve or close). Legacy escape: the interactive menu and per-PR approve/close loop need PTY runtime interaction that the steps runner cannot express (its children receive closed stdin).APISESSIONSGITHUB0 STEPSREAD ONLY2 ↓265Gmail Check Application RepliesCheck Gmail for replies to job/internship application emails sent within a configurable date rangeAPISESSIONSGMAIL-API3 STEPSREAD ONLY2 ↓266Cleanup Old Git WorktreesRemoves stale linked worktrees from any local Git repository while preserving the primary worktree, the current worktree, locked worktrees, and parents of registered nested worktrees.ROTE1 STEPSREAD ONLY2 ↓267DevfixRead-only repository failure triage with evidence-backed fixes.ROTE1 STEPSREAD ONLY2 ↓268Why Cant This Pr MergeExplain exactly why one GitHub pull request cannot merge, who owns each blocker, and the next actionAPISESSIONSGITHUB8 STEPSREAD ONLY2 ↓269ShipcheckAudits a software repository and produces a concise, evidence-backed production-readiness report. It inspects repository structure, README and documentation, dependency/runtime requirements, environment/configuration requirements, authentication and security-sensitive implementation, tests and CI, and build/deployment configuration. It does not modify the repository. ROTE1 STEPSREAD ONLY2 ↓270Systems Knowledge Gap Map RecursiveRecursively crawl a Notion knowledge base and compare a resource against detailed systems knowledge gapsAPIBROWSERSESSIONSNOTION0 STEPSREAD ONLY2 ↓271Systems Knowledge Gap MapAnalyze a resource or blog link, map it to systems knowledge gaps, and identify application contextsBROWSERSHELLSESSIONS3 STEPSREAD ONLY2 ↓272PlayproofTrust-audits a rote Play by validating its inputs and inspecting its structure.ROTE8 STEPSREAD ONLY2 ↓273Stop Docker DesktopList and stop user-owned Docker Desktop processes without sudo; launch Docker Desktop manually afterward.ROTE1 STEPSREAD ONLY2 ↓274Pricing Page AssessmentIs my pricing page helping or hurting? Choose any reasoning CLI on your PATH as the harness; it snapshots the plan grid, persona, messaging, and CTAs from a pricing-page URL or a folder of pricing docs into a structured file, then applies Heavybit Crucible pricing guidance to produce a decision memo.APIBROWSERSESSIONSCRUCIBLE6 STEPSREAD ONLY2 ↓275Research Paper Evidence AnalysisCreates a domain-neutral evidence packet and analysis request from a local source document. PDF support is limited to born-digital Flate-compressed text PDFs.ROTE1 STEPSREAD ONLY2 ↓276Github Review Queue By StackRank open GitHub PRs that request the authenticated user's review, ordering stack bottoms first so each review unblocks its dependents.APISESSIONSGITHUB5 STEPSREAD ONLY2 ↓277City Weather Day Night PrecipMulti-day weather forecast for any coordinate with precipitation split into day (06:00-20:59) and night (21:00-05:59) totals in mm, plus max/min temperature, precipitation probability and max wind.APISESSIONSOPEN-METEO1 STEPSREAD ONLY2 ↓278Git Worktree Pr Cleanup ReportReport git worktrees whose associated GitHub pull requests are merged and local trees are clean or prunable.SESSIONS0 STEPSREAD ONLY2 ↓279Github Issue CreateionCreate a GitHub issue in a repository from a title and Markdown bodySESSIONS0 STEPSREAD ONLY2 ↓280Check Failing WorkflowsROTE1 STEPSREAD ONLY1 ↓281JobwatchDaily job-search briefing from RemoteOK and WWRROTE3 STEPSREAD ONLY1 ↓282Playoffs PulseROTE1 STEPSREAD ONLY1 ↓283Start My DayCross-source morning brief joining GitHub PRs and Google Calendar meetings into a prioritized list.APISESSIONSCALENDARGITHUB7 STEPSREAD ONLY1 ↓284Git Credential ExposureThe three places git authentication leaks in cleartext, all covered in one sweep. Five jobs: scan_global reads ~/.git-credentials -- the file `credential.helper=store` writes, one URL per stored credential -- parsing every line as a URL and reducing every embedded user:token pair it finds to HOST, a token SHAPE (a recognized pattern -- sk-, ghp_, gho_, xox[bp]-, AKIA, an eyJ-led JWT -- else the generic "stored-credential" bucket), and a 4-character-plus-length preview -- NEVER the token itself, and never the username either, which can itself be a real email or personal identifier this play has no business repeating; the file's own permission bits are read via os.stat and flagged whenever group- or world-readable, since a credential store readable by anyone but its owner is its own finding regardless of what it contains. scan_global also resolves the EFFECTIVE `credential.helper` value at system and global scope, in that order, via `git config <scope> --get-all credential.helper` (never re-derived by hand, never assumed single-valued -- git treats this key as cumulative; an empty value is git's own reset marker, preserved and replayed rather than dropped, so `store` followed by a reset is correctly not flagged): only a coarse KIND is ever reported (store, cache, osxkeychain, ...), never the raw configured value, which can itself be an arbitrary shell command or path. helper=store is flagged with an advisory to switch to osxkeychain (macOS) or your platform's credential manager, and an unset helper on macOS gets a plain informational note, since macOS enables no automatic Keychain integration on its own. scan_repos, one bounded sweep of base_dir up to max_depth levels (pruning node_modules and the same conservative noise list this fleet's other git sweeps already established, never descending into a found repository's own .git internals), then for every discovered repo reads its EFFECTIVE credential.helper -- system, global, local, and worktree scope, in git's own cumulative order, one `--show-scope` call -- since a local-only read cannot see a `store` inherited from global/system, nor a local reset that neutralizes one; flagged repos report whether `store` came from an explicit local override or was merely inherited -- and reads `git remote -v`, parsing every remote URL (password percent-decoded before classification) for an embedded user:token or x-access-token:token credential the identical way the file scan parses stored-credential lines, de-duplicated across a remote's fetch and push lines, reduced to remote name, host, shape, and the same 4-char preview; every git call here is --no-optional-locks with a scrubbed environment (GIT_TERMINAL_PROMPT=0, LC_ALL=C, inherited GIT_DIR/GIT_WORK_TREE/GIT_INDEX_FILE stripped), one repo's failed git call degrades that repo alone to an unknown row, and git missing from PATH entirely is the one essential-capability failure that fails scan_repos closed, since no per-repo read means anything without it. The presentation joins both independent root steps into per-surface sections, a text-only advisory block per finding class (rotate first, then reconfigure the helper, then delete ~/.git-credentials -- nothing here is ever executed on your behalf), and a CHECKED/UNVERIFIED coverage ledger that never claims a clean bill unless something was actually scanned AND fully, undegraded -- an unreadable credentials file, a parse error, a failed helper check, an unknown repository, or a truncated walk all withhold both `ok` and the clean bill, never silently defaulting to zero, and discloses upfront that credentials already sitting in your OS keychain -- the SAFE place -- are exactly what this play does NOT scan. shell-history-leak-scan covers what you TYPED at a shell prompt; this play covers git's own three cleartext auth surfaces instead -- the file, the config, and the remote URL. Read-only, no credentials, no network; needs python3 and git.ROTE2 STEPSREAD ONLY1 ↓285Agent Plugin InventoryYour harness extensions accumulate like browser toolbars -- this inventories them. Four jobs, two steps: (1) Claude Code plugins -- every entry in installed_plugins.json (name, version, scope, marketplace, install/update timestamps), cross-referenced against settings.json's enabledPlugins map (a plugin absent from that map is treated as enabled by Claude Code's own default, disclosed rather than guessed disabled) and measured on disk -- present/missing/empty/inaccessible, plus an apparent-size byte count (POSIX st_size, no `du` dependency, matching agent-disk-tax's own approach); (2) personal skills under ~/.claude/skills/* (name, frontmatter description FIRST LINE truncated to 80 characters, file mtime) -- no other file content is ever read, from a personal skill or from a skill bundled inside an installed plugin; (3) known marketplaces from known_marketplaces.json (name, last-sync time when known_marketplaces.json actually records one -- never guessed when it does not); (4) Codex plugin-equivalents where present, read from ~/.codex/config.toml's [plugins."name@marketplace"] and [marketplaces.<name>] tables (enabled bool, recorded last-sync when present) -- probed defensively and this whole source degrades alone, never the rest of the report, when ~/.codex or its config.toml is absent or unparseable; on a pre-3.11 Python this narrows to a fallback reader recognizing only the shapes Codex's own config actually uses, disclosed in the report, never a lost source. FOUR FLAGS, each conservative and "-suspect", never a certainty: name-collision-suspect (a skill name found under more than one owner, compared case-insensitively -- two plugins bundling the same skill name, or a plugin skill sharing a name with a personal one; which one actually wins at runtime is harness-defined and never evaluated here, since nothing here spawns or loads anything to find out); broken-install-suspect (an installed plugin, Claude Code or Codex, whose own cache directory is missing or empty -- an inaccessible cache directory, a permission problem rather than evidence of a broken install, and a plugin with no installPath recorded at all or one outside Claude's own plugin cache root, neither evidence of a broken install, are both counted separately and never folded into this flag); stale-suspect (a Claude Code marketplace not refreshed in stale_days or more -- Codex's own marketplace sync recency is a separate, disclosed, unevaluated boundary); disabled-but-cached (a plugin explicitly disabled in its own harness config whose cache directory is still present on disk -- a disk note, not a security finding, that ties by name to agent-disk-tax, our separately published play that measures what that disk cost actually is). Every skill description is truncated to 80 characters before this play ever holds onto it, and no path this play would otherwise print survives into a diagnostic -- an OS error is reduced to a short, non-secret reason instead. Read-only throughout: this play edits, deletes, installs, enables, disables, and moves nothing, kills no process, and makes no network call of its own; needs only python3.ROTE2 STEPSREAD ONLY1 ↓286Python Ssl DoctorOne HTTPS request fails with CERTIFICATE_VERIFY_FAILED and silently breaks every tool built on that python -- the real-incident hook here: a single shadowed interpreter failing exactly that way once quietly broke four separate downstream tools before anyone thought to check which python each one was actually running. Five jobs, in order: finds EVERY python3 (and bare python) executable on THIS machine's PATH -- all hits, not just the one a bare `python3` would resolve to, since shadowing means the broken interpreter may be exactly the one a cron job or background tool runs, never the one a human happens to test by hand; fingerprints each install's SOURCE from its path and, when available, its own sys.prefix -- python.org framework build, homebrew, conda-anaconda, pyenv, uv-managed, system Command Line Tools, or unknown; runs exactly ONE bounded TLS handshake per discovered python against a fixed, well-known host (pypi.org:443 -- socket connect then an SSL wrap_socket() handshake, no HTTP request line, nothing sent or received beyond the handshake itself, run once per python and never more -- this is the play's only network activity, because that handshake outcome IS the diagnosis); for every python that fails, derives the EXACT fix for its own install source -- python.org: run its own Install Certificates.command; conda: conda install ca-certificates, and use that conda's python only inside its own envs; pyenv/homebrew: an openssl-linkage note plus a certifi check, both using this python's own measured values -- plus a universal fallback (pip install certifi; export SSL_CERT_FILE) shown for every broken python regardless of source; and reports, per python, its ssl module linkage (ssl.OPENSSL_VERSION), whether certifi is installed and where its bundle lives, and whether SSL_CERT_FILE / REQUESTS_CA_BUNDLE are set -- NAMES plus a set/unset flag plus whether the file each one points at exists, never the path value itself and never file contents. A timeout on any one python's handshake degrades only that python to an honest "unreachable -- network?, not necessarily a cert problem" verdict, kept deliberately separate from a real certificate failure; when every python fails identically, this play cross-notes that a network outage or DNS/firewall block would look exactly the same from here, since pypi.org's own availability is never independently confirmed beyond these per-python handshakes. Read-only, no credentials transmitted; TRUST BOUNDARY disclosed explicitly: this play executes EVERY matching python/python3/python3.N found anywhere on this user's own PATH -- not only the one a bare python3 would resolve to, since that breadth is the whole point of catching a shadowed interpreter -- with fixed -c scripts carrying no user input, twice per match (fingerprint, then handshake); each execution is gated by a fail-closed pre-exec trust check first (resolved target must be a regular file owned by root or this user, never world-writable, never writable by a group this user does not belong to, never sitting in a world-writable directory lacking the sticky bit), so a same-named file that is not actually this user's own trusted interpreter is reported as discovered but never run; needs only python3.ROTE2 STEPSREAD ONLY1 ↓287Scheduled Job GraveyardReports the scheduled jobs on THIS machine you have probably forgotten exist: your user crontab (crontab -l), your ~/Library/LaunchAgents plists (parsed via plutil -convert json, degrading per-file on a bad plist), launchd own live status for those LaunchAgents (launchctl list -- pid and last-exit code), and -- names only, content never opened, no sudo -- /etc/crontab, /etc/cron.d, and the system LaunchDaemons directories: five sources in all. On Linux the same crontab is read and systemd user timers (systemctl --user list-timers, plus each activated units own ExecStart line) stand in for LaunchAgents; every source degrades on its own rather than failing the whole play, and an absent source (no crontab, no LaunchAgents dir) is reported as a plain, honest absence, never a warning. Each user-owned job is classified as healthy, target-missing (the first absolute-path token found in its command no longer exists on disk), stale-suspect (that target mtime is older than stale_days with no recent-run evidence -- a live pid, or a recently-touched stdout/stderr log -- mtime alone is circumstantial, never proof), silent-failure-suspect (launchd own last exit status for that job, via launchctl list, is nonzero -- including the exit-127 signature that on macOS often means TCC quietly denied the job folder access, a real, documented failure mode this play demonstrates live on its own machine), or opaque (its command could not be parsed at all, or carried no absolute path -- labeled, never guessed at). Target-extraction is deliberately simple and shell-aware: only the first absolute-path token in a command is ever tested (after stripping any leading VAR=value environment assignments, and never scanning ahead into a later argument or into a shell wrapper quoted string such as sh -c "..."), so an interpreter-wrapped job such as /bin/zsh script.sh is checked against the interpreter, not the script -- a disclosed blind spot, not a bug, and exactly why launchd own exit status is weighed ahead of target mtime in this play classification order. Every inferential label carries -suspect wording and its rule stated plainly, never a certainty, and a nonzero exit status is reported as literally "last exit N -- check it", never "broken" or "dead". Nothing here edits a crontab, rewrites a plist, or loads/unloads/signals any job; every remove-or-fix and TCC advisory is printed as text only, for you to act on yourself. Read-only, no sudo, no credentials, no network; needs only python3 (plutil is macOS-builtin and optional, degrading per-file and per-source when it or a plist is missing or unparseable).ROTE2 STEPSREAD ONLY1 ↓288Command Shadow AuditWhen you type python3, what ACTUALLY runs -- and what did it silently replace? Five jobs, in order: statically parses a fixed list of shell rc files (~/.zshrc, ~/.zprofile, ~/.zshenv, ~/.bashrc, ~/.bash_profile, ~/.profile, ~/.bash_aliases -- plus whatever they literally `source` one level deep, tilde-expanded, cycle-safe, each file degrading independently) for alias, function, and PATH-export definitions, by reading their own text; walks THIS process's own $PATH, in order, for a watchlist of common commands (a built-in list plus anything you add), recording every hit -- directory, whether it is a symlink, its one-level link target, and which version-manager convention that directory matches (asdf, nvm, pyenv, rbenv, conda/anaconda, brew, ~/.local/bin, ~/.rote/bin, or plain system); joins the two and reports, per command, the winner using the shell's own precedence -- a function beats an alias beats the first PATH hit, stated explicitly because that is the one number this whole play hangs on -- and everything that decision silently shadows; optionally reads --version from every duplicate, but only for a small fixed allowlist of binaries (python3, python, node, git, curl, ruby, go, rustc, java), one 3-second-capped call each, never anything else and never through a shell; and grades each command's severity -- a function quietly standing in for a real binary is worst, a PATH duplicate carrying a different feature version is next, a same-version duplicate is just informational. Motivated by two real failure classes: a shell function silently shadowing curl and node once broke an entire plugin toolchain on a real machine, with nothing in the error output pointing at why; and on another machine, an older Anaconda python3 sat ahead of a newer Homebrew python3 on PATH -- one had Python's tomllib in its standard library and the other did not, so the exact same command ran a different program depending on shell state nobody had looked at. This play never executes your shell rc files and never opens an interactive shell -- every alias and function it reports comes from statically reading the rc files' own text, never from running them. Read-only, no credentials, no network; the only things this play ever executes are the fixed safe-allowlist version probes (python3/python/node/git/curl/ruby/go/rustc --version, java -version), each capped at 3 seconds, only when probe_versions=1; needs only python3.ROTE3 STEPSREAD ONLY1 ↓289Sql Query ReviewerValidate and review SQL queries for syntax and common engineering risks.ROTE2 STEPSREAD ONLY1 ↓290Change Impact MapRead-only change impact analysis for a proposed code change. Given a repository path, target symbol, and change description, locates definitions, direct and indirect references, imports, tests, git history, and config touchpoints; separates real dependencies from coincidental text matches; and returns a risk-ranked impact map with verification steps. Never modifies, commits, or pushes files.ROTE7 STEPSREAD ONLY1 ↓291Meeting To ActionROTE1 STEPSREAD ONLY1 ↓292Github Repo Committer Issue CheckTop committers and issues opened in the last N days for a GitHub repositoryAPISESSIONSGITHUB4 STEPSREAD ONLY1 ↓293Find Wasted TokensFind giant files and useless junk eating up your AI tokens. Scans your AI agent's chat history to show which files were loaded into memory but never actually used, how much money you wasted, and what you can safely remove. Zero setup, zero API keys, needs only python3.ROTE1 STEPSREAD ONLY1 ↓294Find Repeated PromptsFind the questions and instructions you type to your AI agent over and over again. Automatically groups your repeated prompts so you can turn them into fast, reusable 1-click tools. Zero setup, zero API keys, runs completely locally.ROTE1 STEPSREAD ONLY1 ↓295Find Outdated SkillsFind broken or outdated commands in your AI agent's instructions. Checks instructions in your README, SKILL.md, or AGENTS.md against the actual tools installed on your computer and shows you what needs fixing. Zero setup, zero keys, 100% safe.ROTE1 STEPSREAD ONLY1 ↓296Fact Check Ai ClaimsFact-check claims made by your AI against real public websites. Compares dates, prices, rules, and facts from 2 to 8 web pages and clearly flags when sources agree or contradict each other. Zero setup, zero API keys, 100% read-only.ROTE2 STEPSREAD ONLY1 ↓297Catch Sneaky ChangesCatch secret files, deleted code, or hidden changes your AI agent made without telling you. Compares your workspace before and after an agent session so nothing unexpected slips into your code. Zero setup, zero API keys, 100% safe and read-only.ROTE1 STEPSREAD ONLY1 ↓298Meeting Action TrackerConvert text into a concise action and decision report.ROTE2 STEPSREAD ONLY1 ↓299Smart Fitness CoachCustom daily workout split and fitness routine generator based on user goals and level.ROTE1 STEPSREAD ONLY1 ↓300Rl Signal DetectionDetect PPO/GRPO policy collapse, exploration death, and reward crashes with deterministic threshold citations.ROTE1 STEPSREAD ONLY1 ↓301Calorie Meal AdvisorCalorie target calculator and macro-tailored meal planner based on body metrics.ROTE1 STEPSREAD ONLY1 ↓302Why Did This BreakBounded-transition metadata forensics for finding time-aligned changes between a last-known-good and first-observed-broken state.ROTE1 STEPSREAD ONLY1 ↓303Ml Repository Due DiligenceInvestigate a public ML/AI GitHub repository and produce an evidence-backed use, reproduction, and research-value verdict.APISESSIONSGITHUB6 STEPSREAD ONLY1 ↓304ProbePostman in your CLI. Takes any URL or curl command, profiles latency (p50/p95/p99), auth/JWTs, and payload contracts, and generates an OpenAPI 3.1 spec ready for rote adapter create. Zero config, needs only python3 and curl.ROTE1 STEPSREAD ONLY1 ↓305Mindcraft 3d Game ForgeRegenerates the current MindCraft 3D game from its design and runs the self-healing browser playtest.ROTE2 STEPSREAD ONLY1 ↓306Agent Context PackerScans any local repo and instantly generates a complete Agent Context Brief — verified commands (test, build, lint, typecheck), stack fingerprint, architecture topology, sensitive path warnings, git state, env var preflight, and a ready-to-paste agent prompt. Run once at the start of every agent session. Zero network calls. Works on any language or framework. ROTE1 STEPSREAD ONLY1 ↓307Review Dependency Update PrReviews a public GitHub dependency update pull request and returns a conservative merge, review, or block recommendation with evidence, unknowns, and next checks.ROTE4 STEPSREAD ONLY1 ↓308Api Retry BackoffRetry API calls with exponential backoff on 429/5xx, give up after 5 attempts, log each retryROTE1 STEPSREAD ONLY1 ↓309Llm Cost TrackerTrack LLM token usage across sessions, calculate costs per provider, alert on budget threshold, log cost spikesROTE1 STEPSREAD ONLY1 ↓310Vibe DebtAudits what an AI coding session left behind in a repository: env vars read at runtime that no .env.example or README documents, packages imported but undeclared (and declared but unused), vendor credentials inlined in source, and files nothing imports. Read-only, no network, no credentials.ROTE4 STEPSREAD ONLY1 ↓311Agentic Generate ReviewGenerates code for a task using a local coding model (spark-coder, a Claude-Code-CLI-compatible wrapper pointed at a local model), then reviews the resulting git diff with an Anthropic model via the claude CLI. Returns the review text ending in a VERDICT: APPROVE or VERDICT: CHANGES NEEDED line. Requires spark-coder (or an equivalent local generator) to actually produce code; degrades to a labeled unknown if it is absent.ROTE2 STEPSREAD ONLY1 ↓312Github Pr Mergeability MonitorMonitors a GitHub pull request with gh, runs an unattended Codex CLI worker for new reviews and CI failures, and reports when the PR reaches a stable mergeable state.ROTE0 STEPSREAD ONLY1 ↓313Spark Fleet HealthChecks a local LLM dev backend's fleet readiness: whether claude-code-router is running, whether the model host is reachable via Ollama or llama-server, which models are loaded, and a combined READY/NOT READY verdict. Read-only, no credentials, no adapters.ROTE3 STEPSREAD ONLY1 ↓314Cypher Network SpycrapValorant Cypher surveillance: monitors DNS drift, TLS certificate expiration dates, and stale CNAME takeovers.ROTE1 STEPSREAD ONLY1 ↓315Shinobi Dead Route AssassinSekiro stealth: crawls backend Express/Fastify routes and eliminates dead, deprecated, and unauthenticated endpoints.ROTE1 STEPSREAD ONLY1 ↓316Expedition Cache InvalidatorExpeditions-grade cache sync: purges CloudFront, Redis, and Cloudflare stale CDN edges across microservice clusters.ROTE1 STEPSREAD ONLY1 ↓317Omen Killer Db Pool DoctorDetects connection pool starvation, deadlocks, and unindexed slow queries in PostgreSQL, MySQL, and MongoDB.ROTE1 STEPSREAD ONLY1 ↓318Llm Provider HealthMonitor LLM provider health, trip circuit breaker on 429/5xx, switch to fallback, log healing actionROTE1 STEPSREAD ONLY1 ↓319Github Pr QaInspect a GitHub pull request, test its user-facing behavior through an accessible deployment or isolated local fallback, and return a PASS/FAIL browser QA report.SESSIONS0 STEPSREAD ONLY1 ↓320Job Resume MatchAnalyze a public job posting against a local resume and produce an evidence-backed application analysis.ROTE4 STEPSREAD ONLY1 ↓321Explain Github IssueFetches a single GitHub issue by owner/repo/number and presents a structured digest for plain-English explanationAPISESSIONSGITHUB2 STEPSREAD ONLY1 ↓322Ml Deployment ReadinessRead-only ML deployment-readiness assessment for a local project.ROTE4 STEPSREAD ONLY1 ↓323List Google SheetsLists Google Sheets spreadsheets in your Google account with title, ID, modified time, and web URL.APISESSIONSDRIVE-API-V32 STEPSREAD ONLY1 ↓324Hackathon Release ReadinessInspect a repository and report release blockers, safe test/demo results, and whether tests pass while the documented demo path is broken.ROTE4 STEPSREAD ONLY1 ↓325Last Commit SummaryReturn the last commit SHA, author, date, and message for a GitHub repositoryROTE2 STEPSREAD ONLY1 ↓326Env DoctorIs your .env healthy? Checks key drift vs .env.example, scans for leaked secrets, validates KEY=VALUE format, and verifies optionalROTE4 STEPSREAD ONLY1 ↓327Hackathon Official Source AuditAudits an official hackathon website for dates, prizes, eligibility, judging, sponsor technology, submission and social requirements, blockers, and a T-minus plan.ROTE5 STEPSREAD ONLY1 ↓328Github Authored Issues In RangeLists open GitHub issues authored by a user within a created-date range, verified against GitHub's search total.APISESSIONSGITHUB6 STEPSREAD ONLY1 ↓329Github My Issues PriorityList open GitHub issues assigned to a user in a repo and rank them by priority/effort matrix (high priority, low effort first)APISESSIONSGITHUB2 STEPSREAD ONLY1 ↓330Axiom Pippin Error InvestigatorInvestigates a Pippin Discord error ID in Axiom, resolves its trace, and reports Discord API failures and the likely failed source message.SESSIONS0 STEPSREAD ONLY1 ↓331Github Actions Workflow DispatchDispatch a GitHub Actions workflow_dispatch run with optional inputs and return the run URLSESSIONS0 STEPSREAD ONLY1 ↓332Github Create Pull RequestCreate a GitHub pull request from a pushed branch.SESSIONS0 STEPSREAD ONLY1 ↓333Github Pr Ci TriageSummarize non-success GitHub check runs for a pull request head SHA and poll after updatesSESSIONS0 STEPSREAD ONLY1 ↓334Femme Cadence WatcherBiological cadence daemon, hormonal phase telemetry probe, and adaptive self-care dispatcher.ROTE1 STEPSREAD ONLY0 ↓335Secret LoggingFinds the places a codebase writes a credential into a log. Reports a secret-named value handed to a log call, a whole environment, header, config or request object logged wholesale, a caught error logged with its full request context, and JSON serialisation of an object with secret-shaped keys, across JavaScript, TypeScript, Python, Go and Java-ish sources. Comments and string bodies are masked by a language-aware lexer, so a comment or doc string that merely names a logging call is never a finding, and every argument is screened for redaction first: a boolean, a length, a hash or a deliberate last-four slice is how careful code logs a credential presence, not a leak. tokenizer, tokens, keyboard, secretName, passwordField and API_KEY_HEADER_NAME are not secret values, and process.env.NODE_ENV is not process.env. Read-only, no network, no credentials.ROTE2 STEPSREAD ONLY0 ↓336Sourcemap ExposureFinds production build output that hands the public your original source. Grades by reach and by content instead of counting *.map files. A map in .next/static is served to every visitor, a map in .next/server ships inside the image but no browser can fetch it, and a map under .next/dev or .next/cache was written by the dev server and never published at all. Content then decides severity, because a map carrying sourcesContent for your own code is full source disclosure, the same map carrying only node_modules source leaks bundle shape, and a map with relative sources and no content leaks a file tree and nothing more. Reads index maps through their sections, so a turbopack map with an empty top-level sources array is still graded on what its sections carry. Follows every sourceMappingURL comment and separates a reference whose target is shipped from a broken one that 404s, and decodes data URI maps that travel inside the bundle where there is no separate file to delete. Also reads the build config that decides the next build, including productionBrowserSourceMaps, webpack devtool, and the vite and tsup sourcemap options, with a real tokenizer, so a commented-out setting and a NODE_ENV ternary are not reported as enabled. Read-only, never builds anything.ROTE2 STEPSREAD ONLY0 ↓337Makefile AuditFinds the Makefile problems that make a build silently wrong rather than loudly broken, with make syntax actually parsed instead of grepped. Reports targets that are not .PHONY but produce no file of their own name, so `make test` turns into a no-op the moment a directory named test exists; targets declared .PHONY that no rule defines, so make prints Nothing to be done and exits 0; duplicate recipes where the later one silently wins; bash-only syntax in a recipe while SHELL is still /bin/sh; a cd on one recipe line that is thrown away before the next, because each line is its own shell; a shell variable read back empty across that same boundary; $(shell ...) in a := over a path this Makefile itself builds; undefined variables that expand to nothing, which is what turns rm -rf $(BUILD_DIR)/ into rm -rf /; prerequisites nothing defines; and sibling prerequisites that write the same path, so make -j races them. It knows where make's rules do not apply, so it does not invent findings: recipe lines start with a TAB and a space-indented line is not a recipe, backslashes join logical lines, ifeq/ifdef branches mean a target may be conditionally defined, pattern and static pattern and double-colon and suffix rules are not ordinary targets, .PHONY accumulates across every declaration, special targets are not build targets, a target that really does produce its own file is right not to be .PHONY, $@ and lt; and $^ are automatic variables, a variable the recipe guards with [ "$(TAG)" ] is a documented command-line parameter, .ONESHELL retires the per-line shell rules and .NOTPARALLEL retires the -j rule. Read-only, and it never runs make.ROTE2 STEPSREAD ONLY0 ↓338Package ShipReports what an npm package will actually publish, as against what its author believes it publishes. The gap between those two is where credentials and dead weight escape. Derives the tarball statically, the way npm does: the files allowlist if package.json has one, else .npmignore, else .gitignore, plus the always-included list (package.json, README, LICENSE, the main file) and the always-excluded list (.git, node_modules, .npmrc, lockfiles). Names the credentials that would ship and opens each one to confirm it holds a live value rather than a placeholder, the entry points in main, module, types, exports and bin that resolve to a path the tarball will not contain (a package that installs broken), the files patterns that match nothing, the total shipped size and the largest shipped files. Skips private packages, because a private package is never published and its contents are not a publishing risk. Never runs npm pack, which would need a network-capable npm, execute the package prepare scripts and write a tarball into the directory under audit. Offline, read-only, no registry call, no credentials.ROTE2 STEPSREAD ONLY0 ↓339Playoffs PulseLeaderboard for the Rote Playoffs hackathon.ROTE2 STEPSREAD ONLY0 ↓340Sponsor Track MatcherProvide a structured sponsor-track-matcher plan from supplied project context, with explicit uncertainty and no external side effects.ROTE1 STEPSREAD ONLY0 ↓341Hackathon Rule CheckerProvide a structured hackathon-rule-checker plan from supplied project context, with explicit uncertainty and no external side effects.ROTE1 STEPSREAD ONLY0 ↓342Fallback Plan GeneratorProvide a structured fallback-plan-generator plan from supplied project context, with explicit uncertainty and no external side effects.ROTE1 STEPSREAD ONLY0 ↓343Pitch Claim CheckerProvide a structured pitch-claim-checker plan from supplied project context, with explicit uncertainty and no external side effects.ROTE1 STEPSREAD ONLY0 ↓344Telegram PosterPost content to Telegram with text, optional media, and optional schedulingROTE1 STEPSREAD ONLY0 ↓