Skip to content
CAI
Software that uses CAICheck a score

agntcy/oasf

59.0

Adequate · 3 October 2026

12.4k

lines of production code

Elixir

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Open Agentic Schema Framework (OASF), a Kubernetes-deployable HTTP service built with Elixir and Phoenix that manages and serves versioned AI agentic schema definitions. It provides RESTful API endpoints and a browser-based interface for browsing, validating, and visualizing schema entities such as skills, domains, and modules. The service supports multi-version deployments and includes tooling for generating JSON schemas, sample data, and interactive class graphs.

Features

Added v1 and alpha schema definitions for AI agentic records

This change introduces the Protocol Buffer schema definitions for the OASF Record object, establishing the data model for versioned AI agentic content. It adds the \v1\ stable schema (including \Descriptor\, \Domain\, \Locator\, \Module\, \Record\, and \Skill\ messages) alongside \v1alpha0\, \v1alpha1\, and \v1alpha2\ experimental versions. These definitions provide the structured format for describing record metadata, source locators (such as Helm charts or container images), skills, and modules, enabling clients to serialize, validate, and distribute records as OCI artifacts.

proto/agntcy · high confidence

Initial implementation of schema web views and layout helpers

The server now includes the core view modules for the schema web interface, introducing \ErrorView\, \LayoutView\, and \PageView\. \LayoutView\ provides helpers for formatting profiles and extensions, and implements version-aware path generation to support accessing documentation and resources under specific schema version URLs. \PageView\ contains the logic for generating class and object graph paths, rendering profile badges and links, and calculating indentation levels for class hierarchies, enabling the UI to correctly display nested class structures and applicable profiles.

_server/lib/schema\web/views · high confidence

Initial release of schema web controllers and routing infrastructure

This change introduces the core web controllers and supporting plugs for the schema server. It adds a health check endpoint, a page controller that renders class graphs (skills, domains, modules), object graphs, data types, profiles, and category taxonomies, and a schema controller exposing API endpoints for versions, data types, extensions, and profiles. It also includes a version-aware Swagger UI controller that dynamically prefixes API paths with the schema version, and plugs for request logging (silencing health checks) and stripping version prefixes for local development.

_server/lib/schema\web/controllers · high confidence

Initial release of the OASF Helm chart

This change introduces the OASF Helm chart for Kubernetes deployment, establishing the foundational configuration structure. The chart defines the application version as 1.16.0 and provides default values for image repositories, service exposure (ClusterIP by default), and environment variables. It includes specific test value files (\values-test.yaml\, \values-test-versions.yaml\) that enable ingress, NodePort services, and multi-version server support for local development and testing scenarios.

install/charts/oasf · high confidence

Initial release of the OASF Schema API server and web interface

This change introduces the core web infrastructure for the Open Agentic Schema Framework (OASF) server. It establishes the Phoenix-based HTTP endpoint and router, exposing a comprehensive set of RESTful API endpoints under \/api\ and \/schema\ for managing skills, domains, modules, objects, and data types, including specific routes for validation and translation. Additionally, it provides a browser-accessible web interface for browsing these categories and graphs, along with a version-aware Swagger UI accessible at \/doc\ and \/:version/doc\ to document the API.

_server/lib/schema\web · high confidence

Initial release of the schema server library

The schema server library is now available in \server/lib/schema\, providing the core infrastructure for managing, validating, and generating data based on the OASF schema. This includes a cache system for loading schema definitions, a JSON schema generator for creating standard JSON schemas, a validator for checking input data against the schema, a translator for converting internal types to user-friendly formats, and a sample data generator. The library also supports schema extensions and provides utilities for handling class taxonomies, profiles, and graph visualizations.

server/lib/schema · high confidence

Initial repository structure and documentation

The repository is initialized with foundational project files, including a .gitignore, pre-commit configuration for formatting, and a .trivyignore file that suppresses specific CVEs ([CVE redacted], [CVE redacted]) with documented justifications. Standard open-source governance documents are added, such as the Apache 2.0 License, Code of Conduct, Contributor Covenant, and Maintainers list. A comprehensive README introduces the Open Agentic Schema Framework (OASF), its key concepts, and integration with the Directory MCP Server. Development tooling is established via a Taskfile.yml for building and deploying the server in a Kind cluster, a docker-bake.hcl for container builds, and a renovate.json for automated dependency updates.

(repo-wide) · high confidence

Initial server configuration setup

The server's configuration files (config.exs, dev.exs, prod.exs, releases.exs, test.exs) have been added, establishing the baseline settings for the Phoenix application. This includes environment-specific logging levels, endpoint configurations for HTTP ports and schema paths, and the integration of Google Analytics via an environment variable. It also sets up the JSON library (Jason) and Swagger documentation paths.

server/config · high confidence

Initial server implementation and Docker build configuration

The server component is introduced as a new Phoenix-based HTTP service for browsing and using the Open Agentic Schema Framework (OASF) schema. This change adds the complete build infrastructure, including a multi-stage Dockerfile that compiles the Elixir release and runs it on Alpine Linux, along with development scripts and environment samples. The server exposes port 8080 and is configured via environment variables such as SCHEMA\_DIR and LOG\_LEVEL, providing the foundational runtime and deployment artifacts for the schema service.

server · high confidence

Initial server private assets and static styles

The server/priv directory now includes foundational static assets and data files. This adds a complete set of CSS stylesheets (app, base, components, layout, tables, and variables) to define the application's visual presentation, including typography, status badges, and deprecated element styling. It also introduces a placeholder file for SSL certificates and several data files containing country/continent codes, file extension mappings, and word/name lists, which support server-side data processing and UI generation.

server/priv · high confidence

The application layout now includes support for Google Analytics tracking, gated by explicit user consent. A cookie consent banner is displayed to users who have not previously made a choice, allowing them to accept or decline tracking. If consent is granted, the Google Tag Manager script is loaded; if declined, tracking is disabled. This change ensures compliance with privacy preferences while enabling usage analytics for the Open Agentic Schema Framework UI.

_server/lib/schema\web/templates/layout · high confidence

Introduction of multi-version schema support and family-parameterized class access

The server now supports managing multiple schema versions simultaneously via the new \Schemas\ module, which parses and stores version metadata (including server, API, and default flags) in an Agent. This enables the \Schema\ module to expose family-parameterized accessors for skills, domains, and modules, allowing users to query classes, taxonomies, and profiles by specifying a \:skill\, \:domain\, or \:module\ family. The \SchemaWeb\ module provides the standard Phoenix web interface entry points for controllers, views, and routers, integrating with the new schema context.

server/lib · high confidence

New schema documentation pages for classes, objects, and categories

The schema documentation UI now includes dedicated pages for classes, objects, categories, profiles, and data types, replacing the previous single-page layout. Users can browse a taxonomy or card view of the schema, view detailed attribute tables with requirement filtering (optional/recommended), and explore interactive network graphs for class and object relationships. The new pages also support JSON Schema viewing, sample data display, and validation API access directly from the interface.

_server/lib/schema\web/templates/page · high confidence

Support for multi-version schema deployments

The Helm chart now supports deploying multiple schema versions simultaneously. Instead of a single deployment, the chart iterates over a list of image versions (defined in \image.versions\), creating separate Deployment, Service, and HorizontalPodAutoscaler resources for each schema version, distinguished by labels and names. A ConfigMap is also generated to track the available schema and server versions, and helper templates have been added to manage ingress path regexes and annotations for both community and F5 ingress controllers.

install/charts/oasf/templates · high confidence

Test coverage

Added Elixir integration tests for SchemaController and Swagger XSS protection; Added schema validation and regression tests; Added schema validation tests for entity files and extensions; Added tests for JSON schema and Proto synchronization; Added tests for SchemaWeb layout and page view helpers.

Dependencies

Initial dependency manifests for security scripts and test modules

This change introduces the initial dependency lockfiles and manifests for three distinct areas: the GitHub Actions security scripts (using Node.js with @octokit/rest and glob), the Go-based proto test module, and the Go-based schema test module. It also adds the initial Elixir server project configuration (mix.exs and mix.lock) defining the Phoenix stack and development tooling. These files establish the baseline package versions and build tooling for these specific components.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 55 → 59 (+3.8)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 89 → 92 (+2.6)
  • Architecture 88 → 92 (+3.9)
  • Maturity 54 → 54 (+0.2)
  • Readiness 69 → 77 (+7.1)
  • Security 75 → 84 (+8.7)
  • Accessibility 43 → 48 (+4.1)

Resolved (28)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (18 lines × 5) (server/lib/schema_web/views/page_view.ex)
  • Duplicated block (31 lines × 4) (server/lib/schema_web/views/page_view.ex)
  • Duplicated block (6 lines × 2) (server/lib/schema/json_schema.ex)
  • High CVE: [GHSA redacted] (server/mix.lock)
  • High CVE: [GHSA redacted] (server/mix.lock)
  • High CVE: [GHSA redacted] (server/mix.lock)
  • High CVE: [GHSA redacted] (server/mix.lock)
  • High CVE: [GHSA redacted] (server/mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (server/mix.lock)
  • Medium IaC: WD-DOCKER-0003 (server/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (server/Dockerfile)
  • Members sharing a duplicated core (5 members, 50+ identical tokens) (server/lib/schema_web/views/page_view.ex)
  • No artifact signing
  • No build provenance
  • …and 8 more

New (22)

  • Duplicated block (19 lines × 5) (server/lib/schema_web/views/page_view.ex)
  • Duplicated block (31 lines × 4) (server/lib/schema_web/views/page_view.ex)
  • Duplicated block (6 lines × 2) (server/lib/schema/profiles.ex)
  • Duplicated block (8 lines × 2) (server/lib/schema/json_schema.ex)
  • Medium CVE: EEF-[CVE redacted] (server/mix.lock)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Members sharing a duplicated core (5 members, 50+ identical tokens) (server/lib/schema_web/views/page_view.ex)
  • …and 2 more

Changes since last survey

  • 17 commits — 12 feature/other, 5 fixes

By area

  • .github/workflows — 6 commits
  • server/lib — 6 commits
  • (root) — 2 commits
  • proto/test — 1 commit
  • server/Dockerfile — 1 commit
  • server/config — 1 commit

Notable commits

  • fix: fix(ci): scope image cleanup packages token to the job (#499)
  • fix: fix(server): bump alpine runtime image for openssl CVEs (#523)
  • fix: fix(server): escape the name echoed in 404 responses (#527)
  • fix: fix(server): escape the swagger document embedded in the UI page (#525)
  • fix: fix(server): stop converting request-supplied names to new atoms (#508)
  • change: chore(server): record why the sobelow findings are safe (#535)
  • change: chore(server): remove the unused splunk config (#533)
  • change: ci(ci): pin remaining unpinned dependencies by hash (#503)
  • change: ci(ci): point the latest tag at the image built from main (#531)
  • change: ci(ci): publish an image from main and scan it instead of the release (#529)
  • change: ci(ci): scan elixir with sobelow and workflows with codeql (#514)
  • change: ci(ci): sign the server image and attest build provenance (#521)
  • change: deps(ci): update go test module dependencies for security advisories (#504)
  • change: deps(server): update elixir dependencies for security advisories (#506)
  • change: docs(ci): add a CHANGELOG to the repository root (#520)
  • change: docs(ci): add openssf best practices badge (#515)
  • change: test(server): add property-based tests for the validator and translator (#511)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

agntcy/oasf was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 56f1bfb155d09d759a38be17cad8c640940bc692 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-24c657e50118.