mvanhorn/last30days-skill
72.7
Strong · 26 September 2026
56.4k
lines of production code
Python
primary language
4
measurements over time
What this system is
This system is a research and briefing tool that aggregates public sentiment and news from sources like Reddit, X, and YouTube to generate daily or weekly digests. It operates as a standalone Go-based MCP server for Claude Desktop, embedding a Python research engine that supports local file corpora and interactive topic discovery. The platform includes comprehensive evaluation harnesses for quality regression testing and security scanning to ensure reliable and safe installation.
Features
Embedded Python research engine with automatic cache extraction
The MCP server now bundles the 'last30days' Python research engine directly into the binary. On first use, the engine is automatically extracted to a per-user cache directory (configurable via the LAST30DAYS\_CACHE\_DIR environment variable) and executed via a subprocess. This change introduces a five-minute default execution timeout (configurable via LAST30DAYS\_MCP\_TIMEOUT) and ensures the engine's internal Python path is isolated by deduplicating the PYTHONPATH environment variable for the child process.
mcp/internal/engine · high confidence
New MCP tools for safe preflight checks and topic research
The MCP server now exposes two new tools: a 'preflight' tool that summarizes what the system would read, write, and contact without performing any actions, and a 'research' tool that aggregates public sentiment from sources like Reddit, X, and YouTube. The research tool includes a consent-gated browser-cookie feature, disabled by default and only enabled via the LAST30DAYS\_MCP\_ALLOW\_BROWSER\_COOKIES environment variable, and supports saving outputs as markdown reports.
mcp/internal/tools · high confidence
New last30days MCP server for Claude Desktop
A new standalone executable (last30days-pp-mcp) is introduced to serve as an MCP server for Claude Desktop. It registers a single 'research' tool via the internal tools package and communicates over stdio, allowing users to access the last30days functionality directly within the Claude Desktop environment.
mcp/cmd · high confidence
New local corpus source and structured discovery handoff protocol
The skill now supports a local file corpus source that scans user-specified directories for text and PDF documents, integrating them as ranked signals alongside web sources. Additionally, a new three-leg discovery protocol has been introduced, allowing users to nominate topics, provide host judgments, and finalize angles via file-based handoff contracts, enabling a more interactive and host-judged topic discovery workflow.
last30days-skill · high confidence
New operational scripts and library modules for the last30days skill
This change introduces a suite of new runtime components for the last30days skill. It adds a morning briefing generator (\briefing.py\) that synthesizes watchlist findings into daily and weekly digest data. It includes a new X login helper (\box\_chrome\_login.py\) to manage throwaway Chrome sessions for extra hosts, and an \agentcookie\ sidecar reader to extract X cookies from an external CLI. The update also brings in source modules for Amazon (via Bright Data), arXiv, and a search quality evaluation harness (\evaluate\_search\_quality.py\). Additionally, it provides build and testing utilities, including a skill packaging script (\build-skill.sh\) and an A/B test runner (\compare.sh\).
skills/last30days/scripts · high confidence
Packaging and repository hygiene files added
The repository now includes \.clawhubignore\, \.skillignore\, \.gitattributes\, and \.gitignore\ to control which files are included in skill bundles and git archives. These files exclude non-runtime artifacts such as documentation, tests, and development scripts from the public skill package, ensuring a cleaner and more secure installation. Additionally, \.gitattributes\ normalizes line endings to LF to prevent unnecessary diffs on Windows.
(repo-wide) · high confidence
Removals
Removal of legacy last30days skill library modules
The \scripts/lib\ directory has been completely removed, deleting the underlying implementation for the \last30days\ skill. This eliminates the local caching, near-duplicate detection, environment configuration, HTTP utilities, model auto-selection, data normalization, output rendering, data schemas, and popularity-aware scoring logic that previously powered the skill's research and reporting capabilities.
scripts/lib · high confidence
Removal of the standalone last30days research script
The dedicated \scripts/last30days.py\ script, which previously allowed users to research topics from the last 30 days using Reddit and X (via OpenAI and xAI APIs), has been removed from the codebase. This change eliminates the specific CLI entry point and its associated logic for date-filtered, dual-source research, indicating that this capability has likely been integrated into the main engine or replaced by other search features.
scripts · high confidence
Behavioural changes
Automated Python engine synchronization for Go binary embedding
A new shell script, sync-engine.sh, has been added to the mcp/scripts directory to manage the bundling of the Python engine into the Go application. This script mirrors the source files from skills/last30days/scripts/ into the internal/engine/vendored/ directory, ensuring that the Go binary's embed.FS captures the latest engine code at build time. It automatically handles directory creation, removes stale content, and strips Python cache files (\_\pycache\\_, .pyc) to maintain deterministic builds, serving as the required pre-build step for local development and CI.
mcp/scripts · high confidence
Improved security scanning and installation reliability for the Last 30 Days skill
The Last 30 Days skill now includes a \.skillignore\ file to exclude non-runtime artifacts (such as build scripts, test suites, and vendor libraries) from install-time security scans, preventing false-positive CRITICAL findings that previously caused the installation verdict to show as 'caution'. Additionally, the skill's metadata has been updated to version 3.25.0, and the documentation has been corrected to reflect the accurate count of eleven governing laws (LAWs) for output formatting.
skills/last30days · high confidence
New fixtures for Reddit scraping and offline evaluation
Added sample data files to support the new Reddit scraping implementation and quality evaluation workflows. The \fixtures/reddit\_listing\_cards\_sample.html\, \fixtures/reddit\_search\_rss\_sample.xml\, and \fixtures/reddit\_shreddit\_comments\_sample.html\ files provide captured HTML and Atom XML structures for the new keyless RSS and shreddit-based scraping paths, replacing the previous JSON-dependent methods. Additionally, \fixtures/eval\_topics.json\ introduces a set of predefined topics and query types to enable offline quality evaluation of the system's responses.
fixtures · high confidence
Test coverage
Added regression test to prevent re-blocking Hermes community installs; Added research-quality regression evaluation harness and fixtures; Added structural validation tests for the MCPB v0.3 manifest.
Dependencies
Introduce Go-based MCP server and update Python/JS dependencies
This change scaffolds a new Go module under the \mcp/\ directory to provide a stdio Model Context Protocol (MCP) server, upgrading the \github.com/mark3labs/mcp-go\ dependency to v1.0.0. It also adds a \pyproject.toml\ for the \last30days-skill\ Python project (version 3.25.0) with development dependencies like pytest and towncrier, and vendors a \bird-search\ Node.js package (v0.8.0) requiring Node \>=22.
(dependencies) · high confidence
Housekeeping
Changelog management workflow and release notes for Windows MCP controls and save-suffix security fix
This change introduces a towncrier-based changelog fragment workflow, including a README and a .gitkeep file to manage release notes. It also adds specific release notes for two distinct changes: the addition of consent-gated Windows MCP host controls (allowing explicit Python interpreters and browser cookie restrictions) and a security fix that sanitizes the --save-suffix argument to prevent directory traversal.
changelog.d · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 53 → 73 (+20.0)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 85 → 74 (-11.6)
- Architecture 93 → 98 (+5.3)
- Maturity 72 → 63 (-9.6)
- Readiness 28 → 85 (+57.2)
- Security 70 → 94 (+23.9)
Resolved (54)
- ADR not followed: 891.fixed (changelog.d/891.fixed.md)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (10 lines × 2) (tests/test_fusion_v3.py)
- Duplicated block (10 lines × 2) (tests/test_signals_v3.py)
- Duplicated block (12 lines × 2) (tests/test_planner_v3.py)
- Duplicated block (16 lines × 2) (tests/test_pipeline_v3.py)
- Duplicated block (16 lines × 3) (tests/test_render_v3.py)
- Duplicated block (5 lines × 2) (tests/test_transcribe.py)
- Duplicated block (5 lines × 2) (tests/test_youtube_yt.py)
- Duplicated block (6 lines × 2) (tests/test_bluesky.py)
- Duplicated block (6 lines × 2) (tests/test_bluesky.py)
- Duplicated block (6 lines × 2) (tests/test_last_run_state.py)
- Duplicated block (6 lines × 2) (tests/test_setup_wizard.py)
- Duplicated block (6 lines × 4) (tests/test_grounding_v3.py)
- Duplicated block (7 lines × 2) (tests/test_cli_v3.py)
- Duplicated block (7 lines × 2) (tests/test_evaluator_v3.py)
- Duplicated block (7 lines × 2) (tests/test_github.py)
- Duplicated block (7 lines × 2) (tests/test_linkedin.py)
- Duplicated block (7 lines × 2) (tests/test_rerank_v3.py)
- …and 34 more
New (531)
- Change coupling: instagram.py ↔ tiktok.py (skills/last30days/scripts/lib/instagram.py)
- Duplicated block (10 lines × 2) (skills/last30days/scripts/lib/render.py)
- Duplicated block (10 lines × 2) (skills/last30days/scripts/store.py)
- Duplicated block (10 lines × 3) (skills/last30days/scripts/lib/github.py)
- Duplicated block (10 lines × 3) (skills/last30days/scripts/lib/instagram.py)
- Duplicated block (10 lines × 3) (skills/last30days/scripts/lib/instagram.py)
- Duplicated block (10–11 lines × 2) (skills/last30days/scripts/lib/normalize.py)
- Duplicated block (10–11 lines × 2) (skills/last30days/scripts/lib/tiktok.py)
- Duplicated block (11 lines × 2) (skills/last30days/scripts/lib/brightdata.py)
- Duplicated block (11 lines × 2) (skills/last30days/scripts/lib/normalize.py)
- Duplicated block (11–12 lines × 2) (skills/last30days/scripts/lib/bird_x.py)
- Duplicated block (11–12 lines × 2) (skills/last30days/scripts/lib/instagram.py)
- Duplicated block (11–17 lines × 2) (skills/last30days/scripts/lib/normalize.py)
- Duplicated block (12 lines × 2) (skills/last30days/scripts/lib/reddit.py)
- Duplicated block (12 lines × 2) (skills/last30days/scripts/lib/rerank.py)
- Duplicated block (12–13 lines × 2) (skills/last30days/scripts/lib/reddit_listing.py)
- Duplicated block (13–14 lines × 2) (skills/last30days/scripts/lib/render.py)
- Duplicated block (13–16 lines × 5) (skills/last30days/scripts/lib/pipeline.py)
- Duplicated block (13–17 lines × 2) (skills/last30days/scripts/lib/pipeline.py)
- Duplicated block (14 lines × 2) (skills/last30days/scripts/lib/render.py)
- …and 511 more
Changes since last survey
- 108 commits — 58 feature/other, 50 fixes
By area
- (root) — 25 commits
- skills/last30days — 23 commits
- .github/workflows — 20 commits
- mcp/go.mod — 3 commits
- mcp/internal — 2 commits
- changelog.d/+base-url-api-root.fixed.md — 1 commit
- changelog.d/+doctor-transient-probe.fixed.md — 1 commit
- changelog.d/+fence-escape.security.md — 1 commit
- changelog.d/+fixture-credential-redaction.security.md — 1 commit
- changelog.d/+grok-x-windows-utf8-decode.fixed.md — 1 commit
- changelog.d/+groq-transcribe-user-agent.fixed.md — 1 commit
- changelog.d/+keychain-presence.security.md — 1 commit
- changelog.d/+safari-cookie-domain-match.security.md — 1 commit
- changelog.d/+verify-v3-test-runner.fixed.md — 1 commit
- changelog.d/1017.fixed.md — 1 commit
- changelog.d/1043.fixed.md — 1 commit
- changelog.d/1051.fixed.md — 1 commit
- changelog.d/1053.security.md — 1 commit
- changelog.d/1062.security.md — 1 commit
- changelog.d/1063.fixed.md — 1 commit
Notable commits
- fix: fix(amazon): start review lane at search time so multi-source runs keep a real budget (#999)
- fix: fix(arxiv): preserve adapter-valid papers during normalization (#947)
- fix: fix(bird): pass only the vendored client's env surface to the subprocess (#1072)
- fix: fix(bluesky): use refresh tokens for expired sessions (#1065)
- fix: fix(ci): restore scheduled OSV scanner startup (#1112)
- fix: fix(ci): skip changelog fragments for Dependabot PRs (#1143)
- fix: fix(competitors): refuse a comparison headed by a competitor when the main topic fails (#1117)
- fix: fix(cookies): anchor Safari cookie host matching to the domain (#1118)
- fix: fix(cookies): parse Windows Firefox profiles.ini as UTF-16 (#1068)
- fix: fix(docs): fix broken star history chart (#1023)
- fix: fix(doctor): retry rate-limited probes instead of reporting a false outage (#971)
- fix: fix(env): add LAST30DAYS_SKIP_KEYCHAIN so tests can seal the Keychain source (keychain-only port of #1050) (#1090)
- fix: fix(env): strip trailing inline comments from unquoted .env values (#1121)
- fix: fix(env): treat unsubstituted config templates as unconfigured (#1126)
- fix: fix(github): bound qualifier-only topic fragments in errors and logs so fanout cannot spam them (#954) (#1039)
- fix: fix(github): qualifier-only or empty topics are clean no-results, not ERROR (#953) (#1130)
- fix: fix(github): query is:issue and is:pull-request when authenticated + partition honesty (#994)
- fix: fix(github): strip planner-injected search qualifiers from topic queries (#955)
- fix: fix(github): strip wrapped search qualifiers from topics (#952) (#970)
- fix: fix(grok): decode CLI stdout as UTF-8, not the OS locale codec (#1025)
- …and 88 more
Architecture
- Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed
Added bounded contexts (1)
- last30days-skill
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mvanhorn/last30days-skill was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 084662b501fb0dba95bd55eff0c258d35e0dc499 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-09659c52afae.