Skip to content
CAI
Software that uses CAICheck a score

NoahDuongMaster/vibe-code-stack-for-ceos

66.5

Adequate · 21 September 2026

13.3k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a monolithic, multi-service platform for cryptocurrency trading and administration, built on a strict, layered architecture. It comprises distinct applications for the user-facing dapp, admin panel, and marketing landing page, all supported by specialized backend services for authentication, market data, and API routing. The infrastructure manages critical data persistence and disaster recovery for PostgreSQL, while the codebase enforces rigorous engineering standards through automated tooling and architectural boundaries.

Features

Add PostgreSQL backup and disaster-recovery infrastructure

The infrastructure now includes a complete PostgreSQL backup and disaster-recovery system. This introduces a \postgres-backup\ service that manages scheduled incremental, differential, and full backups, along with Point-in-Time Recovery (PITR) drills and monthly archive retention. The change adds the necessary Docker Compose configurations, Dockerfiles, and shell scripts to support these backup operations across development, staging, and production environments.

infra · high confidence

Add automated validation scripts for toolchain, architecture, and deployment

The repository now includes a suite of TypeScript scripts in the \scripts/\ directory that enforce structural and operational constraints. \check-toolchain.ts\ validates that the local Node.js and pnpm versions match the project's \.nvmrc\ and \packageManager\ declarations. \check-backend-architecture.ts\ enforces module boundaries and import rules for the backend codebase. \check-install-context.ts\ and \.pnpmfile.mjs\ prevent direct \pnpm install\ usage, requiring developers to use \mise setup\ instead. \check-mise-routing.ts\ ensures all root scripts are routed through \mise\ without recursion. \check-pr-size.ts\ enforces pull request size limits. \check-deployment-infrastructure.test.ts\ and \check-deployment-workflow.test.ts\ verify that deployment configurations, Docker images, and CI workflows meet security and operational standards. \smoke-deployment.ts\ provides a runtime smoke test for deployed services. These changes shift the repository from manual or unverified states to an automated, self-asserting development and deployment environment.

scripts · high confidence

Add sign-in feature with login form and API integration

Introduced the complete sign-in capability for the application, including a client-side login form (email and password fields with validation), a React Query-based mutation hook, and an API layer that submits credentials to the backend. The feature includes a typed error class for handling authentication failures and a server-side credential verification function that checks against environment-configured demo credentials, with production safeguards to prevent placeholder passwords from being used.

apps/dapp/src/features/sign-in · high confidence

Admin app scaffolding and configuration

The admin application is now fully configured for development and production. A sample environment file (.env.sample) is provided for local overrides, and the app is set up with Rsbuild for the build process. Security headers and robots.txt are configured to restrict indexing and enforce safe browsing practices. The project includes a comprehensive ESLint configuration to enforce code quality and architecture rules, alongside a Panda CSS theme configuration that mirrors the main app's design system. Additionally, the app is prepared for deployment on Cloudflare Pages via a Wrangler configuration.

apps/admin · high confidence

Initial release of the protocol package with gRPC/Connect service definitions

The \packages/protocol\ package has been introduced, providing the first stable (1.0.0) release of the shared protocol definitions. This includes the generated TypeScript code and Protobuf schemas for the \AdminService\, \AuthService\, \TradingService\, and \HealthService\. The package also exports legacy \ApiService\ types (marked as deprecated) alongside the new \HealthService\ contract, allowing consumers to migrate from the old API to the new, more specific service interfaces.

packages/protocol · high confidence

Introduce @packages/api-core with a fetch-based Connect adapter and architecture enforcement

The api-core package now provides a runtime-agnostic API layer that exposes a fetch-based handler for Connect RPCs, supporting any environment that implements the Fetch API (e.g., Cloudflare Workers, Bun, Deno, or Node). It includes a health check feature, a legacy echo endpoint, and a public API surface that abstracts away the internal adapters and features. Additionally, an architecture checker script is introduced to enforce strict module boundaries, preventing features from importing from outer adapter layers or shared utilities, and ensuring each feature slice exposes a public API index.

packages/api-core · high confidence

Introduce RPC host bootstrap, deployment, and monitoring scripts alongside legacy API and admin authentication features

The RPC host infrastructure now includes a Terraform module that provisions the VPC, subnets, NAT gateway, and EC2 instance, while injecting three new shell scripts into the host: bootstrap.sh handles initial setup (installing Docker, downloading compose, downloading deploy/monitor scripts from S3, mounting EBS volumes, and enabling systemd services); deploy.sh manages the actual container deployment by fetching secrets, resolving image tags, and performing a rolling update with automatic rollback on failure; monitor.sh checks container health, disk/inode/memory usage, and backup status, reporting metrics to CloudWatch. In the application layer, a legacy echo feature is added to the API core, and the admin RPC service gains a new authentication feature that includes gRPC and Connect RPC routes, a login use case, and JWT-based access token issuance.

infra/terraform/modules/rpc-stack, packages/api-core/src/features/legacy-echo, services/admin-rpc/src/features/authentication · high confidence

Introduce admin-rpc service and api-gateway gateway application

Added the admin-rpc service, which exposes HTTP and native gRPC endpoints for authentication and market data, along with a health check. The api-gateway now includes a Hono-based HTTP adapter that enforces rate limiting, CORS, and authentication before routing requests to upstream services. Both services are configured with runtime environment variables and file-backed secrets for secure credential management.

services/api-gateway · high confidence

Introduce architecture boundary enforcement and structured logging for the trading-rpc service

The trading-rpc service now enforces a strict feature-layer architecture, preventing domain code from importing root runtime modules or external frameworks, with automated tests validating these rules. Additionally, the service adds a sample environment configuration file (.env.sample) and a Drizzle ORM configuration for PostgreSQL migrations, while introducing structured request logging and health check endpoints for both HTTP and gRPC transports.

services/trading-rpc · high confidence

Introduce crypto market data retrieval via Connect and gRPC endpoints

The trading-rpc service now exposes a new GetMarkets RPC that accepts a list of crypto asset IDs and a quote currency, returning current market snapshots. The change adds domain models (CoinId, QuoteCurrency, MarketSnapshot) with strict validation, application use cases, and adapters for both Connect-Web and gRPC transports. A PostgreSQL repository using Drizzle handles upserting the latest market state, and a CoinGecko HTTP adapter fetches live data. On the api-gateway side, a new auth middleware validates bearer tokens against a configurable allowlist, returning 401 for unauthorized requests. Tests cover the full stack from RPC handlers to domain logic and infrastructure.

services/api-gateway/src/features/access-control, services/trading-rpc/src/features/market-data · high confidence

Launch of the Astro-based landing page with SEO, security, and monitoring support

The landing app is introduced as a static Astro site, providing a zero-JS default build with optional Sentry error monitoring gated by the PUBLIC\_SENTRY\_DSN environment variable. The site includes a home page, a 404 page, and a robots.txt route that respects staging environments. Security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and Content-Security-Policy) are enforced via the \_headers file. SEO is supported through OpenGraph, Twitter, and JSON-LD structured data, while the site shell provides consistent header, footer, and navigation. The app is configured for deployment to Cloudflare Workers as static assets, with environment-specific routing and rollback capabilities.

apps/landing · high confidence

Launch of the dapp with a crypto market dashboard and liquidity terminal

The dapp application is now live, featuring a crypto market dashboard that displays real market logos and a liquidity terminal shell. The update includes a new account page, sign-in flow, and health check endpoint. E2E tests have been added to verify the auth flow, market dashboard rendering, and navigation. Configuration files for environment variables, ESLint, and Playwright have also been introduced.

apps/dapp · high confidence

Repository-wide configuration and tooling setup for the monorepo

The repository now includes foundational configuration files that define the development environment and tooling. A \.env.sample\ file provides default port mappings for Docker Compose services, while \.npmrc\ enforces exact dependency versions and strict engine checks. The project specifies Node.js 22 via \.nvmrc\ and configures pnpm 11 as the package manager. Linting and formatting are handled by Biome and ESLint, with a \.lintstagedrc.ts\ file wiring these tools to run on staged files. Additional configuration includes \.editorconfig\ for consistent editor settings, \.gitattributes\ for line-ending and diff handling, and \.mcp.json\ for AI agent integration. The \Makefile\ provides commands for managing the Docker-based development stack, including PostgreSQL backup and restore operations. These changes establish the baseline for the monorepo's build, test, and development workflows.

(repo-wide) · high confidence

Behavioural changes

Enforce Conventional Commits and branch naming via Husky hooks

The .husky directory now contains new scripts that enforce commit message formatting and branch naming conventions. The commit-msg hook validates commit headers against the Conventional Commits specification, requiring types such as feat, fix, or refactor, and warns if the header exceeds 100 characters. The pre-commit hook runs lint-staged to check staged files. The pre-push hook validates branch names against a kebab-case pattern (e.g., feat/user-profile), with exemptions for long-lived branches like main or develop. These changes ensure that all commits and branches follow a consistent, automated structure.

.husky · high confidence

Removed default Next.js template files

The default Next.js application template has been removed. Specifically, the entry point (pages/\_app.tsx), the example API route (pages/api/hello.ts), the main page (pages/index.tsx), and the associated CSS styles (styles/Home.module.css, styles/globals.css) have all been deleted from the repository.

pages, styles · high confidence

Test coverage

Added comprehensive test coverage for the admin application; Added tests for sign-in functionality.

Dependencies

Upgrade to Next.js 15/16 and React 19 across the monorepo

The project has been upgraded to React 19 and Next.js 15/16, providing access to the latest React features and performance improvements. The dapp and admin apps now use React 19.2.8, while the dapp specifically upgrades to Next.js 16.2.12. Additionally, the root package.json has been updated to specify Node.js \>=22.22.0 and pnpm \>=11, and the monorepo structure now includes dedicated package.json files for admin, dapp, landing, api-client, api-core, protocol, admin-rpc, api-gateway, and trading-rpc services, each with their respective dependencies and devDependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 65 → 66 (+1.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 93 (-1.7)
  • Architecture 98 → 79 (-19.5)
  • Maturity 65 → 69 (+3.7)
  • Readiness 58 → 67 (+9.1)
  • Security 68 → 62 (-6.1)
  • Accessibility 71 → 71 (+0.2)

Resolved (22)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium IaC: CKV2_AWS_11 (infra/terraform/modules/rpc-stack/main.tf)
  • Medium IaC: CKV2_AWS_64 (infra/terraform/modules/rpc-stack/main.tf)
  • Medium IaC: CKV_AWS_18 (infra/terraform/modules/rpc-stack/main.tf)
  • Medium IaC: CKV_DOCKER_2 (infra/docker/dapp.Dockerfile)
  • Medium IaC: CKV_DOCKER_2 (infra/docker/workspace-dev.Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (infra/docker/postgres.Dockerfile)
  • Medium IaC: CKV_DOCKER_8 (infra/docker/trading-rpc.Dockerfile)
  • No exposed public API
  • …and 2 more

New (100)

  • Critical vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Critical vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency advisory scan runs only on code events
  • FunctionTooLong: market-dashboard.MarketOverview (apps/admin/src/screens/dashboard/ui/market-dashboard.tsx)
  • FunctionTooLong: market-dashboard.MarketsTable (apps/admin/src/screens/dashboard/ui/market-dashboard.tsx)
  • FunctionTooLong: market-table.MarketTable (apps/dapp/src/screens/home/ui/market-table.tsx)
  • FunctionTooLong: not-found-page.NotFoundPage (apps/dapp/src/screens/not-found/ui/not-found-page.tsx)
  • FunctionTooLong: users-table.UsersTable (apps/admin/src/screens/users/ui/users-table.tsx)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High IaC: WD-COMPOSE-0002 (infra/docker/compose.yaml)
  • …and 80 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

NoahDuongMaster/vibe-code-stack-for-ceos was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d76ad18ae4fb9ef1ba0dc40785d7c1c3fad9bb87 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.