Skip to content
CAI
Software that uses CAICheck a score

StarkNitish/NexusOS

54.1

Adequate · 22 September 2026

23.2k

lines of production code

TypeScript

with JavaScript, Python

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

NexusOS is a modular orchestration platform that manages automated development pipelines and multi-channel communication. It features a Rust-based traffic controller that coordinates agent workflows and state, while a Next.js dashboard provides real-time monitoring and task submission. The system integrates a wide range of external services and AI providers through a standardized connector library, all supported by a plugin-based architecture for channel and agent extensibility.

Features

Add one-command setup script for NexusOS

A new shell script, scripts/init.sh, has been added to automate the initial setup of the NexusOS development environment. Running the script checks for required tools (Rust, Node.js, pnpm, Docker), installs dependencies, builds the Rust-based Traffic Controller, configures environment files, and starts infrastructure services, streamlining the process of getting the platform running locally.

scripts · high confidence

Core channel logic for account snapshots, access control, and message handling

The \packages/channels\ directory now includes a comprehensive set of new core modules that define how channel accounts are snapshotted, how senders and channels are validated against allowlists, and how messages and commands are gated. Specifically, \account-snapshot-fields.ts\ and \account-summary.ts\ introduce logic to project safe, read-only account fields (excluding webhooks and public keys) and build channel account snapshots. \allow-from.ts\ and \allowlist-match.ts\ provide the core logic for merging, resolving, and matching sender and channel allowlists, including support for wildcards and in-place list updates. \channel-config.ts\ handles channel entry matching with fallbacks and normalization. \ack-reactions.ts\ and \command-gating.ts\ implement the logic for sending acknowledgment reactions and gating control commands based on access groups. These changes establish the foundational behavior for channel configuration, sender validation, and message processing within the channels package.

packages/channels · high confidence

Expanded connector library with new integrations and infrastructure

The connectors package now includes 25 integrations, adding support for AI and search services (Anthropic, HuggingFace, OpenAI, Perplexity), cloud and infrastructure services (AWS S3, Cloudflare, DockerHub, Railway), monitoring and alerting (Datadog, PagerDuty, PostHog), and productivity tools (Figma, Firebase, GitHub, Gmail, Google Calendar, Jira, Linear, Notion, Slack). The update also introduces a Dockerfile for containerized deployment of the connector bridge on port 3002, a reusable \_template for new connectors, and an index file that exports all available connectors for easy discovery and instantiation.

packages/connectors · high confidence

Integrate Everything-Claude-Code (ECC) agent harness with specialized agents and workflows

The agent-harness package now includes the full Everything-Claude-Code (ECC) integration, providing 16 specialized agents (including architect, code-reviewer, tdd-guide, security-reviewer, and others) along with 65+ workflow skills, 40 slash commands, and automated hook-based workflows. This adds a comprehensive set of production-ready agent instructions, skills, and commands for software development, testing, and security review within the agent harness.

packages/agent-harness · high confidence

Introduce SDK Bridge with stubbed agent adapters

The SDK Bridge package now provides a registry of agent adapters for Claude Code, LangChain, LangGraph, and a generic Python adapter. Each adapter implements a common interface with an invoke method that returns a stubbed result and a healthCheck method that currently always returns true. The bridge exports functions to retrieve an adapter by type, list all registered adapters, and perform health checks on all of them.

packages/sdk-bridge · high confidence

Introduce the NexusOS Traffic Controller orchestration layer

Users can now trigger and monitor automated development pipelines through a new Rust-based gateway on port 3000. This component manages a P0–P8 state machine that executes tasks, persists mission data in a local SQLite database, and provides real-time updates via a WebSocket stream. It also integrates with the OpenClaw platform to send human-in-the-loop approval requests and receive status notifications.

packages/traffic-controller · high confidence

NexusOS Dashboard delivery layer initialized with Next.js 14, Tailwind CSS, and OpenClaw integration

The dashboard area now provides a Next.js 14 delivery layer featuring a dark-mode, glassmorphism UI built with Tailwind CSS. It includes a CommandBar for submitting agent tasks, a LiveFeed for real-time mission updates via WebSocket, and an AuditLog for mission history. The implementation adds a gateway client (\lib/gateway.ts\) that handles REST and WebSocket communication with the Traffic Controller API, alongside health checks for both the gateway and OpenClaw services. Configuration files for ESLint, PostCSS, and TypeScript are also introduced to support the new frontend stack.

dashboard · high confidence

Restructure channel plugins and onboarding into a modular, extension-backed architecture

The channel plugins for Discord, Signal, Telegram, and iMessage have been restructured into a modular, extension-backed architecture. This change introduces a new plugin-based system where each channel's actions, normalization, and onboarding logic are handled by dedicated modules (e.g., \actions/discord.ts\, \normalize/signal.ts\, \onboarding/helpers.ts\). The diff shows the addition of new files for handling channel-specific actions (like reactions and message handling), target normalization, and onboarding wizards. This restructuring allows for better separation of concerns, easier maintenance, and a more consistent interface for adding new channels or modifying existing ones. Users will benefit from a more robust and extensible channel configuration process, with improved error handling and validation for channel-specific settings.

(repo-wide) · high confidence

Dependencies

Initialize monorepo with new package dependencies

The project is structured as a monorepo with new package definitions for the dashboard (Next.js 16.1.6, React 19.2.3), agent-harness (ecc-agentshield 1.3.0), channels, connectors (AWS S3, Firebase), SDK bridge, and traffic controller (Axum, Tokio, Rusqlite).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 53 → 54 (+1.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 72 → 75 (+3.1)
  • Architecture 100 → 90 (-10.4)
  • Maturity 70 → 76 (+6.5)
  • Readiness 37 → 40 (+2.9)
  • Security 62 → 63 (+1.0)
  • Accessibility 63 → 63 (+0.0)

Resolved (46)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (packages/agent-harness/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (packages/agent-harness/pnpm-lock.yaml)
  • High IaC: DS-0029 (packages/traffic-controller/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 26 more

New (178)

  • ADR not followed: 📋 NexusOS — Build Log & Decision Record (.agent/BUILD_LOG.md)
  • CloudflareConnector.execute (cyclomatic 17) (packages/connectors/cloudflare/index.ts)
  • Context/problem and consequences/trade-offs are absent; only a decision log with rationale and boundary set sections appear (.agent/BUILD_LOG.md)
  • DatadogConnector.execute (cyclomatic 16) (packages/connectors/datadog/index.ts)
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • FileTooLong: onboarding/helpers.ts (packages/channels/core/plugins/onboarding/helpers.ts)
  • FileTooLong: routing/resolve-route.ts (packages/channels/routing/resolve-route.ts)
  • FileTooLong: scripts/instinct-cli.py (packages/agent-harness/skills/continuous-learning-v2/scripts/instinct-cli.py)
  • FirebaseConnector.execute (cyclomatic 19) (packages/connectors/firebase/index.ts)
  • FunctionTooLong: claw.main (packages/agent-harness/scripts/claw.js)
  • FunctionTooLong: resolve-route.resolveAgentRoute (packages/channels/routing/resolve-route.ts)
  • FunctionTooLong: status-reactions.createStatusReactionController (packages/channels/core/status-reactions.ts)
  • FunctionTooLong: tmux-worktree-orchestrator.buildOrchestrationPlan (packages/agent-harness/scripts/lib/tmux-worktree-orchestrator.js)
  • High CVE: [GHSA redacted] (packages/agent-harness/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (packages/agent-harness/pnpm-lock.yaml)
  • High IaC: DS-0029 (packages/traffic-controller/Dockerfile)
  • High IaC: DS-0029 (packages/traffic-controller/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 158 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

StarkNitish/NexusOS was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a012476b479baf872d77e1152c995820981974a6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.