genesiscode2026/genesis-repository-truth-context · v1.0.0
What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.
Harness · 4 scripts · 3 test files · 5 docs · 1 config file · 1 asset · 1 other file · 15 files · text 18.8 kB · binary 221 B (1%) · Python 100% · licence undetermined
scan passed 2026-09-17 · scanner 2026.09.1 · 1 release · last release today · 15% of files seen elsewhere
computed 2026-09-17 11:41 UTC · analyzer 0.1.0Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from all three are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- none in 4 packages
- OSV
- known vulnerabilities
- 3 moderate, 2 low in 4 packages — see below
- OSV
- dependency behaviour
- 2 direct packages declare network access, shell access, filesystem access and more · 462 more in transitive packages · 37 packages flagged for review
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- listed below
- X402 Git
What this can do
- Tools
- none
- Runs
- pyproject.toml ([build-system])
- bin/genesis-truth-context
- genesis_truth_context/__main__.py
- Talks to
- nothing
- Reads
- no environment variables
- At install
- something runs
Findings (54)
- HIGHyargs 17.7.3 (dev only) — yargs 17.7.3 (transitive, dev only) — contains an obfuscated file
- MODERATEpyproject.toml — [build-system] runs when this is installed
- MODERATEexpress — express (npm): Express ressource injection GHSA-cm5g-3pgc-8rg4 CVE-2024-10491
- MODERATEexpress — express (npm): No Charset in Content-Type Header in express GHSA-gpvr-g6gh-9mc2 CVE-2014-6393
- MODERATEexpress — express (npm): Express.js Open Redirect in malformed URLs GHSA-rv95-896h-c2vc CVE-2024-29041
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — ships compiled native code
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — ships compiled native code
- MODERATEexpress 4.22.3 — express 4.22.3 (direct) — makes network requests at runtime
- MODERATEexpress 4.22.3 — express 4.22.3 (direct) — makes network requests at runtime
- MODERATEexpress 4.22.3 — express 4.22.3 (direct) — makes network requests at runtime
- MODERATEexpress 4.22.3 — express 4.22.3 (direct) — makes network requests at runtime
- flagged for reviewpicomatch 2.3.2 (dev only) — picomatch 2.3.2 (transitive, dev only) — flagged for review as a possible vulnerability
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — runs shell commands
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — runs shell commands
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — evaluates code at runtime
- MODERATEsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — evaluates code at runtime
- LOWexpress 4.22.3 — express 4.22.3 (direct) — loads modules by a computed name
- LOWexpress 4.22.3 — express 4.22.3 (direct) — reads environment variables
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads environment variables
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads environment variables
- LOWexpress 4.22.3 — express 4.22.3 (direct) — reads or writes files
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads or writes files
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — reads or writes files
- LOWexpress — express (npm): Express Open Redirect vulnerability GHSA-jj78-5fmv-mv28 CVE-2024-9266
- LOWexpress — express (npm): express vulnerable to XSS via response.redirect() GHSA-qw6h-vgh9-j6wx CVE-2024-43796
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- flagged for reviewsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — flagged for review by Socket's classifier as anomalous
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
- LOWcors 2.8.6 — cors 2.8.6 (direct) — published by an author new to this package
- LOWbin/genesis-truth-context — Ships the script bin/genesis-truth-context
- LOWgenesis_truth_context/__main__.py — Ships the script genesis_truth_context/__main__.py
- LOWis-arrayish 0.2.1 (dev only) — is-arrayish 0.2.1 (transitive, dev only) — trivially small
- LOWexpress 4.22.3 — express 4.22.3 (direct) — contains hard-coded URLs
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — contains hard-coded URLs
- LOWsetuptools 84.0.0 (dev only) — setuptools 84.0.0 (direct, dev only) — contains hard-coded URLs
- flagged for reviewgptAnomaly — 29 transitive packages, e.g. content-disposition@0.5.4, mime-types@2.1.35, chalk@4.1.2
- MODERATEusesEval — 11 transitive packages, e.g. depd@2.0.0, jest-snapshot@29.7.0, @babel/traverse@7.29.8
- MODERATEshellAccess — 7 transitive packages, e.g. jest-haste-map@29.7.0, jest-worker@29.7.0, babel-plugin-istanbul@6.1.1
- MODERATEnetworkAccess — 3 transitive packages, e.g. debug@2.6.9, methods@1.1.2, fb-watchman@2.0.2
- LOWunmaintained — 67 transitive packages, e.g. safe-buffer@5.2.1, object-assign@4.1.1, vary@1.1.2
- LOWenvVars — 41 transitive packages, e.g. debug@2.6.9, depd@2.0.0, finalhandler@1.3.2
- LOWfilesystemAccess — 35 transitive packages, e.g. debug@2.6.9, etag@1.8.1, send@0.19.2
- LOWurlStrings — 31 transitive packages, e.g. debug@2.6.9, iconv-lite@0.4.24, @jest/core@29.7.0
- LOWnewAuthor — 18 transitive packages, e.g. encodeurl@2.0.0, finalhandler@1.3.2, http-errors@2.0.1
- LOWdynamicRequire — 17 transitive packages, e.g. @jest/core@29.7.0, import-local@3.2.0, jest-config@29.7.0
- LOWdebugAccess — 16 transitive packages, e.g. on-finished@2.4.1, raw-body@2.5.3, @jest/core@29.7.0
- LOWminifiedFile — 3 transitive packages, e.g. yargs@17.7.3, resolve.exports@2.0.3, react-is@18.3.1
- LOWdeprecated — 2 transitive packages, e.g. glob@7.2.3, inflight@1.0.6
Description self_reported
Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.
Compile verified repository context facts for AI prompts
When to use it. When requiring verified Context Engineering functionality in autonomous workflows
Readme
Genesis Repository Truth Context Compiler
Deterministic codebase fact extraction and context engineering compiler for autonomous coding agents (Codex CLI, Claude Code, Cursor, Gemini).
1. What Problem Does This Solve?
Coding agents frequently hallucinate build commands, invent nonexistent dependencies, execute incorrect test runners, or misinterpret project topology when fed uncurated repository dumps or generic README files.
genesis-repository-truth-context solves this by statically inspecting project manifests (package.json, pyproject.toml, Cargo.toml), git telemetry, and risk zones to compile a compact, verified fact manifest. Crucially, it enforces strict structural separation between Verified Facts (deterministic ground truth) and Heuristic Inferences (static hypotheses), preventing models from treating guesses as established truth.
2. Who Buys It?
- AI Engineers and Agentic Framework Developers.
- Engineering teams using autonomous coding agents in large or complex codebases.
- Platform architects building context-injection pipelines for enterprise LLM agents.
3. What Does It Output?
- A compact, token-efficient Markdown context document optimized for LLM system prompts.
- Structured JSON (
--json) for automated agent orchestration harnesses.
4. How Fast Can You Test It?
Under 3 seconds. Run:
python3 -m genesis_truth_context ./tests/fixtures/sample_repo
5. Why Is This Different From Generic README Summarizers?
Generic summarizers produce unverified prose with no operational guarantees. genesis-truth-context runs AST and manifest parsers to extract factual test/build commands, dirty git states, and security risk zones, while cleanly demarcating inferences so agents never act blindly on assumptions.
Installation & Usage
# Compile truth context for current repository
python3 -m genesis_truth_context .
# Output to markdown file for agent system prompt
python3 -m genesis_truth_context /path/to/repo --out ./agent-context.md
# Output machine-readable JSON for orchestration pipeline
python3 -m genesis_truth_context /path/to/repo --json
Compiler Architecture & Separation of Concerns
Repository Root
├── Git Telemetry ──┐
├── Package Manifests ──┼──► [VERIFIED FACTS] ──► High Confidence Constraints
├── Build & Test Scripts ──┤ (Zero Model Guesswork)
└── Security Risk Zones ──┘
Static AST Patterns ─────► [INFERENCES] ──► Explicitly Labelled Hypotheses
(Requires Pre-flight Confirmation)
Supported Manifest Ecosystems
- Node.js:
package.json(scripts, dependencies, devDependencies) - Python:
pyproject.toml,requirements.txt,pytest.ini - Rust:
Cargo.toml(packages, targets, cargo test/build) - Git: Working tree cleanliness, branch tracking, commit hash verification
License
Commercial — Genesis Code (genesiscode2026). See LICENSE.
Contents
| Size | Path |
|---|---|
| 103 B | .gitignore |
| 497 B | CHANGELOG.md |
| 961 B | LICENSE |
| 445 B | QUICKSTART.md |
| 3.1 kB | README.md |
| 274 B | SECURITY.md |
| 6 B | VERSION · binary |
| 215 B | bin/genesis-truth-context · binary |
| 218 B | genesis_truth_context/__init__.py |
| 1.4 kB | genesis_truth_context/__main__.py |
| 8.9 kB | genesis_truth_context/compiler.py |
| 596 B | pyproject.toml |
| 281 B | tests/fixtures/sample_repo/package.json |
| 42 B | tests/fixtures/sample_repo/src/index.js |
| 1.9 kB | tests/test_compiler.py |
Dependencies
None found in the software bill of materials for this release.
computed 2026-09-17 11:41 UTC · analyzer 0.1.0Releases
| Version | Date | Scan | Changed | Notes |
|---|---|---|---|---|
| v1.0.0 | 2026-09-17 | pass | — | Production-ready release. Compiles accurate repository context for LLM consumption without hallucinated file paths or stale summaries. |
Machine-readable at https://x402git.com/api/v/genesiscode2026/genesis-repository-truth-context/releases. Entries cannot be deleted by the creator.
Order
GET v1.0.0 · $39 · new releases $9
The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.
# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/genesiscode2026/genesis-repository-truth-context
# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/genesiscode2026/genesis-repository-truth-context \
-H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"The first request answers this — a real quote, made for this page load:
HTTP/1.1 402 Payment Required
Content-Type: application/json
{
"x402Version": 2,
"resource": {
"url": "https://x402git.com/api/r/genesiscode2026/genesis-repository-truth-context",
"description": "genesiscode2026/genesis-repository-truth-context v1.0.0 — release. Compile verified repository context facts for AI prompts Security scan passed; signed download, 5-minute URL.",
"mimeType": "application/zip",
"serviceName": "genesis-repository-truth-context",
"tags": [
"harness",
"scripts",
"tests",
"docs",
"config"
]
},
"accepts": [
{
"scheme": "exact",
"network": "eip155:8453",
"amount": "39000000",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
"maxTimeoutSeconds": 300,
"extra": {
"name": "USD Coin",
"version": "2"
},
"maxAmountRequired": "39000000",
"resource": "https://x402git.com/api/r/genesiscode2026/genesis-repository-truth-context",
"description": "genesiscode2026/genesis-repository-truth-context v1.0.0 — release. Compile verified repository context facts for AI prompts Security scan passed; signed download, 5-minute URL.",
"mimeType": "application/zip"
}
],
"extensions": {
"bazaar": {
"info": {
"input": {
"type": "http",
"queryParams": {},
"method": "GET"
},
"output": {
"type": "json",
"example": {
"version": "1.0.0",
"artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
"download_url": "https://storage.example/genesiscode2026/genesis-repository-truth-context/1.0.0.zip?signed=…",
"expires_at": "2026-09-16T12:05:00.000Z",
"version_endpoint": "https://x402git.com/api/r/genesiscode2026/genesis-repository-truth-context/v/1.0.0",
"manifest_url": "https://x402git.com/api/label/genesiscode2026/genesis-repository-truth-context",
"all_versions": false
}
}
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"input": {
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"type": "string",
"enum": [
"GET"
]
},
"queryParams": {
"type": "object",
"properties": {}
}
},
"required": [
"type",
"method"
],
"additionalProperties": false
},
"output": {
"type": "object",
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"version": {
"type": "string",
"description": "Semantic version of the release served."
},
"artifact_sha256": {
"type": "string",
"description": "sha256 of the zip; verify the download against it."
},
"download_url": {
"type": "string",
"description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
},
"expires_at": {
"type": "string",
"format": "date-time"
},
"version_endpoint": {
"type": "string",
"description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
},
"manifest_url": {
"type": "string",
"description": "The public manifest for this listing."
},
"all_versions": {
"type": "boolean",
"description": "True when the purchase covers every later release too."
}
},
"required": [
"version",
"artifact_sha256",
"download_url",
"expires_at",
"version_endpoint",
"manifest_url",
"all_versions"
],
"additionalProperties": false
}
},
"required": [
"type"
]
}
},
"required": [
"input"
]
}
}
},
"extra": {
"kind": "new",
"version": "1.0.0",
"manifest_url": "https://x402git.com/api/label/genesiscode2026/genesis-repository-truth-context",
"scan_badge_url": "https://x402git.com/api/label/genesiscode2026/genesis-repository-truth-context#scan",
"update_price_micro": "9000000",
"quote_id": "q_7c38d2c8a7c98f6e7fd347338c28ab88",
"valid_before": "2026-09-17T14:55:21.944Z",
"instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/genesiscode2026/genesis-repository-truth-context again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/genesiscode2026/genesis-repository-truth-context, and the free manifest at https://x402git.com/api/label/genesiscode2026/genesis-repository-truth-context shows what is inside before anyone pays.",
"listing_url": "https://x402git.com/genesiscode2026/genesis-repository-truth-context",
"skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
"mcp_url": "https://x402git.com/api/mcp"
}
}- Resource
- https://x402git.com/api/r/genesiscode2026/genesis-repository-truth-context
- Manifest
- https://x402git.com/api/label/genesiscode2026/genesis-repository-truth-context
- Version
- https://x402git.com/api/v/genesiscode2026/genesis-repository-truth-context
- Artifact sha256
- c7ef4e0a8b19e617fbdc3fbc7065f017a06da46e3215c71b10b908b35e540c03
Later releases cost $9, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.
Sold by genesiscode2026. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.