{"schema":"cloudm0n.agent-handoff.v1","generatedAt":"2026-09-01T19:34:55.210Z","software":{"slug":"github/codeql","name":"codeql","source":"https://github.com/github/codeql","tagline":"CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security","summary":"CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security","topics":["codeql","github-advanced-security","github-security-lab","semmle-ql","works-with-codespaces"]},"decision":{"fitScore":92,"verdict":"MUST TRY","analysisState":"ANALYZED","whatItDoes":"CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security","whyFound":"CLOUDM0N matched this repository through its capability signals: codeql, github-advanced-security, github-security-lab, semmle-ql, works-with-codespaces.","bestFor":"Agents and teams that specifically need the capability provided by codeql.","tradeOff":"No explicit trade-off is documented in the current CLOUDM0N analysis. Review the source, trust evidence, and target environment before adoption.","adoption":"VERIFY_FIRST"},"trust":{"security":{"status":"REVIEW","score":80,"commitSha":"b0fa3e770386f18fd4d63225301ea4c41e7a5721","scannedAt":"2026-09-01T14:51:12.544Z"}},"architecture":{"evidenceLevel":"CODE_EVIDENCE","source":"ARCHITECTURE_SCAN","commitSha":"b0fa3e770386f18fd4d63225301ea4c41e7a5721","strategy":null,"runtimeImage":null,"workdir":null,"protocol":null,"capabilities":["codeql","github-advanced-security","github-security-lab","semmle-ql","works-with-codespaces"],"note":"Architecture context comes from static code and repository evidence. CLOUDM0N does not execute the repository before adoption."},"install":{"evidenceLevel":"AGENT_VERIFICATION_REQUIRED","source":null,"installCommand":null,"startCommand":null,"healthCommand":null,"networkDuringInstall":null,"protocolProbe":null,"caution":"Installation is intentionally deferred to the user’s coding agent. The agent must inspect official documentation and the target environment before proposing or making changes."},"alternatives":[{"slug":"Graphify-Labs/graphify","name":"graphify","fitScore":74,"verdict":"WATCH","security":{"status":"REVIEW","score":45},"focus":"Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store."},{"slug":"DeusData/codebase-memory-mcp","name":"codebase-memory-mcp","fitScore":71,"verdict":"WATCH","security":{"status":"REVIEW","score":55},"focus":"This MCP server transforms how developers interact with codebases by building a persistent knowledge graph that indexes repositories in milliseconds across 155 programming languages. With sub-millisecond query speeds and 99% token reduction, it enables AI coding assistants like Cursor, Claude Code, and Windsurf to understand your entire codebase context without drowning in context windows. Built as a single static binary with zero dependencies, it runs anywhere."},{"slug":"holaboss-ai/holaOS","name":"holaOS","fitScore":71,"verdict":"WATCH","security":{"status":"REVIEW","score":45},"focus":"holaOS คือ Agentic OS ที่ทำให้ AI Agent สามารถทำงานดิจิทัลได้ทุกอย่างบนคอมพิวเตอร์ของคุณ ไม่ว่าจะเป็นการจัดการไฟล์ ท่องเว็บ หรือรันโปรแกรมต่างๆ ผ่าน Natural Language ด้วย Electron + TypeScript + MCP Protocol ที่ Open Source สำหรับ Developer ที่อยากสร้าง Desktop AI Agent ของตัวเอง"}],"nextAction":"Review or complete Security evidence before adoption. Do not install based on Fit alone.","policy":{"sponsoredRanking":false,"cloudm0nExecutesInstall":false,"approvalRequiredBeforeChanges":true,"fitDoesNotOverrideTrust":true}}