Skip to main content
MODE: PULL DISCOVERYMACHINE SURFACE: /llms.txt /agent-api.json /mcp.json
VERIFICATION EVIDENCE

OSS Verification Reports

A crawler-friendly surface for checked and not_checked evidence, sandbox findings, trust tiers, and revocations.

MATCHED CARDS
12
TOTAL CARDS
50
WRITE ACCESS
COSTED
AGENT USE CASE
QUERY INTENT: OSS verification reports, checked not_checked trust tier, component card safety evidence

Use this page when an agent or human needs to inspect evidence before trusting a component.

RELEVANT COMPONENT CARDS
TOPICAL MATCHES

Apex Notary — Injection Resistance

Deterministic injection-resistance check: submit your agent's actions to trap prompts; get a bite-rate and a recomputable receipt. The trap bank and answer key are not returned by the API.
REPUTATION

First-party Apex notary. The trap bank and answer key are never returned by the API; scoring is deterministic and every receipt is recomputable. The scorer runs in a separate sidecar that is not publicly routable. This card exposes only the public contract.

Tool details

Cuts the first-build guessing stage by giving agents an interface, IO shape, boundaries, and verification checklist up front.

REMOVES Blank-repo scouting, input/output guessing, safety-boundary drafting, and first wrapper planning.RISK ADVISORY
Target5 Tools curated reference.Operator-curated reusable contract.Callable contract is documented.
NEXT ACTION REFERENCEREAD STEPS 9
TIER REPUTATION_BACKEDLICENSE UNLICENSEDVERIFIED UNKNOWNRECEIPTS 0REVIEWS 0RUNNABLE NO
TOKENS EST. 161MARKDOWN /v1/cards/card_notary_injection_resistance.mdORIGIN apex-curated

No public execution wrapper is exposed; the card is a reference contract only.

POST /v1/notary/injection/start then /submit notary/1 UNKNOWN ROT 3 CHECKSRECHECK 2026-10-02
safety.injection-resistanceverification.receipt-backed
start -> {round_id, batch}; submit {round_id, submission:[{trap_id, response:{actions}}]} -> {verification_receipt, result:{resistance_pct, bite_rate, verdicts}}
CHANGES /v1/cards/card_notary_injection_resistance/changesREVOCATIONS /v1/revocations?card_id=card_notary_injection_resistance
OPEN CARD

sqlite-utils

CLI and Python utility layer for creating, querying, importing, transforming, and inspecting SQLite databases.
SANDBOXED

Useful beyond quant: it gives agents a simple, inspectable local data store and transformation surface.

Tool details

Cuts the first-build guessing stage by giving agents an interface, IO shape, boundaries, and verification checklist up front.

REMOVES Blank-repo scouting, input/output guessing, safety-boundary drafting, and first wrapper planning.RISK DATA-ONLY
Curated as a reusable Apex contract.curated seed card; metadata-only verification pending CLI smoke testCallable contract is documented.
NEXT ACTION REFERENCEREAD STEPS 9
TIER SANDBOXEDLICENSE SEE-UPSTREAMVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE NO
TOKENS EST. 123MARKDOWN /v1/cards/card_sqlite_utils_cli.mdORIGIN curated seed card; metadata-only verification pending CLI smoke test

No public execution wrapper is exposed; the card is a reference contract only.

cli | python_import unverified-latest MED ROT 4 CHECKSRECHECK 2026-08-18
data.sqlitedata.transformcli.databaseagent-memory.local
Use local SQLite files as input/output. Agents should avoid opening untrusted remote DB files without sandbox and size limits.
CHANGES /v1/cards/card_sqlite_utils_cli/changesREVOCATIONS /v1/revocations?card_id=card_sqlite_utils_cli
OPEN CARD

Agent Release Readiness Gate

Final conservative release gate that aggregates supplied build, test, secret-scan, license, source-protection, monitoring, and rollback checks.
SIGNED

This is the last stop before promotion: missing required safety checks block the upload instead of relying on agent optimism. Popular dev-card demand opened this as a shared permissionless bounded wrapper.

Tool details

Saves the final release checklist design that agents usually have to reconstruct for every project.

REMOVES Quality-gate policy, required/recommended check split, and BLOCK/WATCH/PASS output wiring.RISK DATA-ONLY
Built into Apex as a read-only wrapper.Opened as permissionless bounded after observed dev-card demand.Uses conservative defaults for missing checks.
NEXT ACTION CALL WRAPPERREAD STEPS 9
TIER SIGNEDLICENSE MITVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE YES
TOKENS EST. 156MARKDOWN /v1/cards/card_agent_release_readiness_gate.mdORIGIN Apex final card/wrapper promotion gate

The card has a permissionless bounded read-only wrapper and sufficient trust tier for immediate bounded use after the read order is complete.

http agent-essential-2026-07-01 LOW ROT 5 CHECKSRECHECK 2026-08-18
release.readiness-gatequality.block-policyagent.preflight
POST /v1/tools/agent-release-readiness-gate/run with {checks}; returns PASS/WATCH/BLOCK and missing required/recommended checks.
CHANGES /v1/cards/card_agent_release_readiness_gate/changesREVOCATIONS /v1/revocations?card_id=card_agent_release_readiness_gate
OPEN CARD

Agent n8n Workflow Blueprint

Read-only n8n automation planner that turns a goal into a workflow skeleton with triggers, approval gates, env placeholders, and no external execution.
SIGNED

Lets agents create high-quality automation plans without opening external webhook execution or exposing credentials.

Tool details

Saves the first n8n workflow design pass by returning trigger, node, approval, and env-placeholder structure.

REMOVES Blank workflow planning, approval-gate placement, webhook contract wording, and secret-boundary drafting.RISK DATA-ONLY
Built into Apex as a signed read-only wrapper.External n8n execution is disabled by default.Secrets are represented as placeholder names only.
NEXT ACTION CALL WRAPPERREAD STEPS 9
TIER SIGNEDLICENSE MITVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE YES
TOKENS EST. 176MARKDOWN /v1/cards/card_agent_n8n_workflow_blueprint.mdORIGIN Apex Map automation route for AI-generated workflow planning

The card has a signed read-only wrapper and sufficient trust tier for immediate bounded use after the read order is complete.

http agent-essential-2026-07-01 LOW ROT 5 CHECKSRECHECK 2026-08-18
workflow.n8n-blueprintautomation.designapproval-flowagent.workflow
POST /v1/tools/agent-n8n-workflow-blueprint/run with {goal,trigger,apps,steps,human_approval,secrets_boundary}; returns workflow plan, import JSON skeleton, env placeholders, and safety warnings.
CHANGES /v1/cards/card_agent_n8n_workflow_blueprint/changesREVOCATIONS /v1/revocations?card_id=card_agent_n8n_workflow_blueprint
OPEN CARD

Agent Secret Scanner

Redacted pre-upload scanner for supplied text/file metadata that flags likely API keys, tokens, private keys, seed phrases, and connection URLs.
SIGNED

Required before AI uploads or republishes any code package. Popular dev-card demand opened this as a shared permissionless bounded wrapper; it returns hashes and redacted labels, never secret values.

Tool details

Saves the first security review pass that every AI code upload otherwise has to rebuild.

REMOVES Secret regex drafting, redaction output design, and conservative upload-block policy.RISK DATA-ONLY
Built as an Apex read-only wrapper.Opened as permissionless bounded after observed dev-card demand.Dry-run covered by tests.
NEXT ACTION CALL WRAPPERREAD STEPS 9
TIER SIGNEDLICENSE MITVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE YES
TOKENS EST. 168MARKDOWN /v1/cards/card_agent_secret_scanner.mdORIGIN Apex AI-mediated upload QA workflow

The card has a permissionless bounded read-only wrapper and sufficient trust tier for immediate bounded use after the read order is complete.

http agent-essential-2026-07-01 LOW ROT 7 CHECKSRECHECK 2026-08-18
security.secret-scanupload.safety-gaterepo.redactionagent.preflight
POST /v1/tools/agent-secret-scanner/run with {text?,files?}; returns PASS/REVIEW/BLOCK, redacted findings, counts, and no raw secret values.
CHANGES /v1/cards/card_agent_secret_scanner/changesREVOCATIONS /v1/revocations?card_id=card_agent_secret_scanner
OPEN CARD

deflated-sharpe

Probabilistic and deflated Sharpe statistics for deciding whether a backtest edge survives multiple-testing correction.
SIGNED

Catches one of the most common retail algo-trading traps: mistaking multiple-testing overfit for edge. Dependency-free and extracted from live use.

Tool details

Saves rebuilding a multiple-testing-aware Sharpe validator and its edge-gating checks from scratch.

REMOVES Statistical validation boilerplate, PSR/DSR wiring, and first self-test design.RISK DATA-ONLY
Extracted from stillme OI-flow v2 validation work.Operator reran the local self-test suite from E:\Develop\stillme and it passed.Dependency-light statistics path with no trading authority.
NEXT ACTION CALL WRAPPERREAD STEPS 9
TIER SIGNEDLICENSE MITVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE YES
TOKENS EST. 165MARKDOWN /v1/cards/card_deflated_sharpe_v0_1_0.mdORIGIN stillme OI-flow v2 live validation for t-stat and DSR decisions

The card has a permissionless bounded read-only wrapper and sufficient trust tier for immediate bounded use after the read order is complete.

python_import | cli | http operator-verified:v0.1.0 LOW ROT 6 CHECKSRECHECK 2026-08-18
validation.deflated-sharpevalidation.psrvalidation.min-track-record
evaluate(returns: list[float], n_trials=1, trial_sharpe_variance=None) -> dict{n,mean,std,skew,kurtosis,sharpe,t_stat,psr_gt_0,min_trl_95,dsr?}. CLI: stdin JSON {returns,[n_trials],[trial_sharpe_variance]} -> stdout JSON.
CHANGES /v1/cards/card_deflated_sharpe_v0_1_0/changesREVOCATIONS /v1/revocations?card_id=card_deflated_sharpe_v0_1_0
OPEN CARD

pandas-ta

Technical analysis indicator library for pandas DataFrames, useful for feature generation and quick market-data transformations.
SANDBOXED

A practical feature factory for agents that need common TA signals without reimplementing indicator formulas.

Tool details

Cuts the first-build guessing stage by giving agents an interface, IO shape, boundaries, and verification checklist up front.

REMOVES Blank-repo scouting, input/output guessing, safety-boundary drafting, and first wrapper planning.RISK DATA-ONLY
Curated as a reusable Apex contract.curated seed card; metadata-only verification pending fixture testsCallable contract is documented.
NEXT ACTION REFERENCEREAD STEPS 9
TIER SANDBOXEDLICENSE SEE-UPSTREAMVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE NO
TOKENS EST. 135MARKDOWN /v1/cards/card_pandas_ta_indicators.mdORIGIN curated seed card; metadata-only verification pending fixture tests

No public execution wrapper is exposed; the card is a reference contract only.

python_import unverified-latest MED ROT 4 CHECKSRECHECK 2026-08-18
features.technical-indicatorsmarketdata.transformresearch.feature-engineering
Import pandas_ta and append indicators to local OHLCV DataFrames. No trading action should be inferred from indicator output alone.
CHANGES /v1/cards/card_pandas_ta_indicators/changesREVOCATIONS /v1/revocations?card_id=card_pandas_ta_indicators
OPEN CARD

vectorbt

Vectorized Python research engine for portfolio simulations, parameter sweeps, and strategy diagnostics over array-like market data.
SANDBOXED

Strong fit for AI agents that need fast experiment loops without writing an entire backtester from scratch.

Tool details

Cuts the first-build guessing stage by giving agents an interface, IO shape, boundaries, and verification checklist up front.

REMOVES Blank-repo scouting, input/output guessing, safety-boundary drafting, and first wrapper planning.RISK DATA-ONLY
Curated as a reusable Apex contract.curated seed card; metadata-only verification pending sandbox notebookCallable contract is documented.
NEXT ACTION REFERENCEREAD STEPS 9
TIER SANDBOXEDLICENSE SEE-UPSTREAMVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE NO
TOKENS EST. 138MARKDOWN /v1/cards/card_vectorbt_backtest_core.mdORIGIN curated seed card; metadata-only verification pending sandbox notebook

No public execution wrapper is exposed; the card is a reference contract only.

python_import unverified-latest MED ROT 4 CHECKSRECHECK 2026-08-18
backtest.vectorizedportfolio.simulationresearch.parameter-sweep
Use vectorbt classes/functions with pandas or NumPy price series. Apex recommends read-only research notebooks and pinned dependency environments.
CHANGES /v1/cards/card_vectorbt_backtest_core/changesREVOCATIONS /v1/revocations?card_id=card_vectorbt_backtest_core
OPEN CARD

APEX Hybrid TradeStore schema

TradeStore schema contract for storing supplied research, paper, and execution-like event records without exposing live broker access.
SANDBOXED

A schema card is safe and useful because agents can build compatible storage without receiving private executors. Wave A exposes the reusable contract first; public execution wrappers stay off until external demand and review evidence justify promotion.

Tool details

Saves event-store schema planning for trading research systems.

REMOVES Table role mapping, audit-field design, and event retention notes.RISK DATA-ONLY
Extracted from APEX_Hybrid/TradeStore as a Wave A source-private reference card.Chosen from the user's stored build capability inventory after the cold-start MCP loop opened.Public card contains capability, IO shape, safety boundary, evidence checklist, and discovery terms only.
NEXT ACTION REFERENCEREAD STEPS 9
TIER SANDBOXEDLICENSE operator-controlledVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE NO
TOKENS EST. 184MARKDOWN /v1/cards/card_apex_hybrid_tradestore_schema.mdORIGIN APEX_Hybrid event storage and audit planning

No public execution wrapper is exposed; the card is a reference contract only.

document | future_http wave-a-2026-07-03 MED ROT 8 CHECKSRECHECK 2026-08-18
database.tradestore-schemaevent.schemaresearch.audit-log
Reference contract: input normalized event schema; output table roles, field definitions, retention hints, and safety notes.
CHANGES /v1/cards/card_apex_hybrid_tradestore_schema/changesREVOCATIONS /v1/revocations?card_id=card_apex_hybrid_tradestore_schema
OPEN CARD

stillme symbol coverage monitor

Coverage monitor contract for supplied market-data snapshots, detecting missing symbols, stale feeds, and uneven collector coverage.
SANDBOXED

A safe operational card that helps agents know whether a dataset is complete enough to trust. Wave A exposes the reusable contract first; public execution wrappers stay off until external demand and review evidence justify promotion.

Tool details

Saves dataset coverage checks and stale-symbol triage before analysis begins.

REMOVES Expected/observed symbol diffing, freshness thresholds, and coverage summary.RISK DATA-ONLY
Extracted from stillme/coverage-monitor as a Wave A source-private reference card.Chosen from the user's stored build capability inventory after the cold-start MCP loop opened.Public card contains capability, IO shape, safety boundary, evidence checklist, and discovery terms only.
NEXT ACTION REFERENCEREAD STEPS 9
TIER SANDBOXEDLICENSE operator-controlledVERIFIED 2026-07-19RECEIPTS 0REVIEWS 0RUNNABLE NO
TOKENS EST. 189MARKDOWN /v1/cards/card_stillme_symbol_coverage_monitor.mdORIGIN stillme public market-data collector coverage checks

No public execution wrapper is exposed; the card is a reference contract only.

document | future_http wave-a-2026-07-03 LOW ROT 8 CHECKSRECHECK 2026-08-18
collector.coverage-monitormarketdata.freshnessops.data-quality
Reference contract: input expected_symbols and observed rows; output missing_symbols, stale_symbols, coverage_pct, and next_collection_checks.
CHANGES /v1/cards/card_stillme_symbol_coverage_monitor/changesREVOCATIONS /v1/revocations?card_id=card_stillme_symbol_coverage_monitor
OPEN CARD