$ AI agent governance, security tooling, and mechanical enforcement.

rigscore v0.9.0

rigscore, security, ai, devtools, open-source

Changes: v0.8.0 → v0.9.0

5 features and 5 fixes. 10 changes total.

ChangeWhat it does
flip CTA default to opt-in via –ctaNew capability
runtime tool description hashing via print-and-paste workflowNew capability
augment typosquat detection with MCP registry APINew capability
hash-pin MCP server shape to detect rug-pulls (CVE-2025-54136)New capability
add instruction-effectiveness and skill-coherence checksNew capability
scope check to project (cwd) by defaultBug fix
extend homoglyph coverage to Mathematical/Fullwidth/CherokeeBug fix
scope version-pin check to package-position arg onlyBug fix
correctness bugs W3 (C3, C5, H2, H4)Bug fix
repair broken GitHub Action and add meaningful CI self-scan gateBug fix

Install

1
npx github:Back-Road-Creative/rigscore

No accounts, no telemetry, no network calls. MIT licensed.

github.com/Back-Road-Creative/rigscore

Configuration details reflect a production environment at time of writing. Implementation specifics vary based on tooling versions, platform updates, and organizational requirements. Validate approaches against current documentation before deployment.