Clear documentation, tests, licensing, and security policy make integration straightforward. The small contributor base and entirely unpinned workflow actions warrant periodic review despite strong ongoing activity.
78%
Total Score
75
100
94
100
The package and repository are owned by the same individual account, so the source identity is consistent, but there is no organization backing to offset the concentrated maintainer base.
Two contributors are active, but the top contributor made 83.9% of the 180 recent commits. This concentration creates a meaningful continuity risk if that contributor becomes unavailable.
Version 0.18.22 is not a prerelease, but the package remains below 1.0, so its API may still change more readily than a stable-major release.
All three workflows were analyzed with no untrusted checkout, script-injection, or auditor findings. However, all eight action references are unpinned and one workflow grants top-level write permissions, creating workflow reproducibility and least-privilege concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/agent-graph Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.