How the assessment works
The agent readiness assessment reads the source of one repository at one commit and reports what it finds. This page describes exactly what happens.
What it reads
Section titled “What it reads”- The assessment reads files through the GitHub API at the latest commit on the repository’s default branch.
- The repository is not cloned.
- Each assessment is pinned to that commit, so a result always refers to one exact revision.
Some paths are never read:
.git,node_modules,dist,build,.next,coverage, andvendor- environment files such as
.env, except example files - key and credential files
- images, media, and archives
- binary files and symbolic links
Lockfiles are recorded by path only. Their contents are not read.
What it never does
Section titled “What it never does”- It does not run your code. No application, package script, configuration script, dependency installer, test suite, or browser is run as part of an assessment.
- It does not write to your repository. Starting an assessment does not create or edit a pull request.
- It does not send your source to a model provider. The assessment uses fixed parsers and checks. No model requests are made.
What access it uses
Section titled “What access it uses”Repository access is controlled on GitHub, through a GitHub App installation that you configure.
- You choose which repositories the installation may access. The picker in Nxtstack only selects one of those repositories. It does not change the installation.
- For each assessment, Nxtstack requests a token limited to read access to the contents of the one selected repository. If GitHub grants anything beyond metadata and contents, the read is rejected.
- The token is revoked after the read.
The GitHub App is shared with Nxtstack code review. Code review posts comments on pull requests, so the app registration also has pull request write permission. The assessment does not use that permission.
Confirming the purpose
Section titled “Confirming the purpose”Before the checks run, you confirm what the application is meant to do, roughly how many users it has, and whether it has launched. Findings are judged against that purpose. The purpose can be filled in for you from the README, the package description, the GitHub repository description, or your previous assessment of the same repository.
What is supported today
Section titled “What is supported today”The checks are validated against one profile during the pilot: Next.js 16 with TypeScript on Node 22.
- A repository that matches the profile gets the full set of supported checks.
- A repository on another Next.js version is assessed and marked as outside the validated profile.
- Other frameworks get the checks that do not depend on a framework.
Checks that this version cannot assess are reported as Not assessed by this version. They are never counted as passes. See What we check.
What a result means
Section titled “What a result means”The assessment reviews only the source code available at the time of analysis and may miss issues. A good result does not guarantee that your app is secure, reliable, or production ready.