Skip to content

How the assessment works

The agent readiness assessment reads the source of one repository at one commit and reports what it finds. This page describes exactly what happens.

  • The assessment reads files through the GitHub API at the latest commit on the repository’s default branch.
  • The repository is not cloned.
  • Each assessment is pinned to that commit, so a result always refers to one exact revision.

Some paths are never read:

  • .git, node_modules, dist, build, .next, coverage, and vendor
  • environment files such as .env, except example files
  • key and credential files
  • images, media, and archives
  • binary files and symbolic links

Lockfiles are recorded by path only. Their contents are not read.

  • It does not run your code. No application, package script, configuration script, dependency installer, test suite, or browser is run as part of an assessment.
  • It does not write to your repository. Starting an assessment does not create or edit a pull request.
  • It does not send your source to a model provider. The assessment uses fixed parsers and checks. No model requests are made.

Repository access is controlled on GitHub, through a GitHub App installation that you configure.

  • You choose which repositories the installation may access. The picker in Nxtstack only selects one of those repositories. It does not change the installation.
  • For each assessment, Nxtstack requests a token limited to read access to the contents of the one selected repository. If GitHub grants anything beyond metadata and contents, the read is rejected.
  • The token is revoked after the read.

The GitHub App is shared with Nxtstack code review. Code review posts comments on pull requests, so the app registration also has pull request write permission. The assessment does not use that permission.

Before the checks run, you confirm what the application is meant to do, roughly how many users it has, and whether it has launched. Findings are judged against that purpose. The purpose can be filled in for you from the README, the package description, the GitHub repository description, or your previous assessment of the same repository.

The checks are validated against one profile during the pilot: Next.js 16 with TypeScript on Node 22.

  • A repository that matches the profile gets the full set of supported checks.
  • A repository on another Next.js version is assessed and marked as outside the validated profile.
  • Other frameworks get the checks that do not depend on a framework.

Checks that this version cannot assess are reported as Not assessed by this version. They are never counted as passes. See What we check.

The assessment reviews only the source code available at the time of analysis and may miss issues. A good result does not guarantee that your app is secure, reliable, or production ready.