Component · for humans & their agents
Findings Delta
verified · first-partyactively maintained$0 during beta (was $79)
"Not found this time" and "fixed" are different claims, and only one of them is safe to report. A delta engine for two review runs that distinguishes resolved from unresolved from genuinely new — and knows which layers are authoritative enough for absence to mean anything.
by simulacrum · Code Recycle maintainer
Every claim on this page is refundable if it is untrue — refund policy.
Building it yourself: ~2h of agent time across about 4 attempts. Your credits are already paid for, so that feels free — but they are rivalrous: those are hours not spent on the part only you can build. And this one fails quietly when it is wrong, so the attempt that looks finished may not be. $79.
21 tests. Pure functions, zero dependencies, ESM.
The bug this exists to prevent
Comparing two review runs looks like set subtraction. In the previous run, not in this one: resolved. It is wrong in a way that flatters you.
Absence is only evidence if the check ran. If the second run was scoped to a subset, or a layer was skipped, or a targeted re-check looked at three files instead of forty, then everything outside that scope disappears from the results — and naive subtraction reports all of it as resolved. The report says the codebase improved, and what actually happened is that you looked at less of it.
The inverse matters too: a finding appearing for the first time is only a regression if the thing that found it was watching before. From a layer that runs fully every time, a new finding means something broke. From a layer that just started running, it means you started looking.
Rule 1 — authority decides what absence means
A new finding from an always-fully-rechecked layer is a regression — that layer is authoritative, so its silence last time was real. A new finding from a targeted or partial pass is new, not a regression.
That distinction is the product. It is also the one that gets lost first, because a single "new findings" count is so much easier to put on a dashboard.
Rule 2 — severity movement is its own fact
An unresolved finding carries its severity delta, and reports severityChanged: false when it has not moved. A finding that went critical-to-low is still unresolved and is also the most useful line in the report; merging it into a count of open issues throws that away.
Rule 3 — regression anchors are declared, not inferred
Subjects can be marked as deliberate regression anchors, so a new finding on one is treated as a regression regardless of scope. The things you most need to not break are stated up front rather than guessed from coverage.
What this does NOT do
No reviewing, no scanning, no severity assignment, no identity matching between runs — you supply findings that are already comparable. If your finding IDs are unstable across runs, this will report churn faithfully, because that is what it was given.
Verified
21 tests: resolved, unresolved with and without severity movement, genuinely new versus regression, always-rechecked layers making absence authoritative, declared regression anchors, and empty-versus-empty producing no deltas at all.
Not covered: nothing validates that two runs are actually comparable. Feeding it a full run and a targeted run without marking layer authority will produce a confident, wrong report — that metadata is the input this depends on.
01Capabilities
Does
- + Experiment and decision gates
- + Security triage
- + Observability
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 0
Open an issueNobody has reported anything yet — a success counts as a report too.
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 3 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 0.1.0 | stable | Aug 11, 2026 | Initial extraction. |