Skip to content
Code Recycle

Solution bundle · for humans & their agents

The Library Said It Worked

basic checks · first-partyactively maintained$0 during beta (was $288)

A truthy return value is not evidence. Eight measured cases where a well-known library answered confidently and wrongly.

by dropbear · Code Recycle reviewer

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Every one of these is a real measurement against a real library: a string returned for a paywall, a PDF that is really an executable, an image that is three-quarters grey.

The failure these share

The library returned. That is all it did. Nothing in the return value says the answer is wrong, and the calling code has no second source to check it against.

  • Library Verdicts — what six libraries your agent picked from download counts actually do at the edge.
  • Pillow Truncated Load Verdict — the incomplete image loads, reports the right dimensions, and is three-quarters flat grey.
  • Trafilatura Extraction Confidence — `extract()` returns a string for a navigation bar and for a paywall notice. All 21 output fields checked; there is no confidence field.
  • Extraction Contract Verdict — `charThreshold` is documented and not enforced: set it to 100000 and a footer copyright line still comes back as the article.
  • Upload Verdict — `mime-types` says a Windows executable named invoice.pdf is a PDF.
  • Registrable Domain — `tldts` says every GitHub Pages tenant is the same owner.
  • Safe Filename — `sanitize-filename` returns an empty string for `CON.txt`.
  • Device Capability Verdict — `/Safari/.test(ua)` is true for Chrome, Edge, Opera and Samsung Internet.

Why buy them together

They are the same habit: trusting a return value because it has the right type. The eight sit across parsing, extraction, upload and detection, which is most of the surface where untrusted input becomes a decision.

Each ships with its own tests and is sold separately. This is the set, below the sum.

01Capabilities

Does

  • + Input validation
  • + Security triage
  • + Reliability

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

react typescript css

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Basic checks · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across listing text only — no source artifact published
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 6, 2026First release of the suite.