{
  "contract": "open/1",
  "generated": "2026-10-04",
  "door": "https://flashyos.com/open",
  "depth": "https://flashy.tools/open",
  "licence": {
    "spdx": "Apache-2.0",
    "holder": "Flashy Labs"
  },
  "packages": [
    {
      "name": "@flashyos/aao",
      "version": "0.4.2",
      "status": "published",
      "description": "The AAO manifest and charter format, naming standard and conformance suite — what makes an organization an Agentic Autonomous Organization on the DeAI Operating System.",
      "install": "npm i @flashyos/aao",
      "registry": "https://www.npmjs.com/package/@flashyos/aao",
      "page": "https://flashyos.com/packages/aao"
    },
    {
      "name": "@flashyos/agent",
      "version": "0.21.0",
      "status": "published",
      "description": "Report agent state to the FlashyOS mesh — the DeAI Operating System for Agentic Autonomous Organizations (AAOs).",
      "install": "npm i @flashyos/agent",
      "registry": "https://www.npmjs.com/package/@flashyos/agent",
      "page": "https://flashyos.com/packages/agent"
    },
    {
      "name": "@flashyos/alchemy",
      "version": "0.1.0",
      "status": "held",
      "description": "alchemy/1 — a world is a document. Seven operations, laws that are data, and a proof that is the sequence of moves rather than a claim about it.",
      "why": "A format is unpublished until its first adopter — the estate's own rule, which reward/1, wallet/1, ritual/1, pulse/1 and deploy/1 all obey. alchemy/1 has exactly one world today and it is ours, so a registry listing would be adoption theatre. It publishes on the day a second party writes a ruleset, which is also the day the vocabulary stops being ours alone and starts being worth agreeing on."
    },
    {
      "name": "@flashyos/api",
      "version": "0.1.0",
      "status": "internal",
      "description": "FlashyOS API — orgs, agent sessions, membership, and the live event stream."
    },
    {
      "name": "@flashyos/artifact",
      "version": "0.1.0",
      "status": "published",
      "description": "artifact/1 — a dated public commitment to content nobody can read yet. Existence precedes discovery.",
      "install": "npm i @flashyos/artifact",
      "registry": "https://www.npmjs.com/package/@flashyos/artifact",
      "page": "https://flashyos.com/packages/artifact"
    },
    {
      "name": "@flashyos/assetmesh",
      "version": "0.1.0",
      "status": "published",
      "description": "rwa/1 — a machine-readable record of a real-world asset, the attestations that stand behind it, and the obligations issued against it. Dependency-free, publishable at your own domain, verifiable by anyone.",
      "install": "npm i @flashyos/assetmesh",
      "registry": "https://www.npmjs.com/package/@flashyos/assetmesh",
      "page": "https://flashyos.com/packages/assetmesh"
    },
    {
      "name": "@flashyos/backlog",
      "version": "0.1.1",
      "status": "published",
      "description": "backlog/1 — the future tense of a record. One item per intention, filed where the work happens, emitted as a fragment per repository and merged into one list across an estate or a portfolio. Filed is private, publication takes a named human, and every item decays.",
      "install": "npm i @flashyos/backlog",
      "registry": "https://www.npmjs.com/package/@flashyos/backlog",
      "page": "https://flashyos.com/packages/backlog"
    },
    {
      "name": "@flashyos/bolt",
      "version": "0.2.2",
      "status": "published",
      "description": "bolt/1 — one secret, split across an estate. A hunt verified by commitment, in the finder's own browser.",
      "install": "npm i @flashyos/bolt",
      "registry": "https://www.npmjs.com/package/@flashyos/bolt",
      "page": "https://flashyos.com/packages/bolt"
    },
    {
      "name": "@flashyos/canon",
      "version": "0.1.0",
      "status": "published",
      "description": "canon/1 — a lockfile for facts. One authority per fact, fetched by every property that renders it, with drift as a build failure rather than a silent update.",
      "install": "npm i @flashyos/canon",
      "registry": "https://www.npmjs.com/package/@flashyos/canon",
      "page": "https://flashyos.com/packages/canon"
    },
    {
      "name": "@flashyos/checkpoint",
      "version": "0.2.0",
      "status": "published",
      "description": "checkpoint/1 — a Merkle tree head over the sealed claims an organisation already publishes. RFC 6962 hashing, inclusion and consistency proofs, verifiable offline against the fragments themselves.",
      "install": "npm i @flashyos/checkpoint",
      "registry": "https://www.npmjs.com/package/@flashyos/checkpoint",
      "page": "https://flashyos.com/packages/checkpoint"
    },
    {
      "name": "@flashyos/compute",
      "version": "0.1.0",
      "status": "held",
      "description": "compute/1 — an append-only, per-initiative history of the inference compute an AAO spent. Token counts and request ids, never money; cost is derived at read from a caller-supplied rate table, never stored.",
      "why": "Not published, and the reason is the format's own subject. compute/1 records the inference compute an AAO spent per initiative, and the estate has spent none through the seam yet — LLM_PROVIDER has never been flipped to gatewayz outside tests, so every history the format would carry today is empty or uncaptured. Publishing a package for a per-initiative compute history when no initiative has captured compute is a registry entry for a thing nobody does, which is the adoption theatre this estate measures elsewhere. The estate's rule for exactly this is written down repeatedly: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing."
    },
    {
      "name": "@flashyos/conformance",
      "version": "0.2.3",
      "status": "published",
      "description": "Run the FlashyOS conformance suite against any domain, or audit your own charter and handshake offline. Scaffolds a new property to L2 with one command. Exit 0 only when the level you asked for is actually met.",
      "install": "npm i @flashyos/conformance",
      "registry": "https://www.npmjs.com/package/@flashyos/conformance",
      "page": "https://flashyos.com/packages/conformance"
    },
    {
      "name": "@flashyos/countersign",
      "version": "0.1.0",
      "status": "published",
      "description": "Verification over a directory/1 record: a countersignature from the party a claim is about, an audit of what a website can prove, and a badge that carries a date. Ed25519 over the canonical assertion, verifiable offline from two published keys.",
      "install": "npm i @flashyos/countersign",
      "registry": "https://www.npmjs.com/package/@flashyos/countersign",
      "page": "https://flashyos.com/packages/countersign"
    },
    {
      "name": "@flashyos/create-mesh-agent",
      "version": "0.2.0",
      "status": "published",
      "description": "Scaffold a dependency-free FlashyOS mesh starter agent into your repo — a standing worker that heartbeats, works your org's approved joint-initiative tasks (you supply the evidence), and surfaces roadmap matches, in one file. Agents suggest, humans consent; the agent completes work but never seals.",
      "install": "npm i @flashyos/create-mesh-agent",
      "registry": "https://www.npmjs.com/package/@flashyos/create-mesh-agent",
      "page": "https://flashyos.com/packages/create-mesh-agent"
    },
    {
      "name": "@flashyos/create-mesh-node",
      "version": "0.1.0",
      "status": "published",
      "description": "Join the FlashyOS mesh in one command — scaffolds a charter, handshake, directory fragment and emit workflow, then verifies you pass L2 before it finishes. No account, nothing published.",
      "install": "npm i @flashyos/create-mesh-node",
      "registry": "https://www.npmjs.com/package/@flashyos/create-mesh-node",
      "page": "https://flashyos.com/packages/create-mesh-node"
    },
    {
      "name": "@flashyos/defined",
      "version": "0.1.0",
      "status": "held",
      "description": "defined/1 — one term, one authority, federated. A vocabulary standard: definitions that decay rather than seal, citations that link rather than copy, and a collision reported as a defect.",
      "why": "Not published, and the reason is this family's own rule for formats: publication on the first adopter, never before. No party outside the estate this was written in publishes a defined/1 fragment yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing."
    },
    {
      "name": "@flashyos/delivery",
      "version": "0.1.0",
      "status": "published",
      "description": "delivery/1 — the rungs between a merged commit and a thing somebody actually has. Published, distributed and linked are measured by fetching, never declared.",
      "install": "npm i @flashyos/delivery",
      "registry": "https://www.npmjs.com/package/@flashyos/delivery",
      "page": "https://flashyos.com/packages/delivery"
    },
    {
      "name": "@flashyos/deploy",
      "version": "0.1.0",
      "status": "held",
      "description": "deploy/1 — where a repository is hosted, declared in the repository. Root directory, production branch, framework and registrar, checked against the tree rather than remembered from a hosting panel.",
      "why": "Not published, and by the same rule reward/1 carries: publication on the first adopter, never before. deploy/1 is a format and a dependency-free checker meant to be vendored into any repository that serves a domain, and no party outside this estate declares one yet — so a registry entry today would be a package for a thing nobody does, which is the adoption theatre this estate measures elsewhere. Apache rather than AGPL because a checker a party can only run under copyleft is one the parties who most need to declare a deployment cannot embed."
    },
    {
      "name": "@flashyos/dialects",
      "version": "0.1.0",
      "status": "published",
      "description": "One charter, many dialects — emits the surfaces other standards define (agents.txt/agents.json, A2A Agent Card) from an organisation's AAO charter, so the same facts cannot drift between them. Refuses to emit a surface the organisation does not serve.",
      "install": "npm i @flashyos/dialects",
      "registry": "https://www.npmjs.com/package/@flashyos/dialects",
      "page": "https://flashyos.com/packages/dialects"
    },
    {
      "name": "@flashyos/directory",
      "version": "0.2.0",
      "status": "published",
      "description": "The estate directory — one record per real thing, emitted as fragments by each repository and merged into a single world model every property renders a view over.",
      "install": "npm i @flashyos/directory",
      "registry": "https://www.npmjs.com/package/@flashyos/directory",
      "page": "https://flashyos.com/packages/directory"
    },
    {
      "name": "@flashyos/eslint-config",
      "version": "0.1.0",
      "status": "published",
      "description": "The estate's shared ESLint base. One config every property extends, so a lint rule is argued once.",
      "install": "npm i @flashyos/eslint-config",
      "registry": "https://www.npmjs.com/package/@flashyos/eslint-config",
      "page": "https://flashyos.com/packages/eslint-config"
    },
    {
      "name": "@flashyos/estate-ring",
      "version": "0.1.0",
      "status": "held",
      "description": "estate-ring/1 — read the estate's interlink ring the way a stranger reads it, and render a footer column of one group's properties. Four findings, and only the live are linked.",
      "why": "Not published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate reads an interlink ring as estate-ring/1 yet, so a package on a registry would be adoption theatre. The vendored emitter travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing; the ring the footer renders is the served document, not the package."
    },
    {
      "name": "@flashyos/frontdoor",
      "version": "0.1.0",
      "status": "published",
      "description": "frontdoor/1 — a published door: which lanes an organisation opens, what it asks at each, and what it owes in return. Emitted per repository, validated across an estate, verified from the applicant's own domain.",
      "install": "npm i @flashyos/frontdoor",
      "registry": "https://www.npmjs.com/package/@flashyos/frontdoor",
      "page": "https://flashyos.com/packages/frontdoor"
    },
    {
      "name": "@flashyos/guardian",
      "version": "0.1.0",
      "status": "held",
      "description": "guardian/1 — the signer's shape lifted out: an independent process that re-derives, refuses, holds or escalates any consequential action, with its own key and no import from the packages it guards. A verdict is a signed, checkable thing rather than a boolean.",
      "why": "Not published, and the reason is independence as much as adoption: a guardian is only worth anything if it runs somewhere the guarded code cannot reach, and no organisation outside this repository deploys one yet. Publishing the shape before a second deployment exists would be a package for a thing nobody does, which is the adoption theatre this estate measures elsewhere. It becomes public with the first guardian deployed by a party other than the one it guards."
    },
    {
      "name": "@flashyos/holding",
      "version": "0.1.0",
      "status": "published",
      "description": "holding/1 — a log of what happened to the positions an office holds. Transitions rather than states, consent enforced rather than asserted, and no currency figures in version 1.",
      "install": "npm i @flashyos/holding",
      "registry": "https://www.npmjs.com/package/@flashyos/holding",
      "page": "https://flashyos.com/packages/holding"
    },
    {
      "name": "@flashyos/llm-gateway",
      "version": "0.2.1",
      "status": "published",
      "description": "Provider-agnostic inference seam: adapters, automatic failover, and an empty-success guard. One package so the estate stops carrying copies.",
      "install": "npm i @flashyos/llm-gateway",
      "registry": "https://www.npmjs.com/package/@flashyos/llm-gateway",
      "page": "https://flashyos.com/packages/llm-gateway"
    },
    {
      "name": "@flashyos/llms-txt",
      "version": "0.1.1",
      "status": "published",
      "description": "Parse, validate, and build llms.txt files — machine-readable site metadata for the DeAI web, extracted from the tooling every Flashy property ships in production.",
      "install": "npm i @flashyos/llms-txt",
      "registry": "https://www.npmjs.com/package/@flashyos/llms-txt",
      "page": "https://flashyos.com/packages/llms-txt"
    },
    {
      "name": "@flashyos/mail",
      "version": "0.3.0",
      "status": "published",
      "description": "mail/1 and the estate's mail control plane: a lane policy that refuses, a capture that demands a consent basis, a content-free event record, and a transport seam so the provider is a variable.",
      "install": "npm i @flashyos/mail",
      "registry": "https://www.npmjs.com/package/@flashyos/mail",
      "page": "https://flashyos.com/packages/mail"
    },
    {
      "name": "@flashyos/mcp",
      "version": "0.6.0",
      "status": "published",
      "description": "Model Context Protocol server for FlashyOS — connect any MCP-speaking agent to the mesh in one config block. Wraps @flashyos/agent.",
      "install": "npm i @flashyos/mcp",
      "registry": "https://www.npmjs.com/package/@flashyos/mcp",
      "page": "https://flashyos.com/packages/mcp"
    },
    {
      "name": "@flashyos/mesh",
      "version": "0.1.0",
      "status": "published",
      "description": "One checklist for joining the mesh — what a repository has adopted, what is left, and the command for each.",
      "install": "npm i @flashyos/mesh",
      "registry": "https://www.npmjs.com/package/@flashyos/mesh",
      "page": "https://flashyos.com/packages/mesh"
    },
    {
      "name": "@flashyos/page",
      "version": "0.1.1",
      "status": "published",
      "description": "One page, one card, one claim — per-page social images, canonical metadata and structured data for a property that expects to be cited by search engines and answered from by generative ones.",
      "install": "npm i @flashyos/page",
      "registry": "https://www.npmjs.com/package/@flashyos/page",
      "page": "https://flashyos.com/packages/page"
    },
    {
      "name": "@flashyos/pinned",
      "version": "0.1.0",
      "status": "held",
      "description": "pinned/1 — a drift-detection standard for derived content. A derived artifact (a course, a doc, a vendored file, a figure) declares {source, revision}; a dependency-free checker returns current / stale / unverifiable against live revisions. The verdict is derived, never stored.",
      "why": "Published on the first external adopter, never before — the estate's rule for every record format. pinned/1 is adopted INSIDE the estate today by vendored file copy (flashy.academy's content-graph gate consumes it; flashyos pins its own derived docs through tools/pinned.mjs), which is how every record format here actually travels: node: builtins only, copied byte-for-byte, no install. A registry entry for a standard nobody outside has adopted is the adoption theatre this estate measures against, so it stays private until someone outside asks to install it — at which point being unpublished has cost that adopter nothing."
    },
    {
      "name": "@flashyos/playbook",
      "version": "0.2.0",
      "status": "published",
      "description": "playbook/1 — a way two or more organisations work together, as a published document rather than code. Named roles, ordered steps, and an evidence kind per step. Authored by an org, served at its own domain, adopted by reference.",
      "install": "npm i @flashyos/playbook",
      "registry": "https://www.npmjs.com/package/@flashyos/playbook",
      "page": "https://flashyos.com/packages/playbook"
    },
    {
      "name": "@flashyos/promotion",
      "version": "0.1.0",
      "status": "internal",
      "description": "Internal. Which properties in this estate hear about a ship, and which never do — the three-tier promotion doctrine, its routing table, and the per-property register copy must clear."
    },
    {
      "name": "@flashyos/pulse",
      "version": "0.1.0",
      "status": "held",
      "description": "pulse/1 — condition over time. One dated, sealed, append-only snapshot per reading; deltas are derived and may never be asserted. The fourth tense: what a thing's condition was, not just what it is.",
      "why": "Not published, and by the same rule deploy/1 carries: publication on the first adopter, never before. pulse/1 is a format and a vendored emitter, and no adopter outside this estate keeps a condition series yet — the command centre reads the workspace directly and the vendored file travels by copy, so publishing now would be a registry entry for a thing nobody does. Apache rather than AGPL because a format for measuring your own estate is worth nothing if the parties measuring theirs cannot embed it."
    },
    {
      "name": "@flashyos/register",
      "version": "0.1.0",
      "status": "held",
      "description": "register/1 — what a group owns, who holds it and under what licence, with every fact naming the authority that declared it. Derived fields are refused by name, an unregistered entity is a row rather than an absence, and the renderer emits the awkward halves or throws.",
      "why": "Not published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate publishes a register yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing. The FRAGMENT is served publicly today; that is the document, not the package."
    },
    {
      "name": "@flashyos/reward",
      "version": "0.1.1",
      "status": "held",
      "description": "reward/1 — an append-only accrual log for entitlements that cannot be paid until a settlement venue exists. No currency, one signup per verified identity, and settlement that refuses.",
      "why": "Not published, and the reason is the format's own subject. reward/1 describes entitlements that cannot be paid until a settlement venue exists, and no venue exists — Flashy Finance's shared wallet is the venue and it has not been built. Nothing in this estate emits the format, so publishing it would put a package on a registry for a thing nobody does yet. The estate's rule for exactly this is written down twice: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing."
    },
    {
      "name": "@flashyos/ritual",
      "version": "0.1.0",
      "status": "held",
      "description": "ritual/1 — the estate's present tense: recurring, witnessed, consequence-bearing observances. Agents observe, humans consecrate; unwitnessed practice moves nothing; no value, no standing, append-only.",
      "why": "Not published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. Nothing outside this estate observes a liturgy yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing."
    },
    {
      "name": "@flashyos/shiplog",
      "version": "0.1.0",
      "status": "published",
      "description": "shipped/1 — the past tense of a record. One sealed entry per thing that shipped, emitted per repository and merged into one cross-repository calendar, changelog and attribution report. Verifiable offline; the past is append-only.",
      "install": "npm i @flashyos/shiplog",
      "registry": "https://www.npmjs.com/package/@flashyos/shiplog",
      "page": "https://flashyos.com/packages/shiplog"
    },
    {
      "name": "@flashyos/shipos",
      "version": "0.1.0",
      "status": "internal",
      "description": "The release function, chartered: a consequence-ranked merge queue for every repository an organization ships from."
    },
    {
      "name": "@flashyos/signer",
      "version": "0.1.0",
      "status": "published",
      "description": "The isolated signer for the FlashyOS wallet authorization plane: verifies an Ed25519-signed SpendAuthorization, re-derives the operation from the real call, refuses on any mismatch, executes through Tether WDK, and reports settlement. Holds the seed; never holds the plane's private key.",
      "install": "npm i @flashyos/signer",
      "registry": "https://www.npmjs.com/package/@flashyos/signer",
      "page": "https://flashyos.com/packages/signer"
    },
    {
      "name": "@flashyos/standing",
      "version": "0.1.0",
      "status": "held",
      "description": "standing/1 — a figure that is derived, never asserted. A pure function over verified-evidence history (per agent, per capability, per counterparty, per environment, decaying with time) whose inputs and function are published so any reader recomputes it, and whose only power is to propose an authority change a human resolves.",
      "why": "Not published, and the reason is doctrine as much as adoption: a trust figure is the most tempting derived field this estate will ever hold, and the decision on who may see one is private-tier, promote-only, refused by name in every validator. No organisation outside this repository computes standing/1 yet, so a registry entry would be adoption theatre; and until the figure's visibility rule has a first adopter, publishing the function invites publishing the number."
    },
    {
      "name": "@flashyos/tally",
      "version": "0.1.0",
      "status": "held",
      "description": "tally/1 — the figures an organisation publishes about itself, shaped so a reader can tell which of them the publisher can raise at will. Denominators are required, superlatives and money are refused, and a tally with no figure somebody else has to move is invalid.",
      "why": "Not published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate publishes a tally yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing."
    },
    {
      "name": "@flashyos/verify",
      "version": "0.5.0",
      "status": "published",
      "description": "Re-verify every sealed settlement on the FlashyOS network: fetch the public feed, recompute each sha256, exit 0 only if the books check out. Verify, don't trust — including us.",
      "install": "npm i @flashyos/verify",
      "registry": "https://www.npmjs.com/package/@flashyos/verify",
      "page": "https://flashyos.com/packages/verify"
    },
    {
      "name": "@flashyos/voice",
      "version": "0.1.0",
      "status": "held",
      "description": "voice/1 — a register-and-lint convention: one config a person writes stating how a property sounds, and a mechanical check that a piece of copy obeys it. Not a sealed record format; nothing here is witnessed or consecrated.",
      "why": "Not published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. gda-group is voice/1's first real adopter and it takes the file by copy, not by installing this package, so a registry listing would be adoption theatre before any second repository has asked for one. The vendored file travels by copy, which is how every convention in this estate actually travels, so being unpublished costs an adopter nothing."
    },
    {
      "name": "@flashyos/wallet",
      "version": "0.1.0",
      "status": "held",
      "description": "wallet/1 — one holding across books that are not one book. Balances derived never asserted, every entry naming its ledger, and nothing available until a venue is operational.",
      "why": "Not published, and the reason is the format's own subject. wallet/1 describes a holding that becomes spendable only once a venue declares itself operational and cites an invariant run that passed. Flashy Finance is that venue and it is being built; no fragment in this estate declares an operational one. Publishing the package now would put a wallet contract on a registry ahead of the thing that honours it, which is the failure this format exists to refuse, made one layer up. The estate's rule for exactly this is written down twice: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing."
    },
    {
      "name": "@flashyos/wallet-wdk",
      "version": "0.1.0",
      "status": "published",
      "description": "Governed economic agency for FlashyOS agents on Tether WDK: the AAO WalletCapability, a FlashyOS authorizer client, an MCP elicitation handler, and a WDK policy rule that defers to the authorization plane.",
      "install": "npm i @flashyos/wallet-wdk",
      "registry": "https://www.npmjs.com/package/@flashyos/wallet-wdk",
      "page": "https://flashyos.com/packages/wallet-wdk"
    },
    {
      "name": "@flashyos/wdk",
      "version": "0.1.0",
      "status": "published",
      "description": "The FlashyOS agent object: identity, authority, wallet, memory and partners behind one interface. Create an agent, give it an identity, provision financial capabilities on Tether WDK, set its permissions, let it transact, record what it did, coordinate it with other agents — through one object, one event system, any chain WDK reaches.",
      "install": "npm i @flashyos/wdk",
      "registry": "https://www.npmjs.com/package/@flashyos/wdk",
      "page": "https://flashyos.com/packages/wdk"
    },
    {
      "name": "@flashyos/workflow",
      "version": "0.1.0",
      "status": "held",
      "description": "workflow/1 — a versioned definition of ordered steps, each an agent node, a human-approval node or a deterministic-service node, with retry, timeout and compensation as explicit step properties and evidence required per step by kind. Definition and pure state machine only; persistence belongs to the caller.",
      "why": "Not published, and the reason is the estate's rule for formats: publication on the first adopter, never before. workflow/1 is new in V2-D and no organisation outside this repository runs a workflow through it yet; the invoice-to-payment scenario in its own tests is the only adopter. A registry entry for a format nobody runs would be adoption theatre, which the estate measures elsewhere. It becomes public the day a second property executes a definition it did not write."
    }
  ],
  "repositories": [
    {
      "name": "FlashyLabs/aao",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The AAO manifest spec and its JSON Schema.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/agent-dns",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "agent-dns/1 — domain→organisation→agent resolution over one DNS TXT record, with a dependency-free reference resolver.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/agent-dns"
    },
    {
      "name": "FlashyLabs/agent-wellknown",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "agent/1 — the /.well-known/agent discovery document: how a site exposes an authenticated, discoverable, payable machine interface.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/agent-wellknown"
    },
    {
      "name": "FlashyLabs/agentfile",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "agentfile — answer the accountability question about an organisation in ninety seconds.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/agentfile",
      "planned": true,
      "release": {
        "package": "agentfile",
        "published": false,
        "status": "Not released. The formats it writes are published and stable; the seven questions and the writer are the work that remains. Nothing here is installable yet."
      }
    },
    {
      "name": "FlashyLabs/agentgraph",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "graph/1 — the vendor-neutral spec for the universal graph of the agentic internet: who and what exists, and the evidenced relations between them.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/agentgraph"
    },
    {
      "name": "FlashyLabs/agentpay",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "pay-policy/1 — the vendor-neutral payment-policy abstraction for agents: an allow/deny/escalate evaluator, not a wallet.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/agentpay"
    },
    {
      "name": "FlashyLabs/bastion",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "Bastion — the gateway that exposes an existing site or API as a secure, authenticated, payable machine interface. In design.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/bastion"
    },
    {
      "name": "FlashyLabs/chronicle",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The Chronicle — chronicle.press: agent-drafted news whose every factual claim carries a verifiable receipt against a real sealed record.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/ClaimYour.Gold",
      "licence": "AGPL-3.0-only",
      "holder": "ClaimYour.Gold",
      "what": "The hunter economy and its ledger.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/conformance-kit",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "@flashyos/conformance-kit — run a conformance corpus against any executable, in any language.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/conformance-kit",
      "planned": true,
      "release": {
        "package": "@flashyos/conformance-kit",
        "published": false,
        "status": "Pre-1.0. The line protocol is the part worth freezing and it is deliberately tiny: `{id, set, input, context?}` in, `{id, valid, codes?}` out. It will be locked at 1.0 and has not changed since it was written."
      }
    },
    {
      "name": "FlashyLabs/flashy-academy",
      "licence": "AGPL-3.0-only",
      "holder": "Flashy.Academy",
      "what": "The knowledge layer.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashy-contracts",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The seam between repositories: OpenAPI specs, the identity package and the boundary lint rules. API contracts, not Solidity.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashy-docs",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The documentation hub for the Flashy ecosystem.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/flashy-docs"
    },
    {
      "name": "FlashyLabs/flashy-examples",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "Working examples and tutorials for the estate’s packages.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/flashy-examples"
    },
    {
      "name": "FlashyLabs/flashy-finance",
      "licence": "AGPL-3.0-only",
      "holder": "Flashy Finance",
      "what": "flashy.financial — the wallet and financial rail. A dependency-free static generator.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashy-group",
      "licence": "AGPL-3.0-only",
      "holder": "Flashy Group",
      "what": "flashygroup.com — the parent site and the estate’s brand canon.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashy-ledger",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "@flashylabs/ledger — the multi-asset ledger other properties post through.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/flashy-ledger"
    },
    {
      "name": "FlashyLabs/flashy-network",
      "licence": "AGPL-3.0-only",
      "holder": "Flashy Network",
      "what": "flashynetwork.com — the public face of the mesh, and the ledger explorer.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashy-sdk",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "@flashy/sdk — a typed client for the Hunter Identity API.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashy-tools",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "flashy.tools — the developer-tools property: the estate’s packages, formats and instruments documented with their edge cases.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashyid",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The identity layer and @flashyid/sdk, the grant kernel others enforce with.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/flashyid-spec",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "delegation/1 — the vendor-neutral spec, schema, vectors and checker for cryptographically provable delegated authority for agents.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/flashyid-spec"
    },
    {
      "name": "FlashyLabs/flashyos-spec",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The public home of the estate’s accountability formats — aao/0.1, flashyos/1, directory/1, frontdoor/1 and the rest: spec, schema, conformance corpus and a dependency-free checker per format.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/flashyos-spec",
      "planned": true,
      "release": {
        "package": null,
        "published": false,
        "status": "The specifications are not here yet. They are Apache-2.0 today; carrying the packages out of the monorepo they were written in, *with their real commit history*, is a deliberate operation rather than a copy — a chain of title that begins on the day somebody remembered to copy the files is not a chain of title. Until that runs, this repository is the licence, the security policy and the direction."
      }
    },
    {
      "name": "FlashyLabs/flashyos-tools",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "@flashyos/tools — small answers to questions that fail silently; the estate’s charter and provisioning tooling.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/flashyos-tools",
      "planned": true,
      "release": {
        "package": "@flashyos/tools",
        "published": false,
        "status": "Pre-1.0. `served` and `reachability` have been running against a thirty-eight repository estate for months; the API is small and unlikely to move, but the version says 0.x until somebody outside that estate has depended on it."
      }
    },
    {
      "name": "FlashyLabs/flashyos-wdk",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The public mirror of the WDK wallet stack: the extractor packs, the remote-authorization policy, the isolated signer and the agent object.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/flashyos-wdk"
    },
    {
      "name": "FlashyLabs/gda-group",
      "licence": "AGPL-3.0-only",
      "holder": "GDA Capital",
      "what": "gda.group and its mesh work agent.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/gold-holdings",
      "licence": "AGPL-3.0-only",
      "holder": "Gord Holdings",
      "what": "gord.holdings, gord.capital and gord.enterprises.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/intent-spec",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The canonical, vendor-neutral home of intent/1 — spec, JSON Schema, conformance vectors and a dependency-free checker.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/intent-spec"
    },
    {
      "name": "FlashyLabs/magician",
      "licence": "Apache-2.0",
      "holder": "Flashy Group",
      "what": "Magician — trust routing, consent-gated introductions, sealed outcomes; magician.network.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/mesh-lint",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "@flashyos/mesh-lint — a GitHub Action for the checks that fail silently.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/mesh-lint",
      "planned": true,
      "release": {
        "package": "@flashyos/mesh-lint",
        "published": false,
        "status": "Not released. The code is here; the distribution is not. The three checks run, are tested against fixtures rather than against the estate that found them, and `action.yml` is a composite action with no build step. What does not exist yet is a published package or a tag — measured 2026-09-23, `@flashyos/mesh-lint` answers 404 on npm and this repository has no tags — so `npx @flashyos/mesh-lint` and `uses: flashylabs/mesh-lint@v1` both fail today. Clone it and run `node src/cli.mjs` until they do. That gap is named here rather than left for the first person who copies a line out of the section above, which is the same defect this package's own `well-known` check exists to find."
      }
    },
    {
      "name": "FlashyLabs/ritual-spec",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "ritual/1 — the vendor-neutral spec, schema, vectors and checker for recurring, witnessed, consequence-bearing observances.",
      "visibility": "unread"
    },
    {
      "name": "FlashyLabs/stack.json",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "web4/1 — the machine-readable index of the Web 4 / agentic-internet stack: one document, a schema and a dependency-free checker.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/stack.json"
    },
    {
      "name": "FlashyLabs/therealm",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The Realm — therealm.live: the machine-navigable world over the estate’s houses; realm/1 indexes every house, its door and the Chronicle feed.",
      "visibility": "private"
    },
    {
      "name": "FlashyLabs/trust-spec",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "trust/1 — the vendor-neutral spec, schema, vectors and checker for the estate’s trust-routing / trust-graph wire format.",
      "visibility": "unread"
    },
    {
      "name": "FlashyLabs/trustgraph",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "trustgraph — the service that computes standing over the trust graph, reading graph/1 and trust/1; standing derives from what others assert, never from what a party sets for itself.",
      "visibility": "unread"
    },
    {
      "name": "FlashyLabs/wdk-capability-audit",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "Scan node_modules for installed @tetherto/wdk-* packages and report the chains each declares, refusing to guess at one it does not recognise.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/wdk-capability-audit"
    },
    {
      "name": "FlashyLabs/wdk-policy-guard",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "A spending-policy layer for WDK wallets: grade a transfer against a per-agent envelope and return ALLOW, ESCALATE or DENY, with a reason.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/wdk-policy-guard"
    },
    {
      "name": "FlashyLabs/wdk-staking-kit",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "A reference staking primitive for WDK wallets: lock a balance for a fixed term at a published rate; only yield is a real write, on close.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/wdk-staking-kit"
    },
    {
      "name": "FlashyLabs/web4",
      "licence": "Apache-2.0",
      "holder": "Flashy Labs",
      "what": "The human front door to the Web 4 stack: the map, the architecture, the principles and the rule for how a new protocol joins.",
      "visibility": "public",
      "url": "https://github.com/FlashyLabs/web4"
    }
  ],
  "counts": {
    "packages": 49,
    "published": 30,
    "held": 16,
    "internal": 3,
    "repositories": 39,
    "publicRepos": 21,
    "unreadRepos": 3,
    "plannedRepos": 5
  }
}