agentreadme

Report · marked 26 Aug 2026

aquasecurity/trivy

An agent can work here, but it will waste turns finding its footing.

Go · 37,609 stars · 3,380 files · branch main

Fix these first

01
Agent instruction file
Add an AGENTS.md at the root: what the project is, how to install, how to run, how to test, and the two or three conventions a newcomer always gets wrong.
02
Instruction quality
Instructions earn their keep by naming exact commands. 'Run the tests with `pnpm test`' beats three paragraphs of philosophy.
03
Discoverable commands
Declare the handful of commands that matter in package.json scripts, a Makefile, or a justfile. Naming them turns guesswork into a lookup.

The full marking

Every deduction below names the file or setting it came from.

Instructions 3/27 F

Whether the repo tells an agent how to behave before it starts guessing.

Agent instruction file 0/12
None found. Every agent that opens this repo starts from zero.
Add an AGENTS.md at the root: what the project is, how to install, how to run, how to test, and the two or three conventions a newcomer always gets wrong.
Looked for AGENTS.md, CLAUDE.md, .github/copilot-instructions.md, .cursorrules
Instruction quality 0/12
Nothing to judge, since there are no instructions.
Instructions earn their keep by naming exact commands. 'Run the tests with `pnpm test`' beats three paragraphs of philosophy.
README as an entry point 3/3
README has a clear getting-started section.
Setup 10/20 C+

Whether an agent can install the project and get it running without a human.

Deterministic install 6/6
go.sum pins the dependency tree.
Found go.sum
Discoverable commands 0/6
No declared commands. An agent has to infer how to build and run this from the file tree.
Declare the handful of commands that matter in package.json scripts, a Makefile, or a justfile. Naming them turns guesswork into a lookup.
Environment config 0/4
Nothing documents the environment this needs. An agent will get a runtime error it can't diagnose.
Add a .env.example listing every variable with a safe placeholder value. It's the cheapest possible fix and it unblocks the whole first run.
Pinned runtime version 2/2
The language runtime version is pinned.
go.mod declares a Go version
Reproducible environment 2/2
dockerfile gives a known-good environment.
Verification loop 22/22 A+

Whether an agent can check its own work. This is the category that most decides whether agent output is trustworthy.

Tests exist 8/8
665 test files against 1643 source files.
e.g. .github/actions/trivy-triage/helpers.test.js, .github/workflows/bypass-test.yaml, e2e/e2e_test.go
Test command is discoverable 7/7
An agent can find and run `go test ./...`.
Continuous integration 4/4
22 GitHub Actions workflows define what "passing" means.
Lint and format rules 3/3
.golangci.yaml encodes the house style.
Static type checking n/a
Not applicable — the Go compiler type checks every build.
Context economy 9/20 C

Whether the repo fits in a context window, or fights it.

No committed build output 0/6
Generated output is committed: node_modules/, coverage/, .terraform/.
Add these to .gitignore and `git rm -r --cached` them. Generated files pollute search results, so an agent grepping for a function finds the compiled copy and edits the wrong file.
.gitignore hygiene 3/3
.gitignore covers 23 patterns.
File sizes fit in context 6/6
No source file is large enough to crowd out a context window.
Repository weight 0/5
About 941MB checked out. Large enough that cloning and searching are both slow.
Large binaries and vendored trees slow every operation an agent performs. Git LFS or a separate assets repo keeps the working tree navigable.

Here is your AGENTS.md

Drafted from what is actually in this repository: the install command from your lockfile, the commands you already declare, your real directory layout. Anything marked TODO needs a person. Save it at the root as AGENTS.md.

AGENTS.md — drafted for aquasecurity/trivy
# AGENTS.md

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

## Setup

```
go mod download
```

## Commands

```
go test ./...   # run the test suite
```

## Layout

- `pkg/`         1585 source files
- `internal/`    18 source files
- `integration/` 14 source files
- `magefiles/`   10 source files
- `misc/`        3 source files
- `ci/`          2 source files

## Conventions

- Tests live alongside the code they cover, following `.github/actions/trivy-triage/helpers.test.js`.
- CI defines what passing means. See `.github/workflows/auto-close-issue.yaml`, and keep it green.
- TODO: add the two or three conventions a newcomer always gets wrong here.

---

Drafted by agentreadme.com from what is in this repository. Everything marked TODO
needs a human. Check it in as AGENTS.md at the root.

Open the raw markdown  or  curl -o AGENTS.md agentreadme.com/draft/aquasecurity/trivy.md

Show the mark

The badge re-checks daily, so it keeps up as the repository changes. Use mark again to force it now.

agent ready 55 out of 100

[![agent ready](https://agentreadme.com/badge/aquasecurity/trivy.svg)](https://agentreadme.com/aquasecurity/trivy)

Other Go repositories, marked

avelino/awesome-go 78 A- ollama/ollama 85 A golang/go 31 D kubernetes/kubernetes 72 B+ microsoft/TypeScript 82 A- fatedier/frp 96 A+

All Go repositories

Think this mark is wrong?

Every deduction above names the file it came from, so this can be settled by looking. If a check missed something, that is a rule worth fixing.

Open an issue, already filled in