agentreadme

Report · marked 25 Aug 2026

gchq/CyberChef

Solid foundations, held back in a few specific places.

JavaScript · 35,669 stars · 989 files · branch master

Fix these first

01
File sizes fit in context
A single file that fills the context window forces an agent to work from fragments, and it will confidently edit code it never saw. Splitting the worst offenders pays for itself immediately.
02
Environment config
Add a .env.example listing every variable with a safe placeholder value. It's the cheapest possible fix and it unblocks the whole first run.
03
Static type checking
A type checker gives an agent an error message instead of a runtime surprise. It's the second-fastest feedback loop after the compiler.

The full marking

Every deduction below names the file or setting it came from.

Instructions 26/27 A+

Whether the repo tells an agent how to behave before it starts guessing.

Agent instruction file 12/12
AGENTS.md is present, which is the format the most tools read.
Instruction quality 12/12
Specific enough that an agent can act on it.
3,678 characters, a workable length
names the actual commands to run
uses headings, so an agent can skim it
includes copyable code blocks
README as an entry point 2/3
README exists but never explains how to get the thing running.
Give the README an Install and a Usage heading with real commands under each. Agents pattern-match on those headings.
Setup 16/20 A-

Whether an agent can install the project and get it running without a human.

Deterministic install 6/6
package-lock.json pins the dependency tree.
Found package-lock.json
Discoverable commands 6/6
Commands are declared where an agent will look for them.
package.json scripts (start, build, node, repl, test, testnodeconsumer…)
Environment config 0/4
Nothing documents the environment this needs. An agent will get a runtime error it can't diagnose.
Add a .env.example listing every variable with a safe placeholder value. It's the cheapest possible fix and it unblocks the whole first run.
Pinned runtime version 2/2
The language runtime version is pinned.
Found .nvmrc
Reproducible environment 2/2
.devcontainer/devcontainer.json gives a known-good environment.
Verification loop 22/25 A

Whether an agent can check its own work. This is the category that most decides whether agent output is trustworthy.

Tests exist 8/8
235 test files against 884 source files.
e.g. tests/browser/00_nightwatch.js, tests/browser/01_io.js, tests/browser/02_ops.js
Test command is discoverable 7/7
An agent can find and run `npm run test`.
Continuous integration 4/4
5 GitHub Actions workflows define what "passing" means.
Lint and format rules 3/3
eslint.config.mjs encodes the house style.
Static type checking 0/3
No static type checking.
A type checker gives an agent an error message instead of a runtime surprise. It's the second-fastest feedback loop after the compiler.
Context economy 13/20 B

Whether the repo fits in a context window, or fights it.

No committed build output 6/6
No generated directories committed.
.gitignore hygiene 3/3
.gitignore covers 18 patterns.
File sizes fit in context 0/6
5 source files are over 100KB.
A single file that fills the context window forces an agent to work from fragments, and it will confidently edit code it never saw. Splitting the worst offenders pays for itself immediately.
src/core/lib/Magic.mjs — 553KB
tests/operations/tests/ParseQRCode.mjs — 256KB
tests/operations/tests/ParseTLSRecord.mjs — 117KB
Repository weight 4/5
About 98.1MB checked out, which is comfortable.

Here is your AGENTS.md

Drafted from what is actually in this repository: the install command from your lockfile, the commands you already declare, your real directory layout. Anything marked TODO needs a person. Save it at the root as AGENTS.md.

AGENTS.md — drafted for gchq/CyberChef
# AGENTS.md

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

## Setup

```
npm ci
```

## Commands

```
npm run start              # run the app
npm run build              # produce a build
npm run test               # run the test suite, must pass before any commit
npm run lint               # lint
npm run node
npm run repl
npm run testnodeconsumer
npm run testui
```

## Layout

- `src/`   649 source files
- `tests/` 230 source files

## Conventions

- Tests live alongside the code they cover, following `tests/browser/00_nightwatch.js`.
- CI defines what passing means. See `.github/workflows/cla-close-stale.yml`, and keep it green.
- TODO: add the two or three conventions a newcomer always gets wrong here.

## Gotchas

- `src/core/lib/Magic.mjs` is 553KB. It will not fit comfortably in context, so read it in parts.

---

Drafted by agentreadme.com from what is in this repository. Everything marked TODO
needs a human. Check it in as AGENTS.md at the root.

Open the raw markdown  or  curl -o AGENTS.md agentreadme.com/draft/gchq/CyberChef.md

Show the mark

The badge re-checks daily, so it keeps up as the repository changes. Use mark again to force it now.

agent ready 83 out of 100

[![agent ready](https://agentreadme.com/badge/gchq/CyberChef.svg)](https://agentreadme.com/gchq/CyberChef)

Other JavaScript repositories, marked

react/react 71 B+ affaan-m/ECC 90 A trekhleb/javascript-algorithms 69 B Snailclimb/JavaGuide 53 C+ airbnb/javascript 54 C+ vercel/next.js 77 B+

All JavaScript repositories

Think this mark is wrong?

Every deduction above names the file it came from, so this can be settled by looking. If a check missed something, that is a rule worth fixing.

Open an issue, already filled in