Open-source developer from Mossoró, Rio Grande do Norte — Brazil. I build tools that keep repositories honest: driftcheck catches version drift between documentation and the files that actually build the project, taintrace catches typosquatted package names, and a family of small guardrails keeps generated changes inside the lines you drew.
448 merged PRs
— 394 in my own projects, 54 upstream across 32 repositories. Five tools are
on PyPI. driftcheck and aipr carry a -py suffix because the
PyPI names driftcheck and aipr are permanently taken by unrelated projects;
the import name and the command are unchanged in both cases.
| I want to… | Use |
|---|---|
| catch version drift before CI does | pip install driftcheck-py → driftcheck |
| catch typosquatted dependencies | pip install taintrace → taintrace |
| block out-of-scope changes to protected paths | pip install diff-contract → diff-contract |
| run only the CI tests a change actually affects | pip install ci-test-gate → ci-test-gate |
| check a repo's AI policy before contributing | pip install aipr-py → aipr |
| track token cost across agent runs | pip install git+https://github.com/yunaremaia/agentcost.git → agentcost |
| enforce bounded agent permissions | pip install git+https://github.com/yunaremaia/agent-guard.git → agent-guard |
| scan dependencies across ecosystems | pip install git+https://github.com/yunaremaia/depscan.git → depscan |
Every tool is MIT-licensed and runs on Python 3.10+.
driftcheck · 2404 tests
Your README promises Node 18, your package.json says 24, and a new contributor
discovers it as a build failure. driftcheck catches it in CI instead.
86 detector modules across Maven, Gradle, Terraform, CircleCI, GitLab CI, GitHub
Actions, Kubernetes, Helm, Docker Compose, Dependabot, .NET/C#, Taskfile, Rust
toolchain files, Go modules, npm/pnpm/yarn lockfiles, proto schemas, SPDX license
headers, dotfiles, .env, and the A2A agent protocol. --fix rewrites the
documentation side; --sarif emits SARIF 2.1.0 for GitHub code scanning.
2404 tests, green on Python 3.10–3.14 across Linux, macOS and Windows.
taintrace · 444 tests
reqeusts instead of requests is one character away from a malicious package.
Detects typosquat lookalikes across Cargo, Go, npm and PyPI before they reach a
lockfile.
A generated snippet with a hardcoded API key or an unparameterized query ships
before anyone reads it. vibeguard scans generated code for hardcoded secrets,
SQL injection, dangerous eval/exec and CORS wildcards before it ships.
Defects with an actual reproduction, not drive-by changes:
- apache/maka (5.7k⭐, agent runtime) — six merged PRs, including dropping a retired permission mode from the capability audit and classifying usage-limit failures as billing rather than auth.
- anchore/syft (9.6k⭐, SBOM generator) —
skip
docker://references in GitHub Actions PURL generation, which were producing malformed package URLs. - LMCache (11.9k⭐, KV-cache for inference) —
removed stale
gosecsuppressions once the connector adapters were clean. - oras-project/oras (2.5k⭐) — fixed a licenserc CI path resolved relative to the wrong directory.
- rancher/dashboard — IPv6 CIDR support in the network validator.
Plus merged work in MisakaNet, semantica, agent-safe-pipeline, Agentrace,
OpenMAIC, cratestack, neural-trees, tealtiger, Prism-platform, and others.
21 PRs open. The ones worth a maintainer's attention:
goreleaser/nfpm#1145— theipkpackager writes a rawos.FileInfo.Mode()into the tar header, so type bits likefs.ModeDiroverflow the octal field andarchive/tarsilently re-encodes that header as GNU base-256.apkgotnormalizeFileModein #1113;ipkwas left behind.anchore/syft#5373— keep same-name packages apart when resolving Python dependencies, so two distributions sharing a name no longer collidepypa/packaging#1437— merge a partial environment over defaults inselect(), instead of letting an empty field clear a declared onefastapi/typer#1970— skip hidden commands intyper utils docsoutput
Browse the full list.
Drift detection — the recurring theme. When a value is declared in two places,
something will eventually make them disagree, and the failure surfaces to a user as a
confusing build error instead of the configuration mismatch it actually is.
driftcheck (86 detectors), plus
a2a-drift — agent-card and spec-version compliance,
env-drift — .env files that disagree across environments,
license-drift — SPDX headers that do not match the
manifest, dotfiles-drift — the same setting committed
with two different values.
Supply-chain security — taintrace (typosquat detection
for Cargo/Go/npm/PyPI), depscan (multi-ecosystem vulnerability
scanning), ai-reputation-guard.
Guardrails for generated changes — the premise: a large diff is fine; a silent
out-of-scope one is not. diff-contract fails a run that
touches protected paths, aipr surfaces a repo's AI policy before you
build, agent-guard enforces bounded permissions at runtime,
vibeguard and mcp-guard scan
generated code and MCP servers, ai-reputation-guard scores
contributions that look low-effort.
CI intelligence — ci-test-gate (semantic test
selection), ci-sandbox (see what a pipeline would run
without running it), ci-gate-watch (declared branch
protection vs the protection actually set), gfi (good-first-issue
finder).
Agent observability — agentcost (token spend),
memwatch (memory rot detection),
context-bridge (session memory),
agent-undo (rollback),
agent-workspace (worktree isolation),
leanpipe (CLI output filtering),
acc-mcp (Agent Capability Contract enforcement at the
MCP gateway).
# Published on PyPI
pip install driftcheck-py # version drift across 86 detectors
pip install taintrace # typosquat detection
pip install diff-contract # diff guardrails
pip install ci-test-gate # semantic CI test selection
pip install aipr-py # AI contribution policy detectionEverything else installs from source. This is deliberate, not a gap: for
agentcost, agent-guard, depscan and the rest the short PyPI name belongs
to an unrelated project, so a pip install <name> would silently fetch someone
else's software. Install from Git so pip cannot resolve the wrong package:
pip install git+https://github.com/yunaremaia/agent-guard.git # agent permission policy
pip install git+https://github.com/yunaremaia/agentcost.git # LLM token cost tracking
pip install git+https://github.com/yunaremaia/depscan.git # multi-ecosystem scanningSource, issues and PRs live in the yunaremaia/* repos above.
Python Rust C++ Go TypeScript Mojo Bash · pytest · GitHub Actions · SARIF ·
SQLite · rapidfuzz · CLI-first, scriptable, no daemon
| Metric | Value |
|---|---|
| Merged PRs | 448 |
| — in my own projects | 394 |
| — upstream, across 32 repos | 54 |
| Own projects | 44 |
| Public repos | 167 |
| — of which forks of other people's work | 123 |
| Tests across featured tools | 2848+ |
| Packages on PyPI | 5 |
| Stars | 23 |
| Followers | 58 |
| Primary language | Python |
PRs are welcome in any repo above. Before you open one:
- Read the repo's
CONTRIBUTING.mdand any AI policy —aiprdetects those gates automatically - Issues labeled
good first issueare actively maintained — claim before starting - All public artifacts (PRs, commits, issues, comments) are in English
If this saves you time, you can support it:
- Solana / cbBTC:
Eeztv1nCYUt1fwGWpzKC948gaWfjejYCAuLtUMgzDWbW - Or collaborate — pick an open issue in a project above
- Email: [email protected]
- GitHub issues and PRs — fastest channel for anything project-related
- Operating agreement: inicio.md — public identity and contributor rules
Numbers verified against the GitHub API.



