SWE-AF

Autonomous software engineering fleet of AI agents for production-grade PRs on AgentField: plan, code, test, and ship.

Coding Agents Go Grade C Listed Apache-2.0
50.7/100
Rank #909 of 1328
Compare SWE-AF

How does it stack up against its Coding Agents neighbours?

Pick any agent to compare →

Thin or incomplete trust evidence. Review carefully before production use.

Open compare tool Suggest correction
Listing state
Listed
Evidence coverage
Grade C · 2/5 signals
Last push
2026-09-09 · 9d ago
Recent change
Grade Changed +7

Is SWE-AF safe? SWE-AF scores 50.7/100 (Grade C), ranked #909 of 1328 tracked open-source AI agent projects, on evidence coverage C (2 of 5 independent signal types). The public evidence: no package-provenance attestation found; OSSF Scorecard rates its supply-chain practices 3.6/10; 78% of recent commits are signed; last pushed 2026-09-09. Every point is earned from checkable signals — never paid placement. How scoring works →

Ranked neighbours in Coding Agents

Quick Trust Read

What Would Improve It
Publish package provenance or release attestations for stronger supply-chain evidence.
Recent Changes
2026-09-18
Grade Changed
Trust grade D → C
2026-09-18
Rank Moved
Rank rose 50 spots (#959 → #909)
2026-09-15
Rank Moved
Rank dropped 12 spots (#949 → #961)
Maintainer Checklist
Raise Scorecard signals Current OSSF Scorecard is 3.6/10. Tighten the weakest checks to improve public safety evidence.
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
64.2
Activity sub-score · out of 100
#54

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade C reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage C is separate — it grades how many independent signal types back the score (2 of 5), so a high score on thin evidence stays visible. Full methodology →

Signals refreshed 2026-09-18 13:03 UTC · Repo last pushed 9 days ago

Rank Trend

2026-08-11 2026-09-18

Activity & Reach

Stars
1.0k
Forks
173
Last Push
2026-09-09
9 days ago
Commits (4 wk)
8
Downloads (7d)
HN mentions (30d)
Open Issues
6
Rank Change
▲50
was #959

Analysis

HVTrust Dimensions vs Coding Agents

50.7 / 100 · 100.0% confidence

SWE-AF Coding Agents average (72 agents)

Safety / Integrity50% OSSF Scorecard · 30% provenance · 20% signed commits
8.4 / 25
0.6 below avg 9.0
Identity / Provenance60% listing status · 40% build provenance
10.8 / 18
1.0 below avg 11.8
Transparency50% declared license · 50% OSSF Scorecard
11.6 / 17
in line with avg 11.8
Maintenance60% last-push freshness · 40% commit activity
15.2 / 20
in line with avg 14.9
AdoptionLog-scaled stars · package downloads
7.2 / 20
5.0 below avg 12.2

Activity Inputs

64.2 / 100
StarsRepository reach
18.0 / 30
FreshnessLast push recency
23.8 / 25
ActivityRecent commits
11.9 / 25
CommunityFork signal
10.4 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
3.6 / 10
OpenSSF Scorecard · scanned Sep 15, 2026
Signed Commits
78%
of last 100 commits verified
Binary-Artifacts 2
Branch-Protection 6
CI-Tests 10
CII-Best-Practices 0
Code-Review 2
Contributors 6
Dangerous-Workflow 10
Dependency-Update-Tool 0
Fuzzing 0
License 10
Maintained 10
Packaging -1
Pinned-Dependencies 0
SAST 0
Security-Policy 4
Signed-Releases -1
Token-Permissions 0
Vulnerabilities 0

Is SWE-AF safe?

Public trust evidence for SWE-AF is thin: several supply-chain signals are missing or weak. This does not mean the project is unsafe — it means an outside observer cannot easily verify the usual integrity checks. Treat with extra scrutiny.
Does SWE-AF publish package provenance?
No published build provenance is currently detected for SWE-AF. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does SWE-AF have an OpenSSF Scorecard?
SWE-AF has an OpenSSF Scorecard score of 3.6/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is SWE-AF actively maintained?
Maintained. Last push was 9 days ago.
What license does SWE-AF use?
SWE-AF ships under Apache-2.0. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are SWE-AF's commits signed?
78% of the last 100 commits to SWE-AF are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

AI agent surface

MCP, providers, tool surface
Scored in HVTrust

These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →

MCP Server Support
None detected
No MCP server signal detected.
Detailed evidence is not shown in the public view.
External Service Dependencies
high confidence
4 detected
Public provider/service dependencies detected.
Credential signal: API keys or service config markers documented.
Tool / Plugin Surface
None detected
No clear plugin system or broad tool surface detected.
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
  • MCP signal live
  • External deps live
  • Tool / plugin surface live
  • Package provenance drift live
How this surface has changed

Detected changes to SWE-AF's runtime surface and supply-chain posture, from daily public-signal snapshots. A change here means our detectors see something different — a genuinely changed capability, or better evidence of an existing one.

2026-08-12
Tool Surface Changed
Detected tool/plugin surface changed: declared → none

Maintain SWE-AF?

For maintainers

HVTrust scores SWE-AF from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

Signal history
Rank 25Grade 3Listed 1Surface 1HVTrust 1Scorecard 1
2026-09-18
Grade Changed
Trust grade D → C
2026-09-18
Rank Moved
Rank rose 50 spots (#959 → #909)
2026-09-15
Rank Moved
Rank dropped 12 spots (#949 → #961)
2026-09-14
Grade Changed
Trust grade C → D
2026-09-14
Rank Moved
Rank dropped 46 spots (#903 → #949)
2026-09-13
Rank Moved
Rank dropped 33 spots (#870 → #903)
2026-09-12
Rank Moved
Rank dropped 12 spots (#858 → #870)
2026-09-11
Rank Moved
Rank dropped 10 spots (#848 → #858)
2026-09-09
Rank Moved
Rank rose 24 spots (#878 → #854)
2026-09-08
Rank Moved
Rank dropped 10 spots (#868 → #878)
2026-09-07
Rank Moved
Rank dropped 39 spots (#829 → #868)
2026-09-06
Rank Moved
Rank dropped 16 spots (#813 → #829)
2026-09-05
Rank Moved
Rank dropped 65 spots (#748 → #813)
2026-09-04
Rank Moved
Rank dropped 34 spots (#714 → #748)
2026-09-03
Rank Moved
Rank dropped 43 spots (#671 → #714)
2026-09-02
Rank Moved
Rank dropped 32 spots (#639 → #671)
2026-09-01
Rank Moved
Rank dropped 23 spots (#616 → #639)
2026-08-31
Rank Moved
Rank dropped 37 spots (#579 → #616)
2026-08-29
Rank Moved
Rank dropped 32 spots (#541 → #573)
2026-08-27
Rank Moved
Rank dropped 13 spots (#519 → #532)
2026-08-26
Scorecard Added
OSSF Scorecard: 3.8/10
2026-08-26
Grade Changed
Trust grade D → C
2026-08-26
Rank Moved
Rank rose 511 spots (#1030 → #519)
2026-08-26
HVTrust Changed
HVTrust up 31.2pts (20.9 → 52.1)
2026-08-19
Rank Moved
Rank dropped 10 spots (#1017 → #1027)
2026-08-17
Rank Moved
Rank rose 13 spots (#1032 → #1019)
2026-08-16
Rank Moved
Rank dropped 30 spots (#1002 → #1032)
2026-08-12
Tool Surface Changed
Detected tool/plugin surface changed: declared → none
2026-08-12
Rank Moved
Rank rose 27 spots (#1032 → #1005)
2026-08-10
Rank Moved
Rank dropped 46 spots (#978 → #1024)
2026-08-08
Rank Moved
Rank dropped 472 spots (#484 → #956)
2026-08-03
Newly Listed
First tracked at rank #447

Embed Badge Badge guide for maintainers →

For maintainers
HVTrust 50.7 Grade C
Markdown:
[![HVTrust](https://hvtracker.net/badge/swe-af.svg)](https://hvtracker.net/agents/swe-af)
HTML:
<a href="https://hvtracker.net/agents/swe-af"><img src="https://hvtracker.net/badge/swe-af.svg" alt="HVTrust"></a>

Other agents in Coding Agents

Data sources
GitHub REST API (repo, commits, stars, forks, license) · OpenSSF Scorecard CLI
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.3 · Raw JSON