Mantyl.devHosted passport
digest 1c26942a78d41723Mantyl Verified · independently re-executed
Mantyl · Project passport1abb1a4 · 2026-09-04
Projectmantyl-monorepo
Issued2026-09-04
Stacktypescript, node
Commit1abb1a4
Checks5 / 5 passed
Unknowns10 surfaced
01Verification (5/5 passed)
02Architecture
03Decisions (20)
04Claims (0 · 0 contradicted)
05Risks & unknowns (10)
06Setup & environment (23 vars)
P<MANTYL<MANTYL<MONOREPO<<<<<<<<<<<<<<<<<<<<<1C26942A78D4<5OF5PASSED<20DECISIONS<<<<<<<<<<
§ 01

Verification

+corepack enable && pnpm install --frozen-lockfilepassed (exit 0) · 12s
+corepack enable && pnpm run buildpassed (exit 0) · 35s
+corepack enable && pnpm run typecheckpassed (exit 0) · 23s
+corepack enable && pnpm run testpassed (exit 0) · 30s
+corepack enable && pnpm run lintpassed (exit 0) · 6s
§ 02

Architecture

Inferred

Mantyl is a pnpm/TypeScript monorepo implementing a "software handover" tool: it inspects a repository, collects coding-agent history and verification evidence, and renders a signed "project passport" for a new owner. The design is intentionally modular — packages/schema defines the passport contract, packages/core (the largest package, 36 files) implements workflows and run context, and a set of small satellite packages handle collection (collectors-git, collectors-repository), agent adapters (adapter-claude-code, adapter-codex, adapter-cursor), policy/config, evidence reconciliation, sandboxed verification (runner-docker, verifier-node), cryptographic signing/attestation (signing), and output rendering (renderer-html, renderer-markdown). Most of these satellite packages contain only a handful of files (package.json + src + a single test), suggesting either a clean minimal design or still-early implementation depth, in contrast to the much larger core package. Consumer-facing surfaces are apps/cli (the primary product, packaged as a local tarball), apps/web (a much larger, 171-file Next.js 16 marketing/hosted-passport site), and apps/worker (a small serverless-style worker). Two integration points exist for Claude Code: a dedicated adapter package and a separate integrations/claude-code-plugin. Architecture decisions are documented via ADRs, notably choosing Whop over Stripe for payments and running the worker as a serverless process on GitHub Actions rather than a dedicated server. CI is defined through three GitHub Actions workflows (build/test, IndexNow SEO pinging, and a passport-action smoke test), and the repo has scripts to scan and sync a "public" subset of the CLI. The working tree is clean at HEAD 1abb1a4, dependencies are pnpm-locked, and root scripts cover build/lint/test/typecheck. Several environment variables reveal the operational shape of the system: documented ones cover Anthropic API access, Vercel blob storage, GitHub dispatch, Mantyl API/worker tokens, signing keys, and Whop payment integration, while a second, security-relevant set (MANTYL_ATTEST_PRIVATE_KEY, MANTYL_ATTEST_PUBLIC_KEY, MANTYL_CI_TOKEN) is referenced in code but not documented anywhere. Locally, the web app has been writing ad hoc JSON files under .agency-waitlist and .passport-store directories that are not committed to the repository — local runtime state rather than delivered application data. The README references examples/, poc-static/, and launch/ directories that were deliberately excluded from this scan, so their presence and contents in the actual repository are unverified here.

cliapps/cliRepo
webapps/webRepo
workerapps/workerRepo
adapter-claude-codepackages/adapter-claude-codeRepo
adapter-codexpackages/adapter-codexRepo
adapter-cursorpackages/adapter-cursorRepo
collectors-gitpackages/collectors-gitRepo
collectors-repositorypackages/collectors-repositoryRepo
configpackages/configRepo
corepackages/coreRepo
evidencepackages/evidenceRepo
policypackages/policyRepo
renderer-htmlpackages/renderer-htmlRepo
renderer-markdownpackages/renderer-markdownRepo
runner-dockerpackages/runner-dockerRepo
schemapackages/schemaRepo
signingpackages/signingRepo
verifier-nodepackages/verifier-nodeRepo
§ 03

Decisions

I want to create a really strong landing page that has a top tier design system and clearly communicates the idea

2026-07-15Creator

I want this to be built with next so if I build it our properly the SEO is great from the start

2026-07-15Creator

I want to commit this to my github account, private repo and not on any of the organisations im a part of please make sure it just ends up o

I want to commit this to my github account, private repo and not on any of the organisations im a part of please make sure it just ends up on my account only

2026-07-16Creator

I want this to be top tier and not something that's been done before, the overall idea is to allow picking up and verification of AI project

I want this to be top tier and not something that's been done before, the overall idea is to allow picking up and verification of AI projects between developers and clients and potentially shari

2026-07-21Creator

lets use opus or a cost efficient model to do the analysis with

2026-07-22Creator

I want to bench the productisation for the time being and get the core idea & product fully built and not beind a literal payawall yet

2026-07-23Creator

I want to launch through sites like product hunt and then sync some money into marketing and see what happens, organic socials isn't an opti

I want to launch through sites like product hunt and then sync some money into marketing and see what happens, organic socials isn't an option for this product

2026-08-18Creator

I want to make use of which allows you to create ad creative via AI and get started proving product on their application really quickly

2026-08-26Creator

I want to work on a landing page uplift, where we create a PRD based on these website refernces and anaalyse the sales tactics, pshycology a

I want to work on a landing page uplift, where we create a PRD based on these website refernces and anaalyse the sales tactics, pshycology and layout

2026-08-26Creator

I want to put together a producthunt launch pack, including creative assets that we can use as imagery for Mantyl, can you help me put toget

I want to put together a producthunt launch pack, including creative assets that we can use as imagery for Mantyl, can you help me put together all of the info required and images, we can t

2026-08-28Creator

I want to take it step by step $100 each time, test and iterate each time based on the data we get back

2026-08-28Creator

I want to ensure that we have full SEO compatibility including indexing and content guides, we also need to set-up a proper tracking layer f

I want to ensure that we have full SEO compatibility including indexing and content guides, we also need to set-up a proper tracking layer for the ads

2026-08-28Creator

I want to ensure that once we start ads UX is good across the board and we are immediatley providing value

2026-08-28Creator

I want to use the Whop CLI to put together the first campaign we run, including generating the static content that we show please

2026-08-28Creator

I want to set a pixel for GA4 as that's how anaylitcs are tracked in Whop and I want to keep everything to one platform to make things easie

I want to set a pixel for GA4 as that's how anaylitcs are tracked in Whop and I want to keep everything to one platform to make things easier

2026-08-28Creator

I want to run an A-B test of this skill Iv'e found that is meant to make the site look less AI

2026-08-28Creator

I want to do a full SEO review of this website, where we do some research of any relevant competitors in the space and create a full PRD to

I want to do a full SEO review of this website, where we do some research of any relevant competitors in the space and create a full PRD to get us to that level of SEO implementation techin

2026-08-29Creator

I want to do a deep dive and figure out where we can take this next and keep building on

2026-08-31Creator

I want to gain a full understanding, the potential impact of each addition and once we are happy and agreed on a route forward we can create

I want to gain a full understanding, the potential impact of each addition and once we are happy and agreed on a route forward we can create a PRD for the next steps

2026-08-31Creator

I want to have phase two fully locally developed before we push this live

2026-09-04Creator
§ 04

Claims

None recorded.

§ 05

Risks & unknowns

~GITHUB_OUTPUT is required but undocumented — the next owner will discover it at runtimemedium · repo
~GITHUB_STEP_SUMMARY is required but undocumented — the next owner will discover it at runtimemedium · repo
~MANTYL_ATTEST_PRIVATE_KEY is required but undocumented — the next owner will discover it at runtimemedium · repo
~MANTYL_ATTEST_PUBLIC_KEY is required but undocumented — the next owner will discover it at runtimemedium · repo
~MANTYL_CI_TOKEN is required but undocumented — the next owner will discover it at runtimemedium · repo
!Signing/attestation and CI-auth environment variables (MANTYL_ATTEST_PRIVATE_KEY, MANTYL_ATTEST_PUBLIC_KEY, MANTYL_CI_TOKEN) are referenced in code but have no documentation, unlike the sibling MANTYL_SIGNING_* keys which are documented — an inheriting engineer may not know how to provision or rotate these secrets, and the passport's cryptographic trust chain depends on them. (basis: factStatements list these three variables as 'referenced but NOT documented', in a project whose stated purpose is producing signed/attested passports (packages/signing, docs on 8-state truth model).)high · inferred
~The worker (apps/worker) runs as a serverless process on GitHub Actions per ADR 0002, an unconventional infrastructure choice compared to a dedicated server or standard serverless platform, which may carry hidden constraints (execution time limits, queueing, cold-start behavior, coupling to GitHub's availability) not obvious to a new maintainer. (basis: docs/adr/0002-serverless-worker-on-github-actions.md is present, and apps/worker is a small (8-file) app relative to the rest of the system.)medium · inferred
~Most modular packages (adapters, collectors, evidence, policy, config, renderers, runner-docker, verifier-node) contain only ~4-5 files each, in sharp contrast to packages/core's 36 files, suggesting these components may be thin stubs rather than fully-built implementations despite being architecturally central to the passport pipeline. (basis: directories listing shows most packages at 4-5 files versus packages/core at 36 files, with the README describing all of them as core components of the evidence/verification pipeline.)medium · inferred
~The web app is writing operational data (waitlist entries, passport store entries) as loose JSON files on local disk rather than to a committed or clearly defined persistence layer, and these files are untracked/local-only — if this pattern extends to production, it implies no durable, shared datastore for these features. (basis: untrackedPaths include apps/web/.agency-waitlist/*.json and apps/web/.passport-store/*.json, which are local-disk JSON files not part of the delivered repository.)medium · inferred
~A payment-vendor decision (Whop over Stripe) and an associated set of Whop-specific environment variables are baked into the architecture; switching payment providers later would touch multiple documented env vars and whatever integration code depends on them. (basis: docs/adr/0001-whop-over-stripe.md exists, and WHOP_ACCOUNT_ID, WHOP_API_BASE, WHOP_API_KEY, WHOP_ENV, WHOP_WEBHOOK_SECRET are all documented environment variables.)low · inferred
§ 06

Setup & environment

corepack enable && pnpm install --frozen-lockfileVerified
corepack enable && pnpm run buildVerified
ANTHROPIC_API_KEYdocumentedDocumented
APPDATAdocumentedDocumented
BLOB_READ_WRITE_TOKENdocumentedDocumented
GITHUB_DISPATCH_TOKENdocumentedDocumented
GITHUB_OUTPUTNOT documentedUndocumented
GITHUB_STEP_SUMMARYNOT documentedUndocumented
MANTYL_APIdocumentedDocumented
MANTYL_ATTEST_PRIVATE_KEYNOT documentedUndocumented
MANTYL_ATTEST_PUBLIC_KEYNOT documentedUndocumented
MANTYL_CI_TOKENNOT documentedUndocumented
MANTYL_SIGNING_PRIVATE_KEYdocumentedDocumented
MANTYL_SIGNING_PUBLIC_KEYdocumentedDocumented
MANTYL_TOKENdocumentedDocumented
MANTYL_WORKER_TOKENdocumentedDocumented
NEXT_PUBLIC_GA_IDdocumentedDocumented
NODE_ENVdocumentedDocumented
VERCELdocumentedDocumented
VERCEL_PROJECT_PRODUCTION_URLdocumentedDocumented
WHOP_ACCOUNT_IDdocumentedDocumented
WHOP_API_BASEdocumentedDocumented
WHOP_API_KEYdocumentedDocumented
WHOP_ENVdocumentedDocumented
WHOP_WEBHOOK_SECRETdocumentedDocumented
§ 07

Link to this passport

The badge renders this passport’s live status and links back here, so a delivered repository’s README carries its own proof. It states only what the passport can show: signal yellow appears when an independent verification is signed, and never otherwise.

Mantyl passport badge