Skip to content
SYBERLABS

HOW WE BUILD

Read the source, not the memory.

Our coding agents look up open-source dependencies at the exact version a project uses, through GitHits, a third-party index of public code. This page says what is wired up, what leaves our machines, and how far each piece has got.

WHY

A model remembers a blend of versions.

A language model learns a library from whatever releases were public when it was trained. Asked about a dependency, it answers from that blend: a function renamed two releases ago, an option that exists only on the main branch, an advisory published after its cutoff. The answer reads well and fails against the version in the lockfile.

Reading the source at the pinned version settles the question. GitHits indexes public open-source code, documentation, package metadata, vulnerabilities and changelogs by version, and serves them over MCP, a command-line tool and a REST API. An agent can read the release the lockfile names instead of recalling one.

WHAT WE WIRE UP

One index, two places.

01 / AGENTS

MCP in our repositories

The GitHits MCP server is configured in SyberLabs repositories, so coding agents such as Claude Code can search and read dependency source, docs and changelogs at a named version, and check vulnerabilities and changelogs before a dependency is bumped.

02 / THIS SITE

Dependency panels at build time

Each project page carries a dependency panel generated from GitHits’ package API (api.githits.dev/v1) when the site is built: license, latest version and known vulnerabilities for the packages the project declares. Only fields GitHits returned are shown. Where no snapshot has been fetched yet, the panel says so.

SETUP

The exact commands.

On a developer machine, one command detects the installed coding agents, configures GitHits for them and signs in. Sign-in is OAuth in the browser, and the token is kept in the system keychain.

npx githits@latest init

A repository can also register the hosted server for every agent that opens it, in .mcp.json; the first use asks for sign-in.

{ "mcpServers": { "githits": { "type": "http", "url": "https://mcp.githits.com" } } }

In CI and other headless runs there is no browser. An API token is stored as the repository secret GITHITS_API_TOKEN and exposed to the job as an environment variable. It is never committed or written to a file, and the build still succeeds without it.

# CI: token from the GitHits settings page, stored as a secret
env:
  GITHITS_API_TOKEN: ${{ secrets.GITHITS_API_TOKEN }}

# confirm the token is picked up
npx githits@latest auth status

Commands from the GitHits documentation as of 8 October 2026.

WHAT LEAVES OUR MACHINES

Public names go out. Private code stays.

  • Build-time panels. The requests carry public package names and versions read from each project’s manifests. Nothing else from our repositories is sent.
  • Agents over MCP. A request carries the agent’s query and any context the agent puts in it. GitHits states that signing in gives it no access to private repositories and that it does not access, index, search or store private repository code; the agent keeps working on the local checkout. Because the agent writes the query, our repositories instruct it to name public packages, versions and APIs and never to send unpublished code, content, tokens, secrets or personal data. GitHits’ own docs give the same rule.
  • Retention. Per GitHits’ privacy policy, queries and outputs are kept for 90 days and MCP and API request logs for 30 days, and training on inputs is off unless a user opts in. Their policy governs; this is a summary as of 8 October 2026.

EVIDENCE

Where each piece stands.

  • Implemented

    GitHits MCP configured for coding agents in RISE, OmniOS, SyberWork, MasterMind and this site’s repository, with instructions on what may be sent.

  • Implemented

    Build-time dependency snapshot from GitHits’ package API and the panel on each project page that reads it.

  • Not yet

    No named test covers either piece, and nothing has been measured. We make no claim that agents are faster or make fewer mistakes with GitHits.

Reflects this site and those repositories as of 8 October 2026. Each state is earned by code, a named test, a measurement under stated conditions, or a deployment; none is promoted by wording.

ABOUT GITHITS

A third-party tool, named to say what we use.

GitHits is a product of its own makers. It has not reviewed or endorsed this page, and SyberLabs has no partnership with it. Its home is githits.com and its documentation is at docs.githits.com.