What it does
One format, two readers. People and AI agents now co-write the same document. Legible for people; addressable, verifiable, and versioned for machines. GEML is plain text — organized by one typed block for everything, remembered by a .gemlhistory sidecar.
Installation
dsh plugin --profile web add gemlInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
86e3e2479d2a2026-08-1786e3e2479d2aThe scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
• Static heuristic scan: done (15 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Scan findings · 3
- infoReads process.env.claude/hooks/inject-instructions.mjs:15const root = process.env.CLAUDE_PROJECT_DIR || process.cwd();
- infoMakes network requests (fetch / axios)playground/entry.js:37const res = await fetch(url, { cache: "no-cache" });
- infoMakes network requests (fetch / axios)playground/entry.js:56const res = await fetch(rel, { cache: "no-cache" });
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-17 · activity: Active
• Repo created: 2026-08-17
• Stars: ★ 24 · Forks: 0
• Health: Active — committed within last 30 days
Source
GitHub: github.com/geml-spec/geml
