bundle-bracket-pr — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited bundle-bracket-pr (Rules) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Live scores for the 2026 men's football tournament — in your terminal, your Claude Code / Cursor CLI statusline, and any MCP client. No API key, no signup; all 104 fixtures ship bundled, so the schedule works offline.
<p align="center"> <img src=".github/assets/hero.gif" alt="A Claude Code statusline flipping to a live World Cup score — South Korea 2–1 Czechia — while tests run in the terminal" width="800"> </p> <!-- HERO: real live-match capture from the Jun 11 opener — the statusline flips to South Korea's 81st-minute winner (1–1 → 2–1) while pytest runs. -->
npx @claudinho/cli today # try it in 10 seconds — no install, no key
npx @claudinho/cli live # what's on right now (during match windows)While matches are live, your Claude Code or Cursor CLI statusline reads:
⚽ 🇳🇴 1–1 🇫🇷 87' · 🇸🇳 1–2 🇮🇶 86'And claudinho share prints a card made for the group chat:
<!-- DEMO CARD: verbatim output of claudinho share table A. Chosen over a single match card because it has no fixed date to go stale (a played-and-passed fixture reads as abandoned). Standings still drift across matchdays — REGENERATE periodically, especially before any conversion-sensitive moment. Never hand-edit. -->
Group A · standings
1. 🇲🇽 MEX 6 pts · 2-0-0 · +3
2. 🇰🇷 KOR 3 pts · 1-0-1 · 0
3. 🇨🇿 CZE 1 pts · 0-1-1 · -1
4. 🇿🇦 RSA 1 pts · 0-1-1 · -2
Live data: ESPN
#VibingLaVidaLoca · Independent fan project · not affiliated with FIFA or Anthropic.
Try it: npx @claudinho/cli table A⚠️ Not affiliated with, endorsed by, or connected to FIFA or Anthropic. Claudinho is an independent, open-source fan project. It displays factual match data (scores, fixtures, standings) and uses emoji flags only — no logos, emblems, kits, broadcast footage, or player likenesses.
npm i -g @claudinho/cli
claudinho today
claudinho next MEX --tz America/Mexico_City --lang esOne command wires the live-score statusline and prints the MCP config to paste:
npm i -g @claudinho/cli
claudinho init cursor # statusline → ~/.cursor/cli-config.json (+ the MCP paste)<p align="center"> <img src=".github/assets/cursor-cli-statusline.png" alt="A live World Cup score in a Cursor CLI statusline — Uzbekistan 0–1 Colombia, 42' — with a model and context line below it" width="520"> </p>
Restart your agent session to see it. Prefer to paste it yourself? claudinho init cursor --print emits the snippets, or copy them straight from here:
Statusline — ~/.cursor/cli-config.json:
{
"statusLine": {
"type": "command",
"command": "claudinho prompt",
"padding": 0,
"updateIntervalMs": 1000,
"timeoutMs": 1500
}
}MCP tools — ~/.cursor/mcp.json (global) or a project .cursor/mcp.json:
{ "mcpServers": { "claudinho": { "command": "npx", "args": ["-y", "@claudinho/mcp"] } } }Optional env — a model + context line below the score, or scope to your team:
export CLAUDINHO_CURSOR_META=auto # model + context % line under the score (recommended)
export CLAUDINHO_TEAM=MEX # show only your team's match
export CLAUDINHO_FLAGS=off # 3-letter codes instead of flag emoji (already automatic in Warp)Note: Cursor's beforeSubmitPrompt hook doesn't yet reliably inject context into the model, so the score-aware hook stays Claude Code-only for now — the statusline and MCP server work great in Cursor.npm i -g @claudinho/cli
claudinho init claude # statusline + live-score hook, then the MCP one-linerinit claude backs up ~/.claude/settings.json first and is idempotent. Prefer the pieces à la carte? Run init-statusline, init-hook, and:
claude mcp add claudinho -- npx -y @claudinho/mcpRestart Claude Code to activate.
Monorepo / local dev? Theinit cursor/init claudealiases wire the globalclaudinho. To point a statusline or hook at a local build, use the granular commands with--command, e.g.claudinho init-cursor-statusline --command "node ./packages/cli/dist/index.js prompt"(andinit-statusline/init-hookfor Claude Code).
codex mcp add claudinho -- npx -y @claudinho/mcp # Codex CLIEverything else takes the standard stdio config:
{ "mcpServers": { "claudinho": { "command": "npx", "args": ["-y", "@claudinho/mcp"] } } }today, live, next MEX, table, match <id>, bracket, markets, share (and vibe 😎). --json on everything; TZ-aware via --tz.claudinho init claude / claudinho init cursor (also tmux & Starship via claudinho prompt).UserPromptSubmit hook that drops the live score into the model's context during matches; zero tokens off-match. (Cursor parity pending — its hook can't reliably inject context yet.)get_today, get_live, get_match, get_next_fixture, get_standings, get_bracket, get_market_signal, get_share_snippet) plus my_team / tournament_today prompts.--no-markets / CLAUDINHO_MARKETS=off.claudinho share next MEX --copy puts a plain-text match card on your clipboard; claudinho share table A does the same for a group's live standings; claudinho share bracket for the knockout tree.Speaks en / es / pt / fr, with optional localized commentary flair (¡GOOOOL!) — dial it down with --flavor subtle|off.
_Planned (not shipped yet):_ a desktop notifier and an AI pundit with a public accuracy scorecard.
Do I need an API key or account? No. Nothing to sign up for; npx and done.
Does it work offline? The schedule, next, group skeletons, and knockout bracket structure do — all 104 fixtures are bundled. Only live scores hit the network.
Where does the data come from? Live scores from ESPN's public scoreboard (attributed in output as Live data: ESPN); market signals from Polymarket public data. Rate limits respected.
Is the market line betting advice? No. It's read-only, informational-only market data with attribution — no trading, no links — and it never appears on the statusline or hook.
Why no crests, kits, or player photos? Legal-clean by design: facts and emoji flags only.
Flags show as boxed letters (`CH`, `BA`)? Some terminals — notably Warp — don't compose the regional-indicator pairs into flag glyphs, so 🇨🇭 renders as a boxed CH. claudinho auto-detects Warp and drops the flags: 3-letter codes on the statusline (MEX 1–0 RSA 67') and plain team names in the hook, today / live / table, and next. Force it anywhere with CLAUDINHO_FLAGS=off, or keep flags with CLAUDINHO_FLAGS=on.
Windows? Works, but flag emoji rendering varies by terminal — best on macOS/Linux. See the flags note above; CLAUDINHO_FLAGS=off gives clean codes on any terminal that can't render them.
MIT © 2026 Arturo Garrido. All three packages publish with npm provenance via OIDC trusted publishing.
_Built while watching the games._ #VibingLaVidaLoca ⚽
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.