# khoj-ai/khoj - passport

khoj-ai/khoj: Passed: Source link matches (PyPI:khoj@1.42.10); Refused: No known advisories for this version (last checked 2026-10-11). Not yet checked (not a failure): License file read, MCP tool list hashed, Setup recipe reproduced, Publisher manifest read, Publisher domain checked, OpenSSF Scorecard read, Reviewed by an independent person, Reviewed by a peer agent of a different owner.

## Stamps (passed, refused or changed)

- \[REFUSED\] No known advisories for this version (advisory-clean), version: PyPI:khoj@1.42.10, checked 2026-10-11: Refused: A published advisory affects the current release PyPI:khoj@1.42.10 (GHSA-6whj-7qmg-86qj, PYSEC-2026-1491). (2026-10-11) (<https://karmadue.expo.app/standards#advisory-clean>)
- \[PASSED\] Source link matches (provenance-linked), version: PyPI:khoj@1.42.10, checked 2026-10-11, issued 2026-10-11T14:33, expires 2026-11-10, by KarmaDue check (build-provenance@1): Signed build record for PyPI:khoj@1.42.10 names https://github.com/khoj-ai/khoj at commit a6fe2d2. Sigstore signature verified by deps.dev (Google Open Source Insights), not by KarmaDue. (<https://karmadue.expo.app/standards#provenance-linked>)

## Not yet checked (not a failure)

- License file read (license-checked) (<https://karmadue.expo.app/standards#license-checked>)
- MCP tool list hashed (schema-disclosed) (<https://karmadue.expo.app/standards#schema-disclosed>)
- Setup recipe reproduced (recipe-reproduced) (<https://karmadue.expo.app/standards#recipe-reproduced>)
- Publisher manifest read (manifest-declared) (<https://karmadue.expo.app/standards#manifest-declared>)
- Publisher domain checked (publisher-domain-verified) (<https://karmadue.expo.app/standards#publisher-domain-verified>)
- OpenSSF Scorecard read (openssf-scorecard-read) (<https://karmadue.expo.app/standards#openssf-scorecard-read>)
- Reviewed by an independent person (human-reviewed) (<https://karmadue.expo.app/standards#human-reviewed>)
- Reviewed by a peer agent of a different owner (peer-reviewed) (<https://karmadue.expo.app/standards#peer-reviewed>)

## Identity

- current version: PyPI:khoj@1.42.10 (current release, read from the package registry 2026-10-11; stamps bind to this)
- listed as: master (catalog listing)
- package: PyPI:khoj@1.42.10
- type: github\_repo
- license: AGPL-3.0
- locator: https://github.com/khoj-ai/khoj
- website: https://khoj.dev
- publisher: {"name": "github:khoj-ai; pypi:debanjum singh solanky, saba imran", "basis": "Upstream owner and maintainers read on 2026-10-11 (GitHub owner, npm or PyPI maintainers)."}
- resource id: kd:res:github:khoj-ai/khoj
- source repo: https://github.com/khoj-ai/khoj

## History

- 2026-10-11 stamp.refusal\_withdrawn advisory-clean: listed\_version\_affected
- 2026-10-11 stamp.refused advisory-clean: listed\_version\_affected
- 2026-10-11 stamp.issued provenance-linked
- 2026-10-11 stamp.corrected provenance-linked: issued\_at was the evidence time, not the signing time
- 2026-10-11 stamp.refused advisory-clean: listed\_version\_affected
- 2026-10-11 stamp.issued provenance-linked

## Check it yourself

- Signed statement (kd-subject-passport-v1): 6AZj4BJM8SstaA8MQqupefZR4927OtnMmAGCXKx5Wle\_hMtSBR8BSiZTTuW40gmBH2sjB6aQTi-nN0tdTF97BA
- JSON: GET https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/public-api/v1/passport/kd:res:github:khoj-ai/khoj (<https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/public-api/v1/passport/kd:res:github:khoj-ai/khoj>)
- Standards for every stamp: https://karmadue.expo.app/standards (<https://karmadue.expo.app/standards>)
- Signing key kd-passport-1: https://karmadue.expo.app/.well-known/jwks.json (<https://karmadue.expo.app/.well-known/jwks.json>)
- A passport lists what was checked, for which version, and when. A stamp is a dated record of one check: not an endorsement and not a safety guarantee.

---

Page: https://karmadue.expo.app/passport/kd:res:github:khoj-ai/khoj
Markdown: https://karmadue.expo.app/passport/kd:res:github:khoj-ai/khoj.md
Interactive view: https://karmadue.expo.app/resource?id=kd:res:github:khoj-ai/khoj
Any HTTP client (no bot checks): https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/docs/passport/kd:res:github:khoj-ai/khoj.md

KarmaDue keeps passports for AI agents and the tools they use: signed, dated records of what was checked. MCP: https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/mcp · Guide: https://karmadue.expo.app/llms.txt
