# The Five-Minute Repo Check

From Distru's No Bullshit AI Course, module 02 lesson 03. Print it, or keep it open next to GitHub. Five questions, in order. Stop at the first bad answer and move to the next candidate. Last verified: September 2026. License: CC0.

## The card

| # | Question | Where to look | Pass | Walk |
|---|---|---|---|---|
| 1 | When was it last touched? | The date next to the newest commit, top of the file list | Within the last 12 months | Older than a year for anything that talks to an AI model or an API; those move fast |
| 2 | Does anyone answer? | The Issues tab. Open a few closed ones | The owner replies, even with "no" | Dozens of open issues, no owner replies, or Issues switched off |
| 3 | Are you allowed to use it? | A `LICENSE` file in the root, or the license badge in the sidebar | MIT, Apache-2.0, BSD, CC0, MPL | No license file (that means all rights reserved), or "non-commercial only" |
| 4 | What does it ask for? | README setup section, `.env.example`, config files | Read-only keys, your own machine or server | Your Metrc or ERP key sent to someone else's server; admin rights; curl-piped-to-shell installs |
| 5 | Does it run in ten minutes? | README install steps, top to bottom | You get one real output from your own data | No install steps, or step 3 fails and nobody has filed the same failure |

Stars are a weak signal. A repo with 40 stars and an owner who answered an issue last week beats one with 4,000 stars and silence since 2024.

## The same five, on the command line

```bash
gh repo view owner/name                       # description, license, stars, last push
gh repo view owner/name --json pushedAt,licenseInfo,isArchived
gh issue list -R owner/name --state open -L 20
git clone --depth 1 https://github.com/owner/name && cd name
git log -1 --format='%cd %s'                  # last commit date and message
grep -rn --include='*.md' --include='*.sh' --include='*.json' -E 'curl[^|]*\|\s*(ba)?sh' .   # pipe-to-shell installs
grep -rn -iE 'api[_-]?key|secret|token' .env.example README.md 2>/dev/null       # what it wants from you
cat package.json | python3 -c 'import json,sys; p=json.load(sys.stdin); print(p.get("scripts",{}).get("postinstall")); print(len(p.get("dependencies",{})), "deps")'
```

A `postinstall` script that downloads or executes anything is a stop, not a warning.

## Saved searches

Paste into the GitHub search box. Change the date each quarter.

```text
metrc pushed:>2025-09-01
cannabis topic:api pushed:>2025-09-01 license:mit
metrc language:python pushed:>2025-09-01
"model context protocol" cannabis
n8n metrc
```

GitHub qualifiers used: `pushed:>YYYY-MM-DD`, `topic:`, `license:`, `language:`, `stars:>=n`. Reference: https://docs.github.com/en/search-github/searching-on-github/searching-for-repositories

Other places, in the order we check them:

| Place | URL | What lives there |
|---|---|---|
| This course's giveaways | /giveaways/ | Cannabis-specific skills, prompts, n8n flows, sheets. Tested. |
| n8n template library | https://n8n.io/workflows/ | Ready-made workflows. Search the boring part of your job (Gmail to Sheet, CSV to Slack), not "cannabis". |
| Skill directories | https://skills.sh | Skills for coding agents; install with `npx skills add owner/repo`. Read the SKILL.md before you install. |
| Official MCP registry | https://registry.modelcontextprotocol.io | MCP servers by name. Check the publisher and what scopes the server asks for. |
| GitHub | https://github.com/search?type=repositories | Everything else. Use the saved searches above. |

## Asking an AI to search for you

Paste this into a chat tool with web search switched on. Then open every link yourself; models invent repositories that do not exist.

```text
I run a cannabis [dispensary / cultivation / distribution] business. I want an existing
open-source tool, n8n template, skill or MCP server that does: [one sentence].

Search the web. List up to five real candidates. For each give: the exact URL, the date
of the last commit or update, the license, what credentials or access it asks for, and
one sentence on what I would have to change for my case. If you cannot verify a URL,
say so instead of guessing. Do not invent projects.
```
