Assesses an arbitrary open-source software repository through two lenses: the Digital Public Goods (DPG) Standard and the OpenSSF Concise Guide for Evaluating OSS, with additional emphasis on architecture and code evaluation. Evidence-first: makes no assumptions about forge, CI, security tooling or project structure, distinguishes "not found", "not evidenced", "observed absence" and "unknown", and produces OSS-ASSESSMENT.md without an overall score or recommendation. Does not modify the target repository.