Local-first, profile-level AI collaboration analytics for GitHub: aggregate explicit AI provenance across repositories into privacy-safe SVG/JSON README assets.
Project description
ai-profile
English · 繁體中文
Local-first, profile-level AI collaboration analytics for your GitHub
README. aiprofile scans your local Git repositories for explicit AI
provenance — AI-* commit trailers and known AI co-author trailers (Claude
Code, Codex, Cursor, Copilot, Aider, …) — normalizes it into a common event
schema (ACE), stores it in a local SQLite database, and renders privacy-safe
SVG cards + a JSON summary you can embed in a GitHub Profile README.
What it looks like
Samples rendered from a synthetic showcase fixture; no real repository data. The heatmap is the view no other tool draws: intensity is your whole commit rhythm (your own commits included), hue is how much of each day was AI collaboration.
It is not an AI code detector: nothing is ever inferred from code style.
Commits without explicit evidence are honestly reported as unknown —
never silently counted as human, never guessed into a provider.
As far as we know it is the only free, local-first, cross-repository, explicit-provenance profile aggregation tool (line-level attribution belongs to tools like git-ai; full analysis: landscape & positioning).
Status: v0.3 — the v0.1 vertical slice (one repo → trailers → SQLite →
aggregate → summary card) plus provider brand identity (15 marks, two
icon sources), the publishable-only isometric daily calendar, and the
collaboration-ratio heatmap + badge. Design docs live in
docs/:
architecture · ACE schema ·
MVP boundary · landscape & non-duplication
· decision records.
Install
Compatibility: Python 3.11–3.14 · git ≥ 2.17 · SHA-1 repositories (SHA-256 object format fails with a clear error in v0.1) · Windows, macOS, Linux. Zero runtime dependencies.
pip install git+https://github.com/WenyuChiou/ai-profile
The PyPI package will be ai-profile-cli (upload in progress;
PyPI's name-similarity rule blocks ai-profile because an unrelated
project already holds aiprofile — and pip install aiprofile gets
you that other project, not this one). Once live:
pip install ai-profile-cli.
From a clone (development):
pip install -e ".[dev]" # dev extras = pytest + ruff + hypothesis
Quickstart
aiprofile init # run from INSIDE one of your repos - seeds your
# identity from that repo's git config user.email
aiprofile scan ~/my/repo # register + scan (replace with a real path;
# private-safe default)
aiprofile aggregate # print the published stats = privacy preview
aiprofile render # write dist/: summary + heatmap + badge SVG
# pairs (light/dark) + profile.json
Run one render at a time per output directory — concurrent renders
into the same directory are unsupported and can publish assets from
different scans.
Only commits authored by your configured identities count (seeded from
git config user.email at init; add more emails in
~/.aiprofile/config.json).
Run aiprofile init from inside one of your own repos: identity
seeding reads git config user.email in the directory where you run
it, so running from an unrelated folder can seed your global email
instead of the one you actually commit with (or none at all). Check
the seeded identities in ~/.aiprofile/config.json after init.
Embed in your profile README:
<picture>
<source media="(prefers-color-scheme: dark)" srcset="dist/summary-dark.svg">
<img alt="AI collaboration summary" src="dist/summary-light.svg">
</picture>
Declaring AI participation (trailers)
If you commit through Claude Code, Codex, Cursor, Copilot, Aider, or
Amp, you likely have nothing to do: tools that add their own
co-author trailer (e.g. Claude Code's
Co-Authored-By: Claude <noreply@anthropic.com>) are recognized
automatically via a verified identity registry.
For everything else — or for richer detail (model, role, review
status) — declare explicitly with AI-* trailers; product names like
Kimi, Claude, or Gemini resolve too:
feat: add aggregation service
AI-Provider: Anthropic
AI-Model: Claude-Sonnet
AI-Tool: Claude-Code
AI-Role: implementation, documentation
AI-Mode: AI-Assisted
AI-Reviewed-By: Human
One commit can carry
several AI actor presences ("Claude implements, Codex reviews" =
1 unique commit, 2 presences — the two metrics are never conflated; a
presence means "this provider/tool appeared in this commit", so Claude
implementing AND reviewing one commit counts once, honestly). A commit
that is explicitly yours alone: AI-Mode: Human-Only.
Privacy model (defaults are safe)
- Everything stays on your machine; no network calls, no telemetry.
- Every scanned repository defaults to
aggregate_only: it contributes counts, never its name.scan --fullis the explicit opt-in that marks a repository's counts as explicitly publishable (a policy decision you make — NOT a claim about GitHub visibility);excludedremoves a repository entirely. - Publication policy lives in
config.jsononly — edit it and the nextaggregate/renderrespects it, no rescan needed. - Public outputs contain counts, provider names, evidence totals, and a
UTC date. Never: repository names/paths, org names, branches, commit
SHAs or messages, raw trailer strings, emails, or timestamps finer than
a date. Unrecognized provider spellings are bucketed as "Unrecognized"
in public assets (see the raw values locally with
aggregate -v). aiprofile aggregateprints exactly what would be published — it is the privacy preview.- Honest limit: aggregate-only publication is identity redaction, not
anonymity. Repository names never appear, but repeatedly published
exact counts let an observer infer when your aggregate-only activity
changed and which provider appeared. Full threat model:
docs/PRIVACY.md. Output labels are policy-based ("explicitly publishable" / "aggregate-only"), never claims about GitHub visibility. - Do not sync
~/.aiprofileinto published dotfiles (it holds a salt and private repository paths). Deleting that directory deletes all local data; generateddist/files are yours to remove separately. On POSIX the directory and files are owner-only (0700/0600); Windows has no equivalent permission bits, so thereos.chmodis a documented no-op — the data still never leaves your machine.
Metrics, honestly labeled
- AI-attributed commits — unique commits with ≥1 explicit AI actor presence. Per-provider counts may sum to more than this (multi-AI commits) and are labeled as provider-attributed commits, never as unique totals. Evidence chips state their population; percentages state their denominator; active days are commit author dates.
- Evidence quality is first-class:
verified > declared > imported > inferred > unknown. v0.1 producesdeclared(trailers) andunknown.
License
MIT — see LICENSE. Contributions welcome under CONTRIBUTING.md.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ai_profile_cli-0.3.0.tar.gz.
File metadata
- Download URL: ai_profile_cli-0.3.0.tar.gz
- Upload date:
- Size: 406.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
98f405eb5b9d63dee25da80b111022706e89e6b3e185cbad2119b6bfedc26533
|
|
| MD5 |
70f2428abab5704d3d85824a0eb669ce
|
|
| BLAKE2b-256 |
37140d7f4d0076363d2155760b6811add5305956cd683e12e55bb57fa42f6ec5
|
Provenance
The following attestation bundles were made for ai_profile_cli-0.3.0.tar.gz:
Publisher:
publish.yml on WenyuChiou/ai-profile
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_profile_cli-0.3.0.tar.gz -
Subject digest:
98f405eb5b9d63dee25da80b111022706e89e6b3e185cbad2119b6bfedc26533 - Sigstore transparency entry: 2230440698
- Sigstore integration time:
-
Permalink:
WenyuChiou/ai-profile@b70f3a5b3183aa2df06886ac6275b98b4808a49b -
Branch / Tag:
refs/tags/v0.3.0 - Owner: https://github.com/WenyuChiou
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@b70f3a5b3183aa2df06886ac6275b98b4808a49b -
Trigger Event:
push
-
Statement type:
File details
Details for the file ai_profile_cli-0.3.0-py3-none-any.whl.
File metadata
- Download URL: ai_profile_cli-0.3.0-py3-none-any.whl
- Upload date:
- Size: 102.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a28493e9e2d1b05513e6aabbbdd30ff885f25870941c79c71a0dc28ae5d43577
|
|
| MD5 |
253391f9a297bc95af2ca8be2c13d56d
|
|
| BLAKE2b-256 |
dcc8b4bbf6375eb0aa03fe4e770ca9a8c7dc01a22ebf7eafc07af3aac85b5265
|
Provenance
The following attestation bundles were made for ai_profile_cli-0.3.0-py3-none-any.whl:
Publisher:
publish.yml on WenyuChiou/ai-profile
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_profile_cli-0.3.0-py3-none-any.whl -
Subject digest:
a28493e9e2d1b05513e6aabbbdd30ff885f25870941c79c71a0dc28ae5d43577 - Sigstore transparency entry: 2230441220
- Sigstore integration time:
-
Permalink:
WenyuChiou/ai-profile@b70f3a5b3183aa2df06886ac6275b98b4808a49b -
Branch / Tag:
refs/tags/v0.3.0 - Owner: https://github.com/WenyuChiou
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@b70f3a5b3183aa2df06886ac6275b98b4808a49b -
Trigger Event:
push
-
Statement type: