cgh-summarize
Prose summaries of indexed files for cgh, produced by whatever model you already have, behind a confidentiality egress gate.
pip install cgh-summarize
cgh summarize status # detected backends, gate posture, coverage
cgh summarize run # summarize what the gate clears
cgh findings --key summary
cgh insights # cross-file patterns from the summaries
Backends
| Backend | Runs | Egress |
|---|---|---|
cli:claude |
claude -p, light model |
cloud |
cli:gemini |
gemini -p, flash tier |
cloud |
cli:codex |
codex exec |
cloud |
cli:bob |
bob -p, IBM BobShell routes the model itself |
cloud |
ollama |
local Ollama daemon, model is a config line | none |
openai |
any OpenAI-compatible endpoint (vLLM, LM Studio, watsonx, ...) | cloud |
structural |
cgh's own outline, no model at all | none |
backend = "auto" (default) picks the first available in that order.
Third-party plugins add backends through the summarize.backend
extension namespace without touching this plugin.
The egress gate
Before any cloud backend sees a file, its findings are checked: a
confidential flag or any block-severity finding (private keys, cloud
credentials) stops it, PII findings stop it unless allow_pii = true.
With mode = "secure" in the cgh config, the gate switches to
allowlist: only files explicitly labeled non-confidential go out.
Local backends (ollama, structural) bypass the gate since nothing
leaves the machine. Every cloud call is logged to
.codegraph/activity.log.
Configuration
[plugin.summarize]
# backend = "auto" # or cli:claude, cli:gemini, cli:codex,
# # cli:bob, ollama, openai, structural
# min_kb = 4 # skip files smaller than this
# allow_pii = false
# language = "en"
# claude_model = "haiku"
# gemini_model = "gemini-2.5-flash"
# # no bob_model: BobShell routes the model itself
# ollama_model = "qwen2.5:1.5b"
# ollama_url = "http://127.0.0.1:11434"
# openai_base_url = "" # e.g. http://localhost:8000/v1
# openai_model = ""
# openai_api_key_env = "OPENAI_API_KEY"
Re-summarize policy: unchanged content is never re-scanned (blob SHA); when content changes, the old summary is carried forward while the drift stays under 30% of lines and fewer than 5 changes accumulated, then a fresh summary is produced.
Metadata
Release files for cgh-summarize 0.2.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cgh_summarize-0.2.4.tar.gz | 17.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cgh_summarize-0.2.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 33.7 kB
Release files / cgh_summarize-0.2.4.tar.gz
| Download URL | cgh_summarize-0.2.4.tar.gz |
|---|---|
| Size | 17.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1b0db2d8d4becbc49549bee08f1466ecf1968f4c4b399e3c39041e78a93be550
|
|
BLAKE2b-256 checksum How to use checksums |
bc81589c864ff2a60d299d5ac7f3b715dcc927a3cf54eb990750c6c587e60257
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 14, 2026.
Transparency logRelease files / cgh_summarize-0.2.4-py3-none-any.whl
| Download URL | cgh_summarize-0.2.4-py3-none-any.whl |
|---|---|
| Size | 16.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8c61553dfe512f32efc7ddfa97b451e6869b65dea43fdb1c354aa6a19a897090
|
|
BLAKE2b-256 checksum How to use checksums |
cec608a05f7881acf849f53fa753ba85c7eab33c6f76c7b5f4c24aa5758a1f1a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 14, 2026.
Transparency log