Skip to main content

cgh-summarize

Prose summaries of indexed files for cgh, produced by whatever model you already have, behind a confidentiality egress gate.

pip install cgh-summarize
cgh summarize status      # detected backends, gate posture, coverage
cgh summarize run         # summarize what the gate clears
cgh findings --key summary
cgh insights              # cross-file patterns from the summaries

Backends

Backend Runs Egress
cli:claude claude -p, light model cloud
cli:gemini gemini -p, flash tier cloud
cli:codex codex exec cloud
cli:bob bob -p, IBM BobShell routes the model itself cloud
ollama local Ollama daemon, model is a config line none
openai any OpenAI-compatible endpoint (vLLM, LM Studio, watsonx, ...) cloud
structural cgh's own outline, no model at all none

backend = "auto" (default) picks the first available in that order. Third-party plugins add backends through the summarize.backend extension namespace without touching this plugin.

The egress gate

Before any cloud backend sees a file, its findings are checked: a confidential flag or any block-severity finding (private keys, cloud credentials) stops it, PII findings stop it unless allow_pii = true. With mode = "secure" in the cgh config, the gate switches to allowlist: only files explicitly labeled non-confidential go out. Local backends (ollama, structural) bypass the gate since nothing leaves the machine. Every cloud call is logged to .codegraph/activity.log.

Configuration

[plugin.summarize]
# backend = "auto"          # or cli:claude, cli:gemini, cli:codex,
#                           # cli:bob, ollama, openai, structural
# min_kb = 4                # skip files smaller than this
# allow_pii = false
# language = "en"
# claude_model = "haiku"
# gemini_model = "gemini-2.5-flash"
#                           # no bob_model: BobShell routes the model itself
# ollama_model = "qwen2.5:1.5b"
# ollama_url = "http://127.0.0.1:11434"
# openai_base_url = ""      # e.g. http://localhost:8000/v1
# openai_model = ""
# openai_api_key_env = "OPENAI_API_KEY"

Re-summarize policy: unchanged content is never re-scanned (blob SHA); when content changes, the old summary is carried forward while the drift stays under 30% of lines and fewer than 5 changes accumulated, then a fresh summary is produced.

Metadata

Release files for cgh-summarize 0.2.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cgh-summarize 0.2.4
File Size Uploaded
cgh_summarize-0.2.4.tar.gz 17.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cgh-summarize 0.2.4
File Interpreter ABI Platform
cgh_summarize-0.2.4-py3-none-any.whl Python 3 none any Details

Total release size: 33.7 kB

Release files / cgh_summarize-0.2.4.tar.gz

Download URL cgh_summarize-0.2.4.tar.gz
Size 17.1 kB
Tags Source
SHA-256 checksum
How to use checksums
1b0db2d8d4becbc49549bee08f1466ecf1968f4c4b399e3c39041e78a93be550
BLAKE2b-256 checksum
How to use checksums
bc81589c864ff2a60d299d5ac7f3b715dcc927a3cf54eb990750c6c587e60257
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 14, 2026.

Transparency log

Release files / cgh_summarize-0.2.4-py3-none-any.whl

Download URL cgh_summarize-0.2.4-py3-none-any.whl
Size 16.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8c61553dfe512f32efc7ddfa97b451e6869b65dea43fdb1c354aa6a19a897090
BLAKE2b-256 checksum
How to use checksums
cec608a05f7881acf849f53fa753ba85c7eab33c6f76c7b5f4c24aa5758a1f1a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 14, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.0

2 release files

This release

0.2.4 This release

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page