GhSpy
GitHub OSINT tool — extract intelligence from any GitHub user profile.
Discover emails, estimate timezones, map tech stacks, find collaborators, and analyze activity patterns — all from your terminal. GhSpy uses the public GitHub API to gather open-source intelligence on any GitHub user.
- Email Discovery — extract real email addresses from commit history
- Timezone Estimation — estimate location from commit hour patterns
- Activity Analysis — peak hours, active days, contribution streaks
- Tech Stack Mapping — languages, topics, original vs forked repos
- Collaborator Detection — frequent interactions, orgs, following
- Identity Mapping — cross-reference commit emails and author names
Installation
pip install ghspy
Requires Python 3.8+. Works on Linux, macOS, and Windows.
Usage
# Full OSINT scan
ghspy scan torvalds
# Extract emails from commit history
ghspy emails dhh
# Estimate timezone
ghspy timezone antirez
# Activity patterns
ghspy activity shazeus
# Tech stack
ghspy techstack gvanrossum
# Collaborators & organizations
ghspy collabs octocat
# Export to JSON
ghspy export torvalds --format json -o report.json
# Export to CSV
ghspy export torvalds --format csv -o report.csv
Commands
| Command | Description |
|---|---|
ghspy scan <user> |
Full OSINT scan with all modules |
ghspy emails <user> |
Extract emails from commit history |
ghspy timezone <user> |
Estimate timezone from commit patterns |
ghspy activity <user> |
Activity breakdown by hour, day, and event type |
ghspy techstack <user> |
Languages, topics, and repo statistics |
ghspy collabs <user> |
Collaborators, organizations, and following |
ghspy export <user> |
Export findings to JSON or CSV |
ghspy rate-limit |
Check GitHub API rate limit |
Configuration
GitHub Token
Without a token you get 60 requests/hour. With a token you get 5,000 requests/hour. A full scan uses 20–50 requests depending on the user's repo count.
# Set as environment variable (recommended)
export GITHUB_TOKEN=ghp_your_token_here
# Or pass directly
ghspy --token ghp_xxxx scan torvalds
Generate a token at github.com/settings/tokens — no special scopes needed for public data.
JSON Output
Every command supports --json-output for piping to other tools:
ghspy scan user --json-output | jq '.emails'
ghspy scan user --json-output | jq '.timezone.estimated_timezone'
How It Works
GhSpy queries the public GitHub REST API to collect:
- User profile — public info, bio, location, social links
- Repositories — languages, topics, fork status, activity dates
- Commit history — author emails, timestamps, committer info
- Public events — pushes, PRs, issues, comments
- Social graph — followers, following, organizations
All data is publicly available through GitHub's API. No authentication bypass or scraping is involved.
Disclaimer
This tool only accesses publicly available data through the official GitHub API. It does not bypass access controls, scrape private information, or violate GitHub's Terms of Service. Use responsibly.
License
Metadata
Release files for ghspy 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ghspy-0.1.0.tar.gz | 12.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ghspy-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.5 kB
Release files / ghspy-0.1.0.tar.gz
| Download URL | ghspy-0.1.0.tar.gz |
|---|---|
| Size | 12.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
71789401005c03ed0db5d1857e5e31a107e8d98ec95f8caf750c5aa530677646
|
|
BLAKE2b-256 checksum How to use checksums |
31ad73c214c8cee563fba9a14311b71e0cea85c60f994ce26f164cc733e0b3f2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.13
|
Release files / ghspy-0.1.0-py3-none-any.whl
| Download URL | ghspy-0.1.0-py3-none-any.whl |
|---|---|
| Size | 12.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
318b482bb9242e41efa0c389be8a89e651216b96a16caf6baf1185b8132c1420
|
|
BLAKE2b-256 checksum How to use checksums |
f4e092cb2733a15e5c8c96f6bf766735a1e114c941c9e8f4dbcaa1b574556e42
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.13
|