Find what broke in your agent calls. Pin it so it never ships again. Local call forensics and regression guards for AI agents: deterministic, byte-reproducible, free, MIT, CI-native. Nothing leaves your machine.
Project description
hotato
Find what broke in your agent calls. Pin it so it never ships again.
pip install hotato
hotato autopsy --demo # a failing call ships with the install
hotato autopsy ./call.wav # then your own recording
hotato vapi health # or your last 100 Vapi calls
Zero config. Works with Vapi, Retell, Bland, Synthflow, Millis, or local audio. No judges. No cloud. No bill. MIT.
What it finds
- Barge-in → Say-do gaps: Caller interrupts to cancel; agent says "canceled" but the booking tool still fires: a bug that fires actions the caller canceled. (Timing from the audio; the tool-fire check reads your call's tool log: hotato ingests Vapi/OTel traces.)
- Latency spikes: 800ms → 5s unpredictability that makes users hang up.
- Dead air: Long silences that kill conversation flow.
- Talk-over: Agent speaks over the caller; never yields.
Quickstart
Vapi
pip install hotato
export VAPI_API_KEY=...
hotato vapi health --last 7d --output report.html
Open report.html. See your Voice Stability Score and every critical incident.
Retell
export RETELL_API_KEY=...
hotato retell health --call-id CALL_ID
--call-id is required and repeatable: Retell has no verified
list-recent-calls endpoint, so hotato never guesses one. hotato bland health,
hotato synthflow health, and hotato millis health follow the Vapi shape;
those stacks export one mixed channel, so their reports carry the
measured-confidence mono observations block.
Local audio
hotato autopsy ./call.wav
Writes a detailed, self-contained HTML incident report under hotato-output/;
open it in your browser.
From finding bugs to preventing them
autopsy finds bugs. scan tracks trends across a folder of calls. When you
are ready, pin incidents to your CI so they never ship again: hotato pin
turns one incident into a portable failure check, and hotato prove is the CI
check that re-runs every stored piece of evidence and fails closed. Every
verdict carries its evidence across five dimensions (outcome, policy,
conversation, speech, reliability).
For continuous use: run hotato vapi health on a schedule, and open
hotato console --production-db DB to inspect stored runs locally.
Wire it into CI
The step's exit code is the verdict: 0 pass, 1 fail, 2 refuse.
# .github/workflows/voice-qa.yml
on: [pull_request]
jobs:
hotato:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: attenlabs/hotato@v1.17.1
with:
contracts: contracts/
hotato-version: 1.17.1
Copy-paste workflow with a commit-SHA pin: docs/CI.md.
Point your agent at it
Point Claude Code, Cursor, or any coding agent at this repo: it reads
AGENTS.md and runs the loop end to end, offline, no key. The MCP
server exposes the scorer plus read/verify/propose tools over local stdio:
uvx --from "hotato[mcp]" hotato-mcp (docs/MCP.md).
Nothing leaves your machine
hotato runs offline, on the machine that invokes it. The core is stdlib-only Python: no account, no key, no network call of its own. Your traces, prompts, and audio stay local, and the local-judge lane is opt-in and quality-gated, separate from the deterministic core.
Go deeper
The whole loop, command by command: docs/LIFECYCLE.md.
First touch to a CI gate: docs/GETTING-STARTED.md.
Feed it what you already have: docs/CONNECT.md ·
docs/TRACE.md · docs/SIMULATE.md.
What every verdict stands on: docs/EVIDENCE-CONTRACT.md.
Next to the hosted alternatives: docs/COMPARE.md.
The deep toolkit -- capture, simulation, load, benchmarking, the fix ladder,
the fleet control plane -- lives under hotato lab (hotato lab --help).
The public commands are durable; hotato lab evolves faster; every pre-1.17
top-level spelling keeps working unchanged.
Specifications
| Property | Value |
|---|---|
| Footprint | ~10 MiB installed, 0 runtime dependencies (stdlib-only) |
| Reproducibility | byte-for-byte, content-addressed checks |
| Exit codes | 0 pass · 1 fail · 2 refuse |
| Release integrity | OIDC Trusted Publishing + build-provenance attested |
| Runtime | offline, off the production data path |
Verify the measurement yourself
PYTHONPATH=src python3 -m hotato.benchmark \
--scenarios corpus/real/scenarios --audio corpus/real/audio
On 13 recorded AMI Meeting Corpus clips, the median error between measured caller-onset and the human word-alignment label is 20 ms. Provenance: corpus/real/README.md · method: METHODOLOGY.md.
Timing is measurable only when the two voices arrive on separate channels; a mono or mixed export is marked NOT SCORABLE and refused (hotato trust --stereo call.wav). The full four-tier evidence policy (what each verdict stands on, per input) is docs/EVIDENCE-CONTRACT.md.
Contribute
Issues and PRs welcome: CONTRIBUTING.md · SECURITY.md · CHANGELOG · docs/
License
MIT (LICENSE)
mcp-name: io.github.attenlabs/hotato
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file hotato-1.17.1.tar.gz.
File metadata
- Download URL: hotato-1.17.1.tar.gz
- Upload date:
- Size: 8.7 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a76cf0d74faf21a57ba056a6a8442dc4faed1453a489f6c23566063705efe8ac
|
|
| MD5 |
b63e41abef77568ee7063c92120f42af
|
|
| BLAKE2b-256 |
29ee95fd1255b53e241150df2b1a07047d5383f14d5e11016630ed25ecbc4f8a
|
Provenance
The following attestation bundles were made for hotato-1.17.1.tar.gz:
Publisher:
publish-pypi-oidc.yml on attenlabs/hotato
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
hotato-1.17.1.tar.gz -
Subject digest:
a76cf0d74faf21a57ba056a6a8442dc4faed1453a489f6c23566063705efe8ac - Sigstore transparency entry: 2276993069
- Sigstore integration time:
-
Permalink:
attenlabs/hotato@e8f74cad4e2b025c328c815cf9c0c8bb3095c4e7 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/attenlabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi-oidc.yml@e8f74cad4e2b025c328c815cf9c0c8bb3095c4e7 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file hotato-1.17.1-py3-none-any.whl.
File metadata
- Download URL: hotato-1.17.1-py3-none-any.whl
- Upload date:
- Size: 6.1 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
61026ca98e745c2e0912b56f58572888267fadad3fadde9c764c83f6cd98be4e
|
|
| MD5 |
884039b67d2766e19b575da389a86b4d
|
|
| BLAKE2b-256 |
56b3f9583f04a026ab400a2962b21e9814c50057393cc388f0b472bb3722916e
|
Provenance
The following attestation bundles were made for hotato-1.17.1-py3-none-any.whl:
Publisher:
publish-pypi-oidc.yml on attenlabs/hotato
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
hotato-1.17.1-py3-none-any.whl -
Subject digest:
61026ca98e745c2e0912b56f58572888267fadad3fadde9c764c83f6cd98be4e - Sigstore transparency entry: 2276993124
- Sigstore integration time:
-
Permalink:
attenlabs/hotato@e8f74cad4e2b025c328c815cf9c0c8bb3095c4e7 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/attenlabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi-oidc.yml@e8f74cad4e2b025c328c815cf9c0c8bb3095c4e7 -
Trigger Event:
workflow_dispatch
-
Statement type: