repo-roast
A terminal CLI that reads a GitHub profile through the GitHub REST API — repos, language breakdown, stars, abandoned projects, and a sample of recent commit messages — then asks an LLM to roast the developer's coding habits.
It shows its receipts: every roast is preceded by an evidence table, and the model is instructed to only joke about facts that are actually in the data.
$ repo-roast roast torvalds --spice hot
Install
pip install -e .
Configure
cp .env.example .env
Then fill in:
| Variable | What it is |
|---|---|
GITHUB_TOKEN |
A personal access token. public_repo scope is enough for public data; add repo to include your own private repos. |
LLM_API_KEY |
A free Groq key (no credit card; starts with gsk_). |
LLM_BASE_URL |
Defaults to https://api.groq.com/openai/v1. |
LLM_MODEL |
Defaults to llama-3.3-70b-versatile. |
Usage
repo-roast roast # roast yourself (the authenticated user)
repo-roast roast torvalds # roast someone else
repo-roast roast torvalds --spice hot # roast them harder
repo-roast roast torvalds --dry-run # evidence + the exact prompt, no LLM call
repo-roast --help # the commands
repo-roast roast --help # the flags below
Breaking change in 0.2.0. The tool now takes a sub-command:
repo-roast torvaldsbecamerepo-roast roast torvalds. This makes room for the commands that follow —compare,repo— withoutcomparebeing ambiguous with a user who happens to be called compare. The old form prints the new one rather than a bare "No such command".
Flags
Flags belong to roast. --version belongs to the top level.
| Flag | Default | Meaning |
|---|---|---|
username (positional) |
authenticated user | Which GitHub user to roast. |
--spice / -s |
medium |
mild, medium, or hot. |
--model / -m |
$LLM_MODEL or llama-3.3-70b-versatile |
Model name to send to the provider. |
--repos / -r |
5 |
How many recently-pushed repos to sample commit messages from. |
--commits / -c |
8 |
Commits to sample per repository (1–50). |
--evidence / --no-evidence |
on | Show the stats table. |
--format / -f |
text |
text, json, or markdown. |
--dry-run |
off | Gather stats, print the evidence table and the exact prompt, then exit — no LLM call and no LLM_API_KEY required. |
--version |
off | Print the installed version and exit. |
--dry-run is the quickest way to check the GitHub half on its own.
Scripting it
--format json prints one document to stdout and nothing else:
repo-roast roast torvalds -f json | jq '.stats.total_stars'
repo-roast roast torvalds -f json --dry-run | jq -r '.prompt.user'
Progress spinners and error messages go to stderr, so a pipe receives either a valid document or nothing at all — never half of one. Failures still exit non-zero, with the message on stderr where it belongs.
--format markdown prints the evidence table and the roast as Markdown, ready to
paste into an issue or a README.
Provider
The default backend is Groq: free, no credit card, and OpenAI-compatible.
repo-roast talks to it with the official openai SDK pointed at a custom base
URL, so any OpenAI-compatible endpoint works — switching providers is just three
environment variables.
| Provider | LLM_BASE_URL |
Example LLM_MODEL |
|---|---|---|
| Groq (default) | https://api.groq.com/openai/v1 |
llama-3.3-70b-versatile |
| Google Gemini | https://generativelanguage.googleapis.com/v1beta/openai/ |
gemini-2.0-flash |
| Mistral | https://api.mistral.ai/v1 |
mistral-small-latest |
| OpenRouter | https://openrouter.ai/api/v1 |
meta-llama/llama-3.3-70b-instruct:free |
| Cerebras | https://api.cerebras.ai/v1 |
llama-3.3-70b |
Model strings change over time — if a call 404s, check the provider's current model list.
Running it with Docker
No local Python needed. Images are published to the GitHub Container Registry
on every release, for linux/amd64 and linux/arm64:
docker run --rm -e GITHUB_TOKEN=ghp_... -e LLM_API_KEY=gsk_... \
ghcr.io/amayyas/repo-roast roast torvalds --spice hot
Environment variables, not a mounted .env: simpler, and there is no file to
accidentally bake into a container. LLM_BASE_URL and LLM_MODEL work the
same way if you are pointing at a different provider.
Tags: latest tracks the newest release, vX.Y.Z pins a specific one — same
versions as PyPI.
How it stays polite to the API
Repo metadata (languages, stars, descriptions, push dates) comes from the single
repo listing that PyGithub already paginates. The only per-repo calls are for
commit messages, and they are bounded on both axes: the --repos most recently
pushed originals, up to 8 commits each.
Ethical use
repo-roast generates jokes about named, real people from their public GitHub activity. That comes with rules, not just a disclaimer:
- Roast the code and the habits — commit hygiene, abandoned repos, a
suspicious
TODO— never the person. No appearance, no identity, no protected characteristic. The system prompt enforces this on every call, and it's the first hard rule inroast.py. - Don't use the output to harass, dogpile, or target someone who didn't ask for it. A roast run against a stranger without their knowledge is not the friendly-jab use case this tool is built for.
- This isn't only a prompt-level promise. SECURITY.md documents the structural defense that keeps a booby-trapped repo from turning the tool into a weapon against whoever is being roasted.
This project follows a Code of Conduct; the same spirit applies to how the tool itself gets used.
Support
Questions, bugs, or a roast that missed? See SUPPORT.md, or reach out directly at amayyas.aouadene@epitech.eu.
Found a security issue? See SECURITY.md instead of opening a public issue.
Want to contribute? See CONTRIBUTING.md. This project follows a Code of Conduct.
License
MIT © Amayyas Aouadene
Metadata
Release files for repo-roast 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| repo_roast-0.3.0.tar.gz | 27.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| repo_roast-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 47.0 kB
Release files / repo_roast-0.3.0.tar.gz
| Download URL | repo_roast-0.3.0.tar.gz |
|---|---|
| Size | 27.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
aa9dd646405e21538f08b3b91582399e2fe28cef9139a0669fbcb0f2863a2099
|
|
BLAKE2b-256 checksum How to use checksums |
9f149a9edd907334c7f6638e80ff1a77544228d7661e8d5a12fe1ea62dc78c4a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 8, 2026.
Transparency logRelease files / repo_roast-0.3.0-py3-none-any.whl
| Download URL | repo_roast-0.3.0-py3-none-any.whl |
|---|---|
| Size | 19.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cdd162e0750897942942c1278d2fc52c0f981f7db57700a9dc69652095b7a409
|
|
BLAKE2b-256 checksum How to use checksums |
e7ec7ad36cdc7302eb7fe777030826f9ec856e9ef24b17b273a4a4f29bb39370
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 8, 2026.
Transparency log