A valid-and-reliable hybrid of Turnitin-style authorship attribution and autopsy-style forensic reconstruction, for repositories. Point it at a repo, a file set, or a whole estate — it clones the target, reads it read-only, and tells you which agents (Claude, Gemini, Codex, Vibe, …) or humans have been operating there, what they did, and what residues they left behind. Even when bots act under human accounts without declaring themselves.
Educators and developers both. Educators get per-student baselines and conservative false-positive budgets. Developers get estate-scale batch forensics and prioritised findings. One detection engine, two audience modes.
Inspired by perplexity-based "AI text detectors" being broken by design — this is the defensible alternative.
See ROADMAP.adoc for the capability ladder (v0 observe → v1 detect → v2
reverse → v3 repair → v4 multi-agent interaction → v5 pseudointent) and
docs/decisions/ for the architectural decisions.
|
Warning
|
v0 (in progress): shallow-signal scanners, clone-first isolation, A2ML reports. No classifier yet — that arrives in v1. No remediation. No writes to the subject under any circumstances. |
-
Touch nothing. The tool never writes to the subject. Targets are cloned into an isolation area and only the clone is touched.
-
Single write channel. Any outbound change proposal is routed through
feedback-o-tron. The core has no other side-effect path. -
Bundled scanners, not reimplemented.
panic-attacktravels with the tool as a subprocess dependency. -
Safe to set loose live. No destructive operations, no automated remediation in v1. Defensible on a production estate.
# Scan a remote repo (clones into /mnt/eclipse/robofishy-scenes/<ts>-<slug>/)
robofishy scan https://github.com/example/some-repo
# Scan a local path
robofishy scan /path/to/local/repo
# Skip panic-attack if it's not on PATH
robofishy scan --skip-panic-attack /path/to/local/repoThe A2ML report path is printed on stdout; the scene directory is logged on stderr. Nothing else is written anywhere else.
This repo was bootstrapped from rsr-template-repo. Below is the template’s
inherited structure; see the template’s own documentation for details.
Canonical command model:
-
intake repo <path> -
checkpoint change <path> -
verify maintenance <path> -
verify substantial <path> -
verify release <path> -
close planned <path> -
close urgent <path> -
recover repo <path> -
handover full <path> -
handover split <path> -
handover model <path> -
handover human <path>
Local binding files in this template:
-
session/dispatch.sh -
session/custom-checks.k9 -
session/local-hooks.sh -
session/README.md -
coordination.k9
Run just session-help for local aliases.
The template keeps a verified interface seam split:
-
ABI (Idris2):
src/interface/Abi/*.idr -
FFI (Zig):
src/interface/ffi/src/*.zig -
Generated artifacts:
src/interface/generated/
| Path | Purpose |
|---|---|
|
Machine-readable policy and project metadata. |
|
Thin local bindings to central session-management standards. |
|
Local coordination wiring to canonical session commands. |
|
Human-facing technical and governance documentation. |
|
ABI/FFI/generated seam scaffolding. |
|
Proof and verification scaffolding. |
-
AUDIT.adoc — local audit gate summary
-
EXPLAINME.adoc — template claim-to-implementation map
-
session/README.md — session binding usage
-
docs/governance/README.adoc — governance docs index