Skip to content

Latest commit

 

History

144 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Something’s [Robo] Fishy

OpenSSF Best Practices License: MPL-2.0 Green Web OpenSSF Scorecard

A valid-and-reliable hybrid of Turnitin-style authorship attribution and autopsy-style forensic reconstruction, for repositories. Point it at a repo, a file set, or a whole estate — it clones the target, reads it read-only, and tells you which agents (Claude, Gemini, Codex, Vibe, …) or humans have been operating there, what they did, and what residues they left behind. Even when bots act under human accounts without declaring themselves.

Educators and developers both. Educators get per-student baselines and conservative false-positive budgets. Developers get estate-scale batch forensics and prioritised findings. One detection engine, two audience modes.

Inspired by perplexity-based "AI text detectors" being broken by design — this is the defensible alternative.

See ROADMAP.adoc for the capability ladder (v0 observe → v1 detect → v2 reverse → v3 repair → v4 multi-agent interaction → v5 pseudointent) and docs/decisions/ for the architectural decisions.

Warning

v0 (in progress): shallow-signal scanners, clone-first isolation, A2ML reports. No classifier yet — that arrives in v1. No remediation. No writes to the subject under any circumstances.

Hard invariants

  1. Touch nothing. The tool never writes to the subject. Targets are cloned into an isolation area and only the clone is touched.

  2. Single write channel. Any outbound change proposal is routed through feedback-o-tron. The core has no other side-effect path.

  3. Bundled scanners, not reimplemented. panic-attack travels with the tool as a subprocess dependency.

  4. Safe to set loose live. No destructive operations, no automated remediation in v1. Defensible on a production estate.

Quickstart (v0 prototype)

# Scan a remote repo (clones into /mnt/eclipse/robofishy-scenes/<ts>-<slug>/)
robofishy scan https://github.com/example/some-repo

# Scan a local path
robofishy scan /path/to/local/repo

# Skip panic-attack if it's not on PATH
robofishy scan --skip-panic-attack /path/to/local/repo

The A2ML report path is printed on stdout; the scene directory is logged on stderr. Nothing else is written anywhere else.

Project layout inherited from rsr-template-repo

This repo was bootstrapped from rsr-template-repo. Below is the template’s inherited structure; see the template’s own documentation for details.

Session Management Integration

Canonical command model:

  • intake repo <path>

  • checkpoint change <path>

  • verify maintenance <path>

  • verify substantial <path>

  • verify release <path>

  • close planned <path>

  • close urgent <path>

  • recover repo <path>

  • handover full <path>

  • handover split <path>

  • handover model <path>

  • handover human <path>

Local binding files in this template:

  • session/dispatch.sh

  • session/custom-checks.k9

  • session/local-hooks.sh

  • session/README.md

  • coordination.k9

Run just session-help for local aliases.

ABI/FFI Seam Layout

The template keeps a verified interface seam split:

  • ABI (Idris2): src/interface/Abi/*.idr

  • FFI (Zig): src/interface/ffi/src/*.zig

  • Generated artifacts: src/interface/generated/

Repository Layout

Path Purpose

.machine_readable/

Machine-readable policy and project metadata.

session/

Thin local bindings to central session-management standards.

coordination.k9

Local coordination wiring to canonical session commands.

docs/

Human-facing technical and governance documentation.

src/interface/

ABI/FFI/generated seam scaffolding.

verification/

Proof and verification scaffolding.

Quick Start

just init
just verify
just session-help

Documentation

License

This project is licensed under the Mozilla Public License, v. 2.0. See the LICENSE file for details.

SPDX-License-Identifier: CC-BY-SA-4.0