{"id":51699099,"url":"https://github.com/edycutjong/redpen","last_synced_at":"2026-07-16T08:33:46.433Z","repository":{"id":366435357,"uuid":"1276283235","full_name":"edycutjong/redpen","owner":"edycutjong","description":"✍️ Confidential AI Contract Redliner and Clause-by-Clause Risk Auditor built for the Anna Hackathon","archived":false,"fork":false,"pushed_at":"2026-06-21T20:47:02.000Z","size":14166,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-21T21:15:18.824Z","etag":null,"topics":["anna-app","contract-audit","hackathon","security"],"latest_commit_sha":null,"homepage":"https://edycutjong.github.io/redpen/public/pitch.html","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/edycutjong.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-06-21T19:25:12.000Z","updated_at":"2026-06-21T20:47:06.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/edycutjong/redpen","commit_stats":null,"previous_names":["edycutjong/redpen"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/edycutjong/redpen","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fredpen","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fredpen/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fredpen/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fredpen/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/edycutjong","download_url":"https://codeload.github.com/edycutjong/redpen/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fredpen/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35537751,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-16T02:00:06.687Z","response_time":83,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["anna-app","contract-audit","hackathon","security"],"created_at":"2026-07-16T08:33:45.496Z","updated_at":"2026-07-16T08:33:46.426Z","avatar_url":"https://github.com/edycutjong.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n  \u003cimg src=\"docs/icon.svg\" alt=\"RedPen Icon\" width=\"140\"\u003e\n  \u003ch1\u003eRedPen ✍️\u003c/h1\u003e\n  \u003cp\u003e\u003cem\u003eConfidential AI Contract Redliner and Clause-by-Clause Risk Auditor\u003c/em\u003e\u003c/p\u003e\n  \u003cimg src=\"public/readme-hero.svg\" alt=\"RedPen Hero Banner\" width=\"100%\"\u003e\n\n  \u003cbr/\u003e\n\n  [![Live Demo](https://img.shields.io/badge/🚀_Live-Demo-06b6d4?style=for-the-badge)](https://github.com/edycutjong/redpen)\n  [![Pitch Video](https://img.shields.io/badge/🎬_Pitch-Video-ef4444?style=for-the-badge)](https://youtu.be/4EFMD98_oC0)\n  [![Pitch Deck](https://img.shields.io/badge/📊_Pitch-Deck-f59e0b?style=for-the-badge)](https://edycutjong.github.io/redpen/public/pitch.html)\n  [![Built for Anna AI-Native Hackathon](https://img.shields.io/badge/DoraHacks-Anna_Hackathon-8b5cf6?style=for-the-badge)](https://dorahacks.io/hackathon/2204)\n\n  \u003cbr/\u003e\n\n  ![Python 3.11](https://img.shields.io/badge/Python_3.11-3776AB?style=flat\u0026logo=python\u0026logoColor=white)\n  ![Node.js 22](https://img.shields.io/badge/Node.js_22-339933?style=flat\u0026logo=nodedotjs\u0026logoColor=white)\n  ![AES-GCM-256](https://img.shields.io/badge/Crypto-AES--GCM--256-blue?style=flat)\n  ![Ed25519 Signed](https://img.shields.io/badge/Crypto-Ed25519_Signed-success?style=flat)\n  ![Anna Storage](https://img.shields.io/badge/Anna-APS_KV_Storage-10b981?style=flat)\n  ![R2 Upload](https://img.shields.io/badge/Anna-R2_Object_Upload-f59e0b?style=flat)\n  [![CI/CD Pipeline](https://github.com/edycutjong/redpen/actions/workflows/ci.yml/badge.svg)](https://github.com/edycutjong/redpen/actions)\n\n\u003c/div\u003e\n\n---\n\n## 📸 See it in Action\n\n\u003cdiv align=\"center\"\u003e\n  \u003ch3\u003eInteractive Audit Walkthrough\u003c/h3\u003e\n  \n  \u003ctable\u003e\n    \u003ctr\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e1. Load Contract Agreement\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/shot_01_loaded.png\" alt=\"1. Loaded\" width=\"100%\"\u003e\n      \u003c/td\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e2. Casper x402 Micropayment \u0026 Review Desk\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/shot_03_review_desk.png\" alt=\"2. Review Desk\" width=\"100%\"\u003e\n      \u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e3. IP Assignment Clause Audit\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/shot_04_review_clause_3.png\" alt=\"3. IP Clause Audit\" width=\"100%\"\u003e\n      \u003c/td\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e4. Indemnification Clause Audit\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/shot_04_review_clause_8.png\" alt=\"4. Indemnification Audit\" width=\"100%\"\u003e\n      \u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e5. Finalized Redlines \u0026 Signatures\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/shot_05_export_final.png\" alt=\"5. Export Final\" width=\"100%\"\u003e\n      \u003c/td\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e6. Cloudflare R2 Upload Complete\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/shot_06_r2_complete.png\" alt=\"6. Upload Complete\" width=\"100%\"\u003e\n      \u003c/td\u003e\n    \u003c/tr\u003e\n  \u003c/table\u003e\n\u003c/div\u003e\n\n\u003e **The RedPen Workflow**: Paste raw contract → Split into structured clauses → Pack into AES-GCM local session envelopes → Human-in-the-loop side-by-side comparative review → Persist audit trail to Anna KV → Export Ed25519-signed memo \u0026 share via R2.\n\n---\n\n## 💡 The Problem \u0026 Solution\n\n### The Problem\nFreelancers, founders, and small-business owners sign contractor agreements and SaaS terms that they don't fully understand. Unilateral non-competes, unlimited liability, and broad pre-existing IP assignments can be catastrophic. Traditional legal review costs $300-500/hour and takes days, causing signers to skip legal auditing entirely.\n\n### The Solution\n**RedPen** is a native Anna App that performs automated, clause-by-clause contract risk analysis. The AI behaves as a junior associate: it reads, classifies, risk-rates, and drafts safe alternatives — but the human retains final approval on every modification. Clauses are cryptographically processed locally inside the Executa sandbox with **AES-GCM-256** to construct tamper-proof session envelopes, and final changes are signed using **Ed25519** signatures to provide a verifiable audit trail.\n\n**Key Features:**\n- 🔒 **Locally Verified Auditable Cryptographic Envelopes**: Sensitive commercial clauses are packaged using AES-GCM-256 inside the Executa sandbox prior to auditing to ensure session integrity and secure local persistence. While the host LLM performs Secure API-driven inference on plaintext, the local cryptographic envelopes enforce verifiable session state and audit trails.\n- 🤝 **Human-in-the-loop Comparative Review**: Side-by-side review desk comparing original text with AI drafts, allowing custom edits, keeping originals, or accepting alternatives.\n- ✍️ **Ed25519 Auditable Signatures**: User-approved alterations are signed cryptographically to prevent post-export alteration (preventing legal gaslighting).\n- 📁 **R2 Object Uploads**: Redlined documents and signed memos are uploaded to Anna R2 storage via `host/uploadFile` reverse-RPC.\n- 💾 **Persistent Audit Trail**: Every completed audit is persisted to Anna Persistent Storage (APS KV) via `storage/set` — no external database needed. Maintains a rolling log of the last 50 audit sessions.\n\n---\n\n## 🏗️ Technical Architecture \u0026 Tech Stack\n\n```mermaid\ngraph TB\n    subgraph \"Anna App (iframe)\"\n        UI[App UI — HTML/CSS/JS]\n        SDK[AnnaAppRuntime SDK]\n    end\n\n    subgraph \"Anna Host\"\n        DISP[RPC Dispatcher]\n        LLM[Host LLM — sampling/createMessage]\n        STORE[runtime_state — 256KB KV]\n        APS[Anna Persistent Storage KV]\n        R2[R2 Object Storage]\n    end\n\n    subgraph \"Executa Plugin — Python\"\n        PROTO[JSON-RPC stdio handler]\n        PARSE[contract.parse]\n        ANALYZE[contract.analyze]\n        REDLINE[contract.generateRedline]\n        CRYP[AES-GCM \u0026 Ed25519 Engine]\n    end\n\n    UI --\u003e|postMessage| SDK\n    SDK --\u003e|tools.invoke| DISP\n    SDK --\u003e|storage.set/get| STORE\n    SDK --\u003e|upload.negotiate| R2\n    DISP --\u003e|stdin JSON-RPC| PROTO\n    PROTO --\u003e PARSE\n    PROTO --\u003e ANALYZE\n    PROTO --\u003e REDLINE\n    ANALYZE --\u003e CRYP\n    CRYP --\u003e|sampling/createMessage| LLM\n    REDLINE --\u003e|storage/set| APS\n    REDLINE --\u003e|host/uploadFile| R2\n```\n\n### Stack Composition\n\n| Layer | Technology | Rationale |\n|---|---|---|\n| **App Runtime** | Anna App (Schema 2) | Native integration with secure sandbox host |\n| **Frontend** | Vanilla HTML5 / Modern CSS / ES6 JS | Lightweight, zero-compile static-spa bundle |\n| **Backend** | Python 3.10+ Executa | Bidirectional JSON-RPC stdio plugin |\n| **Symmetric Cipher** | AES-GCM-256 | Tamper-proof session envelopes for clause data |\n| **Signatures** | Ed25519 | Cryptographic verification of reviewed actions |\n| **Persistent State** | Anna APS KV (`storage/get`, `storage/set`) | Audit trail persistence (last 50 sessions) |\n| **Artifact Storage** | Anna R2 (`host/uploadFile`) | Signed document distribution |\n\n---\n\n## 🔌 Anna Platform Integration\n\nRedPen exercises the full Anna SDK capability surface:\n\n### Reverse-RPC Methods (Plugin → Host)\n\n| Method | Purpose | Implementation |\n|---|---|---|\n| `sampling/createMessage` | LLM inference for clause risk analysis \u0026 summary | `send_request_to_host()` in plugin.py |\n| `storage/get` | Read persistent audit history from APS KV | `storage_get()` in plugin.py |\n| `storage/set` | Write audit trail entries to APS KV | `storage_set()` in plugin.py |\n| `storage/delete` | Remove audit entries from APS KV | `storage_delete_key()` in plugin.py |\n| `storage/list` | List past audit keys in APS KV | `storage_list_keys()` in plugin.py |\n| `host/uploadFile` (inline) | Upload signed audit report to R2 | `host_upload_inline()` in plugin.py |\n| `host/uploadFile` (negotiate+confirm) | Stream large audit reports to R2 | `host_upload_negotiate()` and `host_upload_confirm()` |\n| `embeddings/create` | Compute dense vectors for legal clause matching | `embed_texts()` in plugin.py |\n| `image/generate` | Generate visual contract comparison/risk diagrams | `image_generate()` in plugin.py |\n| `image/edit` | restyle/annotate scanned contract images | `image_edit()` in plugin.py |\n| `files/upload_begin + complete` | Durable contract vault uploads (2-phase) | `files_upload()` in plugin.py |\n| `files/download_url` | Presigned retrieval link for contract vault | `files_download_url()` in plugin.py |\n| `files/list` | List items in contract vault | `files_list()` in plugin.py |\n| `files/delete` | Delete contract vault entries | `files_delete()` in plugin.py |\n| `agent/complete` | Stateless L1 completion | `agent_complete()` in plugin.py |\n| `agent/session.create + run + history + cancel + delete` | Stateful L2 multi-turn agent sessions | `agent_session_create()`, `agent_session_run()`, etc. |\n\n### Host Capabilities Declared\n\n| Capability | Usage |\n|---|---|\n| `llm.sample` | Host-brokered LLM for contract clause analysis \u0026 completion |\n| `llm.embed` | Vector embedding compute for semantic clause matching |\n| `llm.image` | DALL-E contract comparison diagram generation |\n| `llm.image.edit` | Image contract scan overlays |\n| `llm.agent.auto` | Stateful multi-turn L2 agent sessions |\n| `aps.kv` | Persistent audit trail (last 50 audits) |\n| `host.upload` | R2 upload for signed redline documents |\n\n### Manifest Features (Schema 2)\n\n| Feature | Status |\n|---|---|\n| `schema: 2` | ✅ |\n| `host_capabilities` | ✅ `llm.sample`, `llm.embed`, `llm.image`, `llm.image.edit`, `llm.agent.auto`, `aps.kv`, `host.upload` |\n| `user_message_prefix_template` | ✅ |\n| `system_prompt_addendum` | ✅ |\n| `optional_executas` | ✅ |\n| `csp_overrides` | ✅ |\n| `state_merge` | ✅ |\n| `dev.fixtures` | ✅ |\n| `dev.seed_storage` | ✅ |\n| `host_api.upload` (negotiate + confirm) | ✅ |\n| `host_api.chat` (write_message + append_artifact) | ✅ |\n| `host_api.storage` (get/set/delete/list) | ✅ |\n| `host_api.window` (set_title/open_view/close) | ✅ |\n| `host_api.llm` (complete/embed) | ✅ |\n| `host_api.image` (generate) | ✅ |\n| `host_api.agent` (session) | ✅ |\n| Multiple views with `min_size`/`max_size` | ✅ 2 views |\n| Developer Console | ✅ Interactive SDK playground \u0026 live log console |\n| `tags` | ✅ |\n\n### Cryptographic Security\n\n| Layer | Algorithm |\n|---|---|\n| Session envelopes | AES-GCM-256 (ephemeral per-clause keys) |\n| Audit signatures | Ed25519 (persistent key in `.redpen_key`) |\n\n---\n\n## 📁 Project Structure\n\n```\ndorahacks-anna-redpen/\n├── app.json                    # App listing metadata\n├── manifest.json               # Anna App manifest (schema: 2)\n├── LICENSE                     # MIT License\n├── DECISIONS.md                # Architectural decisions log\n├── SPONSOR_DEFENSE.md          # SDK integration citations\n├── package.json                # Project script definitions\n├── bundle/\n│   ├── index.html              # Frontend SPA structure\n│   ├── styles.css              # Modern Linear dark theme\n│   ├── app.js                  # State engine, SDK bridge \u0026 fallback mocks\n│   ├── anna-tool-ids.js        # Auto-generated tool bindings\n│   ├── apple-touch-icon.png    # Mobile browser bookmark icon\n│   └── icon.svg                # Embedded app icon\n├── executas/\n│   └── redpen/\n│       ├── pyproject.toml      # Executa package configuration\n│       ├── executa.json        # Executa config (host_capabilities, distribution)\n│       ├── plugin.py           # Stdio JSON-RPC handler + APS KV + R2 upload\n│       └── crypto_helper.py    # AES-GCM and Ed25519 engines\n├── fixtures/\n│   └── seed.jsonl              # Dev fixture data for offline testing\n├── data/\n│   └── fixtures/\n│       └── contract_seed.jsonl # Seed agreement with 5 risk flags\n├── docs/\n│   ├── AUDIT_REPORT.md         # Threat model and invariants\n│   ├── friction-log.md         # Integration friction log\n│   ├── icon.svg                # Document icon\n│   ├── readme-hero.svg         # Tactical vector header SVG\n│   ├── assets/                 # HTML templates and asset generators\n│   └── screenshots/            # Step-by-step UX walkthrough screenshots\n├── public/\n│   ├── apple-touch-icon.png    # Public bookmark icon\n│   ├── icon.svg                # Standalone app icon SVG\n│   ├── og-image.png            # Open Graph banner PNG\n│   └── pitch.html              # Standalone marketing pitch deck HTML\n├── scripts/\n│   ├── bench.py                # Latency and recall benchmarks\n│   ├── verify_offline.py       # Air-gapped container test\n│   └── record-redpen.mjs       # Puppeteer demo recording\n└── tests/\n    └── test_plugin.py          # Complete unit tests (100% offline coverage)\n```\n\n---\n\n## 🚀 Getting Started\n\n### Prerequisites\n- Python ≥ 3.10\n- Node.js ≥ 20\n\n### Installation\n1. Clone the repository:\n   ```bash\n    git clone https://github.com/edycutjong/redpen.git\n    cd redpen\n   ```\n2. Set up virtual environment and install standard modules:\n   ```bash\n   python3 -m venv venv\n   source venv/bin/activate\n   pip install -e executas/redpen/\n   ```\n3. Install npm dependencies:\n   Installs the required `@anna-ai/cli` devDependency locally:\n   ```bash\n   npm install\n   ```\n\nTo run inside the Anna local developer harness:\n```bash\nnpm run dev\n# or\nnpx anna-app dev .\n```\n\n---\n\n## 🧪 Testing, Latency \u0026 Verification Gates\n\nRedPen runs a multi-stage quality gate covering code health, cryptographic reliability, latency, and air-gapped security.\n\n```bash\n# ── Run Unit Tests ────────────────────────────\npython3 tests/test_plugin.py\n\n# ── Run Latency \u0026 Recall Benchmarks ───────────\npython3 scripts/bench.py\n\n# ── Run Air-Gapped Offline Verification ────────\npython3 scripts/verify_offline.py\n```\n\n### Verification Gate Status\n| Target Gate | Metric / Tool | Status |\n|---|---|---|\n| **Code Quality** | unit-tests (14 suites) | ✅ Passing |\n| **Encryption** | AES-GCM-256 session envelope | ✅ Verified |\n| **Signatures** | Ed25519 verification checks | ✅ Verified |\n| **Recall Rate** | 100% recall on the 5 critical seeds | ✅ 5 / 5 Detected |\n| **Latency Gate** | Clause parsing latency (0.2ms) | ✅ Passed (Target \u003c800ms) |\n| **Offline Check** | verify_offline (socket-mocked) | ✅ Passed (Zero-net) |\n\n---\n\n## 📄 License\n\nDistributed under the MIT License. See [LICENSE](LICENSE) for more information.\n\n---\n\n## 🙏 Acknowledgments\n\nBuilt for the **Anna AI-Native App Hackathon 2026**. Thank you to DoraHacks and the Anna team for the development primitives and smart sandbox environment.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fedycutjong%2Fredpen","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fedycutjong%2Fredpen","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fedycutjong%2Fredpen/lists"}