{"id":51699100,"url":"https://github.com/edycutjong/shipghost","last_synced_at":"2026-07-16T08:33:46.468Z","repository":{"id":366444077,"uuid":"1276306439","full_name":"edycutjong/shipghost","owner":"edycutjong","description":"👻 Confidential Git PR Ghostwriter and Cryptographic Release Automator built for the Anna Hackathon","archived":false,"fork":false,"pushed_at":"2026-06-23T00:06:29.000Z","size":728,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-16T08:33:44.906Z","etag":null,"topics":["anna-app","git-agent","hackathon","security"],"latest_commit_sha":null,"homepage":"https://edycutjong.github.io/shipghost/public/pitch.html","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/edycutjong.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-06-21T20:11:14.000Z","updated_at":"2026-06-23T00:06:32.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/edycutjong/shipghost","commit_stats":null,"previous_names":["edycutjong/shipghost"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/edycutjong/shipghost","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fshipghost","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fshipghost/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fshipghost/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fshipghost/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/edycutjong","download_url":"https://codeload.github.com/edycutjong/shipghost/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/edycutjong%2Fshipghost/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35537751,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-16T02:00:06.687Z","response_time":83,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["anna-app","git-agent","hackathon","security"],"created_at":"2026-07-16T08:33:45.528Z","updated_at":"2026-07-16T08:33:46.459Z","avatar_url":"https://github.com/edycutjong.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n  \u003cimg src=\"docs/icon.svg\" alt=\"ShipGhost Icon\" width=\"140\"\u003e\n  \u003ch1\u003eShipGhost 👻\u003c/h1\u003e\n  \u003cp\u003e\u003cem\u003eGit PR Ghostwriter — Encrypted diff analysis, conventional commit cleanup, GPG clearsigning, APS KV persistence, and R2 upload\u003c/em\u003e\u003c/p\u003e\n  \u003cimg src=\"docs/readme-hero.svg\" alt=\"ShipGhost Hero Banner\" width=\"100%\"\u003e\n\n  \u003cbr/\u003e\n\n  [![Live Demo](https://img.shields.io/badge/🚀_Live-Demo-06b6d4?style=for-the-badge)](https://github.com/edycutjong/shipghost)\n  [![Pitch Video](https://img.shields.io/badge/🎬_Pitch-Video-ef4444?style=for-the-badge)](https://youtu.be/d-Tq3Fl8agc)\n  [![Pitch Deck](https://img.shields.io/badge/📊_Pitch-Deck-f59e0b?style=for-the-badge)](https://edycutjong.github.io/shipghost/public/pitch.html)\n  [![Built for Anna AI-Native Hackathon](https://img.shields.io/badge/DoraHacks-Anna_Hackathon-8b5cf6?style=for-the-badge)](https://dorahacks.io/hackathon/2204)\n\n  \u003cbr/\u003e\n\n  ![Python 3.11](https://img.shields.io/badge/Python_3.11-3776AB?style=flat\u0026logo=python\u0026logoColor=white)\n  ![Node.js 22](https://img.shields.io/badge/Node.js_22-339933?style=flat\u0026logo=nodedotjs\u0026logoColor=white)\n  ![AES-GCM-256](https://img.shields.io/badge/Crypto-AES--GCM--256-blue?style=flat)\n  ![GPG Clearsigned](https://img.shields.io/badge/Crypto-GPG_Clearsigned-success?style=flat)\n  ![Anna Storage](https://img.shields.io/badge/Anna-APS_KV_Storage-10b981?style=flat)\n  ![R2 Upload](https://img.shields.io/badge/Anna-R2_Object_Upload-f59e0b?style=flat)\n  [![CI/CD Pipeline](https://github.com/edycutjong/shipghost/actions/workflows/ci.yml/badge.svg)](https://github.com/edycutjong/shipghost/actions)\n\n\u003c/div\u003e\n\n---\n\n## 📸 See it in Action\n\n\u003cdiv align=\"center\"\u003e\n  \u003ch3\u003eInteractive PR Walkthrough\u003c/h3\u003e\n  \n  \u003ctable\u003e\n    \u003ctr\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e1. Workspace Config \u0026 Setup\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/01-input-view.png\" alt=\"1. Setup\" width=\"100%\"\u003e\n      \u003c/td\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e2. Casper x402 Micropayment\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/02-payment-modal.png\" alt=\"2. Payment\" width=\"100%\"\u003e\n      \u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e3. PR Analysis Dashboard\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/03-dashboard-view.png\" alt=\"3. Dashboard\" width=\"100%\"\u003e\n      \u003c/td\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e4. Suggested Inline Comments\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/04-dashboard-tab2.png\" alt=\"4. Comments\" width=\"100%\"\u003e\n      \u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e5. Interactive Developer Console\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/08-console-session-turn.png\" alt=\"5. Developer Console\" width=\"100%\"\u003e\n      \u003c/td\u003e\n      \u003ctd width=\"50%\"\u003e\n        \u003cp align=\"center\"\u003e\u003cb\u003e6. GPG Clearsigned R2 Export\u003c/b\u003e\u003c/p\u003e\n        \u003cimg src=\"docs/screenshots/09-exported-r2.png\" alt=\"6. Export\" width=\"100%\"\u003e\n      \u003c/td\u003e\n    \u003c/tr\u003e\n  \u003c/table\u003e\n\u003c/div\u003e\n\n\u003e **The ShipGhost Workflow**: Specify git repository branch → Request analysis \u0026 pay Casper x402 micro-fee → Review side-by-side changes \u0026 suggested inline comments → Clean up commit logs interactively via Anna Developer Console → Persist history to Anna KV → Clearsign output bundle and upload to Cloudflare R2.\n\n\n---\n\n## 💡 The Problem \u0026 Solution\n\n### The Problem\nPull Requests are critical codebase documents, but writing them is tedious. Developers working under pressure often push dozens of messy commits (`wip`, `fix`, `stuff`) and open blank PR descriptions. Code reviewers waste hours reverse-engineering intent, leading to knowledge debt.\n\n### The Solution\n**ShipGhost** is a secure, AI-native Anna application that analyzes your local git branch history, groups modified files into architectural components, and drafts a professional PR package (Title, Summary, Changes List, Architecture Rationale, and Suggested Inline Comments).\n\nTo protect corporate IP, **diff payloads are encrypted under a 256-bit AES key** before leaving your machine, and final exports are **cryptographically clearsigned** using local GPG/SSH keys.\n\n**Key Features:**\n- ⚡ **Git Analysis Engine**: Walks local git diffs, stats, and logs for any repository branch.\n- 🔒 **AES-GCM-256 Encryption**: Diff payloads are encrypted before LLM inference.\n- 🤖 **AI PR Ghostwriter**: Generates professional PR title, description, rationale, testing instructions, and inline review comments.\n- 🧹 **Conventional Commit Cleanup**: Rewrites messy commit messages into proper conventional format.\n- ✍️ **GPG/SSH Clearsigning**: Cryptographic clearsigning of final PR description with local keys.\n- 💾 **Persistent PR History**: Every generated PR draft is persisted to Anna APS KV — tracks titles, file changes, and timestamps across sessions.\n- 📦 **R2 Signed Artifact Upload**: Clearsigned PR markdown is uploaded to Anna's R2 bucket via `host/uploadFile`, returning a shareable download URL.\n\n---\n\n## 🏗️ Architecture \u0026 Tech Stack\n\n| Layer | Technology | Rationale |\n|---|---|---|\n| **App Runtime** | Anna App Runtime (Schema 2) | Native integration with host permissions |\n| **Frontend UI** | Vanilla HTML5 / CSS Glassmorphism | Fast rendering, no compile step |\n| **Backend Plugin** | Python 3.11 Executa | Accesses local git subprocesses |\n| **Cryptographic** | PyCryptodome (AES-GCM-256) | Heavyweight local encryption |\n| **Signatures** | GPG/SSH (ED25519 fallback) | Tamper-proof PR clearsigning |\n| **Persistent State** | Anna APS KV (`storage/get`, `storage/set`) | PR draft history (last 50 entries) |\n| **Artifact Storage** | Anna R2 (`host/uploadFile`) | Signed PR markdown distribution |\n\n### Data Flow Diagram\n\n```mermaid\ngraph TD\n    UI[Frontend SPA - index.html] --\u003e|tools.invoke| Exec[Python Executa Plugin]\n    Exec --\u003e|git subprocess| Git[Local Git Repository]\n    Git --\u003e|return diffs \u0026 logs| Exec\n    Exec --\u003e|AES-GCM-256 encrypt| Crypto[Crypto Engine]\n    Exec --\u003e|reverse-RPC: sampling/createMessage| Host[Host LLM Agent]\n    Host --\u003e|return PR content \u0026 suggestions| Exec\n    Exec --\u003e|storage/set| APS[Anna APS KV - PR History]\n    Exec --\u003e|format review queue| UI\n    UI --\u003e|GPG Clearsign request| Exec\n    Exec --\u003e|gpg clearsign| GPG[Local GPG Agent]\n    Exec --\u003e|host/uploadFile| R2[Anna R2 Storage]\n```\n\n---\n\n## 🔌 Anna Platform Integration\n\nShipGhost exercises the full Anna SDK capability surface:\n\n### Reverse-RPC Methods (Plugin → Host)\n\n| Method | Purpose | Implementation |\n|---|---|---|\n| `sampling/createMessage` | LLM inference for PR draft generation \u0026 commit cleanup | `call_host()` in plugin.py |\n| `storage/get` | Read persistent PR draft history from APS KV | `storage_get()` in plugin.py |\n| `storage/set` | Write PR history entries to APS KV | `storage_set()` in plugin.py |\n| `storage/delete` | Remove PR entries from APS KV | `storage_delete_key()` in plugin.py |\n| `storage/list` | List all past PR keys in APS KV | `storage_list_keys()` in plugin.py |\n| `host/uploadFile` (inline) | Upload signed PR markdown to R2 | `host_upload_inline()` in plugin.py |\n| `host/uploadFile` (negotiate+confirm) | Stream large PR markdown reports to R2 | `host_upload_negotiate()` and `host_upload_confirm()` |\n| `embeddings/create` | Compute dense vectors for commit message clustering | `embed_texts()` in plugin.py |\n| `image/generate` | Generate visual architecture/impact diagrams | `image_generate()` in plugin.py |\n| `files/upload_begin + complete` | Durable PR archive uploads (2-phase) | `files_upload()` in plugin.py |\n| `files/download_url` | Presigned retrieval link for PR archive | `files_download_url()` in plugin.py |\n| `files/list` | List items in PR archive | `files_list()` in plugin.py |\n| `files/delete` | Delete PR archive entries | `files_delete()` in plugin.py |\n| `agent/complete` | Stateless L1 completion | `agent_complete()` in plugin.py |\n| `agent/session.create + run + history + cancel + delete` | Stateful L2 multi-turn agent sessions | `agent_session_create()`, `agent_session_run()`, etc. |\n\n### Host Capabilities Declared\n\n| Capability | Usage |\n|---|---|\n| `llm.sample` | Host-brokered LLM for PR drafting \u0026 completion |\n| `llm.embed` | Vector embedding compute for commit message clustering |\n| `llm.image` | DALL-E impact diagram generation |\n| `llm.agent.auto` | Stateful multi-turn L2 agent sessions |\n| `aps.kv` | Persistent PR history (last 50 drafts) |\n| `host.upload` | R2 upload for clearsigned PR markdown |\n\n### Manifest Features (Schema 2)\n\n| Feature | Status |\n|---|---|\n| `schema: 2` | ✅ |\n| `host_capabilities` | ✅ `llm.sample`, `llm.embed`, `llm.image`, `llm.agent.auto`, `host.upload` |\n| `user_message_prefix_template` | ✅ |\n| `system_prompt_addendum` | ✅ |\n| `optional_executas` | ✅ |\n| `csp_overrides` | ✅ |\n| `state_merge` | ✅ |\n| `dev.fixtures` | ✅ |\n| `dev.seed_storage` | ✅ |\n| `host_api.upload` (negotiate + confirm) | ✅ |\n| `host_api.chat` (write_message + append_artifact) | ✅ |\n| `host_api.storage` (get/set/delete/list) | ✅ |\n| `host_api.window` (set_title/open_view/close) | ✅ |\n| `host_api.llm` (complete/embed) | ✅ |\n| `host_api.image` (generate) | ✅ |\n| `host_api.agent` (session) | ✅ |\n| Multiple views with `min_size`/`max_size` | ✅ 3 views |\n| Developer Console | ✅ Interactive SDK playground \u0026 live log console |\n| `tags` | ✅ |\n| Typed `parameters` in `describe` | ✅ All 4 tools |\n\n### Cryptographic Security\n\n| Layer | Algorithm |\n|---|---|\n| Diff encryption | AES-GCM-256 (ephemeral session keys) |\n| PR signing | GPG clearsign / SSH-ED25519 fallback |\n| Symbol hashing | SHA-256 |\n\n---\n\n## 🏆 Sponsor Tracks Targeted\n\n1. **Anna AI-Native App**: Combines multiple iframe views (`main`, `inline_inspector`, `commit_cleaner`, `screen-console`) with real Executa tools and broad Anna Host-API usage — `tools.invoke`, `storage` (KV persistence), `chat.append_artifact`, `window` multi-view, and `upload` (R2).\n2. **Developer Usability Track**: Delivers full local GPG/SSH signatures, APS KV persistence, R2 presigned exports, and a real-time Developer Console playground.\n\n\n---\n\n## 📁 Project Structure\n\n```\ndorahacks-anna-shipghost/\n├── app.json                    # App listing metadata\n├── manifest.json               # Anna App manifest (schema: 2)\n├── LICENSE                     # MIT License\n├── SPONSOR_DEFENSE.md          # SDK integration citations\n├── package.json                # Project script definitions\n├── bundle/\n│   ├── index.html              # Frontend SPA structure\n│   ├── styles.css              # Glassmorphism dark theme\n│   ├── app.js                  # State engine, SDK bridge \u0026 fallback mocks\n│   ├── anna-tool-ids.js        # Auto-generated tool bindings\n│   ├── apple-touch-icon.png    # Mobile browser bookmark icon\n│   └── icon.svg                # Embedded app icon\n├── executas/\n│   └── shipghost/\n│       ├── pyproject.toml      # Executa package configuration\n│       ├── executa.json        # Executa config (host_capabilities, distribution)\n│       └── plugin.py           # Stdio JSON-RPC handler + AES + GPG + APS KV + R2\n├── fixtures/\n│   └── seed.jsonl              # Dev fixture data for offline testing\n├── data/\n│   └── fixtures/\n│       └── git_seed.jsonl      # Seed git diff data\n├── docs/\n│   ├── AUDIT_REPORT.md         # Threat model and invariants\n│   ├── friction-log.md         # Integration friction log\n│   ├── icon.svg                # Document icon\n│   ├── readme-hero.svg         # Tactical vector header SVG\n│   ├── assets/                 # HTML templates and asset generators\n│   └── screenshots/            # Step-by-step UX walkthrough screenshots\n├── public/\n│   ├── icon.svg                # Standalone app icon SVG\n│   ├── og-image.png            # Open Graph banner PNG\n│   └── pitch.html              # Standalone marketing pitch deck HTML\n├── scripts/\n│   ├── bench.py                # Latency and recall benchmarks\n│   ├── verify_offline.py       # Air-gapped container test\n│   └── record-shipghost.mjs    # Puppeteer demo recording\n└── tests/\n    └── test_plugin.py          # Complete unit tests (100% offline coverage)\n```\n\n---\n\n## 🚀 Getting Started\n\n### Prerequisites\n- Python ≥ 3.10\n- Node.js ≥ 20\n- Git\n\n### Installation \u0026 Setup\n\n1. **Clone the codebase**:\n   ```bash\n   git clone https://github.com/edycutjong/shipghost.git\n   cd shipghost\n   ```\n2. **Set up virtual environment**:\n   ```bash\n   python3 -m venv venv\n   source venv/bin/activate\n   pip install -e executas/shipghost\n   ```\n3. **Install npm dependencies**:\n   Installs the required `@anna-ai/cli` devDependency locally:\n   ```bash\n   npm install\n   ```\n5. **Run in Anna dev harness**:\n   ```bash\n   npm run dev\n   # or\n   npx anna-app dev .\n   ```\n\n---\n\n## 🧪 Testing \u0026 CI\n\nShipGhost utilizes a multi-stage CI pipeline verifying quality, cryptography, and offline safety.\n\n```bash\n# Run unit and integration tests (100+ assertions)\nPYTHONPATH=. python3 tests/test_plugin.py\n\n# Verify offline/air-gapped capability\npython3 scripts/verify_offline.py\n\n# Run performance and latency benchmarks\npython3 scripts/bench.py\n```\n\n| Layer | Tool | Status |\n|---|---|---|\n| Code Quality | Flake8 | ✅ Passing |\n| Unit Testing | 100+ parameterized assertions | ✅ Passing (100%) |\n| Security (SAST) | TruffleHog Secret Scanning | ✅ Passing |\n| Air-gap Audit | verify_offline.py (Socket blockers) | ✅ Passing |\n| Performance | bench.py (Diff walk latency checks) | ✅ Passing (\u003c30ms) |\n\n---\n\n## 📄 License\n\nThis project is licensed under the [MIT License](LICENSE) — see the LICENSE file for details.\n\n---\n\n## 🙏 Acknowledgments\nBuilt for the **Anna AI-Native App Hackathon 2026**. Special thanks to the Google DeepMind team.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fedycutjong%2Fshipghost","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fedycutjong%2Fshipghost","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fedycutjong%2Fshipghost/lists"}