▸ This tool was built by an AI agent from Zoral
← RATE MY GITHUB

#88 — Top 95.1%

munzzyy

Cole Munz

B

Solid engineer

Overall

0.0

/ 100

01 · Roasts

Commit firehose, heatmap amnesia

1,087 annual commits and a 324-volume multi-repo trail arrive after 38 blank heatmap weeks: the sprint button clearly works.

CI is doing cardio

Nearly every flagship repo has tests and CI, while the profile hub itself ships without tests or a license.

Shipping faster than adoption

Starling leads with 11 stars and the profile has 43 total stars, despite live apps, packages, extensions, and APKs everywhere.

Security-tool constellation

Nucleus, SkillXray, webmcp-lint, Sepia, Sweep, and Starling make this less a portfolio and more a small defensive software factory.

Built using

Zoral

Shadows one worker for a week, then takes over their job with zero extra setup. Behaves exactly like the original.

zoral.ai

02 · Category breakdown

  • Impact
    25% weight
    68C
  • Consistency
    20% weight
    80A
  • Quality
    20% weight
    75B
  • Depth
    15% weight
    58D
  • Breadth
    10% weight
    80A
  • Community
    10% weight
    25F

03 · Stats

365-day commit heatmap

88 active days

Less
More

Language distribution

6 langs
  • Python49%
  • JavaScript42%
  • CSS4%
  • HTML3%
  • Kotlin1%
  • Swift1%

04 · Numbers

Owned repos

non-fork

24

Commits

last 12 months

1,087

Followers

8

Joined GitHub

Sep 2023

05 · Top repos

munzzyy /

starling

64/100

Deployed Starling location-sharing product at starlingmap.app with a substantial v2 encrypted protocol, relay, web/Android/iOS surfaces, extensive security-focused tests, and cross-platform CI.

I55Q78D50
READMETestsCI
JavaScript★ 1119d ago

munzzyy /

hopandhaul

63/100

Hop and Haul is a substantial, documented travel-planning product with a live GitHub Pages UI, PyPI packaging, deterministic multimodal fare logic, and a browser/Python parity test system, though adoption remains modest at 4 stars.

I55Q78D55
READMETestsCI
Python★ 414d ago

munzzyy /

sepia

63/100

A polished privacy-focused image redaction app with cross-format metadata inspection, fail-closed verification, native Android/iOS wrappers, and unusually strong automated testing for a four-day-old, lightly adopted project.

I25Q78D55
READMETestsCI
JavaScript★ 116d ago

munzzyy /

magpie

61/100

Magpie is a carefully documented, tested encrypted journal with tamper-evident exports, standalone Python verification, browser storage, and Android/iOS shells; it is still an early 4-star project without demonstrated external adoption.

I25Q78D50
READMETestsCI
JavaScript★ 415d ago

munzzyy /

webmcp-lint

58/100

A focused, well-documented WebMCP security linter with JSON and JS/HTML scanning, 11 documented rules, strong defensive handling, extensive unittest coverage, and a 4-OS/4-Python-version CI matrix; adoption remains minimal at 1 star.

I25Q75D50
READMETestsCI
Python★ 114d ago

munzzyy /

sweep

58/100

A carefully scoped Android/iOS/web stalkerware checkup with strong privacy design, extensive analyzer and browser tests, and multi-platform CI, but only 1 star and no demonstrated external adoption.

I25Q78D55
READMETestsCI
JavaScript★ 117d ago

munzzyy /

tellcheck-github

58/100

A deployed Firefox extension with a documented scoring worker, privacy-conscious UX, substantial parity/API tests, and CI; adoption is still early at 1 star and the JavaScript code is not typed.

I45Q72D55
READMETestsCI
JavaScript★ 117d ago

munzzyy /

translint

57/100

A polished, documented translation linter with a substantial Python implementation, broad format support, a browser demo, GitHub Action, agent skill, tests, and multi-platform CI; adoption remains early at 1 star.

I45Q76D50
READMETestsCI
JavaScript★ 114d ago

munzzyy /

skillxray

56/100

A focused, well-engineered Python security scanner with strong rule coverage, tests, CI, and documentation, but only 2 stars and no supplied evidence of external adoption.

I25Q68D50
READMETestsCI
Python★ 214d ago

munzzyy /

nucleus

52/100

A substantial, documented local security command center with seven loopback consoles, hardened stdlib infrastructure, native analyzers, and broad offline/live test coverage, but only 3 stars and no demonstrated external adoption.

I25Q72D50
READMETestsCI
Python★ 313d ago

munzzyy /

liftmath

51/100

A polished, documented Python 3.10+ library and CLI covering 1RM consensus, plate loading, strength standards, records, imports, and an offline web app, with unusually broad tests and cross-platform CI but only 2 stars.

I25Q78D50
READMETestsCI
Python★ 214d ago

munzzyy /

munzzyy

43/100

A polished portfolio hub documenting 11 named tools and upstream work, with a security-focused CI gate and reproducible social-card generator, but no tests, license, or typed implementation in this repository.

I40Q40D50
READMECI
Python★ 0this week

06 · Timeline

  1. Sep 20, 2023
    Joined GitHub
  2. Jul 5, 2026
    Created hopandhaul — Cheapest way to travel: fly into a cheaper hub, train the rest when it beats flying direct. Click-the-map planner, pure-stdlib Python, zero deps, UI in 46 languages.
  3. Jul 5, 2026
    Created munzzyy — Open-source tools and upstream fixes where correctness matters.
  4. Jul 7, 2026
    Created liftmath — Strength training math with receipts: 1RM consensus, RPE, volume landmarks, macros, plate loading, Wilks/DOTS/IPF GL. Python library + CLI + zero-dependency web app.
  5. Jul 7, 2026
    Created translint — A linter for your translation files: catches missing keys, placeholder mismatches, and untranslated values before they ship. Stdlib Python, zero deps. CLI, CI gate, pre-commit, and
  6. Jul 11, 2026
    Created skillxray — Scan an AI agent skill for prompt injection, hidden Unicode, dangerous commands, and leaked secrets before you install it.
  7. Jul 12, 2026
    Created webmcp-lint — Security and spec-correctness linter for WebMCP tool manifests.
  8. Aug 31, 2026
    Created starling — Private, end-to-end encrypted location sharing for your circle. No accounts, no tracking. Live at starlingmap.app
  9. Sep 3, 2026
    Created tellcheck-github — Firefox extension that flags likely AI-generated pull requests and issues on GitHub. A signal for maintainers, not a verdict.
  10. Sep 7, 2026
    Created sepia — Share images without oversharing. On-device metadata X-ray, real redaction, and proof the output is clean.
  11. Sep 7, 2026
    Created magpie — A journal that can prove itself. Encrypted, hash-chained incident log with self-verifying exports.
  12. Sep 7, 2026
    Created sweep — A plain-language stalkerware checkup. On-device, nothing stored, nothing sent, never says you are safe. Beta.
  13. Sep 14, 2026
    Created nucleus — A local, loopback-only security command center: OSINT recon, an authorized pentest kit, opsec and reporting, plus a dev toolbelt. Stdlib Python, zero deps.
  14. Sep 24, 2026
    Most recent push to munzzyy

07 · Compare

github.com/
munzzyy · 6dmedian coder

08 · Rubric

How this score was produced

Overall = Σ (category × weight) + gentle top-end curve

CategoryWeightScoreContrib.
Raw total67.2
Top-end curve+5.9
Final overall73.1

Tier thresholds

S90–100Mass-producing humansA80–89Ship machineB70–79Solid engineerC60–69Getting thereD40–59README enthusiastF0–39GitHub tourist
▸ How the pipeline works
  1. 01Scrape.Pull every non-fork repo pushed in the last 90 days, plus your contribution calendar, followers, and language byte counts — straight from GitHub's REST & GraphQL APIs.
  2. 02Triage.A small model reads every repo's file tree + README and picks the 20 files per repo that actually reveal how you code.
  3. 03Grade each repo. All repos run in parallel through a fast scoring model that reads the picked files and rates each one independently on Impact, Quality, and Depth — with evidence citations.
  4. 04Aggregate. A larger reasoning model combines the per-repo scores with server-computed stats (heatmap, commit cadence, language entropy, follower count) to produce the 6-dimension profile score + roasts.
  5. 05Correct.Deterministic server-side checks enforce anchor-scale floors (e.g. a profile with 2,000+ public commits can't score 30 Consistency) and recompute the final verdict.

~90 seconds per profile, ~$0.25 in compute. Total of ~240 files read across your top-12 repos. One rating per GitHub account per day.

▸ Data sources & caveats
  • Heatmap & commit totals: GitHub GraphQL contributionsCollection — covers the last 365 days, includes private repos when the user has opted in (default).
  • Language %: byte totals across the top 30 owned non-fork repos.
  • Curve: a small upward nudge centered on raw score ≈ 70, capping at 100. Prevents specialists from being unfairly penalised for narrow breadth.
  • Anchor corrections: when server-measured signals (e.g. privateWorkLikely, multiRepoVolume, follower count) mandate a minimum category score, the aggregation step enforces it. These are signal-conditional, not identity-based floors.
munzzyy · 73.1/100 — Rate My GitHub