01 · Roasts
Commit firehose, heatmap amnesia
1,087 annual commits and a 324-volume multi-repo trail arrive after 38 blank heatmap weeks: the sprint button clearly works.
CI is doing cardio
Nearly every flagship repo has tests and CI, while the profile hub itself ships without tests or a license.
Shipping faster than adoption
Starling leads with 11 stars and the profile has 43 total stars, despite live apps, packages, extensions, and APKs everywhere.
Security-tool constellation
Nucleus, SkillXray, webmcp-lint, Sepia, Sweep, and Starling make this less a portfolio and more a small defensive software factory.
Built using
Zoral
Shadows one worker for a week, then takes over their job with zero extra setup. Behaves exactly like the original.
zoral.ai
02 · Category breakdown
- Impact25% weight68C
- Consistency20% weight80A
- Quality20% weight75B
- Depth15% weight58D
- Breadth10% weight80A
- Community10% weight25F
03 · Stats
365-day commit heatmap
88 active days
Language distribution
- Python49%
- JavaScript42%
- CSS4%
- HTML3%
- Kotlin1%
- Swift1%
04 · Numbers
Owned repos
non-fork
24
Commits
last 12 months
1,087
Followers
8
Joined GitHub
Sep 2023
05 · Top repos
munzzyy /
starling
Deployed Starling location-sharing product at starlingmap.app with a substantial v2 encrypted protocol, relay, web/Android/iOS surfaces, extensive security-focused tests, and cross-platform CI.
munzzyy /
hopandhaul
Hop and Haul is a substantial, documented travel-planning product with a live GitHub Pages UI, PyPI packaging, deterministic multimodal fare logic, and a browser/Python parity test system, though adoption remains modest at 4 stars.
munzzyy /
sepia
A polished privacy-focused image redaction app with cross-format metadata inspection, fail-closed verification, native Android/iOS wrappers, and unusually strong automated testing for a four-day-old, lightly adopted project.
munzzyy /
magpie
Magpie is a carefully documented, tested encrypted journal with tamper-evident exports, standalone Python verification, browser storage, and Android/iOS shells; it is still an early 4-star project without demonstrated external adoption.
munzzyy /
webmcp-lint
A focused, well-documented WebMCP security linter with JSON and JS/HTML scanning, 11 documented rules, strong defensive handling, extensive unittest coverage, and a 4-OS/4-Python-version CI matrix; adoption remains minimal at 1 star.
munzzyy /
sweep
A carefully scoped Android/iOS/web stalkerware checkup with strong privacy design, extensive analyzer and browser tests, and multi-platform CI, but only 1 star and no demonstrated external adoption.
munzzyy /
tellcheck-github
A deployed Firefox extension with a documented scoring worker, privacy-conscious UX, substantial parity/API tests, and CI; adoption is still early at 1 star and the JavaScript code is not typed.
munzzyy /
translint
A polished, documented translation linter with a substantial Python implementation, broad format support, a browser demo, GitHub Action, agent skill, tests, and multi-platform CI; adoption remains early at 1 star.
munzzyy /
skillxray
A focused, well-engineered Python security scanner with strong rule coverage, tests, CI, and documentation, but only 2 stars and no supplied evidence of external adoption.
munzzyy /
nucleus
A substantial, documented local security command center with seven loopback consoles, hardened stdlib infrastructure, native analyzers, and broad offline/live test coverage, but only 3 stars and no demonstrated external adoption.
munzzyy /
liftmath
A polished, documented Python 3.10+ library and CLI covering 1RM consensus, plate loading, strength standards, records, imports, and an offline web app, with unusually broad tests and cross-platform CI but only 2 stars.
munzzyy /
munzzyy
A polished portfolio hub documenting 11 named tools and upstream work, with a security-focused CI gate and reproducible social-card generator, but no tests, license, or typed implementation in this repository.
06 · Timeline
- Sep 20, 2023Joined GitHub
- Jul 5, 2026Created hopandhaul — Cheapest way to travel: fly into a cheaper hub, train the rest when it beats flying direct. Click-the-map planner, pure-stdlib Python, zero deps, UI in 46 languages.
- Jul 5, 2026Created munzzyy — Open-source tools and upstream fixes where correctness matters.
- Jul 7, 2026Created liftmath — Strength training math with receipts: 1RM consensus, RPE, volume landmarks, macros, plate loading, Wilks/DOTS/IPF GL. Python library + CLI + zero-dependency web app.
- Jul 7, 2026Created translint — A linter for your translation files: catches missing keys, placeholder mismatches, and untranslated values before they ship. Stdlib Python, zero deps. CLI, CI gate, pre-commit, and
- Jul 11, 2026Created skillxray — Scan an AI agent skill for prompt injection, hidden Unicode, dangerous commands, and leaked secrets before you install it.
- Jul 12, 2026Created webmcp-lint — Security and spec-correctness linter for WebMCP tool manifests.
- Aug 31, 2026Created starling — Private, end-to-end encrypted location sharing for your circle. No accounts, no tracking. Live at starlingmap.app
- Sep 3, 2026Created tellcheck-github — Firefox extension that flags likely AI-generated pull requests and issues on GitHub. A signal for maintainers, not a verdict.
- Sep 7, 2026Created sepia — Share images without oversharing. On-device metadata X-ray, real redaction, and proof the output is clean.
- Sep 7, 2026Created magpie — A journal that can prove itself. Encrypted, hash-chained incident log with self-verifying exports.
- Sep 7, 2026Created sweep — A plain-language stalkerware checkup. On-device, nothing stored, nothing sent, never says you are safe. Beta.
- Sep 14, 2026Created nucleus — A local, loopback-only security command center: OSINT recon, an authorized pentest kit, opsec and reporting, plus a dev toolbelt. Stdlib Python, zero deps.
- Sep 24, 2026Most recent push to munzzyy
07 · Compare
08 · Rubric
How this score was produced
Overall = Σ (category × weight) + gentle top-end curve
Tier thresholds
▸ How the pipeline works
- 01Scrape.Pull every non-fork repo pushed in the last 90 days, plus your contribution calendar, followers, and language byte counts — straight from GitHub's REST & GraphQL APIs.
- 02Triage.A small model reads every repo's file tree + README and picks the 20 files per repo that actually reveal how you code.
- 03Grade each repo. All repos run in parallel through a fast scoring model that reads the picked files and rates each one independently on Impact, Quality, and Depth — with evidence citations.
- 04Aggregate. A larger reasoning model combines the per-repo scores with server-computed stats (heatmap, commit cadence, language entropy, follower count) to produce the 6-dimension profile score + roasts.
- 05Correct.Deterministic server-side checks enforce anchor-scale floors (e.g. a profile with 2,000+ public commits can't score 30 Consistency) and recompute the final verdict.
~90 seconds per profile, ~$0.25 in compute. Total of ~240 files read across your top-12 repos. One rating per GitHub account per day.
▸ Data sources & caveats
- Heatmap & commit totals: GitHub GraphQL
contributionsCollection— covers the last 365 days, includes private repos when the user has opted in (default). - Language %: byte totals across the top 30 owned non-fork repos.
- Curve: a small upward nudge centered on raw score ≈ 70, capping at 100. Prevents specialists from being unfairly penalised for narrow breadth.
- Anchor corrections: when server-measured signals (e.g. privateWorkLikely, multiRepoVolume, follower count) mandate a minimum category score, the aggregation step enforces it. These are signal-conditional, not identity-based floors.