Skip to content
hikarimingPublic

About

Discover the best developers — and become one. Drop a GitHub handle for a 0–100 value & trust score in 30s: see your gaps, discover top devs, get found. Exposes PR farmers, AI bots & fork-hoarders. Deterministic scoring, self-hostable.

Topics

Resources

Contributing

Stars

242 stars

Watchers

1 watching

Forks

Latest commit

 

History

993 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ghfind 🔥

Discover the best developers — and become one.

An evidence-based platform to find great developers, measure where you stand, and grow from there.

Start with a brutally honest 0–100 value & trust score on any public GitHub profile — see your gaps, learn where to go, then explore the strongest builders in your ecosystem, find worthy peers and rivals, and let your own work get discovered.

English · 中文

🔍 Score a GitHub profile · 🏆 Discover top developers · 🤖 Install GitHub Bot · ⭐ View source

ghfind developer profile preview

Measure. Grow. Discover.

📊 Know exactly where you stand in 30 seconds

Enter a GitHub handle to get a 0–100 value & trust score, a five-tier verdict (🏆 GOD / 🥇 ELITE / 💪 SOLID / 🫥 NPC / 💩 TRASH), and a brutally honest read grounded in public data. Six scoring dimensions and ten farming red flags separate sustained engineering work from star farming, fork hoarding, bots, and self-merged PRs — so the score tells you what's real and where to improve.

🧭 Discover the developers worth knowing

ghfind is a discovery engine, not just a scorer. Use the leaderboard and public profiles to find strong open-source contributors, builders in your ecosystem, potential collaborators, and the developers you want to measure yourself against — and let the right people find you.

ghfind developer leaderboard

🪪 Turn your GitHub work into a shareable identity

Every assessment can generate a live badge and light/dark developer card for your GitHub profile, project README, portfolio, or personal site. Here is a real example:

The scoring core comes from the open-source Claude skill github-account-value. This site ports its Python scoring logic line-by-line into TypeScript, with unit tests locking the two outputs in parity.

GitHub App: spend less time triaging, more time maintaining

Every issue asks for your attention. Get the author's context before you invest it.

Install ghfind Review to label new issues with the author's public ghfind score. Color-coded review: bands help you sort the queue without opening each profile first.

  • Build your review queue around score bands. Filter issues by review: labels and set your team's review priorities.
  • Make stronger profile signals stand out. Muted grey and light blue keep lower bands quiet; soft apricot and wheat mark higher bands.
  • Screen sources before deep review. Route low or missing scores into a manual source-check queue.

The current bands are fixed at 40, 70 and 90. The App labels issues and pull requests. It does not post conversation comments, or block and close submissions. A profile score is a starting point for review, not proof of contribution quality.

Start with one repository. Let the next issue arrive with a score label. Missing labels are created automatically; no workflow or repository secret is required.

Install GitHub App · English guide · 中文指南

How it works

browser ─▶ /api/scan ─▶ [Redis cache?] ─▶ lib/github.ts  (GitHub REST + GraphQL, operator PAT)
                                     └─▶ lib/score.ts   (deterministic scoring, parity with the Python skill)
                                     └─▶ write cache 24h
         ─▶ /api/roast (streaming) ─▶ LLM judge pass (bounded score calibration)
                                      └─▶ LLM writer pass (roast/report text only)
                                      └─▶ lib/llm.ts (OpenAI-compatible; defaults to StepFun; bring-your-own key)
  • The base score is deterministic — computed server-side by lib/score.ts.
  • The LLM runs in two separated passes: a factual judge may apply a bounded ±10 calibration, then a writer turns the fixed result into tags, the top roast line, and the report. The writer cannot change the score.
  • 6 dimensions (account maturity / original project quality / contribution quality / ecosystem impact / community influence / activity authenticity) + 10 farming red flags. Weights lean toward hard-to-fake signals (PRs merged into real repos, sustained activity) and discount buyable ones (stars, followers).
  • The site also includes share cards, README badges, profile comments, and GitHub-authenticated profile reactions.

ghfind API, MCP server & SDKs

Everything on the site is available programmatically — full reference at ghfind API documentation:

  • REST API — GET https://ghfind.com/api/score/{username} for a deterministic 0–100 score (no auth, no LLM); OpenAPI 3.1 spec at ghfind.com/openapi.json
  • MCP server — Streamable HTTP at ghfind.com/mcp; add it to Claude, Cursor, or any MCP client to score and compare GitHub accounts from inside the agent
  • SDKs — @hikariming/ghfind (npm) · ghfind (PyPI)
  • For AI agents — ghfind.com/llms.txt links every machine-readable surface

Local development

pnpm install
cp .env.example .env.local

pnpm dev uses Wrangler's local D1 emulator and never connects to Cloudflare or requires wrangler login. Local D1 state persists under .wrangler/state/v3. Apply the schema locally once before using database-backed features:

pnpm exec wrangler d1 migrations apply ghfind --local
pnpm exec wrangler d1 migrations apply ghfind-feed-dev --local

Set GITHUB_TOKEN in .env.local to enable higher GitHub API rate limits. LLM_API_KEY is additionally needed for operator-funded roast text, not for deterministic scanning and scoring.

pnpm dev

Always set GITHUB_TOKEN. Without a token, GitHub's GraphQL dimensions (contributions / activity / external contributions) all drop to zero (scores get badly underestimated), and REST is rate-limited to 60/h. A read-only PAT raises the limit to 5000/h and unlocks every dimension.

Commands

Command Description
pnpm dev Local development
pnpm start or pnpm build/start One-command production build + run
pnpm build / pnpm start:prod Build only / run an existing production build
pnpm cli:build Build the standalone ./bin/ghfind CLI (requires Go 1.23+)
pnpm test Vitest test suite (scoring, prompts, DB, UI helpers, reactions, etc.)
pnpm typecheck tsc --noEmit
pnpm lint ESLint

Agent CLI

The CLI is a thin remote wrapper around the public website APIs. It does not run GitHub scanning, scoring, or LLM logic locally.

Build the standalone binary with Go 1.23+ installed:

pnpm cli:build
./bin/ghfind commands --json
./bin/ghfind update check -o json
./bin/ghfind score hikariming -o json
./bin/ghfind roast hikariming --lang en -o markdown
./bin/ghfind leaderboard --view trending --window all -o json
./bin/ghfind developers --type language -o json

The standalone CLI is built as ./bin/ghfind. The separately published npm SDK also provides a ghfind executable; it is not installed by the root workspace.

The default service host is https://ghfind.com. Override it for local dev:

GHFIND_HOST=http://localhost:3000 ./bin/ghfind roast hikariming --lang en

GITHUB_ROAST_HOST is still accepted as a backward-compatible alias.

Production /api/scan uses Turnstile for browser calls. For agent/CLI calls, set GITHUB_ROAST_CLI_API_KEY on the server and pass the same value to the CLI as GHFIND_API_KEY or --api-key; the CLI sends it as Authorization: Bearer ... to the same /api/scan endpoint. GITHUB_ROAST_API_KEY remains a backward-compatible alias.

/api/scan checks machine auth or Turnstile before it reads the scan cache or uses the server GitHub token. If GITHUB_ROAST_CLI_API_KEY is not configured and Turnstile is enabled, an unauthenticated CLI request can fail before cache lookup, even when the server has a GitHub token and Redis cache.

Version/update management:

ghfind --version
ghfind update check -o json
ghfind update install --method binary --dry-run -o json
ghfind update install --method binary
ghfind update npm --dry-run -o json
ghfind update npm
ghfind update pip
ghfind update brew

update check compares the local CLI version with the latest GitHub release and prints update_available, latest_version, and release_url. It only reports; it never modifies the installed binary.

update install --method binary downloads the current platform's GitHub release asset, writes it next to the running binary, and replaces the local ghfind binary by rename. Use --dry-run first to inspect the selected asset and target path. Package-manager shortcuts run the matching upgrade command:

  • ghfind update npm: npm install -g @hikariming/ghfind@latest
  • ghfind update pip: python3 -m pip install --upgrade ghfind
  • ghfind update brew: brew upgrade ghfind

These commands modify the local installation only when explicitly invoked. They are not triggered by update check.

Connected website APIs:

  • scan / score: POST /api/scan, factual structured score data.
  • roast: POST /api/scan + POST /api/roast, web-facing roast report.
  • stats: GET /api/stats, platform aggregate metadata.
  • leaderboard: GET /api/leaderboard, cached ranking/discovery entries.
  • developers: GET /api/developers, language/org/repo discovery facets.

For agent decisions about one account, use scan or score; leaderboard and developer directory commands are discovery/catalog surfaces, not fresh scoring facts.

Environment variables

See .env.example. Local scanning requires GITHUB_TOKEN and a reachable database (TURSO_DATABASE_URL, plus TURSO_AUTH_TOKEN when the server requires authentication). A fresh scan must persist its result before it can succeed. Add LLM_API_KEY for operator-funded roast text (defaults to StepFun; OpenAI-compatible providers are supported). Redis caching/rate limiting, Turnstile, and GitHub OAuth are optional for local scanning; their configuration enables the corresponding features. A rendered homepage alone does not prove that scanning works. Production requires UPSTASH_REDIS_REST_URL + UPSTASH_REDIS_REST_TOKEN: when the limiter is unavailable, only protected uncached cost-bearing routes return 503 with Retry-After; edge-cached responses and ordinary browsing continue. RATE_LIMIT_FAIL_OPEN=1 is an emergency operator override and should not be set during normal operation.

Leaderboard + percentile (Cloudflare D1)

Production stores scores in the Cloudflare D1 GHFIND_D1 binding configured in wrangler.jsonc. Follow the Cloudflare deployment runbook to verify the target account and database before deploying. TURSO_* remains a local/maintenance fallback and is not the production database. Each scan upserts the account's latest score into the DB (one row per account); percentile = the share of stored scores strictly below yours. The public board only lists accounts scoring ≥60; lower scores still count toward the percentile but are not publicly named (anti-harassment). The leaderboard display can degrade without a database, but fresh scans require working persistence.

# local development only
TURSO_DATABASE_URL=http://127.0.0.1:8080

Deploy to Cloudflare Workers

The frontend and backend run together in one OpenNext Cloudflare Worker. See the Cloudflare deployment runbook for account/resource preflight, secrets, smoke checks, and rollback.

pnpm exec wrangler whoami
pnpm cf:build
pnpm cf:deploy:dev       # dev.ghfind.com
pnpm cf:deploy:prod      # ghfind.com

Production deploys also run from .github/workflows/deploy-cf-production.yml in the canonical hikariming/ghfind repository: a successful upstream main CI run checks out that exact SHA, deploys to Beiming's Cloudflare account, and automatically rolls back the single frontend/backend Worker if deployment or post-deploy smoke fails. Configure secrets with wrangler secret put --env <env>; do not commit secret values. Cloudflare D1/R2 bindings are defined in wrangler.jsonc.

Bring your own model / API key

Click "Use your own model" on the page and enter Base URL + API Key + Model. Compatible with any OpenAI-style API (OpenAI / OpenRouter / Groq / DeepSeek / local). The key lives only in your own browser's localStorage, is passed directly on call, and is never uploaded to the server or persisted.

Regenerating the scoring-parity test baseline

src/lib/__tests__/score-fixtures.json is the ground truth produced by the Python skill's score(). After the skill formula changes, re-run score() from github-account-value/scripts/fetch_github_profile.py on the same inputs, overwrite that file, then pnpm test to verify the port didn't drift.

Disclaimer

This site generates scores and commentary automatically from public GitHub data only. It roasts an account's public behavior and data, is not directed at individuals, does not constitute a factual finding, and must not be used for harassment. Private contributions are excluded, so active members of private orgs may be underrated.

Sponsorship & fairness

Sponsorship is welcome to cover running costs (GitHub API, LLM, hosting). Note that:

  • Sponsorship does not affect any score or ranking. Scores are computed deterministically by src/lib/score.ts; sponsors cannot buy a higher score, a better rank, or "whitewashing". Sponsor placements and leaderboard data are physically separated in the product.
  • Sponsor perks are attribution/placement only and never touch the scoring logic.

License

Licensed under GNU AGPL-3.0.

  • You may freely use, modify, and self-host this project.
  • If you modify it and offer it as a network service (SaaS / hosted), AGPL requires you to release your modifications under AGPL as well (users interacting over the network are entitled to the source).
  • The scoring core is ported from the open-source Claude skill github-account-value, kept as the single source of truth.

Trademark: the "ghfind / 毒舌 GitHub 评分" name, logo, and domain are not covered by the open-source license; all rights reserved. You may self-host from this code, but please do not use the project's name/brand to impersonate the official site or cause confusion.

About

Discover the best developers — and become one. Drop a GitHub handle for a 0–100 value & trust score in 30s: see your gaps, discover top devs, get found. Exposes PR farmers, AI bots & fork-hoarders. Deterministic scoring, self-hostable.

Topics

Resources

Contributing

Stars

242 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages