Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -155,3 +155,7 @@ Preserve the owner-selected sortable ledger and delegated answer-first direction
Content comparison is explicit because it reads local document bodies. Matching contents link to counterpart locations; independent scope remains a review decision. Document changes require a before/after preview, with archive consequences and guarded recovery visible. Plugin action sheets show exact owner, scope and command before applying. Activity distinguishes filtered session history from unfiltered live aggregates and gives direct folder-preserving review actions.

Responsive native renders cover 390, 768 and 1440 points. These are fixture renders, not evidence that cloud memories or unsupported agent adapters are resolved. Installed interactive checks are tracked separately in artifacts/design/complete-workflows/verification.md.

## Claude reset detail completion

Preserve the released two-provider-card composition. Within Claude Reset grants, label Full resets and 5-hour resets separately, put each reported expiry immediately below its scope, and qualify paused or currently unusable grants. Keep failed details unknown with a visible message and the existing Claude Usage handoff. Provenance and check time remain inside the source disclosure. No redemption control is introduced.
1 change: 1 addition & 0 deletions PRODUCT.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ The primary user is a developer running Codex, Claude, Cursor, Devin, or Grok on
- Historical usage can be inspected by service, observed model or inferred model provider, time range, metric, and day/week/month scale. Model and provider mix comes from daily accounting. Project grouping and recent activity use separately labelled, verified session identities and may not reconcile to daily totals. Devin's indexed daily tokens join the same model and provider history, with a shared agent filter; cost and project attribution remain unavailable.
- ccusage history is read directly and offline; CodeVetter is not a runtime dependency. Provider allowance has a manual check and an opt-in, throttled check on opening Usage. Devin's indexed daily tokens join local history independently of ccusage availability. Unavailable history is explicitly labelled.
- Codex full-reset credit expiry is shown only when the provider returns detail rows, and is labelled the latest reported expiry because the provider may cap those rows.
- Claude full and 5-hour reset grants are scoped read-only usage readings, separate from scheduled reset times and paid credits. Grant expiry and paused/unusable states remain explicit; unavailable or unsupported responses never imply zero. The existing default Claude Code credential is read only during manual or opted-in allowance checks, without credential writes, refreshes or reset redemption.
- OTEL sessions, tools, models, tokens, compactions, errors, and named skill injections remain distinct signals instead of being flattened into one activity score.
- OTEL is directly reachable and reports a disconnected local source as unavailable, never as zero activity.
- Overlapping operation durations are never added together as wall time.
Expand Down
8 changes: 4 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# ContextDaddy

ContextDaddy is a local-first macOS control plane for coding-agent context. It answers two questions without reading secrets or capturing prompt bodies:
ContextDaddy is a local-first macOS control plane for coding-agent context. It answers two questions through bounded local discovery without capturing prompt bodies:

1. Which skills can Codex, Claude, Cursor, Devin, and Grok discover, and how can each runtime invoke them?
2. What are those agents consuming in context tokens, logical network events, and tool calls when trustworthy local telemetry exists?
Expand Down Expand Up @@ -28,7 +28,7 @@ The primary navigation is **Usage**, **Skills**, **Projects**, and **OpenTelemet
- Usage first scan shows side-by-side Codex/Claude allowance followed by one local history chart including Devin. The historical chart has shared agent filters, model/model-provider/project grouping where supported, range, day/week/month scale, generated/cache/cost metrics where available, selectable periods and exact breakdown. Model, project, and session drill-downs remain below. Cache reads, generated tokens, and estimated cost stay separate; unpriced models are flagged.
- Skills can run an explicit, read-only **Read local history** scan. Claude and Devin `skill` tool calls are counted separately from Cursor/Grok skill-file reads and Codex tool calls that reference a `SKILL.md` path. The library shows last-seen dates, agent and folder evidence, 30/90-day or all-history windows, and an evidence-only filter. Cursor dates use transcript modification time because its records lack event timestamps. Name-only tool calls cannot identify a particular same-name copy; no recorded event never means unused. This backfill is held in memory for the app session and does not automatically remove skills.
- Project grouping is a separately labelled session ledger, joining ccusage session IDs to Codex's read-only thread-index `cwd`, Grok's project paths, and Claude's encoded project slugs. It queries only Codex rollout path and working directory metadata, never prompt bodies. Buckets use session last activity, not an invented daily allocation; totals may not reconcile to daily accounting. Missing session identity remains **Unattributed**. Model-provider labels are inferred from reported model names, not billing endpoints; unknown aliases remain unknown. Devin's indexed daily tokens participate in the shared model and provider grouping; project attribution remains unavailable.
- Provider allowance for Codex and Claude is fetched on **Check both allowances**, or on opening Usage after the user enables the opt-in automatic switch (at most once per 15 minutes). It is never added to local token history. Codex's reported credit balance appears in credit units, separately from full-reset grants; unlimited, unavailable, and unreported balances remain explicit. Codex reset-credit expiry is shown only when reported; detail rows may be capped. Claude's available usage-reset count is shown in the labelled Reset grants section when its CLI emits a limit-reset notice; absent counts are explicitly not reported, never assumed to be zero, with a direct link to Claude Settings > Usage. Scheduled reset times stay with their allowance meters, and Source & reading details discloses the provider source and full check time. These grants are separate from paid usage credits and may cover only particular limits. ContextDaddy only reads the notices and never invokes `/limit-reset` or consumes a grant.
- Provider allowance for Codex and Claude is fetched on **Check both allowances**, or on opening Usage after the user enables the opt-in automatic switch (at most once per 15 minutes). It is never added to local token history. Codex's reported credit balance appears in credit units, separately from full-reset grants; unlimited, unavailable, and unreported balances remain explicit. Codex reset-credit expiry is shown only when reported; detail rows may be capped. Claude's full and 5-hour reset grants are read from its usage endpoint with the existing default Claude Code sign-in and the installed CLI version. Each grant keeps its expiry and paused/unusable state. Confirmed empty grants show None; failed, ineligible or unsupported responses remain explicitly unavailable, with CLI notice counts and a Claude Settings > Usage link as fallbacks. Scheduled reset times stay with their allowance meters, and Source & reading details discloses the provider source and full check time. These grants are separate from paid usage credits and may cover only particular limits. ContextDaddy makes only a GET usage request for reset details. It never invokes `/limit-reset`, redeems a grant, refreshes/writes credentials, follows redirects, or stores credential/response bodies. Locked or unavailable Keychain access and custom Claude configuration homes remain explicit unavailable states.
- Skills and OTEL review panels can **Copy all issues** into an agent-ready brief with IDs, evidence, source scope, and verification limits. After skill edits, **Verify after changes** rescans and distinguishes detector-cleared, still-detected, and unverified findings. The library supports previewed local skill edits with recovery; OTEL signals need a new comparable observation window.
- Files & diagnostics configuration findings have the same copy-all and rescan handoff without copying configuration values or modifying files. This file audit detects the two misplaced `otel.*` keys but cannot detect launch-time `session-flags.token_budget`; that warning must be traced to the launcher supplying the flag.
- Cursor remains inventory-only for usage until a verified source exists.
Expand Down Expand Up @@ -60,7 +60,7 @@ swift run ContextDaddy

The app requires macOS 14 or newer. Its Codex adapter reads the loopback-only local telemetry stack and renders Prometheus metrics and Tempo sessions inside ContextDaddy. A separate Claude adapter reads Claude Code metrics from the same local Prometheus path only if Claude exports to that collector; ContextDaddy does not enable or reroute Claude telemetry. The rest of the product still works when either source is absent or partial.

ContextDaddy runs [ccusage](https://github.com/ccusage/ccusage) 20.0.24 directly in offline mode for local history. The packaged app carries its own pinned helper and [MIT acknowledgement](CONTEXTDADDY_NOTICES.md); no CodeVetter installation or CLI is needed at runtime. A **Refresh history** action rescans local logs. **Check allowance** separately calls Codex app-server and Claude Code `/usage` through their installed CLIs; opt-in automatic checking uses the same adapters with a 15-minute minimum interval. These readings are not ccusage totals.
ContextDaddy runs [ccusage](https://github.com/ccusage/ccusage) 20.0.24 directly in offline mode for local history. The packaged app carries its own pinned helper and [MIT acknowledgement](CONTEXTDADDY_NOTICES.md); no CodeVetter installation or CLI is needed at runtime. A **Refresh history** action rescans local logs. **Check allowance** separately calls Codex app-server and Claude Code `/usage` through their installed CLIs. Claude's usage endpoint supplies allowance windows and reset grants from one read, while the CLI supplies plan and paid-credit details. If the CLI display fails, those unreported details remain unavailable. Opt-in automatic checking uses the same adapters with a 15-minute minimum interval. These readings are not ccusage totals.

The general usage dashboard lives in ContextDaddy's Focus Desk. Devin's distinct indexed history comes from a bounded, read-only scan of the Devin CLI SQLite session index, separate from ccusage. It deduplicates repeated assistant message IDs and reports daily token classes and models for each range. Devin is included by default in Historical usage and can be filtered with the other agent chips. Devin cost remains explicitly unavailable until a provider-verified rate source exists; a missing or unreadable index is never presented as zero usage.

Expand All @@ -79,7 +79,7 @@ ContextDaddy was extracted from StorageDaddy's MIT-licensed context work, with t

## Privacy boundary

ContextDaddy inspects well-known agent roots and opens at most 64 KiB of each `SKILL.md` to parse frontmatter and compute a one-way SHA-256 fingerprint; it does not retain or display the skill body during discovery. Other eligible document bodies open only after an explicit Preview action, through a guarded regular-file reader capped at 256 KiB, and MCP configuration bodies are never previewed. Configuration health reads only bounded structural fields and ignores credential, header, environment, and MCP argument values. It skips secret-shaped and generated directories during discovery. The explicit skill-history scan reads local transcript records, extracts structured skill tool calls and file-path evidence, and retains only names, agents, session keys, dates, project paths, and evidence classes in memory; prompt, response, and command bodies are discarded. Telemetry is fetched from a loopback-only local stack whose collector removes prompt, response, command, argument, result, account, and host fields before persistence. Offline ccusage history remains in memory for the current app session. ContextDaddy performs no config writes and makes no claim about exact internet bytes without a dedicated sensor.
ContextDaddy inspects well-known agent roots and opens at most 64 KiB of each `SKILL.md` to parse frontmatter and compute a one-way SHA-256 fingerprint; it does not retain or display the skill body during discovery. Other eligible document bodies open only after an explicit Preview action, through a guarded regular-file reader capped at 256 KiB, and MCP configuration bodies are never previewed. Configuration health reads only bounded structural fields and ignores credential, header, environment, and MCP argument values. It skips secret-shaped and generated directories during discovery. The explicit skill-history scan reads local transcript records, extracts structured skill tool calls and file-path evidence, and retains only names, agents, session keys, dates, project paths, and evidence classes in memory; prompt, response, and command bodies are discarded. Telemetry is fetched from a loopback-only local stack whose collector removes prompt, response, command, argument, result, account, and host fields before persistence. Offline ccusage history remains in memory for the current app session. Explicit or opted-in Claude allowance checks read only the default Claude Code Keychain sign-in into memory to fetch reset-grant availability from Anthropic; no credential value is displayed, logged or persisted. ContextDaddy performs no config writes and makes no claim about exact internet bytes without a dedicated sensor.

## Status

Expand Down
Loading
Loading