{"_id":"@charan6924/ducky","_rev":"2-3e71aeb2f76e9bda96ca70f49966b54b","name":"@charan6924/ducky","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@charan6924/ducky","version":"1.0.0","keywords":["ai","tracking","cli","developer-tools"],"author":{"name":"Charan6924"},"license":"MIT","_id":"@charan6924/ducky@1.0.0","maintainers":[{"name":"charan6924","email":"charanvardham@gmail.com"}],"homepage":"https://github.com/Charan6924/Ducky#readme","bugs":{"url":"https://github.com/Charan6924/Ducky/issues"},"bin":{"ducky":"dist/index.js"},"dist":{"shasum":"2147fb63e0dec223424ae38e5c350dae607edc5d","tarball":"https://registry.npmjs.org/@charan6924/ducky/-/ducky-1.0.0.tgz","fileCount":32,"integrity":"sha512-2tsJ5udVoIxDeVlkH3GGeIhE4IdqtJXoTPiT7Vur3pDinK1wAr1boPRmb/bdL6TakZ/yH9y+B+2uzCuB4ElK5g==","signatures":[{"sig":"MEQCIG88D/SO7Hx6bORJQc4hs70Hi2GelcZdGzodhfXGLGphAiAjR6XDmMIbHlEmM96uhDsg2BVZW7fUPoBapAKMrq9V7Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31590},"main":"dist/index.js","type":"commonjs","types":"./dist/index.d.ts","gitHead":"7457a6d002e7d35196c2e8988e4f7bf515b50c3b","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"charan6924","email":"charanvardham@gmail.com"},"repository":{"url":"git+https://github.com/Charan6924/Ducky.git","type":"git"},"_npmVersion":"11.4.2","description":"A CLI tool that passively monitors a developer's local environment to capture signals about AI coding assistant usage during a session.","directories":{},"_nodeVersion":"24.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^6.0.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/ducky_1.0.0_1778908645604_0.3464440393018402","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@charan6924/ducky","version":"1.0.1","description":"A CLI tool that passively monitors a developer's local environment to capture signals about AI coding assistant usage during a session.","main":"dist/index.js","bin":{"ducky":"dist/index.js"},"scripts":{"build":"tsc","prepublishOnly":"npm run build","test":"vitest run","test:watch":"vitest"},"repository":{"type":"git","url":"git+https://github.com/Charan6924/Ducky.git"},"keywords":["ai","tracking","cli","developer-tools"],"author":{"name":"Charan6924"},"license":"MIT","publishConfig":{"access":"public"},"type":"commonjs","bugs":{"url":"https://github.com/Charan6924/Ducky/issues"},"homepage":"https://github.com/Charan6924/Ducky#readme","devDependencies":{"@types/node":"^25.7.0","typescript":"^6.0.3","vitest":"^4.1.6"},"_id":"@charan6924/ducky@1.0.1","gitHead":"5612d9f9a13939dfb5002fab03c0d3c21792cbb2","types":"./dist/index.d.ts","_nodeVersion":"24.3.0","_npmVersion":"11.4.2","dist":{"integrity":"sha512-w3y+1x1RbsuqoXyjZCtVTZQAl7TeDBrBcxb6TCR0h78IRIb/sXxNft/VswlhCtpCK6pCduvFmnZddpr5Q0F48g==","shasum":"e6e18c9084cdf936448e5a9e1d2501b0d6d01e32","tarball":"https://registry.npmjs.org/@charan6924/ducky/-/ducky-1.0.1.tgz","fileCount":32,"unpackedSize":31627,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGjxcd3PSpQMLuXTgdGcFNv91x3SATatRlO+/+ssqAn2AiEAvPBVdflayZnRYNYNCbk6vCGc6XaKM4ICpxpaRL45Ewk="}]},"_npmUser":{"name":"charan6924","email":"charanvardham@gmail.com"},"directories":{},"maintainers":[{"name":"charan6924","email":"charanvardham@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ducky_1.0.1_1778908905975_0.6759325498548963"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-16T05:17:25.528Z","modified":"2026-05-16T05:21:46.299Z","1.0.0":"2026-05-16T05:17:25.763Z","1.0.1":"2026-05-16T05:21:46.167Z"},"bugs":{"url":"https://github.com/Charan6924/Ducky/issues"},"author":{"name":"Charan6924"},"license":"MIT","homepage":"https://github.com/Charan6924/Ducky#readme","keywords":["ai","tracking","cli","developer-tools"],"repository":{"type":"git","url":"git+https://github.com/Charan6924/Ducky.git"},"description":"A CLI tool that passively monitors a developer's local environment to capture signals about AI coding assistant usage during a session.","maintainers":[{"name":"charan6924","email":"charanvardham@gmail.com"}],"readme":"# ducky\n\nA CLI tool that passively monitors a developer's local environment to capture signals about AI coding assistant usage during a session.\n\n## Installation\n\n```bash\nnpm install -g @charan6924/ducky\n```\n\nOr to run without installing:\n\n```bash\nnpx @charan6924/ducky start\n```\n\n## Usage\n\n```\nducky start   — begin tracking AI usage in the current directory\nducky stop    — stop tracking and generate ducky-report.json\n```\n\nTracking runs as a detached background process. The session file is written to `ducky.session.json` every 5 seconds. When stopped, a `ducky-report.json` is generated in the project root.\n\n## How It Works\n\nDucky runs 7 watchers concurrently as a background daemon:\n\n| Tracker | Signal Captured | Method |\n|---|---|---|\n| **Process Watcher** | AI-related processes running on the system | Polls `ps aux` every 5s, matches against known AI tool names |\n| **Window Watcher** | Active window title and app name | Polls `osascript` every 5s, checks if the frontmost window matches AI tool patterns |\n| **Filesystem Watcher** | File changes in the project directory | Uses `fs.watch` recursively, logs all file change events |\n| **File Pattern Watcher** | AI-specific file artifacts (.aider, .copilot, CLAUDE.md, etc.) | Scans the project tree every 60s for known AI tool marker files |\n| **Shell History Watcher** | AI commands in shell history | Reads `~/.zsh_history` on start, scans for AI-related commands |\n| **Git Log Watcher** | Git commits with AI-generated messages | Runs `git log`, flags commits containing AI-typical patterns |\n| **Network Watcher** | Network connections to known AI API endpoints | Runs `lsof -i` every 10s, matches against known AI API domains |\n\nAll tracking is **passive** — it only reads system state and never interferes with the developer's workflow. All data stays **local** — nothing is sent to any external service.\n\n## Report Format\n\n`ducky-report.json` contains:\n\n- **metadata**: Session start/end time, duration in ms, project directory\n- **tracking**: Per-tracker data with all captured signals\n\n---\n\n## Writeup\n\n### 1. Tracking Approach\n\nDucky focuses on breadth of signal. The seven trackers cover seven distinct attack surfaces:\n\n- **Process snapshots** reveal which AI tools are actively running (e.g., Claude Code as a terminal process, Cursor as an Electron app).\n- **Window titles** capture the *context* of AI use — what file is the developer editing when they invoke an AI assistant?\n- **Filesystem changes** log *what* the AI is writing — new files, modified files, deletion patterns.\n- **File pattern scanning** detects AI tool presence even when tools aren't actively running (a `.copilot` config, a `CLAUDE.md` instruction file, a `.aider` file).\n- **Shell history** captures the developer's *interaction style* — do they craft detailed prompts? Do they chain AI calls? Do they use AI to write git commits?\n- **Git log analysis** flags commits that have AI-generated messages — a strong signal of AI-assisted development.\n- **Network connections** reveal which AI *services* are being used (Anthropic API, OpenAI, GitHub Copilot), distinguishing between local and cloud AI tools.\n\nThe design philosophy is defense-in-depth for signal: any single tracker can be evaded, but seven independent sensors make it very difficult to use AI tools without leaving a trace.\n\n### 2. Why AI Usage Tracking Matters\n\nTracking AI usage evaluates a developer's ability beyond what traditional assessments capture:\n\n- **Tool fluency** — Top AI users aren't prompting blindly; they know when to use AI and when to write code themselves. Usage patterns reveal judgment.\n- **Workflow integration** — Does the developer use AI as a crutch (always-on chat, accepting all suggestions) or as a force multiplier (targeted prompts, reviewing outputs critically)?\n- **Burst patterns** — Rapid-fire AI interactions suggest exploration/learning. Long, deliberate prompts suggest experienced orchestration. The ratio between AI interaction and human review is telling.\n- **Attribution awareness** — Developers who mark AI-generated commits vs. those who don't reveals intellectual honesty and understanding of code ownership.\n\nTraditional assessments (resumes, interviews, whiteboard coding) don't capture how someone *actually* builds software day-to-day. AI usage signals are a window into genuine engineering habits.\n\n### 3. Limitations & Extensions\n\n**Current Limitations:**\n\n- **macOS-only** — Several trackers (osascript for windows, lsof for network) are macOS-specific. Linux/Windows support would require platform-specific alternatives.\n- **No editor plugin** — Tracking happens at the OS level, not inside the editor. An IDE extension could capture inline completions (Copilot, TabNine) that leave no process or window trace.\n- **Shell history only on start** — Currently snapshots `.zsh_history` once at startup. A continuous tail would capture commands issued during the session.\n- **False positives** — Substring matching on process names and window titles can trigger on non-AI tools. A deny-list or confidence scoring would improve accuracy.\n\n**Desired Extensions (no constraints):**\n\n1. **Editor plugin (VS Code, JetBrains)** — Track inline completion acceptance/rejection rates, prompt lengths, file-level attribution. This is the richest signal and what I'd prioritize first.\n2. **Clipboard monitoring** — AI tools frequently copy-paste code into editors. Tracking clipboard origin and destination would catch AI use invisible to process/window watchers.\n3. **Browser extension** — Capture ChatGPT/Claude.ai web interactions, prompt content, code snippet copy events. This would catch web-based AI usage that leaves no local process trace.\n4. **Keystroke dynamics** — Measure paste vs. type ratios. AI-generated code is pasted, not typed. High paste-to-type ratio is a strong heuristic.\n5. **Prompt caching analysis** — Monitor terminal scrollback and editor temporary files to reconstruct prompt context. This would reveal *how* the developer structures prompts, not just *that* they used AI.\n6. **AI-powered classification** — Use an LLM to classify code as AI-generated vs. human-written based on style, comment patterns, naming conventions. This would catch AI use even when no known tool name appears.\n","readmeFilename":"README.md"}