Visitar URL original
feat: detect Amp, OpenHands, Factory Droid and Jules signatures by shenxianpeng · Pull Request #606 · commit-check/commit-check · GitHub
Skip to content

feat: detect Amp, OpenHands, Factory Droid and Jules signatures - #606

Merged
shenxianpeng merged 2 commits into
mainfrom
claude/project-thread-pofwgp
Oct 8, 2026
Merged

shenxianpeng merged 2 commits into
mainfrom
claude/project-thread-pofwgp

Conversation

@shenxianpeng

@shenxianpeng shenxianpeng commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Before: commits that Amp, OpenHands, Factory Droid or Jules sign by default passed every AI attribution rule. Commit Check did not know their trailers, so a message ending in Co-authored-by: Amp <amp@ampcode.com> passed ai_attribution = "forbid", and under disclose it was not asked for an Assisted-by:.

After: the four agents are in the signature catalog. That message now fails forbid with CC013 ai-attribution: Amp. Under disclose it fails CC014 and CC015, and the suggested fix is Assisted-by: Amp.

Agent What it writes by default Source
Amp Co-authored-by: Amp <amp@ampcode.com> and Amp-Thread-ID: https://ampcode.com/threads/T-… Amp settings
OpenHands commits as openhands <openhands@all-hands.dev>, and keeps that as a co-author when the user sets their own identity OpenHands application settings
Factory Droid Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com> (includeCoAuthoredByDroid) Droid settings
Jules commits as, or co-authors with, google-labs-jules[bot] (Commit Authoring setting) Jules changelog, 2026-02-19

How: four KnownAiTool entries before GENERIC_AI, built from the existing _identity, _stamp_trailer and _names helpers. Names that people also have are guarded, and the tests cover each case: Amp counts only with no address or Amp's own, Jules Verne and Jules <jules@example.com> are not flagged because Jules and Droid match only their [bot] app names, and OpenHands matches by name rather than by the all-hands.dev domain its staff share.

The second commit keeps the scan of human trailers as cheap as on main. Each branch of a trailer alternation used to sit inside its own capturing group, which the regex engine enters before the branch can reject a line, at a cost that grows with the number of groups before it. So every tool added made each human Co-authored-by or Signed-off-by line dearer to scan. The group is now empty and closes its branch; lastindex still names the matching pattern.

Performance. Instructions per call, measured with callgrind (PYTHONHASHSEED=0):

What runs main this PR
test_no_signatures_in_clean_commit (human sign-off) 54.6k 54.4k
detect_ai_signatures, human co-author 52.7k 52.7k
has_ai_signature, human co-author 65.0k 67.1k
test_clean_message (has_ai_signature("feat: add feature")) 14.3k 17.0k (+18%)
test_generic_ai_catch_all (Assisted-by: gpt-4:openai) 84.6k 103.3k (+22%)
test_all_* catalog loops +17% to +32%

CodSpeed reported no change on this head (622 benchmarks untouched, 4 new): it times each whole test, about 360 µs, so these per-call differences stay under its threshold. The last three rows grow with the catalog itself: has_ai_signature reads the message once per trailer key and Amp-Thread-ID is a new key; a disclosure that names no known tool is checked against every tool's name; and the test_all_* tests loop over the catalog. In wall-clock terms the worst is about 1 µs per message (6.0 to 7.0 µs for the disclosure case).

Not in this PR:

Checked locally:

  • Full test suite: 1191 passed. The permission test that fails only as root was deselected.
  • pre-commit (ruff, mypy, codespell) is clean.
  • Coverage of ai_signatures.py and ai_signatures_data.py stays at 100%.
  • The CLI fails an Amp commit under forbid on this branch (exit 1); main passes it (exit 0).

🤖 Generated with Claude Code

https://claude.ai/code/session_013rE6bouKaJvsRyKA4tjqCb


Generated by Claude Code

Summary by CodeRabbit

  • New Features
    • Added recognition for AI-generated commit signatures from Amp, OpenHands, Factory Droid, and Jules, including their co-author, sign-off, disclosure, and stamp formats.
    • Amp signatures with thread IDs are also recognized, helping distinguish these tool attributions from human names and unrelated text.

Each pattern matches what the agent writes into a commit by default:

- Amp adds an Amp co-author with amp@ampcode.com and an Amp-Thread-ID
  trailer (https://ampcode.com/docs/cli/settings).
- OpenHands commits as openhands <openhands@all-hands.dev> and stays on
  as a co-author when the user sets their own identity
  (https://docs.openhands.dev/openhands/usage/settings/application-settings).
- Factory Droid adds a factory-droid[bot] co-author
  (https://docs.factory.com/droid-cli/settings.md).
- Jules commits or co-authors as google-labs-jules[bot]
  (https://jules.google/docs/changelog/2026-02-19).

People named Jules or Amp, and people with an all-hands.dev address,
are not flagged.
Each branch of a trailer alternation sat inside its own capturing
group, which the regex engine entered before the branch could reject
a line, at a cost that grows with the number of groups before it. So
every tool added to the catalog made each human Co-authored-by or
Signed-off-by line dearer to scan: with the four tools from the
previous commit, detect_ai_signatures took about 10% more instructions
on a message with a human sign-off.

The group is now empty and closes its branch, so it is entered only
once the branch has matched, and lastindex still names the pattern
that matched. That message costs the same as on main again.
@shenxianpeng
shenxianpeng requested a review from a team as a code owner October 8, 2026 17:48
@github-actions github-actions Bot added the enhancement New feature or request label Oct 8, 2026
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d4de27b3-a478-4fd0-9750-f124e1dda644
📥 Commits

Reviewing files that changed from the base of the PR and between f643ecd and caf8fc4.

📒 Files selected for processing (3)
  • commit_check/ai_signatures.py
  • commit_check/ai_signatures_data.py
  • tests/ai_signatures_test.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The trailer parser changes numbered capture placement. The AI-tool registry adds signatures for Amp, OpenHands, Factory Droid, and Jules, with tests covering signature recognition and false-positive inputs.

Changes

AI signature recognition

Layer / File(s) Summary
Trailer-pattern capture placement
commit_check/ai_signatures.py
Trailer-pattern branches now place numbered empty capturing groups after the value pattern. The _Group documentation describes the updated placement.
New tool signatures and recognition tests
commit_check/ai_signatures_data.py, tests/ai_signatures_test.py
The ordered registry adds signatures for Amp, OpenHands, Factory Droid, and Jules. Tests cover role attribution, tool-name matching, and false-positive inputs.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to caf8f

No actionable merge-blocking risk is established by the supplied review evidence.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding Amp, OpenHands, Factory Droid, and Jules signature detection.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (f643ecd) to head (caf8fc4).

Additional details and impacted files
@@            Coverage Diff            @@
##              main      #606   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           14        14           
  Lines         2292      2296    +4     
=========================================
+ Hits          2292      2296    +4     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@codspeed

codspeed Bot commented Oct 8, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 622 untouched benchmarks
🆕 4 new benchmarks
⏩ 126 skipped benchmarks1

Performance Changes

Benchmark BASE HEAD Efficiency
🆕 test_bare_human_name_not_detected[Co-authored-by: Amp <amp@example.com>] N/A 361.5 µs N/A
🆕 test_bare_human_name_not_detected[Co-authored-by: Graham Neubig <graham@all-hands.dev>] N/A 372.6 µs N/A
🆕 test_bare_human_name_not_detected[Co-authored-by: Jules <jules@example.com>] N/A 361 µs N/A
🆕 test_bare_human_name_not_detected[Co-authored-by: Jules Verne <jules@example.com>] N/A 370.2 µs N/A

Comparing claude/project-thread-pofwgp (caf8fc4) with main (f643ecd)

Open in CodSpeed

Footnotes

  1. 126 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@shenxianpeng
shenxianpeng merged commit 57e7666 into main Oct 8, 2026
34 checks passed
@shenxianpeng
shenxianpeng deleted the claude/project-thread-pofwgp branch October 8, 2026 22:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant