// the find
Albert-Weasker/niubi_guard
Open-source GitHub repository abuse detection and response system.
Niubi Guard is a TypeScript CLI and Next.js web console that scans a repository's Issues and comments for abuse patterns such as copy-paste accusations, mass mentions, and coordinated harassment. It is for maintainers who are being targeted and want to set their own detection rules, model, and response actions instead of relying on a hosted service.
- Dry-run is the default, and every destructive action (delete, close, lock, block, interaction limits) is off in the example config. A real repo can't be damaged until someone passes --apply and flips the flags.
- Each detection carries the matched rule or username, the model's confidence, the reason, the evidence strings, and the planned action. A bad call is easy to audit, which matters more for a moderation tool than raw accuracy alone.
- The LLM adapter uses the OpenAI chat-completions shape with a strict JSON contract, a configurable confidence threshold, and review_only as the default mode. Switching models or pointing at a local endpoint is a config change.
- allowPhrases and allowUsers sit alongside denyUsers and keywords, so a maintainer can exempt good-faith security disclosures and trusted contributors before the classifier sees them.
- The optional cold-start rule flags accounts that are newly created with an empty bio and, optionally, no avatar. That describes plenty of legitimate first-time contributors. The README gives no false-positive numbers for it, and review queues and false-positive management are still on the v0.2 roadmap.
- The example config puts the LLM API key inline as an apiKey field. The README never says to keep guard.config.json out of version control or to read the key from an environment variable, so it is easy to commit a secret by accident.
- The README has more promotion than detail: Trendshift badges, a 'protected by' badge that advertises the project inside other repos, and a pitch for a hosted service with a support email. It doesn't say how detection accuracy was measured against the attack corpus it links to, or what the AI detector's precision and recall look like on that corpus.