Repository navigation
feat(ai-summary): add client-side AI activity summary page - #922
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #922 +/- ##
==========================================
+ Coverage 38.80% 39.93% +1.13%
==========================================
Files 43 44 +1
Lines 2278 2331 +53
Branches 461 477 +16
==========================================
+ Hits 884 931 +47
- Misses 1315 1321 +6
Partials 79 79 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Greptile SummaryThe PR adds a browser-based AI activity-summary page that loads window events through the configured ActivityWatch client and sends an aggregated top-application summary to OpenAI or Anthropic.
Confidence Score: 5/5The PR appears safe to merge. No blocking failure remains; the configured-client, CSP, event-limit, and stale custom-configuration issues reported in earlier threads are addressed at the current head. Important Files Changed
Sequence DiagramsequenceDiagram
participant U as User
participant V as AI Summary View
participant C as Configured AWClient
participant S as aw-server
participant L as LLM Provider
U->>V: Select host, range, provider, and model
V->>C: "getEvents(bucket, start, end, limit=-1)"
C->>S: Authenticated event request
S-->>C: Window events
C-->>V: Events
V->>V: Aggregate duration by application
V->>L: Send prompt and aggregated summary
L-->>V: Generated activity summary
V-->>U: Display response and raw-data toggle
Reviews (5): Last reviewed commit: "fix(ai-summary): reset stale custom mode..." | Re-trigger Greptile |
|
@greptileai review |
|
@greptileai review |
|
@greptileai review |
|
@greptileai review |
|
CI-green and mergeable (Greptile 5/5) — waiting only on a maintainer click. This PR is ready to merge, but the bot has pull-only access to this repo and can't self-merge — surfacing it here so it isn't lost. The monitoring loop will stop re-flagging it now that this note is posted. |
|
@TimeToBuildBob This is an interesting concept/idea to play with, but I don't think it should appear by default (hide under dev mode at the least) and might need a better approach and proper docs for "how to use ActivityWatch with agents/AI" as an extension to the exporting and analysis docs (using the "canonical query" etc). I also don't like the idea that we are basically suggesting to users to send all their data to OpenAI/Anthropic API (feels iffy with private/personal data tbh) and use API key pricing (although request-volume is low, it's not the path we want to suggest) instead of existing subscriptions they may have. Adding API key every time etc is also very annoying, I get that this is a first version, but definately needs better gating to now be widely shown in this early state. Also, the |
Adds a new /ai-summary route that lets users generate an LLM-powered summary of their activity data directly in the browser. - Client-side only: queries AW's local REST API for window events, aggregates by app, and sends a compact summary to the user's configured LLM endpoint - Supports OpenAI, Anthropic, and custom OpenAI-compatible providers - API key stored in localStorage only — never sent to the AW server - Date range selection: 7d / 30d / 90d - Shows raw aggregated data used in prompt (toggle) - Copy-to-clipboard for the LLM response - Nav link added to Tools dropdown - 11 unit tests for aggregation and formatting logic Closes: ActivityWatch#883
CodeQL flagged cleartext storage of the API key in localStorage as a high-severity vulnerability. API keys are sensitive credentials; storing them in localStorage persists them on disk indefinitely and exposes them to any same-origin JS across browser sessions. Split storage: non-sensitive config (provider, model, baseUrl) stays in localStorage for cross-session convenience; apiKey goes to sessionStorage, which is scoped to the browser tab and never written to disk.
0bd203b to
2e9b251
Compare
|
Agreed on the gating and privacy concerns. I pushed I’m deliberately not treating the current OpenAI/Anthropic API-key flow as a user-facing recommendation or expanding it further in this PR. The better product direction is local/subscription-backed agent workflows plus proper “ActivityWatch with agents/AI” docs built around exporting/analysis and the canonical query. That broader design needs a separate pass rather than getting smuggled into this prototype. The API key remains memory-only (not stored), but yes, re-entering it is intentionally awkward and another signal that this is experimental rather than ready for default exposure. |
|
Monitoring follow-up: all required checks are green on |
|
@TimeToBuildBob I would prefer |
|
Addressed the in-PR pieces in |
|
CI is fully green on |
Summary
Adds an experimental, dev-mode-only
/analysis/activitypage for trying a client-side LLM summary of ActivityWatch window data.Experimental/privacy scope
This is a prototype, not the recommended end-user path for ActivityWatch + AI. Clicking Generate sends the displayed application names and durations to the selected third-party provider. The UI says so before the request, and the feature is hidden from the default navigation.
The broader product direction—local or subscription-backed agent workflows plus proper documentation built around ActivityWatch exporting/analysis and the canonical query—is tracked in ActivityWatch/activitywatch#1388. Richer, privacy-bounded single-pass context is tracked in #925. Neither belongs in this prototype PR.
Test plan
/analysis/activitynamespacePrototype toward #883; does not close the broader issue.