wonka-audit
v0.3.2
Published
Local AI usage audit CLI for Claude Code, Codex, Cursor and Git.
Maintainers
Readme
Wonka AI Usage Audit
Local AI usage audit CLI for Claude Code, Codex, Cursor and local Git signals.
The goal is to create a pre-training baseline before Wonka workshops, then run the same audit again after the training cycle to measure whether AI habits improved.
This is not a token-consumption report. It measures whether people use AI better:
- more real work context;
- more files, projects and concrete inputs;
- fewer vague prompts;
- more workflow-oriented sessions;
- more validation before using AI output.
The score is a directional, uncalibrated coaching indicator. It must not be used as an employee performance score or as proof that training caused a business outcome. See METHODOLOGY.md.
Install And Run
npx wonka-auditBy default, the CLI creates a local folder on the user's Desktop:
Desktop/Wonka AI Audit/<run-folder>/The folder contains:
wonka-ai-usage-audit.pdf
index.html
wonka-ai-wrapped-card.svg
wonka-ai-audit-report.json
wonka-ai-audit-report.md
linkedin-post.txt
wonka-ai-audit-methodology.json
wonka-ai-audit-manifest.jsonindex.html is the local user-friendly recap page. It opens with a terminal-style AI Wrapped card, share actions, and plain-language levers. wonka-ai-wrapped-card.svg is the standalone share card. The PDF is the portable report. linkedin-post.txt is a short privacy-safe draft the user can copy into LinkedIn if they want to share their AI practice recap. The LinkedIn button uses a privacy-safe one-click flow: copy the post text and open LinkedIn. The JSON is useful only if the employee or client explicitly decides to share it with Wonka.
Each run gets its own folder by default, so weekly usage does not overwrite previous reports.
Privacy Model
wonka-audit is local-first.
By default, it does not upload:
- full prompts;
- assistant responses;
- source code;
- secrets;
- environment variables;
- raw conversation logs;
- absolute local paths.
An admin cannot read employee local data through this CLI. Each user runs the audit locally and owns the generated PDF/JSON. Any sharing must be explicit and manual.
To print the privacy model:
npx wonka-audit --explain-privacyDisable prompt/message classification entirely:
npx wonka-audit --metadata-only
# equivalent: --no-contentThis mode still processes structural metadata such as timestamps, counts, tool calls and commands locally.
What It Reads
Claude Code:
~/.claude/projects/*.jsonlCodex:
~/.codex/sessions/**/*.jsonlCursor:
Cursor local state database, when availableGit:
local Git metadata from the current working directory, when availableCursor support depends on a local sqlite3 binary. If sqlite3 is unavailable, Cursor is marked unavailable instead of forcing installation.
Common Commands
Run the default local audit:
npx wonka-auditPreview detected sources:
npx wonka-audit --previewChoose an output directory:
npx wonka-audit --out ./wonka-auditWhen --out is provided, the CLI writes directly to that folder.
Create an explicit weekly run folder:
npx wonka-audit --period weekly --run-label week-2026-27Select a date window:
npx wonka-audit --since 2026-06-01 --until 2026-06-30Compare two local exports:
npx wonka-audit --compare baseline.json checkpoint.json --out ./wonka-compareCreate the private report and a public microsite in one run:
npx wonka-audit --shareThat is the normal sharing command. The private files and the public website are written to separate folders automatically. The local website opens automatically in your browser. It is still private until you deliberately host or publish it. The page explains the observed usage mix, strongest practice signal, clearest gap and recommended next practices. Its LinkedIn button copies the complete post, then opens LinkedIn: paste once in the composer to publish it.
To rebuild a website from an existing export, the optional advanced form remains available:
npx wonka-audit --share ./wonka-ai-audit-report.json --out ./public-shareAfter hosting it, add the final HTTPS URL with --share-url to generate canonical LinkedIn/Open Graph metadata. The share payload excludes organization, team, participant pseudonym, prompts, paths and raw conversations. See docs/SHARE-SITE.md.
Enterprise operators can provide WONKA_AUDIT_PARTICIPANT_ID and a tenant secret of at least 24 characters in WONKA_AUDIT_TENANT_SECRET. The export then contains a stable tenant-scoped HMAC pseudonym used only to remove duplicate participants during aggregation.
Optionally sign and verify an audit manifest with Ed25519 keys:
npx wonka-audit --sign-private-key ./audit-private.pem --out ./signed-audit
npx wonka-audit --verify-signature ./signed-audit/wonka-ai-audit-manifest.signature.json --public-key ./audit-public.pemOnly exports with the same schema, methodology, scoring model and content mode can be compared. Collection windows must be equivalent.
Aggregate compatible employee-owned exports with small-cohort suppression:
npx wonka-audit --aggregate ./approved-exports --min-cohort-size 5 --out ./aggregateScore Calibration
Current model: local_individual_v3_directional.
The AI Practice Score is a directional local individual baseline across Claude Code, Codex and Cursor. Unobservable metrics are excluded and reported as n/a, not scored as zero.
Scale:
40/100: needs work70/100: healthy90/100: strong
Dimensions:
AI Practice Score =
usage consistency 20%
+ real work usage 25%
+ interaction quality 20%
+ proof and impact 25%
+ fair usage 10%The JSON export includes score.calibration, with component-level scores and priority levers. The score is not a black box.
User-Friendly Report
The premium PDF is designed as a coaching recap, not a technical audit.
It shows:
- a local HTML recap page with a shareable AI Wrapped card;
- a standalone SVG card for sharing or design handoff;
- the user's AI profile;
- conversations and message volume;
- top detected tool;
- top detected use case;
- quick chat vs workflow mode;
- the clearest improvement levers;
- three next moves;
- a reusable prompt frame.
Example levers:
- finish with proof;
- give more context;
- use real work material;
- move from chat to workflow.
Pre-Training And Post-Training Flow
Recommended client flow:
- Run the audit before training.
- Use the PDF to help employees understand their current habits.
- Use the aggregate learning patterns to tailor Wonka workshops.
- Run the same audit again after the training cycle.
- Compare baseline vs checkpoint exports.
The core comparison is:
post-training checkpoint vs pre-training baselineLocal Development
npm test
npm run preview
npm run audit:local
npm run report:client
npm run go-live:check
npm run pack:checkThe package intentionally has no npm runtime dependencies.
Weekly Run Folder Structure
If a user runs npx wonka-audit every week, outputs are organized like this:
Desktop/Wonka AI Audit/
baseline_2026-06-01_to_2026-06-30_2026-06-29-10-45/
wonka-ai-usage-audit.pdf
wonka-ai-audit-report.json
wonka-ai-audit-report.md
weekly_2026-06-08_to_2026-07-07_2026-07-06-09-12/
wonka-ai-usage-audit.pdf
index.html
wonka-ai-wrapped-card.svg
wonka-ai-audit-report.json
wonka-ai-audit-report.md
linkedin-post.txtFor managed recurring runs, use explicit labels:
npx wonka-audit --period weekly --run-label week-2026-27Published Package
Package name:
wonka-auditRepository:
https://github.com/Caezarr/wonka-auditCurrent Limitations
- No automatic upload.
- No admin dashboard.
- No central employee monitoring.
- Cursor coverage depends on local
sqlite3. - Git correlation is intentionally basic and local.
- The report is strongest when run over a meaningful activity window.
Security Notes
See SECURITY-CISO.md.
