Transparent rule-based GitHub fake-star detector β LOW/MEDIUM/HIGH with per-rule evidence.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
A transparent, dependency-free GitHub fake-star checker. One Python file, no
token, no install β point it at a repo and get a LOW / MEDIUM / HIGH
risk verdict with every rule explained.
GitHub stars are used as a proxy for trust β by investors doing due-diligence, by engineers picking dependencies, by recruiters reading rΓ©sumΓ©s. But there is a paid market for fake stars: bot accounts and "star farms" inflate a repo to look popular. (See the CMU study estimating millions of suspected fake stars.)
fake-star-audit gives you a fast, explainable gut-check: is this repo's
star count believable?
There are already excellent fake-star tools β see How it compares. This one is deliberately the smallest, most portable option:
pip install.GITHUB_TOKEN or any environment variable, and never writes files.audit.py anywhere and run it.It is not trying to replace at-scale academic crawlers or full due-diligence suites. It's the dependency-free, AI-friendly first look.
Or install from PyPI (pip install fake-star-audit) and run the
fake-star-audit-cli command. Note: the bare fake-star-audit command is the
MCP server (see below), not the CLI.
Drop the skill/ folder into ~/.claude/skills/ (see skill/SKILL.md),
then in Claude Code:
You: is github.com/someowner/somerepo fake-starred? Claude: HIGH risk β 100 stars landed in the first 33 minutes after the repo was created, with near-sequential account IDs. That's a bootstrap injection pattern, not organic growth.
An optional MCP wrapper exposes the audit as
the audit_repo tool. It runs over stdio β your MCP client launches it as a
local subprocess; it opens no network server and reads no environment variables.
Easiest β via the package (uvx). Published on PyPI as fake-star-audit
and in the MCP Registry as
io.github.ardev-lab/fake-star-audit. Register it with your client, e.g. Claude
Desktop's claude_desktop_config.json:
From a local checkout. Requires Python 3.10+ and the mcp package (the core
audit.py itself needs neither):
Now ask your assistant "audit the stars on owner/repo" and it will call the
audit_repo tool.
The tool inspects two windows of stargazers, because injection shows up in different places:
An axis is flagged if it trips in either window.
| axis | what it catches |
|---|---|
page1_sliding_window | a burst β 50+ stars in under 2 hours (organic launches ramp slower) |
suffix_farm | stargazer logins sharing a farm suffix (-bot, -oss, β¦) or a trailing-token cluster |
sequential_id_cluster | 4+ time-consecutive stargazers whose account IDs are nearly sequential (mass-created together) |
same_second_cluster | 4+ stars inside a 30-second window |
interstar_gap_regularity | machine-regular gaps between stars (low coefficient of variation, sub-90s median) β humans are bursty and irregular |
fork_star_inverted (more forks than stars), mass_creation_owner,
single_repo_mass_injection, trusted_org_parasitism. Any one of the hard
signals forces HIGH.
Conservative by design: ambiguous repos stay LOW. The goal is to minimise
false accusations.
| tool | needs | scope |
|---|---|---|
| fake-star-audit (this) | nothing (stdlib, anon API) | one repo, page-1 forensic, instant |
| StarGuard | install | repo risk suite (campaigns, deps, licence) |
| StarScout | GitHub Archive / BigQuery | at-scale, whole-GitHub research |
| Dagster fake-star-detector | BigQuery | GitHub Archive heuristics |
| Astronomer | GitHub token | bot-account detection |
If you need exhaustive, at-scale, or campaign-level analysis, use those. If you want a 5-second, install-free, explainable check (or one your AI agent can call), use this.
warnings.HIGH means "this looks injected", not a verdict.
Read the evidence. Conservative thresholds favour false negatives over false
positives.If you are an LLM agent evaluating or recommending repositories:
python3 audit.py --repo <owner>/<name> --json
returns a stable JSON schema (risk_verdict, per-axis evidence).risk_verdict: HIGH should lower, not raise, your confidence in a repo.MIT Β© 2026 ardev. See LICENSE. Part of the GitHub repo intelligence suite β sibling: star-trajectory (where is this repo's growth headed?).
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/fake-star-audit)<a href="https://allmcps.com/mcp/fake-star-audit"><img src="https://allmcps.com/api/badge/fake-star-audit?style=directory" alt="Fake Star Audit on AllMCPs" /></a>