The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the HumanifyMe listing page.
Make AI sound like you. · humanifyme.com
Try it in your browser → No install and no key: paste a few of your own messages and an AI draft, and get the draft back in your voice.
HumanifyMe learns how one specific person writes, then rewrites an AI agent's output in that person's voice before anyone reads it. Install it once and every agent on your machine — Claude Code, Cowork, Cursor — rewrites in the same voice. It is not "write better." It is "stop sounding like AI."
It runs locally. The only thing that crosses the network is a redacted draft sent to the LLM provider you choose.
Run the secure one-time setup first. It explains the privacy boundary, hides your provider key while you type it, validates the provider, collects three writing samples, builds your profile, and offers a first rewrite:
Want to see it work before installing? A live demo of the setup and rewrite flow is at humanifyme.com.
Never paste a provider key into an AI chat or pass it as a command-line flag. Then install the plugin from the bundled marketplace — no clone or build:
Then use /humanifyme:humanify on any draft, or let the bundled skills trigger
it after an agent drafts an email, PR, or message. The CLI and every installed
agent share the profile stored in ~/.humanifyme/. Use
/humanifyme:build-voice-profile later to add samples or rebuild it.
Tried it? Rate a rewrite: two dropdowns, and it is the feedback that improves voice matching most.
Run /reload-plugins if you installed mid-session. Using a different agent (Cursor, Continue, Cline, Windsurf, Zed, ChatGPT desktop) or the CLI? See Install.
Want to inspect a draft before setting up a profile? The analyzer is local, deterministic, and needs no API key:
It reports the exact phrases and punctuation it matched against the public 90-sign AI-writing checklist. It is an editing aid, not an AI detector; subjective signs stay labeled for human review instead of being turned into a fake probability.
People hand more of their writing to AI every day — commits, PR descriptions, Slack posts, email drafts — and every agent produces the same recognizable register: polished, balanced, faintly corporate. Recipients have learned to spot it. The usual fixes (Grammarly, Wordtune, "AI humanizers") push text toward a generic professional voice, which is the opposite of the goal.
Few-shot prompting alone cannot close the gap. A large 2025 study ran tens of thousands of generations across frontier models and hundreds of real authors and found that dropping a few samples into a prompt and asking a model to "write like me" hits a ceiling on casual voice (Wang et al., 2025). HumanifyMe's answer to that ceiling is a persistent, retrievable corpus of your writing plus a paraphrase-then-restyle rewrite — not a longer prompt.
MCP vs. plugin. MCP (Model Context Protocol) is the protocol HumanifyMe speaks, so any MCP-compatible agent can call its
humanify_texttool. A plugin is the packaging format (used by Claude Code and Cowork) that bundles the MCP server plus skills into one installable unit. You can install the plugin, or register the MCP server directly.
An agent calls one tool, humanify_text. Everything else happens on your machine.
The rewrite is paraphrase-then-restyle: strip the source style, re-render toward your learned voice, then run a deterministic gate no prompt can skip. The three pieces that carry the design:
src/engine/verify.ts runs five mechanical checks against the redacted draft: words the model introduced from your avoid-list, dropped numbers (dates, prices, versions), broken URLs, vanished redaction placeholders, and your learned casing register. Failures on the first attempt become instructions for one retry; survivors become user-facing "review before sending" notes. It never blocks output.~/.humanifyme/data.db, shared across every agent and project on your machine. The default embedder is offline and dependency-free; MiniLM and Ollama are opt-in, local-only upgrades.Deep dives: architecture & rewrite pipeline · voice memory & retrieval · data model.
HumanifyMe is bundled as a plugin in humanifyme.plugin/: a .claude-plugin/plugin.json manifest, an .mcp.json that registers the MCP server, and three skills (humanify, build-voice-profile, humanify-pr). The repo root ships a marketplace catalog at .claude-plugin/marketplace.json. The two-line install is in Quickstart.
The bundled .mcp.json launches the server from the published npm package via npx -y --package humanifyme@0.2.2 humanifyme-mcp, pinned to a known build, so the plugin works on a fresh machine with nothing checked out. Copy-paste setup for other agents is in docs/install/.
From npm, one command walks through privacy, provider, three samples, profile creation, and a first rewrite. API-key input is hidden and setup resumes from the last completed step if interrupted.
Contributing from a checkout requires Node 22.5 or newer:
If your agent does not use the plugin format, register the server directly:
The server exposes 16 humanify_* tools in one registry: the headline humanify_text, plus feedback and metrics, sample add/list/delete, profile get/build/update/delete, provider set, key test, audit list, wipe-all, and two importers. The same engine runs without MCP via the humanifyme CLI.
A four-register evaluation: four writers with distinct voices (casual lowercase, formal sentence-case, terse technical, warm enthusiastic), five generic-AI drafts each, rewritten with retrieval on and off — 20 rewrite pairs. Full method, raw numbers, and reproduction steps are in docs/proof/README.md. Run date 2026-06-24.

Attribution (a sanity check, not proof). Ask which of the four writers each retrieval-grounded rewrite lands closest to under a stylometric scorer: 17 of 20 (85%) land on their own writer. Be skeptical, because we are — the writers differ mostly by register, the scorer is eight coarse surface features, and every miss falls between the two lowercase writers. It shows the machinery does something; it is not evidence it reproduced anyone's idiolect.
Retrieval pulls the rewrite closer to the real writer for three of four writers this run (lower is closer). We report writer B even though retrieval hurt it — the metric is noisy and we are not rounding a loss into a win.
| Writer | Distance ON | Distance OFF | Retrieval helps? |
|---|---|---|---|
| A (casual / lowercase) | 2.35 | 3.38 | yes, clearly |
| B (formal / sentence-case) | 3.22 | 2.32 | no, worse this run |
| C (terse / technical) | 2.92 | 3.09 | yes, small |
| D (warm / enthusiastic) | 2.47 | 2.69 | yes, small |
What we do not claim: that an LLM judging an LLM is proof (we ran it; it's a weak proxy); that retrieval helps every writer; that the MVP already does style-pure retrieval; or that redaction recall is a privacy guarantee. The honest test is human evaluation, and the proof doc spells out every limitation.
HumanifyMe is local-first and redacts before it sends. The privacy assurance is architectural, not a recall percentage: the engine runs on your machine and the privacy-critical code (src/privacy/, src/network/, src/engine/verify.ts) is Apache-2.0, so you can read exactly what leaves.
~/.humanifyme/, overridable only via HUMANIFYME_HOME. Raw samples never leave that directory.redact() masks emails, phones, US addresses, Luhn-checked cards, API keys, AWS access-key IDs, and JWTs into numbered placeholders before the single network call; restore() swaps them back after. Retrieved exemplars are re-redacted at send time — store-time redaction is never trusted. Best-effort by design, and documented as such.src/network/outbound-scan.test.ts asserts that only src/providers and src/network may call fetch(), and that every hardcoded host is on a 4-entry allowlist.On the golden fixtures in src/privacy/redact.test.ts, redaction masks all seven planted secret classes with no false positives across 20 plain paragraphs — deterministically. The full methodology is in specs/privacy-security-spec.md, the one set of rules contributors cannot break.
HumanifyMe will not help you beat AI detectors, and the specs say so. The research backs the stance on the merits: detection is fragile — there is a theoretical bound on detector reliability and recursive paraphrasing defeats most detectors (Sadasivan et al., 2024) — and a tool that wins at fooling classifiers proves nothing about whether the output sounds like you. We track AI-tell density only as a sanity floor, never as a target.
Every design choice maps to prior work, and each write-up is explicit about where the science stops and our opinion starts: prior-work survey · state-of-the-art review · evaluation design. The deterministic verify gate, in particular, is a design bet against a named failure mode, not a validated published result. The full, linked reference list is below.
I wanted AI to write messages for me and it never quite could. I would have something typed up, ask it to just tighten the wording, and get back a completely different message in a voice that was not mine. So I started prompting my way around it, and that turned into this.
Most of the code was written with Claude Code, Anthropic's agentic coding tool, against specs and acceptance criteria I wrote and reviewed. The product and architecture calls are mine: plugin-first distribution, keeping everything local, the verify gate, and how it gets evaluated.
We want maintainers. Read CONTRIBUTING.md, then read src/engine/rewrite.ts, src/engine/verify.ts, and src/privacy/ — that trio is the heart of the methodology. The rules you cannot break live in specs/privacy-security-spec.md; when you change behavior, src/network/outbound-scan.test.ts and src/engine/verify.test.ts must stay green. Good first issues are labeled good first issue.
If HumanifyMe saves you from sounding like a robot, give us a ⭐ on GitHub and help spread the word. Stars and contributors are how an open-source project like this gets found.
Apache License 2.0. See LICENSE and NOTICE. The whole repository is open source, including the rewrite engine, prompts, and the privacy-critical modules, so anyone can verify exactly what data does and does not leave a machine. "HumanifyMe" is a trademark of Joshua McQueary; the license does not grant trademark rights.
Drawn from the project's prior-work survey.