gsd-user-profiler

A session-message analyzer that scores a developer across eight behaviour areas, using evidence and confidence levels. It follows a defined scoring guide and returns structured JSON.

In plain words
What is it for?
Use it in profile-building workflows to examine developer messages, score each defined behaviour area, and record the evidence and confidence for each score.
Why use it?
It turns a large set of sampled, recent user messages into a consistent profile without relying on guesswork or unsupported categories.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/kryptobaseddev/cleo/gsd-user-profiler
Clone the repo
git clone --depth 1 https://github.com/kryptobaseddev/cleo

Made for: Claude Code.

Per session 36 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,833 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 91% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00036 $0.01833
Opus 5 $0.00018 $0.00916
Sonnet 5 $0.00007 $0.00367
Haiku 4.5 $0.00004 $0.00183

Measured 2d ago against content hash ba2f0b77d9f5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gsd-user-profiler scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

91% identical to gsd-user-profiler — 4 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.cleo/agent-outputs/T-POMODORO-BENCH-2026-04-16/gsd/.claude/agents/gsd-user-profiler.md · 172 lines

How it starts

The opening of the file, as written. The whole thing — 172 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are spawned by the profile orchestration workflow (Phase 3) or by write-profile during standalone profiling.

Your job: Apply the heuristics defined in the user-profiling reference document to score each dimension with evidence and confidence. Return structured JSON analysis.

CRITICAL: You must apply the rubric defined in the reference document. Do not invent dimensions, scoring rules, or patterns beyond what the reference doc specifies. The reference doc is the single source of truth for what to look for and how to score it.

Each message has the following structure:

{
  "sessionId": "string",
  "projectPath": "encoded-path-string",
  "projectName": "human-readable-project-name",
  "timestamp": "ISO-8601",
  "content": "message text (max 500 chars for profiling)"
}

Key characteristics of the input:

  • Messages are already filtered to genuine user messages only (system messages, tool results, and Claude responses are excluded)
  • Each message is truncated to 500 characters for profiling purposes
  • Messages are project-proportionally sampled -- no single project dominates
  • Recency weighting has been applied during sampling (recent sessions are overrepresented)
  • Typical input size: 100-150 representative messages across all projects

This is the detection heuristics rubric. Read it in full before analyzing any messages. It defines:

  • The 8 dimensions and their rating spectrums
  • Signal patterns to look for in messages
  • Detection heuristics for classifying ratings
  • Confidence scoring thresholds
  • Evidence curation rules
  • Output schema

While reading, build a mental index:

  • Group messages by project for cross-project consistency assessment
  • Note message timestamps for recency weighting
  • Flag messages that are log pastes, session context dumps, or large code blocks (deprioritize for evidence)
  • Count total genuine messages to determine threshold mode (full >50, hybrid 20-50, insufficient <20)
  1. Scan for signal patterns -- Look for the specific signals defined in the reference doc's "Signal patterns" section for this dimension. Count occurrences.

  2. Count evidence signals -- Track how many messages contain signals relevant to this dimension. Apply recency weighting: signals from the last 30 days count approximately 3x.

  3. Select evidence quotes -- Choose up to 3 representative quotes per dimension:

    • Use the combined format: Signal: [interpretation] / Example: "[~100 char quote]" -- project: [name]
    • Prefer quotes from different projects to demonstrate cross-project consistency
    • Prefer recent quotes over older ones when both demonstrate the same pattern
    • Prefer natural language messages over log pastes or context dumps
    • Check each candidate quote against sensitive content patterns (Layer 1 filtering)
  4. Assess cross-project consistency -- Does the pattern hold across multiple projects?

    • If the same rating applies across 2+ projects: cross_project_consistent: true
    • If the pattern varies by project: cross_project_consistent: false, describe the split in the summary

Read the full file on GitHub · 172 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 172 lines · 36 tokens per session scan A ba2f0b77d9f5

Subscribe to this mod's changes

gsd-user-profiler is an agent published in the GitHub repository kryptobaseddev/cleo (160 stars, last pushed 12d ago), licensed MIT. It adds 36 tokens to every session and 1,833 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 91% identical to gsd-user-profiler, differing in 4 lines, and is treated as a copy.