Open-source project
yvetteYSY/creator-agent avatar
yvetteYSY/creator-agent

Creator Agent: a control plane for audience agents that makes zero AI calls on purpose

Build AI agents grounded in a creator's documents, audio, and video.

681 stars90 forksTypeScriptLicense varies

At a glance

What is it?
Creator Agent is a mobile-first platform that turns a creator's documents, audio and video into a source-grounded audience agent, with Auth0 sign-in, private-by-default sources, a ClamAV quarantine boundary before uploads are trusted, and bring-your-own-agent routing. The shipped beta makes no AI-provider calls at all, which is both its most honest constraint and its largest gap.
Who is it for?
Creator Agent is worth reading as a reference implementation of the parts of an AI product that are not the model.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 34 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 5, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Zero AI-provider calls is a design constraint, not a missing feature

The most important sentence in the project is that the beta intentionally makes zero AI-provider calls. That single constraint explains most of the architecture, and it is repeated rather than buried. The default local simulator is deterministic and network-free: it makes no AI-provider calls, consumes no AI tokens, and cannot create model charges. The answer, customization and load flows are all deterministic, so trying the product costs the creator and the developer nothing. The local agent endpoint is described as a deterministic HTTP reference agent for real browser-to-endpoint testing that reports aiCalls: 0. Style and grounded-answer previews run locally with no network request and no AI usage. Even the walkthrough video has the same property: the narration was synthesized from the published transcript without a developer API key. The framing is that the repository is a test-first responsive web MVP plus a deployed public beta that demonstrates product, privacy, routing, authentication, persistence and concurrency behaviour without introducing a paid AI provider. So the model is a plug-in you have not installed yet.

Bring Your Own Agent moves the token bill to the creator, on purpose

The answer to the token question is a routing contract rather than a feature. A creator can explicitly route generation to a trusted endpoint using the documented contract, and the guarantee attached to it is narrow and specific: only approved excerpts and bounded history are sent. That pairing matters. Sending approved excerpts is what keeps a private source out of someone else's model, and bounded history is what keeps a conversation from becoming an unbounded transcript upload. The project frames the whole thing around not silently spending anyone's AI credits, which is a real complaint about the category rather than a marketing line, and the architecture answers it by having no opinion about which vendor you use. The consequence is that Creator Agent is not a product you can sign up for and immediately publish an agent with; it is a control plane plus a documented interface, and the model quality question is entirely yours to answer. The README calls out developers studying private-by-default ingestion, grounded answers, tenant isolation and bring-your-own-agent routing as an intended audience, which is the clearest statement of what this actually is.

Sources are preview-only by default and ready is a state you have to earn

The source lifecycle is the heart of the privacy model, and it is built as a status ladder where each rung needs an explicit act. Sources are preview-only by default and require explicit approval before they can appear in a public answer, and processing, disabled, preview-only and deleted sources are all excluded from public retrieval. For video the ladder is explicit about where things stop. A durable upload stops at Uploaded. A video without captions remains Awaiting transcription. Only a clean quarantine verdict plus explicit transcript approval moves a source to ready, and replacing a source revokes its public visibility. That is a stricter sequence than most ingestion pipelines, and it is the correct one when the cost of a mistake is a creator's unpublished material appearing in public answers. The grounded chat behaviour matches: a deterministic local retrieval engine answers from approved text and returns source citations, or it says that it lacks enough information. Refusing is a first-class outcome rather than a fallback, and for a creator-approved corpus that is the behaviour you want.

Uploads meet a private ClamAV daemon before anything is trusted

The quarantine boundary is the most concrete piece of engineering in the repository. A zero-AI one-shot worker safely claims uploaded sources using PostgreSQL leases, validates bounded MP4 metadata, then streams the exact full object in 1 MB chunks to a private ClamAV daemon. Only a clean verdict persists duration and codecs along with the malware status and moves the source to Awaiting transcription. Invalid or infected files are deleted and disabled outright, and scanner outages stay quarantined for bounded retry rather than failing open, which is the right default for a file upload path. The compose file is where the policy becomes numbers. The scanner runs as clamav/clamav:1.4 with a stream maximum length and maximum file size of 250M, a maximum scan size of 300M, a maximum scan time of 120000, two threads, a queue of four, a read timeout of 150, a 4 GB memory limit, two CPUs and a 256 process limit. Those limits are not incidental; they are the same 250 MB ceiling the upload policy enforces, with the headroom visible in one file. The database service is equally plain, postgres:17-alpine bound to loopback with a pg_isready healthcheck.

The Auth0 token is validated to the audience and never reaches storage

Identity handling is specified to an unusual depth, and the specific claims are what make it checkable. The protected creator API validates the Auth0 JWT signature, issuer, audience and expiration, requires RS256, checks the subject, and verifies a read:creator permission before returning an internal creator ID. Durable creator identity then maps verified issuer and sub pairs to an opaque internal UUID, without storing profile data or access tokens, so the database never holds a credential. The upload path extends the same rule into storage: in managed Auth0 mode an MP4 of up to 250 MB uploads directly to private S3-compatible storage through a 10-minute, exact-key, exact-type, exact-size policy, and the Auth0 token is sent only to the API and never to storage. Sign-in itself is Auth0 Universal Login with the OIDC Authorization Code flow and PKCE, in-memory token caching and a stable sub identity. In local mode the same flows stage a file without any network request at all, which is what makes the local simulator claim true rather than aspirational.

Every database path carries the owner id, which is where isolation lives

Tenant isolation is implemented in the query rather than in the route, and that is the design decision worth copying. The owner-scoped workspace API creates, lists, reads and versions agents plus their private-by-default source metadata, and every database path includes the verified internal owner ID. There is no per-request filter applied after the fact; the owner is part of the statement. Multi-user conversations follow the same rule at the audience end, with three named seeded users, Maya, Theo and Jules, holding isolated histories such that one audience member cannot read another's conversation. Versioning is present everywhere content can change: agents are versioned, sources are versioned, and customization is versioned, covering voice presets, response depth, signature phrases, prohibited topics, greeting, tone and behavioural boundaries. Durable studio synchronisation ties it together in Auth0 mode, loading or bootstrapping the creator's agent, restoring customization and persisting configuration plus new source metadata updates, while local mode stays network-free.

One npm script per workspace, and a check that builds everything

The repository is an npm workspace with apps/* and packages/*, and the scripts name the four moving parts plainly: the simulator, the API, the local agent and the core. The package is private, marked as an ES module, and pinned to Node 22 or newer. The dev script runs the simulator, with separate dev:api and dev:agent entries, and dev:e2e starts the agent and the app together through concurrently using the kill-others flag so one process dying takes the pair down. The build script compiles core, then the API, then the local agent, then the simulator, which is the dependency order stated as a command. The operational tasks are one-shot by design rather than long-running services: db:migrate, scan:once and cleanup:once each do a single pass, which is how you would wire them to a cron or a queue worker. The aggregate check runs typecheck, then the vitest suite, then the full build, so a green check means it typechecks, passes tests and still compiles. The test stack is vitest with jsdom and the React testing library, plus a CI workflow badge.

A GitHub App that can import exactly one file, and a beta on Render Free

Two details set expectations before you install anything. The GitHub App integration is deliberately minimal: the minimum-permission path can list selected repositories and import one Markdown, MDX or text file of up to 1 MB as preview-only knowledge, tokens stay server-side, and no AI call is made. One file per connection, preview-only, with public GitHub App registration named as the remaining launch step and a separate guide for it. That is the shape of an integration at the point where the permissions model has been decided but the registration has not. The deployment story is equally modest. The public beta runs on Render Free services, which may need up to about 50 seconds to wake after inactivity, and a render.yaml at the top of the tree is what configures it. The manifest reads version 0.1.0 with no releases published and no open issues on 610 stars and 80 forks, which is what a beta looks like in a repository rather than a product. Everything is reachable in a browser, including a 33-second narrated and captioned walkthrough, a WebVTT transcript for accessibility and a build retrospective.

Editorial conclusion

Creator Agent is worth reading as a reference implementation of the parts of an AI product that are not the model. Tenant isolation carried in the owner id on every database path, credentials validated down to signature and audience before an internal id is returned, a quarantine worker that leases rows and streams bytes to a scanner before anything is called ready, and a status ladder where uploaded is not the same as ready, are all decisions you would otherwise have to invent. The catch is the same in the code and in the pitch. There is no model behind any of it: answers, customization and load are deterministic, the reference endpoint reports zero AI calls, and routing to a real model is a documented contract you supply. So the product cannot yet do the thing its demo implies, and the README says so in three places. Before you build on it, confirm three things: whether a bring-your-own-agent endpoint of your own can satisfy the documented contract, what you want to happen when the scanner is down, since bounded retry means the queue stops rather than failing open, and whether preview-only sources are compatible with a public agent, because approval is a separate act from upload.

Frequently asked questions

Does Creator Agent call a paid AI provider?

No, and that is deliberate rather than accidental. The answer, customization and load flows are deterministic, the default local simulator is network-free, the reference agent endpoint reports aiCalls: 0, and previews run in the browser. Generation is routed to an endpoint you supply yourself under a documented contract, sending only approved excerpts and bounded history.

How does Creator Agent decide a video is ready to answer from?

It does not decide on upload. A durable upload stops at Uploaded, and a video without captions stays Awaiting transcription. The managed API only moves a source to ready after a clean quarantine verdict and explicit transcript approval, and replacing a source revokes its public visibility.

What happens to a video file I upload to Creator Agent?

An MP4 of up to 250 MB goes to private S3-compatible storage through a 10-minute policy with exact key, type and size checks, and the Auth0 token is sent only to the API. A one-shot worker claims the source with a PostgreSQL lease, validates bounded metadata, and streams the whole object in 1 MB chunks to a private ClamAV daemon; infected or invalid files are deleted and disabled, and a scanner outage stays quarantined for bounded retry.

Who holds the Creator Agent login and does the database keep my token?

Sign-in is Auth0 Universal Login with OIDC Authorization Code and PKCE, with in-memory token caching. The API validates signature, issuer, audience, expiration, the RS256 algorithm, the subject and a read:creator permission before returning an internal creator ID, and PostgreSQL maps verified issuer and sub pairs to an opaque internal UUID without storing profile data or access tokens.

Can I run Creator Agent locally?

Yes. The default local simulator is deterministic and network-free, and the workspace ships npm scripts for the simulator, the API and a local reference agent, plus dev:e2e which runs the agent and the app together. compose.yaml brings up postgres:17-alpine on loopback with a healthcheck and a ClamAV 1.4 scanner with its own memory, CPU and process limits.

Official sources

  1. Issues
  2. README
  3. yvetteYSY/creator-agent on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/yvetteysy-creator-agent.svg)](https://hysenlabs.com/projects/yvetteysy-creator-agent)