I build local-first tools for understanding, verifying, controlling and
extending AI coding agents — a public devin-* ecosystem organized as
seven products · four jobs · one foundation. Distributed through a
profile-based DevKit, with a maintainer hub and related artifacts in the
catalog.
The ecosystem by job — the products pinned on this profile:
| Track | Packages | ||
|---|---|---|---|
| Understand | devin-explore |
doctor · history · search · graph · pm | What happened in the agent? Diagnose the install, export history, FTS5 search, knowledge graph, per-repo rollups — all local, no telemetry |
| Verify | devin-assure |
qa-pack · evals · metrics | Did the agent do what it said? Flagship evidence gate — PASS / PARTIAL / UNVERIFIED from recorded tool calls |
| Control | devin-control |
bridge · orchestrator · switch · office | Policy-gated ACP client — allow / deny / ask, fail-closed, per-repo session isolation |
| Control | devin-judge |
poordjaevin | Calibrated yes/no/score answers for agentic workflows — measured ECE 0.170 → 0.071 on the shipped eval set |
| Build | devin-devkit |
devkit · skill-catalog | Profile-based distribution: registry-driven installs for Linux, Personal Windows and Corporate Windows |
| Build | devin-brain |
memory | Anti-poisoning memory store — provenance, versioning, quarantine gate, session-learning utilities |
Also in the catalog: devin-state
(Control — redact · backup · janitor) and
devin-internals-spec, the
Foundation — the typed contract for Devin's local stores that the packages
depend on; infrastructure, not an install target.
Start here: audit an agent → devin-assure ·
diagnose an install → devin-explore ·
browse everything → awesome-devin
By role — ordered paths through the ecosystem:
- AI engineers:
devin-control→devin-orchestrator→devin-brain - Data Scientists:
devin-graph→devin-search→devin-history→devin-metrics - DevOps engineers:
devin-state→devin-bridge→devin-switch - Developers:
devin-devkit→devin-skill-catalog→devin-internals-spec→devin-powerups - Local-first ops:
devin-explore→devin-pm→devin-office→devin-backup→devin-janitor - QA engineers:
devin-assure→devin-evals→devin-judge
devin-office: local session dashboard. Live view when a Devin session source is available; demo mode uses synthetic data. Circuit board (above) and a session kanban (RUNNING · BLOCKED · REVIEW · CLOSED) · open the kanban demo
One registry (devin-powerups) is
the source of truth; devin-devkit
is the distribution layer that installs it under three declared environments:
| Environment | Runtime | Install |
|---|---|---|
| Linux | Extended | devin-devkit install full --environment linux |
| Personal Windows | Extended | devin-devkit install full --environment personal-windows |
| Corporate Windows | Local-only | devin-devkit install full --environment corporate-windows |
Extended mode runs locally plus optional Devin VM/QwenPaw delegation where a
tool supports it. Corporate Windows is local-only: no VM, QwenPaw, Slack
dependency, external compute or workload delegation — and it is selected
explicitly, because the OS alone cannot distinguish a personal Windows machine
from a restricted one. The registry records per-tool compatibility; the DevKit
previews the plan before installing (--apply to commit).
See the ecosystem in action → reproducible agent-assurance demo: synthetic sessions with known defects → schema check → claim audit → rubric grading, end to end.
The ecosystem — 7 products · 19 first-party tools · 1 distribution layer · 1 registry hub · 2 related artifacts (23 entries)
(Understand / Verify / Control / Build are the public tracks; Operations, Distribution and Maintainer hub are support roles.)
| Group | Repo | What it does |
|---|---|---|
| Foundation | devin-internals-spec |
Documented internals of Devin Desktop/CLI stores + schema-version detection + fixtures + devin-inspect CLI. |
| Control | devin-state |
Devin state lifecycle monorepo: secret/PII redaction (devin-redact), store snapshot backup/restore (devin-backup) and session janitor (devin-janitor), sharing the devin-install-scheduler package. |
| Understand | devin-history |
Export and audit Devin session history — markdown notes, JSON, CSV, Obsidian-ready. |
| Understand | devin-explore |
Understand Devin sessions: diagnose the local installation (stores, schema, locks, config, disk — with fix suggestions), export and audit session history, run FTS5 full-text search, query a knowledge graph of sessions/projects/files/tools, and roll sessions into per-repo milestones and status reports. All local, no telemetry. |
| Understand | devin-pm |
Project manager over sessions: per-repo rollups, milestones, status reports, registry.json. |
| Verify | devin-assure |
Verification monorepo: session-claim audit (devin-qa-pack), deterministic eval harness with dream corpus generator (devin-evals), and local session observability (devin-metrics). |
| Verify | devin-metrics |
Local-only session observability: activity, context size, and token peaks per project/model/day; zero telemetry. Devin does not persist cost fields, so cost is not claimed. Includes an optional dashboard subpackage and command. |
| Control | devin-backup |
Safe snapshot/verify/restore/rotate of Devin stores with schema-version manifests. |
| Understand | devin-search |
FTS5 full-text search across all Devin sessions, role-tagged and project-filtered. |
| Understand | devin-graph |
Knowledge graph: sessions, projects, files touched, tools used — queryable edges. |
| Verify | devin-evals |
Deterministic eval harness: replay recorded sessions against rubric graders; the dream subgroup generates synthetic sessions with known verdicts (D01-D10, absorbs devin-dream). |
| Build | devin-brain |
Anti-poisoning memory store: provenance, versioning, quarantine gate, and session-learning utilities. |
| Control | devin-janitor |
Session lifecycle janitor: export-then-delete pipeline, tiered classification, pluggable judge, pending-retry for locked stores. |
| Control | devin-control |
Control how Devin runs: a policy-gated ACP bridge (Node.js, isolated sessions per repo with allow/deny/ask rules), a deterministic background-worker fan-out planner (devin-fanout), config profile switching with snapshot and rollback, and a live activity board (office, source-only). |
| Control | devin-orchestrator |
Background-worker fan-out policy: deterministic planner enforcing worker caps (max 3), no nesting, read-only profiles for review, collect-before-report. Skill + always-on rule. |
| Control | devin-office |
Local-first Devin session and subagent dashboard with standalone and optional split modes. |
| Control | devin-judge |
Djævin: calibrated local-first decision layer with typed questions and honest confidence. The Devin ACP backend reuses the model your Devin CLI already runs (no extra download, no API key); the local NLI backend stays as a fully-offline fallback. |
| Control | devin-switch |
Switch between Devin configuration profiles (hooks, MCP, models) with snapshot, sha256 verify, atomic write, journal and rollback. Dry-run by default; secrets never printed. |
| Build | devin-skill-catalog |
Lifecycle + quality gates for .devin skills/rules: scan, lint, diff, G1/G2 gates, quarantined→approved→active lifecycle, sha256-verified export/import bundles (imports land quarantined). |
| Distribution | devin-devkit |
Build on the ecosystem: profile-based installer for the public Devin tools across Linux, Personal Windows and Corporate Windows (isolated uv environments, npm bridge), plus lifecycle and quality gates for .devin skills/rules via devin-skill-catalog. |
| Maintainer hub | devin-powerups |
Public maintainer hub: registry, roadmap, project template, scaffolder, release checks, and community catalog generators. |
| Related Suite | qwenpaw-suite |
Optional QwenPaw add-on for self-hosted model operators. Includes the local-model bridge, health checks, and GitHub/local documentation sync. |
| Related Resource | awesome-devin |
Curated awesome-list of Devin tooling and resources (CC0). |
Every project adapts an existing, proven tool plus one Devin-specific extra that must pass three tests:
- does something the base tool cannot do
- the extra disappears without Devin
- explainable in one sentence
Tools are local-first and send zero telemetry. Destructive or mutating operations are explicit, guarded, and dry-run by default where applicable.
Yes — no VM, no tunnel, no model server, no Slack, no Obsidian. The
DevKit-installable catalog still works on a locked-down corporate machine.
The exceptions are explicit in the registry: devin-control (the npm bridge) needs Node.js
≥ 20 (it is an ACP client for the Devin CLI itself); poordjaevin has a
fully offline NLI fallback; qwenpaw-suite is an optional related suite and
is unsupported in Corporate Windows.
Linux: pipx install devin-doctor — requires Python ≥ 3.10.
Windows: same via py -m pip install --user pipx. Each README documents
the exact data paths and --data-dir overrides for both systems.
The catalog composes into a standing agent runtime when the machine is yours. Each optional piece adds one capability — none is required:
| Optional piece | What it adds |
|---|---|
Hooks (SessionEnd, Stop, UserPromptSubmit) |
Automatic history export and lesson extraction after every session |
| An MCP memory store | Decisions and conventions that survive across sessions |
| A notes vault (e.g. Obsidian) | Curated long-term memory — decisions, learnings, transcripts |
| A scheduler (cron / Task Scheduler) | Periodic checklists — heartbeat, janitor, scheduled reports |
| A comms channel (e.g. Slack) | Talk to the agent and get notified remotely |
poordjaevin as judge |
Cheap yes/no/rate answers — via Devin's own model (ACP), or a fully offline local model |
On a locked-down machine the catalog runs on demand and most of the runtime can still be reconstructed locally:
- Memory and learning are unaffected. Hooks are event-driven
(
UserPromptSubmit,Stop,SessionEnd), so prompt logging, lesson extraction and history export keep working without any scheduler. The MCP memory store andlearned-*skills only need a writable Devin config directory. - Proactivity is mostly recoverable. Instead of a cron heartbeat,
elapsed-time checks can piggyback on
UserPromptSubmit— a checklist runs whenever you are active, which is when it matters. A persistent background loop (while sleep; do devin acp …) is equivalent while the machine is on. - Outbound restrictions are a non-issue — the read/audit tools run
fully offline. Only explicit opt-ins touch the network:
devin-devkitdownloads installs over HTTPS anddevin-control(the npm bridge) speaks ACP to the local Devin CLI.
What a corporate machine genuinely cannot provide:
- Wake-while-idle. With no scheduler and the session closed, nothing ticks — a suspended laptop has no heartbeat.
- Remote reach. Without Slack (or any comms channel), the agent can detect something urgent but cannot reach you. Deferred notification — flag files read on your next prompt — works, but late.
- Offload. Heavy work (browser automation, builds) runs locally and competes for the machine's RAM.
- Multi-machine topology. No tunnel means
devin-officeprobes and hubs are confined to loopback.
The runtime is an enhancement, never a dependency — roughly 90% of it survives a locked-down machine.
The public tools target Linux, Personal Windows and Corporate Windows. Shared
purpose and usage stay in README.md; each repository's Windows and Linux
guides carry platform-specific installation, Devin paths, PATH setup,
scheduling, and troubleshooting. The DevKit additionally documents the
corporate local-only mode and a registry-generated compatibility matrix.
macOS is planned but not yet claimed as tested.



