VYPR
researchPublished Oct 8, 2026· 1 source

New Scripts Aid Forensic Analysis of AI Coding Assistant Activity

Two Python scripts, opencode-chat-replay.py and hermes_forensic_extract.py, have been released to help investigators reconstruct activity logs from popular AI coding assistants.

Security researchers have developed new tools to aid in the forensic investigation of activity generated by AI coding assistants. Two Python scripts, opencode-chat-replay.py and hermes_forensic_extract.py, are now available to parse and reconstruct data from AI tools such as OpenCode and Hermes.

These scripts are designed for incident response and digital forensics, enabling investigators to examine chat histories, model usage, API requests, and application logs. The primary goal is to make the recorded activity of these AI agents accessible and understandable, detailing user prompts, assistant responses, and any tool activity that was captured. The tools are not intended for running or replaying agent actions but for reconstructing evidence from systems under review.

Both scripts require Python 3.10 or later and rely solely on the Python standard library. They offer options to specify a time range for extraction using --start and --end parameters, and can target specific database files or directories where evidence might be stored, such as from a mounted disk image or a collected system archive.

The opencode-chat-replay.py script focuses on reconstructing chat transcripts from OpenCode's SQLite database. It supports different storage methods, including newer consolidated session data, and can output results in readable Markdown or structured JSON formats. The script can list available sessions, allowing investigators to select specific sessions by ID, slug, or by choosing the most recent one.

When generating transcripts, the opencode script includes session metadata such as ID, timestamps, cost, and token usage. The conversation turns are presented in numbered role sections, with reasoning and tool calls optionally displayed in collapsible blocks to maintain readability while preserving detailed information.

In contrast, the hermes_forensic_extract.py script extracts a broader spectrum of evidence. This includes conversation records, details on model usage, dumps of API requests, and application logs. The script aims to provide a comprehensive view of the AI agent's operational footprint, going beyond simple chat logs to capture more technical interaction data.

Before querying the SQLite databases, both scripts create a temporary copy of the database files and associated WAL/SHM files. This precautionary step prevents potential modifications to the original evidence files, ensuring the integrity of the data being analyzed. The scripts then open this snapshot in read-only mode and clean up the temporary files afterward.

The development of these forensic tools highlights the growing need for specialized methods to investigate the increasingly complex digital footprints left by AI agents. As AI coding assistants become more integrated into development workflows and potentially other sensitive operations, the ability to forensically analyze their activity is becoming crucial for security and compliance.

Synthesized by Vypr AI