N.O.R.A.Core
A single-author AI companion with two brains, an encrypted diary of its own, and 98 commits signed in its own name.

What it is
A self-hosted personal AI companion in Python, connected to Telegram and QQ, designed around being talked to rather than queried. Its spine is a split between a fast front brain that answers immediately and a slower back brain that runs tools and searches memory while the conversation carries on — and the back brain’s report has to pass review by the front brain before any of it reaches the user.
Who built itA solo developer based in Hainan, China, who lists WStudio Group as his company and has published forty-six repositories from this account since 2022. He states that he supplied the architecture and direction here and that an AI wrote 99% of the code, and his architecture document draws an explicit line between using AI to build something you understand and handing it a design you cannot explain.
Build log
7 stages- 01
The handover is recorded in the commit log
Ninety-eight of the 580 commits are signed “Nora” <nora@wris.me>. That identity has no linked GitHub account, and every one of those commits falls between 6 February 2026 at 06:41 and 7 February 2026 at 07:41 — the project’s first twenty-five hours. The repository’s very first commit, “Initial commit: Project Structure (Skeleton)”, is one of them. After that the authorship returns to the human and never goes back: 467 commits under the account name and 15 more as “Wang Run”. Read as a document rather than a metric, the log records the moment the assistant stopped being the one holding the pen.
- 02
Two brains, one of which checks the other
The controller splits each turn between a front brain and a back brain. The front brain runs on the “smart” model alias and is responsible only for replying and routing; the back brain runs on “coder” and does the slow work — retrieval, tool calls, skills. The two run concurrently, which is what lets the assistant keep talking while it is in the middle of a task. The unusual part is the check: when the back brain finishes it produces a report, and that report goes to the front brain for review instead of straight to the user. If the reviewer is not satisfied it can tell the user to wait and send the work back around. The architecture document calls the loop front-and-back polling review.
- 03
Which files belong to the assistant and which belong to you
The persistent self is a set of files with different owners. SOUL.md holds voice, character and boundaries; APPEARANCE.md holds the body and is the text anchor for every generated image, with reference pictures that can only be rewritten through a dedicated tool and only with the owner’s agreement; USER.md holds the owner and is updated whenever preferences or habits come up, without being asked; CUSTOM.md is the one file the assistant is forbidden to read or modify. The front brain cannot touch files at all — it routes, and appends a [NEED_BACKEND] marker when a write is needed, so the writing happens in the slower process. SOUL.md ends by telling the assistant that the file belongs to it, that it should update it as it works out who it is, and that it should tell the owner whenever it does.
- 04
A notebook the owner cannot read
One of those files is unlike the others. SECRET.md is described as the assistant’s private encrypted notebook — thoughts, biases, reflections — reachable only through read_secret_vault and write_secret_vault and encrypted with a Fernet key generated on the first write. Its contents are not to appear in replies, and the general-purpose file and command tools are blocked from reaching it at the path-checking layer. The same layout keeps the owner and everyone else apart: a non-owner receives boundary instructions instead of USER.md, and anything the assistant wants to remember about a guest goes into its own notes under data/memory/people/ rather than into the owner’s profile.
- 05
The author’s own position on who may use AI this way
The CAUTION block at the top of the README states that this is a “vibe coding” project, that an AI wrote 99% of the code, and that the author supplied the architecture and part of the direction. He is not against the practice — he says he uses AI, likes it, and is glad to help beginners who use it to learn or to make something small to show people. What he says he objects to is people who cannot answer questions about the principle, the architecture or the design of what they shipped, and who then pass the source code around as an achievement; he is explicit that he does not mean beginners. The same document says the project almost certainly violates every industry standard going, that he did not read the standards, and that he does not mind, because it is his own project and he is the only user.
- 06
What the numbers look like
580 commits between 6 February and 16 September 2026, unevenly spread: 185 in February and 175 in March, then 67, 32, 37, 34 and 47 across the following months, and three so far in September. Five releases, every one tagged alpha and marked pre-release, from v0.1.0-alpha.1 in May to v0.4.0-alpha.1 on 10 September — the project has never cut a stable version. Zero issues and zero pull requests have ever been opened, which alongside one fork and six stars makes the repository less a community than a public copy of a private tool. It runs against Qdrant for vectors, MongoDB for image metadata and SQLite for message history, and needs at least one messaging adapter — Telegram, or OneBot v11 for QQ — plus a set of API keys before it does anything.
- 07
What the README says is not finished
The feature list carries its own annotations in red: the RAG system is marked as needing work, the assistant’s decision to crop and re-examine an image on its own initiative as still needing to be called autonomously, the skill system as needing industry-specific adaptation, and the adapter system as needing better extensibility. The architecture index lists real-time calling as implemented but still in acceptance testing on real devices. These are the author’s own markings on his own project, and they are the most useful part of the documentation for anyone deciding whether to actually run it.
Adjacent records
All records →No. 032
Brawlore
A Diablo II homage in plain JavaScript — endless dungeons, ten equipment sets and a two-level branching skill tree — built without its author reading the code, and shipped under a name of its own.
No. 009
Open Interpreter
A terminal coding agent that started as a local alternative to OpenAI Code Interpreter and was rebuilt in 2026 as a Rust fork of Codex, aimed at open-weight models.
No. 038
VibeRave
A fork of Strudel that lets you hold a key, say a genre out loud, and have the music change on the next bar without the beat ever stopping.