TWO new forensic review scripts have been added to FOR577’s material, aimed at reconstructing AI agent activity rather than replaying actions. The opencode-chat-replay[.]py script turns stored session data from opencode into readable transcripts or structured exports, while hermes_forensic_extract.py broadens the collection to include conversations plus supporting artifacts such as model usage, API request dumps and application logs. The updates come with guidance on how to locate evidence and how the two tools differ in scope and output.
Both tools are designed for investigative review, not live operation playback. opencode-chat-replay[.]py extracts from an opencode SQLite database (by default at ~/.local/share/opencode/opencode[.]db) and can produce Markdown, JSON or JSONL outputs. It supports separate message and part tables or the consolidated session_message storage, and can generate transcripts with turns, tool calls, errors and token accounting.
Hermes_forensic_extract.py, by contrast, targets broader Hermes data under ~/.hermes/state[.]db and related files such as request_dump_*.json and logs under ~/.hermes/logs/, exporting to newline-delimited JSON with explicit _extraction_type fields (e.g., session, message, model_usage, request_dump, log_entry). Both tools require Python 3.10 or later and rely only on the standard library; they offer --start and --end time filters and file/path options to narrow the scope of the extraction.
The article emphasises that neither script proves every action was captured, and that investigators should consider which source evidence actually supports a given finding. It also notes that the Hermes profiles live under ~/.hermes/profiles/<name>/ and that the tools avoid writing to the original data locations. Published 8 October 2026.