Repository intelligence

cvat-ai/cvat

GitHub

A free, self-hosted open-source data annotation platform designed to build high-quality visual datasets for computer vision and visual AI [1].

CLOUDM0N decision
REVIEW BEFORE ADOPTION
Trust REVIEW · 55/100
Good fit if

AI research and production teams seeking to host their own private data annotation platform [1-3].

Watch out for

Advanced features such as SAM 2/SAM 3 auto-labeling, project analytics, quality control UI, AI agents, and SSO are excluded from the Community edition [6].

Practical intelligence

What matters before you adopt it

Problem it solves

The lack of secure, collaborative, and programmatic tools for managing and labeling high-quality visual datasets locally without sacrificing data ownership or exposing proprietary images to external environments [2, 4].

Best for
AI research and production teams seeking to host their own private data annotation platform [1-3].
Annotation teams needing to collaboratively label image, video, and 3D point cloud datasets [2, 4, 5].
Developers wanting to programmatically automate dataset imports, exports, and task creations [2, 4, 6].
Main trade-offs
Advanced features such as SAM 2/SAM 3 auto-labeling, project analytics, quality control UI, AI agents, and SSO are excluded from the Community edition [6].
Serverless dependencies and FFmpeg libraries may operate under different, non-MIT licenses (such as LGPL/GPL or non-commercial) [7].
Platform compatibility is restricted to Chromium-based browsers; Firefox contains caveats, and Safari/WebKit is unsupported [8].
Why it stands out
Ensures complete data ownership by running entirely on self-hosted infrastructure [2].
Released under a permissive MIT license [2, 7].
Supports multiple rich data modalities including images, videos, and 3D point clouds [2, 5].
Trust & CVEs

Security evidence without the noise

Trust remains a decision signal; CVEs and scanner evidence explain what is driving the risk.

Security findings
3
CLOUDM0N scanner findings
Critical
0
High
1
Medium
2
Low
0
View trust evidence & security findings
Why this score
No trust rationale was stored for this scan.
CLOUDM0N findings
HIGH
Container configuration requests host-level control or isolation bypass. 3 sample match(es) found.
MEDIUM
The project can spawn operating-system processes; review command construction and input handling. 5 sample match(es) found.
MEDIUM
1 lifecycle install script(s) require review.
Architecture from code20 modules · 11 edges
Structural evidence

Modules and dependency edges extracted from repository code. This is code evidence, not README inference.

Code files
1627
Modules
20
Dependency edges
11
Core modules
(root)
6 files
components
UI components
1 files
cvat
436 files
cvat-canvas
24 files
cvat-canvas3d
12 files
cvat-cli
19 files
cvat-core
108 files
cvat-data
6 files
cvat-sdk
66 files
cvat-ui
542 files
dev
2 files
serverless
18 files
Dependency flow
(root)cvat
(root)cvat-canvas
(root)cvat-canvas3d
(root)cvat-core
(root)cvat-data
(root)cvat-ui
cvatutils
cvat-ui(root)
utilscvat
Detected languages
TypeScript · Python · JavaScript · Shell · SQL
Detected frameworks
NumPy · Requests · Webpack
Architecture evidence details
flowchart TD
    %% cvat — high-level architecture (DRAFT, refine me)
    n0["(root) · 6 files"]
    n1["components · UI components · 1 file"]
    n2["cvat · 436 files"]
    n3["cvat-canvas · 24 files"]
    n4["cvat-canvas3d · 12 files"]
    n5["cvat-cli · 19 files"]
    n6["cvat-core · 108 files"]
    n7["cvat-data · 6 files"]
    n8["cvat-sdk · 66 files"]
    n9["cvat-ui · 542 files"]
    n10["dev · 2 files"]
    n11["serverless · 18 files"]
    n12["site · 4 files"]
    n13["tests · tests · 375 files"]
    n14["utils · utility helpers · 8 files"]
    n0 --> n2
    n0 --> n3
    n0 --> n4
    n0 --> n6
    n0 --> n7
    n0 --> n9
    n0 --> n13
    n2 --> n14
    n9 --> n0
    n13 --> n0
    n14 --> n2
    class n14 shared
    class n13 test
    class n1 ui
    classDef shared fill:#79706e,color:#ffffff,stroke:#5d5654
    classDef test fill:#499894,color:#ffffff,stroke:#397975
    classDef ui fill:#4e79a7,color:#ffffff,stroke:#3a5b80
Evidence, security & integrations
Integrations
Docker Engine [8].Docker Compose [8].Git [8].Google Chrome [8].Microsoft Edge [8].Python SDK [6].AWS [4].Kubernetes [4].
Security notes
Self-hosted architectures ensure complete privacy since no data leaves the team's personal infrastructure [2].
Vulnerabilities must be evaluated against the project's Security Policy, and critical problems can be reported privately to [email protected] [7].
Still unknown
The README does not specify minimum or recommended hardware resources (RAM, CPU cores, or GPU capacities) needed to run CVAT or deploy Nuclio models [3, 5, 8].
The exact command-line syntax for booting the default Docker stack and creating the admin superuser is omitted from the text [9].
It is noted that Firefox works with 'some caveats' but those caveats are not explicitly defined [8].
Adoption guidance
Adopt if
+ You have strict data-privacy regulations that mandate that all data and labeling infrastructure remain entirely on-premise [2].
+ You require robust manual and automated multi-modal annotation (images, videos, 3D point clouds) across dozens of dataset formats [2, 4, 5].
+ Your pipeline requires deep programmatic automation using Python scripts or REST webhooks [2, 6].
Avoid if
Your annotator team relies strictly on Safari or other non-Chromium WebKit browsers which are not supported [8].
You require advanced enterprise features such as SSO, SAM 2/SAM 3 auto-labeling tools, AI agents, or specialized quality control panels in the free community tier [6].
How it works & getting started
How it works
1.The user clones the repository and deploys the default stack using Docker Compose [8, 9].
2.The administrator creates a superuser account for platform governance [9].
3.The user logs into the local interface via a Chromium-based browser [8, 9].
4.The user uploads raw images, videos, or point clouds, sets up a project, and defines target annotation labels [9].
5.If auto-labeling is needed, the serverless infrastructure is enabled, and models are deployed using nuctl [3, 5].
Getting started
Clone the repository and start the default stack using Docker Compose [8, 9].
Create an admin superuser account [9].
Open http://localhost:8080 in a Chromium-based web browser and log in [8, 9].
Create a project or task, upload your image/video/point cloud data, define labels, and start labeling [9].
Agent handoff
Use with any agent
JSON API
Alternatives

Nearby repositories worth comparing before adoption.

Compare top options →
repowise
repowise-dev/repowise
63
Fit

Repowise is your AI team's new best friend when it comes to understanding codebases at scale. It tackles the messy reality of large codebases by automatically generating documentation, surfacing git analytics, spotting dead code, and extracting architectural decisions — all through the Model Context Protocol (MCP). Whether you're onboarding new devs, debugging legacy code, or feeding context to your favorite AI coding assistant, Repowise turns chaotic repositories into structured, queryable intelligence. With 1.3k stars and growing fast, this tool is quickly becoming essential for teams that want to ship smarter, not harder.

Trust REVIEW · 55
Compare →
Claude-Code-Agent-Monitor
hoangsonww/Claude-Code-Agent-Monitor
54
Fit

🚀 A real-time monitoring dashboard for Claude Code & Codex, built with SQLite3, Node.js, Express, React, Vite, TailwindCSS, & WebSockets. It tracks sessions, agent activity, tool usage, and subagent orchestration, providing live analytics, a Kanban status board, status notifications, a cute buddy, & an interactive web UI/MacOS/Windows native app.

Trust REVIEW · 20
Compare →
XActions
nirholas/XActions
51
Fit

⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/GPT), CLI, browser scripts. No API fees. Open source. Unfollow people who don't follow back. Monitor real-time analytics. Auto follow, like, comment, scrape, without API. Follow Bot. Like bot. Grow your account automatically.

Trust REVIEW · 45
Compare →