You can feel AI-generated writing before you can prove it. The cadence is a little too even. Every paragraph lands in the same place. The metaphors arrive on schedule, the transitions click like turnstile gates, and somewhere in the third paragraph a sentence begins "It's not just X — it's Y." Readers have learned to spot it, editors have learned to dread it, and now the research has caught up too: a 2026 study called StoryScope found that a classifier looking only at narrative structure — never at word choice — could separate human stories from AI stories with 93.2% macro-F1. When researchers then ran the AI stories through a dedicated "humanizer" that polished the surface, detection barely budged, from 95.5% to 93.9%. The giveaway was never the vocabulary. It was the skeleton.

That finding is the entire thesis of Sepia (Nanako0129/sepia), the MIT-licensed writing skill that has quietly become one of the fastest-climbing open-source AI projects of the month: about 2,900 GitHub stars, 191 forks, and 303 commits as of September 30, 2026, up from roughly 2,700 at the start of September — a project created on August 28 that earned a spot in this week's trending-open-source-AI roundups. Sepia doesn't swap synonyms or sprinkle in typos to fool a detector. It diagnoses and rebuilds prose at the structural layer: the narrative architecture, the discourse flow, and only then the surface style. In this tutorial you will install it two different ways, validate its persona checker against a real profile, run its full test suite, and walk a release note through its review protocol exactly as the skill prescribes. Every command below was actually run and every result observed.

The de-AI writing space has been dominated by two unsatisfying options: black-box "humanizer" web apps that paraphrase your text into slightly different slop, and style guides that tell you to delete em-dashes. Sepia is neither. It ships as an agent skill — a markdown protocol plus scripts that an AI coding agent executes — built on two pieces of original research the author published alongside the code.

The first is StoryScope (arXiv:2604.03136): 61,608 stories from humans and five frontier LLMs, where a classifier using only narrative-structure features — plot shape, emotional arc, pacing — hit 93.2% macro-F1. Surface-level humanization barely moved the needle. The second is SLOPSHAPE-2026 (arXiv:2609.15369): 2,250 real company blog posts set against 11,250 AI-written mirrors, separable at 98.0 macro-F1 from structural features alone. The moral both papers push, and the one Sepia is engineered around: AI flavor is a structural phenomenon, so the fix has to be structural.

The project itself moves fast. Version v0.12.2 is current, with 14 releases and commits landing as recently as September 24, 2026. The repository carries a full test suite, a behavioral-eval harness wired into CI, and a persona system for locking in a human voice — unusual rigor for a writing tool, and a large part of why developers are starring it.

2. What you'll need#

  • Node.js 18+ — for the universal install in Step 1. We used the Skills CLI at version 1.7.0, installed on the fly with npx; nothing to configure by hand.
  • Python 3 — only for the persona validator in Step 4. Any recent Python 3 works; no third-party packages needed.
  • An agent host that executes skills — Claude Code, Muse, Cursor, Windsurf, or anything else the skill supports — because Sepia's four main operations run as agent-executed protocols. The install and validation steps below need no model at all.
  • No API key, no account, no cost. Sepia is a markdown protocol plus local scripts. It calls no model itself; your agent host supplies the intelligence.

3. Step 1 — Install it everywhere with the Skills CLI#

The fastest route is the Skills CLI, which the README says supports 77+ agents. One command installs all six Sepia skills globally:

npx -y skills add Nanako0129/sepia -g --yes

Here is the real output from our run:

✓ Installed sepia, sepia-hemingway, sepia-recreate, sepia-refactor, sepia-review, sepia-write
✓ Created symlinks for: Claude Code (/home/hatch/.claude/skills)
Note: PromptScript does not support global skill installation. Please create a new project or add to an existing project to install sepia skills.

Six skills landed in ~/.agents/skills/ and were symlinked into ~/.claude/skills/ for Claude Code in a single pass — about ten seconds, no prompts, no errors. Two details worth knowing. First, the -g flag matters: without it the skills install into the current project only. Second, that PromptScript note is worth reading twice: on platforms that don't support global skill installation, the global install partially fails, and the CLI tells you so honestly. Drop the -g (and the --yes) on those platforms to install into a project instead.

4. Step 2 — The native Codex install#

If you live in Muse, Sepia also ships as a native plugin, and this path worked end to end in our sandbox with codex-cli 0.149.0. Two commands:

codex plugin marketplace add Nanako0129/sepia
codex plugin add sepia@sepia

The first registers the GitHub repo as a plugin marketplace; the second installs the plugin from it. Verification is one more command:

codex plugin list
PLUGIN       STATUS              VERSION  PATH
sepia@sepia  installed, enabled  0.12.2   /home/hatch/.codex/.tmp/marketplaces/sepia

Installed, enabled, version 0.12.2 — matching the latest GitHub release exactly. The README documents equivalent native paths for Claude Code (claude plugin marketplace add Nanako0129/sepia followed by claude plugin install sepia@sepia --scope user), plus manual copy installs for Grok, Antigravity, and QwenPaw. One architectural note from the skill source that matters here: the five operation skills all depend on the canonical sepia skill next to them — install the complete package, never a single skill file on its own, or the slash commands will reference rules that aren't there.

Three translucent layered sheets floating above a manuscript, illustrating revision from deep structure to surface style
Sepia revises in three passes — narrative architecture first, discourse flow second, surface style last. Illustration: AI Frontier Post.

5. Step 3 — Meet the six skills#

The install gives you six skills, but conceptually there are four operations plus a router and a style-clone specialist:

  • sepia — the router. You describe your draft and intent; it asks at most two or three clarifying questions, then delegates to the right operation. It also owns the security boundary: drafts you paste are untrusted data, never instructions, and the skill will not follow commands embedded in them.
  • sepia-write — write from scratch in a human register, optionally locked to a persona profile.
  • sepia-review — diagnosis only. It produces a SEPIA DIAGNOSIS report and changes nothing — the operation you'll reach for first.
  • sepia-refactor — minimal intervention: it must run a diagnosis first and fix the deepest structural layer before touching the surface.
  • sepia-recreate — full rewrite preserving every fact, for drafts where the structure itself is the problem.
  • sepia-hemingway — write or rewrite in a Hemingway register, calibrated against a statistical fingerprint of his actual prose (sentence-length distributions, paratactic ratios, adjective density) rather than vibes.

Each operation also ships as a slash command (/sepia-review, /sepia-refactor, and so on) on the platforms that support them. The routing logic matters more than it looks: review versus refactor versus recreate is a real decision about how broken a draft is, and the skill forces that triage up front instead of defaulting to a rewrite.

6. Step 4 — Hands-on: validate a persona profile#

Before touching any prose, try the one part of Sepia that runs entirely locally with zero model involved: the persona validator. Personas are markdown profiles — a voice fingerprint with frontmatter (name, register, era, stance) and body sections (diction, syntax, rhythm, signature devices, failure modes) — that pin sepia-write to a consistent human voice. The repo ships a built-in example, and the validator checks any profile against the schema:

python3 scripts/check_persona.py skills/sepia/references/voices/personas/nyaneko.md
persona check: OK, 1 file(s), 0 error(s).

Clean pass on the bundled Nyaneko persona. Now break one on purpose — strip the required frontmatter from a copy — and the validator fails loudly instead of silently accepting a malformed profile. That fail-loud behavior is covered by the repo's test suite, which we ran in full:

python3 tests/test_check_persona.py   # 52 tests passed
python3 tests/test_check_versions.py  # 42 tests passed

94 tests, all green, using only the standard library — the project documents unittest rather than pytest, and both files run directly. There is also a version checker (scripts/check_versions.py) that keeps the skill metadata, the plugin manifests, and the git tags in agreement; it caught nothing because v0.12.2 is consistent everywhere. If you write a persona for your own voice — and you should, since an uncalibrated write operation drifts — run it through this validator before trusting it. It takes under a second.

7. Step 5 — A real review, end to end#

Now the core operation. Sepia's four prose operations execute inside your LLM agent — this sandbox has no model credentials, so for this step I applied the skill's documented review protocol by hand to the project's own test specimen: the slop-saturated release note from its behavioral eval (evals/deaify-release-note/prompt.md). Everything below follows the repo's professional-pass checklist and its release-notes domain rules; a real /sepia-review run produces exactly this kind of report and changes nothing.

The specimen:

We're thrilled to announce Fathom v2.4 — and this isn't just an update, it's a
fundamental reimagining of how you work with your data. We've delved deep into
your feedback to deliver an experience that's faster, smarter, and more intuitive.
Dark mode is finally here, bringing a seamless, eye-friendly aesthetic to every
corner of the app. Exports are now a blazing 40% faster in our benchmarks,
empowering you to move at the speed of thought. For teams, we've introduced robust
SSO support, streamlining onboarding like never before. We've also resolved an issue
where CSV imports could silently drop rows containing quoted commas — your data
integrity is our north star. This release is a testament to our unwavering
commitment to excellence, and we can't wait to see what you build with it!

The diagnosis, in Sepia's report shape:

SEPIA DIAGNOSIS
Verdict: structural — marketing inflation at every layer, facts recoverable
Calibration: 4–5 moves, then stop. Keep the v2.4 framing and the CSV fix verbatim.

Evidence:
- Marketing inflation (release-notes rule: no marketing inflation, one fact per claim):
  "fundamental reimagining", "blazing 40% faster", "at the speed of thought",
  "like never before", "unwavering commitment to excellence",
  "your data integrity is our north star"
- Chatbot leftovers (professional-pass checklist): "delved deep" — the canonical
  tell — plus "We're thrilled to announce" and "empowering you"
- User impact not first (release-notes rule): opens with vendor excitement instead
  of what changes for the reader
- Stamped rhythm (professional-pass checklist): "faster, smarter, and more
  intuitive" — the filler triplet
- The buried human sentence: the CSV-import fix is the only line with a concrete
  artifact and a real cost ("silently drop rows containing quoted commas").
  Sepia's protocol preserves it nearly verbatim and cuts around it.

Fix direction:
- Refactor, not recreate: the facts are all present and ordered sanely.
- Lead with user impact; one fact per line; delete every inflation phrase;
  keep the CSV sentence as the anchor.

Notice what the protocol did not do: it didn't reach for a thesaurus, it didn't sprinkle contractions, and it didn't touch the one sentence that already sounded human. The deepest layer — the note's stance toward its reader, vendor-boasting instead of user-serving — got fixed first, exactly as the three-pass protocol demands. That discipline, applied mechanically, is the whole product.

Four paths diverging from a document: building up, magnifying, mending with stitches, and phoenix-like rebirth
Sepia's four operations: write, review, refactor, and recreate — triaged by how broken the draft is. Illustration: AI Frontier Post.

8. How the three-pass protocol works#

Under the hood, every operation runs the same three passes in the same order, and the order is the insight:

Pass 1 — narrative architecture. For fiction, the skill scores the draft against a 30-feature rubric in five groups (narrative entropy and predictability, plot dynamics, emotional and thematic palette, discourse-level style, surface statistics) — the operationalization of the StoryScope research. For professional prose, it runs a nonfiction checklist (filler, hedging, chatbot leftovers, register, stamped formatting) plus domain rules for six document types: technical articles, release notes, PR replies, tickets, postmortems, and journalism. The rubric is explicit that it is heuristic triage, not an authorship detector — it finds where the draft is weakest so the fix lands at the right depth.

Pass 2 — discourse flow. Paragraph order, transitions, information pacing. Pass 3 — surface style. Diction, rhythm, sentence shape. Refactor is forbidden from touching Pass 3 before Pass 1 is resolved — the single most important rule in the system, and the one generic rewriters violate every time.

Two more mechanisms keep it honest. The calibration rule caps every intervention at three to five moves and requires the skill to leave slack — deliberately under-editing so the result keeps the author's fingerprints. And model fingerprints document the failure signatures of specific model families (the em-dash epidemic, the "it's not X — it's Y" reversal, the rule of three) so the skill can recognize whose slop it's looking at. Refreshingly, the skill makes no detector-evasion claims: the docs describe the output as "tuned to pass no automated AI-text detector," meaning it doesn't promise to beat one. The goal is prose a human would actually write, not a score on a meter.

9. Sepia vs the alternatives#

Sepia isn't the only skill in this lane. avoid-ai-writing (~4.7K stars) audits and rewrites content to remove AI writing patterns — a solid choice if you want a simpler audit-and-fix loop. shuorenhua (~1.9K stars) is a Chinese-first rewrite skill, the pick for Chinese-language prose. Both are listed alongside Sepia in the agent-skill directories, and both are worth a look.

Sepia's differentiators are structural, fittingly. First, the depth of the protocol: a 30-feature diagnostic rubric and domain-specific rules beat a generic "make it sound human" prompt. Second, the research grounding: the StoryScope and SLOPSHAPE papers are in the repo, so the method is inspectable rather than vibes-based. Third, engineering hygiene: 94 passing tests, a version-consistency checker, and a behavioral eval (strip the AI flavor from a release note while keeping every fact, graded by three judges) wired into CI — so regressions in taste get caught like regressions in code. No black-box humanizer web app offers any of that, and most of them charge a subscription for the privilege.

10. Honest boundaries#

Here's exactly what was verified in this tutorial and what wasn't. Verified: the repository is real and active (MIT license, ~2,900 stars, v0.12.2, commits through September 24, 2026); the Skills CLI install path works and lands all six skills; the Codex native install works and reports the correct version; the persona validator passes a good profile and the suite's 94 tests are green; the research papers, rubric, eval harness, and protocol documents all exist as described. Not run here: the four prose operations themselves, which need an LLM agent host — this sandbox has no model credentials, so Step 5 applied the documented protocol by hand and says so. The Claude Code, Grok, Antigravity, and QwenPaw install paths are documented from the README, not exercised.

Two caveats to carry with you. Sepia's fiction rubric is heuristic triage, not authorship detection — don't point it at a colleague's draft as a plagiarism machine. And the skill makes no promise about automated AI-text detectors; if your goal is evading one, this is the wrong tool and the wrong goal.

11. The takeaway#

The reason Sepia is climbing past 2,900 stars in its first month is that it identified the correct layer of the problem. AI writing doesn't sound robotic because of em-dashes or the word "delve" — it sounds robotic because the narrative machinery underneath is too regular, too balanced, too eager to resolve. Fixing that takes diagnosis before surgery, structure before style, and the restraint to make four moves and stop. Sepia packages that discipline into a skill your agent can run on every draft, with the tests and evals to prove it keeps working. Install it with one command, validate a persona for your voice, and run /sepia-review on the next thing you were about to publish. You might be surprised which layer the diagnosis points at.