A 0 to 100 score is only a review order
The graph looks definitive because every candidate receives a position, line, color, and confidence tier. The underlying number is a repeated-appearance estimate. For one phase, the model compares binomial likelihoods using hand-set assumptions of 0.70 and 0.16. The README says those constants did not come from a published benchmark. A line therefore means the tool ranked an association for display, not that Instagram confirmed a follow or relationship.
Even the top tier needs that caveat. Raw scores from 99 to 100 display as very high model confidence, yet a 99 is not a measured 99 percent probability. Viewer account, session, selected phases, depth, and date all change what Instagram returns. Scores from different runs are not directly comparable. The application is honest about this, which makes it useful for triage and unsuitable as standalone evidence.
What happened when we ran it
Our sandbox installed commit 6b738ff in 18 seconds. The unprivileged Debian container had 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. Installation succeeded with 46 packages and occupied 243 MB. The build completed in 4 seconds. Pip-audit reported 0 known vulnerabilities in the environment we installed.
There was no test script or target, so the lab skipped tests. The checkout contained 48 files, about 27,134 lines of source, and 2.2 MB before dependencies. It had no CI workflow, Dockerfile, or tests directory. Install and build results say the package environment can be assembled. They say nothing about collection accuracy, endpoint compatibility, graph calibration, or whether an authenticated Instagram run completes.
Private targets require two live cookie values
IG_SESSIONID and IG_DS_USER_ID are the 2 required credentials. Four supplementary cookie values may be supplied or discovered during warmup. A session ID is equivalent to authenticated account access, so the README tells users to keep it out of screenshots, chat, logs, browser cookie extensions, archives, and cloud shares. If it leaks, log out every Instagram session, rotate the test-account password, and collect fresh cookies.
A private target adds a firm access condition: the test account must already be a genuine accepted follower with lawful visibility. The tool does not bypass Instagram privacy controls, and its documentation rejects deceptive follow requests. A new or inactive viewing account also has weak ranking history, so its suggestions may reflect generic onboarding rather than anything about the target.
Depth 5 is the lowest documented request setting
Fast mode with network depth 5 is the recommended starting point. Values from 6 through 15 make more requests and raise runtime plus account-restriction risk. That depth controls repeated discovery calls, not graph hops. The local server rejects overlapping analysis jobs, but a second application instance can still create parallel traffic, so one-target-at-a-time discipline remains an operator responsibility.
Instagram supplies no ban-proof request rate or guaranteed cooldown. HTTP 429, changed 401 or 403 responses, checkpoints, forced logins, and unusual notifications are stop signals. Empty, 400, or 404 responses do not prove that an account or relationship is absent. Undocumented endpoints can change without notice, making a previously successful workflow incomplete the next day.
Port 8000 must stay on loopback
The launcher defaults to 127.0.0.1:8000 and refuses non-loopback hosts. That restriction is essential because the app has no remote-user authentication or TLS. Do not publish it through a tunnel, router, reverse proxy, LAN address, or public VM. Browser automation and cookies run on the same machine as case evidence, so a casual remote exposure could compromise both the viewing account and collected data.
Outputs include ranked JSON and CSV, separate node and edge CSV files, GEXF, and a text report. Raw phase data and cached avatars can remain beside them. A partial refresh updates only selected phases and can be recomputed alongside older files, so time-sensitive work should use a new artifact directory for each event and record the viewer, target numeric ID, phases, and timestamp.
Four same-day commits are the whole visible history
GitHub showed 414 stars, 0 combined open issues and pull requests, and a September 3, 2026 last push when checked on September 29. The visible history contained 4 commits, all dated September 3, including the initial release and README updates. There was no GitHub release, no CI workflow, and no test target. Zero open issues here signals an empty tracker, not proof of defect-free operation.
GitHub also detected no license, and the 8-item root listing contained no license file. That leaves no standard permission grant for reuse or redistribution. The README says academic and technical details will be presented later, but it does not claim that validation already exists. A promised paper cannot substitute for measured precision, recall, false-positive rates, or calibration.
Use the ranking to choose what a human checks next
The model's own validation section asks for precision, recall, false-positive rates, Brier scores, and calibration curves before anyone interprets its output as probability. None is supplied. Until that work exists, the defensible use is narrow: generate candidates, preserve provenance, and confirm every important statement through independent lawful sources. Do not convert a close node on the radial graph into a sentence about friendship, location, or identity.
Our 18-second install and 4-second build make the software easy to inspect. The hard part is protecting the account, securing artifacts, respecting access, and refusing to overread the score. Investigators who already practice those controls may get a useful review queue. Everyone else should choose a simpler collection tool and avoid turning undocumented platform suggestions into claims about real people.
