Simon Willison has released a new tool that checks any Bluesky profile for signs that it’s an automated reply bot. According to Willison, he didn’t write it by hand. He had Anthropic’s Opus 5.5 “vibe code” it, which means he described what he wanted in plain language and let the AI model write the code.
The tool is small, but it deals with a real problem. It also shows how quickly developers can now build their own fixes for annoyances on the platforms they use every day.
Why He Built It
Willison is blunt about why. “Automated reply bots on Twitter are a scourge,” he writes. Because he has a large following, anything he posts on X gets “dozens of mindless automated replies.” Now the same bots are starting to show up on Bluesky.
One difference between the two platforms made the project possible. Willison notes that Bluesky “still has a freely available and useful API.” X has mostly closed off that kind of access. He points out that a missing API doesn’t stop the bots at all. It only makes them harder to investigate.
What the Checker Looks For
You point the tool at a Bluesky profile and it looks for behavior that suggests automation. Willison lists these signals:
- Replies posted seconds apart. If an account posts replies within seconds of its other posts, that’s a strong sign of automation. People need time to read, think and type. Scripts don’t.
- No original content. The tool flags accounts that never post their own material. That includes no images and no links, just replies to other people.
- Always replying to bigger accounts. Bots tend to go after users with more followers than they have. It’s an easy way to get seen. When an account’s replies consistently land under higher-follower users, the checker notes it.
- Lots of question marks. This one is personal. Willison says he’s especially annoyed by bots that try to bait him into answering questions no real person ever asked. Asking a question is a cheap way to fake engagement, because it pulls the original poster into spending time on a reply.
What Stands Out Here
The way it was built is as interesting as the tool itself. Willison is one of the most closely watched voices on practical LLM use, and he’s been showing for a while how AI coding models turn “I wish this existed” into a working tool in one sitting. This checker is a good example: a narrow, useful utility that probably wouldn’t have been worth building by hand.
It also shows why open APIs matter. Bluesky runs on the AT Protocol and keeps its data easy to reach, so any developer can build moderation and analysis tools on top of it. Under the current setup at X, independent researchers and hobbyists mostly can’t. As bots spread across social platforms, this kind of openness decides whether the community can help fight spam or has to wait on the platform to do it.
Limitations Worth Noting
The signals are heuristics, meaning rules of thumb, and they’re not proof. Some things to keep in mind:
- False positives are possible. Some real people mostly reply and rarely post. A fast typist, a busy lurker or someone who asks a lot of questions could trip a few of the flags.
- Bots will adapt. Once patterns like fast reply timing become known, bot operators can add delays or mix in original posts to get past them.
- It shows evidence, not a verdict. Willison describes it as looking for “evidence of a likely reply bot,” which is different from a definitive label.
Willison’s post doesn’t mention pricing or signup, so it looks like a lightweight personal project he shared publicly rather than a commercial product.
What Comes Next
Reply bots are an arms race, and tools like this won’t end it. What they do is lower the cost of checking. Any Bluesky user can now look into a suspicious account in seconds instead of scrolling through its history by hand. And since it was vibe-coded, other developers could easily fork the idea, add new signals or connect it to blocklists.
You can find the full write-up and the tool itself on Simon Willison’s blog.