Category · 32 repos
Code Review & Static Analysis
Linters, formatters, type checkers, code review and analysis tools. Ranked by star velocity over the last 24 hours.
A modular, stack-agnostic toolkit for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
Secure, fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Advanced anti-reverse-engineering library made in C++26
Semantic code linting with Decision Models
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to
JavaScript Style Guide
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Cognitive scaffolding for coding agents
Evidence-grounded repository audit CLI - deterministic scanner, MCP server, live dashboard, and a GitHub Action that posts PR diffs.
The Roslyn .NET compiler provides C# and Visual Basic languages with rich code analysis APIs.
Universal file structure and project architecture linter
Review code changes by what they do, not line by line.
Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)
Opinionated Oxlint rules for rejecting low-evidence TypeScript and JavaScript patterns
Self-hosted runtime for programmable PR review agents with local models, sandboxed tools, and pluggable workflows.
Official CalcKernel language support for Visual Studio Code
Defund the Police.
Official-grade GitHub CI for DeepSeek Harness: composite action.yml, PR review bot with idempotent inline comments and a status-check gate, plus PR/issues tools with every write gated by human approval (Apache-2.0, dsh-plugin).
Java code-formatter for https://github.com/square/javapoet
It's not just a linter that annoys you!
Continuous Inspection
Guard skills for coding agents, quality gates that catch AI-generated failure modes in code, tests, and docs
Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.
Personal software factory built on OpenHands: agents implement, test, review, and publish draft pull requests.
Grok Bot 0.18.0 runtime code archive — unminified bundles, mechanical per-module split, byte-for-byte reproducible
WeChat Mini Program reverse-engineering MCP — online real-time unpacking + AI static analysis to reconstruct API signatures/encryption, producing scripts that run directly in local Node.js (zero intrusion, does not touch the WeChat process).
Codebase intelligence for TypeScript and JavaScript. Health, complexity hotspots, duplication, architecture boundaries, circular dependencies, design-system drift, and unused code, from one graph. CLI, GitHub Action, LSP, MCP, and VS Code. Rust, MIT licensed.
🐚 Map a web app's JavaScript to its API — endpoints, GraphQL, routes and leaked keys from bundles and source maps, plus an OpenAPI skeleton. tree-sitter, not regex.
MCP server providing semantic Java code analysis for AI agents. Built on Eclipse JDT with tools for navigation, refactoring, search, and metrics.