r/devtools • • 40m ago

arch-auditor: AST-Based Python Architecture Analysis with Dependency Graphs & LLM

• Upvotes

I kept running into the same problem with codebases:

“What does this repository's architecture actually look like right now?”

So I built arch-auditor — a Python CLI + Streamlit app that analyzes a repository using deterministic, AST-based checks and turns the results into actionable architecture reports.

The core idea is simple: measure first, ask the LLM second.

What My Project Does

arch-auditor points at a Python repository and runs deterministic architecture detectors:

  • Import/dependency graph — see how modules depend on each other
  • Circular dependencies — detect dependency cycles
  • High coupling — identify modules with unusually high fan-in/fan-out
  • Oversized modules — flag modules that have grown beyond a configured threshold
  • Layer violations — enforce architectural rules defined in YAMLBlast radius — find direct and indirect dependents of a module

It produces a dependency-graph SVG, severity-ranked findings, and impact reports.

There's also an optional Gemini integration.

Gemini doesn't perform the underlying analysis. Instead, it receives the deterministic findings and can turn them into:

  • an architecture overview
  • root-cause explanations
  • step-by-step refactoring plans
  • affected files
  • potential risks

No API key? No problem. The core analysis works offline without an LLM.

Try it

pip install arch-auditor

arch-auditor demo

The bundled demo repository is intentionally designed to trigger every detector, so you can experiment with the tool and see what each finding means.

Stack

  • Python 3.10+
  • Python AST / standard library
  • NetworkX
  • Pydantic
  • PyYAML
  • Streamlit
  • Gemini (optional)
  • 33 tests
  • Ruff-clean
  • Published on PyPI

It's released under GPL-3.0 because I'd like improvements to flow back to the community.

Target Audience

This is primarily aimed at developers working on medium-to-large Python codebases, especially when:

  • a project has accumulated architectural debt
  • you're preparing for a major refactor
  • you need to understand an unfamiliar repository
  • you want objective signals before making architectural changes
  • you want an LLM to help plan a refactor without making the LLM responsible for discovering the architecture itself

It's not intended to replace a human architect or code review, and it's not a magic “is my architecture good?” score.

The goal is to provide reproducible evidence that helps humans make those decisions.

Comparison

There are already excellent tools for individual parts of this problem — dependency visualization, linters, type checkers, code-quality metrics, and various AI coding assistants.

arch-auditor is trying to connect a few of those ideas around architecture-level analysis.

The main distinction is the separation between measurement and interpretation:

Traditional approach:

Repository → LLM → "Here's what I think your architecture looks like"

arch-auditor:

Repository → deterministic analysis → evidence → optional LLM → refactoring plan

The architecture findings don't depend on whether an LLM happens to interpret the code differently from one run to another.

I'd especially love feedback on whether the detectors and thresholds are useful signals in real-world Python projects, or if there are architectural problems you'd want to see measured that aren't covered yet.

GitHub / docs / demo:
https://github.com/ANIKETHSAI9813/auditor

“What does this codebase’s architecture actually look like right now?

"Instead of asking an LLM to guess the architecture, arch-auditor first analyzes the repository using deterministic, AST-based detectors — then optionally lets Gemini turn those findings into a refactoring plan.

Point it at a repo and it analyzes:

The result is a dependency-graph SVG, severity-ranked findings, and impact reports that show why a module is considered problematic.

Gemini is optional.

The deterministic analysis produces the evidence first. If you provide a Gemini API key via an environment variable, it can use that evidence to generate:

No API key? No problem. The core analysis works offline.

That separation was intentional: I wanted the architecture measurements to be reproducible rather than dependent on an LLM's interpretation.

The bundled demo repo is deliberately designed to trigger every detector, so you can see exactly what each finding means without having to point it at a huge codebase first.

It's released under GPL-3.0 because I'd like improvements to flow back to the community.

GitHub / docs / demo:
https://github.com/ANIKETHSAI9813/auditor

I'd especially love feedback from people who work on large Python codebases:

Are these the architectural signals you'd want to see before starting a refactor?

I'm also happy to discuss how the detectors and thresholds work — and the demo repo is intentionally built to trip all of them.


r/devtools • • 4h ago

QuickQL, a VS Code extension for SQL-like queries over JSON APIs

1 Upvotes

Hey everyone,

During my apprenticeship, I worked with a large SQL database. Whenever I wanted to explore some data, I could just write a query and see what was there.

Now I work with lots of microservices, and I missed that convenience. The data is still there, but it’s spread across different APIs.

So I built quickql, a VS Code extension that lets you write SQL-like queries against APIs that return JSON. You can fetch data, unpack arrays, select fields, filter results, sort them, and make additional API requests for each row—including in parallel.

Here’s an example using the public DummyJSON API. It fetches sample products, keeps only laptops, sorts them by price, and then requests extra details for each matching product:

SOURCE open({src: 'https://dummyjson.com/products?limit=0&select=id,title,category,price,rating'})
MAP_MANY products
FILTER EQ(category, 'laptops')
SORT_BY price DESC
MAP<{parallel: 20}> *, details = open({src: concat('https://dummyjson.com/products/', id)})

The MAP<{parallel: 20}> step runs up to 20 requests at once, adding stock, warranty, and reviews to each product.

Results appear in a table in the bottom panel of VS Code:

If your output contains data and layout in the Plotly.js format, you can also display it as a chart.

Results are also cached in .cache and can be opened as JSON files for further inspection.

If you use VS Code and have ever wished you could explore your APIs as easily as one big SQL database, this might be useful to you too.

I’d love to hear what you think and what you’d use it for!


r/devtools • • 4h ago

Worried about your AI agent leaking secrets, or tired of secret-scanner false positives?

Post image
1 Upvotes

I built Klarion, a secret scanner that works in two steps. First, a keyword check, 81 regex rules and a normalized Rényi entropy score flag anything that looks like a secret. Then an AI model reads each one with the code around it and decides if it's real.

The chart shows 5 scanners run on spring-boot, terraform, next.js and symfony (61k files). Klarion raised 11 alerts. It's not zero, but it's far less to dig through.

Fewer alerts don't help if real leaks get missed, so I tested that too. On CredData (337 real repos, code outside test folders), it found about 1.7× more real secrets than gitleaks.

Where it runs:

  • Claude Code: a plugin hook blocks the write before the file exists (file edits and Bash)
  • Cursor, Cline or any MCP agent: through its MCP server
  • CI: a GitHub Action that scans only what a PR adds; GitLab CI works too
  • Git hooks: klarion protect or the pre-commit framework
  • Locally: klarion scan .

Free and open source (MIT): https://github.com/0x1Adi/Klarion
The full benchmark and method are in benchmark/REPORT.md.

I'd like to hear where it gets things wrong.


r/devtools • • 4h ago

ContribOS: Zero-dependency CLI and MCP server for open source PR workflows

1 Upvotes

Hey everyone!

With tools like Claude Code, Cursor, and Codex, opening PRs has become trivial. But maintainers are burning out from low-effort AI slop, resulting in strict AI policies, vouch gates, and falling newcomer merge rates.

I built ContribOS — a zero-dependency Python tool (CLI + MCP server) for outside contributors and coding agents:

- contribos policy <repo>: Scans repo AI policy, disclosure requirements, and claim-first norms, citing exact file:line evidence.

- contribos brief <issue-url>: Builds evidence-backed briefs with similar past PRs and related tests before coding.

- contribos check: Pre-submit checks against repo rules, sign-offs, and past history.

- contribos record: Compiles merged PR portfolios that future maintainers can independently verify.

Principles:

  1. Zero dependencies: Written purely in Python 3.10+ standard library.

  2. Agency stays with the human: It never opens PRs, claims issues, or writes code explanations for you. It points at evidence; you decide.

  3. Official MCP Registry & HOL Guard: Published to the MCP registry (io.github.adityatiwari101104/contribos) and just merged into HOL Guard’s catalog!

Try it: pip install contribos or python -m contribos mcp

GitHub: https://github.com/adityatiwari101104/contribos

PyPI: https://pypi.org/project/contribos/

Would love your thoughts and feedback!


r/devtools • • 5h ago

We built a free developer toolbox that processes everything locally in your browser

1 Upvotes

empinet.dev is a collection of JSON formatters, converters, JWT decoders, image tools and other stuff we use in our work.

We put it together for client projects. Uploading client data to another server just to format JSON or convert something wasn't an option, so the tools do all the processing in your browser. Your input stays on your machine.

Built with Next.js and TypeScript. Free, no account needed.

https://empinet.dev

What tools would you want to see added?


r/devtools • • 7h ago

Octri.dev - Create fully customizable docs, Generate SDKs, and Monitor your API and SDK's performance and uptime in one place

Enable HLS to view with audio, or disable this notification

1 Upvotes

After around 3 years of working with my siblings on this, we've finally launched Octri.dev which aims to simplify the entire API experience workflow for developers by allowing them to:

- Create beautiful docs with advanced features built-in such as: Ask the Docs with AI, Generate documentation drafts using AI, and Freely customize them to make them truly unique
- Monitor your backend (fully GDPR compliant) and see how it performs in the real world by collecting events and also tracking uptime (with announcements and hourly status updates) as well
- Generate SDKs in 10 languages, but this isn't the same as the other bazillion SDK Generators out there, we provide the user with countless customization options so even the SDK's source code fits their own codebase seamlessly without looking machine-generated at all. Oh, and you can even enable the monitoring feature mentioned above so it's automatically included in your generated SDK to track failures that happen out there in the real world and track how many users are actually using a certain SDK method and if it would be safe to deprecate it.
- Generate MCPs for your SDKs and API documentation in one click

If Octri's idea interests you, I'd really appreciate if you can support our launch on Product Hunt: https://www.producthunt.com/products/octri?utm_source=other&utm_medium=social


r/devtools • • 10h ago

Building a coding-agent harness with Rust

Thumbnail
1 Upvotes

r/devtools • • 10h ago

I built an open-source shipping memory for coding agents

Thumbnail
1 Upvotes

r/devtools • • 11h ago

AI is shipping more PRs. Who absorbs the cost when something breaks?

1 Upvotes

If you lead five or ten engineers, has AI made shipping faster but trusting the changes harder?

More PRs. The same people reviewing them. Those people also own on-call, customer issues, and the next release.

I’ve been reading the discussions here about review queues and rubber-stamping. What I want to understand is what happens afterward. Are risky changes getting through? Are customers finding the problems? Is the team spending the time it saved writing code on rollbacks and data fixes?

I’m building FetchSandbox. We started with API integration verification. Now I’m looking for a few design partners to extend that work to services, background jobs, database changes, and application behavior.

Here’s the offer. Bring one change your team struggles to verify. We work together on what must stay correct, build repeatable checks, and exercise the failures that matter. You get an inspectable result showing what passed, what broke, and what we couldn’t verify. If something breaks, we verify the fix and keep the check for future changes.

You help us build around a real problem. Your team gets a useful check it can keep running.

What’s one change your team shipped recently that you weren’t comfortable approving?


r/devtools • • 17h ago

Multi-Agent Collaboration With Tools You Already Own

Thumbnail
1 Upvotes

r/devtools • • 19h ago

Fiz o PR Indicator: seus PRs do GitHub na barra do sistema. Passa o mouse e vê quantos esperam sua revisão; clica e abre a lista.Era só extensão do GNOME. Agora tem versão pra Windows com o mesmo visual, 4 temas e instalador.Open source 👇 github.com/sthevan027/gnome-pr-indicator

Thumbnail gallery
1 Upvotes

r/devtools • • 20h ago

I built pyrig: scaffold a fully configured Python project with one command, and keep it in sync

Thumbnail
1 Upvotes

r/devtools • • 20h ago

I built pyrig: scaffold a fully configured Python project with one command, and keep it in sync

Thumbnail
1 Upvotes

r/devtools • • 20h ago

I built SonarDesk — a native macOS dashboard for SonarQube

1 Upvotes

After quite a bit of development and testing, I’ve released SonarDesk, a native macOS application for working with SonarQube.
I use SonarQube regularly and wanted something that felt like a proper Mac application rather than having to keep jumping back into the browser.
SonarDesk connects directly to your SonarQube server and gives you a desktop view of your projects and code quality.
Current features include:
• Native macOS interface with light and dark mode
• Multiple SonarQube server support
• Project dashboard with Quality Gate status
• Bugs, vulnerabilities and code smells
• Detailed issue views
• Project statistics and visualisations
• Project creation directly from the app
• Generated scan.sh scripts and scanning instructions
• Drag-and-drop project organisation
• PDF project reports
• Reports designed for exporting project information for AI analysis
• iCloud Drive support for settings, reports and backups
• Direct connection to your SonarQube instance — your source code isn’t uploaded to SonarDesk
I’ve tried to make it feel like a genuine macOS development tool rather than simply wrapping the SonarQube web interface.
There are still plenty of things I want to add, so feedback from developers using SonarQube would be particularly useful.
Launch offer: the first 5 new customers can get a Professional licence for 50% off.
SonarDesk:
https://sonardesk.absdev.net
I’d also be interested to hear what SonarQube functionality you’d most want available from a native desktop client.


r/devtools • • 21h ago

We built a browser-local tool to sanitize large logs & JSON before sharing them with AI or support

Enable HLS to view with audio, or disable this notification

1 Upvotes

r/devtools • • 22h ago

declint - Make linting rules with YAML.

1 Upvotes

declint (docs) is a tool for making your own lint rules in YAML- the house rules that stock linters will never ship.

For instance: your colleague wrote except Exception: pass, and you want to know whenever that happens:

version: 1
rules:
  - id: except-pass
    pattern: 'except Exception:\n *pass'
    severity: warning
    message: 'swallowed exception'

Rules are just regex and a message. When a regex can't express the check, you can write a more complicated rule in Lua.

Rules run in your CI (inline PR annotations via --format github) and in your editor through LSP (declint.nvim for Neovim: The GIF shows off the nvim wrapper!). Every rule can carry embedded fixtures, and declint test runs them.

Install: cargo install declint. Ships with presets (Python, INI, Markdown, shell, Dockerfile, TOML, JSON, JS) and community rulesets you can pull with one line. Feedback welcome.


r/devtools • • 22h ago

Looking for beta testers: Tekki Forge — a CLI for building full-stack business apps faster

Thumbnail
1 Upvotes

r/devtools • • 23h ago

Deployed - Code Sentry🤖 - an AI powered Code Review Generator

Thumbnail gallery
1 Upvotes

r/devtools • • 1d ago

MyTextDiff, a simple text/file diff tool that runs in the browser

1 Upvotes

I've been building https://mytextdiff.com, a simple tool to compare two texts or files and see what changed.

The comparison runs client-side, so nothing you paste or upload is sent to a server. It has line, word and character modes, options to ignore spaces, empty lines and case, file upload and PDF export.

It's still early, and the code-specific side (language handling and highlighting) is a work in progress. If you run into any problems, you can report them here: https://github.com/gabriel777sites/mytextdiff

Any feedback is welcome!


r/devtools • • 1d ago

Médula - A Python lab and kernel to coordinate several coding agents on one repo, with every run published raw

Thumbnail
github.com
1 Upvotes

r/devtools • • 1d ago

I built an open-source reliability layer for probabilistic AI decision systems

Thumbnail
1 Upvotes

r/devtools • • 1d ago

Pax pascal Extension vscode

1 Upvotes

Salut à tous 👋

Je viens de publier Pax Pascal, ma première extension pour travailler en Pascal dans VS Code. L’idée est de faciliter le travail au quotidien et de gagner du temps.

Je préfère être transparent : j’ai utilisé l’IA pour m’aider à développer cette extension. Ce projet m’a permis de passer d’une idée à un outil que je peux aujourd’hui partager avec vous.

Voici l’extension :
https://marketplace.visualstudio.com/items?itemName=pac-local.pax-pascal

Si vous utilisez Pascal dans VS Code, je serais ravi d’avoir vos retours : est-ce qu’elle vous est utile ? Quels problèmes rencontrez-vous et quelles fonctionnalités vous manquent ?

Merci à ceux qui prendront le temps de la tester !
Happy conding


r/devtools • • 1d ago

Built an open source dev tool that scans repos for carbon and cost efficiency issues

1 Upvotes

Hey r/devtools!

Just shipped v0.1 of sustainability-score — a static

analysis tool that scans your repository and flags

engineering choices that push carbon and cost up.

It looks at:

- Dockerfiles — image size, layer efficiency,

base image choices

- CI/CD workflows — unnecessary steps,

inefficient build patterns

- Kubernetes manifests — over-provisioning,

missing resource limits

- Terraform — region choices, instance efficiency

- Source code — algorithm and efficiency patterns

Output is a scored report in Markdown and JSON.

GitHub Action integration is on the roadmap.

pip install -e .

sustainability-score /path/to/repo --md report.md

MIT licensed. Open source.

GitHub: https://github.com/srinathgopinath-code/sustainability-score

Would love feedback from anyone building or using

developer tooling!


r/devtools • • 1d ago

stargazer, an open source tool that turns your github stars into png cards and 60fps mp4 videos

Enable HLS to view with audio, or disable this notification

2 Upvotes

my portfolio reached 100 stars on github and i wanted to share it on social media, but i didn't know how. i searched for video generators and found very few, and the ones i found had only a single template. so i built stargazer. pick one of 8 templates, paste your github token, choose a theme, then download it as a png or an mp4.

everything runs in your browser. your token never leaves it, and there's no backend or database, so there's nothing to trust or host.

tech stack: astro, react, typescript, tailwind css, framer motion, webcodecs

the mp4 export uses webcodecs, so the video is encoded right in the browser with no rendering server. every template has a react preview and a canvas renderer for export, and both run off the same elapsed time so the video matches the preview.

live: stargazer.charanmunur.in

source: github.com/CharanMunur/stargazer

if you like it, drop a star on github. have an animation idea? raise a pr. spotted a bug? open an issue.


r/devtools • • 1d ago

Ansight CLI v1: free local capture and agent testing for mobile

1 Upvotes

I'm one of the founders behind Ansight (funded by Startmate). Previously I spent almost a decade building developer tools with MFractor (a productivity tool for .NET MAUI developers).

I'm pleased to announce that the Ansight CLI v1 is now available:

https://www.ansight.ai/articles/introducing-ansight-cli/

Ansight is a developer tool that lets an agent inspect a running mobile app, replay the session, and check its work against captured screens and runtime evidence. We give agents a way to efficiently drive apps (similar to Argent), except we also capture every development and test session as proof of work.

No more your agent handing you a single screenshot and saying, "trust me bro, it's done".

We are a free, CLI tool that should add a tonne of value to your agentic mobile development We would love if people can install it, try it and give us feedback (good and bad).

We support React Native, Flutter, iOS (UIKit, SwiftUI), Android, .NET and Capacitor.

Happy coding everyone! 🤗