AI-Powered Repository Analysis & Security Scanner
RepoPilot is a comprehensive web application that analyzes GitHub repositories or uploaded ZIP files to provide:
- π Auto-generated README documentation
- π Vulnerability scanning (npm audit, semgrep, gitleaks)
- π Bug and code quality analysis (eslint, ruff, pattern scanning)
- π‘ Suggested fixes and recommendations
- π Downloadable Markdown reports
- Multi-Language Support: Analyzes Node.js, Python, and mixed-language repositories
- Comprehensive Security Scanning: Detects vulnerabilities, secrets, and security issues
- Code Quality Analysis: Identifies bugs, code smells, and complexity issues
- Dependency Inventory: Lists all dependencies with version information
- License Compliance: Scans and flags problematic licenses
- Test Coverage Analysis: Evaluates test infrastructure
- Public Access: Exposed via Tailscale Funnel for hackathon demos
- React 18 with TypeScript
- Vite for fast builds
- React Router for navigation
- Tailwind CSS for styling
- Axios for API calls
- Node.js with Express and TypeScript
- Multer for file uploads
- Simple-git for repository cloning
- Rate limiting and security middleware
- JavaScript-based orchestration layer
- Modular agent architecture
- Timeout management and retry logic
- Comprehensive error handling
- Node.js 18+
- Docker & Docker Compose
- Git
- Security tools: semgrep, gitleaks, bandit (optional, will fallback)
- Clone and Install
git clone <your-repo-url>
cd repopilot- Setup Backend
cd backend
npm install
cp .env.example .env
npm run dev- Setup Frontend (in new terminal)
cd frontend
npm install
cp .env.example .env
npm run dev- Access the app
- Frontend: http://localhost:3000/repopilot
- Backend: http://localhost:5000
- Configure Environment
cp .env.example .env
# Edit .env with your settings- Start Services
docker compose up -d- Check Status
docker compose ps
docker compose logs -f- Access the app
- Frontend: http://localhost:3000/repopilot
- Backend API: http://localhost:5000/api/health
See tailscale-setup.md for detailed instructions on exposing RepoPilot publicly for hackathon demos.
repopilot/
βββ frontend/ # React + TypeScript UI
βββ backend/ # Express + TypeScript API
βββ middleware/ # JavaScript orchestration layer
βββ agents/ # JavaScript analysis agents
βββ docker-compose.yml # Container orchestration
βββ tailscale-setup.md # Public access guide
GET /api/health
POST /api/scan
Body: { type: "github", repoUrl: "..." } or { type: "zip", file: <binary> }
GET /api/scan/:scanId
GET /api/scan/:scanId/report
GET /api/scans
- npm audit: Node.js dependency vulnerabilities
- pip-audit: Python dependency vulnerabilities
- semgrep: Static analysis for multiple languages
- gitleaks: Secret detection
- bandit: Python security linting
- eslint: JavaScript/TypeScript linting
- ruff: Python linting
RepoPilot uses a modular agent-based architecture:
- Scan Orchestrator: Coordinates all analysis agents
- Repo Analyzer: Detects languages and frameworks
- README Generator: Creates comprehensive documentation
- Vulnerability Scanner: Runs security tools
- Bug Scanner: Detects code quality issues
- Report Generator: Formats final Markdown report
- Additional Agents: Dependencies, secrets, licenses, complexity, test coverage
- No database required
- Results stored in
/tmp/repopilot/as JSON and Markdown - Automatic cleanup of old scans
- Scan results persist for the session
All configuration via environment variables. See .env.example for available options.
Key settings:
MAX_ZIP_SIZE_MB: Maximum upload size (default: 25MB)SCAN_TIMEOUT_MS: Overall scan timeout (default: 90s)AGENT_TIMEOUT_MS: Per-agent timeout (default: 30s)ALLOWED_ORIGIN: CORS origin (set to Tailscale URL in production)
# Frontend tests
cd frontend
npm test
# Backend tests
cd backend
npm test# Frontend
cd frontend
npm run build
# Backend
cd backend
npm run build# Kill process on port 3000 or 5000
lsof -ti:3000 | xargs kill -9
lsof -ti:5000 | xargs kill -9# Clean restart
docker compose down -v
docker compose up -d --buildRepoPilot will fallback to pattern-based scanning if tools are unavailable. Install tools for best results:
# Semgrep
pip install semgrep
# Gitleaks
brew install gitleaks # macOS
# or download from https://github.com/gitleaks/gitleaks/releases
# Bandit
pip install banditThis is a hackathon project. Contributions welcome!
MIT License - see LICENSE file for details
For judges and evaluators:
- Access the public URL provided (via Tailscale Funnel)
- Paste a GitHub repository URL or upload a ZIP file
- Click "Scan Repository"
- View comprehensive analysis results
- Download the full Markdown report
For issues or questions during the hackathon, contact the team.
Built with β€οΈ for IBM Bob Hackathon