Skip to content

Repository files navigation

RepoScope

A lightweight GitHub repository inspection, code analysis, and security reporting tool for Windows, Linux, and macOS.

RepoScope helps developers, researchers, and security enthusiasts inspect and analyze public GitHub repositories by automatically cloning a repository and generating a structured analysis report containing source files, project structure, file information, binary hashes, and security-related indicators.

It can be used to extract repository files and source code for further analysis, including analysis with AI assistants and LLMs.

The goal is not to replace professional security tools, but to make GitHub repository inspection, source code analysis, and security investigation faster and easier.


Features

Repository inspection

  • Automatic GitHub repository cloning
  • No manual download required
  • Supports public GitHub repositories
  • Automatic project tree generation
  • File inventory generation
  • Repository structure inspection

Source code analysis

  • Source code extraction
  • Important configuration file collection
  • Binary SHA256 hash calculation
  • File information collection
  • Single TXT report generation
  • Repository contents prepared for further code or AI analysis

Security features

  • Suspicious API detection
  • Suspicious command detection
  • Malware-related keyword search
  • Network indicator detection
  • Persistence-related indicator detection
  • Security-focused investigation mode
  • Static inspection of suspicious code patterns

AI-assisted analysis

RepoScope can generate reports designed to be analyzed by AI assistants and LLMs.

This makes it useful for:

  • AI-assisted GitHub repository analysis
  • AI code review
  • Security analysis with an LLM
  • Reviewing large repositories before sending their contents to an AI
  • Extracting source code and repository information for further analysis

User experience

  • Simple .bat launcher
  • Shell launcher for Linux and macOS
  • Python-based transparent code
  • Progress indicators
  • No compiled executable
  • Easy to audit and modify
  • Local analysis

Requirements

Operating System

  • Windows
  • Linux
  • macOS

Required software

  • Python
  • Git

Installing Python

Download Python:

https://www.python.org/downloads/

After installation, verify:

py --version

Installing Git

Download Git:

https://git-scm.com/downloads

After installation, verify:

git --version

Installation

Clone this repository:

git clone https://github.com/Jovatis/RepoScope.git

or download the ZIP archive.

The project structure should look like:

RepoScope/
│
├── RepoScope.bat
├── RepoScope.py
├── README.md
└── LICENSE

or if you are on Linux/macOS:

RepoScope/
│
├── RepoScope.sh
├── RepoScope.py
├── README.md
└── LICENSE

Usage

Run:

RepoScope.bat

or on Linux/macOS:

RepoScope.sh

The tool will then ask you to select an analysis mode:

┌─ MODE ───────────────────────────────────────────────────────────────┐
║ ▶  1. Quick Scan                                                     ║
║     Fast repository inspection.                                      ║
║                                                                      ║
║ ○  2. Full Scan                                                      ║
║     Complete repository inspection.                                  ║
║                                                                      ║
║ ○  3. Security Inspection                                            ║
║     Collect security indicators for further analysis.                ║
║                                                                      ║
║ ○  Q. Quit                                                           ║
└──────────────────────────────────────────────────────────────────────┘

You can navigate using the arrow keys on your keyboard and press Enter to select an option.

Then enter a GitHub repository URL.

Example:

https://github.com/jagt/clumsy

RepoScope will then:

  1. Clone the repository
  2. Inspect the project structure
  3. Collect important files
  4. Generate file information
  5. Calculate hashes for binaries
  6. Create a security report

The generated report will be saved locally inside:

Reports/

Example:

Reports/
└── clumsy-analysis-2026-06-11.txt

Analysis Modes

RepoScope provides three analysis modes:

1. Quick Scan

Fast GitHub repository inspection.

Includes:

  • Project structure
  • Important source files
  • File inventory
  • Binary hashes

Large dependency folders are skipped:

  • node_modules
  • vendor
  • build
  • dist
  • target

Recommended for normal GitHub projects.


2. Full Scan

Complete repository inspection.

Includes:

  • All files
  • Dependencies
  • Generated files

This mode can create larger reports.


3. Security Inspection

Deep static inspection mode.

Includes everything from Full Scan plus:

  • Suspicious API detection
  • Command execution indicators
  • Network-related indicators
  • Persistence-related indicators
  • Malware-related patterns

This mode helps identify suspicious elements but does not automatically prove that a repository is malicious.


AI Security Review

RepoScope reports are designed to be reviewed by AI assistants and LLMs.

The generated report can be provided to an AI with a prompt such as:

You are a senior cybersecurity analyst.

Analyze this GitHub repository inspection report.

Tasks:

1. Review the project structure.
2. Analyze suspicious patterns.
3. Identify possible malicious behavior.
4. Explain false positives.
5. Check for dangerous permissions or persistence.
6. Evaluate potential security risks.
7. Give a trust score from 0 to 10.

Score meaning:

0 = Highly suspicious / unsafe
10 = Very likely trustworthy

Here is the report:

[PASTE REPORT HERE]...

This workflow allows RepoScope to be used as a GitHub repository-to-AI analysis tool, where the repository is inspected locally before its generated report is provided to an AI.


Security Disclaimer

RepoScope does not guarantee that a repository is safe.

It is an inspection and reporting tool.

A safe-looking report does not automatically mean a project is secure.

For important software, combine RepoScope with:

  • Manual code review
  • Antivirus scanning
  • Sandbox testing
  • Dependency analysis
  • Community reputation checks

Privacy

RepoScope:

  • Does not upload repositories
  • Does not send reports anywhere
  • Does not execute downloaded source code
  • Does not install repository dependencies

All analysis happens locally on your computer.


License

This project is licensed under the MIT License.

See the LICENSE file for details.

Releases

Packages

Contributors

Languages