A lightweight GitHub repository inspection, code analysis, and security reporting tool for Windows, Linux, and macOS.
RepoScope helps developers, researchers, and security enthusiasts inspect and analyze public GitHub repositories by automatically cloning a repository and generating a structured analysis report containing source files, project structure, file information, binary hashes, and security-related indicators.
It can be used to extract repository files and source code for further analysis, including analysis with AI assistants and LLMs.
The goal is not to replace professional security tools, but to make GitHub repository inspection, source code analysis, and security investigation faster and easier.
- Automatic GitHub repository cloning
- No manual download required
- Supports public GitHub repositories
- Automatic project tree generation
- File inventory generation
- Repository structure inspection
- Source code extraction
- Important configuration file collection
- Binary SHA256 hash calculation
- File information collection
- Single TXT report generation
- Repository contents prepared for further code or AI analysis
- Suspicious API detection
- Suspicious command detection
- Malware-related keyword search
- Network indicator detection
- Persistence-related indicator detection
- Security-focused investigation mode
- Static inspection of suspicious code patterns
RepoScope can generate reports designed to be analyzed by AI assistants and LLMs.
This makes it useful for:
- AI-assisted GitHub repository analysis
- AI code review
- Security analysis with an LLM
- Reviewing large repositories before sending their contents to an AI
- Extracting source code and repository information for further analysis
- Simple
.batlauncher - Shell launcher for Linux and macOS
- Python-based transparent code
- Progress indicators
- No compiled executable
- Easy to audit and modify
- Local analysis
- Windows
- Linux
- macOS
- Python
- Git
Download Python:
https://www.python.org/downloads/
After installation, verify:
py --versionDownload Git:
After installation, verify:
git --versionClone this repository:
git clone https://github.com/Jovatis/RepoScope.gitor download the ZIP archive.
The project structure should look like:
RepoScope/
│
├── RepoScope.bat
├── RepoScope.py
├── README.md
└── LICENSE
or if you are on Linux/macOS:
RepoScope/
│
├── RepoScope.sh
├── RepoScope.py
├── README.md
└── LICENSE
Run:
RepoScope.bator on Linux/macOS:
RepoScope.shThe tool will then ask you to select an analysis mode:
┌─ MODE ───────────────────────────────────────────────────────────────┐
║ ▶ 1. Quick Scan ║
║ Fast repository inspection. ║
║ ║
║ ○ 2. Full Scan ║
║ Complete repository inspection. ║
║ ║
║ ○ 3. Security Inspection ║
║ Collect security indicators for further analysis. ║
║ ║
║ ○ Q. Quit ║
└──────────────────────────────────────────────────────────────────────┘
You can navigate using the arrow keys on your keyboard and press Enter to select an option.
Then enter a GitHub repository URL.
Example:
https://github.com/jagt/clumsy
RepoScope will then:
- Clone the repository
- Inspect the project structure
- Collect important files
- Generate file information
- Calculate hashes for binaries
- Create a security report
The generated report will be saved locally inside:
Reports/
Example:
Reports/
└── clumsy-analysis-2026-06-11.txt
RepoScope provides three analysis modes:
Fast GitHub repository inspection.
Includes:
- Project structure
- Important source files
- File inventory
- Binary hashes
Large dependency folders are skipped:
node_modulesvendorbuilddisttarget
Recommended for normal GitHub projects.
Complete repository inspection.
Includes:
- All files
- Dependencies
- Generated files
This mode can create larger reports.
Deep static inspection mode.
Includes everything from Full Scan plus:
- Suspicious API detection
- Command execution indicators
- Network-related indicators
- Persistence-related indicators
- Malware-related patterns
This mode helps identify suspicious elements but does not automatically prove that a repository is malicious.
RepoScope reports are designed to be reviewed by AI assistants and LLMs.
The generated report can be provided to an AI with a prompt such as:
You are a senior cybersecurity analyst.
Analyze this GitHub repository inspection report.
Tasks:
1. Review the project structure.
2. Analyze suspicious patterns.
3. Identify possible malicious behavior.
4. Explain false positives.
5. Check for dangerous permissions or persistence.
6. Evaluate potential security risks.
7. Give a trust score from 0 to 10.
Score meaning:
0 = Highly suspicious / unsafe
10 = Very likely trustworthy
Here is the report:
[PASTE REPORT HERE]...
This workflow allows RepoScope to be used as a GitHub repository-to-AI analysis tool, where the repository is inspected locally before its generated report is provided to an AI.
RepoScope does not guarantee that a repository is safe.
It is an inspection and reporting tool.
A safe-looking report does not automatically mean a project is secure.
For important software, combine RepoScope with:
- Manual code review
- Antivirus scanning
- Sandbox testing
- Dependency analysis
- Community reputation checks
RepoScope:
- Does not upload repositories
- Does not send reports anywhere
- Does not execute downloaded source code
- Does not install repository dependencies
All analysis happens locally on your computer.
This project is licensed under the MIT License.
See the LICENSE file for details.