Skip to content

About

Code Buster reports dependency wiring, dead code, cycles, duplication, complexity, architecture-policy violations, feature flags, security and style heuristics, quality scores, and remediation plans.

Topics

Resources

Contributing

Stars

54 stars

Watchers

1 watching

Forks

Latest commit

 

History

90 Commits

Folders and files

Repository files navigation

Code Buster Symbol
Code Buster

Repository-aware static analysis for AI-assisted development

Overview · Installation · Documentation · Contributing

Keep your AI agent grounded

Code Buster gives AI coding agents a deterministic, offline feedback loop they can run while working. Context overload and hallucinations remain practical constraints, so Code Buster examines individual files and relationships across a repository to surface issues that prompts can miss.

It does not upload source code, call an AI provider, consume model tokens, or make semantic changes on its own. The executable is cb; optional repository configuration lives in code-buster.toml.

  • 18 recognized source languages
  • 480+ registered rules
  • 7 report formats
  • 0 required cloud services

See it in action

Code Buster CLI analyzing a repository

Quickstart

Install the native Apple Silicon macOS build with Homebrew:

brew install tool-bunker/tap/code-buster
cb version

Install a native Apple Silicon macOS or x86-64 Linux build with the verified installer:

curl -fsSL https://toolbunker.dev/codebuster/install | sh

On x86-64 Windows PowerShell:

irm https://toolbunker.dev/codebuster/install.ps1 | iex

When Dart 3.11 or newer is already installed:

dart pub global activate code_buster
cb version

Then run Code Buster from a repository root:

cb summary

Configuration is optional. Start with coverage in the summary, then use focused commands such as review, duplication, graph, dead, hotspots, or inspect for the question you need to answer.

Analysis caches live in the operating system's user-cache directory, not in the analyzed repository. Use --no-cache for one-off runs or --cache-dir PATH when a CI job or local workflow needs an explicit cache location. Focused commands and --only RULE execute only the required analysis families. Finding-family caches are reused independently, and --verbose JSON manifests include pipeline and rule-family durations for performance diagnosis.

See the installation guide and quickstart for every supported path.

What Code Buster finds

Code Buster combines file-level rules with repository-wide analysis. It reports:

  • dependency cycles and architecture-policy violations;
  • duplicated blocks, near-duplicate functions, and repeated patterns;
  • unreachable production files and declarations;
  • complexity growth, hotspots, and maintainability risks;
  • correctness, reliability, security, accessibility, performance, and style findings;
  • repository structure, source classification, framework, and design-system drift.

Findings can include a stable rule ID, severity, confidence, location, rationale, remediation guidance, related files, and fingerprint. A finding is evidence for review, not proof that the code is wrong.

Where it fits

Code Buster is a static-analysis CLI. It complements rather than replaces a language compiler, type checker, formatter, linter, test suite, or specialist security scanner. Those tools usually have deeper knowledge of their own language or domain and should remain part of the project's verification.

Code Buster's intended role is one local interface for repository-level and cross-file evidence across supported languages: dependency structure, architecture policy, reachability, duplication, change-review signals, and a broad catalog of language and framework checks. Coverage and precision vary by language and rule; unsupported or partial analysis is reported rather than treated as proof that the repository is clean.

Good prompts, project instructions, and focused context should guide an agent before it edits. Code Buster adds deterministic checks before, during, or after the change because instructions do not guarantee that either AI-generated or human-written code matches the rest of the repository.

Use it with an AI coding agent

Make Code Buster part of the agent's working loop rather than waiting for a final review:

  1. Let the agent implement a focused change.
  2. Run the narrowest relevant Code Buster command.
  3. Have the agent evaluate relevant findings and iterate.
  4. Review the resulting diff, run the project's tests, and exercise the changed behavior.

For a compact, repository-aware review signal without placing the whole codebase in the model's context:

cb review --format json

Code Buster finds potential issues; the developer or agent decides what matters and makes the fix.

Language and framework support

Code Buster recognizes C and C++, Objective-C, C#, Dart, Rust, Mojo, Odin, Nim, Python, JavaScript, TypeScript, Go, HTML, CSS, Java, Wren, SQL, and Lua/Luau. Analysis depth and real-world validation vary by language. Flutter, React, Svelte, PixiJS, and FastAPI are detected as framework profiles rather than separate source languages.

See the current language support matrix.

Reports and integrations

Available formats are text, JSON, NDJSON, Markdown, SARIF 2.1.0, Mermaid, and JUnit XML. The repository also includes starting integrations for GitHub Actions, Gradle, Maven, VS Code, and Code Climate conversion.

See the command reference, report reference, and integration guide.

Current status

Code Buster 0.8.1 is pre-1.0 and under active development. It improves focused change review with stale-contract, high-risk test-coverage, and duplicate implementation evidence; tightens Rust test classification and forwarding analysis; and expands conservative Node.js native-capability guidance. Do not yet rely on it as a blocking production quality gate; evaluate CI and report integrations with explicit policy and preserved coverage.

Development and contributing

Build the canonical Dart implementation from source:

dart pub get
dart compile exe bin/cb.dart -o build/cb
./build/cb version

Open pull requests against main. Keep branches short-lived; main is the single long-lived branch and must remain releasable. Read CONTRIBUTING.md for the complete contribution, verification, and release contract.

About

Code Buster reports dependency wiring, dead code, cycles, duplication, complexity, architecture-policy violations, feature flags, security and style heuristics, quality scores, and remediation plans.

Topics

Resources

Contributing

Stars

54 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages