Open Source · Single Binary · Zero Setup

Understand & secure any codebase.

Download one binary. Point it at any repo. Get interactive documentation with architecture diagrams — or run a full security audit with threat modeling, vulnerability detection, and secrets scanning. All powered by AI. No API keys. No installs. No config.

Terminal
$ codebase-agent understand ./my-project

⏳ Scanning ./my-project...
✅ Loaded 247 files (38,291 lines) across 3 languages
Using Ollama Cloud

🚀 Spawning 4 agents in parallel...

[agent 1] ✅ Project Overview → README.md
[agent 2] ✅ Architecture Diagram → architecture.md
[agent 3] ✅ Data Flow → data-flow.md
[agent 4] ✅ Module Map → module-map.md
[5/5] Building interactive HTML site...
✅ Interactive site → index.html

🎉 Done! Open in browser: file://./my-project/understanding/index.html
~26MB
Single Binary
0
Dependencies
8
AI Agents
15+
Languages

Everything baked in

One binary. D2 diagram engine + AI client compiled inside. Download and go.

🧠

Multi-Agent Architecture

4 AI agents run in parallel — one for project overview, one for architecture diagrams, one for data flow, one for module mapping. ~4x faster than sequential.

📊

D2 Diagrams Built In

The D2 rendering engine is compiled into the binary. Component diagrams, class hierarchies, sequence diagrams, data flow — all rendered as dark-themed SVGs.

🌐

Interactive HTML Output

Generates a single-page website with sidebar navigation, rendered diagrams, syntax-highlighted code, and mobile-responsive design. Just open index.html.

⚡

Zero Configuration

No API keys. No Python. No Node. No Docker. No config files. Download the binary and run it. AI inference handled by Ollama Cloud.

🔍

Smart Scanning

Auto-skips venv, node_modules, __pycache__, .git, build, dist, target, vendor, and 30+ other non-source directories. Or use --include/--exclude for full control.

💬

Interactive Q&A

Beyond docs generation — drop into an interactive REPL and ask questions. "How does auth work?" "Where's the rate limiting?" "What calls this function?"

Security Scanner

AI-powered threat modeling, vulnerability detection, and secrets auditing. One command.

Terminal
$ codebase-agent security ./my-api

🔒 Security scan: ./my-api
✅ Loaded 183 files (24,710 lines) across 2 languages

🔒 Spawning 4 security agents in parallel...

[agent 1] ✅ Threat Model → threat-model.md
[agent 2] ✅ Vulnerability Scan → vulnerabilities.md
[agent 3] ✅ Secrets Audit → secrets-audit.md
[agent 4] ✅ Security Architecture → security-architecture.md
[5/5] Building security report HTML...

🎉 Security report complete!

🎯 Threat Model

STRIDE analysis — Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege. Attack surface mapping with D2 risk diagrams.

🐛 Vulnerability Report

Findings categorized Critical → Info. Each with severity, CWE reference, affected code snippet, impact analysis, and remediation steps.

🔑 Secrets Audit

Scans for hardcoded API keys, passwords, tokens, connection strings. Checks .env files, Docker configs, CI/CD pipelines. Data-at-rest and data-in-transit analysis.

🛡️ Security Architecture

Reviews auth/authz design, cryptography usage, input validation, error handling, dependency risks. Generates security layer diagrams. Top 10 recommendations.

Output goes to security-report/ — separate from understanding docs. Includes an interactive HTML report with a red-themed UI.

The understanding/ directory

Every run generates these files in your project.

📄 README.md

Project overview, tech stack, directory structure, key components with file paths, how the system works end-to-end, design patterns used.

🏗️ architecture.md

D2 component diagram showing module relationships. Class hierarchy diagram. Sequence diagram of the main flow. All rendered as SVGs.

🔀 data-flow.md

Every data entry point, transformation step, storage layer, and exit point documented. D2 flowchart showing data movement through the system.

📦 module-map.md

Module dependency graph, what each module does, its public API, what depends on it, cross-cutting concerns, and boundary analysis.

🌐 index.html

Interactive website with sidebar navigation, all docs rendered with embedded SVG diagrams, dark theme, mobile responsive. Share with your team.

📋 INDEX.md

Quick stats (files, lines, languages) and links to all generated docs. Your starting point.

Three commands

That's the entire CLI.

codebase-agent security ./repo Security scan — threat model, vuln report, secrets audit, architecture review
codebase-agent understand ./repo Generate full docs + interactive HTML with D2 diagrams
codebase-agent ask ./repo Interactive Q&A session about the codebase
codebase-agent ask ./repo -q "..." Ask a single question, get an answer, exit
codebase-agent scan ./repo Quick stats: files, lines, languages, file tree
--exclude tests,docs,migrations Skip specific directories during scan
--include src,lib,pkg Only scan specific directories
--local Use local Ollama instead of cloud (requires ollama + model installed)

Works with your stack

Python TypeScript JavaScript Java Go Rust C C++ Ruby PHP C# Kotlin Swift

Install in 10 seconds

Pick your platform. Download. Run. That's it.

🍎

macOS (Apple Silicon)

M1 / M2 / M3 / M4

🍎

macOS (Intel)

x86_64

🐧

Linux

x86_64 & ARM64

macOS (Apple Silicon)
# Download
$ curl -L https://github.com/devthedeveloper/codebase-agent-go/releases/latest/download/codebase-agent-darwin-arm64 -o codebase-agent
$ chmod +x codebase-agent
$ sudo mv codebase-agent /usr/local/bin/

# Generate docs for any project
$ codebase-agent understand ./my-project

# Or ask questions interactively
$ codebase-agent ask ./my-project
Linux (x86_64)
$ curl -L https://github.com/devthedeveloper/codebase-agent-go/releases/latest/download/codebase-agent-linux-amd64 -o codebase-agent
$ chmod +x codebase-agent
$ sudo mv codebase-agent /usr/local/bin/

Windows: Download codebase-agent-windows-amd64.exe from releases.

Under the hood

A Go binary with an AI brain and a diagram engine.

Architecture
# The binary contains:

Scanner → Walks repo, detects languages, skips junk
Context Builder → Extracts file structure + key code sections
4x AI Agents → Run in parallel via Ollama Cloud API
D2 Engine → Compiles diagram source → SVG (embedded in binary)
HTML Builder → Assembles interactive website with rendered diagrams

# What gets sent to the AI:
File tree + first 80 lines of each file (imports + signatures)
Never raw source dumps — smart context, not brute force

# What comes back:
Markdown docs with D2 diagram code blocks
D2 blocks → rendered to SVG by embedded engine → embedded in HTML

Stop reading code.
Understand & secure it.

Open source. Free forever. Built by Dhruv Gupta.