Download one binary. Point it at any repo. Get interactive documentation with architecture diagrams — or run a full security audit with threat modeling, vulnerability detection, and secrets scanning. All powered by AI. No API keys. No installs. No config.
Features
One binary. D2 diagram engine + AI client compiled inside. Download and go.
4 AI agents run in parallel — one for project overview, one for architecture diagrams, one for data flow, one for module mapping. ~4x faster than sequential.
The D2 rendering engine is compiled into the binary. Component diagrams, class hierarchies, sequence diagrams, data flow — all rendered as dark-themed SVGs.
Generates a single-page website with sidebar navigation, rendered diagrams, syntax-highlighted code, and mobile-responsive design. Just open index.html.
No API keys. No Python. No Node. No Docker. No config files. Download the binary and run it. AI inference handled by Ollama Cloud.
Auto-skips venv, node_modules, __pycache__, .git, build, dist, target, vendor, and 30+ other non-source directories. Or use --include/--exclude for full control.
Beyond docs generation — drop into an interactive REPL and ask questions. "How does auth work?" "Where's the rate limiting?" "What calls this function?"
New
AI-powered threat modeling, vulnerability detection, and secrets auditing. One command.
STRIDE analysis — Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege. Attack surface mapping with D2 risk diagrams.
Findings categorized Critical → Info. Each with severity, CWE reference, affected code snippet, impact analysis, and remediation steps.
Scans for hardcoded API keys, passwords, tokens, connection strings. Checks .env files, Docker configs, CI/CD pipelines. Data-at-rest and data-in-transit analysis.
Reviews auth/authz design, cryptography usage, input validation, error handling, dependency risks. Generates security layer diagrams. Top 10 recommendations.
Output goes to security-report/ — separate from understanding docs. Includes an interactive HTML report with a red-themed UI.
What you get
Every run generates these files in your project.
Project overview, tech stack, directory structure, key components with file paths, how the system works end-to-end, design patterns used.
D2 component diagram showing module relationships. Class hierarchy diagram. Sequence diagram of the main flow. All rendered as SVGs.
Every data entry point, transformation step, storage layer, and exit point documented. D2 flowchart showing data movement through the system.
Module dependency graph, what each module does, its public API, what depends on it, cross-cutting concerns, and boundary analysis.
Interactive website with sidebar navigation, all docs rendered with embedded SVG diagrams, dark theme, mobile responsive. Share with your team.
Quick stats (files, lines, languages) and links to all generated docs. Your starting point.
Usage
That's the entire CLI.
codebase-agent security ./repo
Security scan — threat model, vuln report, secrets audit, architecture review
codebase-agent understand ./repo
Generate full docs + interactive HTML with D2 diagrams
codebase-agent ask ./repo
Interactive Q&A session about the codebase
codebase-agent ask ./repo -q "..."
Ask a single question, get an answer, exit
codebase-agent scan ./repo
Quick stats: files, lines, languages, file tree
--exclude tests,docs,migrations
Skip specific directories during scan
--include src,lib,pkg
Only scan specific directories
--local
Use local Ollama instead of cloud (requires ollama + model installed)
Languages
Get Started
Pick your platform. Download. Run. That's it.
M1 / M2 / M3 / M4
x86_64
x86_64 & ARM64
Windows: Download codebase-agent-windows-amd64.exe from releases.
How it works
A Go binary with an AI brain and a diagram engine.
Open source. Free forever. Built by Dhruv Gupta.