Polyscan

GitHub App · Free for public repos

Your whole repo,
audited every week.

Reviewing one pull request at a time can't show how the codebase as a whole is decaying. Open-source static analysis finds candidate problems across your repository, and an AI agent reads the actual code to check the important ones. The places it recommends fixing first arrive as a GitHub Issue, ten at most.

Every feature is free on public repositories. No card required. Pro brings the same to private repositories.

Audit agent
Health
71▼ 3 this week

polyscan analyze . → 142 findings

  • read_file api/handlers.py:190-262

    ▲ confirmedCC 31, three jobs in one function

  • read_file services/user.py:45-62 + admin.py:23-40

    ▲ confirmed87% clone, same validation twice

  • read_file core/plugins.py:1-44

    ● dismissed"dead code" is a documented plugin hook

142 findings → 6 recommendations · filed as GitHub Issue
Your stack, coveredPythonTypeScriptJavaScriptGoRustC++

The audit agent

Static analysis measures. The agent judges.

Static analysis is exhaustive, but it flags false positives and deliberate design choices just as mechanically as real problems. Polyscan treats that output as a starting point and checks it against the code, the way a human reviewer would.

MEASURE

Measure the whole repository

Open-source analyzers — pyscn for Python, polyscan for JavaScript, TypeScript, Go, Rust, and C++ — measure complexity, duplication, dead code, dependencies, and class design across the entire repository, with the same yardstick on every run.

INVESTIGATE

Read the code to verify

The agent picks the findings that matter most and opens the functions and classes behind them, across files. It is designed to read every copy before recommending a merge, and to set aside findings the code itself explains or that follow the project's own design.

REPORT

Narrow down what to fix

What holds up against the code becomes at most ten recommendations, each naming the file, function, and line, written to a GitHub Issue in one of eight languages.

See how it works in detail

Checked against the code

An audit you can act on, not a list of warnings

Static analyzers print hundreds of warnings and leave it to you to decide which ones are real. Polyscan takes on the first pass of that judgment.

Static analysis alone

  • Hundreds of warnings, listed as-is
  • Can't tell false positives from deliberate design
  • No sense of what to fix first
  • Eventually nobody reads the output

Polyscan

  • The agent reads the actual code behind the important findings
  • Weighs false positives and deliberate design against what the code says
  • At most ten recommendations, with file, function, and line
  • Updates the Issue every week and tracks what changed

Features

Keep watch over your codebase

AUDIT

A whole-repository audit every week

Measures complexity, duplication, dead code, and dependencies across the entire repository every week. The agent reads the code behind the findings, then reports what to fix and what changed in a GitHub Issue.

PR

Catch new decay before merge

Analyzes changed code and flags new complexity or duplication before merge, complementing weekly measurement with real-time feedback.

PR Review Demo

YAML

Simple YAML Configuration

Customize Polyscan behavior with a simple YAML file. No complex setup required.

  • Report language: en, ja, zh, ko, es, fr, de, pt
  • Target directories to analyze
  • Audit interval: daily, weekly, monthly (daily on private repos: Pro)
  • PR review: pr_review: true (off by default; private repos: Pro)

.github/polyscan.yml

# Report language (default: en)
language: ja

# Target directories (default: all)
target_directories:
  - src/

# Audit interval (default: weekly)
audit_interval: weekly

# PR review (default: false; private repos need Pro)
pr_review: true

Readings

Start from measurements, not guesses.

Every investigation starts from these five structural readings, taken across the whole repository.

DEAD

Dead code

Unreachable code you can safely delete, found by walking the control flow graph rather than guessing.

DUP

Duplicate code

Copy-pasted and structurally similar code worth merging — Type 1-4 clone detection via tree edit distance.

CC

Complexity

Functions that are hard to read and hard to test, ranked by cyclomatic complexity so you know where to start.

DEP

Dependencies

Circular imports and unstable module dependencies, plus the module communities your codebase actually forms.

CBO

Class design

Classes that do too much or depend on too much, measured with CBO coupling and LCOM cohesion.

The whole pictureStructure.
Not just style.
See the engine

Open source

The engine is open source.

The analyzers Polyscan uses are MIT licensed. Run them as a CLI on your own machine to see the same readings the agent starts from.

Python

uvx pyscn@latest analyze .

JavaScript / TypeScript / Go / Rust / C++

npx polyscan analyze .

Pricing

Free for open source

Every feature on every public repository, at no cost. Pay only for private repositories.

Free

$0/month
  • Unlimited public repositories, every feature
  • PR review and daily audits on public repos
  • Up to 2 private repos with weekly audits
Get Started Free

Pro

14-Day Free Trial
$10/month
  • Everything in Free
  • Up to 5 private repositories
  • PR review on private repositories
  • Daily audits on private repositories
Start 14-Day Free Trial

Cancel anytime

FAQ

Questions, answered

QWhat is Polyscan?

An AI agent that audits GitHub repositories on a schedule. It measures the whole repository with open-source static analyzers — pyscn for Python, polyscan for JavaScript, TypeScript, Go, Rust, and C++ — then reads the actual code behind the important findings and recommends what to fix first in a GitHub Issue.

QHow is this different from running a static analyzer myself?

An analyzer outputs every finding, including false positives and deliberate design choices, and leaves the triage to you. Polyscan's agent does a first pass of that triage: it reads the code behind the important findings across the repository, sets aside what the code already explains, and narrows the rest down to at most ten recommendations with file, function, and line. The recommendations are an AI's judgment, so treat them as a prioritized starting point rather than a verdict.

QHow is this different from AI code review tools?

Most AI reviewers look only at a pull request's diff. Polyscan measures the entire repository every week and investigates from those measurements, so its findings rest on numbers taken with the same yardstick each run rather than on impressions. PR review is available too, as an opt-in.

QWhere is my code processed?

Your code is analyzed by a local LLM running in our on-premises environment and is never sent to external generative AI APIs. We do not store it: once the report is posted to GitHub, the code is discarded.

QWhich languages are supported?

Python, JavaScript, TypeScript, Go, Rust, and C++. Complexity and duplicate code are measured for every language. Dead code, dependencies, and class design need the import graph and class model that only the Python and JavaScript/TypeScript backends build today, so those dimensions are left out of a Go, Rust, or C++ score rather than counted as clean.

QIs it open source?

The analysis engine — pyscn, polyscan, and the shared core — is MIT licensed and free to run as a CLI. The GitHub App, which adds the agent and runs it for you, is free with every feature on public repositories; Pro covers private repositories.

Install

Put an auditor on your repository

Just install it on GitHub. Every feature is free for public repositories, and the agent reports to a GitHub Issue every week.

Start auditing free