Repository-aware static analysis for AI-assisted development
Overview
·
Installation
·
Documentation
·
Contributing
Code Buster gives AI coding agents a deterministic, offline feedback loop they can run while working. Context overload and hallucinations remain practical constraints, so Code Buster examines individual files and relationships across a repository to surface issues that prompts can miss.
It does not upload source code, call an AI provider, consume model tokens, or
make semantic changes on its own. The executable is cb; optional repository
configuration lives in code-buster.toml.
- 18 recognized source languages
- 480+ registered rules
- 7 report formats
- 0 required cloud services
Install the native Apple Silicon macOS build with Homebrew:
brew install tool-bunker/tap/code-buster
cb versionInstall a native Apple Silicon macOS or x86-64 Linux build with the verified installer:
curl -fsSL https://toolbunker.dev/codebuster/install | shOn x86-64 Windows PowerShell:
irm https://toolbunker.dev/codebuster/install.ps1 | iexWhen Dart 3.11 or newer is already installed:
dart pub global activate code_buster
cb versionThen run Code Buster from a repository root:
cb summaryConfiguration is optional. Start with coverage in the summary, then use focused
commands such as review, duplication, graph, dead, hotspots, or
inspect for the question you need to answer.
Analysis caches live in the operating system's user-cache directory, not in the
analyzed repository. Use --no-cache for one-off runs or --cache-dir PATH
when a CI job or local workflow needs an explicit cache location.
Focused commands and --only RULE execute only the required analysis families.
Finding-family caches are reused independently, and --verbose JSON manifests
include pipeline and rule-family durations for performance diagnosis.
See the installation guide and quickstart for every supported path.
Code Buster combines file-level rules with repository-wide analysis. It reports:
- dependency cycles and architecture-policy violations;
- duplicated blocks, near-duplicate functions, and repeated patterns;
- unreachable production files and declarations;
- complexity growth, hotspots, and maintainability risks;
- correctness, reliability, security, accessibility, performance, and style findings;
- repository structure, source classification, framework, and design-system drift.
Findings can include a stable rule ID, severity, confidence, location, rationale, remediation guidance, related files, and fingerprint. A finding is evidence for review, not proof that the code is wrong.
Code Buster is a static-analysis CLI. It complements rather than replaces a language compiler, type checker, formatter, linter, test suite, or specialist security scanner. Those tools usually have deeper knowledge of their own language or domain and should remain part of the project's verification.
Code Buster's intended role is one local interface for repository-level and cross-file evidence across supported languages: dependency structure, architecture policy, reachability, duplication, change-review signals, and a broad catalog of language and framework checks. Coverage and precision vary by language and rule; unsupported or partial analysis is reported rather than treated as proof that the repository is clean.
Good prompts, project instructions, and focused context should guide an agent before it edits. Code Buster adds deterministic checks before, during, or after the change because instructions do not guarantee that either AI-generated or human-written code matches the rest of the repository.
Make Code Buster part of the agent's working loop rather than waiting for a final review:
- Let the agent implement a focused change.
- Run the narrowest relevant Code Buster command.
- Have the agent evaluate relevant findings and iterate.
- Review the resulting diff, run the project's tests, and exercise the changed behavior.
For a compact, repository-aware review signal without placing the whole codebase in the model's context:
cb review --format jsonCode Buster finds potential issues; the developer or agent decides what matters and makes the fix.
Code Buster recognizes C and C++, Objective-C, C#, Dart, Rust, Mojo, Odin, Nim, Python, JavaScript, TypeScript, Go, HTML, CSS, Java, Wren, SQL, and Lua/Luau. Analysis depth and real-world validation vary by language. Flutter, React, Svelte, PixiJS, and FastAPI are detected as framework profiles rather than separate source languages.
See the current language support matrix.
Available formats are text, JSON, NDJSON, Markdown, SARIF 2.1.0, Mermaid, and JUnit XML. The repository also includes starting integrations for GitHub Actions, Gradle, Maven, VS Code, and Code Climate conversion.
See the command reference, report reference, and integration guide.
Code Buster 0.8.1 is pre-1.0 and under active development. It improves focused change review with stale-contract, high-risk test-coverage, and duplicate implementation evidence; tightens Rust test classification and forwarding analysis; and expands conservative Node.js native-capability guidance. Do not yet rely on it as a blocking production quality gate; evaluate CI and report integrations with explicit policy and preserved coverage.
Build the canonical Dart implementation from source:
dart pub get
dart compile exe bin/cb.dart -o build/cb
./build/cb versionOpen pull requests against main. Keep branches short-lived; main is the
single long-lived branch and must remain releasable. Read
CONTRIBUTING.md for the complete contribution, verification,
and release contract.

