RepoScope shows which files burn the most tokens, audits your .cursorrules for bloat, projects when your Cursor Pro or Claude Pro plan runs out, and catches hardcoded secrets — all locally, in your sidebar. Free to install. Pro adds full cost analysis, subscription intelligence, and compliance mapping across 5 frameworks with audit-ready templates.
Free on every install: a 44-detector security scanner with file:line findings, a token-ranked repo map, and EU AI Act provenance tracking. Upgrade to Pro for full cost analysis, subscription runway tracking, rules audit with 1-click fixes, and the compliance engine.
Now in the Cursor Marketplace · VS Code · Devin Desktop — one-click install →
★ Already using RepoScope? Star on GitHub → · Rate on VS Marketplace →
Most tools hand you a score. RepoScope hands you the documents an auditor actually asks for — generated automatically, branded, and ready to forward. This is real output from a demo repo, not a mockup.
Open the full sample package →
Run Prepare for Audit and RepoScope writes a complete evidence package to your repo — a branded landing page plus four print-ready documents for each framework you assess:
Every control, its status, the evidence, and the owner.
A one-page executive summary with a sign-off block.
Open items ranked by severity — a ready-made POA&M.
Pre-answers the questions an auditor will send you.
Saved to .reposcope/audit/ as self-contained HTML — open in any browser, print to PDF, or forward as-is. No cloud, no consultant, no copy-paste. Browse the full sample → · Drive the interactive demo →
You build apps and tools for clients. Proving the code is secure and compliant used to mean a consultant and days of work. Now you run one command and hand them a SOC 2 gap analysis before the meeting ends — control matrix, attestation memo, gap plan, and an auditor evidence response, each mapped to the exact framework control.
Your AI assistant silently includes rules files, configs, lockfiles, and auto-generated code on every prompt — burning tokens before you type a word. Most developers can't see any of it.
Hidden context overhead — rules files, auto-included configs, bloated lockfiles — burns tokens on every prompt before you even type your question. A 5K-token rules file at 30 prompts/day wastes 4.5M tokens/month. That's why your Cursor Pro plan runs dry by week three.
Hardcoded secrets, SQL injection, and XSS often surface only in post-merge reviews — or never. You need a scanner that finds them in source, with file and line, before Cursor's agent builds on top of them.
Without a fast read on which files are heaviest and what changed recently, every unfamiliar codebase is a week of archaeology before you can make a confident change.
No memory of your architecture, no context about what you're building. You re-explain everything. Every. Single. Session.
OWASP Top 10, SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001 — mapped from your security findings with posture scores, per-control status, and audit-ready templates you can hand to an auditor. One command: Prepare for Audit.
Every competitor asks you to choose: a security scanner or a compliance platform. RepoScope ships both — plus cost intelligence — without charging you $10K to find out what your code is doing.
Model-agnostic token cost per file, ranked by expense — works across GPT, Claude, and Gemini without locking you to any provider's tokenizer. The Budget tab surfaces exactly what your IDE sends to AI on every request: rules files, auto-included configs, lockfiles — the hidden overhead that erodes your subscription. A Context Overhead Scanner quantifies the per-prompt tax. Rules Audit identifies bloated and duplicated instructions in your .cursorrules with one-click fixes. Subscription Runway projects your burn rate daily. AI Game Plan keeps your architecture context persistent across every AI session — no more re-explaining the same codebase from scratch.
A pattern-based workspace scanner that walks your source tree and surfaces committed secrets — GitHub, Slack, Stripe, JWTs, AWS keys, database connection strings — alongside unsafe execution (eval(), os.system, child_process), framework XSS, permissive CORS, disabled TLS verification, weak cryptography, and known-vulnerable dependencies. Every finding carries a confidence level, a CWE ID, a file path, a line number, and a concrete fix. 0–100 security score with a trend. Token-ranked Repo Map gives you a git-aware overview of your full codebase at a glance — every file ranked by what it costs to include in an AI prompt.
RepoScope maps your security findings directly to five regulatory frameworks — OWASP Top 10 (2021), SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001 — scoring your posture per control with PASS / PARTIAL / FAIL status and a trend line. Hit Prepare for Audit and four audit-ready documents generate in seconds: a Control Matrix, an Attestation Memo, a Gap Plan, and an Evidence Response. The deliverables that used to require a compliance consultant. Code provenance tracking for EU AI Act Article 12 runs on every install — free — recording AI-generated files in a SHA-256 hash-chained tamper-evident ledger. Code-level controls only — a development aid, not a certification tool.
| What you need | Without RepoScope | With RepoScope |
|---|---|---|
| Know which files eat your AI tokens | Guess, or wait for the bill | ✓ Per-file token cost ranked, before you prompt |
| Know when your Cursor Pro runs out | Check the usage page manually | ✓ Subscription Runway projects your burn rate daily |
| Find bloated .cursorrules | Read through them yourself | ✓ Rules Audit flags issues + 1-click fix |
| Catch hardcoded secrets before commit | Hope your PR reviewer spots them | ✓ 44 detectors scan on save, file:line findings |
| Understand a new codebase fast | Spend a week reading files | ✓ Repo Map ranks every file by cost + recent changes |
| Show compliance posture to a client | Hire a consultant ($10K+) | ✓ "Prepare for Audit" — 4 docs, 5 frameworks, 30 seconds |
| Keep AI context across sessions | Re-explain everything every time | ✓ Game Plan persists your architecture context |
| Price | Free time + consultant fees | Free forever · Pro $14.99/mo |
Search reposcope in VS Code, Cursor, or Devin Desktop. One click. No configuration required. Works on any project immediately.
Open any workspace and hit Cmd+Shift+Alt+K — or click the RepoScope icon in the activity bar. It scans every file for token cost, security issues, and dependency structure.
Your results land in one sidebar, grouped Free → Pro. Free: Security lists concrete findings — file, line, severity, and fix hint — ranked by risk; Repo Map ranks every file by token cost with branch and recent-commit context; Provenance shows your EU AI Act Article 12 readiness score and AI-generated file inventory — no configuration. Pro unlocks Cost (model-agnostic token cost per file), Budget (context overhead, rules audit, subscription runway), Compliance (OWASP / SOC 2 / PCI-DSS / EU AI Act / ISO 42001 posture with audit-ready templates), the AI Game Plan, and 1-click Audit Prep.
Security: click any finding to jump to the code. Follow the fix hint. Re-scan to confirm it cleared. Pro: run the Rules Audit to find bloated context eating your subscription. Apply the suggestions and watch your per-prompt overhead drop.
If you live in Cursor, VS Code, or Devin Desktop, RepoScope catches risky code and maps your repo for free — and adds Cost, Budget, and Compliance across 5 frameworks with audit-ready templates when you upgrade to Pro.
On Cursor Pro, Claude Pro, or Windsurf Pro? See exactly what's eating your monthly token budget. Audit your rules files, track your subscription runway, and apply one-click fixes to extend your plan by days — not dollars.
Understand an unfamiliar codebase in minutes with token-ranked files and recent-commit context — not a week of archaeology.
Catch hardcoded secrets and risky patterns locally — with file:line findings before your AI agent builds on top of them.
Need to show OWASP, SOC 2, PCI-DSS, EU AI Act, or ISO 42001 posture to an auditor? Compliance maps your security findings to 5 framework controls with pass/fail status and generates audit-ready templates — Control Matrix, Attestation Memo, Gap Plan, Evidence Response — locally, with one command. Code-level controls only, a development aid.
Commit a shared Game Plan, onboard new devs faster, and spot token hotspots before they hit everyone's API bill.
One sidebar, two groups — Free and Pro. Real captures, real numbers. Free: concrete security findings, a token-ranked repo map, and EU AI Act Article 12 provenance tracking. Pro: model-agnostic cost per file, your subscription burn & runway, compliance posture across OWASP / SOC 2 / PCI-DSS / EU AI Act / ISO 42001 with audit-ready templates and the findings to remediate, and an AI game plan — without leaving your editor.
Click through every tab yourself on a sample acme-api repo — then open the report it produces.
Now in the Cursor Marketplace as a native plugin, and on VS Marketplace + Open VSX as an extension. Same features everywhere — nxgentech.reposcope-ai.
Open Extensions (⌘⇧X), search RepoScope by publisher nxgentech, and click Install.
From the Command Palette (⌘⇧P) or your terminal:
ext install nxgentech.reposcope-ai
code --install-extension nxgentech.reposcope-ai
In Cursor, open the Command Palette (⌘⇧P), run Customize, and search RepoScope. One click to install — brings skills, rules, and commands directly into your agent.
Open Extensions (⌘⇧X), search RepoScope by publisher nxgentech, and click Install. Backed by Open VSX, where RepoScope is verified & published.
Devin Desktop (formerly Windsurf) uses Open VSX. Open Extensions (⌘⇧X), search RepoScope by publisher nxgentech, and click Install.
Download the .vsix from Open VSX, then Extensions ⋯ → Install from VSIX…
RepoScope is now in the Cursor Marketplace as a native plugin — hooks, skills, and commands activate immediately in your agent. The VS Code extension is also available everywhere. Every install includes a free 7-day Pro trial; no credit card required.
RepoScope maps security findings to five frameworks: OWASP Top 10 (2021), SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001. Each framework gets a posture score, per-control PASS/FAIL/PARTIAL status, and four audit-ready templates. Code-level controls only — a development aid, not a certification tool.
The security scanner, repo map, and EU AI Act provenance tracking are free on every install — unlimited scans, no credit card. Pro is $14.99/mo ($129/yr) and adds compliance mapping, audit templates, cost tracking, budget intelligence, and the AI Game Plan. Enterprise GRC platforms typically run $10K–$50K/yr.
Yes. Run Prepare for Audit and RepoScope generates four documents per framework: Control Matrix, Attestation Memo, Gap Plan, and Evidence Response — all mapped to your real scan results and saved as self-contained HTML you can open, print, or forward. See a real sample →
Yes. RepoScope works in VS Code, Cursor, and Devin Desktop. In Cursor, install as a native plugin via the Cursor Marketplace (search "RepoScope" in Customize), or as a VS Code extension from Open VSX — same features everywhere.
No. RepoScope provides code-level controls only — it's a development aid that helps you identify gaps and generate evidence, not a certification tool. Consult a qualified auditor for formal compliance certification.
No. RepoScope is 100% local-first. Scans run on your machine via bundled ast-grep. Only anonymous funnel events leave your machine, and you can disable them with reposcope.telemetry.
No credit card required to start. Every install includes a free 7-day Pro trial. Cancel anytime.
Beta pricing · locked in for early teams
5+ seats · SSO/SAML · custom compliance framework mappings · multi-repo posture dashboard · branded audit packages · dedicated CSM · SLA · professional services / SOW · MSP partner program.
Explore Enterprise →RepoScope is early. Instead of inventing testimonials, here's exactly what it does today — measured from the scanner itself.
A quick rating is the single best way to help other developers find it — it takes 20 seconds.
Caught something real with RepoScope?
Tell us what it found →We publish results as real users share them — no fabricated quotes.
Individual devs discover RepoScope in the marketplace. They start a Pro trial. Their compliance scores appear in the sidebar. They ask: "Can I show this to a client?" That's the moment the enterprise deal begins — without a single cold call.
Every developer should be able to prove their code is secure, compliant, and audit-ready — without a $50K platform, a compliance consultant, or shipping their source to a third party.
RepoScope makes that possible from your IDE, for $14.99 a month.