FIND • FIX • REPORT

See what your AI subscription
actually costs you.

RepoScope shows which files burn the most tokens, audits your .cursorrules for bloat, projects when your Cursor Pro or Claude Pro plan runs out, and catches hardcoded secrets — all locally, in your sidebar. Free to install. Pro adds full cost analysis, subscription intelligence, and compliance mapping across 5 frameworks with audit-ready templates.

Free on every install: a 44-detector security scanner with file:line findings, a token-ranked repo map, and EU AI Act provenance tracking. Upgrade to Pro for full cost analysis, subscription runway tracking, rules audit with 1-click fixes, and the compliance engine.

Install Free Try the live demo → See a real report →

Now in the Cursor Marketplace · VS Code · Devin Desktop — one-click install →

Already using RepoScope? Star on GitHub →  ·  Rate on VS Marketplace →

Works on
VS Code Cursor Devin Desktop Python · TS · Go · Rust + 10 more
What You Get

Audit-ready compliance reports,
generated from your code.

Most tools hand you a score. RepoScope hands you the documents an auditor actually asks for — generated automatically, branded, and ready to forward. This is real output from a demo repo, not a mockup.

Real generated output RepoScope Audit Evidence Package landing page for the acme-api demo repo — overall posture 86/100, with SOC 2 Type II 83, EU AI Act Article 12 92, and ISO/IEC 42001 94, each linking to a Control Matrix, Attestation Memo, Gap Plan, and Evidence Response Open the full sample package →

One command. Four documents. Every framework.

Run Prepare for Audit and RepoScope writes a complete evidence package to your repo — a branded landing page plus four print-ready documents for each framework you assess:

Control Matrix

Every control, its status, the evidence, and the owner.

Attestation Memo

A one-page executive summary with a sign-off block.

Gap Plan

Open items ranked by severity — a ready-made POA&M.

Evidence Response

Pre-answers the questions an auditor will send you.

Saved to .reposcope/audit/ as self-contained HTML — open in any browser, print to PDF, or forward as-is. No cloud, no consultant, no copy-paste. Browse the full sample → · Drive the interactive demo →

You build apps and tools for clients. Proving the code is secure and compliant used to mean a consultant and days of work. Now you run one command and hand them a SOC 2 gap analysis before the meeting ends — control matrix, attestation memo, gap plan, and an auditor evidence response, each mapped to the exact framework control.

That's the whole idea: find the gaps, fix what matters, report it in a form you can hand off. Code-level controls only — a development aid, not a certification tool.

The Problem

Your AI subscription
has a leak.

Your AI assistant silently includes rules files, configs, lockfiles, and auto-generated code on every prompt — burning tokens before you type a word. Most developers can't see any of it.

🔁 Your AI subscription runs out too fast

Hidden context overhead — rules files, auto-included configs, bloated lockfiles — burns tokens on every prompt before you even type your question. A 5K-token rules file at 30 prompts/day wastes 4.5M tokens/month. That's why your Cursor Pro plan runs dry by week three.

🔒 Security happens after the fact

Hardcoded secrets, SQL injection, and XSS often surface only in post-merge reviews — or never. You need a scanner that finds them in source, with file and line, before Cursor's agent builds on top of them.

🗺️ New repos take hours to understand

Without a fast read on which files are heaviest and what changed recently, every unfamiliar codebase is a week of archaeology before you can make a confident change.

📋 Every AI session starts from zero

No memory of your architecture, no context about what you're building. You re-explain everything. Every. Single. Session.

5 Frameworks

OWASP Top 10, SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001 — mapped from your security findings with posture scores, per-control status, and audit-ready templates you can hand to an auditor. One command: Prepare for Audit.

The Platform

Three engines.
One sidebar. Zero cloud.

Every competitor asks you to choose: a security scanner or a compliance platform. RepoScope ships both — plus cost intelligence — without charging you $10K to find out what your code is doing.

01
Cost & Subscription Intelligence Pro

See what AI actually costs you.
Before you send the prompt.

Model-agnostic token cost per file, ranked by expense — works across GPT, Claude, and Gemini without locking you to any provider's tokenizer. The Budget tab surfaces exactly what your IDE sends to AI on every request: rules files, auto-included configs, lockfiles — the hidden overhead that erodes your subscription. A Context Overhead Scanner quantifies the per-prompt tax. Rules Audit identifies bloated and duplicated instructions in your .cursorrules with one-click fixes. Subscription Runway projects your burn rate daily. AI Game Plan keeps your architecture context persistent across every AI session — no more re-explaining the same codebase from scratch.

Budget — context overhead, subscription runway, rules audit Cost — model-agnostic token cost per file, ranked Game Plan — persistent AI architecture context
Token cost per file Subscription Runway Rules audit + 1-click fix ~chars/4 estimate
02
Security Intelligence Free

44 detectors. 14 languages.
Every finding: file, line, fix.

A pattern-based workspace scanner that walks your source tree and surfaces committed secrets — GitHub, Slack, Stripe, JWTs, AWS keys, database connection strings — alongside unsafe execution (eval(), os.system, child_process), framework XSS, permissive CORS, disabled TLS verification, weak cryptography, and known-vulnerable dependencies. Every finding carries a confidence level, a CWE ID, a file path, a line number, and a concrete fix. 0–100 security score with a trend. Token-ranked Repo Map gives you a git-aware overview of your full codebase at a glance — every file ranked by what it costs to include in an AI prompt.

Security Scanner — 44 detectors, 14 languages, CWE IDs Repo Map — token-ranked, git-aware, click to open
44 detectors 14 languages 0–100 score + trend CWE IDs on every finding
03
Compliance Intelligence Provenance · Free Compliance · Pro

From scan to audit package.
One command. No consultant.

RepoScope maps your security findings directly to five regulatory frameworks — OWASP Top 10 (2021), SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001 — scoring your posture per control with PASS / PARTIAL / FAIL status and a trend line. Hit Prepare for Audit and four audit-ready documents generate in seconds: a Control Matrix, an Attestation Memo, a Gap Plan, and an Evidence Response. The deliverables that used to require a compliance consultant. Code provenance tracking for EU AI Act Article 12 runs on every install — free — recording AI-generated files in a SHA-256 hash-chained tamper-evident ledger. Code-level controls only — a development aid, not a certification tool.

Compliance — 5 frameworks, 4 audit template types Provenance — SHA-256 hash-chained AI code ledger Audit Prep — 1-click evidence package export
5 frameworks 4 template types Hash-chained ledger 1 command
Without RepoScope vs. With RepoScope
What you need Without RepoScope With RepoScope
Know which files eat your AI tokens Guess, or wait for the bill ✓ Per-file token cost ranked, before you prompt
Know when your Cursor Pro runs out Check the usage page manually ✓ Subscription Runway projects your burn rate daily
Find bloated .cursorrules Read through them yourself ✓ Rules Audit flags issues + 1-click fix
Catch hardcoded secrets before commit Hope your PR reviewer spots them ✓ 44 detectors scan on save, file:line findings
Understand a new codebase fast Spend a week reading files ✓ Repo Map ranks every file by cost + recent changes
Show compliance posture to a client Hire a consultant ($10K+) ✓ "Prepare for Audit" — 4 docs, 5 frameworks, 30 seconds
Keep AI context across sessions Re-explain everything every time ✓ Game Plan persists your architecture context
Price Free time + consultant fees Free forever · Pro $14.99/mo
How It Works

From install to first
fix in under 2 minutes.

01

Install RepoScope

Search reposcope in VS Code, Cursor, or Devin Desktop. One click. No configuration required. Works on any project immediately.

02

Run Your First Scan

Open any workspace and hit Cmd+Shift+Alt+K — or click the RepoScope icon in the activity bar. It scans every file for token cost, security issues, and dependency structure.

03

Read Your Results

Your results land in one sidebar, grouped Free → Pro. Free: Security lists concrete findings — file, line, severity, and fix hint — ranked by risk; Repo Map ranks every file by token cost with branch and recent-commit context; Provenance shows your EU AI Act Article 12 readiness score and AI-generated file inventory — no configuration. Pro unlocks Cost (model-agnostic token cost per file), Budget (context overhead, rules audit, subscription runway), Compliance (OWASP / SOC 2 / PCI-DSS / EU AI Act / ISO 42001 posture with audit-ready templates), the AI Game Plan, and 1-click Audit Prep.

04

Fix What Matters

Security: click any finding to jump to the code. Follow the fix hint. Re-scan to confirm it cleared. Pro: run the Rules Audit to find bloated context eating your subscription. Apply the suggestions and watch your per-prompt overhead drop.

RepoScope · sidebar output · 847 files analyzed
CONTEXT OVERHEAD (per prompt)
────────────────────────────────────────────
.cursorrules ~3,200 tokens ⚠️ audit recommended
.cursor/rules/testing.mdc ~1,100 tokens
package.json ~1,200 tokens
.reposcope-gameplan.json ~1,300 tokens
Total overhead: ~6,800 tokens/prompt

TOP TOKEN OFFENDERS
────────────────────────────────────────────
dist/bundle.min.js 42,891 tokens (auto-generated — exclude)
package-lock.json 18,442 tokens (never useful to AI)
src/types/generated.ts 9,103 tokens (consider splitting)
src/index.ts 6,218 tokens (barrel export — prune)
src/auth/login.ts 1,204 tokens ✓ efficient

SECURITY: 2 critical · 5 medium · 0 low
COMPLIANCE: OWASP 75 · SOC 2 83 · PCI-DSS 88 · EU AI Act 92 · ISO 42001 94
AUDIT: 4 templates ready · Prepare for Audit → full evidence package
SUBSCRIPTION: Cursor Pro · Day 12/30 · ✅ On track
RECOMMENDATIONS: 3 fixes available · save ~24,700 tok/prompt
Who It's For

Built for developers who
pay for AI by the token.

If you live in Cursor, VS Code, or Devin Desktop, RepoScope catches risky code and maps your repo for free — and adds Cost, Budget, and Compliance across 5 frameworks with audit-ready templates when you upgrade to Pro.

🧑‍💻 Subscription developers

On Cursor Pro, Claude Pro, or Windsurf Pro? See exactly what's eating your monthly token budget. Audit your rules files, track your subscription runway, and apply one-click fixes to extend your plan by days — not dollars.

🗺️ New-repo onboarding

Understand an unfamiliar codebase in minutes with token-ranked files and recent-commit context — not a week of archaeology.

🔐 Security-conscious builders

Catch hardcoded secrets and risky patterns locally — with file:line findings before your AI agent builds on top of them.

📋 Security & compliance leads

Need to show OWASP, SOC 2, PCI-DSS, EU AI Act, or ISO 42001 posture to an auditor? Compliance maps your security findings to 5 framework controls with pass/fail status and generates audit-ready templates — Control Matrix, Attestation Memo, Gap Plan, Evidence Response — locally, with one command. Code-level controls only, a development aid.

👥 Team leads & staff engineers

Commit a shared Game Plan, onboard new devs faster, and spot token hotspots before they hit everyone's API bill.

See It In Action

One sidebar, two groups — Free and Pro. Real captures, real numbers. Free: concrete security findings, a token-ranked repo map, and EU AI Act Article 12 provenance tracking. Pro: model-agnostic cost per file, your subscription burn & runway, compliance posture across OWASP / SOC 2 / PCI-DSS / EU AI Act / ISO 42001 with audit-ready templates and the findings to remediate, and an AI game plan — without leaving your editor.

Live capture RepoScope Budget tab — context overhead per prompt, rules audit, and a Subscription Runway projection showing 25.5% of budget used and 117.6 days of runway
Runway 117.6 days Budget used 25.5% Overhead ~502/prompt
Budget — your subscription burn & runway Pro
Live capture RepoScope Cost tab on the acme-api demo repo — estimated ~86.3k tokens, 5 hotspots, costliest file seed-products.json at ~73.6k, with the Tokens Recovered tracker
Est. tokens ~86.3k Hotspots 5 Costliest ~73.6k
Cost — estimated token cost per file (~chars/4) Pro
Live capture RepoScope Security tab on the acme-api demo repo — security score 91, 5 findings across 12 files (0 critical, 0 high, 3 medium, 2 low), each finding with its CWE and OWASP mapping, file:line, and a code snippet
Score 91 Findings 5 Files scanned 12
Security — findings with CWE + OWASP, click to the line Free
Live capture RepoScope Repo Map tab on the acme-api demo repo — 15 files ranked by token count (top file seed-products.json at 73.6k), with branch feature/order-coupons and recent commit context
Files 15 Top file 73.6k Branch order-coupons
Repo Map — files ranked by token cost + git context Free
Live capture RepoScope Game Plan tab on the acme-api demo repo — 8 goals (0 of 8 complete) spanning security findings, token-waste hotspots, and branch hygiene, each with a one-click AI fix, plus a Suggest Goals action
Goals 8 Complete 0/8 AI suggestions on
Game Plan — AI-suggested goals from your scan Pro
Live capture RepoScope Compliance tab — posture scores OWASP Top 10 75, SOC 2 83, PCI-DSS 88, with per-framework passing ratios, coverage percentages, a posture trend, and JSON export
OWASP 75 SOC 2 83 PCI-DSS 88 EU AI Act 92 ISO 42001 94
Compliance — 5 frameworks · audit-ready templates · posture trend Pro
Drive the interactive demo

Click through every tab yourself on a sample acme-api repo — then open the report it produces.

Install

Two ways to install
on every editor.

Now in the Cursor Marketplace as a native plugin, and on VS Marketplace + Open VSX as an extension. Same features everywhere — nxgentech.reposcope-ai.

VS Code

1MarketplaceLive

Open Extensions (⌘⇧X), search RepoScope by publisher nxgentech, and click Install.

One-click install →
2Manual

From the Command Palette (⌘⇧P) or your terminal:

ext install nxgentech.reposcope-ai code --install-extension nxgentech.reposcope-ai

Cursor

1Cursor Plugin MarketplaceLive

In Cursor, open the Command Palette (⌘⇧P), run Customize, and search RepoScope. One click to install — brings skills, rules, and commands directly into your agent.

Browse Cursor Marketplace →
2VS Code Extension (Open VSX)Live

Open Extensions (⌘⇧X), search RepoScope by publisher nxgentech, and click Install. Backed by Open VSX, where RepoScope is verified & published.

One-click install →

Devin Desktop

1Open VSXLive

Devin Desktop (formerly Windsurf) uses Open VSX. Open Extensions (⌘⇧X), search RepoScope by publisher nxgentech, and click Install.

2Manual

Download the .vsix from Open VSX, then Extensions ⋯ → Install from VSIX…

Download from Open VSX →

RepoScope is now in the Cursor Marketplace as a native plugin — hooks, skills, and commands activate immediately in your agent. The VS Code extension is also available everywhere. Every install includes a free 7-day Pro trial; no credit card required.

FAQ

Common questions

What compliance frameworks does RepoScope support?

RepoScope maps security findings to five frameworks: OWASP Top 10 (2021), SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001. Each framework gets a posture score, per-control PASS/FAIL/PARTIAL status, and four audit-ready templates. Code-level controls only — a development aid, not a certification tool.

How much does it cost?

The security scanner, repo map, and EU AI Act provenance tracking are free on every install — unlimited scans, no credit card. Pro is $14.99/mo ($129/yr) and adds compliance mapping, audit templates, cost tracking, budget intelligence, and the AI Game Plan. Enterprise GRC platforms typically run $10K–$50K/yr.

Can RepoScope generate audit-ready reports?

Yes. Run Prepare for Audit and RepoScope generates four documents per framework: Control Matrix, Attestation Memo, Gap Plan, and Evidence Response — all mapped to your real scan results and saved as self-contained HTML you can open, print, or forward. See a real sample →

Does it work with Cursor and Windsurf?

Yes. RepoScope works in VS Code, Cursor, and Devin Desktop. In Cursor, install as a native plugin via the Cursor Marketplace (search "RepoScope" in Customize), or as a VS Code extension from Open VSX — same features everywhere.

Is RepoScope a certification tool?

No. RepoScope provides code-level controls only — it's a development aid that helps you identify gaps and generate evidence, not a certification tool. Consult a qualified auditor for formal compliance certification.

Does my code leave my machine?

No. RepoScope is 100% local-first. Scans run on your machine via bundled ast-grep. Only anonymous funnel events leave your machine, and you can disable them with reposcope.telemetry.

Pricing

Start free.
Scale when you need to.

No credit card required to start. Every install includes a free 7-day Pro trial. Cancel anytime.

Free
$0
Catch secrets and map your repo — no upgrade required.
  • Security scanner — 44 detectors, 14 languages
  • Repo Map — token-ranked file list
  • Provenance — EU AI Act Article 12 readiness tracking
  • Unlimited scans
  • 7-day Pro trial included
Install Free
Beta · Waitlist
Team
$359/mo
5 seats · beta pricing
  • Everything in Pro, for every seat
  • Multi-repo compliance dashboard — one view, every repo
  • Cross-repo posture trends
  • AI support agents — 100 interactions/mo
  • Team admin — invite developers, manage seats
  • Launching with the web dashboard — join the waitlist
Join the waitlist

Beta pricing · locked in for early teams

Enterprise & MSP

5+ seats · SSO/SAML · custom compliance framework mappings · multi-repo posture dashboard · branded audit packages · dedicated CSM · SLA · professional services / SOW · MSP partner program.

Explore Enterprise →
Early Results

Real numbers,
not stock-photo reviews.

RepoScope is early. Instead of inventing testimonials, here's exactly what it does today — measured from the scanner itself.

Downloads
Across VS Marketplace & Open VSX — VS Code, Cursor, Windsurf & Devin Desktop. Zero paid ads.
44
Security detectors
Secrets, framework XSS, unsafe execution, config risks & vulnerable dependencies — each with a confidence level and CWE.
14
Languages analyzed
Python, TypeScript, JavaScript, Go, Rust, Java, C#, Ruby, PHP, Kotlin, Swift, C/C++ and more.
<1s
Sub-second scans
~1,000 source files scanned locally in under a second — no cloud round-trip.
5
Compliance frameworks
OWASP Top 10, SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001 — with audit-ready templates.

Using RepoScope? Leave a review.

A quick rating is the single best way to help other developers find it — it takes 20 seconds.

We publish results as real users share them — no fabricated quotes.

For Security Teams & MSPs

Your developers already installed it.
Your security team is next.

Individual devs discover RepoScope in the marketplace. They start a Pro trial. Their compliance scores appear in the sidebar. They ask: "Can I show this to a client?" That's the moment the enterprise deal begins — without a single cold call.

🔒
Team Compliance Program
$359/mo flat for 5 seats. Shared compliance posture, cross-repo aggregation, team admin.
🏢
Enterprise / SOW
5+ seats, custom frameworks, SSO/SAML, SLA, dedicated CSM, and professional services.
🤝
MSP Partner Program
Deploy across client repos. Generate branded audit packages. Deliver the Gap Plan as a SOW. Recurring posture retainer.
Why we built it

Every developer should be able to prove their code is secure, compliant, and audit-ready — without a $50K platform, a compliance consultant, or shipping their source to a third party.

RepoScope makes that possible from your IDE, for $14.99 a month.

Stop guessing if your
codebase is audit-ready.

Install free. No credit card. No repo connection. First scan takes 30 seconds.

Free forever · unlimited Security + Repo Map + Provenance · 7-day Pro trial · Cursor · VS Code · Devin Desktop · 14 languages