AI Skill Hub 强烈推荐:代码审计工具 是一款优质的Agent工作流。AI 综合评分 8.0 分,在同类工具中表现稳健。如果你正在寻找可靠的Agent工作流解决方案,这是一个值得深入了解的选择。
代码审计工具 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
代码审计工具 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 克隆仓库 git clone https://github.com/TheMorpheus407/RepoLens cd RepoLens # 查看安装说明 cat README.md # 按 README 完成环境依赖安装后即可使用
# 查看帮助 repolens --help # 基本运行 repolens [options] <input> # 详细使用说明请查阅文档 # https://github.com/TheMorpheus407/RepoLens
# repolens 配置说明 # 查看配置选项 repolens --config-example > config.yml # 常见配置项 # output_dir: ./output # log_level: info # workers: 4 # 环境变量(覆盖配置文件) export REPOLENS_CONFIG="/path/to/config.yml"
Multi-lens code audit tool. Runs 337 specialist lenses across 34 domains against any git repository, live server, Android APK, or product specification and creates remote issues for real findings, backlog work, or polishing shortlists. The polish pass also writes ranked suggestion artifacts for review. Think automated code review, agent-driven pentesting, tool-driven static/dynamic analysis, infrastructure auditing, Android auditing, spec-to-backlog planning, and polishing — all with deep specialization.
[!IMPORTANT] RepoLens runs AI agents with shell access against your repository, and a full audit can cost hundreds of dollars in API charges. It is NOT a sandboxed security tool, comes with NO warranty, and you use it entirely at your own risk. Read Warnings & Limits before your first run — especially the cost and security sections.
./repolens.sh --project ~/my-app --agent codex --mode feature --domain testing
| Tool | Required | Purpose | Install |
|---|---|---|---|
bash | Yes (4.0+) | Shell runtime — associative arrays, read -ra, other 4.x features are used throughout | Linux distributions ship 4.0+ already. macOS ships 3.2 by default (GPLv3 avoidance) — upgrade via brew install bash. RepoLens aborts at startup on older bash with an upgrade hint. |
git | Yes | Repo validation, cloning | OS package manager (apt install git, brew install git, nix-env -i git) |
jq | Yes | JSON config parsing | OS package manager (apt install jq, brew install jq, nix-env -i jq) |
timeout (coreutils) | Yes | Per-invocation agent timeout watchdog with SIGKILL escalation grace (see REPOLENS_AGENT_TIMEOUT* and REPOLENS_AGENT_KILL_GRACE below) | Ships in GNU coreutils. Pre-installed on Linux/NixOS. On macOS: brew install coreutils. |
gh, tea, or fj | Yes (unless --local) | Remote forge operations for labels and issue queries | See [Supported forges](#supported-forges) for detection, install links, and auth commands |
| Agent CLI | Yes (at least one) | Run analysis agents | See [Supported Agent CLIs](#supported-agent-clis) below for install + auth per CLI |
docker + docker compose | Only for --hosted | DAST scanning environment | OS package manager |
| Flag | Description |
|---|---|
--project <path\|url> | Local path, APK file, or remote Git URL (cloned read-only if URL) |
--agent <agent> | claude \| codex \| spark \| sparc \| opencode \| opencode/<model> \| antigravity |
./repolens.sh --project /srv/myapp --agent claude --mode deploy --parallel --max-issues 5
./repolens.sh --project /srv/myapp --agent claude --mode deploy --deploy-target server
./repolens.sh --project ~/myapp --agent claude --mode deploy \ --remote ubuntu@198.51.100.10 \ --remote-key ~/.ssh/server_deploy \ --remote-label "Production app server" \ --max-issues 1
./repolens.sh --project /srv/myapp --agent claude --mode deploy --remote ubuntu@host.example.com:2222 --remote-key ~/.ssh/id_ed25519
./repolens.sh --project ~/my-app/app/build/outputs/apk/debug/app-debug.apk --agent claude --mode deploy
./repolens.sh --project ~/my-android-app --agent claude --mode deploy --deploy-target android
Remote deploy mode lets you run deploy-mode server lenses from your workstation while inspecting a server over SSH. Use it only for server targets; it is rejected with --hosted and Android deploy targets.
Remote SSH runs with BatchMode=yes, so the connection must not require an interactive password prompt. Load the key before starting RepoLens, for example with ssh-add ~/.ssh/server_deploy, or pass an unlocked key with --remote-key <path>. RepoLens writes the remote preflight output for each run under logs/<run-id>/.remote/preflight.log.
Remote deploy uses OpenSSH ControlMaster so the run performs one TCP connection and authentication, then multiplexes agent SSH commands over the control socket. The master connection persists for 600 seconds after the last command, which reduces repeated authentication and connection setup during long deploy runs.
For the first run against a remote host, start with --max-issues 1 and avoid --parallel; if you do enable parallel execution, keep it to --parallel --max-parallel 1 until the transcript confirms commands are wrapped correctly and the target handles the SSH load. --max-issues 1 keeps the first pass short, and --max-parallel 1 prevents several lenses from competing for the same remote target while you validate the setup.
Forge actions still happen on the operator workstation. gh, tea, or fj issue creation, label setup, and issue lookups run locally against the configured forge account; only deploy-target investigation commands are wrapped over SSH.
REPOLENS_AGENT_TIMEOUT_DEPLOY=2400 ./repolens.sh --project /srv/myapp --agent claude --mode deploy
```bash
```bash
```bash
| Flag | Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
--mode <mode> | audit (default) \ | feature \ | bugfix \ | bugreport \ | discover \ | deploy \ | custom \ | opensource \ | content \ | greenfield \ | polish |
--bug-report <file\|text> | Required for --mode bugreport. Path to a text file or inline symptom text (read verbatim). Env fallback: REPOLENS_BUG_REPORT_PATH. 100 KB max for file mode. | ||||||||||
--change <statement> | Change impact statement (implies --mode custom) | ||||||||||
--source <file> | Source material (PDF, text, markdown) for content creation or reference | ||||||||||
--logs <path> | Runtime log file or directory for the logs domain (path string only — agent reads it) | ||||||||||
--focus <lens-id> | Run a single lens (e.g., injection, dead-code) | ||||||||||
--lens <lens-id> | Alias for --focus | ||||||||||
--domain <domain-id> | Run all lenses in one domain (e.g., security) | ||||||||||
--relevant-domains <csv> | Comma-separated allowlist of domain ids — the "missing middle" between --focus (1 lens) and full fan-out. The mode-filtered lens list is intersected with this allowlist; unknown or wrong-mode ids abort startup with the offending token named. Whitespace and empty tokens in the CSV are tolerated. Bypassed when --focus or --domain is set (those win). Composes with --scope-by-keywords (AND semantics) and with the triage-side relevant-domains filter. Example: --relevant-domains concurrency,database. | ||||||||||
--scope-by-keywords | Deterministic, LLM-free pruning for --mode bugreport: case-insensitive substring-match the bug-report text against each domain's optional keywords field in config/domains.json. Domains without a keywords field are always kept (back-compat). A zero-match result falls through with no pruning so the lens list never goes empty. Only effective in --mode bugreport (no-op in every other mode). Env fallback: REPOLENS_SCOPE_BY_KEYWORDS=1. | ||||||||||
--agent-override <csv> | Route specific domains or lenses to a different agent than the global --agent, trading API cost against reasoning depth — run a cheap model by default and spend a flagship model only where it matters (e.g. security, architecture). Comma-separated key=agent pairs. Each key is a domain id or a fully-qualified domain/lens; a bare lens id is rejected as ambiguous, since one lens id can live in more than one domain, so lens scope requires the domain/lens form. Each agent accepts the same values as --agent (claude \ | codex \ | spark \ | sparc \ | opencode \ | opencode/<model> \ | antigravity). Precedence: domain/lens > domain > global --agent. The flag may be repeated; pairs accumulate. Meta agents (synthesis, triage, verification, validation, issue filing) always run on the global --agent. An unknown key or an invalid agent aborts startup with the offending token named. When overrides are active, the estimated cost in --dry-run and the confirmation prompt is broken down per agent and the active routing map is shown. Example: --agent opencode --agent-override security=claude,architecture=claude,information-architecture/empty-states=claude. | ||||
--parallel | Run lenses in parallel (one agent process per lens) | ||||||||||
--max-parallel <n> | Max concurrent agents in parallel mode. When unset the default is nproc-aware: clamp(detected CPU cores, 8, 32) (8 on small/CI hosts, up to 32 on many-core machines). An explicit value is always authoritative and is never re-clamped — you can deliberately run below 8 or above 32. A non-positive-integer value is rejected at startup. Higher concurrency trips provider rate limits faster; pin the detected count with REPOLENS_NPROC. | ||||||||||
--resume [<run-id>] | Resume a previous interrupted run. With an explicit run id, resume that run. With no id, auto-select and resume the most recent interrupted run under logs/ (the chosen run is logged) — completed/clean runs and retired (superseded) runs are never auto-picked, and RepoLens errors out (non-zero exit, no fresh run dir created) when no resumable run exists. | ||||||||||
--validate <file> | Post-audit validation: re-verify an existing findings artifact with the flagship --agent and drop its false positives, instead of running a scan. Ingests a findings.jsonl registry, a manifest.json array, or a single JSON finding object (typically produced by a cheaper "Radar" agent), sends each finding to the flagship "Filter" --agent with the repo on disk for context, keeps only the confirmed findings, and writes them to logs/<validate-run>/validated-findings.jsonl with explicit verified/dropped counts. Does not run the lens fan-out or DONE×3 streak; needs --agent and --project. A missing/unreadable/malformed input errors loudly with no dispatch, an empty artifact is a graceful no-op, and an agent failure exits non-zero (never a silent "all false positives"). See [Post-audit validation](#post-audit-validation). | ||||||||||
--spec <file> | Spec/PRD/roadmap to guide analysis (any text file, max 100 KB). Required for --mode greenfield; greenfield treats it as product-owner intent for backlog planning. | ||||||||||
--max-issues <n> | Stop after creating _n_ total issues. In polish mode, this caps emitted polishing shortlist issues rather than individual suggestions | ||||||||||
--min-severity <level> | Only file findings at or above critical, high, medium, or low. Filtered findings are counted in summary.json and reported in final stdout when the count is non-zero. No effect in non-severity modes such as discover, feature, custom, greenfield, and polish. Env fallback: REPOLENS_MIN_SEVERITY. | ||||||||||
--depth <n> | DONE streak depth per lens. Defaults to 3 for audit, feature, and bugfix; defaults to 1 for all other modes. Must be between 1 and 19 | ||||||||||
--rounds <n> | Validated cross-lens round count for multi-round orchestration. Defaults to 1 except bugreport, which defaults to 3. Only bugreport accepts values above 1; audit, feature, bugfix, custom, deploy, opensource, content, discover, greenfield, and polish are locked to 1. --rounds >= 4 requires --i-know-this-is-expensive. The resolved value is shown by --dry-run and sizes the logs/<run-id>/rounds/round-N/ artifact layout | ||||||||||
--strategy <name> | Bugreport round-1 dispatch strategy: fanout (default — every lens runs in round 1, identical to today's --mode bugreport) \ | waves (a narrow set of triage-seeded GENERIC investigators dispatch in round 1; subsequent rounds use the existing role-aware dispatch). waves requires --mode bugreport and rejects with a clear error on any other mode. The resolved value is shown by --dry-run under --mode bugreport. Env fallback: REPOLENS_STRATEGY. Wave width is controlled by REPOLENS_WAVE_WIDTH (default 7, clamped to 1..50). | |||||||||
--local | Write local output files instead of creating remote issues. Most modes write markdown; polish mode writes JSON suggestion objects and grouped polishing shortlist drafts. No forge CLI required | ||||||||||
--output <path> | Output directory for local output files (requires --local, default: logs/<run-id>/rounds/round-1/lens-outputs/) | ||||||||||
--forge <provider> | Override forge auto-detection: gh for GitHub, tea for Gitea, fj for Forgejo/Codeberg. Codeberg is auto-detected; use this for self-hosted Gitea/Forgejo remotes whose hostname is not auto-detected. Self-hosted Forgejo needs an HTTPS or SSH origin remote so RepoLens can pass fj -H <host> | ||||||||||
--hosted | Spin up Docker Compose for DAST scanning (used with toolgate domain) | ||||||||||
--remote <ssh-target> | Remote deploy server target. Accepts host, host:port, user@host, or user@host:port; only valid with --mode deploy server targets; incompatible with --hosted and Android deploy targets. The target is validated, exported to deploy agents, shown in --dry-run, and repeated in deploy authorization and normal run confirmation prompts. | ||||||||||
--remote-key <path> | SSH private key path for --remote. The path must exist and be a regular file. If omitted, remote SSH uses normal SSH key resolution. | ||||||||||
--remote-label <text> | Human-readable label for the remote target. When provided, confirmation prompts show the label and a separate Raw target: ... line with the exact SSH target. Multi-word labels can be quoted or passed as adjacent words before the next option. | ||||||||||
--deploy-target <target> | Deploy target resolver: --deploy-target auto\|server\|android, with auto as the default. Only valid with --mode deploy. auto opportunistically selects Android only for a direct APK, discovered APK, or shallow Android source marker (gradlew, build.gradle, build.gradle.kts, app/build.gradle, or app/build.gradle.kts); otherwise it preserves live-server deploy behavior. server skips Android detection and build handling. Only explicit --deploy-target android receives the no-source/no-APK Android exit when no APK or shallow marker exists. | ||||||||||
--build-android-apk | In Android deploy mode, allow the optional source build fallback to run ./gradlew assembleDebug when no APK is already resolved. The fallback is gated behind deploy authorization and the normal run confirmation, and is never executed during --dry-run. | ||||||||||
--max-cost <amount> | Warn if the **minimum cost estimate** exceeds this dollar amount (e.g., --max-cost 10). The estimate is a lower bound — real runs typically cost 2–5× more due to tool-call churn and iteration non-convergence. Budget accordingly. | ||||||||||
--cross-link <mode> | Synthesizer cross-link strategy: off \ | comment \ | suggest-reopen. Controls whether the synthesizer links related findings across lenses/domains in the synthesized output. Defaults to comment for bugreport, off for every other mode. Env fallback: REPOLENS_CROSS_LINK. | ||||||||
--human-review | Opt into a curated, noise-budgeted human-review digest at finalize time instead of dumping every finding (a full run can emit hundreds). This is the entry point only: the flag takes no argument, is accepted and validated, and the resolved value is shown by --dry-run as Human review: <bool>; the digest renderer itself lands in follow-up work, so today the flag changes no output. Env fallback: REPOLENS_HUMAN_REVIEW=1. | ||||||||||
--i-know-this-is-expensive | Cost-acknowledgement gate required for --rounds >= 4. Does not bypass the REPOLENS_MAX_ROUNDS hard ceiling (default 5). Equivalent to passing --max-cost <budget> together with --yes. | ||||||||||
--dry-run | Validate config and show which lenses would run, then exit (no agents executed) | ||||||||||
--yes, -y | Skip confirmation prompt (for CI/automation) | ||||||||||
--version | Show version and sponsor information, then exit | ||||||||||
--about | Show tool description and sponsor information, then exit | ||||||||||
-h, --help | Show help |
Agent timeouts are resolved per invocation with this precedence: REPOLENS_AGENT_TIMEOUT_<AGENT> > REPOLENS_AGENT_TIMEOUT > REPOLENS_AGENT_TIMEOUT_<MODE> > the mode default. REPOLENS_LENS_MAX_WALL caps the whole lens loop and each invocation is limited to the smaller of the resolved agent timeout and the remaining lens budget. Worst-case agent wall time per lens is bounded by min(resolved agent timeout * MAX_ITERATIONS_PER_LENS, REPOLENS_LENS_MAX_WALL) before rate-limit sleep and non-agent I/O; for a global override, that is min(REPOLENS_AGENT_TIMEOUT * MAX_ITERATIONS_PER_LENS, REPOLENS_LENS_MAX_WALL). With the 1800s default and MAX_ITERATIONS_PER_LENS=20, the raw cap is 30 min * 20 = 10 hours before the default 3600s wall budget applies. Use an agent-specific variable when one backend needs a different cap, or a mode-specific variable when only one workflow needs a different per-invocation cap:
```bash
gh auth login # GitHub tea login add # Gitea fj -H codeberg.org auth login # Codeberg; use your Forgejo host for self-hosted instances
Usage: repolens.sh --project <path|url> --agent <agent> [OPTIONS]
repolens.sh status [run-id] [OPTIONS]
repolens.sh clean [OPTIONS]
repolens.sh supersede <run-id>
./repolens.sh --project ~/my-app --agent claude --mode bugreport --bug-report ~/bug.txt
RepoLens 是一个开源项目,提供了一个命令行工具来帮助开发者发现和修复代码中的缺陷和问题。它支持多种模式和代理,包括发现缺陷、部署和 bug 报告等功能。
RepoLens 的主要功能包括发现缺陷、部署和 bug 报告等。它可以帮助开发者快速发现和修复代码中的问题,提高代码质量和开发效率。
RepoLens 的环境依赖包括 Linux 或 macOS 操作系统,Python 3.6 或更高版本,以及 Docker 和 pip 等工具。开发者需要安装这些依赖项才能使用 RepoLens。
RepoLens 可以通过多种方式安装,包括使用 pip 安装 Python 包、使用 Docker 部署容器化应用,以及从源码编译和安装。具体安装步骤请参考项目的 README 文件。
使用 RepoLens 的步骤包括配置代理、选择模式和参数、运行命令行工具等。具体使用教程请参考项目的 README 文件。
RepoLens 的配置包括环境变量、代理设置和模式参数等。开发者可以通过设置这些配置项来定制 RepoLens 的行为和功能。
RepoLens 的 API 暂未提供详细说明。
RepoLens 的工作流包括发现缺陷、部署和 bug 报告等多个阶段。开发者可以通过配置代理和模式参数来定制这些工作流的行为和功能。
高质量的代码审计工具,值得使用
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
✅ Apache 2.0 — 宽松开源协议,可商用,需保留版权声明和 NOTICE 文件,含专利授权条款。
总体来看,代码审计工具 是一款质量优秀的Agent工作流,在同类工具中具备一定竞争力。AI Skill Hub 将持续追踪其更新动态,建议收藏备用,结合自身场景选择合适时机引入使用。
| 原始名称 | RepoLens |
| 原始描述 | 开源AI工作流:Multi-lens code audit tool — 280 expert AI agents for code review, security test。⭐269 · Shell |
| Topics | 代码审计AI工作流安全测试 |
| GitHub | https://github.com/TheMorpheus407/RepoLens |
| License | Apache-2.0 |
| 语言 | Shell |
收录时间:2026-06-06 · 更新时间:2026-06-06 · License:Apache-2.0 · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端