Readyorai — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Readyorai (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Zero-cost MCP server for local code inspection. Analyzes your code for clean code practices, best practices, and gives actionable recommendations — without modifying your code or making API calls.
ready @filename and AI terminal commands for standalone use.readyorai.json for shared settings// readyorai-ignore commentsClaude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"readyorai": {
"command": "npx",
"args": ["-y", "readyorai"]
}
}
}Claude Code:
claude mcp add readyorai -- npx -y readyoraiVS Code (.vscode/mcp.json):
{
"servers": {
"readyorai": {
"command": "npx",
"args": ["-y", "readyorai"]
}
}
}npm install -g readyoraiready @src/index.ts # Inspect a single file
ready @src/ # Inspect a directory
ready @src/index.ts --checks security,naming # Run specific checks
ready @src/index.ts --json # JSON output
ready @src/index.ts --sarif # SARIF output (GitHub Code Scanning)
ready @src/index.ts --severity warning # Only warnings and errors
ready @src/index.ts --watch # Re-analyze on file changes
ready @src/ --baseline baseline.json # Compare against saved baseline
ready @src/ --save-baseline baseline.json # Save current results as baseline
AI # Inspect current directory
AI @src/utils.ts # Alias with file target| Code | Meaning |
|---|---|
0 | No issues found |
1 | Warnings found |
2 | Errors found |
3 | Runtime error |
Create a .readyorai.json in your project root:
{
"checks": ["complexity", "naming", "security"],
"severity": "warning",
"exclude": ["dist/**", "node_modules/**"]
}Silence specific findings on a line:
eval(code); // readyorai-ignore| Tool | Description |
|---|---|
inspect_file | Analyze a single file for code quality issues |
inspect_directory | Batch analysis of all source files in a directory |
get_metrics | Get quantitative metrics (LOC, complexity, function count) |
compare_files | Compare two file versions and show fixed, introduced, or unchanged findings |
suggest_fixes | Get actionable fix suggestions with context for each finding |
| Prompt | Description |
|---|---|
review-code | Structured code review with optional focus area |
health-check | Project-level health assessment |
| Check | What it detects |
|---|---|
complexity | Cyclomatic/cognitive complexity, deep nesting |
naming | Convention violations, single-letter vars, boolean prefixes |
structure | Long files/functions, too many parameters, long lines |
patterns | console.log, empty catch, magic numbers, nested ternaries, TODOs |
imports | Unused imports, wildcard imports, scattered imports |
documentation | Missing JSDoc/docstrings, low comment ratio |
security | Hardcoded secrets, eval(), SQL injection, XSS patterns |
duplication | Duplicate code blocks, repeated magic strings |
ai-detection | Detects patterns common in AI-generated code |
| Tier | Languages | Analysis |
|---|---|---|
| 1 | JavaScript, TypeScript, Python, Go, Rust | Full AST-powered analysis |
| 2 | Java, C#, Ruby, PHP, Swift, Kotlin, C, C++ | Regex + heuristic analysis |
| 3 | Any text file | Line-based checks (length, TODOs, secrets, duplication) |
git clone https://github.com/TedoNeObichaJavaScript/ReadyOrAI.git
cd ReadyOrAI
npm install
npm run build
npm testIf you find ReadyOrAI useful, consider supporting the project:
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.