AI shipped your codebase. We tell you what's actually inside — before your acquirer, investor, or new hire finds out. We ran LuxScope against express-pin — score 85/100, 7 findings across 51 risk files, plus 10 deterministic handoff docs. View the report →
LuxScope — codebase intelligence scanner. Recon run against express-pin.
terminalluxscope v0.1
LuxScope Score: 85 / 100 rule v0.1.0
Security 69 / 100
Complexity 67 / 100
Documentation 99 / 100
Dependencies 100 / 100
Dead Code 100 / 100
Score is the headline. Report ships findings, fix order, ETAs.View sample report →
LuxFaber — agent-readiness scanner. Run against stelnyx.com.
terminalluxfaber v0.1
Agent-readiness: 91 / 100 rule v0.1.0
Crawl Access 88 / 100
Structured Data 95 / 100
Semantic HTML 90 / 100
Content Clarity 85 / 100
Determinism 97 / 100
Score is the headline. Report ships findings, fix order, ETAs.View sample report →
Everything we build, shipped publicly.
Infrastructure tools built for engineers. MIT where open, proprietary where not.
Intelligence. Delivered as a session.
Deterministic scanners for code, agent-readiness, and the media accessibility debt generic audits miss — each shipped as a scored, versioned report.
Codebase IntelProprietary
LuxScope
Know what breaks before you change it.
Know which files will break before you touch them. Identify the tech debt due-diligence will surface — before the investor does. Give a new hire a working mental model in one report instead of two weeks of context-gathering. Audit AI-generated code you didn't write and can't fully vouch for. LuxScope reads your codebase deterministically — no LLMs, no cloud, runs on your machine.
Your public web surface is being crawled by AI agents — ChatGPT, Operator, Claude, Perplexity, Gemini — whether you designed for it or not. LuxFaber scores your site on agent-readiness: crawl access, structured data, semantic HTML, content clarity, and deterministic output. Same input, same score every time — no LLMs in the scoring path.
Media & document accessibility scanning (ADA Title II / EAA).
Deterministic WCAG 2.1 scoring for the assets HTML scanners skip. Crawls video, audio, PDFs, Office documents, and image alt text — quantifies content accessibility debt in billable units, plus an unscored static-HTML code baseline. Same input, same score, every run.
Two MIT-licensed CLIs we maintain alongside LuxScope. One command, no account, same scoring discipline — built for engineers who already own the codebase, not for buyers commissioning a review.
SecurityMIT · free · zero config
SecGate
One command. One report. One exit code.
$ npx @stelnyx/secgate
Runs Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit in one command. Normalizes findings into one report and fails the pipeline on CRITICAL or HIGH. Aggregation is deterministic — same inputs produce a JSON-byte-identical report every run, locked by determinism + golden snapshot tests.
Inventories every HTTP endpoint across Express, Fastify, NestJS, and OpenAPI specs. Classifies auth posture, diffs code vs spec, fails the pipeline on open writes. 100% static — no HTTP, no credentials, no running server. Same inputs → byte-identical report.