I freelance. Half my work lately is taking over projects built with AI tools like Cursor, Claude, Codex. Clients ship fast, then hit a wall and need a real developer.
Every single time I open one of these repos, the first two hours look the same:
- scroll through git history trying to understand what happened
- grep for hardcoded API keys and secrets
- figure out what stack is actually being used vs what the package.json claims
- find the TODOs nobody tracked
- check if there are tests (usually no)
I did this manually maybe 15 times before I got annoyed enough to automate it.
What it does
rebrief scans a repo and spits out a single REBRIEF.md file with:
- stack detection
- filtered git history (the signal, not every commit)
- a risk map
- secrets detection
- tech debt and TODO list
- test coverage summary
pip install rebrief
rebrief scan .
You get one document instead of two hours of archaeology.
Why not just ask the AI tool that built it
Because by the time a human dev gets involved, the context is gone. The founder who vibe-coded it doesn't know what questions to ask. The dev taking over doesn't trust a summary written by the same tool that may have introduced the mess. rebrief reads the actual code, not a chat log.
It also works in a few other modes if that's useful to you:
- MCP server mode, so an AI agent can query the report directly
- scan a remote repo by URL, no clone needed
- chat mode over the generated report
- interactive HTML output, or XML if you need it machine-readable
State of the project
It's open source, live on PyPI and GitHub, past v0.3.2. Built it because I needed it myself, not because I had a grand plan. Still rough in places. I'm looking for people who actually run it on a real repo and tell me where it breaks.
GitHub: https://github.com/neracu/rebrief
Install: pip install rebrief
If you've ever inherited a vibe-coded project, or built one and need to hand it off, I'd genuinely like to know if this saves you the two hours it used to cost me.
Top comments (2)
Does secrets detection keep the matched value out of REBRIEF.md and the HTML/XML outputs? A handoff report is exactly the file someone might paste into a ticket or an AI chat, so copying a credential into the summary would move the leak rather than contain it.
I'd add a fixture with a deliberately fake credential in a source file and another in an old commit: the report should retain the file/commit reference and finding type without reproducing either value. That would also make the scope clear if current files are scanned but git history is only summarized. I haven't run rebrief; this is a suggested export-boundary test from the features listed here.
Right now the detector reports the file and the line number where it found something hardcoded. I need to double check whether the full line content (including the secret value) gets written into
REBRIEF.mdas is, or just the location. Honestly not 100% sure off the top of my head, so I don't want to give you a wrong answer here.Your fixture idea is the right way to settle this anyway: fake credential in a source file, another in an old commit, then check every output format for whether the raw value survives. I'll run that and either confirm it's already safe or fix it if it's not. Will follow up here once I know.