DEV Community

Cover image for I kept finding the same mess in every vibe-coded repo, so I built a CLI to catch it before I do
Nikita Minakov
Nikita Minakov

Posted on

I kept finding the same mess in every vibe-coded repo, so I built a CLI to catch it before I do

I freelance. Half my work lately is taking over projects built with AI tools like Cursor, Claude, Codex. Clients ship fast, then hit a wall and need a real developer.

Every single time I open one of these repos, the first two hours look the same:

  • scroll through git history trying to understand what happened
  • grep for hardcoded API keys and secrets
  • figure out what stack is actually being used vs what the package.json claims
  • find the TODOs nobody tracked
  • check if there are tests (usually no)

I did this manually maybe 15 times before I got annoyed enough to automate it.

What it does

rebrief scans a repo and spits out a single REBRIEF.md file with:

  • stack detection
  • filtered git history (the signal, not every commit)
  • a risk map
  • secrets detection
  • tech debt and TODO list
  • test coverage summary
pip install rebrief
rebrief scan .
Enter fullscreen mode Exit fullscreen mode

You get one document instead of two hours of archaeology.

Why not just ask the AI tool that built it

Because by the time a human dev gets involved, the context is gone. The founder who vibe-coded it doesn't know what questions to ask. The dev taking over doesn't trust a summary written by the same tool that may have introduced the mess. rebrief reads the actual code, not a chat log.

It also works in a few other modes if that's useful to you:

  • MCP server mode, so an AI agent can query the report directly
  • scan a remote repo by URL, no clone needed
  • chat mode over the generated report
  • interactive HTML output, or XML if you need it machine-readable

State of the project

It's open source, live on PyPI and GitHub, past v0.3.2. Built it because I needed it myself, not because I had a grand plan. Still rough in places. I'm looking for people who actually run it on a real repo and tell me where it breaks.

GitHub: https://github.com/neracu/rebrief
Install: pip install rebrief

If you've ever inherited a vibe-coded project, or built one and need to hand it off, I'd genuinely like to know if this saves you the two hours it used to cost me.

Top comments (2)

Collapse
 
launchgatecheck profile image
Launch Gate •

Does secrets detection keep the matched value out of REBRIEF.md and the HTML/XML outputs? A handoff report is exactly the file someone might paste into a ticket or an AI chat, so copying a credential into the summary would move the leak rather than contain it.

I'd add a fixture with a deliberately fake credential in a source file and another in an old commit: the report should retain the file/commit reference and finding type without reproducing either value. That would also make the scope clear if current files are scanned but git history is only summarized. I haven't run rebrief; this is a suggested export-boundary test from the features listed here.

Collapse
 
neracu1 profile image
Nikita Minakov •

Right now the detector reports the file and the line number where it found something hardcoded. I need to double check whether the full line content (including the secret value) gets written into REBRIEF.md as is, or just the location. Honestly not 100% sure off the top of my head, so I don't want to give you a wrong answer here.

Your fixture idea is the right way to settle this anyway: fake credential in a source file, another in an old commit, then check every output format for whether the raw value survives. I'll run that and either confirm it's already safe or fix it if it's not. Will follow up here once I know.