by Aletheore
Provides a deterministic repository scanner that produces structured evidence for code intelligence, enabling static analysis, secret detection, dependency‑vulnerability checks, API endpoint mapping, and integration with MCP servers, dashboards, and GitHub Actions.
Aletheore delivers a local‑first, deterministic scanner that analyses a codebase and writes machine‑readable evidence (JSON). Every downstream feature – AI‑driven audits, PR reviews, MCP server queries, dashboards – must cite this evidence, guaranteeing that claims are grounded in actual file:line data.
# Install the CLI (recommended with pipx)
pipx install aletheore
# Run a full repository scan
aletheore scan .
# Query the generated evidence
aletheore query "Which packages have known vulnerabilities?"
# Compare two scans without re‑scanning
aletheore diff <scan1> <scan2>
# Start the MCP server (exposes 34+ tools for agents)
aletheore mcp
# Launch the local web dashboard
aletheore dashboard
The GitHub Action can be added to a workflow to automatically scan PRs and post diff‑based comments.
audit can attach LLM‑generated reports to concrete evidence fields.aletheore scan + aletheore diff on every commit to catch secrets or vulnerable dependencies before merge.Q: Do I need an internet connection? A: Only for optional OSV vulnerability and license lookups; you can disable them for a fully offline run.
Q: Which package manager should I use?
A: Install via pipx, which creates an isolated environment and adds the aletheore command to your PATH.
Q: Can I run the scanner in CI without an LLM?
A: Yes. CI pipelines typically execute aletheore scan followed by aletheore diff; no LLM calls are made.
Q: How does the hosted GitHub App differ from the CLI? A: The CLI is free and runs locally. The App adds paid SaaS features like automated PR reviews, AIRview architecture maps, AI‑generated docs, and production monitoring.
Q: What license governs the code? A: Aletheore is released under the PolyForm Non‑commercial License 1.0.0 – free for personal/research use; commercial usage requires a separate license.
Q: How many tools does the MCP server expose?
A: By default 34 tools (35 when ALETHEORE_MCP_ALLOW=external is enabled), covering symbol lookup, dependency graphs, ownership, clustering, dead‑code detection, hotspot analysis, full‑text and semantic search, and more.
$ pipx install aletheore
$ aletheore scan .
Scanning /path/to/your/repo...
→ Detecting languages, frameworks, and build tools
→ Building module dependency graph (parsing source with tree-sitter)
→ Analyzing git history and ownership
→ Scanning working tree for secrets
→ Checking dependencies for known vulnerabilities (OSV.dev)
→ Mapping API endpoints
→ Done
✓ Scan complete
Evidence written to /path/to/your/repo/.aletheore/air.json
No LLM call, no account, no network access beyond the vulnerability/license registry lookups (turn those off too for a fully offline run). That one command gets you a real dependency graph, secrets scan, git-history secret sweep, dependency-vulnerability/license check, and static API endpoint map — for Python, JavaScript/JSX, TypeScript/TSX, Go, Rust, Java, Kotlin, Ruby, PHP, C, C++, C#, and Swift.
audit report, PR review comments, the
architecture wiki) is checked against the file:line it cites. A finding that can't be
verified against real evidence gets dropped or flagged, not shipped silently.scan, query, diff, the MCP server, and the local
dashboard need no account and no API key. Nothing leaves your machine.audit works with six provider families
(Claude, OpenAI, Google, Mistral, xAI, or a local Ollama model) — your key, your cost, your
choice — or skip the LLM step entirely and just use the deterministic evidence.aletheore scan — the deterministic scanner above. Safe to run in CI, on every commit.aletheore audit — scans, then has a coding-agent CLI or API provider write a full
grounded markdown report, citing exact evidence fields throughout. Meant to be run by hand
against your own repo — see src/README.md for why it isn't wired into CI.aletheore query / aletheore diff — answer a targeted question or compare two
scans from existing evidence, no re-scan or LLM call needed.aletheore mcp — a stdio MCP server exposing 34 tools by default (35 with
ALETHEORE_MCP_ALLOW=external enabled) (module/symbol/dependency lookups,
ownership, clusters, dead code, hotspots, full-text and semantic search, scan and index
triggers) so a coding agent can query your repo's structure directly instead of shelling out
or re-reading files on every lookup; it re-scans in the background as files change unless started
with --no-watch. aletheore mcp-install wires it into Claude Code,
Cursor, VS Code, Kiro, Opencode, or Codex CLI automatically.aletheore dashboard — a live local web UI: dependency graph, an Obsidian-style cluster
graph, trend charts across scan history, and the MCP tool list.action.yml, on the Marketplace as "Aletheore") — scans a PR's base and
head refs and posts a diff: new/resolved secrets, dependency vulnerabilities, and
layer-convention violations, as a PR comment, inline annotations, and the run's Step Summary.
CI only ever runs scan + diff — fast and deterministic, never the full agent-driven
audit.- uses: Aletheore/Aletheore@v0.7.2
with:
fail-on-new-secrets: true
Full command reference, MCP tool list, per-language import-resolution details, and
configuration options: src/README.md.
Everything above is the free, local-first CLI (Aletheore Community). Installing the Aletheore GitHub App adds a hosted layer on top of the same evidence — paid plans start at 6.99/mo each):
scan produces.The GitHub App and dashboard code lives in github-app/; see its own
README for deployment and operations details.
src/ — the actual, working CLI code (see its README for everything above in detail).github-app/ — the hosted GitHub App: FastAPI server, RQ workers, migrations. See
Aletheore AIR above for what it does.site/ — the marketing site (Next.js).docs/superpowers/ — design specs and implementation plans written during development.docs/operations/ — current operational baselines: incident response, data handling, SLOs,
deployment verification, branch protection, support process.SECURITY.md — vulnerability reporting and response targets.Related, separate repo: aletheore-benchmarks — the public PR-review benchmark harness and published results.
Aletheore is licensed under the PolyForm Noncommercial License 1.0.0, not an OSI-approved open-source license. It's free for individuals: personal use, research, hobby projects, and evaluation. Any use for or within a company or other organization — including internal tooling at a company you work for — is a commercial use and requires a separate commercial license. Reach out at arihantkaul@outlook.com for commercial licensing, or see Aletheore AIR for the hosted, paid tier.
If it's useful to you personally, consider sponsoring development — no accounts, no tracking, nothing leaves your machine when you run it.
Please log in to share your review and rating for this MCP.
Explore related MCPs that share similar capabilities and solve comparable challenges
by chaitin
A self‑hosted web application firewall and reverse proxy that protects web applications from attacks and exploits by filtering, monitoring, and blocking malicious HTTP/S traffic.
by snyk
Scans installed AI agent components, MCP servers, and skill files for prompt‑injection, tool poisoning, toxic flows, hard‑coded secrets and other supply‑chain risks.
by OpenOSINT
Provides an AI‑driven OSINT workflow that lets users query a natural‑language REPL, CLI, web UI, or MCP server, automatically selecting and chaining 18 reconnaissance tools to collect, pivot, verify, and report public‑source intelligence.
by 2akouwu
Provides deterministic verification of AI‑generated claims against binary artifacts, ensuring every structural or behavioral assertion is grounded in the actual file and preserving verified state across context resets.
by safedep
Provides enterprise‑grade open source software supply chain security by scanning source code, dependencies, containers and SBOMs, detecting vulnerabilities and malicious packages, and enforcing policy as code.
by tufantunc
Provides controlled SSH access for LLM agents with command classification, policy‑based authorization, human‑in‑the‑loop approval, and immutable audit logging.
by semgrep
Offers an MCP server that lets LLMs, agents, and IDEs run Semgrep scans to detect security vulnerabilities in source code.
by KeyValueSoftwareSystems
Enables adversary emulation for AI agents, LLM applications, and MCP servers, letting teams test their AI systems against realistic attack scenarios.
by PortSwigger
Enables Burp Suite to communicate with AI clients via the Model Context Protocol, providing an MCP server and bundled stdio proxy.