One scan, one report: security, performance, duplicate-code, and dependency audits for Ruby and Rails — the ground Brakeman, bundler-audit, Reek, and custom glue scripts usually split between them, covered by a single `scryer` command. (Style/lint is RuboCop's job — Scryer doesn't touch that.) Detects SQL injection, mass assignment, hardcoded secrets, XSS, weak crypto, and more; N+1 queries, missing pagination, and other performance heuristics; near-duplicate code; and known-vulnerable gems via a live OSV.dev dependency audit — on by default, every run. Every finding includes a human-reviewable suggested fix — never auto-applied, optionally rewritten against your actual code by any LLM you configure. Reports in JSON, self-contained HTML, or CSV. Zero runtime dependencies beyond Ruby's own stdlib.
Required Ruby Version
>= 2.7.0
Authors
Ram Laxman Yadav
Versions
- 1.2.1 September 04, 2026 (175 KB)
- 1.2.0 August 16, 2026 (173 KB)
- 1.1.1 August 14, 2026 (136 KB)
- 1.0.0 August 12, 2026 (86.5 KB)
- 0.3.0 August 11, 2026 (66.5 KB)