Detect. Fix. Ship. The local-first code quality CLI that finds AI-generated security and quality issues, then auto-resolves the ones it can safely prove.
Multi-pass scan — style, security, performance, architecture. Catches issues before prod.
Not just detection — Ratchet applies fixes. One command resolves dozens of issues.
Measure cyclomatic complexity, coupling depth, cohesion. Track architectural drift.
Contextual suggestions powered by LLMs. Understands your architecture, not just syntax.
Embeddable score badges for your README. Show your team ships clean code.
Quality thresholds on every PR. Block merges that drop scores. Auto-approve when clean.
npm install -g ratchet-run then ratchet init. Zero config.
ratchet scan analyzes your codebase in seconds. Severity-ranked issues.
ratchet improve auto-resolves. You handle the rest. Ship confident.
Fully open source core. Fork it, extend it, ship it.
Built in public as a focused developer tool, not a borrowed wrapper pitch.
Runs 100% locally. No phone-home, no analytics, no tracking.
Normal scans run locally. AI-powered deep scans are opt-in and send scoped snippets only to the model provider you configure.
Run it on your own infrastructure. Full control, full audit trail.
Bring your own API key for deep analysis and fixes. No Ratchet server sees your repository.
Ratchet: 91/100 (+14) ✓ security: no criticals ✓ fixed 7 safe issues → 3 suggestions left
ratchet score: 91/100
Security clean · complexity trending down · no telemetry.
72 → 84 → 91
Security scanner for AI-generated code. Local by default, BYOK when you want AI help.