Back to Project Hub

RepoPilot

ReactTypeScriptViteExpress.jsNode.jsTailwind CSS

The Problem

Developers and support teams often struggle to quickly understand unfamiliar repositories, identify security risks, and generate useful onboarding documentation for new team members.

The Solution

RepoPilot is an advanced AI-assisted repo scanner that intelligently analyzes GitHub repositories or ZIP uploads to produce comprehensive structured insights, vulnerability reports, bug findings, and developer onboarding summaries, heavily influenced by secure code review thinking and support-friendly reporting.

Key Features

Automated README and onboarding documentation generation
Security scanning via npm audit, semgrep, and gitleaks
Code quality analysis via eslint, ruff, and custom pattern detection
Multi-language support for Node.js and Python projects
License compliance checking, dependency inventory, and test coverage evaluation
ZIP upload support for local, proprietary codebases alongside GitHub repo scanning

Architecture

RepoPilot is built as a React 18 + TypeScript + Vite frontend talking to a Node.js/Express + TypeScript backend, with a modular middleware/agents layer that orchestrates the actual analysis (security scanning, code quality checks, doc generation) with per-agent timeout handling. It clones or unpacks the target repository, runs it through eslint/ruff/semgrep/gitleaks/npm audit, and produces a structured Markdown report. Originally built for the IBM Bob Hackathon, it's deployable via Docker Compose or exposed publicly through Tailscale Funnel.

Security Considerations

Uses temporary, short-lived tokens for GitHub access. ZIP uploads are scanned and immediately discarded after processing to ensure proprietary code is never retained on the server.

Challenges Faced & Solutions Delivered

Challenges Faced

  • •Supporting both GitHub repository input and ZIP upload input.
  • •Handling private repository restrictions properly without exposing confusing backend errors.
  • •Making sure users receive a clear message when a repository is private or inaccessible.
  • •Improving drag-and-drop upload behavior.
  • •Preventing sensitive files such as .env files from being exposed.
  • •Thinking through security risks because one weak component can become the weak link in an application.
  • •Making AI-generated documentation useful, structured, and readable.
  • •Detecting possible vulnerabilities while keeping the results actionable.
  • •Handling backend errors gracefully with user-friendly messages.
  • •Testing flows such as public repo scan, private repo handling, ZIP upload, drag-and-drop, report generation, and documentation output.
  • •Deploying the application securely on a self-hosted server with Tailscale Funnel and HTTPS.
  • •Balancing AI functionality with security, reliability, and user trust.

Solutions Delivered

  • ✓Built an AI-assisted repository analysis tool that helps users understand projects faster.
  • ✓Added support for both GitHub repository links and ZIP uploads.
  • ✓Improved error handling for private or inaccessible repositories.
  • ✓Added security-focused handling to avoid exposing sensitive files like .env files.
  • ✓Generated structured documentation and developer-friendly reports.
  • ✓Combined AI, cybersecurity awareness, testing, and secure deployment into one practical project.
  • ✓Hosted the application through a self-hosted setup using HTTPS and Tailscale Funnel.
  • ✓Treated security as a core feature, not an afterthought, reflecting a true application support mindset.

"RepoPilot combines AI, cybersecurity, documentation automation, testing, and secure deployment into one practical tool, emphasizing secure code review thinking and support-friendly reporting."

Want to know more about the developer?