0
/ 100
Polished and well engineered. Punching above its star count.
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Top fixes
Highest-impact changes first, ranked by point weight
- 1Issue and PR templates6pt
Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
- 2Dependency manifest6pt
Add a [project.urls] table (Homepage, Repository) so PyPI links back to your project.
- 3Dependency manifest6pt
Add `authors = [...]` under [project] so the package has clear ownership.
- 4Dependency manifest6pt
Add a [build-system] table (e.g. setuptools or hatchling) so the package can be built and published.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
96
CONTRIBUTING guide found.
README is present.
README documents how to install the project.
Licensed under MIT.
Engineering
88
No issue or PR templates found (−100 pts).
→ Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
Test files detected (pytest.ini).
CI is configured (.github/workflows/main.yml).
Linter or formatter configured ([tool.ruff] / [tool.black] in pyproject.toml).
Lockfile present (requirements.txt). Installs are reproducible.
Project health
93
Dependency manifest found (pyproject.toml).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- -Commits (30d / 90d)
- 18Forks
- 43Releaseslatest 8mo ago
Community
- -Community health
- -authors own >50% of commits
- 163Watchers
Responsiveness
- -Median issue response
- <1hMedian PR merge time
- 0Open issues
Repository files35 root entries
- .githubGood: CI is configured (.github/workflows/main.yml).Good: Dependabot covers 3 ecosystems (pip, docker, github-actions). Dependencies stay current.
- artifacts
- docsGood: CONTRIBUTING guide found.Issue: CONTRIBUTING guide contents could not be read (−28 pts vs a readable file).Fix: Move the file to the repo root or docs/CONTRIBUTING.md so its setup, style, test, and PR sections can be graded.
- reports
- resources
- reversecore_mcp
- rules
- scratch
- scripts
- templates
- tests
- .coveragerc
- .dockerignore
- .env.example
- .gitignoreGood: .gitignore present.
- .pre-commit-config.yaml
- .trivyignore
- AGENTS.md
- docker-compose.yml
- DockerfileGood: Environment pinned via Dockerfile.
- Dockerfile.base
- icon.png
- LICENSEGood: Licensed under MIT.
- mkdocs.yml
- pyproject.tomlGood: Dependency manifest found (pyproject.toml).
- pytest.iniGood: Test files detected (pytest.ini).
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- requirements-dev.txt
- requirements.txtGood: Lockfile present (requirements.txt). Installs are reproducible.
- res.txt
- SECURITY.mdGood: Security policy present.
- server.py
- test_res_cov.txt
- test_res.txt
- TOOL_TESTING_SUMMARY.md
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/sjkim1127/reversecore_mcp)