arch-auditor
Evidence-backed repository architecture analysis. Deterministic static analysis first (AST-level facts, import graphs, cycle detection, coupling, blast radius), with Gemini as an optional explain-and-plan assistant. Ships a Streamlit web app and a CLI from the same engine.
- Python 3.10+
- Detectors: circular dependencies, high coupling, large modules, layer violations; plus a blast-radius impact report per module.
- Ruleset-driven layer validation (
config/architecture.yaml). - Architecture model, findings, severity, impact:
arch_auditor/models/. - Detector engine:
arch_auditor/analyzer/. - Gemini integration (overview, per-finding insights, refactoring plans):
arch_auditor/ai/. - Streamlit single-page app:
app.py(7 sections per the UI spec).
Install
pip install -e .
or, once published, pip install arch-auditor.
CLI
# Analyze a repository
arch-auditor analyze path/to/repo
# Analyze the bundled demo repository
arch-auditor demo
# Ask Gemini for a refactoring plan for one finding (needs GEMINI_API_KEY)
arch-auditor plan CIRCULAR_DEPENDENCY_1 path/to/repo
# Version
arch-auditor --version
The CLI returns exit code 1 when findings exist, 0 when the repository is clean, and 2 for usage errors. The Gemini key is read from the environment only and is never logged.
Web app
streamlit run app.py
Open the generated localhost URL. Enter a repository path (default: the
bundled demo_repo) and press ANALYZE.
For Streamlit Community Cloud: connect the repo and set the main script path
to arch-auditor/app.py. Dependencies come from arch-auditor/requirements.txt.
Reference architecture ruleset
Layer validation is opt-in: drop config/architecture.yaml (see
arch_auditor/config/architecture.yaml) into the repository being analyzed.
Without a ruleset, layer validation is skipped and the remaining detectors run
on structure alone.
Gemini key
Optional. Set GEMINI_API_KEY in the environment (CLI) or paste a key into
the app's sidebar (session only).
Demo repository
demo_repo/ is an intentionally problematic repository that exercises every
detector:
- cycle
orders -> payments -> users -> orders payment_service.py: > 30 functions (LARGE_MODULE), fan-in 5 + fan-out 1 (HIGH_COUPLING, HIGH impact)database.py -> api.pyinverts the layer rules (LAYER_VIOLATION)
Development
pip install -e ".[dev]"
ruff check .
pytest -q
python -m build
CI (.github/workflows/ci.yml) runs ruff, pytest, pip-audit (dependency
CVE scan), and builds + verifies the distribution on every push and PR.
CodeQL and weekly Dependabot updates keep the supply chain current.
License
GPL-3.0-only. See LICENSE in the repository root and
arch-auditor/LICENSE (shipped inside the wheel).
Metadata
Release files for arch-auditor 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| arch_auditor-0.1.0.tar.gz | 34.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| arch_auditor-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 70.0 kB
Release files / arch_auditor-0.1.0.tar.gz
| Download URL | arch_auditor-0.1.0.tar.gz |
|---|---|
| Size | 34.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b3b6d5565f17f758e26601c342a714ca7bca525894f0d73da05cb3114d78343d
|
|
BLAKE2b-256 checksum How to use checksums |
2a2574f296943b0587678cee812ca18af65ae79c283347ea0a69651a9c8a3dab
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency logRelease files / arch_auditor-0.1.0-py3-none-any.whl
| Download URL | arch_auditor-0.1.0-py3-none-any.whl |
|---|---|
| Size | 35.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
045fc1b5406459a4256b0d73211fc0cb78a50793034bb48358831d62360d317d
|
|
BLAKE2b-256 checksum How to use checksums |
170e9d8c7a2eee53c2849911713cfa60bb94d18c076a8299ff5065a0cf3df856
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency log