One scan, one report: security, performance, duplicate-code, and dependency audits for Ruby and Rails — the ground Brakeman, bundler-audit, Reek, and custom glue scripts usually split between them, covered by a single `scryer` command. (Style/lint is RuboCop's job — Scryer doesn't touch that.) Detects SQL injection, mass assignment, hardcoded secrets, XSS, weak crypto, and more; N+1 queries, missing pagination, and other performance heuristics; near-duplicate code; and known-vulnerable gems via a live OSV.dev dependency audit — on by default, every run. Every finding includes a human-reviewable suggested fix — never auto-applied, optionally rewritten against your actual code by any LLM you configure. Reports in JSON, self-contained HTML, or CSV. Zero runtime dependencies beyond Ruby's own stdlib.
Required Ruby Version
>= 2.7.0
Authors
Ram Laxman Yadav