Let agents check their own work
sc setup installs the agent skill and registers the sc-mcp server for your user, so coding agents can run Scorecard and read the verdict before they hand work back.
cargo install --path crates/sc-mcp
sc setup
Open source · MPL-2.0 · v0.1.3
Scorecard runs your project's build, tests, lint, coverage, dependency and secret checks, scores each gate, and returns pass or fail. No hosted service, no account.
git clone \
https://github.com/moonbase2090/Scorecard
cargo install --path Scorecard/crates/sc-cli
v0.1.3 · SHA256SUMS · all downloads
sc 0.1.3 output, unedited; icons and verdict color added.
How it works
Download the signed macOS disk image or a macOS or Linux tarball from the v0.1.3 release, or build the sc CLI from source with cargo.
sc analyze .Scorecard picks a pack from your project's manifests and runs its real tools. For Rust that's cargo check, cargo test, cargo llvm-cov and cargo clippy.
Each gate passes or fails, and the exit code is the verdict: 0 pass, 1 a gate failed, 2 the analyzer couldn't run. A terminal gets the scorecard shown above; a pipe gets JSON. --format and --out write JSON, Markdown, SARIF or HTML reports.
HTML report
--format html writes a self-contained report that makes no network requests. The flow strip across the top reads left to right, from what was analyzed to the verdict.
sc analyze . --format html --out scorecard.html
sc 0.1.3 HTML reports, cropped to the flow strip: testdata/good_crate (pass) and testdata/failing_test (fail). Open the full reports: good_crate · failing_test · HTML report docsWhat it checks
| Gate | Checks | Fails the run |
|---|
A pack maps each gate to the right tools for a language. --pack picks one when several manifests match. Rust enforces types, tests, crap, secrets and lint. The web pack enforces html. Other packs enforce fewer gates.
Five scores from 0 to 1, reported alongside the gates. Each error lowers its score by 0.25 and each warning by 0.05.
Works where you work
sc setup installs the agent skill and registers the sc-mcp server for your user, so coding agents can run Scorecard and read the verdict before they hand work back.
cargo install --path crates/sc-mcp
sc setup
Run the same analysis in GitHub Actions and fail the check when a gate fails. Writes sc-results.sarif by default.
- uses: moonbase2090/Scorecard/action@v0.1.3
A signed and notarized universal macOS .dmg, plus tarballs for macOS and Linux on x86_64 and aarch64.
Local-first
Analysis happens on your machine or your CI runner. The optional --llm on spec review, off by default, calls an OpenAI-compatible API: a local endpoint (127.0.0.1:11434) unless you set XAI_API_KEY, which sends it to api.x.ai.
This website has no trackers, analytics or cookies. It only remembers your light or dark theme choice, in your browser.
No sign-up and no hosted service. Install it and point it at a repo. An API key is only needed if you turn on --llm with xAI.
Written in Rust and licensed under MPL-2.0. Read the source.
Install
Current version: 0.1.3. Downloads are on GitHub Releases; check them against SHA256SUMS.
Universal (Apple silicon and Intel), signed with Developer ID and notarized. It holds the sc and sc-mcp command-line tools: open it and copy them to a folder on your PATH, such as /usr/local/bin. Requires macOS 11 or later on Apple silicon, or macOS 10.12 or later on Intel.
curl -fsSLO \
https://github.com/moonbase2090/Scorecard/releases/download/v0.1.3/sc-v0.1.3-$(uname -m | sed s/arm64/aarch64/)-apple-darwin.tar.gz
tar -xzf sc-v0.1.3-*-apple-darwin.tar.gz sc sc-mcp
sudo install -d /usr/local/bin && sudo install -m 755 sc sc-mcp /usr/local/bin/curl -fsSLO \
https://github.com/moonbase2090/Scorecard/releases/download/v0.1.3/sc-v0.1.3-$(uname -m)-unknown-linux-gnu.tar.gz
tar -xzf sc-v0.1.3-$(uname -m)-unknown-linux-gnu.tar.gz sc sc-mcp
sudo install -m 755 sc sc-mcp /usr/local/bin/Supported targets: x86_64 and aarch64 (glibc, *-unknown-linux-gnu). The command picks yours with uname -m.
git clone https://github.com/moonbase2090/Scorecard
cd Scorecard
cargo install --path crates/sc-cli
cargo install --path crates/sc-mcpRequires Rust 1.85 or newer. sc-mcp is only needed for agents.
rustup component add llvm-tools
cargo install cargo-llvm-covsc analyze .Independent systems / The maker
Moonbase2090 builds Scorecard. The source is available under the Mozilla Public License 2.0 (MPL-2.0).