Open source · MPL-2.0 · v0.1.3

One verdict for your code, from the tools you already run.

Scorecard runs your project's build, tests, lint, coverage, dependency and secret checks, scores each gate, and returns pass or fail. No hosted service, no account.

git clone \ https://github.com/moonbase2090/Scorecard cargo install --path Scorecard/crates/sc-cli

v0.1.3 · SHA256SUMS · all downloads

Real sc 0.1.3 output, unedited; icons and verdict color added.

How it works

Three steps, one answer.

  1. 01

    Install

    Download the signed macOS disk image or a macOS or Linux tarball from the v0.1.3 release, or build the sc CLI from source with cargo.

  2. 02

    Run sc analyze .

    Scorecard picks a pack from your project's manifests and runs its real tools. For Rust that's cargo check, cargo test, cargo llvm-cov and cargo clippy.

  3. 03

    Get a verdict

    Each gate passes or fails, and the exit code is the verdict: 0 pass, 1 a gate failed, 2 the analyzer couldn't run. A terminal gets the scorecard shown above; a pipe gets JSON. --format and --out write JSON, Markdown, SARIF or HTML reports.

HTML report

See the whole run at a glance.

--format html writes a self-contained report that makes no network requests. The flow strip across the top reads left to right, from what was analyzed to the verdict.

sc analyze . --format html --out scorecard.html
Flow strip from the HTML report of testdata/good_crate: scope tree, 1 skipped; pack rust; engines 9 run, 3 skipped; gates 6/6 pass; verdict pass. Flow strip from the HTML report of testdata/failing_test: scope tree, 1 skipped; pack rust; engines 8 run, 4 skipped; gates 5/6 pass; verdict fail.
Unedited screenshots of real sc 0.1.3 HTML reports, cropped to the flow strip: testdata/good_crate (pass) and testdata/failing_test (fail). Open the full reports: good_crate · failing_test · HTML report docs

What it checks

Quality gates, using your project's own build, test and lint tools.

Quality gates
GateChecksFails the run

Language packs

A pack maps each gate to the right tools for a language. --pack picks one when several manifests match. Rust enforces types, tests, crap, secrets and lint. The web pack enforces html. Other packs enforce fewer gates.

Scores

Five scores from 0 to 1, reported alongside the gates. Each error lowers its score by 0.25 and each warning by 0.05.

Reading a result

  • passCircle with a check: the gate passed
  • failSquare with a cross: the gate failed

Works where you work

The same gates for your agent, your CI and your terminal.

Agents · MCP

Let agents check their own work

sc setup installs the agent skill and registers the sc-mcp server for your user, so coding agents can run Scorecard and read the verdict before they hand work back.

cargo install --path crates/sc-mcp
sc setup
CI · GitHub Action

Gate pull requests

Run the same analysis in GitHub Actions and fail the check when a gate fails. Writes sc-results.sarif by default.

- uses: moonbase2090/Scorecard/action@v0.1.3
macOS · Linux

Run it on your machine

A signed and notarized universal macOS .dmg, plus tarballs for macOS and Linux on x86_64 and aarch64.

Install options →

Local-first

Runs on your machine, with no account needed.

Runs locally

Analysis happens on your machine or your CI runner. The optional --llm on spec review, off by default, calls an OpenAI-compatible API: a local endpoint (127.0.0.1:11434) unless you set XAI_API_KEY, which sends it to api.x.ai.

No trackers here

This website has no trackers, analytics or cookies. It only remembers your light or dark theme choice, in your browser.

No account

No sign-up and no hosted service. Install it and point it at a repo. An API key is only needed if you turn on --llm with xAI.

Open source

Written in Rust and licensed under MPL-2.0. Read the source.

Install

Install Scorecard

Current version: 0.1.3. Downloads are on GitHub Releases; check them against SHA256SUMS.

Signed disk image (.dmg)

Universal (Apple silicon and Intel), signed with Developer ID and notarized. It holds the sc and sc-mcp command-line tools: open it and copy them to a folder on your PATH, such as /usr/local/bin. Requires macOS 11 or later on Apple silicon, or macOS 10.12 or later on Intel.

Tarball

curl -fsSLO \ https://github.com/moonbase2090/Scorecard/releases/download/v0.1.3/sc-v0.1.3-$(uname -m | sed s/arm64/aarch64/)-apple-darwin.tar.gz tar -xzf sc-v0.1.3-*-apple-darwin.tar.gz sc sc-mcp sudo install -d /usr/local/bin && sudo install -m 755 sc sc-mcp /usr/local/bin/

Then, in any repo

sc analyze .

Independent systems / The maker

Moonbase2090

Moonbase2090 builds Scorecard. The source is available under the Mozilla Public License 2.0 (MPL-2.0).

Visit Moonbase 2090 (opens in a new tab)