axm-audit
Code auditing and quality rules for Python, Node.js/TypeScript, React and Svelte projects.
What it does
axm-audit is a Python library exposed through the unified axm CLI that audits project quality across 9 scored categories, producing a composite 0–100 score:
| Category | Tool | Weight |
|---|---|---|
| Linting | Ruff | 15% |
| Type Safety | mypy | 15% |
| Complexity | radon + complexipy | 15% |
| Security | Bandit | 10% |
| Dependencies | pip-audit + deptry | 10% |
| Testing | pytest-cov | 10% |
| Test Quality | AST analysis | 10% |
| Architecture | AST analysis | 10% |
| Practices | AST analysis | 5% |
Two further categories — Structure (pyproject.toml completeness, test-pyramid layout) and Tooling (CLI tool availability) — emit findings but are not scored.
Quick Example
Python
# Python API
from pathlib import Path
from axm_audit import audit_project
result = audit_project(Path("."))
print("Grade:", result.grade, "Score:", result.quality_score)
# Grade: A — 95.0/100
Features
- 🔍 Linting — Ruff for Python; ecosystem-specific tools for JS/TS
- 🔒 Type Safety — mypy or TypeScript using project configuration
- 📊 Complexity — Cyclomatic + cognitive complexity (radon + complexipy)
- 🛡️ Security — Bandit integration + hardcoded secrets detection
- 📦 Dependencies — Vulnerability scanning (pip-audit) + hygiene (deptry)
- 🧪 Testing — Coverage enforcement via pytest-cov
- 🏗️ Architecture — Circular imports, god classes, coupling metrics, duplication detection
- 📐 Practices — Docstring coverage, bare except detection, blocking I/O, test mirroring
- 🔧 Tooling — CLI tool availability checks
- ⚡ Fast & Typed — Direct Python APIs, strict mypy, high test coverage
Learn More
- Getting Started Tutorial
- Run an Audit
- Audit Categories
- CI Badge
- Custom Rules
- Use via MCP
- Read Results
- Troubleshooting
- Architecture
- Scoring
- Glossary
Contracts and scope
- CLI and tools
- Frameworks and workspaces
- Configuration and exclusions
- Python API
- Witness quality gate
The table above describes Python measurements. Frameworks differ, and a score can be unavailable. A successful tool call can contain failed checks.