NVIDIA Nemotron on Nebius Token Factory

Read a codebase
before you own it.

Paste a public repository. CodeLens parses it with Tree-sitter, builds the real import graph, ranks the files that actually hurt, checks what it claims against live sources, and hands back findings you can click through to a line.

No account, no signup. Rate limits apply.

Everything below is computed, not guessed.

A language model reading files produces opinions. CodeLens produces measurements first, then lets the model argue about them - so every number on the dashboard can be traced back to the file it came from.

Real parsing, 19 languages

Tree-sitter parses Python, JS/TS/TSX, Go, Java, Rust, C/C++, C#, Ruby, PHP, Kotlin, Scala, Lua, Elixir, Perl, R and Bash into an AST. Functions, classes, branching nodes and imports come out of the syntax tree, not out of a regex guess - and a file in any other language still reaches the walk as text.

A dependency graph you can walk

Imports are resolved to files, giving real fan-in and fan-out per module. The 3D view is that graph - click a node and read the file it points at.

Hotspots with stated reasons

Ranked by cyclomatic complexity, blast radius, commit churn and open findings. Every rank explains itself: 'imported by 14 other files', 'changed in 37 commits in the last year'.

18 deterministic security rules

Committed credentials, private keys, unsafe deserialization, shell and SQL injection, path traversal, JWT alg=none, CORS wildcards. AST-backed where the grammar allows it, each finding anchored to file and line.

Claims checked against the web

Dependency verdicts are researched live through Tavily. Each answer carries the source links it came from, and anything unverified is labelled unverified instead of being asserted.

A patch that applies

The Fix Advisor writes a unified diff and the server checks it with git apply against the real clone before you ever see it. If it does not apply, you are told so.

The pipeline

From a URL to a reviewable finding.

  1. Clone, shallow and validated

    Only public github.com URLs are accepted, over https, cloned at depth 1. Every path that later reads a file is checked against the clone root, so a crafted path cannot walk out of it.

  2. Parse, then measure

    Files are parsed with Tree-sitter, imports are resolved into a graph, and per-file metrics are computed: complexity, fan-in, fan-out, size, commit churn, findings.

  3. Rank and review

    Hotspots are scored from those signals. The heavyweight Nemotron model reviews the findings and writes the architecture summary, chunked so a large repository still fits.

  4. Ground and verify

    Tavily research backs the dependency and security claims with links. The Fix Advisor turns a finding into a diff, validated against the clone.

progress stream
  • [clone] depth 1, https only
  • [parse] tree-sitter · N files
  • [graph] imports resolved · N edges
  • [hotspot] complexity · fan-in/out · churn
  • [pre-scan] 18 rules · N findings
  • [research] tavily · sources attached
  • [review] nemotron · heavy model
  • [done] report ready

Progress is streamed to the browser over Server-Sent Events. Nothing here is pre-recorded: this is the shape of the log a real run prints.

Two models, chosen per job.

Heavy model, deliberate work

Finding triage and the architecture summary need judgement over the whole repository, so they go to the larger Nemotron model on Nebius Token Factory.

not configured on this instance

Fast model, everyday work

Chat, tool calls and patch drafting are latency-sensitive and run on the smaller, quicker Nemotron model, which keeps the dashboard responsive.

not configured on this instance

Live search, no memory

Tavily does the web lookups, so a CVE identifier or an outdated-package claim is checked now rather than recalled. Sources are attached to the finding.

Tavily Search API

Model IDs are read from the running server, not hardcoded into this page: if the instance is configured you see the exact model it will call, and if it is not, the status panel below says so.

What this instance can do right now.

Asked of /health rather than assumed.

Checking what this instance can do...

Point it at something you maintain.

The heritage of a codebase is usually written down nowhere. Put in a URL and read what the code says about itself.