Free workshop: build with AI without losing control of your project View the workshop →
vibebusters

// AI-generated code audit

Your agent wrote the code. Find out if someone else can take it over.

Claude Code, Codex, Antigravity or another agent can build quickly. The Scan checks whether someone else can understand, run, change and test the repository without starting again.

// takeover index

10 checks, 5 areas, one score out of 20

Each point receives 0, 1 or 2 based on observable evidence in the repository. The report shows the evidence, not only the score.

0missing or blocking 1partial or inconsistent 2present and verified
01
STR

Structure

  1. STR.1 Responsibilities of modules and files EVIDENCE REQUIRED
  2. STR.2 Coupling, boundaries and data flow EVIDENCE REQUIRED
02
REA

Readability

  1. REA.1 Naming and consistency of conventions EVIDENCE REQUIRED
  2. REA.2 Complexity of functions, components and files EVIDENCE REQUIRED
03
VER

Verification

  1. VER.1 Tests for critical journeys EVIDENCE REQUIRED
  2. VER.2 Reproducible build, types, lint and CI EVIDENCE REQUIRED
04
TAK

Takeover

  1. TAK.1 Documented installation and configuration EVIDENCE REQUIRED
  2. TAK.2 Explained architecture, decisions and dependencies EVIDENCE REQUIRED
05
EVO

Evolution

  1. EVO.1 Dependencies, duplication and unused code EVIDENCE REQUIRED
  2. EVO.2 Versioning, change discipline and agent instructions EVIDENCE REQUIRED
0–5 Initial mapping required
6–10 Takeover needs guidance
11–15 Takeover with reservations
16–20 Transferable

The Takeover Index measures the code and its transferability. Security, account ownership, infrastructure and scaling remain separate parts of the complete Scan.

// what you receive

A report you can use without reading the code

The first page explains the situation. The appendices let a developer find each piece of evidence and prepare the corrections.

E-01

The Takeover Index

The score out of 20, five area scores and the evidence behind each result.

E-02

The takeover test

The steps actually verified to install, configure, run and test the project.

E-03

The priorities

Five actions ranked by impact, with an indicative level of effort.

E-04

The evidence

Files, commands, behaviours and metrics that make every finding verifiable.

// report extract

Every finding connects the code to a decision

Illustrative example based on a fictional project. It shows the report's level of detail, not a client's result.

REA.2 HIGH PRIORITY
Finding

The payment component combines rendering, pricing rules, API calls and state management in 742 lines.

Evidence

One file carries four responsibilities, 19 local states and 11 network calls. No test covers plan changes.

Proposed decision

Separate pricing rules and API access, then cover the three payment journeys before the next commercial change.

A working app does not tell you whether the repository is transferable

Using an agent does not determine whether code is good or bad. Claude Code, Codex and Antigravity can read a repository, change multiple files and run tests. The result also depends on the context they receive, the checks that run, the decisions made and how changes are reviewed.

The audit therefore answers a concrete question: can someone who was not part of the prompts take over the project without rediscovering everything?

The score never replaces the findings

Two repositories can receive the same score for very different reasons. One may be well structured but lack tests. Another may have tests while remaining difficult to understand. The report preserves the five area scores, the evidence and the recommended actions. A critical issue is never hidden by an average.

KERN-IT is an AI-native agency

KERN-IT engineers use AI in their own development process. Code remains versioned, reviewed, tested and tied to acceptance criteria. The tool accelerates the work. The team remains responsible for the architecture, decisions and delivered result.

That experience lets us assess a repository without an anti-AI stance. We know what agents do well, what depends on context and where human verification still matters.

Repository only or complete application

If you only need to understand and take over the code, the Takeover Index forms the core of the report. If you also need to assess data, accounts, security, deployment or scaling, the complete Scan connects the repository to the rest of the application. You can prepare access with the control checklist and review our assessment method before the first call.

// faq

The questions we keep hearing

Is this only for Lovable or Bolt apps?

No. The repository may have been built with Claude Code, Codex, Antigravity, Cursor or any other agent. We assess what is in the code, not the tool's brand.

Does the score say whether my application is secure?

No. The Takeover Index measures structure, readability, verification, documentation and ability to evolve. Security remains a separate area of the complete Scan, and any critical issue is reported independently of the score.

Do I need to understand the code to read the report?

No. The summary explains the project impact in plain language. Technical evidence remains available in the appendices for whoever carries out the corrections.

Will you change the repository during the audit?

No. The assessment starts read-only. Tests and measurements run in an isolated copy when needed. Nothing is pushed to your repository without written approval.

How much does the code audit cost?

It uses the same entry point as the Scan: from €1,800 excl. VAT as a fixed fee, with the report delivered within 72 working hours. We confirm scope based on the repository's size and technologies before starting.

Give us the repository, not your assumptions

We confirm scope, read-only access and price before the assessment starts.

Discuss my repository