Ambera

Before you sign

Someone told you it all needs rewriting.

Maybe it does. But a rebuild is the largest contract available to whoever is quoting it, and “I don’t understand this yet” reads a lot like “this is bad” from the inside. Read the codebase first, with something that has nothing to sell you.

Private repo? npx @ambera/review-tax read — runs on your machine, sends nothing anywhere.

What you get

Four questions, answered with counts.

Not a score, not a grade, and not a recommendation. The reading states what was measured, over how much of your codebase, and what it could not see.

What is actually dangerous in here?

Findings carry a severity fixed by the TYPE of finding, decided once and identical for every repository — so nothing is inflated for your quote. Red appears only at the top of that scale: a credential committed to the repository, a privileged key shipped to the browser. Most findings are not emergencies, and the read says so by not saying otherwise.

Is this normal, or unusually bad?

Each finding can be placed against every repository Forge has read — a count alone is unreadable to someone hearing it for the first time. Where the corpus is too thin to say, it withholds rather than producing a confident-looking number.

How would I know if it were fixed?

Every finding carries a machine-checkable criterion: the detector runs again and observes nothing. Not an opinion, not a judgment call — which means you can verify the work you paid for without being able to read the code yourself.

Does the whole thing have to be replaced?

Forge will not answer that, and no honest instrument would — it is a judgment about your business, your runway and your roadmap. What it gives you is the evidence the judgment should be made from, in a document you can put in front of the person who quoted you.

Why this is a second opinion and not a third sales pitch

The incentive, stated plainly.

It does not do the remediation work

Forge reads and reports. It does not take refactoring contracts, so it has no reason to find more work than exists — the structural conflict of interest in asking the person who would do the rebuild whether you need one.

The findings are deterministic, not a model’s opinion

The same repository always reads the same, because the detectors are text analysis with published rules rather than a language model forming a view. Two readings that disagree mean the code changed.

You can run it yourself, for free

npx @ambera/review-tax read runs the same deep read on your own machine — no account, nothing uploaded, private repositories included. If you would rather not take our word for the numbers, don't.

It grades itself afterwards

When work gets filed and a later reading runs, Forge reports whether each finding moved — including where it did not, and including when it cannot tell. A report that could only ever say good things would be worth nothing to you here.

The free read covers any public repository, and the CLI covers private ones on your own machine. A Launch Audit ($69 at launch pricing, $99 after) connects one private repository for 90 days: the deep read, nightly re-reads so the work can be graded, and a closing document comparing the first reading against the last. The whole method, including where the read is wrong, is at forge.ambera.app/methodology.