Twenty analyzers.
One gate.
Claude reads the verdict.
Noeticar runs ruff, mypy, bandit, semgrep, trivy and 15 more analyzers, merges them into a single 0–100 quality score, then asks Claude to review the result like a senior engineer: what's real, what's noise, and what the tools missed.
# scan + Claude second opinion $ noeticar scan . --second-opinion ruff ✓ mypy ✓ bandit ✓ semgrep ✓ radon ✓ +15 score 78/100 gate FAIL (threshold 85) 41 findings · 3 high · 12 medium claude-sonnet-5-5 · second opinion agree B608 SQL built with f-string api/search.py:88 dispute B105 "token" is a constant name, not a secret missed retry loop never backs off queue.py:142 reorder fix B608 first — it is user-reachable confidence 0.82 · 31.4k in / 1.9k out tokens
Analyzers find candidates. Claude decides what matters.
Static analysis is precise but noisy; LLM review is flexible but needs grounding. Noeticar gives Claude the structured scan, code snippets and your team's knowledge base, and asks for a verdict it can defend.
Run every analyzer once
UCC orchestrates 20 runners in parallel, normalises severities and produces one score, SARIF and an SBOM.
Claude second opinion
Claude Sonnet 5.5 agrees, disputes, adds missed issues and re-ranks priorities, returned as strict JSON with a confidence value.
Remember the decisions
GloryStory, a local knowledge base, stores accepted and rejected findings so the next review starts from your team's history.
Why Claude does the reviewing
Noeticar is built on Claude by Anthropic. The Claude API is the default provider, and the MCP server is designed for Claude Code.
- Long context. A whole scan, the relevant snippets and prior KB decisions fit in a single request, so the review sees the full picture.
- Reasoning you can audit. Every dispute carries a reason and a suggested severity; nothing is silently dropped.
- Cost routing. The Plano router sends cheap triage to Haiku 5.5 and deep reviews to Opus 5.5, based on hotspot, impact and diff-size signals.
B608 Query string built with an f-string reaches cursor.execute from a request parameter.B105 TOKEN_HEADER = "X-Token" is a header name, not a credential. Suggest: info.queue.py has no backoff or cap; under an outage it hammers the broker.The right Claude model for each job
Triage
claude-haiku-5-5Small diffs and low-impact changes: fast, cheap first pass.
Review
claude-sonnet-5-5Default second opinion for every scan.
Deep dive
claude-opus-5-5Hotspot files and high blast-radius changes.
44 tools your Claude Code agent can call
Connect once with claude mcp add noeticar -- noeticar-mcp. Your agent can scan before committing, check the gate, look up past decisions and ask for a second opinion without leaving the session.
noeticar_gate
noeticar_fix
noeticar_dimensions
noeticar_sbom
noeticar_second_opinion
noeticar_analyze
noeticar_hotspots
noeticar_impact
noeticar_dora_metrics
noeticar_health
noeticar_workspace_health
noeticar_kb_search
noeticar_kb_add
noeticar_kb_link
noeticar_scan_and_learn
noeticar_scan_changed_and_explain
noeticar_unified_search
noeticar_semantic_search
noeticar_plano_route
noeticar_plano_budget
noeticar_plano_guardrails
noeticar_baseline
noeticar_policy_packs
… and 20 more
FAQ
Which AI model does Noeticar use?
Noeticar is built on Claude by Anthropic. The second-opinion review defaults to Claude Sonnet 5.5 through the Claude API, and the router can use Claude Haiku 5.5 and Claude Opus 5.5. Local models through Ollama are supported for air-gapped setups.
Does my code leave my machine?
The analyzers run locally. Only the scan summary and the snippets you allow in [second_opinion.scope] are sent to the Claude API, and you can cap the context size.
Does Claude change my code?
No. Claude produces a review; fixes come from deterministic auto-fixers (e.g. ruff) or from your own agent, and the quality gate stays the source of truth.
Is it free?
Yes, MIT-licensed and self-hosted. You bring your own Anthropic API key for the Claude review.