Does the code match the label?
Third-party ingredient analysis for AI-slop repos — a badge that says whether the code matches the README.

Every README is a label. Most are lying.
A wave of AI-assisted, vibe-coded, half-generated repos ships daily. That isn't the problem — the problem is when the label and the jar disagree.
"production-ready Rust JavaScript runtime with multi-agent graph intelligence"
three markdown files, a TODO, and a dream.
is this code good?
We don't grade code. We check whether the label is honest.
Code-quality oracles already exist and nobody trusts them. The useful, missing trust layer is narrower: are the claims, examples, and packaging truthful?
A repo can be rough, AI-assisted, incomplete, or cursed and still earn a good badge — if the label matches the jar. Transparent slop wins.
A badge — and the score card behind it.
Five classes. Every badge discloses its diligence level and scope. Tag your repo and it points at a hosted report — or inline the entire card in the README.
label match
A real project whose README outruns the code. 'Production-ready, blazing-fast, multi-agent graph intelligence' with one benchmark claim and no benchmark artifact, plus a 'supports Python, TypeScript, and Go' line where only TypeScript files exist. The core does work — it is just oversold. Wet slop.
Escalating scrutiny. Cheap to start, deep when it counts.
We make inference engines adjudicate, not explore — they judge a compact evidence packet, never wander 30k tokens debating "blazing fast." That's the margin.
Label Scan
Deterministic pass over README, tree, and manifests. No clone, no execution. Slop class + label-match score.
Evidence Scan
Symbol + import graph maps every claim to files, tests, and examples. Evidence packets with source spans.
Attested Scan
Sandboxed build / test / CLI probes, multi-model adjudication, evidence hashes. Chain-of-custody attestation.
The business is escalation.
Static badge + L1 label scan. Hosted report. Zero execution.
GitHub Action. User's CI + model key. Recurring scans on every push.
L2 evidence + symbol graph. Drift tracking. Better judge model.
Sandboxed probes + multi-model + human review. The strongest badge.
Anyone can buy a repo a deeper inspection. Diligence becomes a social object — funny enough to share, useful enough to pay for.
"Mmm — that's a good scrabcake."
AI code isn't going away. Neither are misleading READMEs.
The badge lives in the README. Every tagged repo is an ad, and every reader is one click from a hosted report. The growth loop ships inside the artifact.
Make disclosure funny enough that people actually use it — then turn that disclosure into a real third-party attestation product the moment it's needed.
Label the jar.
We dogfood it. Scrabcake scanned itself and came back meatless cake — mostly marketing, little code. Our own badge says so. Transparent slop wins, and the cake will gain meat.
We're applying to Y Combinator to build the trust layer for a world where most code is AI-assisted.