Quality Audit Report

bolt.diy: Stackblitz's Open-Source AI IDE.
268 Violations. Score: Zero.

We pointed Rigour at bolt.diy — stackblitz's open-source ai ide. 15k+ stars.. The scan took 325ms. 268 violations across 365 files.

February 17, 2026| 365 Files Scanned| 2,840 Patterns| 325ms
0/100
Rigour Score
FAIL
268
Total Violations
3 / 10
Gates Failed
24
Oversized Files
189
Complexity Violations
3
Security Flags
32
Abandoned TODOs

Quality Gate Results

Environment Alignment
Retry Loop Breaker
File Size
Content Check
Structure Check
AST Analysis
Dependency Guardian
Safety Rail
Coverage Guard
Context Drift

Violation Breakdown

File SizeFiles exceeding 400 lines
24
AST ComplexityFunctions with cyclomatic complexity violations
189
Abandoned TODOsTODO/FIXME comments never resolved
32
Max ParamsFunctions with too many parameters
12
Max MethodsClasses with too many methods
8
Content ViolationsHardcoded secrets or debug patterns
3

24 Oversized Files

Twenty-four files exceed the 400-line threshold. The worst offender — BaseChat.tsx at 892 lines — is a single React component handling chat UI, message parsing, file uploads, streaming, and keyboard shortcuts all in one file. This is a common pattern in AI-generated code: everything works, but the architecture is a monolith pretending to be modular.

Worst Offenders

app/components/chat/BaseChat.tsx892 lines
app/lib/modules/llm/manager.ts784 lines
app/components/workbench/Workbench.client.tsx671 lines
app/routes/api.chat.ts623 lines
app/lib/stores/workbench.ts589 lines

189 Complexity Violations

Nearly two hundred functions exceed safe cyclomatic complexity thresholds. The LLM manager, workbench store, and action runner are the worst offenders. These are the modules that orchestrate bolt.diy's core functionality — and they are deeply nested, heavily branched, and difficult to test or modify safely.

32 Abandoned TODOs

Thirty-two TODO and FIXME comments left behind. In a project that ships as fast as bolt.diy, these represent deferred decisions that compound into technical debt. Each one is a known gap that was punted rather than addressed.

3 Security Concerns

Three patterns flagged by Rigour's safety rail. API key exposure via query parameters in development mode, unvalidated config merges in the LLM provider system, and shell command construction from user input. These are common in rapid prototyping but dangerous in a tool that executes code.

Smaller Codebase, Same Pattern.

bolt.diy is a fraction of OpenClaw's size — 365 files vs 2,094. But the pattern is identical: AI-generated code that ships fast, passes tests, and accumulates structural debt underneath.

The difference is scale, not kind. bolt.diy has 268 violations in 365 files (0.73 per file). OpenClaw has 2,080 violations in 2,094 files (0.99 per file). Both score zero. Both fail the same gates. The complexity-per-file ratio is remarkably consistent — suggesting this is a systemic property of AI-generated code, not a project-specific failing.

If both the most popular AI agent and the most popular AI IDE score zero on a quality audit, maybe the problem isn't the projects. Maybe it's the process.

Try It On Your Repo.

Rigour is open source, local-first, and runs in under 4 seconds. Zero cloud. Zero telemetry. MIT licensed.

$ npx @rigour-labs/cli init
$ npx @rigour-labs/cli check

All data generated by running rigour check against the public bolt.diy repository on February 17, 2026. Full JSON report available on request.