It reads the code without running it and without installing anything in the project. What it finds is stored outside the project.
PHP
Classes, functions and what each one calls. Symfony: #[Route] routes, commands, services, Doctrine. composer.json, its lock file and vendor/.
TypeScript and JavaScript
React, Angular and Ionic (routes, modules, guards, components, services and their API calls), Node and Capacitor. package.json, tsconfig and node_modules/.
Go
Packages, types, methods and interfaces, and who implements them. Routes for net/http, chi, gin, echo and fiber. go.mod and go.sum.
SQL and databases
The tables the code names and, if you give it access, the real database: MySQL, PostgreSQL or Supabase, always read-only.
Everything around it
sh scripts, the Dockerfile, compose, GitHub Actions and .env files (with secrets masked): who calls whom and which variable each file uses.
And it uses your tools
Tests: vitest, jest, mocha, playwright, phpunit, pest, go test and ng test. Quality: phpstan, psalm, phpmd, phpcs, eslint, tsc, go vet, staticcheck and golangci-lint. Whatever the project already has: it installs none of them.